Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

29 results about "Threatening behaviour" patented technology

Threatening behavior is intentional behavior which would cause a person of ordinary sensibilities fear of injury or harm. It can include acts of aggression such as yelling at a colleague, pounding on desks, slamming doors,blocking or cornering, and sending threatening voice-mails, e-mails, or other written threats.

Internal threat detection method, system and equipment based on behavior analysis and medium

The invention relates to an internal threat detection method, system and device based on behavior analysis and a medium, and the method comprises the steps: obtaining multi-modal data of a user operation environment, carrying out the time sequence alignment of the multi-modal data based on a time window mechanism, generating a multi-modal feature data set, and constructing a dynamic behavior model in combination with the context information of user behaviors. Performing secondary modeling on the dynamic behavior model by using a graph neural network to generate a user behavior graph; generating an adversarial network based on the user behavior graph so as to generate simulated threat behavior data, and dynamically generating a behavior anomaly detection model by using a reinforcement learning method in combination with the simulated threat behavior data and the user behavior graph; performing threat detection according to the user behavior anomaly detection model, identifying an abnormal behavior, and generating a threat detection result; and calculating a trust score according to the threat detection result, and generating a response priority strategy based on the trust score to execute a response operation on the abnormal behavior. The method has the effect of improving the internal threat detection efficiency.
Owner:SHENZHEN TG NET BOTONE TECH

Systems and methods for privacy-aware weapon anomaly detection via integrated object recognition and skeletal motion analysis

Systems, methods, and frameworks are provided for privacy-aware weapon anomaly detection via integrated object recognition and skeletal motion analysis. This framework integrates real-time object detection and motion analysis to identify weapon anomalies in video surveillance while preserving privacy. The framework combines a fine-tuned object detection model, a head-segmentation module for anonymizing unarmed individuals, and a skeleton-based motion analysis module to detect threatening behaviors. By refining and fusing detection and motion analysis outputs, the framework enhances detection accuracy and reduces false positives, thereby providing a reliable solution for intelligent, privacy-preserving surveillance applications.
Owner:FLORIDA INTERNATIONAL UNIVERSITY

Hospital terminal threat behavior identification method based on interpretable deep learning

The invention discloses a hospital terminal threat behavior recognition method based on interpretable deep learning, and particularly relates to the technical field of network security, threat intelligence analysis and interpretable artificial intelligence. According to the method, a multi-modal hospital terminal operation data set fusing time sequence images, logs and other data is constructed, and different modal data are effectively integrated by adopting a multi-modal data fusion method; integrating a dynamic attention mechanism into a long short-term memory network model for adaptively extracting key features in a terminal user behavior sequence; and a double-layer interpretable framework based on gradient weighted class activation mapping and a local interpretable model irrelevant interpretation technology is introduced, so that high-precision recognition and interpretable analysis of the threat behavior of the hospital terminal user are realized. According to the method, complex threat behaviors in the hospital terminal can be efficiently and accurately identified, the limitation of a traditional method in the aspects of data diversity, interpretability and hidden threat detection is overcome, and the transparency and efficiency of threat analysis are enhanced.
Owner:YUNLONG LAKE LAB OF DEEP UNDERGROUND SCI & ENG +1

Ai multi-domain integrated system and method for automatic generation of cyber crisis scenario

There is provided a method for automatically generating a cyber crisis scenario, performed by a computing system. The method may comprise classifying types of content included in a cyber crisis report and extracting image data and text data from the cyber crisis report, inputting the image data into an image processing model and extracting attack procedure / behavior information included in the image data, inputting the text data into a text processing model and generating structured attack procedure-related data from each attack procedure included in the text data, generating threat behavior data corresponding to the attack procedure-related data, and merging the threat behavior data with the attack procedure-related data, matching the attack procedure-related data to the attack procedure / behavior information and generating a cyber crisis scenario template and automatically generating a cyber crisis scenario based on the attack procedure-related data and the cyber crisis scenario template.
Owner:KOREA INTERNET & SECURITY AGENCY

Method for detecting and analyzing time-series data based on cyber threat framework

This disclosure details a method for detecting and analyzing time-series data with a cyber threat framework. It involves determining target API events, mapping these to threat behaviors, creating threat scenarios, assessing matching degree and risk, predicting threat behaviors based on risk grades, and providing solutions.
Owner:INITECH

Cable tunnel anti-theft and anti-external damage monitoring subsystem and monitoring method thereof

The invention discloses an anti-theft and anti-external damage monitoring subsystem for a cable tunnel and a monitoring method of the anti-theft and anti-external damage monitoring subsystem. According to the system, distributed optical fiber sound wave sensing networks are deployed in a tunnel and underground above the tunnel, and a ground pulsation sensor array in the tunnel is combined. The system adopts a multi-mode threat recognition AI engine, vibration and sound wave signals are classified and recognized through a deep learning model combining a one-dimensional convolutional neural network and a long-short-term memory network, and a threat position and a behavior mode are judged by utilizing a space-time correlation analysis engine. The system further comprises a threat level comprehensive evaluation model which can output quantitative threat indexes and trigger a hierarchical alarm mechanism, and meanwhile, the intelligent video rechecking unit is linked to carry out visual confirmation. According to the invention, accurate identification, accurate positioning and intelligent early warning of threat behaviors inside and outside the tunnel are realized, the problems of high false alarm rate and early warning lag of a traditional monitoring system are effectively solved, and the safety protection level of the cable tunnel is obviously improved.
Owner:SANYE ELECTRIC CO LTD

Internal threat behavior detection method based on few-sample learning

The invention relates to the technical field of network security, in particular to an internal threat behavior detection method based on few-sample learning, and the method comprises the steps: cleaning and normalizing an original data set, and removing interference information composed of noise, missing items and abnormal values; performing feature extraction and dimension reduction operation on the data, and converting the data into a time sequence form; the processed time sequence data are input into a Diffusion-TS model to be trained; gradually adding noise to the time sequence data, denoising in a reverse process to generate high-quality time sequence data, and retaining time sequence dynamic characteristics by using a trend decomposition module; mixing the generated threat behavior data with an original data set to obtain a data set with positive and negative samples tending to be balanced; performing threat detection on the enhanced data set by using an LSTM-DWFCN model; and an output result of the fusion module is spliced, the model is further subjected to nonlinear transformation through an activation function, finally classification information is obtained, and accurate recognition of a complex threat behavior mode is realized.
Owner:GUILIN UNIV OF ELECTRONIC TECH +1

Anti-attack method and system for improving security of intelligent terminal

The invention provides an anti-attack method and system for improving the security of an intelligent terminal, and the method comprises the steps: extracting a parallel call feature of each task process in the intelligent terminal from a behavior data flow of a parallel task process in the intelligent terminal; determining a threat behavior sequence of the parallel task processes in the intelligent terminal according to each parallel calling feature and a communication relationship between the task processes in the intelligent terminal; performing reverse tracking dependence positioning on each threat behavior in the threat behavior sequence according to an intelligent terminal attack tracing module to obtain a plurality of attack dependence nodes of the threat behaviors in the intelligent terminal, and further generating a threat map of an attack link through all the attack dependence nodes; the threat graph is used for automatically generating the hotfix of the threat behavior in the intelligent terminal, and then the loophole is repaired in a mode of differently updating the hotfix without influencing the normal service of the intelligent terminal. On the basis of the scheme, hotfix repair of the attack behavior of the intelligent terminal can be realized, so that the guarantee service continuity of the intelligent terminal can be improved.
Owner:SHENZHEN TOPWISE COMM CO LTD

A pipeline threat behavior identification method and device and a storage medium

The application discloses a pipeline threat behavior identification method and device and a storage medium, and relates to the technical field of machine vision. The method comprises the following steps: acquiring a to-be-detected video photographed by unmanned aerial vehicle inspection; performing target detection on image frames of the to-be-detected video, determining target detection boxes of detection objects in the image frames and target categories of the detection objects; performing trajectory tracking on the target detection boxes to obtain target trajectories of the detection objects; extracting behavior features of the detection objects, wherein the behavior features comprise morphological change features of the detection boxes and trajectory features of the target trajectories of the detection objects; and identifying pipeline threat behaviors of the detection objects based on the target categories, the behavior features of the detection objects and a pre-trained classification model. The method can effectively detect small targets such as personnel and vehicles, effectively determine threat behaviors such as personnel loitering, personnel digging and mechanical digging, and the algorithm has the light-weight feature.
Owner:PIPECHINA SOUTH CHINA CO +1

Resource pool intelligent protection system and method

The invention relates to the technical field of resource pool protection, and discloses an intelligent protection system and method for a resource pool, and the system comprises a construction module which is used for determining a plurality of node function types and constructing an attack recognition model; the determination module is used for setting a data acquisition strategy of the to-be-identified resource node and acquiring real-time audit data of the to-be-identified resource node; the analysis module is used for analyzing the real-time audit data based on the attack recognition model to obtain recognition identifiers, and the recognition identifiers comprise a threat behavior identifier, an unknown behavior identifier and a normal behavior identifier; the calculation module is used for screening out abnormal data and calculating a protection evaluation value corresponding to the to-be-identified resource node when the to-be-identified resource node is not a normal behavior identifier; and the correction module is used for judging whether the corresponding security protection strategy is corrected or not according to the protection evaluation value, if yes, a correction instruction of the security protection strategy is generated, and the security protection efficiency of the resource pool is improved.
Owner:HUANENG INFORMATION TECH CO LTD

Method, device, and computer-readable recording medium for visualizing route and behavior of user by linking security threat and security kernel of server-terminal connection network

In order to provide a technology, when an access having the possibility of a threatening factor according to an access failure is detected, for collecting information about the access to intuitively display the route of the threatening behavior on an interface that outputs the server-terminal connection network, and directly replaying the threatening behavior to intuitively identify the information on the access and easily identify a cause of the threat, a method for visualizing a route and a behavior of a user by linking a security threat and a security kernel of a server-terminal connection network according to one embodiment of the present invention includes: an access detection step of setting a plurality of terminals, servers accessible from the terminals, and communication processing devices between the terminals and the servers as nodes, and detecting an attempt to access one server from one terminal in a server-terminal connection network including a route on the network connecting the set nodes as links; a log collection step, based on the access detected in the access detection step, of collecting log information generated when the one terminal attempts to access; and a visualization step, when a visualization request input for the log information collected in the log collection step is received from an administrator terminal, of visualizing the nodes, the links and the log information on a visualization interface executed in the administrator terminal, wherein the visualization step, with respect to the log information on access failure, includes using the log information to display a node including a terminal attempting the access and a server to be accessed and links between nodes, and a visual effect indicating failure of log information, on the visualization screen of the server-terminal connection network on the visualization interface.
Owner:SGA SOLUTIONS CO LTD

Threat mitigation for vehicles

ActiveCN114630777Bactivate visual deterrentsActivation of auditory deterrentsControl cellTransport engineering
A method for controlling a vehicle is disclosed. The method comprises determining whether one or more surrounding vehicles exhibit a threatening behavior, and controlling the vehicle to perform one or more threat-avoidance actions when it is determined that one or more surrounding vehicles exhibit a threatening behavior. Example threatening behaviors include a first surrounding vehicle directly in front of the vehicle decelerating without a traffic-related reason for deceleration, and, in combination with the former, a second surrounding vehicle in a lane adjacent to the vehicle decelerating in association with the first surrounding vehicle. Corresponding computer programs, computer program products, control units, devices, systems, and vehicles are also disclosed.
Owner:NINGBO GEELY AUTOMOBILE RES & DEV CO LTD

Network security test and evaluation system and method

The invention belongs to the technical field of network security, and discloses a network security test and evaluation system and method, and the system comprises an asset and topology automatic discovery module, a threat behavior simulation and attack chain generation module, a security configuration difference analysis module, a risk quantification and evaluation module, and a linkage protection and verification module. The system recognizes network assets and the dependency relationship thereof through passive traffic analysis and active exploration, generates an attack surface model based on an asset structure, constructs a candidate attack chain by using a heuristic search method, and executes threat simulation operation in a controlled environment. The system can also perform difference analysis on the actual configuration of the target asset and the baseline, calculate a risk index in combination with a simulation result, and automatically trigger a protection measure and verify the effectiveness when the risk reaches a threshold value. According to the method, continuous, real and reproducible security assessment can be realized in a complex network environment, and the risk discovery capability and the reliability of a protection strategy are improved.
Owner:李师谦

AI-based cybersecurity system trained with multimodal large models

ActiveCN120281550BImprove fault prediction accuracyImprove attack detection accuracyKey distribution for secure communicationUser identity/authority verificationAttackMultidimensional data
This invention relates to the field of intelligent security operation and maintenance technology, specifically to an artificial intelligence network security system based on multimodal large model training. The system includes a server fault diagnosis module, a network attack detection module, an endpoint security monitoring module, a key management optimization module, and a threat analysis feedback module. In this invention, multidimensional data analysis improves the accuracy of fault prediction, reducing business interruptions caused by sudden hardware failures. Based on server anomaly assessment, network access frequency, source, and command characteristics are evaluated to improve attack detection accuracy and reduce the risk of false positives. Endpoint device execution behavior, resource calls, and behavior sequences are extracted to achieve fine-grained security monitoring, enhancing attack tracing capabilities. Key policies are dynamically adjusted to improve security adaptability and reduce policy lag risks. Multi-level data is integrated to calculate the fit between threat behavior and attack, enhancing the precision and response speed of threat assessment and improving overall security situation awareness.
Owner:SHENZHEN JINCHAO CLOUD CONTROL TECH CO LTD

Method for mapping API function to threat action in a plurality of cloud environments

To provide a method for effectively identifying and responding to security threats occurring in various cloud environments.SOLUTION: A method for mapping API functions to threat actions in a plurality of cloud environments by a server, comprising the steps for (a) mapping a first API function used in a first cloud environment provided by a first cloud server to a first threat action included in an attack technique database (wherein the attack technique database includes a plurality of threat actions classified into a plurality of types); (b) generating feature information of the first API function based on explanatory information for the first API function provided by the first cloud server; (c) identifying a second API function that matches the first API function among at least one API function used in a second cloud environment provided by a second cloud server based on the feature information for the first API function; and (d) mapping the second API function to the first threat action.SELECTED DRAWING: Figure 4
Owner:ASTRONSECURITY

Vehicle sentry mode threat early warning method and system and vehicle

PendingCN121963440ASolve the problem of low accuracy in identifying threat intentDetection of traffic movementBiological modelsEngineeringThreat level
The invention relates to the technical field of vehicles, in particular to a vehicle sentry mode threat early warning method and system and a vehicle. The method comprises the following steps: acquiring multi-mode sensing data acquired from the periphery of a vehicle body in a sentry mode; extracting key features of each mode in the multi-mode sensing data through an adaptive backbone network to obtain a multi-mode feature sequence; inputting the multi-modal feature sequence into a cross-modal feature interaction fusion module to generate an advanced semantic feature sequence containing threat behavior information; inputting the high-level semantic feature sequence into a high-level semantic reasoning module so as to carry out mixed decision making by utilizing a propagation algorithm based on a causal graph and a symbolized behavior rule knowledge base, and outputting a multi-dimensional behavior intention result; according to the method, quantitative threat assessment is executed according to a multi-dimensional behavior intention result, threat levels of multiple levels are output, differentiated early warning and response strategies are triggered based on the threat levels, and the problem that the potential threat intention recognition accuracy of an existing method is low can be effectively solved.
Owner:BEI DOU ZHI LIAN KE JI YOU XIAN GONG SI

A cyber-security incident handling and assessment system

This invention relates to the field of cybersecurity technology, specifically to a network security incident handling and assessment system. Based on an internet security protection system, this invention collects traffic and identifies threat behaviors from various security protection products such as situational awareness and cloud defense. Upon detecting a security incident, it issues an alert, prompting operations and maintenance (O&M) personnel to take action. The effectiveness of the handling methods is then evaluated, and highly-rated methods are tagged and stored in a method library. When similar security incidents occur again, appropriate handling methods are recommended based on the matching results, assisting O&M personnel in decision-making. Finally, historical data on the security incident handling process is statistically analyzed and displayed in a radar chart format, showing the O&M personnel's skills in dealing with attack threats. This not only allows O&M personnel to continuously iterate their handling plans for various security incidents to obtain optimal solutions, but also presents the O&M personnel's skill level graphically, achieving the purpose of identifying gaps in knowledge and targeted improvement.
Owner:THE 54TH RESEARCH INSTITUTE OF CHINA ELECTRONICS TECHNOLOGY GROUP CORPORATION

A method, apparatus, equipment and storage medium for producing threat intelligence

This invention discloses a method, apparatus, device, and storage medium for producing threat intelligence, applied in the field of network security. The method includes: acquiring raw threat information corresponding to IPs without threat intelligence within a preset time period; aggregating the raw threat information based on the IPs to obtain aggregated raw threat information; extracting features from the aggregated raw threat information to obtain feature vectors; inputting the feature vectors into a trained neural network model; if the IPs exhibit threatening behavior, determining the threat type of the IPs based on the trained neural network model, and producing corresponding threat intelligence based on the threat type. Compared to existing technologies that produce intelligence based on processed data analysis, this method directly utilizes machine learning technology to analyze raw threat information, ensuring the accuracy of threat intelligence production. Furthermore, the threat intelligence produced by this method can be directly applied to security devices, facilitating subsequent security monitoring.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Artificial intelligence-based security detection method, device and storage medium

The application discloses an artificial intelligence-based security detection method and device and a storage medium, and belongs to the technical field of security detection. The method comprises the following steps: acquiring security event data of a detection point, comparing and analyzing the security event data with a preset threat behavior mode through a threat correlation knowledge model, obtaining the correlation between the security event data, matching the entity path of the correlation in a security knowledge graph with a preset threat chain mode, determining a threat event chain according to the matching result, and triggering a security protection mechanism according to the threat analysis result corresponding to the threat event chain. According to the application, the correlation between different threat events is recognized, and the efficiency and accuracy of the threat response of the security detection system are improved.
Owner:ZHEJIANG COMM SERVICES

Network security analysis system and method based on security situation awareness system

InactiveCN121967013AEliminate technical barriersimprove data qualitySecuring communicationTimestampOriginal data
The invention discloses a network security analysis system and method based on a security situation awareness system, and relates to the technical field of network security situation awareness, and the system comprises a data collection module, a processing module, an event reconstruction module, a threat analysis module and a situation generation module which cooperate in sequence. The data acquisition module acquires original data containing encrypted traffic and unstructured alarm from a network boundary probe; the data processing module performs hierarchical decoding and normalization on the data to generate a standardized record with a unified timestamp; the event reconstruction module connects the records into a continuous event sequence according to a time sequence; the threat analysis module compares the event sequence with a threat behavior pattern library, and identifies and marks fragments conforming to an attack chain; and the situation generation module constructs a network security situation portrait accordingly. According to the scheme, effective analysis of encrypted and unstructured security data is realized, a complex and latent attack behavior chain can be identified based on the continuous event sequence, and the depth and accuracy of threat detection are improved.
Owner:INFORMATION & COMM CO OF STATE GRID SHAANXI ELECTRIC POWER CO LTD

A user identity threat detection method and system based on large language model

The present invention discloses a user identity threat detection method and system based on a large language model in the field of network security technology, including establishing a model based on an open source deep learning framework, obtaining historical data set input and training the model to obtain a large language model, and the large language model is used to distinguish the characteristic differences between normal behavior and threatening behavior of user identity. The present invention deeply processes the collected data set through the established large language model, obtains data related to user identity threats and user multi-source data from multiple aspects of the network security data platform and the enterprise internal system, and constructs user behavior semantic association map data through the converted high-dimensional semantic vectors. Through multi-dimensional data analysis, it can deeply reveal user identity threat data, realize accurate and efficient detection and prevention of user identity threats, effectively reduce the false alarm rate and missed alarm rate, reduce the ineffective work of security management personnel, and improve the reliability of threat detection.
Owner:JIANGSU TAIHU HUIYUN DATA SYST CO LTD

A virtual-real combined industrial control software security test platform

The application discloses a kind of industrial control software security test platform based on virtual and real combination, it is related to industrial control system safety testing technical field, including: test monitoring sub-platform, for centralized control simulation environment and test tool operation, to test environment, measured object and threat behavior are visualized output, and record, analyze test data to quantize evaluation security risk;Security test tool set, for monitoring the state parameters of industrial control system and detecting the abnormal behavior of industrial control system, and performing threat injection test;Security information base, for storing the defect information base of industrial control system, hardware and software vulnerability library, network protocol feature library and test case library;Simulation running environment, for building the complete running environment of industrial control system through simulation means.The application supports the interactive test of physical equipment and virtual MES, can simulate bandwidth limit, packet loss rate and other real industrial network environment, improve the credibility of test result.
Owner:INFORMATION CENT OF CHINA NORTH IND GRP

Information intelligent early warning system and method based on big data security analysis

The invention discloses an intelligent information early warning system and method based on big data security analysis, and relates to the technical field of network security. According to the method, the candidate feature fragments are extracted from the historical standard security data flow through the feature extraction network, the candidate feature fragments are mutually matched through the collaborative matching mechanism, then the security event fragments are generated, the security event fragments are marked as the atomic security features, and the atomic security features are clustered and fused to generate the composite security feature. The method comprises the following steps: traversing all historical standard security data streams through composite security features to extract feature data fragments, sorting the feature data fragments to generate a multi-dimensional threat feature matrix, establishing threat behavior association trees according to the multi-dimensional threat feature matrix, matching the threat behavior association trees and connecting the threat behavior association trees with a global threat feature forest to obtain a threat behavior association tree; and converting the standard security data generated in real time into a detection feature sub-matrix, inputting the detection feature sub-matrix into the forest for matching analysis, and outputting a security early warning report.
Owner:ZHONGZHI INTELLIGENT MANUFACTURING (SHANDONG) INTELLIGENT TECHNOLOGY CO LTD

Threat behavior spectrum representation method and apparatus

The application provides a threat behavior spectrum representation method and device, the method comprises the following steps: clustering network attack and vulnerability sample data set according to a clustering algorithm to obtain a plurality of unknown threat clusters, wherein the network attack and vulnerability sample data set comprises a plurality of network attack and vulnerability sample data with cross relationship and a plurality of network attack and vulnerability sample data without cross relationship; inputting each unknown threat cluster into a GNN model which is trained based on a plurality of historical unknown threat clusters in advance, so that the GNN model extracts the network element information of the overall feature space corresponding to each unknown threat cluster; and mapping the network element information of each overall feature space into a threat behavior spectrum according to a graph embedding spectrum representation algorithm. The application can improve the network malicious behavior recognition efficiency, simplify the model structure, improve the model practicability, and unify the management of network malicious behaviors to improve the comprehensiveness of network malicious behavior representation.
Owner:BEIJING UNIV OF POSTS & TELECOMM +1

An anti-attack method and system for improving the security of intelligent terminals

The present application provides an anti-attack method and system for improving the security of smart terminals. The method extracts the parallel call features of each task process in the smart terminal from the behavioral data stream of the parallel task process in the smart terminal, and then determines the threat behavior sequence of the parallel task process in the smart terminal through the communication relationship between each parallel call feature and the task process in the smart terminal; reversely traces and locates the dependency of each threat behavior in the threat behavior sequence according to the attack tracing module of the smart terminal, and obtains multiple attack dependency nodes of the threat behavior in the smart terminal, and then generates a threat map of the attack link through all the attack dependency nodes; uses the threat map to automatically generate a hot patch for the threat behavior in the smart terminal, and then repairs the vulnerability by differentially updating the hot patch without affecting the normal service of the smart terminal. Based on the above scheme, hot patch repair of attack behavior of the smart terminal can be achieved, thereby improving the continuity of the security service of the smart terminal.
Owner:SHENZHEN TOPWISE COMM CO LTD

Industrial control software security test platform based on virtuality and reality combination

The invention discloses an industrial control software security test platform based on virtuality and reality combination, which relates to the technical field of industrial control system security test, and comprises a test monitoring sub-platform used for centrally controlling the operation of a simulation environment and a test tool, visually outputting a test environment, a tested object and a threat behavior, and storing the test environment, the tested object and the threat behavior; recording and analyzing the test data to quantitatively evaluate the safety risk; the safety test tool set is used for monitoring state parameters of the industrial control system, detecting abnormal behaviors of the industrial control system and executing a threat injection test; the security information library is used for storing a defect information library, a software and hardware vulnerability library, a network protocol feature library and a test case library of the industrial control system; and the simulation operation environment is used for building a complete operation environment of the industrial control system through a simulation means. The method supports the interaction test of the physical equipment and the virtual MES, can simulate the real industrial network environment such as bandwidth limitation and packet loss rate, and improves the credibility of the test result.
Owner:INFORMATION CENT OF CHINA NORTH IND GRP

Method for detecting and analyzing time-series data based on cyber threat framework

This disclosure details a method for detecting and analyzing time-series data with a cyber threat framework. It involves determining target API events, mapping these to threat behaviors, creating threat scenarios, assessing matching degree and risk, predicting threat behaviors based on risk grades, and providing solutions.
Owner:ASTRON SECURITY INC

Threat behavior association analysis method for power network security situation awareness

PendingCN121864355AEnhance the ability of core functions to function properlySecuring communicationAttackCorrelation analysis
The invention is suitable for the technical field of power network security, and provides a threat behavior association analysis method for power network security situation awareness, and the method comprises the steps: obtaining IT side data and OT side data in a power network; after processing, generating a standardized security event sequence; matching the standardized security event sequence with a plurality of preset association analysis rules; the correlation analysis rule is used for defining causal, time sequence and logic relationships among different types of security events; generating at least one threat behavior event according to the matching result; according to the generated threat behavior event type and risk level, generating a corresponding power system alarm signal; and sending the generated power system alarm signal to an alarm device to execute early warning feedback. According to the method, an ongoing attack and a possible target can be identified, an abstract network security threat is converted into a specific risk value or grade, and the capability of maintaining normal operation of a core function after the power network is subjected to the network attack is enhanced.
Owner:GUANGXI POWER GRID CORP

A method and device for detecting illegal access of DRA equipment to network elements based on signaling fusion analysis technology

The present invention belongs to the field of mobile communication networks and provides a method and device for detecting illegal access to network elements by DRA equipment based on signaling fusion analysis technology. The method identifies a newly added link based on the DRA link configuration table and performs threat behavior detection on the signaling data on the link to determine whether it is illegal access. At the same time, the access frequency of the network element is calculated and the illegal access is determined based on the indirect access characteristics. Finally, a comprehensive judgment is made by integrating the two detection methods. The present invention can timely detect illegal access behavior by performing newly added link detection through the DRA link configuration table, and detects according to the indirect access characteristics of the illegally accessed network element, which can improve the reliability and accuracy of DRA illegal access detection.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University