Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

11 results about "Virus attack" patented technology

A method and system for encrypted scene detection based on double model adaptive switching

The application relates to the technical field of network security, in particular to an encryption scene detection method and system based on double-model adaptive switching, which comprises the following steps: loading an unsupervised detection model and an unsupervised data collection module; the unsupervised data collection module collects data for the unsupervised detection model to perform unsupervised preliminary screening and obtain a real-time anomaly score; an adaptive switching controller compares the real-time anomaly score with a switching threshold to determine whether the system is abnormal; if the system is normal, the unsupervised preliminary screening is continued; if the system is abnormal, supervised fine screening is performed; a supervised data collection module collects behavior data and inputs the behavior data into the supervised detection model to determine whether the attack is an encryption virus attack; if the attack is an encryption virus attack, corresponding strategies are executed; if the attack is not an encryption virus attack, the unsupervised preliminary screening is continued. The application performs coarse-grained threat preliminary screening in a normal state, and adaptively switches the model to perform fine screening when potential abnormalities are detected, thereby guaranteeing a high detection rate and reducing the influence on system performance.
Owner:KYLIN CORP

Firewall detection method and device for industrial network architecture, equipment, storage medium and product

The invention discloses a firewall detection method and device for an industrial network architecture, equipment, a storage medium and a product. The industrial network architecture comprises a plurality of conventional nodes, virtual nodes are arranged between different conventional nodes, each virtual node is provided with a first firewall, each conventional node is provided with a second firewall, and the first firewall is provided with a first firewall. The firewall detection method of the industrial network architecture comprises the following steps: a first firewall performs preliminary detection on data information passing through a virtual node to obtain a preliminary detection result; under the condition that the preliminary detection result indicates that the data information is abnormal, the first firewall performs abnormal marking on the data information according to the abnormal type of the preliminary detection result to obtain data information with an abnormal marker; and for the data information passing through the conventional node, the second firewall constructs a virtual detection environment of the data information according to the exception type of the exception marker, and performs simulation operation detection on the data information to obtain a first virus attack mode of the data information.
Owner:CHINA MOBILE GRP GUANGDONG CO LTD +2

Ransomware invasion behavior trapping method and device based on multi-agent proxy

The invention relates to a ransomware invasion behavior trapping method and device based on multi-agent agency, and the method comprises the steps: constructing a multi-agent-based interactive honeypot which is used for carrying out the dynamic interaction with a ransomware attacker, inducing the ransomware attacker to carry out an attack behavior, and collecting a system log of an attack sequence in a controlled environment; converting the collected system log of the attack sequence into a structured hypergraph expression form, and generating a ransomware attack traceability hypergraph; and inputting a plurality of ransomware attack traceability hypergraphs into a federated hypergraph learning model, carrying out federated learning, realizing distributed joint modeling under the condition of not sharing original data, and finally aggregating to obtain a trained federated hypergraph learning model so as to carry out ransomware invasion alarm according to an actually measured system log. Compared with the prior art, the method solves the problems that an existing ransomware virus passive detection method is low in precision, low in efficiency and the like, and can provide powerful support for malicious code prevention in the industries of energy, finance and the like.
Owner:STATE GRID INFORMATION & TELECOMM BRANCH +1

Recombinant protein combination of chicken infectious anemia virus vp1 and vp2 proteins and application in preparation of subunit vaccine

The application belongs to the field of veterinary biotechnology and genetically engineered vaccine, and discloses a recombinant protein combination of chicken infectious anemia virus VP1 and VP2 proteins and application thereof in preparation of a subunit vaccine. An engineering cell strain capable of independently and efficiently secreting and expressing VP1 and VP2 proteins is screened, and the recombinant proteins in the supernatant of the suspension culture are purified and assembled into a subunit vaccine in vitro according to a specific ratio. The vaccine can induce chickens to produce high-titer neutralizing antibodies, and the protection rate against virus attack reaches 100%, which is significantly better than existing inactivated vaccines, and the vaccine is safe, has no risk of virus dissemination, and has a differential diagnosis DIVA function.
Owner:HUAZHONG AGRI UNIV

Network virus propagation defense method, device and equipment based on reinforcement learning

The application provides a network virus propagation defense method, device and equipment based on reinforcement learning. The method comprises the following steps: abstracting a target network into a two-dimensional space Graph form as training data for storage; constructing a reinforcement learning training model, and defining a training environment of the reinforcement learning training model; the training environment of the reinforcement learning model comprises a training environment rule, a server state, an invader attack rule and a training end condition; training the reinforcement learning training model to obtain a reinforcement learning defense model; and deploying the reinforcement learning defense model to a management server, inputting a server state in the target network into the reinforcement learning defense model, and performing offline on a server in an output result. In this way, the reaction speed of both attack and defense sides can be considered without considering the defense or attack strength on the premise that the virus attack can be detected, the server group is protected from a macro perspective, and the whole can still run when a small part of computers in a complex network is invaded.
Owner:JINJING YUNHUA TECH +1

Virus defense method, system and device and computer readable storage medium

The invention discloses a virus defense method, system and device and a computer readable storage medium, relates to the technical field of information security and storage protection, and is applied to defense software to detect whether a target host is attacked by a virus or not. In response to the fact that the target host is attacked by the virus, generating a hardware-level blocking signal; the hardware-level blocking signal is sent to a preset hardware device, so that the hardware device modifies firmware area parameters of the target host hard disk after responding to the hardware-level blocking signal, and then the target host hard disk refuses write-in operation on the physical level; wherein the communication link between the defense software and the hardware device is a link independent of the operating system of the target host, and the communication link between the hardware device and the hard disk of the target host is a link independent of the operating system of the target host. According to the method, independent defense which is not influenced by the authority of the operating system can be realized, the defense mechanism can still run normally even if the system is crashed or controlled, the defense capability of the hard disk to viruses is improved, and the security of the hard disk is ensured.
Owner:STATE GRID CHONGQING ELECTRIC POWER CO ELECTRIC POWER RES INST

Kernel-based virus searching and killing method and device, equipment and storage medium

The invention discloses a kernel-based virus searching and killing method, device and equipment and a storage medium, and relates to the technical field of information security, the kernel-based virus searching and killing method comprises the following steps: determining a target file operation on a target file, and determining a first target processing function corresponding to the target file operation; the first target processing function is a function which is configured through a file filtering drive of a kernel and corresponds to the target file operation; identifying whether the target file operation is a virus attack or not through a first target processing function, and if the identification fails, identifying whether the target file operation is the virus attack or not through a target antivirus engine; and if the target file operation is identified as a virus attack, intercepting the target file operation, generating virus attack risk prompt information, obtaining confirmation information generated by a user based on the virus attack risk prompt information, and if the confirmation information represents that interception is agreed, stopping execution of the target file operation, and generating a corresponding processing log. According to the invention, efficient and accurate virus searching and killing of the file can be realized.
Owner:CHENGDU WEISHITONG INFORMATION SECURITY TECH CO LTD

Vaccine composition for resisting Newcastle disease, infectious bronchitis and avian influenza

PendingCN121102457AViral antigen ingredientsAntiviralsAluminum StearateLevamisole
The invention relates to the field of preparation of poultry vaccines, in particular to a vaccine composition for resisting Newcastle disease, infectious bronchitis and avian influenza. 5 to 15 parts of vitamin E; 2 to 10 parts of levamisole; 1-10 parts of a divalent inorganic salt; 1-5 parts of a complexing agent; 20-40 parts of a first bacterial liquid containing inactivated avian influenza virus; 20-30 parts of a second bacterial liquid containing inactivated infectious bronchitis virus; 10-30 parts of a third bacterial liquid containing inactivated Newcastle disease virus; 1 to 3 parts of aluminum stearate; and 10 to 15 parts of an oil phase. The vaccine prepared by the invention does not generate any adverse reaction to chickens, is high in experimental safety, and can induce high-level neutralizing antibodies in immunized chickens, which indicates that the immunized chickens can effectively resist virus attacks of Newcastle disease virus, avian influenza and infectious bronchitis virus.
Owner:SHANGQIU MEILAN BIOENGINEERING CO LTD

A data processing method and related apparatus

Embodiments of the present application disclose a data processing method and related apparatus. For a network environment comprising a plurality of terminal devices, the plurality of terminal devices no longer load a rule base for detecting network threats, thereby realizing cooperative work between the terminal devices and an anomaly detection device for anomaly detection. The plurality of terminal devices extract to-be-detected data based on computing capability, thereby reducing the amount of data reported to the anomaly detection device, alleviating the receiving and processing pressure of the anomaly detection device, shortening the time delay of obtaining an anomaly detection result, and enabling the first terminal device to obtain the anomaly detection result in real time, thereby avoiding a great impact of an abnormal situation on the first terminal device. Moreover, the anomaly detection device detects anomalies of the plurality of terminal devices in the network environment, thereby ensuring that the terminal devices are not attacked by viruses, without the need for the terminal devices to maintain a corresponding rule base locally, thereby freeing the processing resources of the terminal devices and improving the processing capability of the network environment.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Security guarantee system based on Internet

The invention discloses a security guarantee method based on the Internet. The method comprises the following steps: step 1, acquiring service resource security management data of a cloud platform by using each plug-in in a plug-in system; 2, establishing a service resource unified database of the cloud platform, storing the collected service resource data in a hierarchical structured manner, and carrying out resource integration and management; 3, the cloud platform establishes a network security situation awareness terminal, analyzes platform vulnerabilities, virus attacks, security threats and intrusion risks in a service resource data environment in real time, and performs security assurance through an access control strategy and a data information security management strategy of a security terminal by using a server; the threatening situation of each terminal of the cloud platform is comprehensively analyzed, the security policy suitable for the current threat is decided, the security guarantee of the terminal and the user is carried out, and the method has the characteristics of improving the information security guarantee capability and accurately selecting the security guarantee policy.
Owner:卢瑞翔

Encryption scene detection method and system based on double-model adaptive switching

The invention relates to the technical field of network security, in particular to an encryption scene detection method and system based on double-model adaptive switchover, and the method comprises the steps: loading an unsupervised detection model and an unsupervised data collection module; the unsupervised data acquisition module acquires data and sends the data to the unsupervised detection model for unsupervised preliminary screening, and real-time abnormal scores are obtained; the adaptive switching controller compares the real-time abnormal score with a switching threshold value to judge whether the real-time abnormal score is abnormal or not; if normal, continuing unsupervised primary screening; if yes, supervised fine breaking is carried out; the supervised data acquisition module acquires behavior data and inputs the behavior data into the supervised detection model to judge whether the behavior data is attacked by encrypted viruses; if the attack is the attack of the encrypted virus, executing a corresponding strategy; and if the attack is not the attack of the encrypted virus, continuing unsupervised preliminary screening. According to the method, coarse-grained threat preliminary screening is carried out in a normal state, and fine screening is carried out only by adaptively switching the model when potential abnormity is detected, so that the influence on system performance is reduced while the high detection rate is ensured.
Owner:KYLIN CORP