Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

563 results about "Vulnerability" patented technology

Vulnerability refers to the inability (of a system or a unit) to withstand the effects of a hostile environment. A window of vulnerability (WOV) is a time frame within which defensive measures are diminished, compromised or lacking.

CAPEC vulnerability management system based on large language model

The invention discloses a CAPEC vulnerability management system based on a large language model, and belongs to the technical field of network security. The system comprises three modules: a vulnerability-CAPEC dynamic mapping module jointly encodes vulnerability description and code context through a bimodal large language model, accurately associates vulnerability logic with a CAPEC attack mode in combination with comparative learning and knowledge graph construction, and breaks through semantic limitation of traditional rule matching; the adversarial repair code generation module is used for generating high-robustness repair codes through adversarial training and syntax tree verification by fusing CAPEC relieving suggestions and code features on the basis of the association result, so that the secondary vulnerability risk is remarkably reduced; and the full-process automatic verification and DevOps integration module performs multi-dimensional security verification such as symbolic execution, fuzzy testing and the like on the generated repair code, and deeply integrates a development tool chain to realize real-time pushing and closed-loop management of a repair scheme.
Owner:BEIJING SHIXING TECH CO LTD

Failure chain quantitative analysis and risk assessment method and system based on multi-level security model

The invention discloses a failure chain quantitative analysis and risk assessment method and system based on a multi-level security model, and aims to solve the defects that accident cause analysis of a complex social technology system is inaccurate, and a risk assessment result is lack of effective verification. According to the method, a multi-level causal model is systematically constructed, a multi-dimensional failure chain (MDFC) is extracted, multi-dimensional risk quantification is performed on the MDFC, a directed weighted failure propagation network is constructed based on the multi-dimensional risk quantification, and structural features of the directed weighted failure propagation network are analyzed to identify key risk factors. The core innovation of the method is that reverse accident reason tracing and forward risk propagation path analysis based on the weighted network are fused, mutual verification and iterative optimization are realized by comparing analysis results of the two paths, so that the understanding of an accident evolution mechanism is deepened, and the reliability of evaluation is improved. The system vulnerability can be revealed more comprehensively, powerful support is provided for formulating accurate risk control measures, and the overall safety level of a complex system is improved.
Owner:CHINA UNIV OF PETROLEUM (EAST CHINA)

Detecting package execution for threat assessments

Detecting package execution for threat assessments, including: receiving, from an agent on a host of a cloud deployment, data describing one or more active packages installed on the host, wherein each of the one or more active packages are identified by the agent from a plurality of packages in response to detecting a corresponding file open event; and generating a threat assessment for the host describing which of the one or more active packages have any known vulnerabilities.
Owner:FORTINET INC

Intelligent data security exposure surface risk assessment method, system, equipment and medium

The invention provides an intelligent data security exposed surface risk assessment method, system and device and a medium, and relates to the technical field of information security, and the method comprises the steps: constructing an exposed surface asset map through an asset fingerprint recognition engine, and calculating an asset exposure index; constructing a vulnerability knowledge base, and identifying potential vulnerabilities; based on the standard vulnerability score, the vulnerability utilization tool activeness and the attack event frequency in the set time period, calculating the triggering probability of the potential vulnerability as a dynamic vulnerability score; malicious IP access frequency and leakage record matching degree are obtained through firewall logs and dark web monitoring data, and threat intelligence factors are obtained through calculation; calculating an exposed surface risk value in combination with the asset exposure index, the dynamic vulnerability score and the threat intelligence factor; and based on a time decay model, according to the exposed surface risk value and the business influence factor, calculating a residual risk value, and obtaining an exposed surface risk assessment result. The accuracy of risk assessment is further improved through multi-dimensional data fusion.
Owner:YUANBAO TECH

Black box test zero-day vulnerability analysis method and system based on multi-dimensional data

The invention discloses a black-box test zero-day vulnerability analysis method and system based on multi-dimensional data, and aims to solve the problems that a traditional black-box test means is weak in unknown vulnerability recognition capability, high in false alarm rate, lack of path modeling and verification mechanisms and the like. The method comprises the following steps: constructing a cross-time window behavior graph by acquiring multi-dimensional heterogeneous information such as network input, system call, log information and abnormal signals; on the basis, potential abnormal paths are identified through structure entropy change and graph structure mutation analysis, path vector representation is constructed by combining graph representation learning and a path embedding method, and path-level risk modeling and mode clustering analysis are achieved; furthermore, vulnerability confirmation is carried out on the suspicious path through multiple verification mechanisms such as attack replay, fuzzy testing and sensitive function combination identification. The system has a multi-module cooperation capability, can realize automatic mining, verification and visual tracing of zero-day vulnerabilities in a source-source-free environment, and has good universality and expansibility.
Owner:NANJING YUEMING HUICHENG NETWORK SECURITY TECH CO LTD

Method and system for enabling trustworthy artificial intelligence systems through transparent model analysis

PendingUS20250265545A1InstrumentsEngineeringSimilitude
Method and system for analyzing at least one computing system for supply chain vulnerabilities of at least one machine learning model include configuring machine learning model and optionally additional data; decomposing operations of the machine learning model's computational graph into smaller decomposed components; associating properties of each decomposed component with properties of the original operations and associating additional data; detecting the semantic similarity of decomposed component and previously encountered decomposed components; converting decomposed components into a standardized representation; calculating signature of decomposed components; evaluating whether portions of the machine learning model are similar to previously calculated signature; testing for supply chain and model vulnerabilities that exist based on previous signatures; identifying vulnerabilities that persist and correlating defenses; storing the generated signatures, identified vulnerabilities, and identified defenses; and generating report detailing the machine learning model's supply chain, vulnerabilities, and defenses.
Owner:OBJECTSECURITY LLC

Machine learning techniques for analyzing operational technology networks

Machine learning techniques are provided for analyzing operational technology networks. An attack simulation model is trained to simulate attacks on a network replica by a plurality of threats. The attack simulation model outputs simulated attack data comprising a set of simulated attack paths corresponding to one or more threats of the plurality of threats. The network replica comprises a structured representation of a plurality of assets belonging to an OT network environment, communication pathways between the plurality of assets, security controls implemented in the OT network environment, and vulnerabilities. A threat analysis system is generated. The threat analysis system is configured to apply the attack simulation model to an input network replica and provide one or more risk reduction recommendations based on output simulated attack data from the attack simulation model. The threat analysis system is deployed to generate risk reduction recommendations for one or more OT network environments.
Owner:FRENOS INC

Systems and methods for resolving code vulnerabilities through collaborative agents

Systems and methods for resolving code vulnerabilities through collaborative agents which may include accessing a code base of an identified vulnerability; configuring a plurality of autonomous agents, each comprising a predefined agent role associated with application security remediation process; executing a directed workflow of the plurality of agents, wherein the workflow is a conditional sequence of agent-driven processing steps for generating a proposed resolution to the identified vulnerability; and outputting a candidate resolution for the vulnerability based on results produced by the workflow.
Owner:HARNESS INC

Automatic vulnerability processing method and system

The invention provides an automatic vulnerability processing method and system.The method comprises the steps that multi-source heterogeneous data and temperature field distribution of a target system are obtained, vulnerability data and historical repair records are subjected to semantic association, and vulnerability propagation path features are generated in combination with a dynamic dependency chain; and identifying a hardware load abnormal region by matching the temperature field distribution with a thermodynamic mode of known vulnerability attacks. And based on a dynamic graph attention mechanism, collaboratively analyzing vulnerability propagation path characteristics and hardware abnormal data, and generating a patch deployment strategy which comprehensively considers the repair priority and resource allocation. In the execution process, the topological sequence and the data throughput of patch distribution paths are dynamically adjusted, the resource occupation proportion is optimized, and it is ensured that the cross-system service interruption duration is controlled within a safety window. According to the method and the device, the vulnerability repair accuracy and the system stability are improved.
Owner:HUAQING WEIYANG (BEIJING) TECHNOLOGY CO LTD

Custom ai co-pilot for software security pen-testing

Systems and method for detecting vulnerabilities in code are provided herein. A pre-trained artificial intelligence (AI) model is engaged, and a plurality of prompts and the source code are provided to the AI model. A plurality of detected vulnerabilities and a plurality of code locations in the source code are identified using the AI model. Each of the plurality of code locations corresponds to at least one of the plurality of detected vulnerabilities. One or more false positive vulnerabilities in the plurality of detected vulnerabilities are identified. A plurality of augmented prompts is generated, based on the one or more false positive vulnerabilities. The plurality of augmented prompts is outputted to a database of prompts for use in future code analyses, without necessarily having to retrain the AI model.
Owner:UNIV OF SOUTH FLORIDA

Software supply chain security analysis method

The invention relates to the field of software security, and particularly discloses a software supply chain security analysis method which comprises the following steps: S1, collecting data of components of a software supply chain, and calculating a historical security risk weight for each component in the supply chain; s2, collecting behavior data of the software during operation, and performing association analysis in combination with the supply chain data; s3, preprocessing the collected behavior data and supply chain data, and extracting key features; according to the software supply chain security analysis method, through dynamic behavior analysis, runtime threats, such as zero-day vulnerabilities and hidden backdoor threats, which cannot be detected by static analysis can be found, the coverage rate of threat detection is remarkably improved, meanwhile, historical security risk weights are introduced, historical security problems of supply chain components are quantified, and the security of the software supply chain is improved. And intelligent risk assessment and threat traceability are realized by combining a knowledge graph and a graph neural network technology.
Owner:YANGZHOU SHUAN TECH CO LTD

Power network equipment vulnerability repairing method and system based on dynamic behavior analysis

The invention provides a power network equipment vulnerability repairing method and system based on dynamic behavior analysis, and the method comprises the steps: obtaining an operation data set of power network equipment, carrying out the dynamic behavior analysis processing of the operation data set, and obtaining a dynamic behavior feature set of data of a plurality of operation cycles; based on a preset dynamic strategy matching rule, performing vulnerability feature extraction processing on the dynamic behavior feature set, and generating a vulnerability repair strategy set corresponding to the abnormal behavior pattern; according to the execution priority and the execution condition parameter in the vulnerability repair strategy set, triggering vulnerability repair operation of the power network equipment, and obtaining equipment operation verification data after repair; and generating a repair effect evaluation result based on a difference parameter between the equipment operation verification data and a preset safety operation standard, and adjusting the dynamic strategy matching rule according to the difference parameter. According to the invention, the vulnerability repair system can maintain a stable security protection level in a complex and changeable power network environment.
Owner:SHANDONG SIJI TECH CO LTD +2

Multi-dimensional assessment method for credential environment migration

The invention discloses a multi-dimensional evaluation method for credential environment migration, and particularly relates to the field of evaluation. According to the method, an evaluation index system covering infrastructure, an application system, data resources and security compliance is constructed, and comprehensive scanning is realized through instruction set detection, binary analysis and equal security compliance inspection; dynamically calculating the weight by adopting an AHP-entropy weight hybrid model, and triggering weight rebalance based on the volatility; through combination of static scanning and a dynamic probe, the compatibility, performance and safety differences are quantitatively analyzed; and finally, generating a visual risk assessment report, integrating data of each stage to calculate a compatibility score, a performance loss rate and a security level, providing instruction level difference comparison, a performance flame graph and a vulnerability attack path interaction view, and outputting a migration suggestion comprising a priority reconstruction list, an NEON instruction optimization scheme and a staged reinforcement plan.
Owner:ZHONGCHUANG GUOKE (SHANXI) TECH CO LTD

Vulnerability positioning method and system based on cross-modal features

The invention provides a vulnerability positioning method and system based on cross-modal features. The method comprises the following steps: firstly, obtaining cross-modal information of a vulnerability to be positioned; the cross-modal information comprises a vulnerability description text and candidate vulnerability function codes; inputting the cross-modal information into a pre-trained vulnerability positioning model, and obtaining a vulnerability positioning result output by the vulnerability positioning model; wherein the pre-trained vulnerability positioning model is used for determining cross-modal alignment features according to the vulnerability description text and the candidate vulnerability function codes, performing correlation calculation and sorting according to the cross-modal alignment features, and taking a correlation sorting result as a vulnerability positioning result; the cross-modal alignment feature is used for aligning the feature of the vulnerability description text and the feature of the candidate vulnerability function code; the pre-trained vulnerability positioning model is obtained by training based on a vulnerability positioning training set, and the vulnerability positioning training set comprises a vulnerability description text sample and a vulnerability function code sample. According to the invention, automatic vulnerability positioning can be realized, and the accuracy and efficiency of vulnerability positioning are improved.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

RAG-based multi-dimensional network penetration test vulnerability mining method

The invention provides an efficient multi-dimensional network penetration testing method based on RAG, which comprises the following steps: firstly, identifying sub-domain names possibly existing in a target website, and sequentially expanding attack surfaces of penetration testing to obtain vulnerability information pairs; secondly, a design model generated based on retrieval enhancement is adopted, vulnerability information pairs are extracted from the queue to be utilized, knowledge items related to local knowledge base retrieval and network intelligent search retrieval are utilized, and finally, a large model generates vulnerability utilization information according to the knowledge items; acquiring target machine permission for the previously acquired vulnerability information pair construction command injector, and further scanning other hosts of the intranet accessed by the target skipping machine; finally, combining vulnerability information obtained by penetration testing, utilizing a large model to sort vulnerabilities existing in different assets, and outputting penetration testing reports for different assets. According to the method and the system, comprehensive penetration testing of cross-network and cross-system is realized, security experts are helped to quickly identify, verify and repair vulnerabilities in a complex and changeable network environment, and high-efficiency and low-cost network security maintenance is realized.
Owner:SOUTHEAST UNIV

Vulnerability remediation recommendation mechanism

A method is disclosed. The method comprises detecting one or more vulnerabilities in a software package, generating a version upgrade recommendation for each of the detected vulnerabilities, generating a version graph including one or more of the version upgrade recommendations and displaying the version graph at a user interface.
Owner:FORTINET INC

CAPEC vulnerability association identification system based on ATTCK framework

The invention discloses a method based on ATTamp; the invention discloses a CAPEC vulnerability association identification system of a CK framework, and relates to the technical field of network security. Comprising a data integration module, an attack path analysis engine module, a vulnerability association analysis engine module, a dynamic update and intelligence integration module and a visual display module which are connected in sequence. In combination with a CAPEC framework, deeper threat intelligence and defense suggestions are provided from a behavior mode and an attack path of an attacker. Meanwhile, latest vulnerability information is obtained in real time through a dynamic updating and intelligence integration module, the vulnerability management efficiency and the threat detection accuracy are improved by automatically analyzing the incidence relation between the attack path and the vulnerability, the incidence relation between the attack path and the vulnerability is displayed through a graphical interface, a user is helped to visually understand the full view of the threat, and the threatening effect is improved. And a vulnerability influence range and restoration suggestion information are provided.
Owner:BEIJING SHIXING TECH CO LTD

System and method for evaluating risk of a vulnerability

Techniques, methods and / or apparatuses are disclosed that enable prioritization of vulnerabilities in different applications or the same application on different assets. A risk assessment component collects information related to the use environment, activity, functions, and configuration of a device and each of its applications. This collected information is analyzed to prioritize vulnerabilities that may be common across applications but have different levels of risk of exploitation based on their environment, activity, functions, or configuration. The risk of exploitation of a vulnerability is calculated for each asset, for each application, and each application on an asset.
Owner:TENABLE INC

Source code bug repairing method, electronic equipment and storage medium

The invention relates to the technical field of vulnerability repair, in particular to a source code vulnerability repair method, electronic equipment and a storage medium, and the method comprises the following steps: obtaining an abstract syntax tree and a control flow graph according to a source code containing a vulnerability, and generating a vulnerability context feature vector by using a graph neural network model in combination with vulnerability position information, determining a historical vulnerability repair case corresponding to the vulnerability context feature vector from a vulnerability-repair knowledge base, inputting the vulnerability context feature vector and the corresponding historical vulnerability repair case into a code generation model, outputting a candidate repair code set corresponding to the source code, evaluating each candidate repair code, and determining the vulnerability-repair knowledge base according to the candidate repair code set. Screening out an optimal repair code to automatically repair the source code vulnerability; according to the method, deep semantic analysis is performed on the vulnerability context, and intelligent reasoning is performed, so that the repair code with correct grammar and adaptive context can be generated, and the automation level and accuracy of vulnerability repair are remarkably improved.
Owner:QINGDAO WANDAO (BEIJING) INFORMATION TECH CO LTD

Vulnerability mining system and device based on source code similarity

The invention relates to the technical field of software security, in particular to a vulnerability mining system and device based on source code similarity. The vulnerability mining system comprises a vulnerability feature library which comprises vulnerability code snippets and feature information associated with the vulnerability code snippets; the coarse granularity positioning module is used for matching the vulnerability code snippets in the vulnerability feature library with the to-be-analyzed source code aiming at the to-be-analyzed source code, determining suspicious code snippets and forming similar code pairs; the feature representation module is used for acquiring feature information of the suspicious code snippets; the fine granularity positioning module is used for obtaining the semantic similarity, the structural similarity and the subgraph matching degree of the similar code pair according to the feature information associated with the two code snippets in the similar code pair, and determining the comprehensive similarity of the similar code pair; and the judgment module is used for determining whether the suspicious code snippets in the similar code pairs have vulnerabilities or not according to the comprehensive similarity. The method has the beneficial effects that the processing efficiency can be improved while the detection precision can be ensured.
Owner:HANGZHOU INNOVATION RES INST OF BEIJING UNIV OF AERONAUTICS & ASTRONAUTICS +1

Vulnerability closed-loop processing method and system based on intelligent collaboration

The invention discloses a vulnerability closed-loop disposal method and system based on intelligent collaboration, and belongs to the technical field of information security management. Vulnerability data and disposal information in a plurality of independent security systems are collected, and a multi-dimensional vulnerability semantic model is constructed; constructing a state perception graph based on a semantic model, extracting candidate state paths, and constructing a time sequence closed-loop prediction model in combination with a shortest closed-loop path and a historical track; according to a vulnerability influence range, a service dependency chain and a prediction path key node, adaptively dividing responsibility affiliation, generating a dynamic disposal responsibility graph and realizing automatic assignment; combining the node response capability and the task saturation, dynamically calculating the priority and scheduling the processing task; monitoring an actual disposal behavior, correcting an edge weight of the state diagram in real time and updating the model; according to the method, the whole-process intelligence, collaboration and dynamic evolution of vulnerability management are realized, and the processing efficiency and the prediction precision are improved.
Owner:山东九州信泰信息科技股份有限公司

Shipborne intelligent network security protection architecture and method

The invention provides a shipborne intelligent network security protection architecture and method, and relates to the technical field of network security, and the architecture comprises a security domain division module which is used for dividing a shipborne network into three physically isolated security domains, including a key task domain, an operation management domain and a crew life domain; the longitudinal protection strategy module is used for generating a longitudinal strategy comprising a protection instruction, a communication control instruction and a risk quantification instruction based on the security domain structure; and the risk calculation module is used for detecting intra-domain equipment access behaviors by trapping addresses in the key task domain, collecting intra-domain network traffic and service unit logs, and outputting a service asset quantized value, a vulnerability severity quantized value and a threat behavior deviation degree according to a risk quantization instruction. According to the invention, accurate identification, graded response and efficient disposal of shipborne network threats are realized, and the safety of a ship key system is guaranteed.
Owner:SHANGHAI JINGZHI INTELLIGENT TECH CO LTD

Power metering system network security situation analysis method and system based on big data

The invention provides an electric power metering system network security situation analysis method and system based on big data, and relates to the technical field of electric power system information security. According to the method, network traffic, system logs, security alarms, asset information, vulnerability records and external threat intelligence are collected, a security data lake is constructed, and security situation factors are extracted; outputting an anomaly detection result and a threat classification result by using the unsupervised anomaly detection model and the supervised threat classification model; calculating an asset security risk value and an overall security risk value by combining the vulnerability severity and the asset importance, and generating an overall security index, an attack threat level and a vulnerability level; and a time sequence prediction model is further constructed based on the network security situation indexes, and future situation prediction and security early warning are realized. According to the invention, comprehensive perception, accurate analysis and active defense of the network security situation can be realized.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

Electric power system vulnerability assessment method and system considering extreme weather influence

The invention relates to the technical field of power system assessment, and discloses a power system vulnerability assessment method and system considering extreme weather influence, and the method comprises the steps: building a line fault probability model of a power system in extreme weather to determine the line time-varying fault probability under dynamic weather influence; generating a typical scene through a time sequence relativity matching generative adversarial network model with gradient penalty and Monte Carlo simulation; taking the generated typical scene as input, simulating cascading failure evolution through an alternating current cascading failure model, and outputting a cascading failure evolution path; and based on a fault evolution result, through a spectrogram theory and a Bayesian network, in combination with severity analysis, structural vulnerability evaluation and causal-probability pre-judgment, multi-level vulnerability quantification of the power system is realized, and the problems that single-level evaluation is insufficient and causal association is ignored in the prior art are solved. And the risk assessment precision and the disaster prevention capability of the power system in extreme weather are improved.
Owner:STATE GRID ECONOMIC TECH RES INST CO LTD +5

AI-based trojans for evading machine learning detection

Various embodiments provide a robust backdoor attack on machine learning (ML)-based detection systems that can be applied to demonstrate and identify vulnerabilities thereof. In various embodiments, an artificial intelligence (AI)-based Trojan attack is generated and implanted inside a ML model trained for classification and / or detection tasks, and the AI-based Trojan attack can be triggered by specific inputs to manipulate the expected outputs of the ML model. Analysis of the behavior of an ML model having the AI-based Trojan implanted (and / or triggered) then enables identification of vulnerabilities of the ML model and further enables the design of ML models with improved security. Various embodiments of the present disclosure provide a fast and cost-effective solution in achieving 100% attack success rate that significantly outperforms adversarial attacks on ML models, thereby improving applicability and depth in testing ML-based detection systems.
Owner:UNIV OF FLORIDA RESEARCH FOUNDATION INC

Firmware homologous vulnerability mining method and system based on multi-dimensional feature portrait

The invention provides a firmware homologous vulnerability mining method and system based on multi-dimensional feature portray.The firmware homologous vulnerability mining method and system based on the multi-dimensional feature portray.The firmware homologous vulnerability mining method includes the steps that S1, a firmware set to be detected and a firmware set with known vulnerabilities are obtained, and firmware samples are formatted and preprocessed; s2, performing multi-dimensional feature portrait extraction on the preprocessed to-be-detected firmware set and the known vulnerability firmware set to form a standardized five-dimensional feature portrait; s3, based on the five-dimensional feature portrait, performing multi-semantic firmware similarity calculation on the known vulnerability firmware and the to-be-detected firmware by adopting multiple algorithms to obtain a global similarity score; and S4, based on the global similarity score, analyzing and screening out a to-be-detected high-risk firmware sample, automatically generating a vulnerability verification task, performing basic environment configuration, task distribution and multi-node parallel verification, and outputting a vulnerability verification result. According to the method, the full-process closed loop of automatic processing of firmware, deep feature mining, similarity quantitative analysis and vulnerability verification is realized.
Owner:COMMUNICATION UNIVERSITY OF CHINA

Automatic cross-project vulnerability verification method and device based on large language model

The invention provides an automatic cross-project vulnerability verification method and device based on a large language model, relates to the technical field of vulnerability verification, and aims to solve the problem that whether an upstream vulnerability can still be triggered or not is difficult to efficiently confirm in the prior art in a scene that significant differences exist between parameter semantics and input formats of a source project and a target project. According to the method, a multi-agent parallel target sensing parameter migration framework is constructed, and a legal command line parameter combination related to a vulnerability function is automatically generated from a target software manual in combination with an RAG retrieval enhancement technology; a ReAct intelligent agent is further introduced, a source PoC file is embedded into an acceptable input shell of target software in a cross-format mode under the condition that manual intervention is not needed, and an initial cross-format seed is formed. And iteratively optimizing the parameter-seed pair by taking the function-level trajectory similarity as a feedback index, and driving the parameter sensitive grey box fuzzy test to quickly converge to accurate input capable of triggering vulnerabilities.
Owner:XIAMEN UNIV OF TECH

Medical network collaborative penetration test system and method based on artificial intelligence

The invention discloses a medical network collaborative penetration test system and method based on artificial intelligence, and belongs to the technical field of medical information security, and the method comprises the steps: integrating a hospital intranet, medical equipment, cloud data center data and historical network delay data to construct a medical network data center; analyzing association between network vulnerabilities and delay data through a graph neural network, constructing an attack path analysis model containing delay weights, and quantifying risk scores to generate a test target priority list; defining a protocol vulnerability and a delay threshold, designing a test scene and generating an attack vector, matching an attack tool to perform a simulation test, calculating a vulnerability triggering success rate and evaluating a risk; generating a penetration test case according to the test target priority list and the risk level, executing multiple rounds of attack tests and generating a report; and monitoring the change of the vulnerability triggering success rate by dynamically adjusting the delay parameter, setting an early warning threshold value, and monitoring and sending a risk early warning notification in real time.
Owner:AFFILIATED HUSN HOSPITAL OF FUDAN UNIV

Auxiliary decision-making method and system for safety operation center

ActiveCN120415879ASecuring communicationSecurity operations centerAttack
The embodiment of the invention provides an auxiliary decision-making method and system of a safety operation center. The method comprises the following steps: acquiring multi-source heterogeneous data of a target network in a preset historical time period; determining a potential attack chain based on the multi-source heterogeneous data; determining vulnerability data based on the multi-source heterogeneous data and the potential attack chain; based on the vulnerability data, at least one repair reference standard is generated, and the repair reference standard comprises a repair method and repair cost; and generating a repair decision based on the vulnerability data and at least one repair reference criterion, and performing repair based on the repair decision.
Owner:GUANGXI TAYI INFORMATION TECH CO LTD

Security patch classification method and system based on pseudo label learning

The invention belongs to the field of vulnerability type classification, and particularly discloses a security patch classification method and system based on pseudo label learning, and the method comprises the steps: obtaining a to-be-classified security patch; performing feature extraction on the security patch to obtain key semantic features; inputting the key semantic features into a trained security patch model to obtain a classification result of the security patches; wherein the security patch model is obtained by performing key semantic information extraction on a security related patch data set and a label-free patch data set and performing pseudo-label learning according to the key semantic information. According to the invention, the classification accuracy and efficiency of the security patches can be improved.
Owner:HUAZHONG UNIV OF SCI & TECH +1