Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

49 results about "Vulnerability discovery" patented technology

Knowledge extraction and envelope coverage-oriented software vulnerability test method and related equipment

The invention discloses a knowledge extraction and envelope coverage-oriented software vulnerability test method and related equipment, and the method comprises the steps: obtaining vulnerability key information of target software, and obtaining sensitive function features through defect dependence analysis and construction based on the vulnerability key information; performing semantic analysis on the analysis report and the code abstract associated with the sensitive function characteristics, screening to obtain a target sensitive function, performing path envelope reverse tracking on the target sensitive function, and constructing to obtain a target path envelope; and obtaining coverage information enveloped by the target path, and carrying out fuzzy testing on the basis of the coverage information in combination with the iteratively optimized variation sample. According to the method, through intelligent closed loop of analysis-positioning-testing-feedback-optimization, static analysis provides accurate guidance for dynamic testing, and the static analysis strategy is inversely optimized by the result of the dynamic testing, so that the maximum improvement of the testing efficiency and the vulnerability discovery accuracy is realized in limited testing resources, and the testing efficiency and the vulnerability discovery accuracy are improved. The method can be widely applied to the technical field of software security.
Owner:GUANGZHOU UNIVERSITY

Enterprise-level three-party dependent package security management and control system and method

The invention discloses an enterprise-level three-party dependency package security management and control system and method, and relates to the technical field of software supply chain security, and the enterprise-level three-party dependency package security management and control system comprises the following modules: a timed task scheduling module, an external network package pre-scanning module, a private service package monitoring module, a dependency graph construction module, a product management and control module and a notification display module. By establishing an external network packet pre-scanning mechanism, security scanning is performed and a blocking list is generated before a dependent packet enters an enterprise private server, and introduction of a packet containing high-risk vulnerabilities is blocked from the source; meanwhile, through the continuous monitoring of the private server package and the construction of the dependency relationship graph, the vulnerability discovery and the accurate positioning of the influence range of the stored dependency package are realized; and finally, performing hierarchical management and control on the affected products based on vulnerability levels, and realizing timely transmission and situation visualization of risk information through a notification display module. According to the invention, full-life-cycle safety protection from an external network source to internal products of an enterprise is realized, and the safety management level and risk response efficiency of the dependent package of the enterprise are effectively improved.
Owner:CHINA FAW CO LTD +1

Fuzzy test verification method and system for password service interface

The invention discloses a fuzzy test verification method and system for a password service interface, and belongs to the technical field of password service technologies and software testing. The method comprises the following steps: firstly, constructing a password service interface feature library, and extracting key feature information; designing a multi-dimensional fuzzy test variation strategy based on the password service interface feature library, and generating a fuzzy test case set covering grammar exception, semantic exception and encryption scene exception; realizing communication adaptation between a test case and a target password service interface through a dynamic adaptation module, executing a fuzzy test, and collecting information such as response data and an operation state of the interface in real time; and finally, carrying out deep analysis on the acquired information through an anomaly detection and analysis module, positioning a vulnerability type and a trigger path, and generating a standardized test report. According to the method, different types of password service interfaces can be accurately adapted, the test coverage and the vulnerability discovery efficiency are remarkably improved, and reliable support is provided for security verification of the password service interfaces.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Deep learning framework fuzzy testing method based on large model cue word optimization

The invention relates to the cross technical field of artificial intelligence and software security testing, in particular to a deep learning framework fuzz testing method based on large model cue word optimization, which is used for improving vulnerability mining efficiency and testing intelligence level of fuzz testing on a deep learning framework. According to the method, the advantages of a large language model in the aspects of code understanding and generation are fully utilized, and efficient vulnerability detection of a deep learning framework is realized by introducing a cue word adaptive optimization and variation mechanism. The method mainly comprises the following steps: (1) providing a deep learning framework API classification method and a cue word routing mechanism; (2) proposing a large model cue word adaptive optimization mechanism; and (3) proposing a deep learning framework fuzzy test variation strategy and a dynamic selection mechanism. According to the method, the automation and vulnerability discovery capability of fuzzy testing can be remarkably improved while the generation quality is ensured, and the method has relatively high universality and application value.
Owner:HUNAN UNIV

Security test system and method for electric power information system

The invention discloses an electric power information system safety test system and method, and the system comprises a test management scheduling platform, a multi-level test execution engine, a real-time lossless collection and monitoring module, an intelligent analysis and decision engine, a digital twin simulation test platform, and a system self-protection and toughness evaluation module. According to the security test system and method for the electric power information system, all-around and deep security coverage of the electric power information system is realized, the breadth and depth of vulnerability discovery are remarkably improved, meanwhile, a real-time security test with lossless business is realized, high continuity and high availability of electric power production business are guaranteed, and secondly, the security of the electric power information system is improved. The intelligent and automatic testing process is realized, and the testing efficiency and the accurate decision-making capability of safety management are greatly improved.
Owner:STATE GRID HENAN ELECTRIC POWER CO WENXIAN POWER SUPPLY CO

Vulnerability discovery method and system based on symbol-semantic hybrid reasoning

The invention provides a vulnerability discovery method and system based on symbol-semantic hybrid reasoning, and belongs to the technical field of software security. The method comprises the steps that a target program is analyzed, and an event sequence is extracted; converting the event into a symbol with a time sequence label and confidence, and constructing a symbol dependency graph; reasoning based on the dependency graph, calling a large language model to generate a semantic reasoning action when the certainty is insufficient, and updating the state after symbol verification; new rules are extracted from the inference chain passing verification through reinforcement learning, and self-evolution is achieved; and outputting a vulnerability report containing the reasoning path and the confidence coefficient. The system correspondingly comprises a time sequence probability symbol module, a symbol-semantic bidirectional coupling reasoning module, a reinforcement learning self-evolution module and a report generation module. According to the method, the preciseness of symbol logic and the generalization ability of a semantic model are fused, the accuracy, interpretability and adaptive ability of vulnerability detection are effectively improved, and the method is suitable for security audit and code review of a complex software system.
Owner:HUAZHONG UNIV OF SCI & TECH

An IoT Fuzzy Testing Method Based on LLM Guidance and FSM Dynamic Inference

This invention discloses an IoT fuzzing method based on LLM-guided and FSM dynamic inference, belonging to the field of IoT network security and software testing technology. Addressing the problems of low coverage and inaccurate state machine inference in current IoT protocol fuzzing, this invention first constructs an initial FSM by combining IoT protocol specifications and captured traffic data. Then, it generates a large number of test cases through mutation of seed test cases for fuzzing testing. Features are extracted from device responses, and state identification is performed by calculating similarity. When a new state appears, the FSM and state fingerprint database are updated. When coverage becomes a bottleneck, LLM-guided path inference is used to generate extended sub-FSMs and test cases, which are then executed. The FSM is then corrected based on the test results. This invention enables high-precision automated construction of IoT protocol state FSMs, improving test coverage and enhancing the efficiency and accuracy of vulnerability discovery.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Gateway equipment fuzz test tool and method based on multi-protocol linkage

The invention discloses a gateway equipment fuzz testing tool and method based on multi-protocol linkage, and belongs to the technical field of fuzz testing. In order to solve the problem that effective fuzzy testing and anomaly detection cannot be carried out on an embedded gateway client in the prior art, a multi-protocol stack linkage triggering mechanism of an A protocol server and a B protocol client is established in a gateway, and a protocol linkage directional triggering mechanism is combined to simulate the driving and response process of a normal interaction object, so that the real-time performance of the embedded gateway client is improved. And injecting abnormal data to trigger a B protocol client request. According to the invention, indirect testing of the embedded black box client can be realized, abnormity monitoring is carried out, and client vulnerability discovery and robustness verification capabilities are improved.
Owner:NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT

Network penetration and planning method and system based on artificial intelligence

The invention provides a network penetration and planning method and system based on artificial intelligence, and relates to the field of network security, and the method comprises the steps: collecting network topology and host port data, recognizing known and unknown script vulnerabilities, constructing a vulnerability knowledge graph, and generating a penetration link; generating an attack view on the three-dimensional interface; generating a technology and behavior permeation chain and an execution sequence according to the target node; and finally, respectively generating attack instructions or codes for different types of vulnerabilities, and outputting a protection strategy. According to the method, the automation degree of penetration testing is improved, the unknown vulnerability discovery capability is enhanced, and the attack and defense resource configuration is optimized.
Owner:JIANGSU BOZHI SOFTWARE TECH CO LTD

Security risk assessment method and system based on attack chain deduction

PendingCN121864343AFinanceSecuring communicationTotal riskAttack
The invention discloses a security risk assessment method and system based on attack chain deduction, relates to the technical field of network security, and solves the problem that security risks are difficult to comprehensively and accurately assess in the prior art. According to the embodiment of the invention, by establishing the asset-vulnerability-attack stage mapping relationship, the whole-process visual modeling of the attack chain from initial reconnaissance to target achievement is realized, the specific effect of the vulnerability in the attack chain is determined, and the problem that the vulnerability linkage effect is neglected in traditional assessment is solved, so that more comprehensive risk assessment is realized; in addition, the mapping relation can be updated in real time according to asset change and new vulnerability discovery, accurate basic data support is provided for attack path generation, and dynamic construction of an attack surface panoramic view is achieved. Besides, by introducing path selected probability parameters, subjective strategy preferences of the attacker are brought into quantitative evaluation of the risk, so that total risk evaluation better fits real attack decision logic, and a more accurate evaluation result is obtained.
Owner:ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD

Low-interference taint path restoration system and method based on static instrumentation

The invention discloses a low-interference taint path restoration system and method based on static instrumentation, and mainly solves the problems of stiff analysis strategy, high operation overhead and result semantic deficiency faced by existing vulnerability mining and security assessment. The system comprises a target data acquisition end and an analysis engine which run independently and are connected through a shared memory channel; lightweight static instrumentation is performed on a source code in a target program compiling stage, and a shared memory channel with an analysis engine is established; by constructing a "producer-consumer" asynchronous decoupling architecture, time-consuming taint rule management and path restoration logic are stripped from a service main thread; a lockless annular buffer area is utilized to efficiently capture a runtime data stream, and a source code level taint propagation path is restored in an independent analysis engine in combination with debugging information and a call stack Hash algorithm. According to the method, a high-precision source code level analysis result can be obtained while low performance loss is kept, and the efficiency and flexibility of vulnerability mining are greatly improved.
Owner:XIDIAN UNIV

Protocol fuzzy test knowledge automatic construction method based on large language model

The invention relates to a protocol fuzz test knowledge automatic construction method based on a large language model, and belongs to the technical field of network security testing. The method comprises the steps that a standard document of a target protocol is preprocessed, and a document fragment set with a document structure is output; constructing a basic protocol intermediate representation (IR) from the document fragment set by using a large language model; inputting the basic protocol IR and a fuzzy test task indication into a large language model together, and constructing a fuzzy test IR comprising a field semantic category, a normalized constraint description and a fuzzy test related strategy prompt; writing the fuzzy test IR into a protocol fuzzy test knowledge base, and establishing a hierarchical storage and index structure; when the fuzzy test engine executes the fuzzy test task, knowledge in the knowledge base is called to guide generation and variation of the test case set. By using the method provided by the invention, rapid adaptation and protocol perception fuzz testing of multiple protocols can be realized, and the automation degree and vulnerability discovery capability of the protocol fuzz testing are remarkably improved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

A Generative AI-Based Method for Intelligent Discovery and Risk Assessment of Software Security Vulnerabilities

This invention relates to the fields of software security and artificial intelligence, specifically a generative AI-based intelligent vulnerability discovery and risk assessment method for software security. The method includes: generating abnormal behavior patterns by collecting multi-source data from the target software, inputting this data into a pre-trained generative AI model for multi-level correlation reasoning, and automatically outputting a set of vulnerability descriptions containing location, path, and impact. Historical verification of the vulnerability descriptions enhances their accuracy, and a risk posture assessment is performed. The attack entry point exposure, exploitation path feasibility, and system impact scope of each vulnerability are quantitatively calculated to form a structured risk quantification matrix. Based on this matrix, risk level mapping is completed, and remediation suggestions and priority sequences are automatically generated. Finally, a risk assessment report is integrated and output. This method automates and intelligently discovers vulnerabilities and significantly improves the accuracy and operability of risk analysis through multi-dimensional quantitative assessment.
Owner:BEIJING HUAXIN MEASUREMENT & CONTROL TECH CO LTD

Vulnerability discovery method, system and device based on extension and medium

The invention relates to a vulnerability discovery method, system and device based on extension and a medium. The method comprises the following steps: acquiring vulnerability alarm data and system resource state information of a network system, wherein the vulnerability alarm data comprises vulnerability feature information; based on the vulnerability alarm data, generating a risk score by utilizing extension association analysis; determining a vulnerability analysis mode based on the risk score and the system resource state information, and determining an analysis range by using the mode; and in the analysis range, identifying a conduction contradiction between the vulnerability feature information and a known vulnerability matter element library through a preset rule library, and identifying an unknown vulnerability. According to the invention, unknown vulnerabilities can be found efficiently and accurately, and the initiative and reliability of network security protection are improved.
Owner:NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT

Linux kernel vulnerability mining method based on diversity guidance

The invention belongs to the technical field of computer software testing, and particularly relates to a Linux kernel vulnerability mining method based on diversity guidance. According to the method, firstly, collected PoCs are expressed by using a customized abstract syntax tree, clustering is carried out on the PoCs based on a Louvain community discovery algorithm, an initial diversity seed bank is constructed, and seeds are divided into a plurality of communities with different functions; in order to quantify seed diversity, a community prevalence rate index (CPR) is introduced; designing a double-layer multi-arm tiger machine scheduling framework based on the CPR, wherein the framework is used for efficiently allocating variable resources between communities and in the communities; a CPR-guided seed variation strategy is adopted to preferentially carry out rapid variation and expansion on high-diversity seeds, so that the coverage speed and efficiency of vulnerability triggering are improved. Experimental results show that compared with a current most advanced kernel fuzzy test tool, the method has the advantages that the code coverage rate is averagely increased by 17.4%, and the vulnerability discovery number is averagely increased by 9.1 times.
Owner:FUDAN UNIVERSITY

Blockchain-based methods, systems, devices, and media for managing vulnerabilities in the Internet of Vehicles (IoV).

ActiveCN121037074BVulnerability managementData authenticity
This invention provides a blockchain-based method, system, device, and medium for managing vehicle network vulnerabilities, relating to the field of vehicle network technology. The method utilizes a dynamic and static vulnerability detection mechanism to comprehensively identify potential vehicle security risks and generate structured vulnerability reports. By using blockchain to hash and store key data from the report and subsequent remediation processes, the entire process of vulnerability discovery, analysis, and remediation is tamper-proof and traceable, enhancing data authenticity and trustworthiness. Cloud-based verification of report integrity, combined with an AI analysis engine linking CVE databases and threat intelligence, enables intelligent generation and decision support for remediation solutions. On-vehicle verification of OTA patches via on-chain hash digests ensures the credibility of patch sources and the integrity of content. Finally, feedback on installation results and re-archiving on the blockchain completes a closed-loop management system from vulnerability discovery to remediation verification.
Owner:FIFTH ELECTRONICS RSCH INST OF MINISTRY OF IND & INFO TECH

A state protocol fuzzing method and process based on a hierarchical large language model framework

PendingCN122372472ALocal languageLinguistic model
This invention discloses a state protocol fuzzing method and process based on a hierarchical large language model framework, belonging to the field of cyberspace security technology. Addressing the problems of skill dilution, context obfuscation, and high computational cost inherent in existing single large language model-driven fuzzing methods, this invention constructs a syntax analysis layer, a semantic reasoning layer, and a policy optimization layer. Specifically, the syntax analysis layer extracts a structured syntax tree from the raw message using protocol templates and an LLM (Local Language Model); the semantic reasoning layer combines protocol state with the syntax tree to infer business logic constraints, identify vulnerability patterns, and dynamically assess risks; and the policy optimization layer intelligently generates and adaptively adjusts mutation strategies based on risk scores and historical feedback. This invention effectively improves the coverage depth of the protocol state space and the efficiency of vulnerability discovery, while reducing computational costs, providing an efficient, intelligent, and economical solution for the security testing of complex network protocols.
Owner:HANGZHOU INNOVATION RES INST OF BEIJING UNIV OF AERONAUTICS & ASTRONAUTICS +1

A system and method for sbom-based automotive software supply chain security and open source governance

PendingCN122433094AAutomotive softwareTesting Methods
The application discloses a kind of based on SBOM's automobile software supply chain security and open source governance system and method, by identifying the bill of materials SBOM of automobile software provided by supplier, obtain the basic information of software containing multiple components, software extension information;Software basic information in SBOM is matched with trusted vulnerability library, obtain all known vulnerabilities of SBOM;According to the dependency in SBOM, the influence range of each vulnerability is analyzed, and the affected software product and vehicle model are determined;According to the software product, vehicle model, vulnerability hazard affected, determine vulnerability level;Known vulnerabilities of component and vulnerability level are bound with component in SBOM, form SBOM risk view, determine repair scheme based on risk view;From SBOM identification, vulnerability matching, risk assessment, repair scheme determination to SBOM update, cover the whole process of supply chain security management, form the closed-loop management from vulnerability discovery to repair, ensure that the problem is solved.
Owner:CHINA AUTOMOTIVE INTELLIGENT TECHNOLOGY (TIANJIN) CO LTD

A natural language processing-based JavaScript engine directed fuzz testing method and system

The application discloses a JavaScript engine oriented fuzz testing method and system based on natural language processing, which extracts JavaScript language syntax and semantic information through a BERT language model by using a natural language processing technology, performs fine-tuning by combining a residual network and a mask language model, and performs oriented fuzz testing on a JavaScript engine in combination with an AFLGO oriented fuzz testing technology. The bidirectional sequence processing capability of the BERT language model improves the precision of feature extraction, and the residual network further improves the accuracy of the language model. The oriented fuzz testing utilizes coverage information, and improves the speed of vulnerability discovery and the code coverage rate of the fuzz testing. The application takes into account the test case generation efficiency and the utilization of coverage information, greatly improves the effective test case generation rate, and also improves the code coverage rate of the fuzz testing.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

A method and system for fuzz testing of IEC104 protocol

ActiveCN114064451BMulti-dimensional improvementImprove the efficiency of discovering suspected vulnerabilitiesData processing applicationsError detection/correctionProgramming languageEngineering
The application discloses a kind of IEC104 protocol's fuzzy testing method and system, the method includes: establishing XML generation file, XML sending file and XML monitoring file;The XML generation file is parsed, and generates fuzzy test case;The XML sending file is parsed, and the fuzzy test case is sent to the target equipment of open IEC104 protocol;The XML monitoring file is parsed, and the service state is monitored based on the configuration data of the XML sending file and the XML monitoring file with the target equipment.This application uses XML description file to configure control for the three key processes of fuzzy test case generation, test case sending and target monitoring, can carry out fuzzy test for different target equipment specification without modifying metadata analysis tool code, and according to configuration, different service state changes and system survival are alarmed, and the efficiency of suspected vulnerability discovery is improved in multiple dimensions.
Owner:SHENZHEN YILINGKE NETWORK SECURITY CO LTD

Logic vulnerability detection method, system and device for network traffic analysis and medium

The invention belongs to the technical field of network security. The invention belongs to the technical field of network flow analysis, and particularly discloses a logic vulnerability detection method, system and device for network flow analysis and a medium. Service request response data are captured through network flow, non-request data or static resource data are filtered out by setting a filtering rule, the filtered data are analyzed, and the analyzed data are standardized into structured requests. By automatically identifying API semantics, constructing an API calling chain, a state conversion chain and a data dependence propagation chain, establishing cross-interface automatic identification of data flow and control flow, improving the web system logic vulnerability mining efficiency and coverage, and adding an active alarm function for finding vulnerabilities, the vulnerabilities can be found and solved in time; the method has the advantages that lightweight deployment and low-invasion operation are achieved, an API semantic and state model is automatically constructed, the vulnerability mining intelligent level is improved, the false alarm rate is reduced, and a closed-loop mechanism for discovery, verification and alarm is achieved.
Owner:BINZHOU POWER SUPPLY COMPANY OF STATE GRID SHANDONG ELECTRIC POWER

Automated in-pile memory pool analysis assisted vulnerability mining method and device

This invention provides an automated heap memory pool analysis-assisted vulnerability discovery method, apparatus, and electronic device, belonging to the field of data security technology. The method includes: analyzing the memory call behavior of a target application to determine whether the memory region requested by the target application during memory pool management contains multiple memory pages; if so, further analyzing the memory pool management library used by the target application; when the memory pool management library is a general-purpose memory management library, executing a pre-made patch replacement program; when the memory management library is a customized memory management library, employing a heuristic automatic patching program. The automatic patching program selectively receives a set of function names from the target function, performs matching and replacement in the target program code using heuristic rules, and generates the interception code required by LLVM's compile-rt. This solution can effectively discover memory-corruption vulnerabilities.
Owner:ELECTRIC POWER SCI RES INST OF STATE GRID XINJIANG ELECTRIC POWER CO LTD

Message generation method and device, computer device, storage medium and program product

PendingCN122364102AFeature parameterVulnerability discovery
The application relates to a message generation method and device, computer equipment, a storage medium and a program product, relates to the technical field of fuzzy testing, so that a mutation operation can be adjusted according to the stability of a target point and vulnerability triggering potential; and only a mutation function meeting a triggering condition is executed in the mutation process, unnecessary mutation operations are avoided; meanwhile, different mutation functions are used to mutate different dimensional characteristic parameters of effective target points, various characteristic changes of the target points can be comprehensively covered, the efficiency and effectiveness of the mutation operation are improved, more new target point matrices with high vulnerability triggering potential are generated, and the vulnerability discovery capability of the fuzzy testing is further improved.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD

Fuzzy testing method and system for command lines of multi-architecture operating system

The invention provides a fuzzy test method and system for a command line of a multi-architecture operating system. The method comprises the following steps: S1, receiving a command line example or a historical seed file and a test parameter input by a user through a graphical interface; s2, automatically identifying a current system hardware architecture and deploying a corresponding fuzzy test tool supporting a QEMU mode and a dependency environment; s3, automatically generating a test seed file based on user input, and calling a fuzzy test tool to execute a test in a QEMU mode; and S4, automatically collecting test results and generating a visual report. According to the method, through full-process imaging and automatic design, the technical threshold of fuzzy testing is remarkably reduced, unified testing of multiple architecture platforms such as X86, ARM and Loongson is supported, a complete testing closed loop from seed generation to result analysis is formed, and the testing efficiency and the vulnerability mining capacity are effectively improved.
Owner:KYLIN CORP

Power monitoring system vulnerability monitoring method based on dynamic instruction stream analysis

The invention provides a power monitoring system vulnerability monitoring method based on dynamic instruction stream analysis, and belongs to the technical field of information security. The method comprises the steps that a bottom-layer instruction stream in the running period is obtained, and the bottom-layer instruction stream comprises an instruction operation code, an instruction reading register, an instruction writing register, an instruction access address and an instruction execution timestamp; according to the instruction execution timestamp, carrying out time sequence sorting on the underlying instruction stream to obtain a directed time sequence diagram; performing instruction behavior feature extraction according to the directed time sequence diagram to obtain an instruction behavior vector; performing instruction behavior modeling according to the instruction behavior vector in the safe operation state to obtain a normal behavior reference model; performing abnormal instruction detection and vulnerability identification on the currently collected instruction behavior vector according to the normal behavior reference model to obtain a vulnerability identification result; and carrying out risk grading according to the vulnerability identification result to obtain a risk grade. According to the method, the detection coverage rate and the vulnerability discovery depth of vulnerability monitoring can be improved.
Owner:GUANGZHOU ELECTRIC POWER COMM NETWORK LTD

Tamper-resistant binary software package provenance system

The application provides a tamper-proof binary software package tracing system. It includes a data acquisition module that acquires tracing information of a binary software package; a blockchain storage module that stores the tracing information; a user interface module that provides an interface allowing authorized users to query the tracing information through the binary software package information; an SBOM enhancement module that expands the traditional SBOM to obtain an enhanced SBOM according to the tracing information; a verification module that verifies the integrity of the updated software package according to the updated hash value and the hash value stored in the blockchain storage module; and a vulnerability tracking module that constructs a vulnerability influence graph according to the component dependency relationship and vulnerability information stored in the blockchain storage module to identify downstream software packages affected by known vulnerabilities and track their propagation path. In this way, fine-grained tracking of software components and their dependencies is achieved, enabling quick identification of affected software packages after vulnerability discovery and providing accurate repair guidance, thereby enhancing the trustworthiness of the software supply chain.
Owner:NAT UNIV OF DEFENSE TECH

Selective backdoor vulnerability mining method

The invention discloses a selective backdoor vulnerability mining method and relates to the field of network security. According to the method, a target data set is wrongly recognized by a classifier, the data sets need to be processed, trigger-G is added to all the data sets, convergence operation is performed on G by using gradient descent, and finally, an optimal trigger G is obtained. After the trigger G is applied to all the data sets and the model is input for training, the trigger is finely adjusted to find potential vulnerabilities, and the vulnerabilities can be caused when only the target data set is embedded into the trigger by adjusting the trigger. Through the method, the traces of backdoor attacks can be reduced, and the probability of being detected is reduced.
Owner:LIAONING UNIVERSITY

0day-based vulnerability active discovery and defense method and system

The invention relates to the technical field of network security, and discloses an active vulnerability discovery and defense method and system based on 0day, and the method comprises the steps: carrying out the automatic behavior test of a target system, and obtaining the system response data of the target system; performing vulnerability clue identification on the system response data to obtain a vulnerability triggering path; constructing an association graph of the target system according to public related information of suppliers of the target system and users of similar systems; based on the association graph and the vulnerability triggering path, performing batch testing on similar systems of the target system to obtain version matching information of the target system; simulating an attacker utilization process, constructing a complete vulnerability utilization chain, extracting technical vulnerability features of version matching information, and generating a vulnerability feature library; based on the vulnerability feature library and the vulnerability utilization chain, performing continuous monitoring on similar systems of the target system to obtain a layered defense scheme and repair early warning information; according to the invention, the efficiency of active discovery and defense of vulnerabilities based on 0day can be improved.
Owner:XIAN THERMAL POWER RES INST CO LTD

Rag and multi-agent based automated penetration testing method and system

This invention relates to the field of network security technology, and in particular to an automated penetration testing method and system based on RAG and multi-agent systems. The method involves: step S1, acquiring target intelligence files; step S2, precisely driving semantic retrieval of the RAG knowledge base based on the target intelligence files; step S3, planning and scheduling based on a penetration-related knowledge graph; step S4, using dynamic resource scheduling by a scheduling center and parallel execution by a multi-agent cluster; step S5, aggregating and standardizing preliminary test results and applying a predefined set of contradictory rules for consistency verification; and step S6, judging the value of the target task. This achieves precise and flexible allocation of limited testing resources, thereby improving the testing depth and vulnerability discovery efficiency of the core attack surface.
Owner:BEIJING ANJIHUI TECHNOLOGY CO LTD

An embedded system vulnerability detection method based on agent cooperation

This invention discloses an embedded system vulnerability detection method based on intelligent agent collaboration, aiming to address the shortcomings of existing technologies in vulnerability detection in complex embedded environments, including insufficient capability, lack of autonomy, and lack of adaptability. This invention establishes a structured representation of system state evolution by constructing a causal graph including code, hardware state, and physical feedback. It uses an autonomous hunting agent driven by a large language model as its core, autonomously generating a hunting plan based on the causal model and coordinating the use of various tools such as fuzz testing, symbolic execution, and static analysis for vulnerability discovery and verification. After discovering an initial vulnerability, it automatically infers and synthesizes a cross-domain exploit chain to assess the complete attack surface. Finally, it uses a reinforcement learning framework to enable the system to continuously learn from hunting experience and optimize its decision-making strategy. This invention upgrades vulnerability detection from passive pattern matching to an active exploration and reasoning process, achieving efficient and intelligent detection and exploit verification of unknown vulnerabilities in embedded systems.
Owner:ZHANGZHOU POWER SUPPLY COMPANY STATE GRID FUJIANELECTRIC POWER +1