Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

75 results about "Vulnerability discovery" patented technology

Large-model multi-scene antagonism dynamic evaluation system and method based on context perception strategy optimization

The invention discloses a large-model multi-scene antagonism dynamic evaluation system and method based on context perception strategy optimization, relates to the technical field of artificial intelligence safety evaluation, and aims to solve the problems of lack of multi-round context modeling, poor confrontation sample semantic consistency and lack of a feedback-driven optimization mechanism in the prior art. According to the method, a state space and an action space are constructed, an adversarial sample is dynamically generated by adopting a reinforcement learning strategy network, a high-quality sample set is expanded in combination with a semantic disturbance and screening mechanism, and a vulnerability knowledge base is constructed based on an interaction log to guide strategy optimization and security evaluation. The method can effectively improve the security evaluation coverage and vulnerability discovery capability of the model in a high-risk multi-round interaction scene, and is mainly used for security reinforcement and deployment support of large language models in the fields of medical treatment, customer service and the like.
Owner:ARTIFICIAL INTELLIGENCE INNOVATION RES INST OF ZHEJIANG UNIV OF TECH BINJIANG DISTRICT HANGZHOU

Internet of vehicles vulnerability management method, system and device based on block chain, and medium

The invention provides an Internet of Vehicles vulnerability management method, system, device and medium based on a block chain, and relates to the technical field of vehicle networks, the method can comprehensively identify potential safety risks of vehicles through a dynamic and static combined vulnerability detection mechanism, and generates a structured vulnerability report; hash abstract chaining evidence storage is performed on key data of reports and subsequent repair links by using a block chain, so that the whole process of vulnerability discovery, analysis and repair is ensured not to be tampered and traceable, and the authenticity and credibility of data are improved; the integrity of the report is verified at the cloud end, and an AI analysis engine is combined to associate a CVE database and threat intelligence, so that intelligent generation and decision support of a repair scheme are realized; the hash abstract on the chain of the OTA patch is verified at the vehicle end, so that the credibility of the patch source and the integrity of the content are guaranteed; and finally, through feedback of an installation result and secondary uplink archiving, complete closed-loop management from vulnerability discovery to repair verification is formed.
Owner:FIFTH ELECTRONICS RSCH INST OF MINISTRY OF IND & INFO TECH

Industrial control protocol intelligent fuzzy test method and system based on multi-agent large model

The invention discloses an industrial control protocol intelligent fuzzy test method and system based on a multi-agent large model, and relates to an industrial information security test method and system.According to the industrial control protocol intelligent fuzzy test method and system based on the multi-agent large model, the large model is enhanced by integrating the field of the retrieval enhancement generation (RAG) and the low-rank quantization adaptation (QLoRA) technology, and a multi-agent cooperation mechanism is combined; and full-automatic, high-precision and end-to-end fuzzy testing of the industrial protocol is realized. The system generates seed data meeting protocol specifications through the seed generation agent, the test case generation agent executes field, structure and semantic variation based on the seed data, efficient test cases are dynamically generated, a test strategy is optimized in real time through the feedback analysis and strategy adjustment agent, and the vulnerability discovery capability is improved. By dynamically adjusting the variation strategy and optimizing the generation of the test case, the coverage, the accuracy and the efficiency of the test are improved, and the security and the vulnerability detection capability of the industrial control system are remarkably improved.
Owner:SHENYANG INSTITUTE OF CHEMICAL TECHNOLOGY

Knowledge extraction and envelope coverage-oriented software vulnerability test method and related equipment

The invention discloses a knowledge extraction and envelope coverage-oriented software vulnerability test method and related equipment, and the method comprises the steps: obtaining vulnerability key information of target software, and obtaining sensitive function features through defect dependence analysis and construction based on the vulnerability key information; performing semantic analysis on the analysis report and the code abstract associated with the sensitive function characteristics, screening to obtain a target sensitive function, performing path envelope reverse tracking on the target sensitive function, and constructing to obtain a target path envelope; and obtaining coverage information enveloped by the target path, and carrying out fuzzy testing on the basis of the coverage information in combination with the iteratively optimized variation sample. According to the method, through intelligent closed loop of analysis-positioning-testing-feedback-optimization, static analysis provides accurate guidance for dynamic testing, and the static analysis strategy is inversely optimized by the result of the dynamic testing, so that the maximum improvement of the testing efficiency and the vulnerability discovery accuracy is realized in limited testing resources, and the testing efficiency and the vulnerability discovery accuracy are improved. The method can be widely applied to the technical field of software security.
Owner:GUANGZHOU UNIVERSITY

Enterprise-level three-party dependent package security management and control system and method

The invention discloses an enterprise-level three-party dependency package security management and control system and method, and relates to the technical field of software supply chain security, and the enterprise-level three-party dependency package security management and control system comprises the following modules: a timed task scheduling module, an external network package pre-scanning module, a private service package monitoring module, a dependency graph construction module, a product management and control module and a notification display module. By establishing an external network packet pre-scanning mechanism, security scanning is performed and a blocking list is generated before a dependent packet enters an enterprise private server, and introduction of a packet containing high-risk vulnerabilities is blocked from the source; meanwhile, through the continuous monitoring of the private server package and the construction of the dependency relationship graph, the vulnerability discovery and the accurate positioning of the influence range of the stored dependency package are realized; and finally, performing hierarchical management and control on the affected products based on vulnerability levels, and realizing timely transmission and situation visualization of risk information through a notification display module. According to the invention, full-life-cycle safety protection from an external network source to internal products of an enterprise is realized, and the safety management level and risk response efficiency of the dependent package of the enterprise are effectively improved.
Owner:CHINA FAW CO LTD +1

Software supply chain vulnerability assessment method based on multi-Agent collaboration and dynamic hypergraph learning

The invention discloses a software supply chain vulnerability assessment method based on multi-Agent collaboration and dynamic hypergraph learning, which is used for opening a link between vulnerability assessment and repair and realizing full-life-cycle collaboration linkage. For the problem of vulnerability assessment and repair splitting, the method covers the core capabilities of static analysis (SAST), dynamic detection (DAST), interactive analysis (IAST), intelligence analysis and the like. Evaluation results of various agents are output through standardized vulnerability portraits, and a subsequent repair strategy is driven to be automatically generated and executed, so that whole-process closed-loop linkage and fine control of'discovery-evaluation-repair-verification 'of vulnerabilities are realized.
Owner:THE FIRST RES INST OF MIN OF PUBLIC SECURITY

MQTT protocol fuzz testing method and system based on large language model guidance sequence generative adversarial network

The invention discloses an MQTT protocol fuzzy testing method and system based on a large language model guiding sequence generative adversarial network, relates to the field of fuzzy testing, effectively combines the advantages of the large language model and the sequence generative adversarial network, and analyzes basic training data by introducing an intelligent analysis technology of the large language model. And the quality of the training sample of the sequence generative adversarial network is obviously improved. According to the method, the initial seeds can be enriched through the large language model, the discriminator can be assisted to perform multi-dimensional evaluation on the data generated by the generator, and the authenticity and diversity of the test seeds are enhanced. The generation of redundant test cases is greatly reduced, so that the fuzzy test process is more efficient. Meanwhile, a seed elimination technology based on an energy value is designed, it is further ensured that the tested seeds have higher quality, and the efficiency of vulnerability discovery is effectively improved. Meanwhile, according to the maximum coverage length, the test strategy is dynamically adjusted, continuous optimization of the test process is achieved, and a solid guarantee is provided for the test. According to the method, multi-level variation is carried out on the test seeds by utilizing a large language model, vulnerability information existing in the test seeds is quickly positioned, and meanwhile, multi-dimensional and deeper mutation is carried out on the test seeds, so that more existing vulnerability information is explored, namely, the multi-level mutation is carried out on the test seeds; the test seeds which successfully cause the vulnerabilities are verified and optimized by means of the response of the test target, the success and failure positions are summarized, and a more reliable guarantee is provided for subsequent variation.
Owner:LANZHOU UNIVERSITY OF TECHNOLOGY

Multi-agent collaborative HarmonyOS API fuzzy testing method, device and system and storage medium

The invention discloses a multi-agent collaborative HarmonyOS API (Application Program Interface) fuzzy testing method, device and system and a storage medium. The method comprises the following steps: preprocessing a HarmonyOS development document; constructing a cue word input large model by utilizing the pre-processed document, optimizing a cue word template in combination with reinforcement learning, and integrating an Android example code to generate a corresponding driving code; performing grammar detection on the generated drive code to generate a high-quality seed bank; performing cyclic fuzzy testing by utilizing the seed bank, wherein the cyclic fuzzy testing comprises seed selection, variation, compiling operation, log collection and system screenshot; and performing vulnerability analysis based on logs and system screenshots generated in the loop fuzzy test process. According to the invention, the vulnerability discovery efficiency is improved, and the manual workload is reduced.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Fuzzy test verification method and system for password service interface

The invention discloses a fuzzy test verification method and system for a password service interface, and belongs to the technical field of password service technologies and software testing. The method comprises the following steps: firstly, constructing a password service interface feature library, and extracting key feature information; designing a multi-dimensional fuzzy test variation strategy based on the password service interface feature library, and generating a fuzzy test case set covering grammar exception, semantic exception and encryption scene exception; realizing communication adaptation between a test case and a target password service interface through a dynamic adaptation module, executing a fuzzy test, and collecting information such as response data and an operation state of the interface in real time; and finally, carrying out deep analysis on the acquired information through an anomaly detection and analysis module, positioning a vulnerability type and a trigger path, and generating a standardized test report. According to the method, different types of password service interfaces can be accurately adapted, the test coverage and the vulnerability discovery efficiency are remarkably improved, and reliable support is provided for security verification of the password service interfaces.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Deep learning framework fuzzy testing method based on large model cue word optimization

The invention relates to the cross technical field of artificial intelligence and software security testing, in particular to a deep learning framework fuzz testing method based on large model cue word optimization, which is used for improving vulnerability mining efficiency and testing intelligence level of fuzz testing on a deep learning framework. According to the method, the advantages of a large language model in the aspects of code understanding and generation are fully utilized, and efficient vulnerability detection of a deep learning framework is realized by introducing a cue word adaptive optimization and variation mechanism. The method mainly comprises the following steps: (1) providing a deep learning framework API classification method and a cue word routing mechanism; (2) proposing a large model cue word adaptive optimization mechanism; and (3) proposing a deep learning framework fuzzy test variation strategy and a dynamic selection mechanism. According to the method, the automation and vulnerability discovery capability of fuzzy testing can be remarkably improved while the generation quality is ensured, and the method has relatively high universality and application value.
Owner:HUNAN UNIV

Security test system and method for electric power information system

The invention discloses an electric power information system safety test system and method, and the system comprises a test management scheduling platform, a multi-level test execution engine, a real-time lossless collection and monitoring module, an intelligent analysis and decision engine, a digital twin simulation test platform, and a system self-protection and toughness evaluation module. According to the security test system and method for the electric power information system, all-around and deep security coverage of the electric power information system is realized, the breadth and depth of vulnerability discovery are remarkably improved, meanwhile, a real-time security test with lossless business is realized, high continuity and high availability of electric power production business are guaranteed, and secondly, the security of the electric power information system is improved. The intelligent and automatic testing process is realized, and the testing efficiency and the accurate decision-making capability of safety management are greatly improved.
Owner:STATE GRID HENAN ELECTRIC POWER CO WENXIAN POWER SUPPLY CO

Vulnerability discovery method and system based on symbol-semantic hybrid reasoning

The invention provides a vulnerability discovery method and system based on symbol-semantic hybrid reasoning, and belongs to the technical field of software security. The method comprises the steps that a target program is analyzed, and an event sequence is extracted; converting the event into a symbol with a time sequence label and confidence, and constructing a symbol dependency graph; reasoning based on the dependency graph, calling a large language model to generate a semantic reasoning action when the certainty is insufficient, and updating the state after symbol verification; new rules are extracted from the inference chain passing verification through reinforcement learning, and self-evolution is achieved; and outputting a vulnerability report containing the reasoning path and the confidence coefficient. The system correspondingly comprises a time sequence probability symbol module, a symbol-semantic bidirectional coupling reasoning module, a reinforcement learning self-evolution module and a report generation module. According to the method, the preciseness of symbol logic and the generalization ability of a semantic model are fused, the accuracy, interpretability and adaptive ability of vulnerability detection are effectively improved, and the method is suitable for security audit and code review of a complex software system.
Owner:HUAZHONG UNIV OF SCI & TECH

Measuring confounding effects in machine learning-based vulnerability discovery

A system and method include reception of a plurality of code samples and corresponding ground truth classifications, generation, for each of the plurality code samples, of a plurality of perturbed code samples, generation of first probabilities for each of the plurality of code samples and the perturbed code samples using a first classification model, generation of second probabilities for each of the plurality of code samples and the perturbed code samples using a second model, determination of a causal probability for each code sample based on the first probabilities and the second probabilities, determination of a causal performance metric of the first classification model based on the ground truth classifications and the causal probabilities, and presentation of the causal performance metric.
Owner:SAP SE

Webpage API (Application Program Interface) depth discovery method

The invention relates to a webpage API (Application Program Interface) depth discovery method, which comprises the following steps of: injecting a self-defined JS (JavaScript) code into a chromium browser which is started in a headless mode, triggering a webpage event and realizing request interception and hijack monitoring, and gradually triggering and completely traversing a functional process aiming at DOM0 and DOM2 events in the webpage code, meanwhile, a specific execution result is returned through a special DOM event of a HOOK part, the webpage is locked to avoid jumping in the triggering process, the DOM event on the webpage is triggered as completely as possible with the assistance of a field automatic filling function, and meanwhile, URL requests of webpage event functions are recorded and summarized. Compared with the prior art, the method has higher API discovery capability; according to the model, a browser event triggering and function HOOK technology method is adopted, the problems that a vulnerability scanner discovers and captures webpage URL paths and APIs are missing and incomplete are well solved, and the capacity of discovering the APIs and the vulnerabilities in the field of automatic vulnerability discovering is improved.
Owner:SHANGHAI WEIDAO INFORMATION TECH CO LTD

Penetration test method and equipment for vehicle digital key system and medium

The invention provides a penetration test method and device for a vehicle digital key system and a medium, and relates to the technical field of remote data processing.The method comprises the steps that a vehicle state abnormal degree value is obtained through state data of a target vehicle before and after a first test case, and training samples are further stored in a partitioned mode; respectively training a generator and a discriminator based on the training samples stored in the partitions; inputting the random number into a generator which completes at least one round of training to obtain a second test case, and obtaining a decision value corresponding to the second test case according to a discriminator; if the judgment value is smaller than a preset judgment threshold value, sending the judgment value to a target API interface for testing; according to the method, generation of a large number of invalid or redundant test cases is effectively avoided, automatic directional detection and accurate triggering of potential security vulnerabilities such as authentication bypassing, session hijacking and unauthorized control are achieved, and penetration test efficiency and vulnerability discovery capability are remarkably improved.
Owner:SHANDONG ZELU SAFETY TECH CO LTD

An IoT Fuzzy Testing Method Based on LLM Guidance and FSM Dynamic Inference

This invention discloses an IoT fuzzing method based on LLM-guided and FSM dynamic inference, belonging to the field of IoT network security and software testing technology. Addressing the problems of low coverage and inaccurate state machine inference in current IoT protocol fuzzing, this invention first constructs an initial FSM by combining IoT protocol specifications and captured traffic data. Then, it generates a large number of test cases through mutation of seed test cases for fuzzing testing. Features are extracted from device responses, and state identification is performed by calculating similarity. When a new state appears, the FSM and state fingerprint database are updated. When coverage becomes a bottleneck, LLM-guided path inference is used to generate extended sub-FSMs and test cases, which are then executed. The FSM is then corrected based on the test results. This invention enables high-precision automated construction of IoT protocol state FSMs, improving test coverage and enhancing the efficiency and accuracy of vulnerability discovery.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Gateway equipment fuzz test tool and method based on multi-protocol linkage

The invention discloses a gateway equipment fuzz testing tool and method based on multi-protocol linkage, and belongs to the technical field of fuzz testing. In order to solve the problem that effective fuzzy testing and anomaly detection cannot be carried out on an embedded gateway client in the prior art, a multi-protocol stack linkage triggering mechanism of an A protocol server and a B protocol client is established in a gateway, and a protocol linkage directional triggering mechanism is combined to simulate the driving and response process of a normal interaction object, so that the real-time performance of the embedded gateway client is improved. And injecting abnormal data to trigger a B protocol client request. According to the invention, indirect testing of the embedded black box client can be realized, abnormity monitoring is carried out, and client vulnerability discovery and robustness verification capabilities are improved.
Owner:NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT

Network penetration and planning method and system based on artificial intelligence

The invention provides a network penetration and planning method and system based on artificial intelligence, and relates to the field of network security, and the method comprises the steps: collecting network topology and host port data, recognizing known and unknown script vulnerabilities, constructing a vulnerability knowledge graph, and generating a penetration link; generating an attack view on the three-dimensional interface; generating a technology and behavior permeation chain and an execution sequence according to the target node; and finally, respectively generating attack instructions or codes for different types of vulnerabilities, and outputting a protection strategy. According to the method, the automation degree of penetration testing is improved, the unknown vulnerability discovery capability is enhanced, and the attack and defense resource configuration is optimized.
Owner:JIANGSU BOZHI SOFTWARE TECH CO LTD

Security risk assessment method and system based on attack chain deduction

The invention discloses a security risk assessment method and system based on attack chain deduction, relates to the technical field of network security, and solves the problem that security risks are difficult to comprehensively and accurately assess in the prior art. According to the embodiment of the invention, by establishing the asset-vulnerability-attack stage mapping relationship, the whole-process visual modeling of the attack chain from initial reconnaissance to target achievement is realized, the specific effect of the vulnerability in the attack chain is determined, and the problem that the vulnerability linkage effect is neglected in traditional assessment is solved, so that more comprehensive risk assessment is realized; in addition, the mapping relation can be updated in real time according to asset change and new vulnerability discovery, accurate basic data support is provided for attack path generation, and dynamic construction of an attack surface panoramic view is achieved. Besides, by introducing path selected probability parameters, subjective strategy preferences of the attacker are brought into quantitative evaluation of the risk, so that total risk evaluation better fits real attack decision logic, and a more accurate evaluation result is obtained.
Owner:ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD

Low-interference taint path restoration system and method based on static instrumentation

The invention discloses a low-interference taint path restoration system and method based on static instrumentation, and mainly solves the problems of stiff analysis strategy, high operation overhead and result semantic deficiency faced by existing vulnerability mining and security assessment. The system comprises a target data acquisition end and an analysis engine which run independently and are connected through a shared memory channel; lightweight static instrumentation is performed on a source code in a target program compiling stage, and a shared memory channel with an analysis engine is established; by constructing a "producer-consumer" asynchronous decoupling architecture, time-consuming taint rule management and path restoration logic are stripped from a service main thread; a lockless annular buffer area is utilized to efficiently capture a runtime data stream, and a source code level taint propagation path is restored in an independent analysis engine in combination with debugging information and a call stack Hash algorithm. According to the method, a high-precision source code level analysis result can be obtained while low performance loss is kept, and the efficiency and flexibility of vulnerability mining are greatly improved.
Owner:XIDIAN UNIV

Building network vulnerability discovery method and device, optimization method, equipment and medium

The embodiments of the present application relate to the field of artificial intelligence technology, and relate to a method and apparatus for discovering poor points in a building network, an optimization method, equipment, and a medium. The specific scheme is: clustering each complaint sample according to the complaint location information to obtain at least one clustering area; according to the building location information, obtaining the local buildings within the at least one clustering area; for each of the clustering areas, determining a preset number of high sampling point cells for each local building within the clustering area, and when the high sampling point cells meet the poor performance index, determining the clustering area as a network poor point. The embodiments of the present application realize the discovery of poor points in a building network based on complaint samples, can accurately locate network problems, discover large-scale poor areas in the network in advance, guide relevant personnel to conduct timely investigation and processing, avoid later complaint problems, improve the efficiency of solving complaint problems, and improve customer satisfaction.
Owner:BEIJING TUOMING COMM TECH

Protocol fuzzy test knowledge automatic construction method based on large language model

The invention relates to a protocol fuzz test knowledge automatic construction method based on a large language model, and belongs to the technical field of network security testing. The method comprises the steps that a standard document of a target protocol is preprocessed, and a document fragment set with a document structure is output; constructing a basic protocol intermediate representation (IR) from the document fragment set by using a large language model; inputting the basic protocol IR and a fuzzy test task indication into a large language model together, and constructing a fuzzy test IR comprising a field semantic category, a normalized constraint description and a fuzzy test related strategy prompt; writing the fuzzy test IR into a protocol fuzzy test knowledge base, and establishing a hierarchical storage and index structure; when the fuzzy test engine executes the fuzzy test task, knowledge in the knowledge base is called to guide generation and variation of the test case set. By using the method provided by the invention, rapid adaptation and protocol perception fuzz testing of multiple protocols can be realized, and the automation degree and vulnerability discovery capability of the protocol fuzz testing are remarkably improved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

A Generative AI-Based Method for Intelligent Discovery and Risk Assessment of Software Security Vulnerabilities

This invention relates to the fields of software security and artificial intelligence, specifically a generative AI-based intelligent vulnerability discovery and risk assessment method for software security. The method includes: generating abnormal behavior patterns by collecting multi-source data from the target software, inputting this data into a pre-trained generative AI model for multi-level correlation reasoning, and automatically outputting a set of vulnerability descriptions containing location, path, and impact. Historical verification of the vulnerability descriptions enhances their accuracy, and a risk posture assessment is performed. The attack entry point exposure, exploitation path feasibility, and system impact scope of each vulnerability are quantitatively calculated to form a structured risk quantification matrix. Based on this matrix, risk level mapping is completed, and remediation suggestions and priority sequences are automatically generated. Finally, a risk assessment report is integrated and output. This method automates and intelligently discovers vulnerabilities and significantly improves the accuracy and operability of risk analysis through multi-dimensional quantitative assessment.
Owner:BEIJING HUAXIN MEASUREMENT & CONTROL TECH CO LTD

Vulnerability discovery method, system and device based on extension and medium

The invention relates to a vulnerability discovery method, system and device based on extension and a medium. The method comprises the following steps: acquiring vulnerability alarm data and system resource state information of a network system, wherein the vulnerability alarm data comprises vulnerability feature information; based on the vulnerability alarm data, generating a risk score by utilizing extension association analysis; determining a vulnerability analysis mode based on the risk score and the system resource state information, and determining an analysis range by using the mode; and in the analysis range, identifying a conduction contradiction between the vulnerability feature information and a known vulnerability matter element library through a preset rule library, and identifying an unknown vulnerability. According to the invention, unknown vulnerabilities can be found efficiently and accurately, and the initiative and reliability of network security protection are improved.
Owner:NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT

Method and apparatus for discovering protocol inconsistency vulnerabilities based on human-machine collaboration

This invention provides a method and apparatus for discovering protocol inconsistency vulnerabilities based on human-machine collaboration. The method involves acquiring multiple target middleware to be processed; testing each target middleware using pre-generated test samples to obtain test results; wherein the test samples are extracted and generated based on a pre-stored document analyzer; and analyzing each test result based on a pre-stored difference analysis algorithm to obtain analysis results. If the analysis results include preset differences, then a protocol inconsistency vulnerability is determined to exist among the target middleware. This invention takes a novel human-machine collaborative vulnerability discovery approach, targeting HTTP middleware, and utilizes a document analyzer to extract and generate test samples, along with differential testing methods, to semi-automatically discover protocol inconsistency vulnerabilities caused by semantic differences in various HTTP middleware. This achieves a systematic, scalable, more efficient, and more accurate discovery of protocol inconsistency vulnerabilities.
Owner:TSINGHUA UNIVERSITY

Fuzzing system and method for wasm module in JavaScript engine

The application provides a kind of fuzzy testing system and method for WASM module in JavaScript engine, the system is cooperatively constituted by seed generation module, target engine adaptation module and fuzzy testing module, seed generation module combines the new features of WASM, seed generation algorithm is designed.This algorithm not only strengthens the coverage of WASM and JavaScript interaction, but also ensures the semantic correctness of the test sample generated by dynamic parameter adjustment and syntax constraint.Target engine adaptation module adopts weighted coverage feedback and additional correctness checking mechanism to accurately identify potential boundary access and type confusion vulnerabilities.Fuzzy testing module efficiently discovers and reproduces security issues in the engine.The application can quickly locate the vulnerabilities such as memory corruption and boundary access in WASM module of JavaScript engine, providing key protection for web security, helping JavaScript engine developers and security researchers quickly identify security risks, improving testing efficiency and the number of vulnerability discovery, and enhancing the security of JavaScript engine.
Owner:SHANGHAI JIAOTONG UNIV

Linux kernel vulnerability mining method based on diversity guidance

The invention belongs to the technical field of computer software testing, and particularly relates to a Linux kernel vulnerability mining method based on diversity guidance. According to the method, firstly, collected PoCs are expressed by using a customized abstract syntax tree, clustering is carried out on the PoCs based on a Louvain community discovery algorithm, an initial diversity seed bank is constructed, and seeds are divided into a plurality of communities with different functions; in order to quantify seed diversity, a community prevalence rate index (CPR) is introduced; designing a double-layer multi-arm tiger machine scheduling framework based on the CPR, wherein the framework is used for efficiently allocating variable resources between communities and in the communities; a CPR-guided seed variation strategy is adopted to preferentially carry out rapid variation and expansion on high-diversity seeds, so that the coverage speed and efficiency of vulnerability triggering are improved. Experimental results show that compared with a current most advanced kernel fuzzy test tool, the method has the advantages that the code coverage rate is averagely increased by 17.4%, and the vulnerability discovery number is averagely increased by 9.1 times.
Owner:FUDAN UNIVERSITY

Zero-trust power terminal network security authentication system based on self-arrangement access sequence

The invention discloses a zero-trust power terminal network security certification system based on a self-arranged access sequence, which relates to the technical field of network security communication, and comprises a self-adaptive security assessment layer, the framework of which comprises closed-loop processes of vulnerability discovery, verification, assessment and protection strategies, and adopts a self-learning mechanism, historical data and running logs are continuously analyzed, a vulnerability detection model and a protection rule are dynamically adjusted, and the detection efficiency and accuracy are improved; and the network gating module is used for constructing a self-arrangement access sequence model, carrying out dynamic permission adjustment management on access of network resources through a dynamic access verification and single packet authentication mechanism, and constructing a closed loop mechanism from vulnerability detection to protection through a dynamic patch technology, a virtualization isolation method and a zero-trust network architecture. Through a dynamic port sequence verification and single packet authentication mechanism, only equipment passing complete access sequence verification is allowed to access core resources, and the authority of the equipment is dynamically adjusted at the same time.
Owner:ELECTRIC POWER SCI RES INST OF STATE GRID XINJIANG ELECTRIC POWER CO LTD

Blockchain-based methods, systems, devices, and media for managing vulnerabilities in the Internet of Vehicles (IoV).

This invention provides a blockchain-based method, system, device, and medium for managing vehicle network vulnerabilities, relating to the field of vehicle network technology. The method utilizes a dynamic and static vulnerability detection mechanism to comprehensively identify potential vehicle security risks and generate structured vulnerability reports. By using blockchain to hash and store key data from the report and subsequent remediation processes, the entire process of vulnerability discovery, analysis, and remediation is tamper-proof and traceable, enhancing data authenticity and trustworthiness. Cloud-based verification of report integrity, combined with an AI analysis engine linking CVE databases and threat intelligence, enables intelligent generation and decision support for remediation solutions. On-vehicle verification of OTA patches via on-chain hash digests ensures the credibility of patch sources and the integrity of content. Finally, feedback on installation results and re-archiving on the blockchain completes a closed-loop management system from vulnerability discovery to remediation verification.
Owner:FIFTH ELECTRONICS RSCH INST OF MINISTRY OF IND & INFO TECH

A state protocol fuzzing method and process based on a hierarchical large language model framework

PendingCN122372472ALocal languageLinguistic model
This invention discloses a state protocol fuzzing method and process based on a hierarchical large language model framework, belonging to the field of cyberspace security technology. Addressing the problems of skill dilution, context obfuscation, and high computational cost inherent in existing single large language model-driven fuzzing methods, this invention constructs a syntax analysis layer, a semantic reasoning layer, and a policy optimization layer. Specifically, the syntax analysis layer extracts a structured syntax tree from the raw message using protocol templates and an LLM (Local Language Model); the semantic reasoning layer combines protocol state with the syntax tree to infer business logic constraints, identify vulnerability patterns, and dynamically assess risks; and the policy optimization layer intelligently generates and adaptively adjusts mutation strategies based on risk scores and historical feedback. This invention effectively improves the coverage depth of the protocol state space and the efficiency of vulnerability discovery, while reducing computational costs, providing an efficient, intelligent, and economical solution for the security testing of complex network protocols.
Owner:HANGZHOU INNOVATION RES INST OF BEIJING UNIV OF AERONAUTICS & ASTRONAUTICS +1