Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

600 results about "Whitelist" patented technology

Whitelisting is the practice of explicitly allowing some identified entities access to a particular privilege, service, mobility, access or recognition. It is the reverse of blacklisting.

File uploading attack interception method based on semantic entropy enhancement

The invention provides a file uploading attack interception method based on semantic entropy enhancement, and aims at overcoming the defects of an existing file uploading security protection technology in the face of complex attacks. The method specifically comprises the steps that S1, file format analysis and content extraction are conducted, hidden scripts are mined through nested content recognition, and intermediate representation is generated through grammar cleaning and coding specifications; s2, constructing an abstract syntax tree and semantic entropy calculation, tracking a pollution chain, analyzing a high-risk function, identifying a high-entropy character string, modeling and controlling flow complexity, and generating a semantic entropy vector; s3, dynamic scoring and decision making are carried out, and accurate judgment is carried out in combination with white list perception, feature comparison, multi-modal model scoring, adaptive threshold and sandbox observation; and S4, carrying out real-time interception and feature synchronization, blocking malicious file landing, generating an attack log and synchronizing an attack fingerprint. The method takes the semantic entropy vector as a core, breaks through the limitation of static features, remarkably improves the recognition rate of complex attacks, reduces missed judgment, and guarantees the safety of Web applications.
Owner:CHINA LIFE INSURANCE CO LTD

Mutually cooperative door lock complementary acquisition method and system

The invention discloses a mutual cooperative door lock complementary acquisition method and system, and the method comprises the steps: extracting the structural feature data of a target person according to an event that a self door lock recognizes a non-white list person, generating an assistance request containing a target ID and the feature data, and transmitting the assistance request to an adjacent door lock; according to the assistance request received by the adjacent door lock, target feature matching is carried out, and after matching succeeds, a target video stream is collected and selectively coded; according to the time points when the target appears and disappears, generating an association starting pointer and an association ending pointer, and synchronously storing the pointers between the door locks; and analyzing the association pointer according to the playback request, and automatically starting stream playing of the association video streams of the plurality of door locks to realize multi-view synchronous display. By utilizing the embodiment of the invention, continuous automatic tracking and multi-view synchronous playback of cross-equipment target activities can be realized through active cooperation and data association between door locks, and the continuity and efficiency of security monitoring are improved.
Owner:DESSMANN CHINA MACHINERY & ELECTRONICS

Non-screen POS machine data acquisition method and system based on NFC and WeChat applet, POS machine and storage medium

The invention discloses a non-screen POS machine data acquisition method and system based on NFC and a WeChat applet. A POS machine simulates an NFC Type 4 label through a non-contact chip, performs SM2 signature and encryption on equipment data containing a timestamp and a random number by using a private key instantaneously reconstructed by a PUF, and performs Base64URL-CRC packaging, segmented NDEF writing and 30s TTL setting; the mobile terminal automatically pulls up the WeChat applet after triple verification of radio frequency field stability detection, URL white list and integrity fingerprint; the small program uploads parameters through an AES-128-GCM secondary encryption and a Reed-Solomon fragment tunnel; the background adopts a Redis idempotent lock, an HSM private key decryption, an SGX enclave one-time token display mechanism and other mechanisms to complete signature verification and decryption, and it is ensured that the device data are only briefly visible in the WeChat security sandbox. According to the invention, the problems of difficult operation and maintenance data acquisition, high cost and poor security of the non-screen POS machine are solved, and cross-platform, anti-replay and man-in-the-middle-resistant high-security data acquisition can be completed within 10 seconds.
Owner:AITIWEIER ELECTRONICS TECH BEIJING

Transformer area edge safety linkage method based on electricity utilization information acquisition terminal

The invention discloses a zone area edge security linkage method based on an electricity utilization information acquisition terminal, and relates to the technical field of power distribution terminal security, and the method comprises the steps: only reading an object, an action and a time window to generate an intention fingerprint, building an edge security access partition, and allowing a certificate and a one-time token to enter and carrying out retention audit; generating an exclusive session window, and implementing selective communication between virtual segments and a switch array, carrier communication session key rolling (secret exchange), four and eight exclusive sessions and white list current limiting; a shadow integrity label and a sequence commitment are calculated in the end, abnormity is judged in combination with physical fingerprints, grading processing is carried out according to the minimum influence range, and bypass mirror images and equivalent migration mapping are recorded; performing dual authorization and time limit and range checking on the related control, solidifying an evidence chain, and completing rotation and upgrading of a key certificate; on the premise of not changing the meter, the reading and control reliability, traceability and compliance verifiability are improved, the port layer contention is reduced, and the influence radius is reduced.
Owner:LIYANG HUAPENG ELECTRIC POWER METER

Unmanned aerial vehicle parameter consistency configuration method based on template management

The invention relates to the technical field of unmanned aerial vehicle control and management, in particular to an unmanned aerial vehicle parameter consistency configuration method based on template management, which adopts a structured parameter configuration template in a JSON format, comprises four blocks of metadata, parameter definition, constraint rules and digital signatures, establishes an MAVLink communication link with an unmanned aerial vehicle flight controller through a template management terminal, and provides an unmanned aerial vehicle parameter consistency configuration method. And executing an automatic configuration process based on a finite-state machine, and ensuring parameter logic consistency by using a difference comparison and constraint verification mechanism. According to the method, temporary storage, batch writing and atomic submission of parameter changes are achieved through the atomization transaction submission protocol, the integrity of the configuration process is guaranteed, the digital signature auditing log containing the timestamp, the device identifier, the template hash and the change details is generated after configuration is completed, whole-process tracing is supported, and the method is high in practicability and easy to popularize. Headless mode operation, parameter white list control and hardware abstraction layer adaptation are supported, and high automation, standardization and safety of unmanned aerial vehicle parameter configuration can be achieved.
Owner:JIANGXI LIANCHUANG (WANNIAN) ELECTRONICS CO LTD

Robot, operation method thereof, operation device, storage medium, and program product

The embodiment of the invention provides a robot and an operation method and device thereof, a storage medium and a program product. The method comprises the steps that natural language instruction information and multiple robot sensing data are received; performing spatial feature extraction processing based on at least part of the robot sensing data to obtain spatial feature information of the corresponding robot sensing data; performing time sequence feature fusion based on the spatial feature information of the perception data of the at least two robots to generate space-time semantic implicit representation information; performing cross-modal interaction based on the natural language instruction information and the space-time semantic implicit representation information to generate space target representation information; and path planning and / or action control are / is carried out based on the spatial target representation information, so that the robot is controlled to execute operation corresponding to the natural language instruction information. Therefore, high information integrity can be kept under the condition of low computing power, serious information loss caused by white list detection is reduced, and the universality of robot operation control is remarkably improved.
Owner:AGIBOT INNOVATION (SHANGHAI) TECHNOLOGY CO LTD

Campus intelligent alarm linkage method and system based on face recognition

The invention discloses a campus intelligent alarm linkage method and system based on face recognition, and the method comprises the steps: collecting a video stream in real time, and extracting a face image in a video frame through a face detection algorithm; comparing the face image with a white list database pre-stored in a campus in real time, and generating an identity recognition result and a confidence score of the face; calculating the threat level of the current behavior scene through a dynamic early warning judgment model and generating a graded early warning signal based on the identity recognition result and the confidence score in combination with the real-time analysis of the personnel behavior scene; automatically triggering a corresponding equipment linkage instruction according to the graded early warning signal; and on the basis of the execution state of the equipment linkage instruction and a subsequent video analysis result, generating a complete security event disposal report containing an incident position, an incident-related personnel image and a disposal suggestion. According to the embodiment of the invention, the active early warning capability and the emergency response efficiency of the campus security system can be improved.
Owner:ZHEJIANG TONGJI VOCATIONAL COLLEGE OF SCI & TECH +1

Vehicle-mounted system safety detection and risk assessment system

The invention discloses a vehicle-mounted system safety detection and risk assessment system, which belongs to the technical field of vehicle-mounted network safety, and comprises a vehicle-mounted terminal environment sensing module used for collecting multi-level environment information of a vehicle-mounted system, including system layer information, network layer information and safety layer information; the vehicle-mounted configuration file and communication white list detection module is connected to the vehicle-mounted terminal environment sensing module and is used for establishing and maintaining a safety white list library according to the collected system information, comparing the current configuration file, the dynamic library, the port and the certificate state of the system with the safety white list library through periodic scanning, and sending the comparison result to the vehicle-mounted terminal environment sensing module; detecting configuration abnormity and file tampering events; a vehicle-mounted process and control task analysis module; a communication abnormity detection and code identification module; and a safety evaluation and risk feedback module. According to the invention, all-around monitoring and intelligent analysis of vehicle-mounted system configuration, process behaviors and network communication can be realized, and hidden backdoors, abnormal processes and malicious communication can be effectively identified.
Owner:HUBEI UNIV

Telecommunication network fraud case multi-dimensional graph series-parallel and visualization method based on graph database

The invention discloses a multi-dimensional graph series-parallel and visualization method for telecommunication network fraud cases based on a graph database. According to the method, intelligent series-parallel analysis across time-space cases is realized by constructing a knowledge graph containing various entities such as cases, personnel, accounts and equipment and deeply fusing a hard association matching algorithm and a soft similarity graph algorithm. The system has the functions of white list filtering, time sequence behavior analysis, NLP information extraction and the like, and can effectively identify criminal gangs, track fund flow directions and mine crime modes. And finally, dynamic visual display is carried out through a plurality of interactive views such as a force-oriented graph, a time axis and a mulberry-based graph, and clue intelligent pushing and report automatic generation are supported. According to the method, the case association mining depth, the serial-parallel analysis efficiency and the interpretability of a complex network are remarkably improved, and an efficient technical support is provided for the public security organization to fight against telecommunication network fraud.
Owner:ZHUHAI XINDEHUI INFORMATION TECH

Dynamic expansion service node management method based on Camuda process engine

The invention discloses a method for managing service nodes capable of being dynamically expanded based on a Camuda process engine, which belongs to the technical field of electric digital data processing and comprises the following steps of: uniformly configuring service process nodes into a pointing proxy delegation class; querying an external mapping table based on the execution context to obtain a business logic unit identifier; obtaining metadata from a logic registration center according to the identifier, and dynamically loading and instantiating a business logic implementation class through a sandbox class loader; driving service logic execution through a security context object of a white list only exposure method; and recording a full-link audit log. According to the method, structural decoupling of process definition and service logic is realized, so that the process definition does not need to be modified during service change, and dynamic replacement and gray release are supported; through sandbox isolation and security agent, isolated operation of dynamic codes and security and stability of an engine are ensured; and in combination with an audit tracking and fusing mechanism, the observability, the reliability and the operation and maintenance efficiency of the system are improved.
Owner:SUZHOU REKTEC INFORMATION TECH CO LTD

Shared economic credit evaluation and evidence storage method based on block chain

The invention particularly relates to a shared economic credit evaluation and evidence storage method based on a block chain. According to the shared economic credit evaluation and evidence storage method based on the block chain, during first registration and login, initialization processing is performed on a user identity, service behavior data is acquired in real time, preprocessing is performed, feature engineering processing is performed, and credit factors are extracted and normalized; constructing a multi-dimensional credit model, and realizing dynamic credit score and threshold adaptive calibration; generating a multi-dimensional abstract, and storing an evidence on a chain; the target sharing economy platform obtains the credit voucher of the user in a cross-platform manner and performs verification and synchronization; multiple security and compliance strategies are provided, and privacy protection, compliance supervision and black and white list feedback closed-loop management are realized. According to the shared economy credit assessment and evidence storage method based on the block chain, credit credibility and traceability are improved, migration and verification of user credit among multiple shared economy platforms are realized, user privacy and compliance are guaranteed, and multi-platform joint management and risk early warning are realized.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Control method and apparatus for radio frequency broadcast signals, and tire pressure monitoring system

PCT designated stageWO2025261198A1Tyre measurementsControl engineeringWhitelist
A control method for radio frequency broadcast signals. The method comprises: acquiring tire pressure information and the wheel speed of a vehicle (1) (S100); on the basis of the tire pressure information and the wheel speed, determining the operational status of tire pressure measurement devices (11, 12, 13, 14) (S200); and on the basis of the operational status of the tire pressure measurement devices (11, 12, 13, 14), enabling or disabling the transmission of radio frequency broadcast signals. In the method, a radio frequency broadcast function is intelligently enabled or disabled on the basis of the operational status of tire pressure measurement devices (11, 12, 13, 14), thereby ensuring the reliability, efficiency and safety of a system and also reducing the unnecessary energy consumption of the devices in each operating stage, and thus prolonging the service life of the devices; and a whitelist mechanism is combined with an identity authentication process within a limited time period to provide a safer and more efficient authentication method for the tire pressure measurement devices (11, 12, 13, 14), thereby preventing access by unauthorized devices, and also enhancing the user convenience for authenticated devices by means of a simplified reconnection process. Further disclosed are a control apparatus for radio frequency broadcast signals, and a tire pressure monitoring system.
Owner:BAOLONG HUF SHANGHAI ELECTRONICS CO LTD

Vehicle log pushing method, electronic equipment and storage medium

The invention provides a vehicle log pushing method, electronic equipment and a storage medium, the method is applied to the field of vehicle electronics, and the method comprises the following steps: collecting a fault log of a vehicle; judging whether the fault log meets a preset pushing condition or not; and if the fault log meets the preset pushing condition, performing marking processing on the fault log to obtain a to-be-pushed fault log, and sending the to-be-pushed fault log to a preset mobile terminal. According to the method, a fault log is collected in real time at an OTA server side, repeated alarm suppression within one minute can be realized based on error-reported source code information, meaningless noise of the fault log is filtered by neglecting a keyword white list, and a high-quality mark is triggered for a key service white list in the fault log; and finally, the graded alarm is pushed to a mobile terminal of operation and maintenance personnel through a push interface adaptive to a multi-platform protocol, so that the accuracy, the timeliness and the operability of fault log alarm are remarkably improved on the premise of ensuring that continuous faults are not missed to be reported.
Owner:GREAT WALL MOTOR CO LTD

Cross-system data interaction security collaboration method, system and device of electric power management and control platform, and medium

The invention discloses a cross-system data interaction security collaboration method, system, equipment and medium for a power management and control platform, and belongs to the technical field of power management and control, and the method comprises the steps: uniformly managing cross-system security policies through a security policy collaboration center, generating a global policy template, and eliminating policy conflicts through a conflict arbitration mechanism; dynamically adjusting the token validity period and the multi-factor authentication strength based on the risk level by combining a security authentication gateway; the data interaction bus integrates a multi-protocol adapter and an LZ77 compression algorithm to improve transmission efficiency, guarantees cross-system transaction atomicity through a three-stage protocol and a fusing mechanism of a transaction coordinator, and supports ten thousand-level concurrent interaction; and the risk perception module fuses the interaction frequency, the data sensitivity and the historical event quantitative risk level, links the dynamic strategy execution engine to trigger the authority falling, desensitization or current limiting measures, realizes the binding control of authority and transaction duration by adopting white list life cycle management, and effectively intercepts more than 8500,000 times of sensitive data leakage risk.
Owner:GUIZHOU POWER GRID CO LTD

Industrial control-oriented localized trusted dual-system protection method and system

The invention relates to a domestic trusted dual-system protection method and system oriented to industrial control, and belongs to the technical field of industrial control security, and constructs a dual-system architecture based on hardware isolation: a domestic operation subsystem executes service logic, and a protection subsystem realizes independent security control through a TCM / TPCM trusted root. And the protection subsystem has a one-way access permission to form a hardware-level protection barrier. When the system is started, UBoot, a kernel and an application program are measured step by step through a TPCM chip, and a trusted chain is constructed; during operation, the active monitoring module calculates a process hash value in real time, compares the process hash value with the reference library, and executes security policies such as process termination / network blocking. The executable file, the network port and the source IP access control are covered by adopting a white list technology of encrypted signature. The full-period active protection of the terminal from starting to running is realized, the defect that a traditional scheme depends on kernel safety is overcome, the safety and reliability of a system are remarkably improved, and the requirement of an industrial control system for protection 2.0 is met.
Owner:FUJIAN NETPOWER TECH DEV CO LTD

Management method and device after change of vehicle-mounted terminal network equipment

The invention relates to the technical field of vehicles, and provides a vehicle-mounted terminal network equipment post-replacement management method and device, and the method comprises the steps: carrying out the network access verification of old piece equipment based on a preset first white list and a logic network address carried in a request under the condition that a network connection request of the old piece equipment is received, the first white list stores logic network addresses of offline old pieces; and under the condition that the network verification result indicates that the old piece equipment is allowed to access the in-vehicle domain network, vehicle binding relationship verification is performed on the old piece equipment based on a preset second white list, the equipment identification code of the old piece equipment and the change condition of the vehicle identification code bound with the old piece equipment, and the equipment identification code of the offline old piece is stored in the second white list. According to the method and the device provided by the invention, a traditional mode which completely depends on manual recording, judgment and operation is replaced, so that human errors are reduced, and accurate and automatic management of the life cycle state of the equipment is realized.
Owner:WUHAN JIANGXIA CHUNENG AUTOMOBILE TECHNOLOGY R&D CO LTD

Domestic environment-oriented power application performance anomaly detection method and system

The invention relates to a domestic environment-oriented power application performance anomaly detection method and system, and the method comprises the following steps: S1, obtaining a domestic basic environment, power real-time data, an application system performance index and a business operation log, and carrying out the preprocessing, and obtaining a multi-dimensional time series data matrix; s2, performing feature engineering and feature optimization based on the multi-dimensional time sequence data matrix to obtain an optimized feature matrix; s3, constructing a multi-level AI anomaly detection model based on the optimized feature matrix in combination with historically labeled anomaly samples; s4, according to the multi-level AI anomaly detection model and the preprocessed real-time data, obtaining an anomaly detection result; and S5, according to an anomaly detection result, obtaining an alarm strategy and a disposal white list, and converting the anomaly detection result into operable alarm and disposal. According to the method, the operation and maintenance pressure and the response risk are powerfully reduced, and the whole-process intelligent and refined management from anomaly detection to alarm disposal is realized.
Owner:STATE GRID INFORMATION & TELECOMM GRP CO LTD +1

LLM-oriented Text-to-SQL intention query method and system

The invention discloses an LLM-oriented Text-to-SQL (Structured Query Language) intention query method and system, and the method comprises the steps: after receiving a natural language query, driving a large language model to carry out intention analysis and task decomposition on the natural language query through a prompt template with a built-in security constraint rule, and outputting an atomic task with a security label; for each atomic task, combining the task description with the obtained database mode information to form a prompt, and driving a large language model to generate a candidate SQL (Structured Query Language); sequentially executing multi-layer verification of mode consistency verification, operation white list verification and semantic security verification on the generated candidate SQL; and then executing the SQL marked as safe and executable to obtain an actual query result, capturing an intermediate reasoning result of the large language model in the generation process, and optimizing the large language model according to a comparison result of the real data and the intermediate reasoning result. According to the method, the practicability, the reliability and the auditing performance of database intelligent query are remarkably improved.
Owner:WUHAN UNIV

Equipment black and white list management method and device, storage medium and electronic equipment

The invention relates to an equipment black and white list management method and device, a storage medium and electronic equipment. The method comprises the following steps: receiving feedback information input by a user, and identifying a feedback identifier, an equipment problem type and a user appeal in the feedback information; obtaining business data of the target equipment from a business background according to the feedback identifier, and inputting the feedback information and the business data into a target large model, so that the target large model executes semantic understanding and rule reasoning according to the feedback information and the business data in combination with a business knowledge base, and generates a black and white list change suggestion; processing the original blacklist and whitelist of the target device based on the blacklist and whitelist change suggestion, and generating a new blacklist and whitelist meeting user demands; and uploading the new black and white list to a cloud storage platform, and feeding back a processing result of the downloading link containing the new black and white list to the user. The technical problems that equipment capability identification depends on manual editing of black and white lists, the process is tedious and inefficient, and errors are prone to occurring are solved.
Owner:BEIJING QIYI CENTURY SCI & TECH CO LTD

Transaction traceability method based on fluff-stage transaction broadcast mechanism

PendingCN121660788AFinanceGrey listEngineering
The invention discloses a transaction tracing method based on a fluff-stage transaction broadcast mechanism, and the method comprises the steps: triggering the connection reset of a target node after filling a gray list node list and a white list node list of the target node, and achieving the outgoing connection occupation of the target node; judging the current stage of the target node through two controllable nodes which establish incoming connection with the target node; and when the target node is in a fluff stage, if a controlled node in the occupied outgoing connection nodes receives a transaction of a step stage sent by the target node, judging that the transaction is an originating transaction of the target node. According to the invention, the identification precision of the originating transaction can be improved, and the complexity and resource consumption of the identification method can be reduced.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Remote operation and maintenance method and system for secondary equipment of intelligent substation

The invention discloses an intelligent substation secondary equipment remote operation and maintenance method and system, and relates to the technical field of power system automation. According to the method, an integrated remote operation and maintenance system is constructed by deploying an intelligent remote operation platform at a master station end and deploying a secondary equipment intelligent terminal at a station end. The system automatically configures communication based on an SCD file, and acquires operation data of secondary equipment of the whole station; and the master station subscribes data as required, so that hierarchical and scenarized panoramic monitoring is realized. Three independent channels of operation and maintenance management, remote operation and maintenance and data acquisition are set, and white list, work order approval and SM2 / SM4 encryption authentication strategies are adopted, so that four types of remote operation of pressing plate operation, fixed value operation, device resetting and equipment emergency operation are safely realized. According to the method, the problems of low efficiency and high safety risk of a traditional on-site operation and maintenance mode are solved, the operation and maintenance quality is improved, and digital transformation of operation and maintenance of the secondary equipment of the transformer substation is promoted.
Owner:ELECTRIC POWER SCI RES INST OF STATE GRID XINJIANG ELECTRIC POWER CO LTD

Directed traffic flow free-flow method, device, terminal, server and storage medium

The application provides a method, device, terminal, server and storage medium for targeted traffic flow exemption. The method comprises the following steps: monitoring whether an application program triggers a traffic data access request by using a software development kit (SDK) embedded in the application program; if yes, generating a targeted traffic data access request when a source address corresponding to the traffic data access request is determined as a targeted traffic whitelist address by using the SDK, and sending the targeted traffic data access request to a proxy server corresponding to the SDK, so that the proxy server sends the targeted traffic data access request to a first server corresponding to the source address when the targeted traffic data access request meets a preset traffic flow exemption access condition. The method of the application determines whether to allow traffic flow exemption through the embedded SDK and re-authenticates through the proxy server, and does not need to configure the IP address of the application program of the targeted traffic flow through the GGSN, so that the demand for a large amount of targeted traffic flow can be met, and a relatively complex configuration process is avoided.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +1

Camera parameter reporting method, readable storage medium, program product and electronic equipment

The invention relates to the technical field of terminals, in particular to a camera parameter reporting method, a readable storage medium, a program product and electronic equipment. The camera parameter reporting method is applied to the electronic equipment, and the electronic equipment can screen the resolution parameters reported by the cameras based on a pre-stored white list of the resolution parameters after acquiring the resolution parameters reported by the cameras so as to clear redundant resolution parameters. When the compatibility test is carried out on the camera of the electronic equipment, the test quantity of the resolution parameter can be reduced, so that the test time is reduced, and the test failure caused by overtime compatibility test of the electronic equipment is avoided.
Owner:HONOR DEVICE CO LTD

Interpreted script pre-execution verification method and device, medium and program product

The invention provides an interpreted script pre-execution verification method and device, a medium and a program product. The method comprises the steps that an interpreted script to be verified is obtained and analyzed to generate an abstract syntax tree; before traversal type interpretation execution is carried out on the abstract syntax tree, script access objects are recognized based on the abstract syntax tree to form a to-be-verified access object set, the to-be-verified access object set is compared with a preset access object white list, and abnormal access objects are determined; configuring a verification executor as an interpretation execution main body of the abstract syntax tree, pointing an execution process of the abstract syntax tree to the verification executor, and further performing traversal type interpretation execution on the abstract syntax tree; in the traversal type interpretation execution process, a coverage type execution rule is adopted for grammar nodes in the abstract grammar tree, so that a plurality of execution paths are executed, verification execution on the other grammar nodes and the execution paths is not interrupted when abnormity occurs, and a pre-execution verification result of the script is generated. The automation degree and efficiency of the verification execution process are improved.
Owner:SHANGHAI SHANGHU INFORMATION TECH CO LTD

Communication system, anomaly detection apparatus, anomaly detection method, and program

A communication system that performs communication among a plurality of nodes by a broker-less type publishing / subscribing model, includes: a computer including a memory and a processor configured to, in a case where a network configuration of the communication system changes, detect an anomaly of the communication system based on configuration information indicating the network configuration and at least one of a predefined white list or black list.
Owner:NT T INC

Url limiting method based on operation and maintenance auditing system application release

The invention discloses a url limiting method based on operation and maintenance auditing system application release, and relates to the technical field of operation and maintenance auditing systems.Before a session starts or during the session, a policy token subjected to trusted service digital signature is obtained from a trusted policy release service and loaded at an agent end; the policy token comprises a policy identifier, a version number, an effective starting and ending time, an allowable domain path template, a parameter blacklist, a rate limit and policy hash, and the agent verifies a signature and an effective period before the policy is loaded. Through short-time authorization of the policy signature, the agent only accepts the signed policy within the validity period locally, the policy is prevented from being tampered or forged halfway by the local or network, the defects of a static white list in long-term validity and trust proof are overcome, a temporary authorization scene is supported, the policy trust degree and security are improved, and the security of the policy is improved. And the risk of unauthorized access caused by strategy tampering is reduced, fine session-level authorization management is supported, and compliance proof and afterward traceability are facilitated.
Owner:BEIJING LONGERSEC TECH CO LTD +1

Bayesian network-based threat intelligence automated inference monitoring method

The application discloses a threat intelligence automatic reasoning monitoring method based on a Bayesian network and relates to the field of network security.The method solves the problems of the existing network security protection technology, such as untimely attack detection, high false alarm rate and lack of dynamic adaptive capacity.The method comprises the following steps: collecting network flow data, pre-processing the network flow data and extracting feature information; constructing and compiling a neural network model, training the neural network model, generating a classification model for identifying malicious flow and a corresponding label encoder; inputting real-time network flow into the trained classification model for automatic classification, obtaining the determination results of normal flow and abnormal flow, and writing the determination results into a whitelist file and a blacklist file respectively; dynamically triggering a firewall strategy in combination with the results of the whitelist file and the blacklist file, and automatically blocking malicious IP addresses; constructing a Bayesian network model file; and realizing automatic reasoning of an attack chain and security situation monitoring.
Owner:CHANGCHUN UNIV OF SCI & TECH

A data processing method and device, electronic equipment and storage medium

The application relates to the technical field of data processing, and provides a data processing method and device, electronic equipment and a storage medium. The method receives routing data, analyzes the outer message header of the routing data, obtains a logical service number corresponding to the routing data, determines whether the logical service number is a registered logical service number, determines a processing mode corresponding to the routing data based on the logical service number in the case that the logical service number is the registered logical service number, processes the routing data based on the processing mode, analyzes the outer message header of the inbound routing data to obtain the logical service number, and judges whether the logical service number is the registered logical service number as a whitelist access control. In the case that the logical service number is the registered logical service number, the processing mode is determined based on the logical service number and executed. Thus, a unified link of "recognition, judgment and processing" is formed, and accurate and predictable data processing of the routing data is realized.
Owner:ZHONGKE TIMES (SHENZHEN) COMPUTER SYST CO LTD

Railway signal system based on trusted computing security computing protection technology

The application discloses a kind of railway signal system security computing protection technology and system based on trusted computing.The application takes hardware trusted module as trust root, constructs the end-to-end trusted verification chain covering operation and maintenance terminal, communication link and destination device;Through the trusted management platform of center, the trust measurement and white list management of operation and maintenance tool are realized;Deeply integrate railway "window time" and standard operation process, construct device dynamic trusted benchmark model, and generate operation and maintenance personnel behavior trusted model based on historical behavior data;Deploy lightweight trusted agent to monitor operation and maintenance behavior in real time, and implement hierarchical response and authority control to behaviors deviating from the two models.The application realizes dynamic trusted protection in the whole operation and maintenance process, effectively improves the active defense capability against internal and external threats, balances safety strength and operation and maintenance efficiency, and provides business-aware security protection for railway signal system and key infrastructure.
Owner:CHINA STATE RAILWAY GRP CO LTD +1

System and method for network function (NF) whitelisting in communication network

The present disclosure provides a system (108) for network function (NF) whitelisting in a communication network (106). The present disclosure supports authentication based on client credentials assertion (CCA). The system includes one or more processors (202) and a memory (204) which stores instructions for supporting authentication based on whitelisting conditions / list with the ability to enable or disable the feature. The present disclosure supports authorization for own services (management and discovery) based on open authorization token. Additionally, the system (108) provides support for counters and logs for authentication and authorization.
Owner:JIO PLATFORMS LTD