Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

19 results about "Zero-day attack" patented technology

A zero-day (also known as 0-day) vulnerability is a computer-software vulnerability that is unknown to, or unaddressed by, those who should be interested in mitigating the vulnerability (including the vendor of the target software). Until the vulnerability is mitigated, hackers can exploit it to adversely affect computer programs, data, additional computers or a network. An exploit directed at a zero-day is called a zero-day exploit, or zero-day attack.

Construction method and device of network security knowledge graph, equipment and storage medium

The invention relates to a construction method and device of a network security knowledge graph, equipment and a storage medium, and the method comprises the steps: obtaining multi-source data of a network security application scene, and carrying out distributed processing to obtain a security data set; performing structured storage management and security knowledge extraction on the security data set to obtain an initial knowledge graph; performing zero-day attack prediction construction based on the initial knowledge graph to obtain potential attack data; performing path fusion association on the potential attack data and the initial knowledge graph to obtain attack chain fusion information; and obtaining real-time event data of the network security application scene, and carrying out dynamic iteration updating on the initial knowledge graph by using the real-time event data and the attack chain fusion information to obtain the network security knowledge graph. According to the invention, the timeliness and practicability of the network security knowledge graph can be ensured.
Owner:SHENZHEN TRUSTED CLOUD TECH CO LTD

Firewall dynamic policy adaptation method and system based on big data

The invention discloses a firewall dynamic policy adaptation method and system based on big data, and the method comprises the steps: collecting multi-source heterogeneous data in a network, and constructing a dynamic network entity map in real time; processing the time sequence of the atlas by using a preset time sequence diagram attention network model to obtain a behavior fingerprint vector representing the behavior state of the entity, and calculating the risk score of the entity; when the risk score exceeds a risk threshold value, automatically generating a temporary security policy for managing and controlling the access behavior of the entity; and managing the life cycle of the temporary security policy, and automatically updating, renewing or cancelling according to the entity risk state change. According to the method, the network entity behavior baseline is constructed and the risk prediction is carried out, so that the conversion from passive defense to active defense is realized, the security policy can be automatically and accurately generated and managed, advanced persistent threats and zero-day attacks can be effectively coped with, and the self-adaptability and the intelligent level of network defense are improved.
Owner:HANGZHOU TAICHENG NETWORK TECH CO LTD

Semantic-driven encrypted ransomware detection method and system for unknown sample

The invention discloses an unknown sample-oriented semantic-driven encrypted ransomware detection method and system, and relates to the field of computer security. The method comprises the steps that original log data streams are collected, noise is removed through self-adaptive sampling and triple filtering, and effective candidate events are converted into a semantic structured event set containing standardized natural language description through a retrieval enhancement generation mechanism; performing multi-stage time sequence sorting on the semantic structured events, identifying high-density behavior stages, clustering to generate event clusters, generating macroscopic and microscopic language paragraphs based on event cluster information, and classifying and segmenting event operation information to obtain an inter-segment time alignment relationship; and based on the paragraph and the alignment relationship, carrying out maliciousness test on the behavior chain by adopting four gating verification mechanisms, carrying out quantitative evaluation through a weighted confidence model, and outputting a detection result. According to the method, semantic comprehension and multi-dimensional behavior analysis are deeply fused, and the detection precision, interpretability and system generalization ability of unknown ransomware variants and zero-day attacks are effectively improved.
Owner:XIDIAN UNIV

A method for continuous automated vulnerability mining based on log data

The application discloses a kind of based on log data's continuous automation vulnerability mining method, belong to network and information security technical field.The application can penetrate application surface layer, accurately identify dynamic generation interface, hidden application program interface and deep vulnerability parameter that traditional technology cannot touch, to significantly improve attack entry point coverage in real traffic, realize panoramic coverage of attack surface by quantitative information flow analysis and topology discovery based on data tracing.The application can capture, understand and verify new attack mode including zero-day attack from real traffic in near real time based on static semantics-dynamic time sequence double-layer learning model and closed-loop feedback mechanism, shorten threat response time from several days to several hours, build adaptive threat immunity ability;Through the risk intelligent scheduling mechanism driven by multi-objective genetic algorithm, test resources are preferentially allocated to business critical and highest risk attack entry, to significantly optimize computing resource allocation.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Computer virus intelligent defense method and system based on data mining

PendingCN121000487ASecuring communicationVariant virusBehavioral data
The invention discloses a computer virus intelligent defense method and system based on data mining, and belongs to the technical field of network security, and the defense method comprises the following specific steps: I, collecting various behavior data in a computer system, extracting corresponding behavior characteristics, carrying out entropy modeling according to each behavior characteristic, and analyzing entropy fluctuation in real time; iI, constructing a heterogeneous threat relation graph according to an analysis result, and reasoning a threat propagation path based on the heterogeneous threat relation graph; according to the method, the whole-process defense capability can be improved, normal behaviors and potential threats can be effectively distinguished, false alarm and missing alarm are reduced, the capability of coping with unknown viruses, variant viruses and zero-day attacks is greatly improved, the viruses are prevented from reversely bypassing defense, a complex threat propagation chain can be accurately recognized, the active trapping and behavior reduction capability is improved, and the method is suitable for popularization and application. The attack chain tracking and threat tracing capability is improved, and the system robustness is improved.
Owner:LAIWU VOCATIONAL & TECHNICAL COLLEGE

Network security protection method based on big data

The invention relates to the technical field of network security, in particular to a network security protection method based on big data, which comprises the following steps of: acquiring and preprocessing traffic at a boundary gateway, extracting dominant features and recessive features, constructing a session feature vector, and performing detection and interception judgment by using a pre-constructed gene pool. And meanwhile, based on a clustering algorithm, performing periodic clustering analysis on session feature vectors, evaluating interception rationality and dynamically adjusting related parameters. According to the network security protection method based on the big data, the advantages of the big data are flexibly utilized, so that the limitation that traditional network security protection depends on static feature matching and fixed threshold judgment is overcome, zero-day attacks and novel variant threats can be effectively detected, the false report and missing report rate is reduced, and the network security protection efficiency is improved. According to the invention, automatic optimization and accurate interception of the detection rule are realized, the adaptive capability and real-time detection efficiency of network security protection are improved, and a more intelligent, dynamic and accurate protection mechanism is provided for network information security.
Owner:SHENZHEN DONGFANG XIANDE TECHNOLOGY CO LTD

Incorporating software maturity in attack graphs for zero-day mitigation

In one implementation, a device obtains metrics regarding software executed in a computer network. The device determines, based on the metrics, a probability of the software representing a potential vulnerability. The device generates an attack graph that represents the potential vulnerability along a particular attack path. The device provides the attack graph for analysis.
Owner:CISCO TECHNOLOGY INC

Behavior based identification of malicious workloads in a runtime environment

Software bill of materials (SBOM) vulnerability systems do not monitor software components behavior in real time, and rather rely on the static periodic updates. This gap leaves cloud-native software applications exposed to 0-day or supply chain attacks that exploit vulnerabilities that are not known or updated into the public vulnerability data sources. The techniques described herein provide dynamic and intelligent identification of 0-day and supply chain attacks in runtime environments, mitigate the attacks in real-time, and share intelligence to prevent a malicious workload from being deployed through the CI / CD pipeline.
Owner:CISCO TECHNOLOGY INC

CAN bus attack intrusion detection method based on self-attention mechanism

The invention provides a CAN bus attack intrusion detection method based on a self-attention mechanism, and belongs to the technical field of communication security. Comprising the following steps: S1, CAN bus broadcast message acquisition; s2, data preprocessing and windowing; s3, building a model; and S4, model training, including supervised learning model training and unsupervised classifier model training. According to the method, high-dimensional features in CAN bus data are captured by utilizing an attention mechanism, normal data and attack data are accurately classified on the basis, and meanwhile, the degree of the attack data deviating from a normal mode can be captured by utilizing an auto-encoder architecture and only adopting the normal data for training, so that zero-day attack detection is realized.
Owner:SHENZHEN AUTOMOTIVE RES INST BEIJING INST OF TECH (SHENZHEN RES INST OF NAT ENG LAB FOR ELECTRIC VEHICLES) +1

Continuous automatic vulnerability mining method based on log data

The invention discloses a continuous automatic vulnerability mining method based on log data, and belongs to the technical field of network and information security. According to the method, through quantitative information flow analysis and topology discovery based on data tracing, an application surface layer can be penetrated, and a dynamic generation interface, an application program interface and a deep vulnerability parameter which cannot be touched by a traditional technology can be accurately identified, so that the attack entry point coverage rate in real flow is remarkably improved, and panoramic coverage of an attack surface is realized; on the basis of a static semantic-dynamic time sequence double-layer learning model and a closed-loop feedback mechanism, novel attack modes including zero-day attack can be captured, understood and verified from real traffic nearly in real time, the threat response time is shortened from several days to several hours, and the adaptive threat immunity is constructed; through a risk intelligent scheduling mechanism driven by a multi-target genetic algorithm, test resources are preferentially allocated to an attack entry with key service and highest risk so as to significantly optimize computing resource configuration.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Website operation method and device for containing zero-day attack, computer device and storage medium

The application relates to a website operation method and device for containing zero-day attacks, computer equipment and a storage medium. The method comprises the following steps: after an operator publishes new website content, synchronizing website data of an internal version to an intermediate version; performing production environment adaptation processing on the website data synchronized to the intermediate version, wherein the production environment adaptation processing comprises one or more of database optimization processing, domain name search replacement processing and security reinforcement processing; synchronizing the website data of the intermediate version which has completed the production environment adaptation processing to a public version which is not currently used by users, and updating a user access portal so that the public version is used by users. The application can contain zero-day attacks (attacks based on zero-day vulnerabilities) against WordPress and minimize losses when security protection measures fail.
Owner:ZHUOZHUO TECH

Network information security protection system

The invention discloses a network information security protection system, which relates to the technical field of network information security, and comprises an encrypted traffic analysis module, a collaborative decision module, a dynamic defense execution module and a security protection terminal. According to the method, traditional network features are mapped to a high-dimensional complex vector space and nanosecond-level micro-timing analysis is carried out, so that the feature expression capability and analysis granularity are greatly expanded, and a fine abnormal mode which cannot be perceived by a traditional method can be captured, thereby effectively coping with unknown threats such as zero-day attack and APT attack, solving the problem of encrypted traffic analysis, and improving the safety of encrypted traffic analysis. According to the invention, the method breaks through the detection blind area of the encrypted traffic, achieves the deep analysis of the encrypted traffic, the collaborative decision of privacy protection and dynamic and active defense execution through the introduction of a quantum information processing technology and a mimic defense architecture, and effectively improves the overall protection capability and response efficiency of network security.
Owner:HENAN UNIVERSITY

Mobile intelligent terminal information security detection method

The invention belongs to the technical field of information security, and particularly relates to a mobile intelligent terminal information security detection method which comprises the following steps: S1, static feature deep analysis, S2, dynamic detection enhancement, S3, multi-dimensional correlation analysis, S4, cross-platform detection standardization and S5, intelligent detection and authentication. Malicious logic in obfuscated codes is effectively identified by analyzing intermediate language codes, extracting key features such as an API calling sequence, an authority application mode and a sensitive data access path and combining a rule engine and a machine learning model, so that the false alarm rate is reduced; an application runs in a sandbox environment with multiple operating system versions and hardware configuration, a detection strategy is dynamically adjusted in combination with reinforcement learning, and zero-day attacks and APT behaviors are captured in real time, so that the real-time performance and accuracy of detection are improved.
Owner:SHENZHEN BENXUN TECHNOLOGY CO LTD

Environment-aware zero-trust dynamic access control policy adaptive adjustment method

PendingCN122339790ANetwork linkAttack
This invention discloses an adaptive adjustment method for zero-trust dynamic access control policies based on environment awareness. By continuously collecting and standardizing multi-dimensional dynamic contextual information from the subject, object, and operating environment, it breaks through the limitation of traditional methods that only focus on subject attributes. This enables trust assessment to comprehensively integrate multiple factors such as resource sensitivity, network link status, and real-time threat intelligence, thereby truly reflecting global dynamic risks and exhibiting high dynamic adaptability to scenarios such as sudden changes in network environment and zero-day attacks. By using dynamic weights and decay memory algorithms to calculate real-time trust values ​​and combining a mapping mechanism based on dynamic asymmetric threshold intervals and fuzzy membership functions, it avoids the trust level jump problem caused by fixed threshold hard boundary division in existing technologies.
Owner:GUANGZHOU BAIHAN INFORMATION TECH CO LTD

User security equipment intelligent linkage method based on Internet of Things

PendingCN122001642AEnhance early warning capabilitiesIncrease catch rateSecuring communicationInstrumentsComputer networkInternet privacy
The invention belongs to the technical field of the Internet of Things, and particularly relates to an intelligent linkage method for user security and protection equipment based on the Internet of Things. The method comprises the following steps: dynamically generating a high-simulation virtual device at a home fog node to trap an attacker; capturing interaction behaviors and generating a standardized log; identifying an attack intention through a pre-trained multi-layer perceptron model; when the confidence exceeds a threshold value, isolating real equipment and broadcasting attack characteristics to the community security network; and cooperative neighbor nodes construct an isolation sandbox, redirect attack traffic and inject false information to consume resources thereof. According to the method, through the technical scheme, active trapping, intelligent identification and group collaborative countering are realized, the early warning and defense capability of the home Internet of Things on zero-day attacks is remarkably improved, and high-value threat intelligence is generated.
Owner:LUOYANG XINAO HUAYOU GAS

Systems and methods for malicious command line and script detection through deployment of generative artificial intelligence

Implementations of the disclosure are directed to configuring a pre-trained large language model (LLM) to be used for zero-day attack detection of log data, scripts, commands, operators, etc. The pre-trained LLM may be configured to generate probabilistic labels for data to be analyzed as being part of a cyberthreat or cyberattack. In some instances, generative artificial intelligence (GenAI) technologies may be utilized by or with the pre-trained LLM to generate the probabilistic labels. The probabilistic labels along with features extracted from the data may be provided a machine learning model, which may also receive behavioral analysis results from a user behavioral analytics system (e.g., baseline-based behavioral models) and generate a detection report. Feedback may be utilized in retraining the pre-trained LLM model. Additionally, GenAI techniques may be utilized to generate a natural language summary of the detection report.
Owner:CISCO TECHNOLOGY INC

Malicious traffic detection model based on GAN data enhancement and multi-head attention mechanism

The invention relates to the technical field of network security and traffic detection, in particular to a malicious traffic detection model based on GAN data enhancement and a multi-head attention mechanism. A GAN generative adversarial network is utilized to perform sample expansion on minority class malicious traffic, an undersampling and sample balance strategy is combined, a multi-head cross attention mechanism is introduced into a model structure, multi-dimensional fusion modeling of time sequence features and statistical features is realized, a covert communication mode in encrypted tunnel class traffic can be accurately identified, and the method is suitable for large-scale popularization and application. And the calculation complexity and the prediction delay are reduced through lightweight design, and the requirements of real-time detection and edge deployment are met. According to the method, a zero-day attack simulation and confrontation sample disturbance test mechanism is introduced in training, so that the generalization ability and the anti-interference characteristic of the model are remarkably enhanced. The method is outstanding in detection efficiency and robustness, and can provide efficient and reliable technical support for malicious traffic detection in a complex dynamic network environment.
Owner:ZHENGZHOU POLICE COLLEGE

Network security dynamic early warning method based on quantum key and signal entropy

The invention relates to the technical field of network security, in particular to a network security dynamic early warning method based on quantum keys and signal entropy, and the method specifically comprises the following steps: collecting user behavior data and network flow data; generating a quantum session key to update the credit adjustment factor in real time, and obtaining an operation behavior abnormal index according to the updated credit adjustment factor; extracting a signal entropy feature of the network traffic, and inputting the signal entropy feature into the LSTM model to obtain an attack probability in a time period T; combining the network protection quality index, the attack probability and the operation behavior anomaly index to obtain a network security coefficient and performing judgment; when the network security coefficient is lower than a security threshold, an alarm mechanism is triggered; therefore, the attack and zero-day attack initiated by the forged high-credit identity information can be better and timely warned.
Owner:JIAXING VOCATIONAL TECHN COLLEGE

Abnormal traffic detection system and method based on ensemble learning and dynamic rule base

The invention relates to an abnormal traffic detection system and method based on ensemble learning and a dynamic rule base, and belongs to the technical field of network security. According to the method, the random forest model formed by a plurality of decision models and the dynamic rule base are fused, so that high-precision detection of the network traffic is realized. Through multi-dimensional feature engineering and SHAP value dynamic screening, three-layer collaborative detection logic of a rule base and a model, an adaptive response strategy based on an attack chain, a zero-day attack pre-detection framework and a closed-loop feedback mechanism continuous optimization detection strategy, 98.7% of detection accuracy is realized on a CICIDS2017 data set, compared with a traditional scheme, the false alarm rate and the missing report rate are remarkably reduced, and the detection accuracy is improved. The method is suitable for enterprise-level network security protection scenes.
Owner:BEIJING INST OF COMP TECH & APPL