Most Download articles

    Published in last 1 year | In last 2 years| In last 3 years| All| Most Downloaded in Recent Month | Most Downloaded in Recent Year|

    In last 2 years
    Please wait a minute...
    For Selected: Toggle Thumbnails
    Journal of Information Security Reserach    2024, 10 (E2): 105-.  
    Abstract801)      PDF (929KB)(407)       Save
    Reference | Related Articles | Metrics
    Research for Zero Trust Security Model
    Journal of Information Security Reserach    2024, 10 (10): 886-.  
    Abstract502)      PDF (2270KB)(339)       Save
    Zero trust is considered a new security paradigm. From the perspective of security models, this paper reveals the deepening and integration of security models in zero trust architecture, with “identity and data” as the main focus. Zero trust establishes a panoramic control object chain with identity at its core, builds defenseindepth mechanisms around object attributes, functions, and lifecycles, and centrally redirects the flow of information between objects. It integrates information channels to achieve layered protection and finegrained, dynamic access control. Finally, from an attacker’s perspective, it sets up proactive defense mechanisms at key nodes in the information flow path. Since zero trust systems are bound to become highvalue assets, this paper also explores the essential issues of inherent security and resilient service capabilities in zerotrust systems. Through the analysis of the security models embedded in zerotrust and its inherent security, this paper aims to provide a clearer technical development path for the architectural design, technological evolution, and selfprotection of zero trust in its application.
    Reference | Related Articles | Metrics
    A Review of Adversarial Attack on Autonomous Driving Perception System
    Journal of Information Security Reserach    2024, 10 (9): 786-.  
    Abstract627)      PDF (1560KB)(324)       Save
    The autonomous driving perception system collects surrounding environmental information through various sensors and processes this data to detect vehicles, pedestrians and obstacles, providing realtime foundational data for subsequent control and decisionmaking functions. Since sensors are directly connected to the external environment and often lack the ability to discern the credibility of inputs, the perception systems are  potential targets for various attacks. Among these, adversarial example attack is a mainstream attack method characterized by high concealment and harm. Attackers manipulate or forge input data of the perception system to deceive the perception algorithms, leading to incorrect output results by the system. Based on the research of existing relevant literature, this paper systematically summarizes the working methods of the autonomous driving perception system, analyzes the adversarial example attack schemes and defense strategies targeting the perception system. In particular, this paper subdivide the adversarial examples for the autonomous driving perception system into signalbased adversarial example attack scheme and objectbased adversarial example attack scheme. Additionally, the paper comprehensively discusses defense strategy of the adversarial example attack for the perception system, and subdivide it into anomaly detection, model defense, and physical defense. Finally, this paper prospects the future research directions of adversarial example attack targeting autonomous driving perception systems.
    Reference | Related Articles | Metrics
    A Trust Framework for Large Language Model Application
    Journal of Information Security Reserach    2024, 10 (12): 1153-.  
    Abstract465)      PDF (1420KB)(275)       Save
    The emergence of large language model has greatly propelled the rapid application of artificial intelligence across various domains. In practice, however, there are a series of security and trust challenges in the applications of large language models caused by “model hallucinations”. These challenges make it difficult for practical applications to trust and adopt the results returned by the large language models, especially in securityrelated application domains. In many professional fields, we find that there lacks a unified technical framework to ensure the trustworthiness of results returned by large language models, which seriously hinders the application of largescale model technology in professional fields. To address this issue, a largescale model trusted application framework DKCF, integrating sufficient data (D), expertise knowledge (K), intellectual collaboration (C), and efficient feedback (F), is proposed. This framework is developed based on our practical applications in professional fields such as finance, healthcare, and security. We believe that DKCF can shed light on secure and reliable applications of large language models, and facilitate the intellectual revolution across various professional domains.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 24-.  
    Abstract391)      PDF (555KB)(273)       Save
    Reference | Related Articles | Metrics
    A Federated Learning Privacy Protection Method for Multikey Homomorphic  Encryption in the Internet of Things
    Journal of Information Security Reserach    2024, 10 (10): 958-.  
    Abstract699)      PDF (1704KB)(254)       Save
    With federated learning, multiple distributed IoT devices can jointly train a global model by updating the transmission model without leaking raw data. However, federated learning systems are susceptible to model inference attacks, resulting in compromised system robustness and data privacy. A federated learning privacy protection method for multikey homomorphic encryption in the Internet of Things is proposed to address the issues of existing federated learning solutions being unable to protect the confidentiality of shared gradients and resisting collusion attacks initiated by clients and servers. This method utilizes multikey homomorphic encryption to achieve gradient update confidentiality protection. Firstly, by using proxy reencryption technology, the ciphertext under different public keys is converted into encrypted data under the public key, ensuring that the cloud server can decrypt the gradient ciphertext. Then, IoT devices use their own public key and random secret factor to encrypt local gradient data, which can resist collusion attacks initiated by malicious devices and servers. Secondly, an identity authentication method based on hybrid cryptography was designed to achieve realtime verification of the identities of participants in federated modeling. In addition, in order to further reduce client computing costs, some decryption calculations are coordinated with trusted servers for computation, and users only need a small amount of computation. A comprehensive analysis was conducted on the proposed solution to evaluate its safety and efficiency. The results indicate that the proposed scheme meets the expected security requirements. Experimental simulation shows that compared to existing schemes, this scheme has lower computational overhead and can achieve faster and more accurate model training.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 32-.  
    Abstract427)      PDF (3674KB)(247)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 27-.  
    Abstract489)      PDF (763KB)(235)       Save
    Reference | Related Articles | Metrics
    Research on Security Risk and Governance Path of Large Models
    Journal of Information Security Reserach    2024, 10 (10): 975-.  
    Abstract309)      PDF (1104KB)(228)       Save
    Reference | Related Articles | Metrics
    Research on Risk Analysis of Opensource Software Supply Chain Security
    Journal of Information Security Reserach    2024, 10 (9): 862-.  
    Abstract393)      PDF (1824KB)(211)       Save
    Opensource software has become one of the most fundamental elements that support the operation of the digital society. It has also been penetrated to various industries and fields. As the opensource software supply chain becomes increasingly complex and diversified, the risks caused by security attacks on the opensource software supply chain are also intensified. This paper summarizes the current development of the opensource software supply chain ecosystem and the strategic layout of opensource software supply chain security in major countries. From the dimensions of development security, usage security, and operation security, this paper proposes an opensource software supply chain security risk analysis system. It identifies the major security risks currently faced by the opensource software supply chain. Besides, this paper constructs a security assurance model for the opensource software supply chain and offers countermeasures and suggestions for the security and development of China’s opensource software supply chain from the dimensions of supply chain phases, relevant entities, and safeguard measures.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 54-.  
    Abstract437)      PDF (1425KB)(193)       Save
    Reference | Related Articles | Metrics
    Research on Deep Learningbased Spatiotemporal Feature Fusion  Network Intrusion Detection Model
    Journal of Information Security Reserach    2025, 11 (2): 122-.  
    Abstract299)      PDF (1944KB)(193)       Save
    As the number of network attacks increases, network intrusion detection systems are becoming increasingly important in maintaining network security. Most studies have used deep learning approaches for network intrusion detection but have not fully utilized the features of traffic from multiple perspectives. Additionally, these studies often suffer from the use of outdated experimental datasets. In this paper, a parallelstructured DSCInceptionBiLSTM network is proposed to evaluate the designed network model using stateoftheart datasets. The model consists of two branches, network traffic image, and text anomaly traffic detection. Spatial and temporal features of traffic are extracted by improved convolutional neural networks and recurrent neural networks, respectively. Finally, network intrusion detection is achieved by fusing spatiotemporal features. The experimental results show that our model achieves 99.96%, 99.19%, and 99.95% accuracy on the three datasets of CICIDS 2017, CSECICIDS 2018 and CICDDoS 2019, respectively, effectively classifying the anomalous traffic with high precision and meeting the requirements of intrusion detection system.
    Reference | Related Articles | Metrics
    Multifamily Malicious Domain Intrusion Detection Based on #br# Collaborative Attention#br#
    Journal of Information Security Reserach    2024, 10 (12): 115-.  
    Abstract354)      PDF (1317KB)(192)       Save
    The timely and accurate detection of illegal domain names can effectively prevent the information loss caused by server crashes or unauthorized intrusions. A multifamily malicious domain name intrusion detection method based on collaborative attention is proposed. Firstly, the deep autoencoder network is used to encode and compress layer by layer, extracting the domain name encoding features at the intermediate layer. Secondly, the longdistance and shortdistance encoding features of the domain name string are extracted from the temporal and spatial dimensions, and the selfattention mechanism is constructed on the temporal and spatial encoding feature maps to enhance the expressiveness of the encoding features in local space. Thirdly, the crossattention mechanism is used to establish information interaction between the temporal and spatial encoding features, enhancing the expressiveness of different dimension encoding features in the global space. Finally, the softmax function is used to predict the probability of the domain name to be tested, and quickly determine the legitimacy of the domain name according to the probability value. The results of testing on multiple families of malicious domain name datasets show that the proposed method can achieve a detection accuracy of 0.9876 in the binary classification task of normal and malicious domain names, and an average recognition accuracy of 0.9568 on 16 family datasets. Compared with other classic methods of the same kind, the proposed method achieves the best detection results on multiple evaluation metrics.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 40-.  
    Abstract397)      PDF (839KB)(182)       Save
    Reference | Related Articles | Metrics
    A Large Language Model Detection System for Domainspecific Jargon
    Ji Xu, Zhang Jianyi, Zhao Zhangchi, Zhou Ziyin, Li Yilong, and Sun Zezheng
    Journal of Information Security Reserach    2024, 10 (9): 795-.  
    Abstract332)      PDF (2610KB)(179)       Save
    Large language model (LLM) retrieve knowledge from their own structures and reasoning processes to generate responses to user queries, thus many researchers begin to evaluate the reasoning capabilities of large language models. However, while these models have demonstrated strong reasoning and comprehension skills in generic language tasks, there remains a need to evaluate their proficiency in addressing specific domainrelated problems, such as those found in telecommunications fraud. In response to this challenge, this paper presents the first evaluation system for assessing the reasoning abilities of DomainSpecific Jargon and proposes the first domain specific jargon dataset. To address issues related to cross matching problem and complex data calculation problem, we propose the collaborative harmony algorithm and the data aware algorithm based on indicator functions. These algorithms provide a multidimensional assessment of the performance of large language models. Our experimental results demonstrate that our system is adaptable in evaluating the accuracy of questionanswering by large language models within specialized domains. Moreover, our findings reveal, for the first time, variations in recognition accuracy based on question style and contextual cues utilized by the models. In conclusion, our system serves as an objective auditing tool to enhance the reliability and security of large language models, particularly when applied to specialized domains.
    Reference | Related Articles | Metrics
    An Adaptive Network Attack Analysis Method Based on Federated Learning
    Journal of Information Security Reserach    2024, 10 (12): 1091-.  
    Abstract285)      PDF (3389KB)(177)       Save
    To analyze network attack behavior issues efficiently and securely, an adaptive network attack analysis method based on federated learning (NAAFL) is proposed. This approach can fully leverage data for network attack analysis while ensuring privacy protection.. Firstly, a costeffective defense mechanism based on DQN (dynamic participant selection mechanism) is proposed to act in the process of federated learning model parameter sharing and model aggregation. It dynamically selects the best participants for each round of model updates, reducing the impact of poorly performing local models on the global model during training. It also reduces communication overhead time and improving the efficiency of federated learning. Secondly, an adaptive feature learning network intrusion detection model is designed, which is able to intelligently learn and analyze according to changing attack features to cope with complex network environments. It effectively reduces the time and space overhead of feature selection. Finally, comparative experiment is performed on a public data set (NSL KDD). The NAAFL method detects attacks with an accuracy of 98.9%. Dynamically selecting participants increases server accuracy by 4.48%. The experimental results show that the method has excellent robustness and efficiency.
    Reference | Related Articles | Metrics
    An Optimized Computation Method for Cipher Symbol Functions  Based on Homomorphic Encryption
    Journal of Information Security Reserach    2025, 11 (2): 100-.  
    Abstract329)      PDF (1092KB)(173)       Save
    Fully homomorphic encryption extends encryption to computations, allowing ciphertext processing without decryption. Comparative operations, crucial in applications like deep learning, pose a challenge in homomorphic encryption environments restricted to addition and multiplication. Feng et al. (CNS 2023) proposed a comparison method using dynamic polynomial combinations. This paper enhances dynamic polynomial, allowing polynomial fluctuations within (-2,2). It introduces a novel equation system for solving dynamic polynomials and utilizes finite third and fifthdegree polynomials to construct more precise composite polynomials for approximating the sign function. It analyzes the method’s optimality in depth consumption and computational complexity, achieving a 32% reduction in runtime compared to the optimal method in a previous study (CNS 2023). The homomorphic comparison algorithm in this paper, for ε=2-20,α=20 requires only 0.69ms in amortized runtime.
    Reference | Related Articles | Metrics
    Research on Risk Analysis and Countermeasures of Software Supply  Chain in Critical Information Infrastructure
    Journal of Information Security Reserach    2024, 10 (9): 833-.  
    Abstract327)      PDF (1295KB)(169)       Save
    System security protection is crucial to critical information infrastructures (CII), and  software supply chain risk analysis is indispensable. In recent years, the number of supply chain attack incidents has increased rapidly. This paper first analysis the potential problems of “external” software components, personnel, tools, etc., which are the main causes of software supply chain threats, and then summarize the current research of domestic and foreign policies and technologies. Based on these findings, a software supply chain security framework for power industry systems is proposed. It covers 15 groups of security measures across 4 aspects, including external component governance, supplier management, development and operation facilities reinforcement, usage mechanism of the software bill of materials (SBOM), all of which can be  further extended. This framework can provide references on software supply chain security protection in power industry information systems.
    Reference | Related Articles | Metrics
    Overview of Regulation of Crossborder Data Flow
    Journal of Information Security Reserach    2025, 11 (2): 164-.  
    Abstract401)      PDF (1274KB)(165)       Save
    The development of the digital economy has made crossborder data flow an inevitable trend, and while bringing economic benefits, the security of crossborder data flow cannot be ignored. Due to the complexity of the subjects and scenes involved in the process of crossborder data flow, and the uncontrollability of the process, how to regulate the possible security problems in the process of crossborder data flow has become the focus of the world. So far, there is no unified governance rule system for crossborder data flow in the world, and at the same time, there are huge differences in legislation on crossborder data flow in different countries, which results in the complex situation of legislation on crossborder data flow in the world. This paper describes the current situation of crossborder data flow from the perspectives of laws and regulations, bilateral agreements and standards, and in this way develops horizontal comparisons, sorts out the existing regulatory differences, analyzes the challenges and opportunities China faces under the current trend, and gives reasonable countermeasures.
    Reference | Related Articles | Metrics
    Research on the Development Trend of Cybersecurity Technology
    Journal of Information Security Reserach    2025, 11 (1): 2-.  
    Abstract320)      PDF (563KB)(162)       Save
    Related Articles | Metrics
    Privacypreserving Federated Learning Research Based on #br# Confused Modulo Projection Homomorphic Encryption#br#
    Journal of Information Security Reserach    2025, 11 (3): 198-.  
    Abstract294)      PDF (1298KB)(160)       Save
    In the current era of big data, deep learning is booming and has become a powerful tool for solving realworld problems. However, traditional centralized deep learning systems are at risk of privacy leakage. To address this problem, federated learning, a distributed machine learning approach, has emerged. Federated learning allows multiple organizations or individuals to train models together without sharing raw data, by uploading local model parameters to the server, aggregating each user’s parameters to construct a global model, and returning it to the user. This approach achieves global optimization and avoids private data leakage. However, even with federated learning, attackers may still be able to reconstruct user data by obtaining the model parameters uploaded by users, thus violating  privacy. To address this issue, privacy protection has become the focus of federated learning research. In this paper, we propose a federated learning scheme FLFC (federated learning with confused modulo projection homomorphic encryption) based on confused modulo projection homomorphic encryption to address the above issues. This scheme adopts a selfdeveloped modular fully homomorphic encryption algorithm to encrypt user model parameters. The modular fully homomorphic encryption algorithm has the advantages of high computational efficiency, support for floatingpoint operations, and localization, thus achieving stronger protection of privacy. Experimental results show that the FLFC scheme exhibits a higher average accuracy and good stability compared to the FedAvg scheme in experiments.
    Reference | Related Articles | Metrics
    A Retrospective and Future Development Study of Zero Trust Architecture
    Journal of Information Security Reserach    2024, 10 (10): 896-.  
    Abstract309)      PDF (1683KB)(156)       Save
    With the rapid development of the internet, big data, and cloud computing, the zero trust architecture has been proposed as a new security paradigm to address the challenges of modern digitalization. This security model is built on never inherently trusting any internal or external requests, emphasizing that access must be granted through constant verification and monitoring. The core principles of zero trust include comprehensive identity verification, access control, least privilege, pervasive encryption, and continuous risk assessment and response. This article primarily reviews the development history of zero trust architecture, elaborates on the basic concepts of the zero zrust mechanism, and finally summarizes the future development of zero trust architecture.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 139-.  
    Abstract295)      PDF (676KB)(156)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 2-.  
    Abstract351)      PDF (1381KB)(155)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 68-.  
    Abstract417)      PDF (1105KB)(149)       Save
    Reference | Related Articles | Metrics
    Traffic Anomaly Detection Method by Secondorder Feature 
    Journal of Information Security Reserach    2024, 10 (12): 1082-.  
    Abstract292)      PDF (2415KB)(148)       Save
    A method is proposed to address the challenge of low detection rates for minority class attack traffic in deep learning models when dealing with imbalanced massive highdimensional network traffic data. Firstly, the isolation forest (iForest) is employed to remove outliers from normal class samples, used for training an enhanced Convolutional Denoising Autoencoder (CDAE) to mitigate the impact of noise and outliers on model training, resulting in a lowdimensional enhanced representation of the original features. Secondly, leveraging ADASYN on the outlierfree dataset to synthetically generate minority class attack samples, thereby resolving the data imbalance issue. Subsequently, using iForest to clean the newly generated samples from outliers, a new dataset is obtained. Employing the pretrained CDAE on this dataset achieves a firstround feature extraction, and the extracted features serve as input for a selfdistilled ResNet model to perform secondorder feature extraction. Finally, precise identification of anomalous traffic is accomplished by combining the trained CDAE and ResNet models. The method achieves the highest fiveclass accuracy and F1 score of 91.52% and 92.05%, respectively, on the NSLKDD dataset. Experimental results demonstrate that, compared to existing methods, this approach effectively enhances the detection rates for minority class attack traffic.
    Reference | Related Articles | Metrics
    Innovative and Professional Talent Education Architecture of  Cyberspace Security in New Situation
    Journal of Information Security Reserach    2025, 11 (4): 385-.  
    Abstract283)      PDF (3780KB)(145)       Save
    The emerging new problems and technologies in the field of cybersecurity currently do not match the applicability and timeliness of existing talent cultivation in technological development. In response to this, this paper investigates the innovative professional training system for cybersecurity talents under new circumstances. We systematically examine key issues in talent cultivation, dynamic updates of training objectives, evolution of knowledge systems, and cultivation of innovative competencies. The study proposes and constructs a comprehensive, multilevel, and dynamic talent cultivation framework for cyberspace security professionals, encompassing core theoretical research, critical technology R&D, and comprehensive innovation capability development that adapts to new technological trends. Through innovative processes including instructional objective design, content adaptation, teaching implementation, and feedback mechanisms, we establish an internationally adaptable training system that dynamically responds to technological advancements. This approach strengthens the dynamism, adaptability, and practical orientation of cybersecurity talent cultivation, effectively addressing the demand for innovative professionals in cyberspace security under evolving technological landscapes and emerging requirements.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 230-.  
    Abstract412)      PDF (3359KB)(142)       Save
    Reference | Related Articles | Metrics
    Research and Analysis of Named Entity Recognition Technology in #br# Threat Intelligence#br# #br#
    Journal of Information Security Reserach    2024, 10 (12): 1122-.  
    Abstract263)      PDF (990KB)(141)       Save
    In the face of increasingly complex network security attacks, it is very important to quickly obtain the latest network threat intelligence for realtime identification, blocking and tracking of network attacks. The key to solve this problem is how to obtain network threat intelligence data effectively, and named entity recognition technology is one of the hot technologies to solving this problem. This paper systematically analyzes several named entity recognition methods based on deep learning, and then designs a named entity recognition model suitable for threat intelligence field, and carries out experimental verification and analysis. Finally, the challenges faced by named entity recognition methods and their development prospects in the field of network security are analyzed and prospected.
    Reference | Related Articles | Metrics
    A Review of Fuzz Testing Techniques for Autonomous Driving Systems
    Journal of Information Security Reserach    2024, 10 (11): 982-.  
    Abstract195)      PDF (1389KB)(139)       Save
    Autonomous driving is the future development trend of the automotive industry, while autonomous vehicles heavily rely on interconnected systems and software that control their operation. System software vulnerabilities lead to serious safety hazards for vehicles. Therefore, automatic driving safety test is an important link to further improve the safety of autonomous vehicle. Fuzz testing, as an automated vulnerability testing technology, exhibits outstanding vulnerability exploration capabilities when dealing with complex software systems. It holds significant potential for widespread application in autonomous driving systems. This paper provides a systematic summary of widely used opensource fuzz testing tools. Through an indepth analysis of the characteristics of autonomous driving systems, the study identifies key challenges currently faced by research in this field, including: 1) difficulty in comprehensively considering input dimensions; 2) challenges in uncovering issues related to multifunctional collaborative concurrency; 3) mismatch of security issue categories. In response to these challenges, the research proposes corresponding recommendations, providing guidance for future related research.
    Reference | Related Articles | Metrics
    A Malicious TLS Traffic Detection Method with Multimodal Features
    Journal of Information Security Reserach    2025, 11 (2): 130-.  
    Abstract300)      PDF (3159KB)(136)       Save
    The malicious TLS traffic detection aims to identify network traffic that involves malicious activities transmitted through the TLS protocol. Due to the encryption properties of the TLS protocol, traditional textbased traffic analysis methods have limited effectiveness when dealing with encrypted traffic. To address this issue, a malicious TLS traffic detection method called MultiModal Feature Fusion for TLS Traffic Detection (MTBRL) has been proposed. This method extracts and fuses features from different modalities to detect malicious TLS traffic. Firstly, expert knowledge is employed for feature engineering, extracting key features from encrypted traffic, including protocol versions, encryption suites, and certificate information. These features are processed and transformed into twodimensional image representations. Then, ResNet is utilized to encode these images and extract their features. Simultaneously, an encrypted traffic pretrained BERT model is used to encode TLS flows, allowing the learning of contextual and semantic features of the TLS traffic. Additionally, an LSTM model is employed to encode the sequence of packet length distributions of the encrypted traffic, capturing temporal characteristics. Finally, through feature fusion techniques, the different modality features are integrated, and the model’s weight parameters are automatically learned and optimized using the backpropagation algorithm to accurately predict malicious TLS traffic. Experimental results demonstrate that this method achieves accuracy, precision, recall, and F1score of 94.94%, 94.85%, 94.15%, and 94.45%, on the DataCon2020 dataset. This performance is significantly superior to traditional machine learning and deep learning methods. 
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2026, 12 (2): 98-.  
    Abstract200)      PDF (532KB)(134)       Save
    Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 117-.  
    Abstract491)      PDF (625KB)(133)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 7-.  
    Abstract509)      PDF (1507KB)(131)       Save
    Reference | Related Articles | Metrics
    Design of SDP Trust Evaluation Model Based on Federated Learning
    Journal of Information Security Reserach    2024, 10 (10): 903-.  
    Abstract287)      PDF (1860KB)(131)       Save
    With the increasing blurring of network boundaries, zero trust has emerged as a new paradigm for network security defense. A federated learningbased SDP trust evaluation model and its deployment method are proposed to address the issues of low trust evaluation efficiency and difficulty in effectively protecting user data privacy in the face of massive contextual information and diverse terminal scenarios brought by the zero trust security architecture in the era of big data. This model adopts a decentralized approach to train a global model without sharing raw data, protecting the user data privacy of each distributed SDP controller node. Through experiments and comparative analysis, it has been proven that this zero trust evaluation model can effectively classify malicious and legitimate data streams, and its efficiency is superior to similar literature schemes.
    Reference | Related Articles | Metrics
    A Survey of Network Topology Obfuscation Techniques
    Journal of Information Security Reserach    2025, 11 (4): 296-.  
    Abstract291)      PDF (1248KB)(131)       Save
    LinkFlooding Attack (LFA) is a novel distributed denialofservice (DDoS) attack that exploits network topology detection. Network Topology Obfuscation serves as an effective deceptive defense mechanism against this attack, aiming to provide proactive protection before an attack occurs. Over the past decade, relevant research has continuously made progress, proposing corresponding obfuscation solutions for different scenarios and objectives. This paper comprehensively reviews the network topology obfuscation techniques. First, it combines the basic principles and classifications of network topology discovery to point out the risks of topology leakage in current network topology discovery. Next, it formally defines network topology obfuscation design and presents a proactive defense model. Then, based on the obfuscation concept, the technologies are divided into packet modification, decoy traps, routing mutation, and metric forgery schemes, and proposes a set of metrics to comprehensively compare the current mainstream network topology obfuscation techniques.
    Reference | Related Articles | Metrics
    Design and Implementation of Resourceefficient SM4 Algorithm on FPGA
    Journal of Information Security Reserach    2025, 11 (6): 490-.  
    Abstract309)      PDF (2238KB)(128)       Save
    In the hardware implementation of the SM4 algorithm, the lookup table method is commonly adopted for realizing the Sbox, which consumes a significant amount of hardware resources. This paper proposes an implementation scheme for the SM4 algorithm based on polynomial basis. Two construction schemes are developed for the 8×8 Sbox used in the SM4 algorithm, one based on composite field GF((24)2) and the other on composite field GF(((22)2)2). The test results indicate that the scheme based on polynomial bases GF((24)2) is optimal. Taking into account both resource utilization and performance, this paper designs two hardware implementation structures for SM4: a state machine parallel structure and a pipelined structure. Compared with the traditional lookup table approach, the state machine parallel structure reduces resource utilization by 21.98% while increasing the operating frequency by 14.4%. The pipelined structure achieves a reduction in resource utilization by 54.23%.
    Reference | Related Articles | Metrics
    Application of Behavior Anomaly Detection in Zero Trust Access #br# Control Method#br#
    Journal of Information Security Reserach    2024, 10 (10): 921-.  
    Abstract250)      PDF (1620KB)(127)       Save
    Zero trust is a solution to the problem of fuzzy network boundaries and has been widely used in many access control methods. Most zerotrust access control methods only use statistical methods to calculate trust values, which has poor ability to prevent unknown risks and lacks adaptability to different users. A zerotrust access control method that applies behavior anomaly detection was proposed to solve those problems. The proposed method designed a trust engine that included a behavior anomaly detection strategy, which can use autoencoders and bidirectional long shortterm memory neural networks to characterize user behavior patterns. The proposed method used the mean square error loss function to describe the degree of abnormality in user behavior, and calculated the trust value together with other elements. The proposed method used abnormal behavior representation values to set trust thresholds and adaptively adjust access policies. The experimental results show that the proposed method is sensitive to the correlation between user behaviors. The proposed method can detect the abnormal behaviors and stop the authorization, which achieve  continuous trust evaluation and finegrained access control.
    Reference | Related Articles | Metrics
    Traffic Anomaly Detection Based on Improved Pigeon Inspired Optimizer and #br# Pyramid Convolution#br#
    Journal of Information Security Reserach    2024, 10 (12): 1107-.  
    Abstract229)      PDF (1717KB)(126)       Save
    The Improved Pigeon Inspired Optimizer (IPIO) and Pyramid Convolution Neural Network (PyConv) are the foundation of a traffic anomaly detection approach that aims to address the issues of a high number of redundant features in network traffic and the low detection accuracy of machine learning methods. Firstly, a feature selection method based on IPIO is designed to reduce feature redundancy. The pigeon group is initialized to increase population quality and quicken convergence by estimating the feature set’s information gain rate. The present ideal solution is modified at random using a twostage mutation process, which also looks for solutions close to it to prevent local optimum formation. Second, deep feature extraction is implemented using PyConv. PyConv is made to use multiscale convolution kernels to extract features of various sizes and fuse them to create new features. Finally, the classification is realized by Softmax classifier to improve the accuracy of traffic anomaly detection. Experimental results on the UNSWNB15 dataset show that the proposed method significantly reduces redundant features while improving accuracy.
    Reference | Related Articles | Metrics
    Image Processing Model Watermarking Method Based on #br# Attention Mechanism and Passport Layer Embedding#br#
    Journal of Information Security Reserach    2024, 10 (9): 849-.  
    Abstract304)      PDF (2025KB)(124)       Save
    With the wide application of deep neural networks in the field of artificial intelligence, the copyright protection of deep neural networks has received extensive attention. However, so far, most of the methods for model copyright protection focus on detection or classification tasks, and are difficult to be directly applied to image processing networks. To this end, this paper proposes an image processing model copyright protection framework combining attention mechanism and passport layer embedding. Firstly, the channel and spatial attention network are used in the watermark embedding network to locate the human eye insensitive area in the image, which improves the robustness and imperceptibility of the watermark. Secondly, the passport layer watermark is inserted after the convolution layer of the target model to improve the ability to resist the ambiguity attacks. Finally, the combination loss is designed to guide the convergence direction of the model in combination with structural consistency and passport layer factors. Experimental results on superresolution and semantic segmentation models show that the watermark extraction rate of this method is more than 98%, and it has good robustness to surrogate attack and ambiguity attack.
    Reference | Related Articles | Metrics