Most Download articles

    Published in last 1 year | In last 2 years| In last 3 years| All| Most Downloaded in Recent Month| Most Downloaded in Recent Year|

    Most Downloaded in Recent Month
    Please wait a minute...
    For Selected: Toggle Thumbnails
    Survey of Coverage-guided Grey-box Fuzzing
    Journal of Information Security Reserach    2022, 8 (7): 643-.  
    Abstract681)      PDF (1745KB)(368)       Save
    In recent years, coverageguided greybox fuzzing has become one of the most popular techniques for vulnerability mining, which plays an increasingly important role in the software security industry. With the increasing variety of application scenarios and complexity of test applications, the performance requirements of coverageguided greybox fuzzing are further improved. This paper studies the existing coverageguided greybox fuzzing methods, summarizes its general framework, and analyzes its challenges and the development status. The experimental results of these methods are summarized and the problems existing in the experimental evaluation are discussed. Finally, the future development trend of coverageguided greybox fuzzing is prospected.Key words fuzzing; hole mining; coverageguided; greybox; software security

    Related Articles | Metrics
    Research on Federated Learning-based Intrusion Detection Methods for the Internet of Things
    Journal of Information Security Reserach    2026, 12 (9): 780-788.   DOI: 10.12379/j.issn.2096-1057.2026.09.01
    Abstract120)      PDF (723KB)(38)       Save
    The rapid expansion of the Internet of Things (IoT) has given rise to pressing cybersecurity challenges. Traditional centralized intrusion detection approaches encounter difficulties in balancing model performance and data privacy protection. Federated learning enables collaborative model training without sharing raw data among participants, which provides a novel paradigm for IoT intrusion detection. This paper presents a systematic review of federated learning-driven IoT intrusion detection methods. It first introduces the fundamental background and typical architectures of this research field. It then categorizes existing methods into three types: federated machine learning, federated deep learning, and federated reinforcement learning, and analyzes the characteristics, application scenarios,and existing limitations of each category. This paper further summarizes common enhancement mechanisms, cutting-edge technologies, public datasets, and evaluation indicators used in this field. Finally, this paper discusses key open challenges, including label scarcity, Non-Independent and Identically Distributed (Non-IID) data, federated multimodal large models and security enhancement, and proposes potential future research directions. This review can provide a useful technical reference for subsequent research and practical applications in this field.
    Reference | Related Articles | Metrics
    Core Isolation Method of ARM Processor for OutofOrder Execution  Vulnerability Test
    Journal of Information Security Reserach    2023, 9 (4): 347-.  
    Abstract267)      PDF (1904KB)(189)       Save
    With the discovery of processor microarchitecture vulnerabilities represented by spectre and meltdown, microarchitecture security vulnerabilities have gradually attracted the attention of academia, and automatic testing schemes for related microarchitecture vulnerabilities have also been proposed. However, in the real test environment, the test microarchitecture environment will be interrupted and disturbed by the scheduling system, resulting in the omission of effective test cases. Therefore, this paper proposes an arm processor core isolation method for outoforder execution test. By using the management mechanism of interrupt and scheduling between ARM processor and Linux kernel and designing the corresponding process synchronization mechanism, this method can isolate the processor core from the interrupt and scheduling system during the test process, so as to ensure that the operation of test instruction block will not be interrupted by interrupt and scheduling program. The corresponding synchronization mechanism is designed to ensure that the process switching process will not be inserted and executed by other processes, so as to ensure the effectiveness of the test.
    Reference | Related Articles | Metrics
    Security Problem and Countermeasure Research of SDN
    Journal of Information Security Research    2020, 6 (3): 202-211.  
    Abstract316)      PDF (1584KB)(489)       Save
    In recent years, softwaredefined networking (SDN) has been the focus of research. SDN may replace traditional networks and become the nextgeneration network architecture, because its programmability and scalability bring new opportunities for network management. We have comprehensively analyzed the hidden dangers of softwaredefined network (SDN), thoroughly analyzed its own security problems in softwaredefined network, and proposed corresponding countermeasures and suggestions. We discussed the characteristics and standards of SDN, and based on the three levels of the SDN paradigm, namely the data forwarding layer, the control layer, and the application layer, analyzed the security threats and countermeasures at each level in detail and introduced Countermeasure techniques that can be used to prevent, mitigate or resolve such attacks.
    Reference | Related Articles | Metrics
    Meiya Pico,Innovation to Enhance the Core Technology of Cybersecurity
    Journal of Information Security Research    2017, 3 (9): 770-780.  
    Abstract451)      PDF (1952KB)(1149)       Save
    Related Articles | Metrics
    The Structural Risk Evolution of Virtual Currency Crimes and Chinese Governance Practices
    Journal of Information Security Reserach    2026, 12 (9): 860-866.   DOI: 10.12379/j.issn.2096-1057.2026.09.09
    Abstract73)      PDF (683KB)(28)       Save
    With the deep development of blockchain technology and the accelerated integration of the global digital economy, virtual currencies are reshaping the financial ecosystem, but simultaneously giving rise to new types of criminal activities with diverse forms and far-reaching harms. These activities exhibit deep-seated characteristics such as disembedded subject identities, modularized criminal activities, technological iteration of criminal methods, and networked criminal hazards, becoming new structural risk carriers in the financial sector. Based on the triple analytical framework of “technology-institution-capital,” this paper systematically analyzes the evolutionary path and deep-seated generation logic of virtual currency crimes from instrumental application to ecological infiltration. On this basis, transcending simple policy reviews, this paper theoretically refines Chinese practical experience in governing new types of virtual currency crimes. The research shows that China has constructed a comprehensive and penetrative governance system through the reshaping of the institutional dimension, the countermeasures in the technological dimension, and the regulation of the capital dimension. This practice not only effectively curbs local risks but also contributes Chinese wisdom with theoretical depth and practical value to risk governance and order reconstruction in the era of global digital finance.
    Reference | Related Articles | Metrics
    To Create a Positive Cyberspace by Safeguarding Network Security with Active Immune Trusted Computing 3.0
    Journal of Information Security Research    2018, 4 (4): 282-302.  
    Abstract280)      PDF (2291KB)(1010)       Save
    Related Articles | Metrics
    Research on Loop Security Problem in Binary Programs
    Journal of Information Security Reserach    2023, 9 (4): 364-.  
    Abstract417)      PDF (2829KB)(173)       Save
    Loop is a common structure in programs and improperly using loop is one of the most important reasons resulting in security problems, making detecting loop security problem is important and valuable. As the path state explosion and loop modeling problems in binary code, statically analyzing of loop security is extremely challenging, and traditional methods are unable to solve these problem. In this paper, we proposed a detecting method for loop security problems based on binary static analyzing,having the ability of detecting out of bound memory access in loop and infinite loop problem. Firstly, we present an accurate extracting and recovering method of loop factors in binary based on analyzing of loop structure and then multiple path explore strategies are utilized to solving the path state explosion and sorting problem. Moreover, we propose a function summary method based on static concrete execution to solving constraints growing problem caused by induction function invoking in loops. Finally, we proposed an inductive analysis method based on loop predicates to detect insecure loop in binary. We have applied our methods on ten real world programs and compared with Angr. The experimental results turn out that our method is capable of detecting more loop problems than Angr.
    Related Articles | Metrics
    Train of Thought on Governance of Dark Web
    Journal of Information Security Research    2018, 4 (9): 846-852.  
    Abstract477)      PDF (1707KB)(508)       Save
    Internet has become an indispensable impetus to accelerate the development of human society. But what cannot be overlooked is while Internet promotes human development and progress, its unique unboundedness and anonymity have also brought many hidden dangers to global security. Dark Web, the most covert and darkest part of cyberspace, carries the worst cybercrimes. Drug, population and arms trafficking, terrorism, political subversive activities and other crimes are almost filled with the entire dark Web space, which poses a great threat to global security. Effective methods to dark Web governance is extremely urgent. Many Internet powers have taken actions to dark Web governance, but produce very little effect due to the differences in their respective purposes, methods, and even ideologies. Dark Web governance has become a common problem facing all countries. On December 16, 2015, General Secretary Xi Jinping proposed to build “a community of shared future in cyberspace” for the first time at the Second World Internet Conference, emphasizing that “Cyberspace is a common activity space for human, and the future of cyberspace should be shared by all countries in the world. Every country should strengthen communication, expand consensus, and deepen cooperation.” This undoubtedly provides a Chinese idea for dark Web governance. In the context of rapid development of globalization and with the guidance of building “a community of shared future in cyberspace”, we propose several methods and recommendations for dark Web governance.
    Reference | Related Articles | Metrics
    A Construction Method of Hybrid Covert Channels Based on Federated Learning
    Journal of Information Security Reserach    2026, 12 (9): 789-800.   DOI: 10.12379/j.issn.2096-1057.2026.09.02
    Abstract80)      PDF (3249KB)(23)       Save
    Federated Learning (FL) is designed to solve the irreconcilable contradiction between data sharing requirements and privacy needs. As a kind of distributed machine learning, FL needs to exchange a large number of model parameters between participants and the central server, which leads to a large amount of data communication. The iterative process of FL model updating depends on distributed data transmission, and once the transmission channel is located, its model data security and integrity will be difficult to guarantee. In this paper, a hybrid Covert Storage-Timing Channel (CSTC) scheme for FL is proposed. The secret message is firstly split into parallel-distributed coding units, and the secret data communication is achieved via adjusting the inter-packet delays to indicate which block is to be transmitted, and the overt traffic’s packet payload is selectively replaced with secret blocks according to the payload content. Thus, the position indicator of a secret block is embedded in both the time and storage features of the overt traffic, while the feature-location correspondence is pre-shared by the receiver and sender, and the adversary cannot grasp a secret message unless all features locating the secret block are obtained. Moreover, three variants of the original CSTC are proposed to fulfill the different performance requirements, and the experiments show that the undetectability and capacity of the proposed schemes are reasonable.
    Reference | Related Articles | Metrics
    Research on Data Classification and Grading Method Based on Data Security Law
    Journal of Information Security Reserach    2021, 7 (10): 933-.  
    Abstract1750)      PDF (2157KB)(1137)       Save
    The Data Security Law of the People's Republic of China (hereinafter referred to as the Data Security Law) has been formally promulgated, which clearly stipulates that the state establishes data classification and grading protection system, and implements classified and graded protection for data. However, at present, the relevant standards and specifications of data classification and grading in China are relatively lacking, and the practical experiences that can be used for reference in various industries are relatively insufficient. How to effectively implement the data classification and grading protection is still a thorny problem. Based on Article 21 of the Data Security Law, this paper analyzes the factors such as the influence object, influence breadth and influence depth after the data is damaged, puts forward the principles and methods of data classification and data grading, and gives an implementation path of data classification and grading according to the application scenarios and industry characteristics of the data, which provide a certain reference for data classification and grading protection of various industries.
    Reference | Related Articles | Metrics
    Research on Network Malicious Traffic Detection Technology Based on  Ensemble Learning Strategy
    Journal of Information Security Reserach    2023, 9 (8): 730-.  
    Abstract372)      PDF (2586KB)(232)       Save
    Network traffic is the main carrier of network attacks, and the identification and analysis of malicious traffic is an important means to ensure network security. Machine learning method has been widely used in malicious traffic identification, which can achieve high precision identification. In the existing methods, the fusion model is more accurate than the single statistical model, but the depth of network behavior mining is insufficient. This paper proposes a stacking model that identifies multilevel network features and is MultiStacking for malicious traffic. It employs the network behavior patterns of network traffic in different session granularity and combines the robust fitting capability of the stacking model for multidimensional data to deeply heap malicious network behaviors. By verifying the detection capabilities of multiple fusion models on the CICIDS2017 and CICIDS2018 datasets, various detection methods are comprehensively quantified and compared, and the performance of MultiStacking detection methods in MultiStacking scenarios is deeply analyzed. The experimental results show that the malicious traffic detection method based on multilevel stacking can further improve the detection accuracy.
    Reference | Related Articles | Metrics
    Log Anomaly Detection Method based on LLM-Enhanced Dynamic Graph Relational Learning and Explainable Diagnosis
    Journal of Information Security Reserach    2026, 12 (9): 823-830.   DOI: 10.12379/j.issn.2096-1057.2026.09.05
    Abstract105)      PDF (979KB)(21)       Save
    System logs record the complete operational data of computer systems, and form the core foundation for system stability assurance, security guarantee and fault diagnosis. Existing graph-based log anomaly detection methods are incapable of extracting deep log semantics, mitigating class imbalance, modeling complex temporal dependencies, and providing intuitive anomaly interpretation simultaneously. This paper presents an anomaly detection scheme that integrates Large Language Model and dynamic graph networks. Based on the classic Graph Log Anomaly Detection framework, this paper incorporates semantic augmentation, data augmentation and multi-scale temporal graph modeling to propose LLM-GLAD, an LLM-driven log relational anomaly detection framework. An interpretable diagnosis module based on LLM is constructed to generate natural language anomaly explanations and root cause suggestions for practical deployment. Comparative experiments conducted on three public log datasets demonstrate that the proposed method achieves a precision of 96.45%, a recall of 93.43% and an F1-score of 94.92%.
    Reference | Related Articles | Metrics
    Face Antispoofing Detection Algorithm Based on a Multimodal  and  Multiscale Fusion
    Journal of Information Security Reserach    2022, 8 (5): 513-.  
    Abstract492)      PDF (3977KB)(206)       Save
    This paper studies the problem that multimodal features are not fully utilized in facial liveness detection, and proposes a face antispoofing detection algorithm based on multimodal and multiscale fusions, which makes full use of the complementary characteristics of visible light, nearinfrared light and depth to filter the forged samples step by step. For the samples to be tested, firstly the playback attacks are filtered by nearinfrared face detection, and then plane attacks are filtered by deep discriminant network. Finally, the samples which were difficult to be classified are input into multimodal fusion module for comprehensive discrimination to obtain the final classification. In this paper, a high resolution multimodal data set of nearly 20000 groups is constructed, and lightweight discriminant networks with multiscale input are designed to further improve the adaptability of the algorithm. The experimental results show that the proposed algorithm has significantly higher detection accuracy than the single modal solution, and the total number of parameters and reasoning time are only 480000 and 8.07ms, which are far lower than other popular fusion methods.Key wordsface detection; demonstration attack; multimodal; weighted fusion; lightweight network

    Related Articles | Metrics
    Finite-Time Control of Markov Jump Systems Under Cyber-Attacks
    Journal of Information Security Research    2021, 7 (2): 145-154.  
    Abstract276)      PDF (1736KB)(226)       Save
    The characteristics of diversity, distributed and high frequency of cyber-attacks bring great threat to national economy and social development. In the field of industrial control, the research of networked control systems security becomes more and more important. The problem of Markov jump systems based on hybrid-drive mechanism and both channel quantizations is investigated in this paper, and the finite-time stability and H_∞ performance of the system under cyber-attacks are considered. Firstly, an output feedback Markov jump system model is formulated and the corresponding output feedback controller is designed. For the purpose of releasing the sharing network bandwidth burden and reducing the invalid signal transmission rate, hybrid-driven mechanism and both channel logarithmic quantizers are introduced on the basis of traditional event-triggered mechanism to balance the system performance and communication data transmission rate. Then, the model of cyber-attacks is established to enhance the resistance of Markov jump system to external attack. By constructing Lyapunov-Krasovskii functions, the system finite-time stability criteria and H_∞ performance index are given with linear matrix inequations. Finally, two simulations are shown to illustrate the effectiveness of the deduced theorem.
    Reference | Related Articles | Metrics
    Research on the Legal Positioning and Liability Allocation of AI Agent
    Journal of Information Security Reserach    2026, 12 (8): 681-690.   DOI: 10.12379/j.issn.2096-1057.2026.08.01
    Abstract248)      PDF (682KB)(22)       Save
    The autonomous operation and continuous functioning capabilities of AI agents have transcended the operational boundaries of traditional generative AI, which centers on the "input-output" paradigm, and present new normative challenges to the existing "tool-control-responsibility" framework a framework predicated on stable human control. In terms of behavior identification, responsibility attribution, and operational regulation, the current legal system is insufficient to fully accommodate the cross-subject, multi interactive, and continuously operating characteristics of AI agents. Against this backdrop, this paper contends that AI agents should not be granted independent legal personality. Instead, it proposes a response grounded in the functional reconstruction of traditional static tool-oriented rules, while preserving the stability of the existing subject system. Adopting "functional instrumentalism" as the fundamental legal orientation for AI agents, this paper constructs a dual track identification framework "technological identity" and "legal attribution" to align behavioral identifiability with responsibility attributability under conditions of continuous operation. Furthermore, it introduces a "relationalist attribution" approach, which takes control relationships, interest structures, and risk sources as analytical dimensions to allocate responsibilities among multiple subjects in a structured manner. Employing the "principle of minimum necessity" as the boundary for institutional expansion, the paper thereby outlines an integrated governance framework that connects current law, special rules, and technical standards. Accordingly, the logic of AI governance is shifting from a static structure centered on behavioral outcomes and one off liability determinations toward a dynamic structure oriented around process of continuous operation.
    Reference | Related Articles | Metrics
    Federated Learning Backdoor Attack Method Based on Dynamic Trigger Transformation
    Journal of Information Security Reserach    2026, 12 (9): 801-812.   DOI: 10.12379/j.issn.2096-1057.2026.09.03
    Abstract85)      PDF (1674KB)(17)       Save
    To address the rapid degradation of fixed-trigger backdoor attacks in Federated Learning after attack termination, a backdoor attack method based on dynamic trigger transformation was developed. The method dynamically adjusted the position, size, and pattern of the trigger during federated training, selected trigger states according to historical attack success rates in data preprocessing, and introduced supervised contrastive learning in the adaptation stage to align representations of poisoned samples with the target class and mitigate catastrophic forgetting. Experiments were conducted on MNIST, CIFAR-10, and Tiny-ImageNet under multiple aggregation algorithms and five representative defense mechanisms, evaluating attack effectiveness, stealthiness, and persistence. The attack success rate exceeded 95% across the evaluated defense scenarios. In the CIFAR-10 setting, the attack success rate remained approximately 90% after trigger injection had been stopped for 1,000 rounds. These results indicate that dynamic trigger selection and supervised contrastive learning improve the persistence and adaptability of federated learning backdoor attacks.
    Reference | Related Articles | Metrics
    Quantitative Research on Privacy Risk of LargeScale Mobile Users
    Journal of Information Security Research    2019, 5 (9): 778-788.  
    Abstract770)      PDF (3810KB)(571)       Save
    The increasing number of mobile applications have given mobile Internet service providers the opportunity to collect large amounts of user data. However, the unreasonable and abnormal collection and use of data have made mobile users face extremely serious privacy risk. How to analyze the status of user privacy risk and protect user privacy have become an urgent issue. Based on the permission analysis of mobile applications, this paper proposes a novel user privacy risk quantification model. This model first identifies the personal privacyrelated data collection of mobile applications through 39 privacy permissions which are considered as leakage data source, then consider the possibility of data leakage and the privacy hazard degree of data. This model is further constructed with the assist of application usage data of 30 million mobile devices. Finally, the distribution of privacy risks of individual users is analyzed. Then through analyzing the average user privacy risk value of each user group, the China privacy risk index is formulated to reflect the differences in privacy risks among various user groups, including the regional privacy risk index, the population privacy risk index, and the behavioral privacy risk index.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E2): 39-.  
    Abstract125)      PDF (1221KB)(58)       Save
    Reference | Related Articles | Metrics
    Risk Analysis and Governance Approaches for Online Protection of Minors in the Age of Artificial Intelligence
    Journal of Information Security Reserach    2026, 12 (9): 867-876.   DOI: 10.12379/j.issn.2096-1057.2026.09.10
    Abstract82)      PDF (684KB)(15)       Save
    The rapid advancement of Artificial Intelligence (AI), while offering minors diverse opportunities in education, entertainment, and social interaction. However, it has simultaneously catalyzed a range of complex new victimization risks. These include deepfake identity fraud, virtual sexual exploitation, cyberbullying, internet addiction, misinformation and fraud, algorithmic discrimination, and privacy breaches. Traditional governance models are inadequate to fully address these emerging threats. Through a comparative analysis of legal policies and governance practices across different countries and regions, this study identifies distinct approaches: the European Union emphasizes rights-based orientations and platform accountability, the United States prioritizes interstate innovation and flexible regulation, while China focuses on institutional development and educational guidance. These differences reflect varied governance traditions and offer valuable insights for international mutual learning and cooperation. Consequently, this paper proposes five pathways for protecting minors online in the AI era: Firstly, innovating legal policies to provide agile responses to novel AI risks. Secondly, fostering home-school collaborative education to enhance minors' digital literacy. Thirdly, leveraging technological innovation to promote safe and user-friendly AI interaction design. Fourthly, strengthening platform governance and supervision through targeted rectification of the online environment. Fifthly, facilitating the integration of government, industry, academia, and research to enable multi-stakeholder participation in comprehensive governance. This research aims to provide academic support and policy implications for the theoretical construction and practical pathways of the protection of minors in the AI era, ultimately contributing to the creation of a safe, healthy, and inclusive digital ecosystem for minors.
    Reference | Related Articles | Metrics
    Research of Threat Intelligence Sharing and Using for Cyber Attack Attribution
    Yang Zeming, Li Qiang, Liu Junrong, and Liu Baoxu
    Journal of Information Security Research    2015, 1 (1): 31-36.  
    Abstract1175)      PDF (5527KB)(1657)       Save
    With the increasingly complexity of cyberspace security, the attack attribution has become an important challenge for the security protection system. The emergence of threat intelligence provided plentiful data source support for the attack attribution, which makes large-scale attack attribution became possible. To realize effective attack attribution, based on the structure expression of the threat information, a light weight framework of threat intelligence sharing and utilization was proposed. It included threat intelligence expression, exchange and utilization, which can achieve the attack attribution result. Take the case of C2 relevant information, we described the expression of threat intelligence sharing and utilization, and verified the framework. Results show that the framework is practical, and can provide new technical means for attack attribution. In addition, based on the understanding of threat intelligence, several thinking about the construction of sharing and utilization mechanisms were promoted in the end.
    Related Articles | Metrics
    VEDA, Establishing the AI Dynamic Defense System for Cyber Security
    Journal of Information Security Research    2017, 3 (12): 1058-1066.  
    Abstract451)      PDF (1526KB)(997)       Save
    Related Articles | Metrics
    Image Steganography Methods from Traditional to Deep Learning
    Journal of Information Security Research    2019, 5 (3): 230-235.  
    Abstract531)      PDF (1665KB)(553)       Save
    This paper summarizes the schemes of typical traditional embedded image steganography and new nonembedded image steganography algorithm based on deep learning, and points out that the traditional method is difficult to resist the current stateoftheart steganalysis based on machine learning in this field, and the embedding capacity of new method is not enough, the embedding process is more complicated. Then the design of steganography without embedding (SWE) based on the generative adversarial networks or deep convolutional generative adversarial networks is proposed. Combining traditional and new algorithms and compensating for each other, the image steganography gets further development.
    Reference | Related Articles | Metrics
    An Intrusion Detection Method for Industrial Control Systems Integrating Memory Autoencoder and CNN-Transformer
    Journal of Information Security Reserach    2026, 12 (9): 831-841.   DOI: 10.12379/j.issn.2096-1057.2026.09.06
    Abstract69)      PDF (1467KB)(12)       Save
    To address the problems of high false alarm rate in unsupervised detection and insufficient generalization capability of supervised detection in existing industrial control system intrusion detection methods, this paper proposes an intrusion detection method integrating memory autoencoder and CNN-Transformer. First, the sliding window technique is employed to construct temporal contexts, so as to mitigate detection blind spots caused by static features. Second, multi-dimensional feature enhancement is implemented to expand the original data representation, which improves the model's robustness against complex attack patterns and reduces misclassification caused by insufficient dimensionality. Furthermore, a Memory AutoEncoder (MemAE) and a Transformer-equipped Convolutional Neural Network (CNN-Transformer) are constructed as supervised models, and a parallel intrusion detection model termed MemAE-CT is established by combining the two modules. The proposed model incorporates an adaptive weight distribution mechanism to dynamically adjust the decision contribution of each component, thereby balancing the accurate identification of known attacks and the generalized detection of unknown threats. The proposed method achieves an accuracy of 97.26% and an F1-score of 96.23% on the natural gas pipeline dataset released by Mississippi State University, which verifies its excellent performance. Its generalization capability is further validated on the CICIDS2017 dataset, and the method provides a reliable solution for industrial control system security.
    Reference | Related Articles | Metrics
    Survey of Software Supply Chain Security Detection and Assessment Technologies
    Journal of Information Security Reserach    2026, 12 (7): 586-597.  
    Abstract149)      PDF (1750KB)(80)       Save
    In the context of the digital era, software supply chain has become a critical component supporting the stable and healthy development of the digital economy. It is an indispensable part of the nation’s key information infrastructure and economic and social systems. The security of software supply chain directly determines the security of the key businesses carried by the software supply chain. Therefore, based on the development needs of the digital age, this article summarizes the current technologies, methods, and development trends related to software supply chain security detection and evaluation, providing reference and guidance for industry insiders, researchers, and decisionmakers. It includes a review and detailed explanation of the background and methods of software supply chain security detection and evaluation technology, detailing the principles of mainstream technologies such as component analysis, vulnerability scanning, code review, runtime monitoring, threat modeling, and fuzz testing, and comparing and analyzing the advantages and disadvantages of various technologies; Analyze the current technical challenges and countermeasures faced by technology; And propose ten major trends for the development of this field in the next decade, in order to improve the security level of the software supply chain and promote the development of the software industry.
    Reference | Related Articles | Metrics
    Overview on SM9 Identity Based Cryptographic Algorithm
    Journal of Information Security Research    2016, 2 (11): 1008-1027.  
    Abstract3815)      PDF (13949KB)(6275)       Save
    SM9 identitybased cryptographic algorithm is an identitybased cryptosystem with bilinear pairings. In such a system the user s private key and public key may be extracted from user s identity and key generation centers parameters. The most common cryptographic uses of SM9 are with digital signature, data encryption, key exchange protocol and key encapsulation mechanism etc. The application and management of SM9 will not require digital certificate, certificate base, and key base. The key length of the SM9 cipher algorithm is 256b. SM9 cryptographic algorithm was issued as the cryptography standard in 2015. This paper will summarize the design, algorithm, software and hardware implementation and cryptanalysis of SM9 cryptographic algorithm. We also give some concrete examples in appendix.
    Reference | Related Articles | Metrics
    Research on Webshell Detection Method Based on Logistic Regression Algorithm
    Journal of Information Security Research    2019, 5 (4): 298-302.  
    Abstract293)      PDF (1096KB)(711)       Save
    Webshell is a commonly used tool for hackers to carry out network intrusion. It has the characteristics of high concealment and great power. The existing Webshell detection method has high detection accuracy when detecting known Webshell, but the detection accuracy is very low in the face of complex and flexible unknown and variant Webshell. In response to this problem, this paper discusses the characteristics and working principle of Webshell, analyzes the difference between Webshell and the traditional Webshell using obfuscated encryption coding technology, and proposes a Webshell machine learning detection model based on logistic regression algorithm. The model can effectively detect the confusingly coded Webshell, reduce the false positive rate and improve the detection accuracy.
    Reference | Related Articles | Metrics
    A Survey of Research on Network Attack Model
    Journal of Information Security Research    2020, 6 (12): 1058-1067.  
    Abstract1485)      PDF (1774KB)(1216)       Save
    With the rapid development of information technology, network attacks have gradually presented multi-stage, distributed and intelligent characteristics. Single firewalls, intrusion detection systems and other traditional network defense measures cannot well protect the network system security in an open environment. As a kind of attack scene representation from the attacker's perspective, the network attack model can comprehensively describe the network attack behavior in a complex and changeable environment, and is one of the commonly used network attack analysis and response tools. This paper first introduces the current main network attack models, including traditional trees, graphs, nets structure models and modern attack chains, ATT&CK, diamond models, etc. Then the analysis and application of network attack model will be explained. The analysis process for the purpose of solving the attack index mainly includes the probability framework, the assignment method and the solution method, and the application of the attack model based on the life cycle includes the application of the attackers and the defenders' perspective; Finally, the current challenges and future directions of the network attack model and its analysis and application are summarized.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E2): 141-.  
    Abstract50)      PDF (2650KB)(39)       Save
    Reference | Related Articles | Metrics
    The Mechanism of Disinformation Generation and Governance Pathways in Generative AI Models
    Journal of Information Security Reserach    2026, 12 (7): 606-612.  
    Abstract150)      PDF (1256KB)(41)       Save
    While driving transformations in online information order, generative AI models also generate disinformation risks characterized by an “objective+subjective” overlap. An analytical framework tailored to their technical characteristics is urgently needed. This study systematically deconstructs the technical logic of false information production in generative AI models based on their hybrid expert architecture, treelike reasoning patterns, localized semantic understanding attributes, and opensource ecosystem mechanisms. It analyzes the transmission mechanisms of false information risks across four stages: data input, algorithmic operation, content presentation, and cognitive dissemination. To address these risks: At the algorithmic level, implement a processbased oversight scheme encompassing “access reviewoperation disclosurepostevent verification”; at the presentation level, strengthen scenariobased, interactive “warning notice” labeling mechanisms; at the cognitive level, cultivate users' digital literacy and selfrestraintt capabilities to achieve effective information security governance in the AI era.
    Reference | Related Articles | Metrics
    Survey of Hash Functions
    Wang Xiaoyun1,2 and Yu Hongbo3
    Journal of Information Security Research    2015, 1 (1): 19-30.  
    Abstract1839)      PDF (11279KB)(3931)       Save
    One of the fundamental primitives in modern cryptography is the cryptographic hash functions, often informally called hash functions. They are used to compress messages of arbitrary length to fixed length hash values which are also called hash codes, message digests or digital fingerprints. A primary motivation for cryptographic hash functions is that they serve as compact representative images of input messages, which they can uniquely identify. Changing a single letter will change most of the digits in the hash code. The most common cryptographic uses of hash functions are with digital signature and for data integrity. Hash functions are frequently used in digital signature schemes to compress large messages for processing by public-key cryptosystems such as RSA. They are also used to design message authentication codes (MACs) and many secure cryptographic protocols. Hash functions occur as components in various cryptographic applications (e.g. protection of pass-phrases, protocols for payment, broadcast authentication etc.), where usually their property as a computational one-way function is used. So the study of the hash functions is of great significance in the cryptanalysis field.
    Related Articles | Metrics
    A Survey of Zero Trust Research
    Journal of Information Security Research    2020, 6 (7): 608-614.  
    Abstract1536)      PDF (2068KB)(1703)       Save
    With the popularization of cloud computing, mobile office and other technologies, the enterprise network structure becomes complex. The traditional network security model is based on the idea of boundary protection, which can not meet the current needs. Zero trust is a new network security model, where no distinction is made between internal and external networks and all entities need authentication and authorization before accessing resources, which can be used to protect the network whose perimeter is increasingly fuzzy. This paper gives the definition of zero trust, introduces the architecture of zero trust, analyzes the core technology of zero trust, compares and analyses several representative zero trust schemes, summarizes the development status, points out the research direction needing attention in this field, which can provide reference for the research and application of zero trust.
    Reference | Related Articles | Metrics
    Overview of Data Security Governance at Home and Abroad
    Journal of Information Security Reserach    2021, 7 (10): 922-.  
    Abstract1883)      PDF (3579KB)(1083)       Save
    With the rapid development of digital economy, privacy infringement, data leakage, platform monopoly, misinformation and other issues emerge one after another, increasingly becoming an important issue that threatens individual rights, industrial development and national security. This article, on the national policy and law level, sorts out four categories of data governance, that is, personal data protection, cross-border data flow regulation, data market governance, and data content management. Countries and regions like United States, European Union and China are the centers of global digital economy. This article summarizes their practices and experience in above-mentioned four categories, and on this basis, puts forward some suggestions on strengthening China's data security governance system and capacity building, that is, further improving the legal system to compete for the leadership of the digital economy, deeply participating in global data governance to enhance the international voice of rule-making, and strengthening support and oversight of new technologies and applications to seize new heights in digital economy governance.
    Reference | Related Articles | Metrics
    An Overview of Application and Technology of Artificial Intelligence in Cybersecurity
    Journal of Information Security Reserach    2022, 8 (2): 110-.  
    Abstract2190)      PDF (1142KB)(1501)       Save
    Compared with the developed countries, the basic research and technology application in the field of artificial intelligence in China started later, especially the application of artificial intelligence in the important field of network security. Domestic and abroad disparity is still very obvious, which seriously affects the improvement of China's cybersecurity capability. This paper elaborates the relationship between artificial intelligence, network attack and network defense, and widely investigates the application status of artificial intelligence in major information security companies at home and abroad. It points out that APT detection, 0day vulnerability mining and cloud security are three core areas that affect the level of cybersecurity capability, This paper deeply analyzes the key technologies of artificial intelligence technology applied in these three fields, and puts forward the safety risks of artificial intelligence technology, and points out that artificial intelligence technology is not a panacea for all diseases, This Paper provides a scientific reference for the further research and application of artificial intelligence technology in China's information security industry.
    Reference | Related Articles | Metrics
    Federated Foundation Model Finetuning Based on Differential Privacy#br#
    #br#
    Journal of Information Security Reserach    2024, 10 (7): 616-.  
    Abstract603)      PDF (1752KB)(290)       Save
    As the availability of private data decreases, large model finetuning based on federated learning has become a research area of great concern. Although federated learning itself has a certain degree of privacy protection, privacy security issues such as gradient leakage attacks and embedding inversion attacks on large models still threaten the sensitive information of participants. In the current context of increasing awareness of privacy protection, these potential privacy risks have significantly hindered the promotion of large model finetuning based on federated learning in practical applications. Therefore, this paper proposes a federated large model embedding differential privacy control algorithm, which adds controllable random noise to the embedded model of the large model during efficient parameter finetuning process through a global and local dual privacy control mechanism to enhance the privacy protection ability of federated learning based large model parameter finetuning. In addition, this paper demonstrates the privacy protection effect of this algorithm in large model finetuning through experimental comparisons of different federation settings, and verifies the feasibility of the algorithm through performance comparison experiments between centralization and federation.
    Reference | Related Articles | Metrics
    Generative Logic and Coping Strategies of Personal Information Security Risks in Digital Platform
    Journal of Information Security Reserach    2026, 12 (5): 445-.  
    Abstract107)      PDF (1235KB)(39)       Save
    While digital platform provides tremendous convenience for public production and daily life, security risks such as personal information leakage and misuse have simultaneously escalated. As a new tier in governance structures, guiding digital platform to strike a balance between information protection and data openness is crucial for advancing the modernization of cyberspace governance systems and enhancing governance capacity. Examining digital platform from the perspective of data controllers, this paper explores the generative logic of personal information security risks through a threetiered framework: unauthorized collection, unregulated processing and improper application. The paper proposes coping strategies including refining “informed consent” operational details to stabilize the privacy policy framework of platform, strengthening the application of data desensitization technologies to standardize the automated decisionmaking processes of platform, and improving the information provision and disclosure mechanisms to enhance the internal information management of platform, so as to achieve a balance between personal information protection and the release of the value of data elements.
    Reference | Related Articles | Metrics
    A Review of Large Language Model-Driven Network Penetration Testing Agents
    Journal of Information Security Reserach    2026, 12 (8): 691-711.   DOI: 10.12379/j.issn.2096-1057.2026.08.02
    Abstract185)      PDF (3915KB)(13)       Save
    With the accelerated development of artificial intelligence, intelligent agents have demonstrated notable advantages in environmental perception, task planning, and multi-tool coordination. Concurrently, breakthroughs in Large Language Models concerning natural language understanding, logical reasoning, and multimodal processing have provided crucial support for the evolution of intelligent agents. The deep integration of these two technological strands has given rise to LLM-driven autonomous agents for network penetration testing, promoting a gradual shift from the traditional "tool-assisted" paradigm toward "autonomous intelligence." This paper systematically reviews the key challenges and principal technical approaches identified in existing research across four core modules: agent role definition, task planning, memory management, and interactive execution. It further examines the limitations of current methods in areas such as multimodal information processing, automated interaction, and context management. To address these issues, and in view of the ongoing technological evolution of intelligent agents, this paper proposes several promising research directions for intelligent penetration testing. These include multimodal fusion mechanisms, collaborative strategies integrating memory enhancement with reinforcement learning, and knowledge-graph-based vulnerability discovery methods. The analysis indicates that LLM-driven agents for network penetration testing provide substantial technical support for advancing the intelligence and autonomy of cybersecurity operations.
    Reference | Related Articles | Metrics
    SAFE-SCVDM: Sequence Feature-Enhanced Smart Contract Vulnerability Detection Model
    Journal of Information Security Reserach    2026, 12 (9): 842-849.   DOI: 10.12379/j.issn.2096-1057.2026.09.07
    Abstract68)      PDF (943KB)(9)       Save
    Aiming at the insufficient integration of local features and global features in existing smart contract vulnerability detection methods, as well as inadequate modeling of code contextual dependencies, this paper proposes a sequence feature-enhanced vulnerability detection model for smart contracts-SAFE-SCVDM. The model innovatively integrates multi-dimensional code representations through a three-stage feature extraction architecture to improve detection accuracy. First, we design a structured traversal based transformation strategy for abstract syntax trees , converting AST into sequential structures that preserve lexical and hierarchical features. Second, a node extraction script is developed to mine token-level information from smart contract code, retaining semantic characteristics. Subsequently, global contextual dependencies are captured by leveraging a large-scale code model to generate code comments from source code, thereby preserving cross-function semantic relationships. Finally, an enhanced LoRA detection model is proposed, utilizing a self-attention mechanism to jointly model textual sequences (code tokens), structural sequences (SBT-AST), and global annotations (code comments). Experimental results demonstrate that the proposed method achieves an accuracy of 88.41% in smart contract vulnerability detection, outperforming state-of-the-art baseline models by 9.8%.
    Reference | Related Articles | Metrics
    A Review of Adversarial Attack on Autonomous Driving Perception System
    Journal of Information Security Reserach    2024, 10 (9): 786-.  
    Abstract639)      PDF (1560KB)(325)       Save
    The autonomous driving perception system collects surrounding environmental information through various sensors and processes this data to detect vehicles, pedestrians and obstacles, providing realtime foundational data for subsequent control and decisionmaking functions. Since sensors are directly connected to the external environment and often lack the ability to discern the credibility of inputs, the perception systems are  potential targets for various attacks. Among these, adversarial example attack is a mainstream attack method characterized by high concealment and harm. Attackers manipulate or forge input data of the perception system to deceive the perception algorithms, leading to incorrect output results by the system. Based on the research of existing relevant literature, this paper systematically summarizes the working methods of the autonomous driving perception system, analyzes the adversarial example attack schemes and defense strategies targeting the perception system. In particular, this paper subdivide the adversarial examples for the autonomous driving perception system into signalbased adversarial example attack scheme and objectbased adversarial example attack scheme. Additionally, the paper comprehensively discusses defense strategy of the adversarial example attack for the perception system, and subdivide it into anomaly detection, model defense, and physical defense. Finally, this paper prospects the future research directions of adversarial example attack targeting autonomous driving perception systems.
    Reference | Related Articles | Metrics
    A LTE NAS Protocol Fuzzing Method Based on Weighted State Selection
    Journal of Information Security Reserach    2025, 11 (1): 12-.  
    Abstract197)      PDF (1581KB)(60)       Save
    NAS protocol is the main control plane protocol between mobile devices and LTE core network, and its security is of great significance to ensure the robustness and safety of the whole 4G network. Fuzz testing is a widely used vulnerability mining technique, and existing fuzz testing methods for NAS Protocol have problems such as low testing efficiency and difficulty test case formulation. In order to solve these problems, this paper e proposes a weight based test state selection algorithm, which is based on NAS protocol state machine and can dynamically adjust the weight of test states based on feedback; Additionally, this paper devises a test case generation strategy rooted in the information element and develops the fuzzing tool named NASFuzzer, which is tested on open source core networks open5GS and real terminal devices. The test result shows that the method in this paper can effectively find the vulnerabilities in the LTE NAS protocol implementation.
    Reference | Related Articles | Metrics