Most Download articles

    Published in last 1 year | In last 2 years| In last 3 years| All| Most Downloaded in Recent Month| Most Downloaded in Recent Year|

    Most Downloaded in Recent Month
    Please wait a minute...
    For Selected: Toggle Thumbnails
    Survey of Software Supply Chain Security Detection and Assessment Technologies
    Journal of Information Security Reserach    2026, 12 (7): 586-597.  
    Abstract114)      PDF (1750KB)(68)       Save
    In the context of the digital era, software supply chain has become a critical component supporting the stable and healthy development of the digital economy. It is an indispensable part of the nation’s key information infrastructure and economic and social systems. The security of software supply chain directly determines the security of the key businesses carried by the software supply chain. Therefore, based on the development needs of the digital age, this article summarizes the current technologies, methods, and development trends related to software supply chain security detection and evaluation, providing reference and guidance for industry insiders, researchers, and decisionmakers. It includes a review and detailed explanation of the background and methods of software supply chain security detection and evaluation technology, detailing the principles of mainstream technologies such as component analysis, vulnerability scanning, code review, runtime monitoring, threat modeling, and fuzz testing, and comparing and analyzing the advantages and disadvantages of various technologies; Analyze the current technical challenges and countermeasures faced by technology; And propose ten major trends for the development of this field in the next decade, in order to improve the security level of the software supply chain and promote the development of the software industry.
    Reference | Related Articles | Metrics
    The Mechanism of Disinformation Generation and Governance Pathways in Generative AI Models
    Journal of Information Security Reserach    2026, 12 (7): 606-612.  
    Abstract74)      PDF (1256KB)(31)       Save
    While driving transformations in online information order, generative AI models also generate disinformation risks characterized by an “objective+subjective” overlap. An analytical framework tailored to their technical characteristics is urgently needed. This study systematically deconstructs the technical logic of false information production in generative AI models based on their hybrid expert architecture, treelike reasoning patterns, localized semantic understanding attributes, and opensource ecosystem mechanisms. It analyzes the transmission mechanisms of false information risks across four stages: data input, algorithmic operation, content presentation, and cognitive dissemination. To address these risks: At the algorithmic level, implement a processbased oversight scheme encompassing “access reviewoperation disclosurepostevent verification”; at the presentation level, strengthen scenariobased, interactive “warning notice” labeling mechanisms; at the cognitive level, cultivate users' digital literacy and selfrestraintt capabilities to achieve effective information security governance in the AI era.
    Reference | Related Articles | Metrics
    Overview on SM9 Identity Based Cryptographic Algorithm
    Journal of Information Security Research    2016, 2 (11): 1008-1027.  
    Abstract3770)      PDF (13949KB)(6264)       Save
    SM9 identitybased cryptographic algorithm is an identitybased cryptosystem with bilinear pairings. In such a system the user s private key and public key may be extracted from user s identity and key generation centers parameters. The most common cryptographic uses of SM9 are with digital signature, data encryption, key exchange protocol and key encapsulation mechanism etc. The application and management of SM9 will not require digital certificate, certificate base, and key base. The key length of the SM9 cipher algorithm is 256b. SM9 cryptographic algorithm was issued as the cryptography standard in 2015. This paper will summarize the design, algorithm, software and hardware implementation and cryptanalysis of SM9 cryptographic algorithm. We also give some concrete examples in appendix.
    Reference | Related Articles | Metrics
    A Deep Learning Differential Privacy Protection Scheme Based on  Adaptive Clipping
    Journal of Information Security Reserach    2026, 12 (6): 490-.  
    Abstract170)      PDF (1728KB)(103)       Save
    To address the issues of utility degradation in deep learning models under differential privacy protection and the gap between theoretical and actual privacy protection effectiveness, this paper proposes a deep learning differential privacy protection scheme based on adaptive clipping. The scheme optimizes the process through a fourstep mechanism: firstly, gradient adaptive clipping controls the gradient magnitude during training by dynamically adjusting the gradient clipping threshold, thereby enabling the control of the magnitude of noise added subsequently; secondly, group label selection identifies the group with the smallest gradient as the privacypreserving object, and more accurate privacy loss can be obtained by training this group; thirdly, optimized privacy loss calculation combines the gaussian mechanism based on subsampling to reduce the computational overhead of model privacy loss calculation; finally, optimized gradient adaptive descent realizes the adaptive descent of gradients by adjusting the conditional smoothing parameter, thus improving the usability of the model. Experiments were conducted on the VGG architecture using the MNIST, CIFAR10, and MedicalMNIST datasets. The results show that the model accuracy rates after training with this scheme are 81.08%, 72.30%, and 67.91% respectively, representing improvements of 15.60%, 10.60%, and 9.71% compared to the traditional DPSGD, and 0.63%, 2.50%, and 4.40% over the widely used Nadam algorithm in recent years. The model training efficiency has been improved by 35.5% and 39.4%, respectively.
    Reference | Related Articles | Metrics
    Research of Threat Intelligence Sharing and Using for Cyber Attack Attribution
    Yang Zeming, Li Qiang, Liu Junrong, and Liu Baoxu
    Journal of Information Security Research    2015, 1 (1): 31-36.  
    Abstract1160)      PDF (5527KB)(1643)       Save
    With the increasingly complexity of cyberspace security, the attack attribution has become an important challenge for the security protection system. The emergence of threat intelligence provided plentiful data source support for the attack attribution, which makes large-scale attack attribution became possible. To realize effective attack attribution, based on the structure expression of the threat information, a light weight framework of threat intelligence sharing and utilization was proposed. It included threat intelligence expression, exchange and utilization, which can achieve the attack attribution result. Take the case of C2 relevant information, we described the expression of threat intelligence sharing and utilization, and verified the framework. Results show that the framework is practical, and can provide new technical means for attack attribution. In addition, based on the understanding of threat intelligence, several thinking about the construction of sharing and utilization mechanisms were promoted in the end.
    Related Articles | Metrics
    Dynamic Searchable Encryption Scheme Supporting Fuzzy Multiple Keywords
    Journal of Information Security Reserach    2024, 10 (11): 1064-.  
    Abstract266)      PDF (2035KB)(98)       Save
    With the development of cloud computing, the convenience and costeffectiveness of cloud storage have caused a large number of users to store personal data on thirdparty cloud servers. While encrypted storage of data in the cloud ensures data security, it also introduces challenges in data retrieval. Dynamic symmetric searchable encryption technology emerged as the times require, which not only effectively protects data privacy but also enables multikeyword joint search functions. Additionally, the fuzzy search introduced by this technology in practical applications enhances the user’s search experience and improves search efficiency. However, the current searchable encryption schemes that supports fuzzy search has certain security risks and do not adequately address potential information leakage issues during dynamic updates. To tacklethese issues, this paper proposes a dynamic searchable encryption scheme that supports fuzzy multikeywords, ensuring information security during dynamic updates, and also supporting multikeyword joint search and fuzzy search. This scheme designs a keyword encoding algorithm and localitysensitive hash function to build a fuzzy index, and uses a Bloom filter encryption algorithm to encrypt the index to achieve fuzzy search. Furthermore, a trusted execution environment is introduced to reduce the communication overhead and computing overhead as well as the number of interactions between users and servers. Finally, the safety and effectiveness of this scheme were verified through experiments.
    Reference | Related Articles | Metrics
    A Deep Learningbased Method for Background Traffic Generation in Railway Cyber Range
    Journal of Information Security Reserach    2026, 12 (7): 613-624.  
    Abstract58)      PDF (2996KB)(22)       Save
    Cybersecurity threats have permeated all aspects of the railway industry, necessitating that railway cybersecurity ranges keep pace with the latest security demands. Background traffic is a core element in constructing a realistic simulation environment for cyber ranges and serves as a critical technology supporting range operations. However, effectively capturing the complex spatiotemporal characteristics of network traffic and generating highfidelity background traffic remains a significant challenge. This paper proposes a novel method for generating background traffic in railway cyber ranges (referred to as B2Diff). By integrating deep learning techniques such as BERT, bidirectional long shortterm memory networks, and diffusion models, the method captures features such as contextual semantics, spatiotemporal dependencies, and complex traffic distributions in traffic samples, thereby generating highly realistic and diverse background traffic. Experimental results demonstrate that B2Diff significantly outperforms existing methods in terms of the quality and diversity of the generated background traffic, validating its effectiveness in enhancing the simulation realism of cyber ranges.
    Reference | Related Articles | Metrics
    Interactive Dynamic Privacy Risk Assessment and Adaptive Protection Methods in Data Publishing
    Journal of Information Security Reserach    2026, 12 (7): 598-605.  
    Abstract58)      PDF (1786KB)(21)       Save
    Data publishing is an important way to promote data sharing. However, studies have shown that it is accompanied by the risk of privacy leakage of sensitive attribute information due to large and frequent access to data by malicious parties. Although existing evaluation methods consider the scenarios of above issue, most of them are noninteractive and static settings. Therefore, in practical applications, dynamic risk cannot be accurately assessed by data publishers, and even the noise protection causes an imbalance between privacy and utility. In this paper, we propose an interactive dynamic privacy risk assessment and adaptive protection method. It firstly utilizes machine learning prediction models to determine the privacy level of difficulttodefine attributes. And secondly we sets a mechanism to dynamically adjust the privacy level according to the actual requests of the data demander and timely restricts the leakage of sensitive attribute caused by highfrequency access. Finally, an adaptive noiseadding mechanism is proposed after obtaining the high risk of evaluation feedback, to ensure that the balance of privacy and utility achieveing good results when the data is released. Experimental results show that the privacy risk index increases gradually with the number of accesses and the accesses containing associated attributes lead to an increase in the privacy risk index by more than 15%. Adaptive noise addition, on the other hand, provides a similar level of privacy protection to overall noise addition at 0.5, yet improves data utility by more than 30% over overall noise addition.
    Reference | Related Articles | Metrics
    Research on Smart Contract Vulnerability Detection Method Based on  Multimodal Feature Fusion
    Journal of Information Security Reserach    2026, 12 (6): 503-.  
    Abstract88)      PDF (1602KB)(59)       Save
    Most of the smart contract vulnerability detection methods rely on single mode feature extraction, which leads to the problem of low detection accuracy due to insufficient key feature extraction. This paper proposes a smart contract vulnerability detection method based on multimodal feature fusion. Firstly, the construction of the control flow graph (CFG) is constructed by leveraging the abstract syntax tree (AST) trimmed at the source code layer and the data flow relationship based on the opcode layer, which is imported into the graph attention network (GAT) to extract two types of static features. Secondly, the fuzzing test report generated by echidna, a dynamic detection tool, is used to extract path coverage, state changes and other information to build a graph model, and the dynamic features are extracted by graph neural network (GNN). Finally, the extracted static and dynamic features are fused and input into CNN bilstm att model for vulnerability detection, and relevant experiments are carried out on 47398 smart contracts. Experimental results show that compared with eight mainstream detection methods, such as SmartCheck, Mythril, Oyente, BiGGNN, ASTNN, DRGCN, SVCB and CBGRU, the accuracy, recall and F1 value of this method in reentry vulnerability, timestamp vulnerability, integer overflow vulnerability and Tx.origin vulnerability are increased by 50.26%, 59.54% and 58.40%.
    Reference | Related Articles | Metrics
    Overview on Public Key Crytographic Algorithm SM2 Based on Elliptic Curves
    Journal of Information Security Research    2016, 2 (11): 972-982.  
    Abstract1803)      PDF (7813KB)(991)       Save
    Public key cryptographic algorithm SM2 based on elliptic curves (SM2 algorithm for abbreviation) was firstly issued in December 2010, had become the Chinese commercial cryptographic standard (GMT 0003—2012) in 2012, and had become the Chinese national cryptographic standard (GBT 32918—2016) in 2016. This paper briefly describe the development background of SM2 algorithm,describe SM2 algorithm in details,introduce the researches on its security, and evaluate its implementation efficiencies. All the researches on SM2 algorithm so far indicate that the provable securities of SM2 algorithm reach the supreme levels of public key cryptographic algorithms securities, and its implementation efficiencies are equivalent to or slightly superior to those similar elliptic curve cryptographic algorithms in some international standards.
    Reference | Related Articles | Metrics
    VEDA, Establishing the AI Dynamic Defense System for Cyber Security
    Journal of Information Security Research    2017, 3 (12): 1058-1066.  
    Abstract446)      PDF (1526KB)(984)       Save
    Related Articles | Metrics
    Application of Network Security Situational Awareness Platform Based on Big Data in the Field of Private Network
    Journal of Information Security Research    2019, 5 (2): 168-175.  
    Abstract270)      PDF (1678KB)(561)       Save
    In order to improve the information security defense capability of the private network, the institutions with private network pay more and more attention to the information network security situational perception technology to realize the prediction and prevention of security events. Based on the brief introduction of situational awareness and related technologies, this paper puts forward a set of applicable network security situational awareness functional architecture targeting industryspecific network needs. This paper details the functional elements contained in each system from the functional level, which would provide reference for relevant institutions to build a network security situational awareness platforms.
    Reference | Related Articles | Metrics
    A Survey of Research on Network Attack Model
    Journal of Information Security Research    2020, 6 (12): 1058-1067.  
    Abstract1457)      PDF (1774KB)(1205)       Save
    With the rapid development of information technology, network attacks have gradually presented multi-stage, distributed and intelligent characteristics. Single firewalls, intrusion detection systems and other traditional network defense measures cannot well protect the network system security in an open environment. As a kind of attack scene representation from the attacker's perspective, the network attack model can comprehensively describe the network attack behavior in a complex and changeable environment, and is one of the commonly used network attack analysis and response tools. This paper first introduces the current main network attack models, including traditional trees, graphs, nets structure models and modern attack chains, ATT&CK, diamond models, etc. Then the analysis and application of network attack model will be explained. The analysis process for the purpose of solving the attack index mainly includes the probability framework, the assignment method and the solution method, and the application of the attack model based on the life cycle includes the application of the attackers and the defenders' perspective; Finally, the current challenges and future directions of the network attack model and its analysis and application are summarized.
    Reference | Related Articles | Metrics
    Research on AIempowered Cybersecurity Detection and  Assessment Technologies
    Journal of Information Security Reserach    2026, 12 (6): 559-.  
    Abstract107)      PDF (1820KB)(64)       Save
    In response to the challenges faced by traditional cybersecurity detection and assessment technologies—such as large system scales, dynamic supply chain risks, and insufficient evaluation depth—this paper explores the application of AI technologie to advance this field. Methodologically, an endtoend implementation framework for largescale models is proposed, consisting of “data preparationdistillation and annotationcluster trainingquantitative deployment.” A localized compliance assessment model based on retrievalaugmented generation (RAG) technology is developed, and a multimodal model supporting joint textimage analysis is deployed. The large model significantly shortens the assessment cycle in scenarios such as provincial government clouds, improves the efficiency of compliance knowledge matching while reducing computational load by 70%, and markedly enhances the detection rate of inherent defects. The conclusion indicates that AI technology can effectively overcome the limitations of traditional assessment methods, promoting cybersecurity detection and assessment toward greater intelligence, adaptability, and comprehensiveness, thereby providing support for building resilient cybersecurity protection systems and fostering related ecosystem development.
    Reference | Related Articles | Metrics
    Deepfake Face Detection Method Based on Multiloss Fusion
    Journal of Information Security Reserach    2026, 12 (7): 634-643.  
    Abstract44)      PDF (2942KB)(14)       Save
    Most existing deepfake face detection methods rely on specific forgery patterns, such as noise artifacts or local textures, making them highly dependent on known forged features and lacking generalization to unknown forgeries. To address this issue, this paper proposes a multiloss fusion detection framework based on the reconstructionclassification learning(RECCE) network. A prototype similarity mechanism is introduced to measure the distance between sample features and class prototypes, enhancing the model’s ability to detect unknown forgeries. A joint loss function combining prototype loss, binary crossentropy loss, reconstruction loss, and metric learning loss is designed to strengthen feature learning from multiple perspectives. Moreover, multilevel encoder features are fused, and a reconstructionguided attention mechanism focuses the model on forged regions rather than the entire face, improving robustness and accuracy. Experiments conducted on several benchmark datasets and compared with six stateoftheart methods demonstrate significant improvements: training time is reduced to 28% of the original model, and the AUC increases by 1.48% in crossdomain evaluation when trained on FaceForensics++ (c40) and tested on CelebDF. The results verify the superior performance and generalization ability of the proposed method.
    Reference | Related Articles | Metrics
    PeopleNet, Independently Developing Core Technology of Cyber Information Security
    Journal of Information Security Research    2017, 3 (7): 578-588.  
    Abstract452)      PDF (1448KB)(863)       Save
    Related Articles | Metrics
    Multidomain Fake News Detection Model Based on Prompt Learning and Fuzzy Labels
    Journal of Information Security Reserach    2026, 12 (7): 625-633.  
    Abstract55)      PDF (1230KB)(13)       Save
    The widespread popularity of the Internet and intelligent devices has provided convenience for the public to access news. However, this also creates a breeding ground for the generation and propagation of fake news. Fake news spans multiple domains, whereas existing detection models often overlook the specificity of corpora across different domains, limiting their accuracy. To adress this issue, this paper proposes a multidomain fake news detection model based on prompt learning and fuzzy labels. This model employs RoBERTa to extract textual features and reformulates the detection task as a cloze problem by constructing prompt templates containing domain characteristics; meanwhile, it utilizes domain fuzzy membership probabilities generated by a neural network to guide the prompt learning process, effectively enhancing accuracy and generalization ability. Experimental results on the public datasets Weibo17 and Weibo21 demonstrate that this model outperforms traditional finetuning methods and existing stateoftheart methods under both domainunlabeled and multidomain conditions, with an average F1 score improvement of 1.16 percentage points, validating its feasibility and effectiveness in multidomain fake news detection tasks.
    Reference | Related Articles | Metrics
    Image Steganography Model Based on Improved Generative Adversarial Network and Selfdistillation
    Journal of Information Security Reserach    2026, 12 (7): 652-661.  
    Abstract45)      PDF (2835KB)(13)       Save
    Existing image steganography methods have made significant progress in concealment and antiattack capabilities, but still suffer from low image quality, limited information embedding capacity, and insufficient model stability and generalization ability. To address these issues, this paper proposes an image steganography model based on an improved GAN and selfdistillation (RCSDGAN). First, a residualchannel attention mechanism is designed and integrated into the DenseNet architecture to optimize its structure. Second, an encoding network and decoding network based on the enhanced DenseNet are constructed, combined with a discriminative network to form a complete image steganography framework. Finally, a selfdistillation training strategy is introduced. The selfdistillation loss is defined by calculating the difference between the teacher model’s output and the student model’s output from the same network, and this loss is incorporated into the overall loss function to enhance model stability and generalization capability. Experimental results demonstrate that, at an embedding rate of D=1bpp, the steganographic images achieve a PSNR of 50.4131dB, an SSIM of 0.9992, and an Accuracy of 99.96%.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E2): 2-.  
    Abstract68)      PDF (1416KB)(55)       Save
    Reference | Related Articles | Metrics
    DBAPPSecurity:Support Security China, Boost Digital Economy
    Journal of Information Security Research    2019, 5 (4): 274-281.  
    Abstract204)      PDF (3884KB)(814)       Save
    Related Articles | Metrics
    Research on Maintenance and Security of Industrial Control Networks in Electric Power Industry
    Journal of Information Security Research    2019, 5 (8): 679-684.  
    Abstract263)      PDF (2038KB)(692)       Save
    As an important part of national key infrastructure, the importance of operation and maintenance security of electric power industry control network is selfevident. Especially with the increasing security incidents of industrial control networks in the world in recent years, effective measures must be taken to protect the safe operation of industrial control networks, which also puts forward higher requirements for the operation, maintenance and safety protection of industrial control networks and industrial systems. Through indepth analysis of the characteristics of industrial control network in electric power industry, especially the key characteristics of the data type and network topology structure of the electric power network, effective operation and maintenance methods and security risk prevention methods are put forward. In operation and maintenance, the backup of system data and the state monitoring of the system itself are strengthened. Security measures, such as physical isolation, industrial control flow monitoring, fault recovery management and so on should be taken, and effective policies and behavioral norms should be provided. Finally, form safety protection measures suitable for electric power industry control network, to achieve the purpose of safe operation of the electric power industry control network.
    Reference | Related Articles | Metrics
     A Survey of Forensic Network Attack Source Traceback
    Journal of Information Security Reserach    2024, 10 (4): 302-.  
    Abstract373)      PDF (1134KB)(258)       Save
    The concealment and anonymity of cyber attackers pose significant challenges to the field of network attack traceback. This study provides a comprehensive overview of the current state of research on network attack traceback analysis techniques, focusing on three aspects: traffic, scenarios, and samples. Firstly, with respect to traffic traceback, the paper outlines methods and applications based on log records, packet marking, ICMP tracing, and link testing. Secondly, it categorizes traceback techniques for different scenarios, encompassinganonymous networks, zombie networks, springboards, local area networks, and advanced persistent threat attacks, as well as their applications and limitations in realworld environments. Finally, concerning sample analysis, the paper discusses the progress and application scenarios of static and dynamic traceback analysis in the context of malicious code analysis and attack tracing.
    Reference | Related Articles | Metrics
    Research on ECDSA Key Recovery Attacks Based on the Extended  Hidden Number Problem
    Journal of Information Security Reserach    2026, 12 (2): 174-.  
    Abstract101)      PDF (797KB)(59)       Save
    Elliptic curve digital signature algorithm (ECDSA) is one of the most widely used digital signature algorithms. During the signing process, it requires computing scalar multiplication on elliptic curves, which is typically the most timeconsuming component of the signature. In many present cryptographic libraries, the windowed nonadjacent form representation is commonly used to represent the ephemeral key in order to reduce time consumption. This exposes sidechannel vulnerability to malicious attackers, allowing them to extract partial information about the ephemeral key from sidechannel traces and subsequently recover the signing key. Leveraging the extended hidden number problem to extract information from sidechannel traces and applying latticebased attacks to recover keys constitutes one of the mainstream attack frameworks against ECDSA. Based on above, we propose three optimization methods. First, we introduce a neighboring dynamic constraint merge strategy. By dynamically adjusting the merging parameters, we reduce the dimension of the lattice and control the amount of known information lost during the attack, ensuring high success rates for key recovery across all signatures. Second, we analyze and optimize the embedding number in the lattice, reducing the Euclidean norm of the target vector by approximately 8%, thereby improving the success rate and reducing time consumption. Finally, we propose a linear predicate method which significantly reduces the time overhead of the lattice sieving. In this work, we achieve a success rate of 0.99 in recovering the private key using only two signatures.
    Reference | Related Articles | Metrics
    Dynamic Invisible Backdoor Attack via Frequency Domain Injection
    Journal of Information Security Reserach    2026, 12 (6): 510-.  
    Abstract93)      PDF (1536KB)(31)       Save
    Deep neural networks are highly vulnerable to the threat of backdoor attacks due to their noninterpretability and high dependence on data during training. Although the current mainstream backdoor attack methods generally use fixed trigger design to simplify implementation, these triggers are often significantly different from the training data distribution, resulting in easy detection and identification. To this end, this paper proposes a dynamic invisible backdoor attack method via frequency domain injection: firstly, a generative network is used to generate a specific trigger pattern based on the input samples, and then the highfrequency information of the pattern is injected into the wavelet domain of the samples, ensuring the triggers remain stealthy. Additionally, this paper designs a fair screening strategy to select samples that are more influential to the backdoor model through cosine similarity and Kmeans clustering algorithm. Experimental results show that this method outperforms existing methods (e.g., BadNets, Blend, WaNet, and WABA) in terms of attack success rate and stealthiness, and effectively circumvents a variety of stateoftheart defence mechanisms (e.g., FP, NC, SentiNet, and SCALEUP), providing significant robustness and extensive practical potential.
    Reference | Related Articles | Metrics
    Semantics Based Webshell Detection Method Research
    Journal of Information Security Research    2017, 3 (2): 145-150.  
    Abstract510)      PDF (4585KB)(655)       Save
    A semanticsbased Webshell detection method was proposed. This method obtained the code behavior and related dependencies by syntax analysis of the file, and achieved semantic understanding to complete the Webshell detection by the risk model. A critical abstract syntax subtree extraction method which can reject irrelevant factor and get the malicious behavior occurrence point was proposed. The description of behavior in risk model database was defined with BackusNaur Form, finally a smooth risk value curve could be obtained by graph matching algorithm, which can finish the criticality assessment of the file and can get a better result by adjusting the threshold A webshell detection system based on that detection method was designed and finished, the experimental results have demonstrated that the SemanticsBased method was effective in Webshell detection.
    Reference | Related Articles | Metrics
    Remote Office Solution and Its Application Based on Secure Instant Messaging Technology
    Journal of Information Security Research    2020, 6 (4): 301-310.  
    Abstract212)      PDF (3086KB)(399)       Save
    Remote office is getting more and more favored by users for its characteristics of unconstrained time and space, high-efficiency and convenience, fragmentation time utilization and so on, but it also raised a lot of security problems. This article systematically introduces a security solution for remote office and its innovative applications. Based on the secure instant messaging architecture of interconnection and interworking, it realizes vertical security support and application aggregation, as well as horizontal data sharing and application collaboration through open aggregation interfaces. Therefore an remote office ecosystem is built. The solution has been widely used in sectors such as government, military, finance and energy, providing a security application solution to meet the requirements of relevant national standards for the high-security users’ remote office.
    Reference | Related Articles | Metrics
    Flow Anomaly Detection Based on Hierarchical Clustering Method
    Journal of Information Security Research    2020, 6 (6): 0-0.  
    Abstract1302)      PDF (1784KB)(718)       Save
    With the advent of the big data era, the attacks in network traffic are rising dramatically. Detecting malicious traffic through abnormal flow detection is vital. Nowadays, the equipment of abnormal flow detection used in industry mainly adopts statistical analysis method or simple machine learning method. However, the amount of flow data and redundant data is large. The precision rate is low and the false alarm rate is high. In order to solve these problems, this paper presents a new method to detect flow anomalies based on hierarchical clustering in data processing. This method first uses the hierarchical clustering algorithm to achieve the purpose of data reduction. Then based on seven different machine learning algorithms, an abnormal traffic model based on hierarchical clustering is constructed. The experimental results show that this method can detect the abnormal behavior on the DARPA dataset with a precision rate of 99% and a recall rate of 99%. At the same time, while maintaining the precision rate of 90%, the data reduction can be up to 47.58%, which greatly improves the detection efficiency.
    Related Articles | Metrics
    Research Review on Collaborative Intrusion Detection Based on Federated Learning
    Journal of Information Security Reserach    2026, 12 (6): 526-.  
    Abstract120)      PDF (1168KB)(45)       Save
    The increasing complexity of cyber attacks challenges traditional centralized intrusion detection systems. Federated learningbased collaborative intrusion detection enables collaborative modeling and knowledge sharing among multiple nodes without sharing raw data, thereby effectively improving the detection capability for crossdomain and unknown attacks. This paper systematically reviews the research progress of federated learningbased collaborative intrusion detection. Existing methods are classified and analyzed from multiple perspectives, including architectureaware, model adaptation and evolutiondriven, as well as privacy and security enhanced approaches. Commonly used datasets and evaluation metrics are summarized. Finally, the major challenges and future research directions are discussed, providing references for subsequent research in this field.
    Reference | Related Articles | Metrics
    Chinese Dark Web Product Detection and Classification Based on  Multimodal Data Augmentation#br#
    Journal of Information Security Reserach    2026, 12 (6): 575-.  
    Abstract74)      PDF (4502KB)(30)       Save
    In order to address the issues of coarse granularity in existing dark Web intelligence classification research and the predominance of Englishlanguage datasets, this paper proposes a finegrained analysis study focused on Chinese dark Web content. To overcome the scarcity of Chinese dark Web data and the misalignment of multimodal data, this study employs a large language model prompt rewriting strategy and a differentiated image enhancement strategy to achieve text and image data augmentation. By integrating product data from a certain platform on the Surface Web, a dataset comprising 14,052 product records was constructed. A feature selection optimization module was designed to establish an intertask coupling mechanism, and a Chinese dark Web product detection and classification model based on multimodal data augmentation was proposed. Experimental results demonstrate that the proposed model achieves macroF1 scores of 0.992 and 0.941 in dark Web product detection and classification tasks, respectively, representing an approximately 2% improvement over the best baseline model in  classification task and significantly outperforming existing singlemodal and multimodal methods. This approach effectively enhances the performance of finegrained classification tasks for Chinese dark Web intelligence, offering new insights and methodologies for dark Web intelligence analysis.
    Reference | Related Articles | Metrics
    Advanced Persistent Threat Detection Based on Generative Subgraph Contrastive Autoencoder
    Journal of Information Security Reserach    2026, 12 (7): 672-680.  
    Abstract39)      PDF (2020KB)(10)       Save
    With the increasing sophistication and stealth of cyber attacks, particularly the continuous evolution of advanced persistent threats (APT) targeting critical information infrastructure, which are characterized by high concealment and longterm persistence, accurately distinguishing intrusions from normal behavior has become a critical challenge. Provenancebased intrusion detection systems can capture finegrained causal relationships among system entities, demonstrating strong advantages in distinguishing benign from malicious behaviors and uncovering stealthy attacks. However, existing learningbased approaches still suffer from the absence of proper node weighting, insufficient utilization of edge features, and inadequate learning of local subgraph structures, while also facing high computational costs when applied to largescale datasets. To address these limitations, we propose GSCAE, a novel APT detection framework based on a Generative Subgraph Contrastive Autoencoder. First, we construct node representations by integrating edge interaction features with local clustering coefficients and compute node importance using the entropy weight method. Then, we design a generative subgraph contrastive learning algorithm that jointly incorporates edgelevel and topological losses to more effectively learn local structures and interaction patterns. Finally, the learned graph embeddings are fed into a lightweight node classifier to perform anomaly detection, achieving a balance between detection accuracy and computational efficiency. Experiments conducted on the DARPA public dataset demonstrate that GSCAE outperforms most existing learningbased approaches in both accuracy and efficiency, validating its effectiveness and practicality in complex host environments.
    Reference | Related Articles | Metrics
    Evidence Extraction of USB Storage Device Accessing Traces under the Windows 7 System
    Journal of Information Security Research    2016, 2 (4): 333-338.  
    Abstract433)      PDF (5162KB)(870)       Save
    With the rapid development and popularization of computer technology, cyber crimes come one after another,there are a lot of computer evidences existing in the USB storage device. When USB storage device has access to computers, registry keys and computer log will record the accessing traces. Therefore, computer forensic investigators can accordingly confirm which USB device has connected to the computer at what time. This paper introduces the position of accessing traces and extraction methods, providing great support and help for certain evidence factors in judicial activities.
    Reference | Related Articles | Metrics
    Research on Source Code Vulnerability Detection Based on BERT Model
    Journal of Information Security Reserach    2024, 10 (4): 294-.  
    Abstract491)      PDF (3199KB)(308)       Save
    Techniques such as code metrics, machine learning, and deep learning are commonly employed in source code vulnerability detection. However, these techniques have problems, such as their inability to retain the syntactic and semantic information of the source code and the requirement of extensive expert knowledge to define vulnerability features. To cope with the problems of existing techniques, this paper proposed a source code vulnerability detection model based on BERT(bidirectional encoder representations from transformers) model. The model splits the source code to be detected into multiple small samples, converted each small sample into the form of approximate natural language, realized the automatic extraction of vulnerability features in the source code through the BERT model, and then trained a vulnerability classifier with good performance to realize the detection of multiple types of vulnerabilities in Python language. The model achieved an average detection accuracy of 99.2%, precision of 97.2%, recall of 96.2%, and an F1 score of 96.7% across various vulnerability types. This represents a performance improvement of 2% to 14% over existing vulnerability detection methods. The experimental results showed that the model was a general, lightweight and scalable vulnerability detection method.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E2): 89-.  
    Abstract121)      PDF (1508KB)(66)       Save
    Reference | Related Articles | Metrics
    A Unified Distributionpreserving Residual Watermark Embedding Method for Diffusion Models
    Journal of Information Security Reserach    2026, 12 (7): 662-671.  
    Abstract43)      PDF (2733KB)(9)       Save
    Aiming at the challenge that diffusion model watermarking can hardly achieve both generation quality preservation and antidistortion robustness, this paper proposes a unified distributionpreserving residual embedding method. Without modifying the diffusion backbone parameters, the proposed method adopts a twostage strategy. First, latent variables are mapped to a uniform distribution using the cumulative distribution function of the Gaussian distribution, and watermark bits are embedded via interval partitioning and inverse mapping, ensuring that the latent distribution remains unchanged. Second, a lightweight residual module is inserted into the midblock of the UNet, where watermark bits are projected and injected into feature maps. Only this module is trained, achieving watermark embedding with minimal extremely small perturbations. The training phase jointly optimizes diffusion reconstruction loss and watermark prediction loss. Experiments on Stable Diffusion 2.1 demonstrate that the method maintains high visual fidelity of watermarked images, and the perturbation amplitude is far below the perceptual threshold. Under various distortions scenarios including JPEG compression, cropping, Gaussian noise, brightness and contrast adjustments, color quantization, and Diffwa(diffusion models for watermark attack) reconstruction, bit accuracy consistently exceeds 90%. Particularly, nearperfect accuracy is achieved under distortionfree and Diffwa reconstruction conditions, effectively balancing generation quality and robustness.
    Reference | Related Articles | Metrics
    The ZUC Stream Cipher Algorithm
    Journal of Information Security Research    2016, 2 (11): 1028-1041.  
    Abstract1732)      PDF (7769KB)(810)       Save
    祖冲之算法,简称ZUC,是一个面向字设计的序列密码算法,其在128b种子密钥和128b初始向量控制下输出32b的密钥字流.祖冲之算法于2011年9月被3GPP LTE采纳为国际加密标准(标准号为TS 35.221),即第4代移动通信加密标准,2012年3月被发布为国家密码行业标准(标准号为GMT 0001—2012),2016年10月被发布为国家标准(标准号为GBT 33133—2016).简单介绍了祖冲之算法,并总结了其设计思想和国内外对该算法安全性分析的主要进展.
    Reference | Related Articles | Metrics
    Differential Privacy and Applications
    Journal of Information Security Research    2015, 1 (3): 224-229.  
    Abstract1268)      PDF (5750KB)(1266)       Save
    As the emergence and development of application requirements such as data analysis and data publication, a challenge to those applications is to protect private data and prevent sensitive information from disclosure. With the highspeed development of information and network, big data has become a hot topic in both the academic and industrial research, which is regarded as a new revolution in the field of information technology. However, it brings about not only significant economic and social benefits, but also great risks and challenges to individuals` privacy protection and data security. People on the Internet leave many data footprint with cumulatively and relevance. Personal privacy information can be found by gathering data footprint in together.Malicious people use this information for fraud. It brings many trouble or economic loss to personal life.Privacy preserving, especially in data release and data mining, is a hot topic in the information security field. Differential privacy has grown rapidly recently due to its rigid and provable privacy guarantee. We analyze the advantage of differential privacy model relative to the traditional ones, and review other applications of differential privacy in various fields and discuss the future research directions. Following the comprehensive comparison and analysis of existing works, future research directions are put forward.
    Reference | Related Articles | Metrics
    Security Architecture and Key Technologies of Blockchain
    Yan Zhu
    Journal of Information Security Research    2016, 2 (12): 1090-1097.  
    Abstract1251)      PDF (6838KB)(859)       Save
    Blockchain, both the cryptocurrency and the underlying Bitcoin technology, have attracted significant attention around the world. The reason is that blockchain is a decentralization technology with Consensus Trust Mechanism (CTM), which is obviously different from the traditional centralization system with Outer Trust Mechanism (OTM). This has made a great influence on the trust mechanism of people and promoted the usage of security technology in the blockchain. In this paper, we present the security architecture and key technologies of the blockchain, and explain how the blockchain ensure the integrity, non repudiation, privacy, consistency for the stored data through P2P network, distributed ledger, asymmetric encryption, consensus mechanism and smart contracts. Moreover, we analyze some new security threats and measures, for example, the preventing technology of Denial of Service (DoS) attack against the Transaction Storm (TS), the cryptographic access control (CAC) technology to enhance the data privacy, the key management technology against losing and stealing of digital asset, and so on. We also discuss the future security problems and technologies that might be discovered after the blockchain syncretizes new technologies, including, AI, Big Data, IOT, cloud computing, mobile Internet technologies.
    Reference | Related Articles | Metrics
    Blockchain Technology and Its Prospect of Industrial Application
    Journal of Information Security Research    2017, 3 (3): 200-210.  
    Abstract596)      PDF (9369KB)(397)       Save
    The Blockchain industry is current developing rapidly globally, with a clearer picture of the whole industry chain. The underlying infrastructure and platform, Blockchain applications in different industry segments, and venture capital investment all have sound foundations. The paper introduces the basic concept and work principle of Blockchain, describes the design philosophy, technological application and security issues of the three mainstream Blockchain platforms nowadays (Bitcoin, Ethernet and Hyperledger), and then puts forward a number of potential Blockchain application scenarios in the world. With great attention on Blockchain in terms of industry application, its helpful for Blockchain practices with Design Thinking and IBM Garage. Both in China and around the world, the paper summarizes the status quo of the Blockchain industry development, and outlines its future in general.
    Reference | Related Articles | Metrics
    Building Cyber Security Defense by Trusted Computing 3.0
    Journal of Information Security Research    2017, 3 (4): 290-298.  
    Abstract446)      PDF (1075KB)(2035)       Save
    Related Articles | Metrics
    The Study of Defect Patterns Matching Based on Static Analysis
    Journal of Information Security Research    2018, 4 (4): 359-363.  
    Abstract375)      PDF (1162KB)(520)       Save
    The software defect mode is the model extracted according to the rules, and the summary of the defects that causes errors or improper running results due to some of the same reasons. Checking the defects by using defect patterns matching technology to the code is more efficient and accurate. We optimize the matching method based on the existing defect modes and methods. We can detect the overflow caused by misusing of increment and decrement through code replacement, and the inconformity of data type through the new regular expression matching statement. We make a check test with Cppcheck, and the experimental results verify the feasibility of the method.
    Reference | Related Articles | Metrics