Most Download articles

    Published in last 1 year | In last 2 years| In last 3 years| All| Most Downloaded in Recent Month| Most Downloaded in Recent Year|

    Most Downloaded in Recent Month
    Please wait a minute...
    For Selected: Toggle Thumbnails
    Survey of Software Supply Chain Security Detection and Assessment Technologies
    Journal of Information Security Reserach    2026, 12 (7): 586-597.  
    Abstract110)      PDF (1750KB)(65)       Save
    In the context of the digital era, software supply chain has become a critical component supporting the stable and healthy development of the digital economy. It is an indispensable part of the nation’s key information infrastructure and economic and social systems. The security of software supply chain directly determines the security of the key businesses carried by the software supply chain. Therefore, based on the development needs of the digital age, this article summarizes the current technologies, methods, and development trends related to software supply chain security detection and evaluation, providing reference and guidance for industry insiders, researchers, and decisionmakers. It includes a review and detailed explanation of the background and methods of software supply chain security detection and evaluation technology, detailing the principles of mainstream technologies such as component analysis, vulnerability scanning, code review, runtime monitoring, threat modeling, and fuzz testing, and comparing and analyzing the advantages and disadvantages of various technologies; Analyze the current technical challenges and countermeasures faced by technology; And propose ten major trends for the development of this field in the next decade, in order to improve the security level of the software supply chain and promote the development of the software industry.
    Reference | Related Articles | Metrics
    Overview on SM9 Identity Based Cryptographic Algorithm
    Journal of Information Security Research    2016, 2 (11): 1008-1027.  
    Abstract3768)      PDF (13949KB)(6264)       Save
    SM9 identitybased cryptographic algorithm is an identitybased cryptosystem with bilinear pairings. In such a system the user s private key and public key may be extracted from user s identity and key generation centers parameters. The most common cryptographic uses of SM9 are with digital signature, data encryption, key exchange protocol and key encapsulation mechanism etc. The application and management of SM9 will not require digital certificate, certificate base, and key base. The key length of the SM9 cipher algorithm is 256b. SM9 cryptographic algorithm was issued as the cryptography standard in 2015. This paper will summarize the design, algorithm, software and hardware implementation and cryptanalysis of SM9 cryptographic algorithm. We also give some concrete examples in appendix.
    Reference | Related Articles | Metrics
    A Deep Learning Differential Privacy Protection Scheme Based on  Adaptive Clipping
    Journal of Information Security Reserach    2026, 12 (6): 490-.  
    Abstract168)      PDF (1728KB)(103)       Save
    To address the issues of utility degradation in deep learning models under differential privacy protection and the gap between theoretical and actual privacy protection effectiveness, this paper proposes a deep learning differential privacy protection scheme based on adaptive clipping. The scheme optimizes the process through a fourstep mechanism: firstly, gradient adaptive clipping controls the gradient magnitude during training by dynamically adjusting the gradient clipping threshold, thereby enabling the control of the magnitude of noise added subsequently; secondly, group label selection identifies the group with the smallest gradient as the privacypreserving object, and more accurate privacy loss can be obtained by training this group; thirdly, optimized privacy loss calculation combines the gaussian mechanism based on subsampling to reduce the computational overhead of model privacy loss calculation; finally, optimized gradient adaptive descent realizes the adaptive descent of gradients by adjusting the conditional smoothing parameter, thus improving the usability of the model. Experiments were conducted on the VGG architecture using the MNIST, CIFAR10, and MedicalMNIST datasets. The results show that the model accuracy rates after training with this scheme are 81.08%, 72.30%, and 67.91% respectively, representing improvements of 15.60%, 10.60%, and 9.71% compared to the traditional DPSGD, and 0.63%, 2.50%, and 4.40% over the widely used Nadam algorithm in recent years. The model training efficiency has been improved by 35.5% and 39.4%, respectively.
    Reference | Related Articles | Metrics
    The Mechanism of Disinformation Generation and Governance Pathways in Generative AI Models
    Journal of Information Security Reserach    2026, 12 (7): 606-612.  
    Abstract73)      PDF (1256KB)(28)       Save
    While driving transformations in online information order, generative AI models also generate disinformation risks characterized by an “objective+subjective” overlap. An analytical framework tailored to their technical characteristics is urgently needed. This study systematically deconstructs the technical logic of false information production in generative AI models based on their hybrid expert architecture, treelike reasoning patterns, localized semantic understanding attributes, and opensource ecosystem mechanisms. It analyzes the transmission mechanisms of false information risks across four stages: data input, algorithmic operation, content presentation, and cognitive dissemination. To address these risks: At the algorithmic level, implement a processbased oversight scheme encompassing “access reviewoperation disclosurepostevent verification”; at the presentation level, strengthen scenariobased, interactive “warning notice” labeling mechanisms; at the cognitive level, cultivate users' digital literacy and selfrestraintt capabilities to achieve effective information security governance in the AI era.
    Reference | Related Articles | Metrics
    Research of Threat Intelligence Sharing and Using for Cyber Attack Attribution
    Yang Zeming, Li Qiang, Liu Junrong, and Liu Baoxu
    Journal of Information Security Research    2015, 1 (1): 31-36.  
    Abstract1159)      PDF (5527KB)(1643)       Save
    With the increasingly complexity of cyberspace security, the attack attribution has become an important challenge for the security protection system. The emergence of threat intelligence provided plentiful data source support for the attack attribution, which makes large-scale attack attribution became possible. To realize effective attack attribution, based on the structure expression of the threat information, a light weight framework of threat intelligence sharing and utilization was proposed. It included threat intelligence expression, exchange and utilization, which can achieve the attack attribution result. Take the case of C2 relevant information, we described the expression of threat intelligence sharing and utilization, and verified the framework. Results show that the framework is practical, and can provide new technical means for attack attribution. In addition, based on the understanding of threat intelligence, several thinking about the construction of sharing and utilization mechanisms were promoted in the end.
    Related Articles | Metrics
    Dynamic Searchable Encryption Scheme Supporting Fuzzy Multiple Keywords
    Journal of Information Security Reserach    2024, 10 (11): 1064-.  
    Abstract261)      PDF (2035KB)(97)       Save
    With the development of cloud computing, the convenience and costeffectiveness of cloud storage have caused a large number of users to store personal data on thirdparty cloud servers. While encrypted storage of data in the cloud ensures data security, it also introduces challenges in data retrieval. Dynamic symmetric searchable encryption technology emerged as the times require, which not only effectively protects data privacy but also enables multikeyword joint search functions. Additionally, the fuzzy search introduced by this technology in practical applications enhances the user’s search experience and improves search efficiency. However, the current searchable encryption schemes that supports fuzzy search has certain security risks and do not adequately address potential information leakage issues during dynamic updates. To tacklethese issues, this paper proposes a dynamic searchable encryption scheme that supports fuzzy multikeywords, ensuring information security during dynamic updates, and also supporting multikeyword joint search and fuzzy search. This scheme designs a keyword encoding algorithm and localitysensitive hash function to build a fuzzy index, and uses a Bloom filter encryption algorithm to encrypt the index to achieve fuzzy search. Furthermore, a trusted execution environment is introduced to reduce the communication overhead and computing overhead as well as the number of interactions between users and servers. Finally, the safety and effectiveness of this scheme were verified through experiments.
    Reference | Related Articles | Metrics
    A Deep Learningbased Method for Background Traffic Generation in Railway Cyber Range
    Journal of Information Security Reserach    2026, 12 (7): 613-624.  
    Abstract56)      PDF (2996KB)(21)       Save
    Cybersecurity threats have permeated all aspects of the railway industry, necessitating that railway cybersecurity ranges keep pace with the latest security demands. Background traffic is a core element in constructing a realistic simulation environment for cyber ranges and serves as a critical technology supporting range operations. However, effectively capturing the complex spatiotemporal characteristics of network traffic and generating highfidelity background traffic remains a significant challenge. This paper proposes a novel method for generating background traffic in railway cyber ranges (referred to as B2Diff). By integrating deep learning techniques such as BERT, bidirectional long shortterm memory networks, and diffusion models, the method captures features such as contextual semantics, spatiotemporal dependencies, and complex traffic distributions in traffic samples, thereby generating highly realistic and diverse background traffic. Experimental results demonstrate that B2Diff significantly outperforms existing methods in terms of the quality and diversity of the generated background traffic, validating its effectiveness in enhancing the simulation realism of cyber ranges.
    Reference | Related Articles | Metrics
    Interactive Dynamic Privacy Risk Assessment and Adaptive Protection Methods in Data Publishing
    Journal of Information Security Reserach    2026, 12 (7): 598-605.  
    Abstract56)      PDF (1786KB)(20)       Save
    Data publishing is an important way to promote data sharing. However, studies have shown that it is accompanied by the risk of privacy leakage of sensitive attribute information due to large and frequent access to data by malicious parties. Although existing evaluation methods consider the scenarios of above issue, most of them are noninteractive and static settings. Therefore, in practical applications, dynamic risk cannot be accurately assessed by data publishers, and even the noise protection causes an imbalance between privacy and utility. In this paper, we propose an interactive dynamic privacy risk assessment and adaptive protection method. It firstly utilizes machine learning prediction models to determine the privacy level of difficulttodefine attributes. And secondly we sets a mechanism to dynamically adjust the privacy level according to the actual requests of the data demander and timely restricts the leakage of sensitive attribute caused by highfrequency access. Finally, an adaptive noiseadding mechanism is proposed after obtaining the high risk of evaluation feedback, to ensure that the balance of privacy and utility achieveing good results when the data is released. Experimental results show that the privacy risk index increases gradually with the number of accesses and the accesses containing associated attributes lead to an increase in the privacy risk index by more than 15%. Adaptive noise addition, on the other hand, provides a similar level of privacy protection to overall noise addition at 0.5, yet improves data utility by more than 30% over overall noise addition.
    Reference | Related Articles | Metrics
    Research on Smart Contract Vulnerability Detection Method Based on  Multimodal Feature Fusion
    Journal of Information Security Reserach    2026, 12 (6): 503-.  
    Abstract88)      PDF (1602KB)(59)       Save
    Most of the smart contract vulnerability detection methods rely on single mode feature extraction, which leads to the problem of low detection accuracy due to insufficient key feature extraction. This paper proposes a smart contract vulnerability detection method based on multimodal feature fusion. Firstly, the construction of the control flow graph (CFG) is constructed by leveraging the abstract syntax tree (AST) trimmed at the source code layer and the data flow relationship based on the opcode layer, which is imported into the graph attention network (GAT) to extract two types of static features. Secondly, the fuzzing test report generated by echidna, a dynamic detection tool, is used to extract path coverage, state changes and other information to build a graph model, and the dynamic features are extracted by graph neural network (GNN). Finally, the extracted static and dynamic features are fused and input into CNN bilstm att model for vulnerability detection, and relevant experiments are carried out on 47398 smart contracts. Experimental results show that compared with eight mainstream detection methods, such as SmartCheck, Mythril, Oyente, BiGGNN, ASTNN, DRGCN, SVCB and CBGRU, the accuracy, recall and F1 value of this method in reentry vulnerability, timestamp vulnerability, integer overflow vulnerability and Tx.origin vulnerability are increased by 50.26%, 59.54% and 58.40%.
    Reference | Related Articles | Metrics
    Overview on Public Key Crytographic Algorithm SM2 Based on Elliptic Curves
    Journal of Information Security Research    2016, 2 (11): 972-982.  
    Abstract1800)      PDF (7813KB)(991)       Save
    Public key cryptographic algorithm SM2 based on elliptic curves (SM2 algorithm for abbreviation) was firstly issued in December 2010, had become the Chinese commercial cryptographic standard (GMT 0003—2012) in 2012, and had become the Chinese national cryptographic standard (GBT 32918—2016) in 2016. This paper briefly describe the development background of SM2 algorithm,describe SM2 algorithm in details,introduce the researches on its security, and evaluate its implementation efficiencies. All the researches on SM2 algorithm so far indicate that the provable securities of SM2 algorithm reach the supreme levels of public key cryptographic algorithms securities, and its implementation efficiencies are equivalent to or slightly superior to those similar elliptic curve cryptographic algorithms in some international standards.
    Reference | Related Articles | Metrics
    Research on AIempowered Cybersecurity Detection and  Assessment Technologies
    Journal of Information Security Reserach    2026, 12 (6): 559-.  
    Abstract106)      PDF (1820KB)(64)       Save
    In response to the challenges faced by traditional cybersecurity detection and assessment technologies—such as large system scales, dynamic supply chain risks, and insufficient evaluation depth—this paper explores the application of AI technologie to advance this field. Methodologically, an endtoend implementation framework for largescale models is proposed, consisting of “data preparationdistillation and annotationcluster trainingquantitative deployment.” A localized compliance assessment model based on retrievalaugmented generation (RAG) technology is developed, and a multimodal model supporting joint textimage analysis is deployed. The large model significantly shortens the assessment cycle in scenarios such as provincial government clouds, improves the efficiency of compliance knowledge matching while reducing computational load by 70%, and markedly enhances the detection rate of inherent defects. The conclusion indicates that AI technology can effectively overcome the limitations of traditional assessment methods, promoting cybersecurity detection and assessment toward greater intelligence, adaptability, and comprehensiveness, thereby providing support for building resilient cybersecurity protection systems and fostering related ecosystem development.
    Reference | Related Articles | Metrics
    Application of Network Security Situational Awareness Platform Based on Big Data in the Field of Private Network
    Journal of Information Security Research    2019, 5 (2): 168-175.  
    Abstract270)      PDF (1678KB)(559)       Save
    In order to improve the information security defense capability of the private network, the institutions with private network pay more and more attention to the information network security situational perception technology to realize the prediction and prevention of security events. Based on the brief introduction of situational awareness and related technologies, this paper puts forward a set of applicable network security situational awareness functional architecture targeting industryspecific network needs. This paper details the functional elements contained in each system from the functional level, which would provide reference for relevant institutions to build a network security situational awareness platforms.
    Reference | Related Articles | Metrics
    PeopleNet, Independently Developing Core Technology of Cyber Information Security
    Journal of Information Security Research    2017, 3 (7): 578-588.  
    Abstract452)      PDF (1448KB)(862)       Save
    Related Articles | Metrics
    VEDA, Establishing the AI Dynamic Defense System for Cyber Security
    Journal of Information Security Research    2017, 3 (12): 1058-1066.  
    Abstract445)      PDF (1526KB)(981)       Save
    Related Articles | Metrics
    A Survey of Research on Network Attack Model
    Journal of Information Security Research    2020, 6 (12): 1058-1067.  
    Abstract1455)      PDF (1774KB)(1203)       Save
    With the rapid development of information technology, network attacks have gradually presented multi-stage, distributed and intelligent characteristics. Single firewalls, intrusion detection systems and other traditional network defense measures cannot well protect the network system security in an open environment. As a kind of attack scene representation from the attacker's perspective, the network attack model can comprehensively describe the network attack behavior in a complex and changeable environment, and is one of the commonly used network attack analysis and response tools. This paper first introduces the current main network attack models, including traditional trees, graphs, nets structure models and modern attack chains, ATT&CK, diamond models, etc. Then the analysis and application of network attack model will be explained. The analysis process for the purpose of solving the attack index mainly includes the probability framework, the assignment method and the solution method, and the application of the attack model based on the life cycle includes the application of the attackers and the defenders' perspective; Finally, the current challenges and future directions of the network attack model and its analysis and application are summarized.
    Reference | Related Articles | Metrics
    Deepfake Face Detection Method Based on Multiloss Fusion
    Journal of Information Security Reserach    2026, 12 (7): 634-643.  
    Abstract43)      PDF (2942KB)(13)       Save
    Most existing deepfake face detection methods rely on specific forgery patterns, such as noise artifacts or local textures, making them highly dependent on known forged features and lacking generalization to unknown forgeries. To address this issue, this paper proposes a multiloss fusion detection framework based on the reconstructionclassification learning(RECCE) network. A prototype similarity mechanism is introduced to measure the distance between sample features and class prototypes, enhancing the model’s ability to detect unknown forgeries. A joint loss function combining prototype loss, binary crossentropy loss, reconstruction loss, and metric learning loss is designed to strengthen feature learning from multiple perspectives. Moreover, multilevel encoder features are fused, and a reconstructionguided attention mechanism focuses the model on forged regions rather than the entire face, improving robustness and accuracy. Experiments conducted on several benchmark datasets and compared with six stateoftheart methods demonstrate significant improvements: training time is reduced to 28% of the original model, and the AUC increases by 1.48% in crossdomain evaluation when trained on FaceForensics++ (c40) and tested on CelebDF. The results verify the superior performance and generalization ability of the proposed method.
    Reference | Related Articles | Metrics
    “Internet +”Power: Overview of AsiaInfo Secruity’s Cyber Security
    Journal of Information Security Research    2016, 2 (8): 670-684.  
    Abstract517)      PDF (1873KB)(1760)       Save
    Related Articles | Metrics
     A Survey of Forensic Network Attack Source Traceback
    Journal of Information Security Reserach    2024, 10 (4): 302-.  
    Abstract371)      PDF (1134KB)(258)       Save
    The concealment and anonymity of cyber attackers pose significant challenges to the field of network attack traceback. This study provides a comprehensive overview of the current state of research on network attack traceback analysis techniques, focusing on three aspects: traffic, scenarios, and samples. Firstly, with respect to traffic traceback, the paper outlines methods and applications based on log records, packet marking, ICMP tracing, and link testing. Secondly, it categorizes traceback techniques for different scenarios, encompassinganonymous networks, zombie networks, springboards, local area networks, and advanced persistent threat attacks, as well as their applications and limitations in realworld environments. Finally, concerning sample analysis, the paper discusses the progress and application scenarios of static and dynamic traceback analysis in the context of malicious code analysis and attack tracing.
    Reference | Related Articles | Metrics
    LLMenhanced Static Analysis for Detecting Broken Object Level Authorization Vulnerabilities in Java Web Applications#br#
    #br#
    Journal of Information Security Reserach    2026, 12 (5): 394-.  
    Abstract77)      PDF (1497KB)(63)       Save
    Broken object level authorization (BOLA) is currently one of the critical security threats to Web applications. As a typical unauthorized access vulnerability, BOLA arises when a system fails to properly validate a user’s access permissions to target objects. The key to static detection of BOLA vulnerabilities lies in: accurately identifying objectlevel sensitive operations and analyzing unprotected access behaviors during path traversal. Since BOLA is an application logiclevel vulnerability, its detection effectiveness directly depends on the precision of understanding the expected objectlevel authorization policies. However, existing detection methods predominantly rely on empirical heuristic rules to identify sensitive and protected operations, making them difficult to adapt to the actual business logic of different applications, resulting in high false positives and false negatives in detection results. To address this limitation, this paper innovatively proposes a large language model (LLM)enhanced static detection method for BOLA vulnerabilities in Web applications, LLM4BOLA. First, leveraging LLM’s advanced code comprehension and semantic reasoning capabilities to infer objectlevel sensitive operations and custom authorization policies in specific business scenarios. Then, identifying diverse permission protection mechanisms. Finally, comprehensively detecting missing objectlevel permission checks along the paths from request entry points to sensitive operations. Experimental results demonstrate that the proposed method not only effectively detects known vulnerabilities but also discovers unknown ones, significantly outperforming traditional rulebased approaches in detection accuracy.
    Reference | Related Articles | Metrics
    Dynamic Invisible Backdoor Attack via Frequency Domain Injection
    Journal of Information Security Reserach    2026, 12 (6): 510-.  
    Abstract92)      PDF (1536KB)(31)       Save
    Deep neural networks are highly vulnerable to the threat of backdoor attacks due to their noninterpretability and high dependence on data during training. Although the current mainstream backdoor attack methods generally use fixed trigger design to simplify implementation, these triggers are often significantly different from the training data distribution, resulting in easy detection and identification. To this end, this paper proposes a dynamic invisible backdoor attack method via frequency domain injection: firstly, a generative network is used to generate a specific trigger pattern based on the input samples, and then the highfrequency information of the pattern is injected into the wavelet domain of the samples, ensuring the triggers remain stealthy. Additionally, this paper designs a fair screening strategy to select samples that are more influential to the backdoor model through cosine similarity and Kmeans clustering algorithm. Experimental results show that this method outperforms existing methods (e.g., BadNets, Blend, WaNet, and WABA) in terms of attack success rate and stealthiness, and effectively circumvents a variety of stateoftheart defence mechanisms (e.g., FP, NC, SentiNet, and SCALEUP), providing significant robustness and extensive practical potential.
    Reference | Related Articles | Metrics
    Multidomain Fake News Detection Model Based on Prompt Learning and Fuzzy Labels
    Journal of Information Security Reserach    2026, 12 (7): 625-633.  
    Abstract49)      PDF (1230KB)(12)       Save
    The widespread popularity of the Internet and intelligent devices has provided convenience for the public to access news. However, this also creates a breeding ground for the generation and propagation of fake news. Fake news spans multiple domains, whereas existing detection models often overlook the specificity of corpora across different domains, limiting their accuracy. To adress this issue, this paper proposes a multidomain fake news detection model based on prompt learning and fuzzy labels. This model employs RoBERTa to extract textual features and reformulates the detection task as a cloze problem by constructing prompt templates containing domain characteristics; meanwhile, it utilizes domain fuzzy membership probabilities generated by a neural network to guide the prompt learning process, effectively enhancing accuracy and generalization ability. Experimental results on the public datasets Weibo17 and Weibo21 demonstrate that this model outperforms traditional finetuning methods and existing stateoftheart methods under both domainunlabeled and multidomain conditions, with an average F1 score improvement of 1.16 percentage points, validating its feasibility and effectiveness in multidomain fake news detection tasks.
    Reference | Related Articles | Metrics
    Image Steganography Model Based on Improved Generative Adversarial Network and Selfdistillation
    Journal of Information Security Reserach    2026, 12 (7): 652-661.  
    Abstract44)      PDF (2835KB)(12)       Save
    Existing image steganography methods have made significant progress in concealment and antiattack capabilities, but still suffer from low image quality, limited information embedding capacity, and insufficient model stability and generalization ability. To address these issues, this paper proposes an image steganography model based on an improved GAN and selfdistillation (RCSDGAN). First, a residualchannel attention mechanism is designed and integrated into the DenseNet architecture to optimize its structure. Second, an encoding network and decoding network based on the enhanced DenseNet are constructed, combined with a discriminative network to form a complete image steganography framework. Finally, a selfdistillation training strategy is introduced. The selfdistillation loss is defined by calculating the difference between the teacher model’s output and the student model’s output from the same network, and this loss is incorporated into the overall loss function to enhance model stability and generalization capability. Experimental results demonstrate that, at an embedding rate of D=1bpp, the steganographic images achieve a PSNR of 50.4131dB, an SSIM of 0.9992, and an Accuracy of 99.96%.
    Reference | Related Articles | Metrics
    Three-Dimensional Way of Acorn Network in Industrial Control Cybersecurity
    Journal of Information Security Research    2017, 3 (8): 0-0.  
    Abstract503)      PDF (3703KB)(833)       Save
    Related Articles | Metrics
    Research Review on Collaborative Intrusion Detection Based on Federated Learning
    Journal of Information Security Reserach    2026, 12 (6): 526-.  
    Abstract113)      PDF (1168KB)(45)       Save
    The increasing complexity of cyber attacks challenges traditional centralized intrusion detection systems. Federated learningbased collaborative intrusion detection enables collaborative modeling and knowledge sharing among multiple nodes without sharing raw data, thereby effectively improving the detection capability for crossdomain and unknown attacks. This paper systematically reviews the research progress of federated learningbased collaborative intrusion detection. Existing methods are classified and analyzed from multiple perspectives, including architectureaware, model adaptation and evolutiondriven, as well as privacy and security enhanced approaches. Commonly used datasets and evaluation metrics are summarized. Finally, the major challenges and future research directions are discussed, providing references for subsequent research in this field.
    Reference | Related Articles | Metrics
    Building Cyber Security Defense by Trusted Computing 3.0
    Journal of Information Security Research    2017, 3 (4): 290-298.  
    Abstract446)      PDF (1075KB)(2035)       Save
    Related Articles | Metrics
    DBAPPSecurity:Support Security China, Boost Digital Economy
    Journal of Information Security Research    2019, 5 (4): 274-281.  
    Abstract204)      PDF (3884KB)(813)       Save
    Related Articles | Metrics
    Remote Office Solution and Its Application Based on Secure Instant Messaging Technology
    Journal of Information Security Research    2020, 6 (4): 301-310.  
    Abstract210)      PDF (3086KB)(399)       Save
    Remote office is getting more and more favored by users for its characteristics of unconstrained time and space, high-efficiency and convenience, fragmentation time utilization and so on, but it also raised a lot of security problems. This article systematically introduces a security solution for remote office and its innovative applications. Based on the secure instant messaging architecture of interconnection and interworking, it realizes vertical security support and application aggregation, as well as horizontal data sharing and application collaboration through open aggregation interfaces. Therefore an remote office ecosystem is built. The solution has been widely used in sectors such as government, military, finance and energy, providing a security application solution to meet the requirements of relevant national standards for the high-security users’ remote office.
    Reference | Related Articles | Metrics
    Flow Anomaly Detection Based on Hierarchical Clustering Method
    Journal of Information Security Research    2020, 6 (6): 0-0.  
    Abstract1301)      PDF (1784KB)(717)       Save
    With the advent of the big data era, the attacks in network traffic are rising dramatically. Detecting malicious traffic through abnormal flow detection is vital. Nowadays, the equipment of abnormal flow detection used in industry mainly adopts statistical analysis method or simple machine learning method. However, the amount of flow data and redundant data is large. The precision rate is low and the false alarm rate is high. In order to solve these problems, this paper presents a new method to detect flow anomalies based on hierarchical clustering in data processing. This method first uses the hierarchical clustering algorithm to achieve the purpose of data reduction. Then based on seven different machine learning algorithms, an abnormal traffic model based on hierarchical clustering is constructed. The experimental results show that this method can detect the abnormal behavior on the DARPA dataset with a precision rate of 99% and a recall rate of 99%. At the same time, while maintaining the precision rate of 90%, the data reduction can be up to 47.58%, which greatly improves the detection efficiency.
    Related Articles | Metrics
    Research on ECDSA Key Recovery Attacks Based on the Extended  Hidden Number Problem
    Journal of Information Security Reserach    2026, 12 (2): 174-.  
    Abstract101)      PDF (797KB)(58)       Save
    Elliptic curve digital signature algorithm (ECDSA) is one of the most widely used digital signature algorithms. During the signing process, it requires computing scalar multiplication on elliptic curves, which is typically the most timeconsuming component of the signature. In many present cryptographic libraries, the windowed nonadjacent form representation is commonly used to represent the ephemeral key in order to reduce time consumption. This exposes sidechannel vulnerability to malicious attackers, allowing them to extract partial information about the ephemeral key from sidechannel traces and subsequently recover the signing key. Leveraging the extended hidden number problem to extract information from sidechannel traces and applying latticebased attacks to recover keys constitutes one of the mainstream attack frameworks against ECDSA. Based on above, we propose three optimization methods. First, we introduce a neighboring dynamic constraint merge strategy. By dynamically adjusting the merging parameters, we reduce the dimension of the lattice and control the amount of known information lost during the attack, ensuring high success rates for key recovery across all signatures. Second, we analyze and optimize the embedding number in the lattice, reducing the Euclidean norm of the target vector by approximately 8%, thereby improving the success rate and reducing time consumption. Finally, we propose a linear predicate method which significantly reduces the time overhead of the lattice sieving. In this work, we achieve a success rate of 0.99 in recovering the private key using only two signatures.
    Reference | Related Articles | Metrics
    Research on Domain Adaptive Intrusion Detection Method Based on  Dynamic Feature Fusion
    Journal of Information Security Reserach    2026, 12 (4): 294-.  
    Abstract153)      PDF (1452KB)(106)       Save
    Aiming at the problems of incomplete feature extraction and limited model generalization ability in intrusion detection research, a domain adaptive intrusion detection method with dynamic feature fusion is proposed. Firstly, a convolutional neural network is used to extract spatial features, while a bidirectional long shortterm memory network is utilized for temporal feature extraction. This approach enables comprehensive extraction of multidimensional feature information from network traffic data. Secondly, the uncertainty is measured by calculating the information entropy of the two features, and different weights are assigned according to the entropy value, and the extracted features are weighted and fused according to the weights. Finally, during the training process, the proposed adaptive domain weight loss algorithm is used to dynamically adjust the contribution of the source domain and target domain data to improve the generalization ability of the model on the target domain data. Experiments are carried out using the NSLKDD and UNSWNB15 datasets. Compared with the existing mainstream methods, this method has higher detection accuracy, which is 0.8563 and 0.916 respectively.
    Reference | Related Articles | Metrics
    Chinese Dark Web Product Detection and Classification Based on  Multimodal Data Augmentation#br#
    Journal of Information Security Reserach    2026, 12 (6): 575-.  
    Abstract73)      PDF (4502KB)(29)       Save
    In order to address the issues of coarse granularity in existing dark Web intelligence classification research and the predominance of Englishlanguage datasets, this paper proposes a finegrained analysis study focused on Chinese dark Web content. To overcome the scarcity of Chinese dark Web data and the misalignment of multimodal data, this study employs a large language model prompt rewriting strategy and a differentiated image enhancement strategy to achieve text and image data augmentation. By integrating product data from a certain platform on the Surface Web, a dataset comprising 14,052 product records was constructed. A feature selection optimization module was designed to establish an intertask coupling mechanism, and a Chinese dark Web product detection and classification model based on multimodal data augmentation was proposed. Experimental results demonstrate that the proposed model achieves macroF1 scores of 0.992 and 0.941 in dark Web product detection and classification tasks, respectively, representing an approximately 2% improvement over the best baseline model in  classification task and significantly outperforming existing singlemodal and multimodal methods. This approach effectively enhances the performance of finegrained classification tasks for Chinese dark Web intelligence, offering new insights and methodologies for dark Web intelligence analysis.
    Reference | Related Articles | Metrics
    Advanced Persistent Threat Detection Based on Generative Subgraph Contrastive Autoencoder
    Journal of Information Security Reserach    2026, 12 (7): 672-680.  
    Abstract36)      PDF (2020KB)(10)       Save
    With the increasing sophistication and stealth of cyber attacks, particularly the continuous evolution of advanced persistent threats (APT) targeting critical information infrastructure, which are characterized by high concealment and longterm persistence, accurately distinguishing intrusions from normal behavior has become a critical challenge. Provenancebased intrusion detection systems can capture finegrained causal relationships among system entities, demonstrating strong advantages in distinguishing benign from malicious behaviors and uncovering stealthy attacks. However, existing learningbased approaches still suffer from the absence of proper node weighting, insufficient utilization of edge features, and inadequate learning of local subgraph structures, while also facing high computational costs when applied to largescale datasets. To address these limitations, we propose GSCAE, a novel APT detection framework based on a Generative Subgraph Contrastive Autoencoder. First, we construct node representations by integrating edge interaction features with local clustering coefficients and compute node importance using the entropy weight method. Then, we design a generative subgraph contrastive learning algorithm that jointly incorporates edgelevel and topological losses to more effectively learn local structures and interaction patterns. Finally, the learned graph embeddings are fed into a lightweight node classifier to perform anomaly detection, achieving a balance between detection accuracy and computational efficiency. Experiments conducted on the DARPA public dataset demonstrate that GSCAE outperforms most existing learningbased approaches in both accuracy and efficiency, validating its effectiveness and practicality in complex host environments.
    Reference | Related Articles | Metrics
    Evidence Extraction of USB Storage Device Accessing Traces under the Windows 7 System
    Journal of Information Security Research    2016, 2 (4): 333-338.  
    Abstract431)      PDF (5162KB)(870)       Save
    With the rapid development and popularization of computer technology, cyber crimes come one after another,there are a lot of computer evidences existing in the USB storage device. When USB storage device has access to computers, registry keys and computer log will record the accessing traces. Therefore, computer forensic investigators can accordingly confirm which USB device has connected to the computer at what time. This paper introduces the position of accessing traces and extraction methods, providing great support and help for certain evidence factors in judicial activities.
    Reference | Related Articles | Metrics
    Research on Maintenance and Security of Industrial Control Networks in Electric Power Industry
    Journal of Information Security Research    2019, 5 (8): 679-684.  
    Abstract260)      PDF (2038KB)(690)       Save
    As an important part of national key infrastructure, the importance of operation and maintenance security of electric power industry control network is selfevident. Especially with the increasing security incidents of industrial control networks in the world in recent years, effective measures must be taken to protect the safe operation of industrial control networks, which also puts forward higher requirements for the operation, maintenance and safety protection of industrial control networks and industrial systems. Through indepth analysis of the characteristics of industrial control network in electric power industry, especially the key characteristics of the data type and network topology structure of the electric power network, effective operation and maintenance methods and security risk prevention methods are put forward. In operation and maintenance, the backup of system data and the state monitoring of the system itself are strengthened. Security measures, such as physical isolation, industrial control flow monitoring, fault recovery management and so on should be taken, and effective policies and behavioral norms should be provided. Finally, form safety protection measures suitable for electric power industry control network, to achieve the purpose of safe operation of the electric power industry control network.
    Reference | Related Articles | Metrics
    Research on Risk Analysis of Opensource Software Supply Chain Security
    Journal of Information Security Reserach    2024, 10 (9): 862-.  
    Abstract377)      PDF (1824KB)(210)       Save
    Opensource software has become one of the most fundamental elements that support the operation of the digital society. It has also been penetrated to various industries and fields. As the opensource software supply chain becomes increasingly complex and diversified, the risks caused by security attacks on the opensource software supply chain are also intensified. This paper summarizes the current development of the opensource software supply chain ecosystem and the strategic layout of opensource software supply chain security in major countries. From the dimensions of development security, usage security, and operation security, this paper proposes an opensource software supply chain security risk analysis system. It identifies the major security risks currently faced by the opensource software supply chain. Besides, this paper constructs a security assurance model for the opensource software supply chain and offers countermeasures and suggestions for the security and development of China’s opensource software supply chain from the dimensions of supply chain phases, relevant entities, and safeguard measures.
    Reference | Related Articles | Metrics
    The ZUC Stream Cipher Algorithm
    Journal of Information Security Research    2016, 2 (11): 1028-1041.  
    Abstract1730)      PDF (7769KB)(810)       Save
    祖冲之算法,简称ZUC,是一个面向字设计的序列密码算法,其在128b种子密钥和128b初始向量控制下输出32b的密钥字流.祖冲之算法于2011年9月被3GPP LTE采纳为国际加密标准(标准号为TS 35.221),即第4代移动通信加密标准,2012年3月被发布为国家密码行业标准(标准号为GMT 0001—2012),2016年10月被发布为国家标准(标准号为GBT 33133—2016).简单介绍了祖冲之算法,并总结了其设计思想和国内外对该算法安全性分析的主要进展.
    Reference | Related Articles | Metrics
    Security Architecture and Key Technologies of Blockchain
    Yan Zhu
    Journal of Information Security Research    2016, 2 (12): 1090-1097.  
    Abstract1251)      PDF (6838KB)(859)       Save
    Blockchain, both the cryptocurrency and the underlying Bitcoin technology, have attracted significant attention around the world. The reason is that blockchain is a decentralization technology with Consensus Trust Mechanism (CTM), which is obviously different from the traditional centralization system with Outer Trust Mechanism (OTM). This has made a great influence on the trust mechanism of people and promoted the usage of security technology in the blockchain. In this paper, we present the security architecture and key technologies of the blockchain, and explain how the blockchain ensure the integrity, non repudiation, privacy, consistency for the stored data through P2P network, distributed ledger, asymmetric encryption, consensus mechanism and smart contracts. Moreover, we analyze some new security threats and measures, for example, the preventing technology of Denial of Service (DoS) attack against the Transaction Storm (TS), the cryptographic access control (CAC) technology to enhance the data privacy, the key management technology against losing and stealing of digital asset, and so on. We also discuss the future security problems and technologies that might be discovered after the blockchain syncretizes new technologies, including, AI, Big Data, IOT, cloud computing, mobile Internet technologies.
    Reference | Related Articles | Metrics
    Semantics Based Webshell Detection Method Research
    Journal of Information Security Research    2017, 3 (2): 145-150.  
    Abstract510)      PDF (4585KB)(653)       Save
    A semanticsbased Webshell detection method was proposed. This method obtained the code behavior and related dependencies by syntax analysis of the file, and achieved semantic understanding to complete the Webshell detection by the risk model. A critical abstract syntax subtree extraction method which can reject irrelevant factor and get the malicious behavior occurrence point was proposed. The description of behavior in risk model database was defined with BackusNaur Form, finally a smooth risk value curve could be obtained by graph matching algorithm, which can finish the criticality assessment of the file and can get a better result by adjusting the threshold A webshell detection system based on that detection method was designed and finished, the experimental results have demonstrated that the SemanticsBased method was effective in Webshell detection.
    Reference | Related Articles | Metrics
    Evolution Research of Network Security Technology in Big Data Era
    Journal of Information Security Research    2019, 5 (5): 406-413.  
    Abstract197)      PDF (1284KB)(567)       Save
    With the advent of the era of big data, information systems have exhibited some new features, including boundary obfuscation, system virtualization, unstructure and diversification, and the low coupling degree of function and data. These features not only lead to a big difference between big data technology (DT) and information technology (IT), but also promote the upgrading and evolution of network security technology. In response to these changes, in this paper we compare the characteristics between IT era and DT era, and then propose four DT security principles: privacy, integrity, traceability, and controllability, as well as active and dynamic defense strategy based on “propagation prediction, tracking audit, dynamic management and control”. We further discusses the security challenges faced by DT and the corresponding assurance strategies. On this basis, the big data security technologies can be divided into four levels: “elimination, continuation, improvement, and innovation”, and we provide analyzation, combination and explaination for these technologies according to six categories: access control, identification and authentication, data encryption, data privacy, intrusion prevention, security audit and disaster recovery. These results will offer important assistance for the evolution of security technologies in the DT era, the construction of big data platform, the designation of security assurance strategies, and technology suitable for big data.
    Reference | Related Articles | Metrics
    Developing our Own CPU Should Take the Road of Marketing Driven Technology
    Journal of Information Security Research    2019, 5 (5): 450-453.  
    Abstract182)      PDF (993KB)(474)       Save
    Related Articles | Metrics