Most Download articles

    Published in last 1 year | In last 2 years| In last 3 years| All| Most Downloaded in Recent Month| Most Downloaded in Recent Year|

    Most Downloaded in Recent Month
    Please wait a minute...
    For Selected: Toggle Thumbnails
    Survey of Software Supply Chain Security Detection and Assessment Technologies
    Journal of Information Security Reserach    2026, 12 (7): 586-597.  
    Abstract120)      PDF (1750KB)(70)       Save
    In the context of the digital era, software supply chain has become a critical component supporting the stable and healthy development of the digital economy. It is an indispensable part of the nation’s key information infrastructure and economic and social systems. The security of software supply chain directly determines the security of the key businesses carried by the software supply chain. Therefore, based on the development needs of the digital age, this article summarizes the current technologies, methods, and development trends related to software supply chain security detection and evaluation, providing reference and guidance for industry insiders, researchers, and decisionmakers. It includes a review and detailed explanation of the background and methods of software supply chain security detection and evaluation technology, detailing the principles of mainstream technologies such as component analysis, vulnerability scanning, code review, runtime monitoring, threat modeling, and fuzz testing, and comparing and analyzing the advantages and disadvantages of various technologies; Analyze the current technical challenges and countermeasures faced by technology; And propose ten major trends for the development of this field in the next decade, in order to improve the security level of the software supply chain and promote the development of the software industry.
    Reference | Related Articles | Metrics
    Overview on SM9 Identity Based Cryptographic Algorithm
    Journal of Information Security Research    2016, 2 (11): 1008-1027.  
    Abstract3778)      PDF (13949KB)(6267)       Save
    SM9 identitybased cryptographic algorithm is an identitybased cryptosystem with bilinear pairings. In such a system the user s private key and public key may be extracted from user s identity and key generation centers parameters. The most common cryptographic uses of SM9 are with digital signature, data encryption, key exchange protocol and key encapsulation mechanism etc. The application and management of SM9 will not require digital certificate, certificate base, and key base. The key length of the SM9 cipher algorithm is 256b. SM9 cryptographic algorithm was issued as the cryptography standard in 2015. This paper will summarize the design, algorithm, software and hardware implementation and cryptanalysis of SM9 cryptographic algorithm. We also give some concrete examples in appendix.
    Reference | Related Articles | Metrics
    The Mechanism of Disinformation Generation and Governance Pathways in Generative AI Models
    Journal of Information Security Reserach    2026, 12 (7): 606-612.  
    Abstract94)      PDF (1256KB)(32)       Save
    While driving transformations in online information order, generative AI models also generate disinformation risks characterized by an “objective+subjective” overlap. An analytical framework tailored to their technical characteristics is urgently needed. This study systematically deconstructs the technical logic of false information production in generative AI models based on their hybrid expert architecture, treelike reasoning patterns, localized semantic understanding attributes, and opensource ecosystem mechanisms. It analyzes the transmission mechanisms of false information risks across four stages: data input, algorithmic operation, content presentation, and cognitive dissemination. To address these risks: At the algorithmic level, implement a processbased oversight scheme encompassing “access reviewoperation disclosurepostevent verification”; at the presentation level, strengthen scenariobased, interactive “warning notice” labeling mechanisms; at the cognitive level, cultivate users' digital literacy and selfrestraintt capabilities to achieve effective information security governance in the AI era.
    Reference | Related Articles | Metrics
    Dynamic Searchable Encryption Scheme Supporting Fuzzy Multiple Keywords
    Journal of Information Security Reserach    2024, 10 (11): 1064-.  
    Abstract268)      PDF (2035KB)(98)       Save
    With the development of cloud computing, the convenience and costeffectiveness of cloud storage have caused a large number of users to store personal data on thirdparty cloud servers. While encrypted storage of data in the cloud ensures data security, it also introduces challenges in data retrieval. Dynamic symmetric searchable encryption technology emerged as the times require, which not only effectively protects data privacy but also enables multikeyword joint search functions. Additionally, the fuzzy search introduced by this technology in practical applications enhances the user’s search experience and improves search efficiency. However, the current searchable encryption schemes that supports fuzzy search has certain security risks and do not adequately address potential information leakage issues during dynamic updates. To tacklethese issues, this paper proposes a dynamic searchable encryption scheme that supports fuzzy multikeywords, ensuring information security during dynamic updates, and also supporting multikeyword joint search and fuzzy search. This scheme designs a keyword encoding algorithm and localitysensitive hash function to build a fuzzy index, and uses a Bloom filter encryption algorithm to encrypt the index to achieve fuzzy search. Furthermore, a trusted execution environment is introduced to reduce the communication overhead and computing overhead as well as the number of interactions between users and servers. Finally, the safety and effectiveness of this scheme were verified through experiments.
    Reference | Related Articles | Metrics
    Interactive Dynamic Privacy Risk Assessment and Adaptive Protection Methods in Data Publishing
    Journal of Information Security Reserach    2026, 12 (7): 598-605.  
    Abstract65)      PDF (1786KB)(22)       Save
    Data publishing is an important way to promote data sharing. However, studies have shown that it is accompanied by the risk of privacy leakage of sensitive attribute information due to large and frequent access to data by malicious parties. Although existing evaluation methods consider the scenarios of above issue, most of them are noninteractive and static settings. Therefore, in practical applications, dynamic risk cannot be accurately assessed by data publishers, and even the noise protection causes an imbalance between privacy and utility. In this paper, we propose an interactive dynamic privacy risk assessment and adaptive protection method. It firstly utilizes machine learning prediction models to determine the privacy level of difficulttodefine attributes. And secondly we sets a mechanism to dynamically adjust the privacy level according to the actual requests of the data demander and timely restricts the leakage of sensitive attribute caused by highfrequency access. Finally, an adaptive noiseadding mechanism is proposed after obtaining the high risk of evaluation feedback, to ensure that the balance of privacy and utility achieveing good results when the data is released. Experimental results show that the privacy risk index increases gradually with the number of accesses and the accesses containing associated attributes lead to an increase in the privacy risk index by more than 15%. Adaptive noise addition, on the other hand, provides a similar level of privacy protection to overall noise addition at 0.5, yet improves data utility by more than 30% over overall noise addition.
    Reference | Related Articles | Metrics
    A Deep Learningbased Method for Background Traffic Generation in Railway Cyber Range
    Journal of Information Security Reserach    2026, 12 (7): 613-624.  
    Abstract60)      PDF (2996KB)(23)       Save
    Cybersecurity threats have permeated all aspects of the railway industry, necessitating that railway cybersecurity ranges keep pace with the latest security demands. Background traffic is a core element in constructing a realistic simulation environment for cyber ranges and serves as a critical technology supporting range operations. However, effectively capturing the complex spatiotemporal characteristics of network traffic and generating highfidelity background traffic remains a significant challenge. This paper proposes a novel method for generating background traffic in railway cyber ranges (referred to as B2Diff). By integrating deep learning techniques such as BERT, bidirectional long shortterm memory networks, and diffusion models, the method captures features such as contextual semantics, spatiotemporal dependencies, and complex traffic distributions in traffic samples, thereby generating highly realistic and diverse background traffic. Experimental results demonstrate that B2Diff significantly outperforms existing methods in terms of the quality and diversity of the generated background traffic, validating its effectiveness in enhancing the simulation realism of cyber ranges.
    Reference | Related Articles | Metrics
    Overview on Public Key Crytographic Algorithm SM2 Based on Elliptic Curves
    Journal of Information Security Research    2016, 2 (11): 972-982.  
    Abstract1808)      PDF (7813KB)(993)       Save
    Public key cryptographic algorithm SM2 based on elliptic curves (SM2 algorithm for abbreviation) was firstly issued in December 2010, had become the Chinese commercial cryptographic standard (GMT 0003—2012) in 2012, and had become the Chinese national cryptographic standard (GBT 32918—2016) in 2016. This paper briefly describe the development background of SM2 algorithm,describe SM2 algorithm in details,introduce the researches on its security, and evaluate its implementation efficiencies. All the researches on SM2 algorithm so far indicate that the provable securities of SM2 algorithm reach the supreme levels of public key cryptographic algorithms securities, and its implementation efficiencies are equivalent to or slightly superior to those similar elliptic curve cryptographic algorithms in some international standards.
    Reference | Related Articles | Metrics
    Multidomain Fake News Detection Model Based on Prompt Learning and Fuzzy Labels
    Journal of Information Security Reserach    2026, 12 (7): 625-633.  
    Abstract62)      PDF (1230KB)(15)       Save
    The widespread popularity of the Internet and intelligent devices has provided convenience for the public to access news. However, this also creates a breeding ground for the generation and propagation of fake news. Fake news spans multiple domains, whereas existing detection models often overlook the specificity of corpora across different domains, limiting their accuracy. To adress this issue, this paper proposes a multidomain fake news detection model based on prompt learning and fuzzy labels. This model employs RoBERTa to extract textual features and reformulates the detection task as a cloze problem by constructing prompt templates containing domain characteristics; meanwhile, it utilizes domain fuzzy membership probabilities generated by a neural network to guide the prompt learning process, effectively enhancing accuracy and generalization ability. Experimental results on the public datasets Weibo17 and Weibo21 demonstrate that this model outperforms traditional finetuning methods and existing stateoftheart methods under both domainunlabeled and multidomain conditions, with an average F1 score improvement of 1.16 percentage points, validating its feasibility and effectiveness in multidomain fake news detection tasks.
    Reference | Related Articles | Metrics
    Deepfake Face Detection Method Based on Multiloss Fusion
    Journal of Information Security Reserach    2026, 12 (7): 634-643.  
    Abstract47)      PDF (2942KB)(15)       Save
    Most existing deepfake face detection methods rely on specific forgery patterns, such as noise artifacts or local textures, making them highly dependent on known forged features and lacking generalization to unknown forgeries. To address this issue, this paper proposes a multiloss fusion detection framework based on the reconstructionclassification learning(RECCE) network. A prototype similarity mechanism is introduced to measure the distance between sample features and class prototypes, enhancing the model’s ability to detect unknown forgeries. A joint loss function combining prototype loss, binary crossentropy loss, reconstruction loss, and metric learning loss is designed to strengthen feature learning from multiple perspectives. Moreover, multilevel encoder features are fused, and a reconstructionguided attention mechanism focuses the model on forged regions rather than the entire face, improving robustness and accuracy. Experiments conducted on several benchmark datasets and compared with six stateoftheart methods demonstrate significant improvements: training time is reduced to 28% of the original model, and the AUC increases by 1.48% in crossdomain evaluation when trained on FaceForensics++ (c40) and tested on CelebDF. The results verify the superior performance and generalization ability of the proposed method.
    Reference | Related Articles | Metrics
    PeopleNet, Independently Developing Core Technology of Cyber Information Security
    Journal of Information Security Research    2017, 3 (7): 578-588.  
    Abstract452)      PDF (1448KB)(865)       Save
    Related Articles | Metrics
    Image Steganography Model Based on Improved Generative Adversarial Network and Selfdistillation
    Journal of Information Security Reserach    2026, 12 (7): 652-661.  
    Abstract49)      PDF (2835KB)(14)       Save
    Existing image steganography methods have made significant progress in concealment and antiattack capabilities, but still suffer from low image quality, limited information embedding capacity, and insufficient model stability and generalization ability. To address these issues, this paper proposes an image steganography model based on an improved GAN and selfdistillation (RCSDGAN). First, a residualchannel attention mechanism is designed and integrated into the DenseNet architecture to optimize its structure. Second, an encoding network and decoding network based on the enhanced DenseNet are constructed, combined with a discriminative network to form a complete image steganography framework. Finally, a selfdistillation training strategy is introduced. The selfdistillation loss is defined by calculating the difference between the teacher model’s output and the student model’s output from the same network, and this loss is incorporated into the overall loss function to enhance model stability and generalization capability. Experimental results demonstrate that, at an embedding rate of D=1bpp, the steganographic images achieve a PSNR of 50.4131dB, an SSIM of 0.9992, and an Accuracy of 99.96%.
    Reference | Related Articles | Metrics
    A Survey of Research on Network Attack Model
    Journal of Information Security Research    2020, 6 (12): 1058-1067.  
    Abstract1461)      PDF (1774KB)(1207)       Save
    With the rapid development of information technology, network attacks have gradually presented multi-stage, distributed and intelligent characteristics. Single firewalls, intrusion detection systems and other traditional network defense measures cannot well protect the network system security in an open environment. As a kind of attack scene representation from the attacker's perspective, the network attack model can comprehensively describe the network attack behavior in a complex and changeable environment, and is one of the commonly used network attack analysis and response tools. This paper first introduces the current main network attack models, including traditional trees, graphs, nets structure models and modern attack chains, ATT&CK, diamond models, etc. Then the analysis and application of network attack model will be explained. The analysis process for the purpose of solving the attack index mainly includes the probability framework, the assignment method and the solution method, and the application of the attack model based on the life cycle includes the application of the attackers and the defenders' perspective; Finally, the current challenges and future directions of the network attack model and its analysis and application are summarized.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E2): 2-.  
    Abstract68)      PDF (1416KB)(55)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2026, 12 (2): 98-.  
    Abstract184)      PDF (532KB)(133)       Save
    Related Articles | Metrics
    The ZUC Stream Cipher Algorithm
    Journal of Information Security Research    2016, 2 (11): 1028-1041.  
    Abstract1737)      PDF (7769KB)(813)       Save
    祖冲之算法,简称ZUC,是一个面向字设计的序列密码算法,其在128b种子密钥和128b初始向量控制下输出32b的密钥字流.祖冲之算法于2011年9月被3GPP LTE采纳为国际加密标准(标准号为TS 35.221),即第4代移动通信加密标准,2012年3月被发布为国家密码行业标准(标准号为GMT 0001—2012),2016年10月被发布为国家标准(标准号为GBT 33133—2016).简单介绍了祖冲之算法,并总结了其设计思想和国内外对该算法安全性分析的主要进展.
    Reference | Related Articles | Metrics
    Survey of Hash Functions
    Wang Xiaoyun1,2 and Yu Hongbo3
    Journal of Information Security Research    2015, 1 (1): 19-30.  
    Abstract1833)      PDF (11279KB)(3927)       Save
    One of the fundamental primitives in modern cryptography is the cryptographic hash functions, often informally called hash functions. They are used to compress messages of arbitrary length to fixed length hash values which are also called hash codes, message digests or digital fingerprints. A primary motivation for cryptographic hash functions is that they serve as compact representative images of input messages, which they can uniquely identify. Changing a single letter will change most of the digits in the hash code. The most common cryptographic uses of hash functions are with digital signature and for data integrity. Hash functions are frequently used in digital signature schemes to compress large messages for processing by public-key cryptosystems such as RSA. They are also used to design message authentication codes (MACs) and many secure cryptographic protocols. Hash functions occur as components in various cryptographic applications (e.g. protection of pass-phrases, protocols for payment, broadcast authentication etc.), where usually their property as a computational one-way function is used. So the study of the hash functions is of great significance in the cryptanalysis field.
    Related Articles | Metrics
    Semantics Based Webshell Detection Method Research
    Journal of Information Security Research    2017, 3 (2): 145-150.  
    Abstract512)      PDF (4585KB)(656)       Save
    A semanticsbased Webshell detection method was proposed. This method obtained the code behavior and related dependencies by syntax analysis of the file, and achieved semantic understanding to complete the Webshell detection by the risk model. A critical abstract syntax subtree extraction method which can reject irrelevant factor and get the malicious behavior occurrence point was proposed. The description of behavior in risk model database was defined with BackusNaur Form, finally a smooth risk value curve could be obtained by graph matching algorithm, which can finish the criticality assessment of the file and can get a better result by adjusting the threshold A webshell detection system based on that detection method was designed and finished, the experimental results have demonstrated that the SemanticsBased method was effective in Webshell detection.
    Reference | Related Articles | Metrics
    VEDA, Establishing the AI Dynamic Defense System for Cyber Security
    Journal of Information Security Research    2017, 3 (12): 1058-1066.  
    Abstract446)      PDF (1526KB)(986)       Save
    Related Articles | Metrics
     A Survey of Forensic Network Attack Source Traceback
    Journal of Information Security Reserach    2024, 10 (4): 302-.  
    Abstract380)      PDF (1134KB)(258)       Save
    The concealment and anonymity of cyber attackers pose significant challenges to the field of network attack traceback. This study provides a comprehensive overview of the current state of research on network attack traceback analysis techniques, focusing on three aspects: traffic, scenarios, and samples. Firstly, with respect to traffic traceback, the paper outlines methods and applications based on log records, packet marking, ICMP tracing, and link testing. Secondly, it categorizes traceback techniques for different scenarios, encompassinganonymous networks, zombie networks, springboards, local area networks, and advanced persistent threat attacks, as well as their applications and limitations in realworld environments. Finally, concerning sample analysis, the paper discusses the progress and application scenarios of static and dynamic traceback analysis in the context of malicious code analysis and attack tracing.
    Reference | Related Articles | Metrics
    Remote Office Solution and Its Application Based on Secure Instant Messaging Technology
    Journal of Information Security Research    2020, 6 (4): 301-310.  
    Abstract212)      PDF (3086KB)(399)       Save
    Remote office is getting more and more favored by users for its characteristics of unconstrained time and space, high-efficiency and convenience, fragmentation time utilization and so on, but it also raised a lot of security problems. This article systematically introduces a security solution for remote office and its innovative applications. Based on the secure instant messaging architecture of interconnection and interworking, it realizes vertical security support and application aggregation, as well as horizontal data sharing and application collaboration through open aggregation interfaces. Therefore an remote office ecosystem is built. The solution has been widely used in sectors such as government, military, finance and energy, providing a security application solution to meet the requirements of relevant national standards for the high-security users’ remote office.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2024, 10 (E2): 105-.  
    Abstract790)      PDF (929KB)(404)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E2): 89-.  
    Abstract125)      PDF (1508KB)(68)       Save
    Reference | Related Articles | Metrics
    A Deep Learning Differential Privacy Protection Scheme Based on  Adaptive Clipping
    Journal of Information Security Reserach    2026, 12 (6): 490-.  
    Abstract176)      PDF (1728KB)(104)       Save
    To address the issues of utility degradation in deep learning models under differential privacy protection and the gap between theoretical and actual privacy protection effectiveness, this paper proposes a deep learning differential privacy protection scheme based on adaptive clipping. The scheme optimizes the process through a fourstep mechanism: firstly, gradient adaptive clipping controls the gradient magnitude during training by dynamically adjusting the gradient clipping threshold, thereby enabling the control of the magnitude of noise added subsequently; secondly, group label selection identifies the group with the smallest gradient as the privacypreserving object, and more accurate privacy loss can be obtained by training this group; thirdly, optimized privacy loss calculation combines the gaussian mechanism based on subsampling to reduce the computational overhead of model privacy loss calculation; finally, optimized gradient adaptive descent realizes the adaptive descent of gradients by adjusting the conditional smoothing parameter, thus improving the usability of the model. Experiments were conducted on the VGG architecture using the MNIST, CIFAR10, and MedicalMNIST datasets. The results show that the model accuracy rates after training with this scheme are 81.08%, 72.30%, and 67.91% respectively, representing improvements of 15.60%, 10.60%, and 9.71% compared to the traditional DPSGD, and 0.63%, 2.50%, and 4.40% over the widely used Nadam algorithm in recent years. The model training efficiency has been improved by 35.5% and 39.4%, respectively.
    Reference | Related Articles | Metrics
    Advanced Persistent Threat Detection Based on Generative Subgraph Contrastive Autoencoder
    Journal of Information Security Reserach    2026, 12 (7): 672-680.  
    Abstract46)      PDF (2020KB)(10)       Save
    With the increasing sophistication and stealth of cyber attacks, particularly the continuous evolution of advanced persistent threats (APT) targeting critical information infrastructure, which are characterized by high concealment and longterm persistence, accurately distinguishing intrusions from normal behavior has become a critical challenge. Provenancebased intrusion detection systems can capture finegrained causal relationships among system entities, demonstrating strong advantages in distinguishing benign from malicious behaviors and uncovering stealthy attacks. However, existing learningbased approaches still suffer from the absence of proper node weighting, insufficient utilization of edge features, and inadequate learning of local subgraph structures, while also facing high computational costs when applied to largescale datasets. To address these limitations, we propose GSCAE, a novel APT detection framework based on a Generative Subgraph Contrastive Autoencoder. First, we construct node representations by integrating edge interaction features with local clustering coefficients and compute node importance using the entropy weight method. Then, we design a generative subgraph contrastive learning algorithm that jointly incorporates edgelevel and topological losses to more effectively learn local structures and interaction patterns. Finally, the learned graph embeddings are fed into a lightweight node classifier to perform anomaly detection, achieving a balance between detection accuracy and computational efficiency. Experiments conducted on the DARPA public dataset demonstrate that GSCAE outperforms most existing learningbased approaches in both accuracy and efficiency, validating its effectiveness and practicality in complex host environments.
    Reference | Related Articles | Metrics
    Evidence Extraction of USB Storage Device Accessing Traces under the Windows 7 System
    Journal of Information Security Research    2016, 2 (4): 333-338.  
    Abstract433)      PDF (5162KB)(870)       Save
    With the rapid development and popularization of computer technology, cyber crimes come one after another,there are a lot of computer evidences existing in the USB storage device. When USB storage device has access to computers, registry keys and computer log will record the accessing traces. Therefore, computer forensic investigators can accordingly confirm which USB device has connected to the computer at what time. This paper introduces the position of accessing traces and extraction methods, providing great support and help for certain evidence factors in judicial activities.
    Reference | Related Articles | Metrics
    DBAPPSecurity:Support Security China, Boost Digital Economy
    Journal of Information Security Research    2019, 5 (4): 274-281.  
    Abstract204)      PDF (3884KB)(815)       Save
    Related Articles | Metrics
    Evolution Research of Network Security Technology in Big Data Era
    Journal of Information Security Research    2019, 5 (5): 406-413.  
    Abstract200)      PDF (1284KB)(568)       Save
    With the advent of the era of big data, information systems have exhibited some new features, including boundary obfuscation, system virtualization, unstructure and diversification, and the low coupling degree of function and data. These features not only lead to a big difference between big data technology (DT) and information technology (IT), but also promote the upgrading and evolution of network security technology. In response to these changes, in this paper we compare the characteristics between IT era and DT era, and then propose four DT security principles: privacy, integrity, traceability, and controllability, as well as active and dynamic defense strategy based on “propagation prediction, tracking audit, dynamic management and control”. We further discusses the security challenges faced by DT and the corresponding assurance strategies. On this basis, the big data security technologies can be divided into four levels: “elimination, continuation, improvement, and innovation”, and we provide analyzation, combination and explaination for these technologies according to six categories: access control, identification and authentication, data encryption, data privacy, intrusion prevention, security audit and disaster recovery. These results will offer important assistance for the evolution of security technologies in the DT era, the construction of big data platform, the designation of security assurance strategies, and technology suitable for big data.
    Reference | Related Articles | Metrics
    An Overview of Application and Technology of Artificial Intelligence in Cybersecurity
    Journal of Information Security Reserach    2022, 8 (2): 110-.  
    Abstract2179)      PDF (1142KB)(1498)       Save
    Compared with the developed countries, the basic research and technology application in the field of artificial intelligence in China started later, especially the application of artificial intelligence in the important field of network security. Domestic and abroad disparity is still very obvious, which seriously affects the improvement of China's cybersecurity capability. This paper elaborates the relationship between artificial intelligence, network attack and network defense, and widely investigates the application status of artificial intelligence in major information security companies at home and abroad. It points out that APT detection, 0day vulnerability mining and cloud security are three core areas that affect the level of cybersecurity capability, This paper deeply analyzes the key technologies of artificial intelligence technology applied in these three fields, and puts forward the safety risks of artificial intelligence technology, and points out that artificial intelligence technology is not a panacea for all diseases, This Paper provides a scientific reference for the further research and application of artificial intelligence technology in China's information security industry.
    Reference | Related Articles | Metrics
    Research on Smart Contract Vulnerability Detection Method Based on  Multimodal Feature Fusion
    Journal of Information Security Reserach    2026, 12 (6): 503-.  
    Abstract93)      PDF (1602KB)(61)       Save
    Most of the smart contract vulnerability detection methods rely on single mode feature extraction, which leads to the problem of low detection accuracy due to insufficient key feature extraction. This paper proposes a smart contract vulnerability detection method based on multimodal feature fusion. Firstly, the construction of the control flow graph (CFG) is constructed by leveraging the abstract syntax tree (AST) trimmed at the source code layer and the data flow relationship based on the opcode layer, which is imported into the graph attention network (GAT) to extract two types of static features. Secondly, the fuzzing test report generated by echidna, a dynamic detection tool, is used to extract path coverage, state changes and other information to build a graph model, and the dynamic features are extracted by graph neural network (GNN). Finally, the extracted static and dynamic features are fused and input into CNN bilstm att model for vulnerability detection, and relevant experiments are carried out on 47398 smart contracts. Experimental results show that compared with eight mainstream detection methods, such as SmartCheck, Mythril, Oyente, BiGGNN, ASTNN, DRGCN, SVCB and CBGRU, the accuracy, recall and F1 value of this method in reentry vulnerability, timestamp vulnerability, integer overflow vulnerability and Tx.origin vulnerability are increased by 50.26%, 59.54% and 58.40%.
    Reference | Related Articles | Metrics
    Research and Progress of the Cyber Security Standardization of Smart City
    Journal of Information Security Research    2016, 2 (5): 442-446.  
    Abstract479)      PDF (4021KB)(619)       Save
    The security risks of smart city are the important problems with the development of smart city. The paper introduces cyber security policies of China, the report of ISOIEC JTC1 SG1, the security architecture of smart city proposed by ITUT FG SSC, the overview of Smart America, and the work on cyber security standardization of smart city of TC260. The paper suggests how we develop the cyber security standards of smart city in China.
    Reference | Related Articles | Metrics
    Blockchain Technology and Its Prospect of Industrial Application
    Journal of Information Security Research    2017, 3 (3): 200-210.  
    Abstract598)      PDF (9369KB)(398)       Save
    The Blockchain industry is current developing rapidly globally, with a clearer picture of the whole industry chain. The underlying infrastructure and platform, Blockchain applications in different industry segments, and venture capital investment all have sound foundations. The paper introduces the basic concept and work principle of Blockchain, describes the design philosophy, technological application and security issues of the three mainstream Blockchain platforms nowadays (Bitcoin, Ethernet and Hyperledger), and then puts forward a number of potential Blockchain application scenarios in the world. With great attention on Blockchain in terms of industry application, its helpful for Blockchain practices with Design Thinking and IBM Garage. Both in China and around the world, the paper summarizes the status quo of the Blockchain industry development, and outlines its future in general.
    Reference | Related Articles | Metrics
    Building Cyber Security Defense by Trusted Computing 3.0
    Journal of Information Security Research    2017, 3 (4): 290-298.  
    Abstract449)      PDF (1075KB)(2036)       Save
    Related Articles | Metrics
    The Study of Defect Patterns Matching Based on Static Analysis
    Journal of Information Security Research    2018, 4 (4): 359-363.  
    Abstract378)      PDF (1162KB)(520)       Save
    The software defect mode is the model extracted according to the rules, and the summary of the defects that causes errors or improper running results due to some of the same reasons. Checking the defects by using defect patterns matching technology to the code is more efficient and accurate. We optimize the matching method based on the existing defect modes and methods. We can detect the overflow caused by misusing of increment and decrement through code replacement, and the inconformity of data type through the new regular expression matching statement. We make a check test with Cppcheck, and the experimental results verify the feasibility of the method.
    Reference | Related Articles | Metrics
    High-Performance Cryptographic Computations in GPUs
    Journal of Information Security Research    2019, 5 (1): 88-96.  
    Abstract490)      PDF (2085KB)(617)       Save
    Cryptology is an important foundation and tool of network security. In recent years, with the continuous and rapid development of big data industry, ecommerce and cloud computing, the amount of users, traffic volumes and the corresponding cryptographic calculations faced by various service providers are also rapidly rising. In response to this situation, researchers began to break the conventional pattern that cryptographic algorithms were implemented by CPUs, ASICs, and FPGAs, migrate them to various parallel computing platforms, such as graphics processing units (GPUs). Driven by huge demand of graphics rendering, artificial intelligence, etc., GPUs gain more than ten times of the computing power promotion over the last decade. Such performance advantages help the GPUbased cryptography implementations outperform others by a wide margin, and give them great potential. This paper summarizes the current progress of the GPUbased cryptography implementation, and gives a brief analysis of its development tendency.
    Reference | Related Articles | Metrics
    Application of Network Security Situational Awareness Platform Based on Big Data in the Field of Private Network
    Journal of Information Security Research    2019, 5 (2): 168-175.  
    Abstract271)      PDF (1678KB)(562)       Save
    In order to improve the information security defense capability of the private network, the institutions with private network pay more and more attention to the information network security situational perception technology to realize the prediction and prevention of security events. Based on the brief introduction of situational awareness and related technologies, this paper puts forward a set of applicable network security situational awareness functional architecture targeting industryspecific network needs. This paper details the functional elements contained in each system from the functional level, which would provide reference for relevant institutions to build a network security situational awareness platforms.
    Reference | Related Articles | Metrics
    Research on Maintenance and Security of Industrial Control Networks in Electric Power Industry
    Journal of Information Security Research    2019, 5 (8): 679-684.  
    Abstract267)      PDF (2038KB)(693)       Save
    As an important part of national key infrastructure, the importance of operation and maintenance security of electric power industry control network is selfevident. Especially with the increasing security incidents of industrial control networks in the world in recent years, effective measures must be taken to protect the safe operation of industrial control networks, which also puts forward higher requirements for the operation, maintenance and safety protection of industrial control networks and industrial systems. Through indepth analysis of the characteristics of industrial control network in electric power industry, especially the key characteristics of the data type and network topology structure of the electric power network, effective operation and maintenance methods and security risk prevention methods are put forward. In operation and maintenance, the backup of system data and the state monitoring of the system itself are strengthened. Security measures, such as physical isolation, industrial control flow monitoring, fault recovery management and so on should be taken, and effective policies and behavioral norms should be provided. Finally, form safety protection measures suitable for electric power industry control network, to achieve the purpose of safe operation of the electric power industry control network.
    Reference | Related Articles | Metrics
    Flow Anomaly Detection Based on Hierarchical Clustering Method
    Journal of Information Security Research    2020, 6 (6): 0-0.  
    Abstract1303)      PDF (1784KB)(718)       Save
    With the advent of the big data era, the attacks in network traffic are rising dramatically. Detecting malicious traffic through abnormal flow detection is vital. Nowadays, the equipment of abnormal flow detection used in industry mainly adopts statistical analysis method or simple machine learning method. However, the amount of flow data and redundant data is large. The precision rate is low and the false alarm rate is high. In order to solve these problems, this paper presents a new method to detect flow anomalies based on hierarchical clustering in data processing. This method first uses the hierarchical clustering algorithm to achieve the purpose of data reduction. Then based on seven different machine learning algorithms, an abnormal traffic model based on hierarchical clustering is constructed. The experimental results show that this method can detect the abnormal behavior on the DARPA dataset with a precision rate of 99% and a recall rate of 99%. At the same time, while maintaining the precision rate of 90%, the data reduction can be up to 47.58%, which greatly improves the detection efficiency.
    Related Articles | Metrics
    Research on Browser Security and Trusted Architecture Under Xinchuang System
    Journal of Information Security Reserach    2021, 7 (4): 328-334.  
    Abstract324)      PDF (2293KB)(305)       Save
    With the rapid development of global informatization, the whole world is rapidly merging into one. A large number of information systems have become the key infrastructure of the country and the government. Many enterprises, organizations, government departments and institutions are building and developing their own networks and connecting them to fully share and utilize the information and resources of the network. The whole country and society are more and more dependent on the network. The network has become a powerful driving force for social and economic development, and its status is becoming more and more important. However, when resource sharing is widely used in political, military, economic and scientific fields, there are also various problems, especially security issues. Therefore, it is of great strategic significance in the process of informatization. This paper focuses on the current development of browsers, the security threats faced by browsers, and the security capabilities that browsers should have under the Xinchuang system. As the interface between users and the network information world, this paper still discusses the security solution of browser under the information innovation system.
    Reference | Related Articles | Metrics
    Research on Source Code Vulnerability Detection Based on BERT Model
    Journal of Information Security Reserach    2024, 10 (4): 294-.  
    Abstract494)      PDF (3199KB)(309)       Save
    Techniques such as code metrics, machine learning, and deep learning are commonly employed in source code vulnerability detection. However, these techniques have problems, such as their inability to retain the syntactic and semantic information of the source code and the requirement of extensive expert knowledge to define vulnerability features. To cope with the problems of existing techniques, this paper proposed a source code vulnerability detection model based on BERT(bidirectional encoder representations from transformers) model. The model splits the source code to be detected into multiple small samples, converted each small sample into the form of approximate natural language, realized the automatic extraction of vulnerability features in the source code through the BERT model, and then trained a vulnerability classifier with good performance to realize the detection of multiple types of vulnerabilities in Python language. The model achieved an average detection accuracy of 99.2%, precision of 97.2%, recall of 96.2%, and an F1 score of 96.7% across various vulnerability types. This represents a performance improvement of 2% to 14% over existing vulnerability detection methods. The experimental results showed that the model was a general, lightweight and scalable vulnerability detection method.
    Reference | Related Articles | Metrics
    Blockchain Security Sharding Scheme Based on Multi-dimensional Reputation
    Journal of Information Security Reserach    2024, 10 (8): 690-.  
    Abstract366)      PDF (2816KB)(236)       Save
    Blockchain faces scalability issues. Sharding improves system performance by dividing the blockchain network into multiple subnetworks that process transactions in parallel. However, sharding can lead to the clustering of malicious nodes, resulting in 51% attacks and affecting system security. The existing singledimensional reputation schemes have the problems of high overhead and insufficient shard consensus in the redistribution process, failing to ensure both performance and security. To address these  problems, a blockchain security sharding scheme based on multidimensional reputation is proposed: Firstly, the scheme integrates multidimensional indicators of nodes to balance shard reputation and computational communication abilities, identifying malicious nodes.  Secondly, a twostage redistribution scheme is proposed to reduce the frequency and cost of redistribution through partial redistribution in first stage and complete redistribution in second stage. Finally, a multidimensional reputation based fast Byzantine faulttolerant consensus (MRFBFT) is designed, which combines voting power and reputation, and introduces consensus among shard leader nodes to prevent malicious behavior. The experimental results show that the shard reputation and computational communication level are more balanced, the consensus delay is reduced by about 20%, and the throughput is increased by about 15%.
    Reference | Related Articles | Metrics