Most Download articles

    Published in last 1 year | In last 2 years| In last 3 years| All| Most Downloaded in Recent Month| Most Downloaded in Recent Year|

    Most Downloaded in Recent Month
    Please wait a minute...
    For Selected: Toggle Thumbnails
    Research on Federated Learning-based Intrusion Detection Methods for the Internet of Things
    Journal of Information Security Reserach    2026, 12 (9): 780-788.   DOI: 10.12379/j.issn.2096-1057.2026.09.01
    Abstract83)      PDF (723KB)(26)       Save
    The rapid expansion of the Internet of Things (IoT) has given rise to pressing cybersecurity challenges. Traditional centralized intrusion detection approaches encounter difficulties in balancing model performance and data privacy protection. Federated learning enables collaborative model training without sharing raw data among participants, which provides a novel paradigm for IoT intrusion detection. This paper presents a systematic review of federated learning-driven IoT intrusion detection methods. It first introduces the fundamental background and typical architectures of this research field. It then categorizes existing methods into three types: federated machine learning, federated deep learning, and federated reinforcement learning, and analyzes the characteristics, application scenarios,and existing limitations of each category. This paper further summarizes common enhancement mechanisms, cutting-edge technologies, public datasets, and evaluation indicators used in this field. Finally, this paper discusses key open challenges, including label scarcity, Non-Independent and Identically Distributed (Non-IID) data, federated multimodal large models and security enhancement, and proposes potential future research directions. This review can provide a useful technical reference for subsequent research and practical applications in this field.
    Reference | Related Articles | Metrics
    The Structural Risk Evolution of Virtual Currency Crimes and Chinese Governance Practices
    Journal of Information Security Reserach    2026, 12 (9): 860-866.   DOI: 10.12379/j.issn.2096-1057.2026.09.09
    Abstract53)      PDF (683KB)(26)       Save
    With the deep development of blockchain technology and the accelerated integration of the global digital economy, virtual currencies are reshaping the financial ecosystem, but simultaneously giving rise to new types of criminal activities with diverse forms and far-reaching harms. These activities exhibit deep-seated characteristics such as disembedded subject identities, modularized criminal activities, technological iteration of criminal methods, and networked criminal hazards, becoming new structural risk carriers in the financial sector. Based on the triple analytical framework of “technology-institution-capital,” this paper systematically analyzes the evolutionary path and deep-seated generation logic of virtual currency crimes from instrumental application to ecological infiltration. On this basis, transcending simple policy reviews, this paper theoretically refines Chinese practical experience in governing new types of virtual currency crimes. The research shows that China has constructed a comprehensive and penetrative governance system through the reshaping of the institutional dimension, the countermeasures in the technological dimension, and the regulation of the capital dimension. This practice not only effectively curbs local risks but also contributes Chinese wisdom with theoretical depth and practical value to risk governance and order reconstruction in the era of global digital finance.
    Reference | Related Articles | Metrics
    Overview on SM9 Identity Based Cryptographic Algorithm
    Journal of Information Security Research    2016, 2 (11): 1008-1027.  
    Abstract3804)      PDF (13949KB)(6271)       Save
    SM9 identitybased cryptographic algorithm is an identitybased cryptosystem with bilinear pairings. In such a system the user s private key and public key may be extracted from user s identity and key generation centers parameters. The most common cryptographic uses of SM9 are with digital signature, data encryption, key exchange protocol and key encapsulation mechanism etc. The application and management of SM9 will not require digital certificate, certificate base, and key base. The key length of the SM9 cipher algorithm is 256b. SM9 cryptographic algorithm was issued as the cryptography standard in 2015. This paper will summarize the design, algorithm, software and hardware implementation and cryptanalysis of SM9 cryptographic algorithm. We also give some concrete examples in appendix.
    Reference | Related Articles | Metrics
    Research on Data Classification and Grading Method Based on Data Security Law
    Journal of Information Security Reserach    2021, 7 (10): 933-.  
    Abstract1745)      PDF (2157KB)(1136)       Save
    The Data Security Law of the People's Republic of China (hereinafter referred to as the Data Security Law) has been formally promulgated, which clearly stipulates that the state establishes data classification and grading protection system, and implements classified and graded protection for data. However, at present, the relevant standards and specifications of data classification and grading in China are relatively lacking, and the practical experiences that can be used for reference in various industries are relatively insufficient. How to effectively implement the data classification and grading protection is still a thorny problem. Based on Article 21 of the Data Security Law, this paper analyzes the factors such as the influence object, influence breadth and influence depth after the data is damaged, puts forward the principles and methods of data classification and data grading, and gives an implementation path of data classification and grading according to the application scenarios and industry characteristics of the data, which provide a certain reference for data classification and grading protection of various industries.
    Reference | Related Articles | Metrics
    Research on the Legal Positioning and Liability Allocation of AI Agent
    Journal of Information Security Reserach    2026, 12 (8): 681-690.   DOI: 10.12379/j.issn.2096-1057.2026.08.01
    Abstract237)      PDF (682KB)(19)       Save
    The autonomous operation and continuous functioning capabilities of AI agents have transcended the operational boundaries of traditional generative AI, which centers on the "input-output" paradigm, and present new normative challenges to the existing "tool-control-responsibility" framework a framework predicated on stable human control. In terms of behavior identification, responsibility attribution, and operational regulation, the current legal system is insufficient to fully accommodate the cross-subject, multi interactive, and continuously operating characteristics of AI agents. Against this backdrop, this paper contends that AI agents should not be granted independent legal personality. Instead, it proposes a response grounded in the functional reconstruction of traditional static tool-oriented rules, while preserving the stability of the existing subject system. Adopting "functional instrumentalism" as the fundamental legal orientation for AI agents, this paper constructs a dual track identification framework "technological identity" and "legal attribution" to align behavioral identifiability with responsibility attributability under conditions of continuous operation. Furthermore, it introduces a "relationalist attribution" approach, which takes control relationships, interest structures, and risk sources as analytical dimensions to allocate responsibilities among multiple subjects in a structured manner. Employing the "principle of minimum necessity" as the boundary for institutional expansion, the paper thereby outlines an integrated governance framework that connects current law, special rules, and technical standards. Accordingly, the logic of AI governance is shifting from a static structure centered on behavioral outcomes and one off liability determinations toward a dynamic structure oriented around process of continuous operation.
    Reference | Related Articles | Metrics
    Log Anomaly Detection Method based on LLM-Enhanced Dynamic Graph Relational Learning and Explainable Diagnosis
    Journal of Information Security Reserach    2026, 12 (9): 823-830.   DOI: 10.12379/j.issn.2096-1057.2026.09.05
    Abstract86)      PDF (979KB)(15)       Save
    System logs record the complete operational data of computer systems, and form the core foundation for system stability assurance, security guarantee and fault diagnosis. Existing graph-based log anomaly detection methods are incapable of extracting deep log semantics, mitigating class imbalance, modeling complex temporal dependencies, and providing intuitive anomaly interpretation simultaneously. This paper presents an anomaly detection scheme that integrates Large Language Model and dynamic graph networks. Based on the classic Graph Log Anomaly Detection framework, this paper incorporates semantic augmentation, data augmentation and multi-scale temporal graph modeling to propose LLM-GLAD, an LLM-driven log relational anomaly detection framework. An interpretable diagnosis module based on LLM is constructed to generate natural language anomaly explanations and root cause suggestions for practical deployment. Comparative experiments conducted on three public log datasets demonstrate that the proposed method achieves a precision of 96.45%, a recall of 93.43% and an F1-score of 94.92%.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E2): 39-.  
    Abstract123)      PDF (1221KB)(57)       Save
    Reference | Related Articles | Metrics
    Survey of Software Supply Chain Security Detection and Assessment Technologies
    Journal of Information Security Reserach    2026, 12 (7): 586-597.  
    Abstract145)      PDF (1750KB)(79)       Save
    In the context of the digital era, software supply chain has become a critical component supporting the stable and healthy development of the digital economy. It is an indispensable part of the nation’s key information infrastructure and economic and social systems. The security of software supply chain directly determines the security of the key businesses carried by the software supply chain. Therefore, based on the development needs of the digital age, this article summarizes the current technologies, methods, and development trends related to software supply chain security detection and evaluation, providing reference and guidance for industry insiders, researchers, and decisionmakers. It includes a review and detailed explanation of the background and methods of software supply chain security detection and evaluation technology, detailing the principles of mainstream technologies such as component analysis, vulnerability scanning, code review, runtime monitoring, threat modeling, and fuzz testing, and comparing and analyzing the advantages and disadvantages of various technologies; Analyze the current technical challenges and countermeasures faced by technology; And propose ten major trends for the development of this field in the next decade, in order to improve the security level of the software supply chain and promote the development of the software industry.
    Reference | Related Articles | Metrics
    A Construction Method of Hybrid Covert Channels Based on Federated Learning
    Journal of Information Security Reserach    2026, 12 (9): 789-800.   DOI: 10.12379/j.issn.2096-1057.2026.09.02
    Abstract60)      PDF (3249KB)(13)       Save
    Federated Learning (FL) is designed to solve the irreconcilable contradiction between data sharing requirements and privacy needs. As a kind of distributed machine learning, FL needs to exchange a large number of model parameters between participants and the central server, which leads to a large amount of data communication. The iterative process of FL model updating depends on distributed data transmission, and once the transmission channel is located, its model data security and integrity will be difficult to guarantee. In this paper, a hybrid Covert Storage-Timing Channel (CSTC) scheme for FL is proposed. The secret message is firstly split into parallel-distributed coding units, and the secret data communication is achieved via adjusting the inter-packet delays to indicate which block is to be transmitted, and the overt traffic’s packet payload is selectively replaced with secret blocks according to the payload content. Thus, the position indicator of a secret block is embedded in both the time and storage features of the overt traffic, while the feature-location correspondence is pre-shared by the receiver and sender, and the adversary cannot grasp a secret message unless all features locating the secret block are obtained. Moreover, three variants of the original CSTC are proposed to fulfill the different performance requirements, and the experiments show that the undetectability and capacity of the proposed schemes are reasonable.
    Reference | Related Articles | Metrics
    A Review of Large Language Model-Driven Network Penetration Testing Agents
    Journal of Information Security Reserach    2026, 12 (8): 691-711.   DOI: 10.12379/j.issn.2096-1057.2026.08.02
    Abstract167)      PDF (3915KB)(12)       Save
    With the accelerated development of artificial intelligence, intelligent agents have demonstrated notable advantages in environmental perception, task planning, and multi-tool coordination. Concurrently, breakthroughs in Large Language Models concerning natural language understanding, logical reasoning, and multimodal processing have provided crucial support for the evolution of intelligent agents. The deep integration of these two technological strands has given rise to LLM-driven autonomous agents for network penetration testing, promoting a gradual shift from the traditional "tool-assisted" paradigm toward "autonomous intelligence." This paper systematically reviews the key challenges and principal technical approaches identified in existing research across four core modules: agent role definition, task planning, memory management, and interactive execution. It further examines the limitations of current methods in areas such as multimodal information processing, automated interaction, and context management. To address these issues, and in view of the ongoing technological evolution of intelligent agents, this paper proposes several promising research directions for intelligent penetration testing. These include multimodal fusion mechanisms, collaborative strategies integrating memory enhancement with reinforcement learning, and knowledge-graph-based vulnerability discovery methods. The analysis indicates that LLM-driven agents for network penetration testing provide substantial technical support for advancing the intelligence and autonomy of cybersecurity operations.
    Reference | Related Articles | Metrics
    Federated Learning Backdoor Attack Method Based on Dynamic Trigger Transformation
    Journal of Information Security Reserach    2026, 12 (9): 801-812.   DOI: 10.12379/j.issn.2096-1057.2026.09.03
    Abstract63)      PDF (1674KB)(12)       Save
    To address the rapid degradation of fixed-trigger backdoor attacks in Federated Learning after attack termination, a backdoor attack method based on dynamic trigger transformation was developed. The method dynamically adjusted the position, size, and pattern of the trigger during federated training, selected trigger states according to historical attack success rates in data preprocessing, and introduced supervised contrastive learning in the adaptation stage to align representations of poisoned samples with the target class and mitigate catastrophic forgetting. Experiments were conducted on MNIST, CIFAR-10, and Tiny-ImageNet under multiple aggregation algorithms and five representative defense mechanisms, evaluating attack effectiveness, stealthiness, and persistence. The attack success rate exceeded 95% across the evaluated defense scenarios. In the CIFAR-10 setting, the attack success rate remained approximately 90% after trigger injection had been stopped for 1,000 rounds. These results indicate that dynamic trigger selection and supervised contrastive learning improve the persistence and adaptability of federated learning backdoor attacks.
    Reference | Related Articles | Metrics
    VEDA, Establishing the AI Dynamic Defense System for Cyber Security
    Journal of Information Security Research    2017, 3 (12): 1058-1066.  
    Abstract448)      PDF (1526KB)(992)       Save
    Related Articles | Metrics
    Overview of Data Security Governance at Home and Abroad
    Journal of Information Security Reserach    2021, 7 (10): 922-.  
    Abstract1876)      PDF (3579KB)(1083)       Save
    With the rapid development of digital economy, privacy infringement, data leakage, platform monopoly, misinformation and other issues emerge one after another, increasingly becoming an important issue that threatens individual rights, industrial development and national security. This article, on the national policy and law level, sorts out four categories of data governance, that is, personal data protection, cross-border data flow regulation, data market governance, and data content management. Countries and regions like United States, European Union and China are the centers of global digital economy. This article summarizes their practices and experience in above-mentioned four categories, and on this basis, puts forward some suggestions on strengthening China's data security governance system and capacity building, that is, further improving the legal system to compete for the leadership of the digital economy, deeply participating in global data governance to enhance the international voice of rule-making, and strengthening support and oversight of new technologies and applications to seize new heights in digital economy governance.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E2): 141-.  
    Abstract50)      PDF (2650KB)(39)       Save
    Reference | Related Articles | Metrics
    The Mechanism of Disinformation Generation and Governance Pathways in Generative AI Models
    Journal of Information Security Reserach    2026, 12 (7): 606-612.  
    Abstract138)      PDF (1256KB)(39)       Save
    While driving transformations in online information order, generative AI models also generate disinformation risks characterized by an “objective+subjective” overlap. An analytical framework tailored to their technical characteristics is urgently needed. This study systematically deconstructs the technical logic of false information production in generative AI models based on their hybrid expert architecture, treelike reasoning patterns, localized semantic understanding attributes, and opensource ecosystem mechanisms. It analyzes the transmission mechanisms of false information risks across four stages: data input, algorithmic operation, content presentation, and cognitive dissemination. To address these risks: At the algorithmic level, implement a processbased oversight scheme encompassing “access reviewoperation disclosurepostevent verification”; at the presentation level, strengthen scenariobased, interactive “warning notice” labeling mechanisms; at the cognitive level, cultivate users' digital literacy and selfrestraintt capabilities to achieve effective information security governance in the AI era.
    Reference | Related Articles | Metrics
    Risk Analysis and Governance Approaches for Online Protection of Minors in the Age of Artificial Intelligence
    Journal of Information Security Reserach    2026, 12 (9): 867-876.   DOI: 10.12379/j.issn.2096-1057.2026.09.10
    Abstract63)      PDF (684KB)(11)       Save
    The rapid advancement of Artificial Intelligence (AI), while offering minors diverse opportunities in education, entertainment, and social interaction. However, it has simultaneously catalyzed a range of complex new victimization risks. These include deepfake identity fraud, virtual sexual exploitation, cyberbullying, internet addiction, misinformation and fraud, algorithmic discrimination, and privacy breaches. Traditional governance models are inadequate to fully address these emerging threats. Through a comparative analysis of legal policies and governance practices across different countries and regions, this study identifies distinct approaches: the European Union emphasizes rights-based orientations and platform accountability, the United States prioritizes interstate innovation and flexible regulation, while China focuses on institutional development and educational guidance. These differences reflect varied governance traditions and offer valuable insights for international mutual learning and cooperation. Consequently, this paper proposes five pathways for protecting minors online in the AI era: Firstly, innovating legal policies to provide agile responses to novel AI risks. Secondly, fostering home-school collaborative education to enhance minors' digital literacy. Thirdly, leveraging technological innovation to promote safe and user-friendly AI interaction design. Fourthly, strengthening platform governance and supervision through targeted rectification of the online environment. Fifthly, facilitating the integration of government, industry, academia, and research to enable multi-stakeholder participation in comprehensive governance. This research aims to provide academic support and policy implications for the theoretical construction and practical pathways of the protection of minors in the AI era, ultimately contributing to the creation of a safe, healthy, and inclusive digital ecosystem for minors.
    Reference | Related Articles | Metrics
    Survey of Hash Functions
    Wang Xiaoyun1,2 and Yu Hongbo3
    Journal of Information Security Research    2015, 1 (1): 19-30.  
    Abstract1836)      PDF (11279KB)(3930)       Save
    One of the fundamental primitives in modern cryptography is the cryptographic hash functions, often informally called hash functions. They are used to compress messages of arbitrary length to fixed length hash values which are also called hash codes, message digests or digital fingerprints. A primary motivation for cryptographic hash functions is that they serve as compact representative images of input messages, which they can uniquely identify. Changing a single letter will change most of the digits in the hash code. The most common cryptographic uses of hash functions are with digital signature and for data integrity. Hash functions are frequently used in digital signature schemes to compress large messages for processing by public-key cryptosystems such as RSA. They are also used to design message authentication codes (MACs) and many secure cryptographic protocols. Hash functions occur as components in various cryptographic applications (e.g. protection of pass-phrases, protocols for payment, broadcast authentication etc.), where usually their property as a computational one-way function is used. So the study of the hash functions is of great significance in the cryptanalysis field.
    Related Articles | Metrics
    Research and Progress of the Cyber Security Standardization of Smart City
    Journal of Information Security Research    2016, 2 (5): 442-446.  
    Abstract480)      PDF (4021KB)(624)       Save
    The security risks of smart city are the important problems with the development of smart city. The paper introduces cyber security policies of China, the report of ISOIEC JTC1 SG1, the security architecture of smart city proposed by ITUT FG SSC, the overview of Smart America, and the work on cyber security standardization of smart city of TC260. The paper suggests how we develop the cyber security standards of smart city in China.
    Reference | Related Articles | Metrics
    Research on Webshell Detection Method Based on Logistic Regression Algorithm
    Journal of Information Security Research    2019, 5 (4): 298-302.  
    Abstract290)      PDF (1096KB)(710)       Save
    Webshell is a commonly used tool for hackers to carry out network intrusion. It has the characteristics of high concealment and great power. The existing Webshell detection method has high detection accuracy when detecting known Webshell, but the detection accuracy is very low in the face of complex and flexible unknown and variant Webshell. In response to this problem, this paper discusses the characteristics and working principle of Webshell, analyzes the difference between Webshell and the traditional Webshell using obfuscated encryption coding technology, and proposes a Webshell machine learning detection model based on logistic regression algorithm. The model can effectively detect the confusingly coded Webshell, reduce the false positive rate and improve the detection accuracy.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E2): 2-.  
    Abstract79)      PDF (1416KB)(55)       Save
    Reference | Related Articles | Metrics
    An Intrusion Detection Method for Industrial Control Systems Integrating Memory Autoencoder and CNN-Transformer
    Journal of Information Security Reserach    2026, 12 (9): 831-841.   DOI: 10.12379/j.issn.2096-1057.2026.09.06
    Abstract51)      PDF (1467KB)(9)       Save
    To address the problems of high false alarm rate in unsupervised detection and insufficient generalization capability of supervised detection in existing industrial control system intrusion detection methods, this paper proposes an intrusion detection method integrating memory autoencoder and CNN-Transformer. First, the sliding window technique is employed to construct temporal contexts, so as to mitigate detection blind spots caused by static features. Second, multi-dimensional feature enhancement is implemented to expand the original data representation, which improves the model's robustness against complex attack patterns and reduces misclassification caused by insufficient dimensionality. Furthermore, a Memory AutoEncoder (MemAE) and a Transformer-equipped Convolutional Neural Network (CNN-Transformer) are constructed as supervised models, and a parallel intrusion detection model termed MemAE-CT is established by combining the two modules. The proposed model incorporates an adaptive weight distribution mechanism to dynamically adjust the decision contribution of each component, thereby balancing the accurate identification of known attacks and the generalized detection of unknown threats. The proposed method achieves an accuracy of 97.26% and an F1-score of 96.23% on the natural gas pipeline dataset released by Mississippi State University, which verifies its excellent performance. Its generalization capability is further validated on the CICIDS2017 dataset, and the method provides a reliable solution for industrial control system security.
    Reference | Related Articles | Metrics
    To Create a Positive Cyberspace by Safeguarding Network Security with Active Immune Trusted Computing 3.0
    Journal of Information Security Research    2018, 4 (4): 282-302.  
    Abstract278)      PDF (2291KB)(993)       Save
    Related Articles | Metrics
    Trend on Cybersecurity Policy Risks of the Trump Administration and China Countermeasures
    Journal of Information Security Research    2018, 4 (10): 870-880.  
    Abstract278)      PDF (1337KB)(1029)       Save
    Reference | Related Articles | Metrics
    DBAPPSecurity:Support Security China, Boost Digital Economy
    Journal of Information Security Research    2019, 5 (4): 274-281.  
    Abstract213)      PDF (3884KB)(818)       Save
    Related Articles | Metrics
    Design and Implementation of Dark Net Data Crawler Based on Tor
    Journal of Information Security Research    2019, 5 (9): 798-804.  
    Abstract1436)      PDF (3976KB)(1522)       Save
    tWith the development of anonymous communication technology, more and more users begin to use anonymous communication to protect personal privacy. Tor, as the most popular application of anonymous communication system, can effectively prevent behavior such as traffic sniffing, eavesdropping and other behaviors. While protecting the privacy of users from being stolen, “dark net” is also used by many criminals. Thus, this has brought great challenges to the supervision of public security. How to strengthen the regulation and crackdown on illegal information of dark network websites is an urgent problem to be solved. Therefore, the data of crawling anonymous websites is an important basis for supervising those websites effectively. The most mainstream dark network anonymous communication system Tor was introduced briefly, its technical principles were analyzed, and a dark network data crawler program was designed, which mainly use Selenium to enter the Tor network, bulk crawl the dark Web pages and save the data to the local. It will help the public security department to further monitor and analyze the relevant content in the dark network, and also propose a feasible technical means for the police department to supervise the dark network.
    Reference | Related Articles | Metrics
    Flow Anomaly Detection Based on Hierarchical Clustering Method
    Journal of Information Security Research    2020, 6 (6): 0-0.  
    Abstract1306)      PDF (1784KB)(725)       Save
    With the advent of the big data era, the attacks in network traffic are rising dramatically. Detecting malicious traffic through abnormal flow detection is vital. Nowadays, the equipment of abnormal flow detection used in industry mainly adopts statistical analysis method or simple machine learning method. However, the amount of flow data and redundant data is large. The precision rate is low and the false alarm rate is high. In order to solve these problems, this paper presents a new method to detect flow anomalies based on hierarchical clustering in data processing. This method first uses the hierarchical clustering algorithm to achieve the purpose of data reduction. Then based on seven different machine learning algorithms, an abnormal traffic model based on hierarchical clustering is constructed. The experimental results show that this method can detect the abnormal behavior on the DARPA dataset with a precision rate of 99% and a recall rate of 99%. At the same time, while maintaining the precision rate of 90%, the data reduction can be up to 47.58%, which greatly improves the detection efficiency.
    Related Articles | Metrics
    A Survey of Zero Trust Research
    Journal of Information Security Research    2020, 6 (7): 608-614.  
    Abstract1533)      PDF (2068KB)(1702)       Save
    With the popularization of cloud computing, mobile office and other technologies, the enterprise network structure becomes complex. The traditional network security model is based on the idea of boundary protection, which can not meet the current needs. Zero trust is a new network security model, where no distinction is made between internal and external networks and all entities need authentication and authorization before accessing resources, which can be used to protect the network whose perimeter is increasingly fuzzy. This paper gives the definition of zero trust, introduces the architecture of zero trust, analyzes the core technology of zero trust, compares and analyses several representative zero trust schemes, summarizes the development status, points out the research direction needing attention in this field, which can provide reference for the research and application of zero trust.
    Reference | Related Articles | Metrics
    A Survey of Research on Network Attack Model
    Journal of Information Security Research    2020, 6 (12): 1058-1067.  
    Abstract1480)      PDF (1774KB)(1211)       Save
    With the rapid development of information technology, network attacks have gradually presented multi-stage, distributed and intelligent characteristics. Single firewalls, intrusion detection systems and other traditional network defense measures cannot well protect the network system security in an open environment. As a kind of attack scene representation from the attacker's perspective, the network attack model can comprehensively describe the network attack behavior in a complex and changeable environment, and is one of the commonly used network attack analysis and response tools. This paper first introduces the current main network attack models, including traditional trees, graphs, nets structure models and modern attack chains, ATT&CK, diamond models, etc. Then the analysis and application of network attack model will be explained. The analysis process for the purpose of solving the attack index mainly includes the probability framework, the assignment method and the solution method, and the application of the attack model based on the life cycle includes the application of the attackers and the defenders' perspective; Finally, the current challenges and future directions of the network attack model and its analysis and application are summarized.
    Reference | Related Articles | Metrics
    A Review of Adversarial Attack on Autonomous Driving Perception System
    Journal of Information Security Reserach    2024, 10 (9): 786-.  
    Abstract634)      PDF (1560KB)(325)       Save
    The autonomous driving perception system collects surrounding environmental information through various sensors and processes this data to detect vehicles, pedestrians and obstacles, providing realtime foundational data for subsequent control and decisionmaking functions. Since sensors are directly connected to the external environment and often lack the ability to discern the credibility of inputs, the perception systems are  potential targets for various attacks. Among these, adversarial example attack is a mainstream attack method characterized by high concealment and harm. Attackers manipulate or forge input data of the perception system to deceive the perception algorithms, leading to incorrect output results by the system. Based on the research of existing relevant literature, this paper systematically summarizes the working methods of the autonomous driving perception system, analyzes the adversarial example attack schemes and defense strategies targeting the perception system. In particular, this paper subdivide the adversarial examples for the autonomous driving perception system into signalbased adversarial example attack scheme and objectbased adversarial example attack scheme. Additionally, the paper comprehensively discusses defense strategy of the adversarial example attack for the perception system, and subdivide it into anomaly detection, model defense, and physical defense. Finally, this paper prospects the future research directions of adversarial example attack targeting autonomous driving perception systems.
    Reference | Related Articles | Metrics
    A LTE NAS Protocol Fuzzing Method Based on Weighted State Selection
    Journal of Information Security Reserach    2025, 11 (1): 12-.  
    Abstract197)      PDF (1581KB)(60)       Save
    NAS protocol is the main control plane protocol between mobile devices and LTE core network, and its security is of great significance to ensure the robustness and safety of the whole 4G network. Fuzz testing is a widely used vulnerability mining technique, and existing fuzz testing methods for NAS Protocol have problems such as low testing efficiency and difficulty test case formulation. In order to solve these problems, this paper e proposes a weight based test state selection algorithm, which is based on NAS protocol state machine and can dynamically adjust the weight of test states based on feedback; Additionally, this paper devises a test case generation strategy rooted in the information element and develops the fuzzing tool named NASFuzzer, which is tested on open source core networks open5GS and real terminal devices. The test result shows that the method in this paper can effectively find the vulnerabilities in the LTE NAS protocol implementation.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2026, 12 (2): 98-.  
    Abstract204)      PDF (532KB)(134)       Save
    Related Articles | Metrics
    Research on Smart Contract Vulnerability Detection Method Based on  Multimodal Feature Fusion
    Journal of Information Security Reserach    2026, 12 (6): 503-.  
    Abstract117)      PDF (1602KB)(67)       Save
    Most of the smart contract vulnerability detection methods rely on single mode feature extraction, which leads to the problem of low detection accuracy due to insufficient key feature extraction. This paper proposes a smart contract vulnerability detection method based on multimodal feature fusion. Firstly, the construction of the control flow graph (CFG) is constructed by leveraging the abstract syntax tree (AST) trimmed at the source code layer and the data flow relationship based on the opcode layer, which is imported into the graph attention network (GAT) to extract two types of static features. Secondly, the fuzzing test report generated by echidna, a dynamic detection tool, is used to extract path coverage, state changes and other information to build a graph model, and the dynamic features are extracted by graph neural network (GNN). Finally, the extracted static and dynamic features are fused and input into CNN bilstm att model for vulnerability detection, and relevant experiments are carried out on 47398 smart contracts. Experimental results show that compared with eight mainstream detection methods, such as SmartCheck, Mythril, Oyente, BiGGNN, ASTNN, DRGCN, SVCB and CBGRU, the accuracy, recall and F1 value of this method in reentry vulnerability, timestamp vulnerability, integer overflow vulnerability and Tx.origin vulnerability are increased by 50.26%, 59.54% and 58.40%.
    Reference | Related Articles | Metrics
    Research of Few-Shot Intrusion Detection Based on the Meta-SGD+ANIL Meta-Learning Framework
    Journal of Information Security Reserach    2026, 12 (8): 712-720.   DOI: 10.12379/j.issn.2096-1057.2026.08.03
    Abstract98)      PDF (1150KB)(8)       Save
    Aiming at the problems of scarce samples for certain attack types, attack sample imbalance, and difficulty in detecting new attacks in network intrusion detection, this paper proposed a meta-learning framework based on the Meta-SGD+ANIL algorithm. The goal is to improve the efficiency and accuracy of few-shot intrusion detection, and enhance the model’s ability to recognize minority-class attacks and unknown attacks. Starting from the application and optimization of data augmentation and meta-learning algorithms, we first perform oversampling and undersampling on imbalanced datasets, then dynamically generate few-shot tasks to provide training scenarios for the model. Using the Meta-SGD algorithm, we enable the model to learn an adaptive learning rate for each parameter of the specific network, thereby improving the parameter update efficiency in different attack scenarios. Secondly, we introduce ANIL’s core idea on top of Meta-SGD: only the parameters of the classification layer or partial network layers are subject to dynamic learning rate adjustment, which effectively balances model adaptiveness and computational efficiency. Experiments on the few-shot image dataset Omniglot show that time overhead is reduced by 20% with only a slight drop in accuracy. On the CIC-IDS2017 and CSE-CIC-IDS2018 datasets, compared with traditional methods, the Meta-SGD algorithm improves the model’s accuracy by an average of 8.89%. After introducing ANIL, accuracy decreases only slightly, while training time is reduced by 18 % and 22 % respectively.
    Reference | Related Articles | Metrics
    Three-Dimensional Way of Acorn Network in Industrial Control Cybersecurity
    Journal of Information Security Research    2017, 3 (8): 0-0.  
    Abstract512)      PDF (3703KB)(840)       Save
    Related Articles | Metrics
    Improve Cyber Confrontation Capability in Actual Combat Experience
    Journal of Information Security Research    2018, 4 (5): 405-406.  
    Abstract190)      PDF (896KB)(406)       Save
    Related Articles | Metrics
    Research on Browser Security and Trusted Architecture Under Xinchuang System
    Journal of Information Security Reserach    2021, 7 (4): 328-334.  
    Abstract327)      PDF (2293KB)(308)       Save
    With the rapid development of global informatization, the whole world is rapidly merging into one. A large number of information systems have become the key infrastructure of the country and the government. Many enterprises, organizations, government departments and institutions are building and developing their own networks and connecting them to fully share and utilize the information and resources of the network. The whole country and society are more and more dependent on the network. The network has become a powerful driving force for social and economic development, and its status is becoming more and more important. However, when resource sharing is widely used in political, military, economic and scientific fields, there are also various problems, especially security issues. Therefore, it is of great strategic significance in the process of informatization. This paper focuses on the current development of browsers, the security threats faced by browsers, and the security capabilities that browsers should have under the Xinchuang system. As the interface between users and the network information world, this paper still discusses the security solution of browser under the information innovation system.
    Reference | Related Articles | Metrics
    An Overview of Application and Technology of Artificial Intelligence in Cybersecurity
    Journal of Information Security Reserach    2022, 8 (2): 110-.  
    Abstract2187)      PDF (1142KB)(1498)       Save
    Compared with the developed countries, the basic research and technology application in the field of artificial intelligence in China started later, especially the application of artificial intelligence in the important field of network security. Domestic and abroad disparity is still very obvious, which seriously affects the improvement of China's cybersecurity capability. This paper elaborates the relationship between artificial intelligence, network attack and network defense, and widely investigates the application status of artificial intelligence in major information security companies at home and abroad. It points out that APT detection, 0day vulnerability mining and cloud security are three core areas that affect the level of cybersecurity capability, This paper deeply analyzes the key technologies of artificial intelligence technology applied in these three fields, and puts forward the safety risks of artificial intelligence technology, and points out that artificial intelligence technology is not a panacea for all diseases, This Paper provides a scientific reference for the further research and application of artificial intelligence technology in China's information security industry.
    Reference | Related Articles | Metrics
    Research on Source Code Vulnerability Detection Based on BERT Model
    Journal of Information Security Reserach    2024, 10 (4): 294-.  
    Abstract505)      PDF (3199KB)(312)       Save
    Techniques such as code metrics, machine learning, and deep learning are commonly employed in source code vulnerability detection. However, these techniques have problems, such as their inability to retain the syntactic and semantic information of the source code and the requirement of extensive expert knowledge to define vulnerability features. To cope with the problems of existing techniques, this paper proposed a source code vulnerability detection model based on BERT(bidirectional encoder representations from transformers) model. The model splits the source code to be detected into multiple small samples, converted each small sample into the form of approximate natural language, realized the automatic extraction of vulnerability features in the source code through the BERT model, and then trained a vulnerability classifier with good performance to realize the detection of multiple types of vulnerabilities in Python language. The model achieved an average detection accuracy of 99.2%, precision of 97.2%, recall of 96.2%, and an F1 score of 96.7% across various vulnerability types. This represents a performance improvement of 2% to 14% over existing vulnerability detection methods. The experimental results showed that the model was a general, lightweight and scalable vulnerability detection method.
    Reference | Related Articles | Metrics
    Federated Foundation Model Finetuning Based on Differential Privacy#br#
    #br#
    Journal of Information Security Reserach    2024, 10 (7): 616-.  
    Abstract601)      PDF (1752KB)(286)       Save
    As the availability of private data decreases, large model finetuning based on federated learning has become a research area of great concern. Although federated learning itself has a certain degree of privacy protection, privacy security issues such as gradient leakage attacks and embedding inversion attacks on large models still threaten the sensitive information of participants. In the current context of increasing awareness of privacy protection, these potential privacy risks have significantly hindered the promotion of large model finetuning based on federated learning in practical applications. Therefore, this paper proposes a federated large model embedding differential privacy control algorithm, which adds controllable random noise to the embedded model of the large model during efficient parameter finetuning process through a global and local dual privacy control mechanism to enhance the privacy protection ability of federated learning based large model parameter finetuning. In addition, this paper demonstrates the privacy protection effect of this algorithm in large model finetuning through experimental comparisons of different federation settings, and verifies the feasibility of the algorithm through performance comparison experiments between centralization and federation.
    Reference | Related Articles | Metrics