Most Down Articles

    Published in last 1 year | In last 2 years| In last 3 years| All| Most Downloaded in Recent Month | Most Downloaded in Recent Year|

    All
    Please wait a minute...
    For Selected: Toggle Thumbnails
    Power Analysis Attack against SM4 in Frequency Domain
    WANG Min, RAO Jin-tao, WU Zhen, DU Zhi-bo
    Netinfo Security    2015, 15 (8): 14-19.   DOI: 10.3969/j.issn.1671-1122.2015.08.003
    Abstract1510)   HTML280)    PDF (1755KB)(124705)      

    SM4 algorithm is the first open promulgated Chinese commercial block cipher algorithm. Since the algorithm is promulgated, some study on cryptanalysis of SM4 algorithm including side channel attack(SCA) by domestic and foreign scholars have been done. Recent literature study on SCA aremanily focus on power attack in time domain to compromise the secret password. But pure signal analysis in time domain has limitation. For instance, the alignment quality of power signal in time domain is the key factor to in fluence power analysis attack. In order to eliminate the effect of the signal alignment on the power analysis attack, the method of the power analysis attack against in frequency domain is proposed. The power analysis attack in frequency domain is not only feasible, but also can elimi nate the effect of the signal alignment. Finally, the method in this paper is successfully im plemented on the SM4 cryptographic in FPGA, in the case of no alignment operation in the frequency domain. The experimental results show that the proposed attack method is effec tive.

    Table and Figures | Reference | Related Articles | Metrics
    A Revocable Authorization Provable Data Possession Scheme in Clouds
    ZHAO Yang, CHEN Yang, XIONG Hu, REN Hua-qiang
    Netinfo Security    2015, 15 (8): 1-7.   DOI: 10.3969/j.issn.1671-1122.2015.08.001
    Abstract671)   HTML230)    PDF (2071KB)(33009)      

    There are two main provable data possession schemes: public verification and verification, but it is very difficult when users want to specify a third party to verify the data. In this regard, we propose a revocable authorization provable data possession scheme in clouds. The scheme allows users to authorize a third party audit to help them perform remote data integrity verification. This can protect users’ privacy. In addition, users can revoke the third party audit’s authorization when they need and authorize a new third party. In our scheme only the third party it has the authorization can complete the verification process and give back the result to users. Furthermore, users can choose to keep the authorized evidence secret, authorize to a third party or public to achieve private verification, authorized verification or public verification. The scheme is designed base on bilinear pairing and identity-based encryption (IDE) technology. And it achieves authorization verification or revocation by embedding authorized evidence to integrity verification. Then we analyze the security and performance of the scheme to prove the scheme is safety and efficiency at last of the paper.

    Table and Figures | Reference | Related Articles | Metrics
    Netinfo Security    2015, 15 (8): 82-82.  
    Abstract547)   HTML34)    PDF (1120KB)(13371)      
    Table and Figures | Reference | Related Articles | Metrics
    Baseline for Classified Protection of Cybersecurity (GB/T 22239-2019) Standard Interpretation
    Li MA, Guobang ZHU, Lei LU
    Netinfo Security    2019, 19 (2): 77-84.   DOI: 10.3969/j.issn.1671-1122.2019.02.010
    Abstract15446)   HTML920)    PDF (8866KB)(10642)      

    Baseline for Classified Protection of Cybersecurity(GB/T 22239-2019) will be formally implemented soon. This paper introduces the background and process of the revision GB/T 22239-2019, the main changes in comparison with GB/T 22239-2008, the main contents of its security general requirements and security special requirements, etc., so as to enable users to better understand and master the contents of GB/T 22239-2019.

    Table and Figures | Reference | Related Articles | Metrics
    Information Security Technology—Evaluation Requirement for Classified Protection of Cybersecurity(GB/T 28448-2019) Standard Interpretation
    Guangyong CHEN, Guobang ZHU, Chunling FAN
    Netinfo Security    2019, 19 (7): 1-8.   DOI: 10.3969/j.issn.1671-1122.2019.07.001
    Abstract20597)   HTML966)    PDF (7610KB)(8255)      

    Evaluation requirements for classified protection of cybersecurity(GB/T 28448-2019) will be formally implemented soon. This paper introduces the revision background and process of this standard, the main changes in comparison with GB/T 28448-2012, the main contents of security general requirements and security special requirements, etc., so that to the main contents can be understood better.

    Table and Figures | Reference | Related Articles | Metrics
    Security Survey of Internet of Things Driven by Block Chain Technology
    Kuo ZHAO, Yongheng XING
    Netinfo Security    2017, 17 (5): 1-6.   DOI: 10.3969/j.issn.1671-1122.2017.05.001
    Abstract1361)   HTML42)    PDF (1332KB)(3578)      

    Nowadays, after the Internet, Internet of Things brings great changes to people’s production and life as a new direction of the third industrial revolution and the future internet technology. The development and application of Internet of Things has achieved remarkable results in recent years. A large number of sensors are connected to the machines and are combined with the Internet, which achieves intelligent management and operation. At the same time, the security and privacy problem in the Internet of Things environment is still the one of the threats to the Internet of Things technology. Because of the topology of the Internet of Things as well as the constraint of resources, the traditional security technologies are not entirely applicable to the Internet of Things. As the basic technology of bitcoin, block chain technology has the characteristics of decentralization, detrust, data encryption and so on. It is suitable for building a distributed system. This paper analyzes the characteristics of block chain technology to solve the security problems in the application of Internet of Things, and discusses the security problems of the combination of block chain and Internet of Things.

    Table and Figures | Reference | Related Articles | Metrics
    Design and Application of General Framework for Side Channel Attack
    Qing WANG, Chenyang TU, shenjiahui@iie.ac.cn
    Netinfo Security    2017, 17 (5): 57-62.   DOI: 10.3969/j.issn.1671-1122.2017.05.009
    Abstract1068)   HTML23)    PDF (1030KB)(3194)      

    At present, many cryptographic algorithms and cryptographic devices add the process of evaluating the risk of side channel when being designed. Side channel attack object is divided into two categories: unprotected cipher algorithm / module and protected cipher algorithm / module. If the attacks are designed separately for each attack object, it is time-consuming and laborious. Therefore, this paper proposes a new generalized analysis framework which can be applied to the vast majority of side channel attacks. Actual side channel attacks would be divided into three steps, the progressive side channel logic vulnerability assessment, side channel information collection, and side channel analysis optimization, in this paper, we detail the realization method of each step. Then, this framework covers all attacking processes and can be applied on the software which is protected by improved low entropy mask and out-of-order instructions. The experiment results verify the rationality and validity of the framework which adapts to most side channel attacks.

    Table and Figures | Reference | Related Articles | Metrics
    Automatic Exploitation of Integer Overflow Vulnerabilities in Binary Programs
    Jianshan PENG, Qi XI, Qingxian WANG
    Netinfo Security    2017, 17 (5): 14-21.   DOI: 10.3969/j.issn.1671-1122.2017.05.003
    Abstract680)   HTML9)    PDF (1283KB)(2985)      

    Integer overflow vulnerabilities have become the second largest threat to software security. The existing tools for mining integer overflow vulnerability do not support automatic exploitation. Neither do the automatic exploitation tools support integer overflow vulnerability. To fill the gaps we proposes an automatic exploitation method of integer overflow vulnerabilities in binary programs. Aiming at the valuable IO2BO vulnerability of integer overflow, firstly trying to avoid crashing in the process of buffer overflow, which would make hijacking control-flow fail. Secondly building suspicious taint set to reduce the scope of taints. Thirdly collecting the loops condition of reading and writing memory by taint analysis and symbolic execution. Lastly overwriting the critical data in the stack and heap by controlling the number of loops and generating new samples for testing by solving constraint. The proposed method can transform the automatic exploitation of IO2BO vulnerability into that of traditional buffer overflow vulnerability. The test results show that this method work well for the typical IO2BO vulnerabilities and could generate new samples for hijacking the control-flow of testing programs.

    Table and Figures | Reference | Related Articles | Metrics
    Malware Familial Classification of Deep Auto-encoder Based on Mixed Features
    TAN Yang, LIU Jiayong, ZHANG Lei
    Netinfo Security    2020, 20 (12): 72-82.   DOI: 10.3969/j.issn.1671-1122.2020.12.010
    Abstract731)   HTML19)    PDF (1419KB)(2635)      

    Malware authors usually evolve software versions to form malware families. The existing malware family classification methods need to be improved in terms of the robustness of feature selection, the effectiveness and accuracy of classification algorithms. To this end, this paper proposes a deep auto-encoder malware classification method based on mixed features. Firstly, by extracting the dynamic API sequence features and static byte entropy features of the malicious samples as mixed features, the global structure of the malicious samples can be obtained; then, the deep auto-encoder is used to reduce the dimensionality of the high-dimensional features; finally, the resulting low-dimensional features are input into the XGBoost algorithm classifier to obtain the malware's family classification. The experimental results show that this method can correctly and effectively distinguish different families, the micro average AUC reaches 98.3%, and the macro average AUC of the classification reaches 97.9%.

    Table and Figures | Reference | Related Articles | Metrics
    A New Cloudware PaaS Platform Based on Microservices Architecture
    GUO Dong, WANG Wei, ZENG Guo-sun
    Netinfo Security    2015, 15 (11): 15-20.   DOI: 10.3969/j.issn.1671-1122.2015.11.003
    Abstract1059)   HTML15)    PDF (1649KB)(2236)      

    With the development of microservice, container technology, the software paradigm is evolved towards Cloudware in cloud environment. Cloudware is based on service, supported by cloud platform, and it is the important method to cloudlization traditional software. It is the most important method for software development, deployment, maintains and usage in future cloud environment, and it is also a new thought for software in cloud platform. We proposed a new Cloudware PaaS platform based on microservice architecture and light weighted container technology. The traditional software can be directly deployed in this platform without modification, and provide service to the client by a browser. By utilizing the microservice architecture, this platform has the following characteristics, such as scalability, auto-deployment, disaster recovery and elastic configuration.

    Table and Figures | Reference | Related Articles | Metrics
    Research on the Consensus Mechanisms of Blockchain Technology
    Xuan HAN, Yamin LIU
    Netinfo Security    2017, 17 (9): 147-152.   DOI: 10.3969/j.issn.1671-1122.2017.09.034
    Abstract1144)   HTML39)    PDF (5330KB)(2180)      

    As the underlying technology in Bitcoin, the blockchain technology has gained wide attention. Blockchain is a kind of feasible method to solve the consistency problem of distributed system. Consensus mechanism is the core of the blockchain technology. Delicate consensus mechanism can improve system performance and promote the application of blockchain in many fields. Based on the consensus mechanisms in existing design of blockchain, this paper summarizes the basic consensus mechanisms including proof of work, proof of stake and Byzantine consistency agreement, and evaluates them from various aspects such as security, scalability, performance, etc. The future research on the blockchain consensus mechanism will be based on the different characteristics of the consensus mechanisms, and design should be carried out around the combination of different consensus mechanisms.

    Table and Figures | Reference | Related Articles | Metrics
    Research on the Security Technology in Virtualization
    Yue GONG, Chao LI, Wei WU
    Netinfo Security    2016, 16 (9): 73-78.   DOI: 10.3969/j.issn.1671-1122.2016.09.015
    Abstract1271)   HTML25)    PDF (2003KB)(1905)      

    For prominent benefits in efficiency, agility, and innovation, cloud computing is widely taken attention by governments. During recent years, the virtualization technology as the core technology of the cloud computing has been further developed with the wide application of the cloud computing. The virtualization technology brings the convenient conditions to the cloud computing, but new security challenges are introduced. The paper made the in-depth research on the related documents and reality. The existing status of the virtualization security including virtual machine sprawl, peculiar set-up hidden, virtual machine hopping, virtual machine escape and denial of service attack, is analyzed from the hidden dangers and the attacks. The practical method of the virtualization security is proposed from three aspects including the security mechanisms of host, Hypervisor and VM. The security technical support is provided for the infrastructure platform.

    Table and Figures | Reference | Related Articles | Metrics
    Authenticated Encryption Modes Based on Block Ciphers
    null
    null    0, (): 8-null.  
    Abstract459)   HTML12)    PDF (1668KB)(1765)      
    It is an inevitable trend to provide authentication encryption modes of operation, which satisfy all kinds of requirements, and have good performance such as high-efficiency, high security, low-cost and simple structure. Authenticated encryption modes based on block ciphers provide both privacy and authenticity of users’ information. As they have many good properties: high-speed, easy standardization, high-efficiency in hardware and software implementation, they have been widely used in the field of information security. In this paper, we give a survey on authenticated encryption modes based on block ciphers, and discuss further research trend in the future.
    Related Articles | Metrics
    An Improved Algorithm based on Abstract Syntax Tree for Source Code Plagiarism Detection
    null
    null    2014, 14 (1): 0-0.  
    Abstract281)      PDF (1011KB)(1705)      
    abstract syntax tree%AST%improved algorithm
    Related Articles | Metrics
    The Summary of Fuzzing Testing Technology
    null
    null    2014, 14 (3): 0-0.  
    Abstract294)      PDF (907KB)(1607)      
    software security%fuzzing testing%code coverage
    Related Articles | Metrics
    Review of Network High Flow Distributed Denial of Service Attack and Defense Mechanisms
    Heng LI, Huawei SHEN, Xueqi CHENG, Yong ZHAI
    Netinfo Security    2017, 17 (5): 37-43.   DOI: 10.3969/j.issn.1671-1122.2017.05.006
    Abstract886)   HTML21)    PDF (1122KB)(1603)      

    Distributed Denial of Service (DDoS) attack is one of the extremely familiar network attack methods. In the condition of high flow capacity, DDoS causes network congestion by means of manufacturing useless data, finally leading to resource exhausting and normal service interrupt. No effective defense for now is against the high flow capacity DDoS. Based on preliminary study and literature researches, this thesis summarizes and analyses the domestic and international research progress of network high flow DDoS defense mechanisms, emphasis on attacks detection and defense principle and attack test, makes a summary of features and disadvantages of different detection and defense mechanisms, in order to establish the comprehensive and effective network high flow DDoS defense mechanisms.

    Table and Figures | Reference | Related Articles | Metrics
    Multi-level File Operations Recording System Based on Minifilter Driver
    null
    null    0, (): 41-null.  
    Abstract351)   HTML5)    PDF (1089KB)(1507)      
    This paper studied for different levels of extraction and monitoring the behavior of file operations, aimed at the existing bypass filter drivers detection method was improved, more effective against malicious software behavior, multi-level technology to extract the file operations. Firstly the paper introduces the file filter driver technology , principle and current application situation,then introduces the widely application of micro file filter driver (Minifilter) technology development principle, steps and application field. Subsequent to the underlying behavior of file operations process are analyzed, and the Minifilter detection principle of the related introduction. To analyze its security and puts forward several methods of current can bypass the filter drivers detection principle. Including by adding filter drivers and send Hook function principle to bypass filter drivers, which the filter driver behavior cannot be detected.Lists the existing several attack methods from different levels to bypass the filter driver, including attached new filter drivers, direct access to the kernel, the sending of the underlying file structure function of different hook skills and so on. According to its attack principle is analyzed, puts forward corresponding detection methods.By adding the above on the basis of the original Minifilter several detection methods, which can realize to test the present a variety of means of attack, so as to add multi-layered protective measures. And then the improved filter drivers for targeted on the function and performance test, shows that the improved test drive to be able to use a smaller time cost to complete more deeper detection. Therefore the behavior of the improved extraction technology can bypass the normal file filter driver to expand to detect malicious behavior, the extraction of deeper malicious software file operations, so as to realize the target of suspicious file operations for a more comprehensive monitoring.
    Related Articles | Metrics
    The Application of a Kind of Reversible Matrix in Secure Communication
    Xiaoming CHEN, Weiqing YOU, Wenxi LI, Hao JIANG
    Netinfo Security    2017, 17 (5): 7-7.   DOI: 10.3969/j.issn.1671-1122.2017.05.002
    Abstract858)   HTML11)    PDF (1323KB)(1486)      

    The cyclic matrix is generated by its first row of elements, and then each row is shifted by the first row. Therefore, the cyclic matrix can not only maximize the utilization of the hardware circuit, but also save the storage space and have high computational efficiency. Constructing a reversible cyclic matrix conforming to the requirements of secure communication systems is a problem worthy of study. This paper corrects the erroneous application of the reversible matrix in secure communication in some documents, and gives the correct application examples and standards. Firstly, a necessary and sufficient condition for constructing the reversible cyclic matrix is obtained by studying the relation between the van Vandermonde Matrix and the cyclic matrix. Secondly, according to the finite field G(28) characteristics, the necessary and sufficient conditions for constructing the reversible cyclic matrix on the real field are extended to the finite field, and a fast generation algorithm of the reversible cyclic matrix is proposed. Finally, a sufficient condition for constructing the cyclic matrix with optimal diffusion performance is proposed.

    Table and Figures | Reference | Related Articles | Metrics
    Research on the Method of Network Attack Detection Based on Convolution Neural Network
    Yuming XIA, Shaoyong HU, Shaomin ZHU, Lili LIU
    Netinfo Security    2017, 17 (11): 32-36.   DOI: 10.3969/j.issn.1671-1122.2017.11.005
    Abstract1096)   HTML23)    PDF (1740KB)(1428)      

    The existing network attack detection methods including static and dynamic types, and there are some shortcomings, such as too dependent on the rules, much false positives. In view of the traditional network attack detection, this paper introduces the convolution neural network technology into the field of network attack detection. In this paper, the basic principle of convolution neural network is explained in the related content of convolution neural network. In the subsequent chapters, this paper creatively maps the extracted log features to a set of gray scale images for anomaly detection, and creatively maps the network attack characteristics into a sheet of gray scale. This paper reads the application log in the large data platform every 10 minutes by Kafka, generates the latest signature library and maps it to the gray scale according to the corresponding characteristics of the local server, and can reduce the noise data by convolution operation. The original signal features are enhanced so that the features can better describe the details of the data and improve the ability to classify.

    Table and Figures | Reference | Related Articles | Metrics
    Research on Unknown Threat Blocking Technology of Web Application Based on URL Intelligent Whitelist
    HUANG Changhui, HU Guangjun, LI Haiwei
    Netinfo Security    2021, 21 (3): 1-6.   DOI: 10.3969/j.issn.1671-1122.2021.03.001
    Abstract891)   HTML74)    PDF (1159KB)(1428)      

    With the increasing confrontation in cyberspace, the security of a large number of Web application systems constructed in the process of information development of important industry units in China is facing severe challenges. Protection technology and measures of various industries are insufficient, and it is urgent to establish effective technical protection system. This paper proposes an unknown threat blocking protection scheme for Web applications based on URL intelligent whitelist. This scheme proceeds from the perspective of compliance behavior, taking access control whitelist and non-compliance behavior blocking as the core. Through building dynamic model of business whitelist and URL access control whitelist, this scheme establishes an active defense system against unknown threats of Web applications which can improve the security protection level of Web application system of important industry units in China.

    Table and Figures | Reference | Related Articles | Metrics