
The emergence of the serverless paradigm, embodied by AWS Lambda functions, has revolutionized the landscape of cloud computing. This model empowers users to offload server management tasks, allowing them to focus their efforts on core business logic while achieving substantial cost savings. However, this transition to serverless exposes significant vulnerabilities, especially in terms of security. This article delves into the specific security challenges associated with AWS Lambda functions, with a focus on major threats such as malicious code injection, sensitive data leaks, DDoS attacks, excessive privileges, vulnerable dependencies, and certificate issues. Our investigation, centered around the AWS Lambda platform, thoroughly analyzes these challenges by identifying underlying mechanisms and inherent risks. We review the state of the art solutions from the literature while examining the strategies adopted by AWS and the industry to enhance security. By implementing these solutions on an AWS server, we concretely illustrate possible protective measures. In this paper, we aims to provide a comprehensive understanding of security issues in the context of Lambda functions, paving the way for recommendations and research directions to bolster the resilience of this essential serverless cloud technology.
Smart contracts are one of the most successful applications of blockchain technology, providing the foundation for a wide range of real-world blockchain applications and occupying a crucial position within the blockchain ecosystem. Hyperledger Fabric, as a influential permissoned blockchain system, warrants in-depth research into the security of its smart contracts. This paper begins by elucidating the sources of security threats to Hyperledger Fabric smart contracts, detailing specific security threats in terms of language inconsistency, external inconsistency, read-write logic, and system security. Subsequently, it provides an overview of research progress in smart contract vulnerability detection techniques, covering feature code matching, symbolic execution, fuzz testing, and intermediate code representation. Based on existing work, it summarizes current methods for detection and evaluation. Finally, drawing upon the summary of existing research efforts, it discusses the challenges faced and potential avenues for future research in the domain of Hyperledger Fabric smart contract vulnerability detection.Related research also facilitates the extension to other heterogeneous permissioned blockchains.
In the context of rapidly evolving cloud service systems and blockchain ecosystems, certain lightweight edge client nodes responsible for continuous generation or transmission of streaming data often exhibit limited computational prowess. Traditional dynamic integrity audit schemes, which rely on one-time initialization frameworks and incur high client-side over-heads, are ill-suited to this scenario. To address these challenges, this paper introduces Iterative Proof of Retrievability (IPoR), an integrity verification scheme for periodic incremental data via optimistic tags generation. We propose a publicly verifiable tripartite IPoR system framework comprised of SDC, EAP and SSP, where the majority of the stream data tagging process is attributed to the SSP responsible for data storage. To ensure the verifiability of the EAP's stream data tag generation process, we introduce a fraud proof based on SMT, the latter substantially decreasing the computational load on public validators. We formally prove under the random oracle model that IPoR satisfies storage integrity and tag generation completeness. Theoretical performance analysis and experimental results demonstrate that our IPoR construction can help clients save over 90% on initial computational overhead.
In the cloud industry, eBPF (extended Berkeley Packet Filter) security technology is one of the most popular and influential technologies in the Linux kernel in recent years. With the rapid development of networking and cloud-native technologies, eBPF is extensively applied in network and security, performance analysis, container and cloud-native environments, operations and troubleshooting, as well as observability of application systems. This paper focuses on the practical application of eBPF technology in cloud environments for ensuring the secure operation, event-driven security handling capability, and performance hotspots observation of transaction systems. The integration of eBPF technology significantly enhances efficiency and reduces costs across the development, testing, and operational phases of systems, providing effective means for security optimization, assisting in testing, and facilitating fault localization and troubleshooting during secure production operations. Moreover, eBPF plays a crucial role in handling security events in cloud environments.
With the increase in the scale of power systems, the development of measurement technology, and the decrease in costs, the amount of data in power systems is showing a rapid growth trend, gradually acquiring the characteristics of big data. Making full use of big data to improve the planning, operation, and control of power systems has received increasing attention. How to evaluate the quality of big data is an important issue worthy of study. There have been considerable research reports on data quality improvement techniques such as data cleaning, data integration, and similar record detection. However, research on data quality evaluation is still in its infancy. Against this background, a comprehensive evaluation method for the quality of power big data is proposed based on the characteristics of power systems and the quality characteristics of power big data. Firstly, an index system for evaluating the quality of power big data is constructed. Then, for the time-sensitive problem of big data processing, a MapReduce parallel K-means clustering algorithm is used to achieve fast preprocessing of big data sample sets. Afterwards, the objective weights of various data sets are calculated using entropy weight method, and the gray evaluation method is used to determine the level of data quality. On this basis, a comprehensive evaluation of sample data sets is realized.
Data migration from legacy systems to modern environments, such as migrating DB2 from z/OS to the cloud, often requires significant effort and time. Customers often encounter confusion when determining the appropriate migration route, use case, and efficient movement of source data to the target data repository. This paper explores various migration patterns and provides recommendations on target technology and platform selection. We propose a core Data Elements Migration (cDEM) strategy, focusing on schema, objects, and data volume, rather than a complete data warehouse. By enabling users to quickly assess workload, extract core data elements, map components from the source data pool to the target repository, and evaluate data volume and migration complexity, this approach reduces workload and accelerates the overall process. The model presented in this paper illustrates the migration of end-to-end data objects from legacy DB2 on z/OS to the public cloud, specifically Azure SQL Server as a demonstration case, while remaining applicable to other cloud providers and popular data repositories like MySQL.
Traditional threshold secret sharing scheme provides a mechanism to prevent the over-concentration of secrets while allowing for flexibility through the distribution and reconstruction of sub-secrets. However, this approach often simplifies participant behavior into categories of complete honesty or continuous deceit, neglecting the nuances of rational decision-making. To address this limitation, the rational secret sharing scheme merges threshold secret sharing with game theory, where each participant is considered rational and acts solely in self-interest. Nonetheless, existing schemes encounter challenges such as the prisoner's dilemma and the inability to reconstruct secrets due to the prioritization of individual interests. To mitigate these issues, our proposed scheme integrates a reward and punishment mechanism that balances short-term gains with long-term incentives, effectively deterring malicious behavior among participants. Moreover, traditional solutions based on elliptic curves and bilinear pairs lack resilience against quantum attacks. In response, our solution incorporates lattice-based cryptography to enhance security in the face of quantum threats. Additionally, we introduce an attribute access control tree to empower secret dealers in selecting suitable participants based on attribute restrictions, ensuring a more flexible, convenient, and secure rational secret sharing plan. This comprehensive approach improves participant selection and strengthens security measures in secret sharing scenarios.
With the development of code generation techniques, selecting the correct code solution from multiple candidate solutions has become a crucial task. This study proposes AutoTest, a novel technique that combines automated test case generation with code solution execution to optimize the selection process using an evolutionary genetic algorithm. Firstly, AutoTest utilizes large pre-trained language models such as codegen-16B, code-davinci-002, and incoder-6B to provide code solutions and their corresponding test cases. Then, by executing the code solutions and evaluating their performance on the test cases, a consensus set is formed. Fine-grained ranking is achieved through the selection, mutation, and crossover mechanisms based on the evolutionary genetic algorithm, with the adjustment of alpha and beta parameters. Finally, the best code solution is chosen. AutoTest demonstrates significant performance improvements on the HumanEval benchmark test. The HumanEval dataset consists of 164 programming problems, and AutoTest achieves approximately a 10% improvement over the baseline method in terms of pass@1 score.
This paper responds to official policies by exploring the positive role of electric power data in areas such as financial risk control. It aims to provide decision support for State Grid Corporation in data monetization and innovative business models, while addressing pain points for governments, financial institutions, and other businesses. By integrating electric power data, the project establishes an enterprise credit evaluation model to overcome the limitations of traditional credit profiling. Leveraging data mining methods and statistical modeling techniques, a credit scorecard model is developed based on electric power data, enabling the calculation of credit scores and corresponding risk levels. This model enhances risk prevention and decision-making effectiveness for relevant institutions. The project contributes to the systematic, normalized, and sustainable development of electric power big data credit reporting, serving other credit markets and promoting the improvement of various credit platforms. The findings provide a foundation for market participants to assess overall risk situations and improve credit risk management. This paper demonstrates the value of integrating electric power data in credit assessment and highlights its potential for enhancing risk control and decision-making processes.
During the 14th Five-Year Plan period, China's urban rail transit market has exhibited steady growth, paralleled by increases in passenger volume and emerging safety challenges. The advent of national standards such as GB 51151 has heightened safety requirements, pressing the need for technological advancements in rail transit security systems. Traditional security systems suffer from isolated operations and inefficient information exchanges, necessitating additional human resources for management. We propose integrating blockchain technology to enhance trust and security across disparate systems. Additionally, the introduction of heterogeneous query blockchain middle-ware facilitates cross-chain data interoperability and advanced querying capabilities, further enriching our multimodal, fine-grained blockchain security management system that leverages Fabric's channel isolation for secondary permission control. This system not only ensures secure data transmission and storage but also addresses privacy and trust issues, enabling unified data handling and traceability across rail transit security platforms. The experiment demonstrated the efficacy of our work
With the swift advancement of technology and the widespread adoption of agile methodologies, integrating security known as DevSecOps-has become essential to maintain software integrity and safety. This paradigm shift focuses on embedding security testing throughout the development lifecycle, advocating for Continuous Security Testing (CST) instead of postponing it to later stages. We propose three custom tools tailored for specific stages of the development cycle. By using these tools, organizations can strengthen their security practices and uphold software integrity throughout the development process. We offer a preliminary analysis of these tools aimed at improving information security within organizations. In the future, they will be made available to end users, and their usability will be assessed.
This paper explores the critical need for robust security measures in microservices and container technologies. This research aims to provide security approaches for microservices and container deployment, covering all life cycle stages. The study assesses the security of containers by using virtual configurations, Grype, and Anchore, together with automated procedures and methods for responding to security incidents. This paper also examines the performance of security tools while considering the trade-off between security and cost in containerized environments. This comprehensive research offers valuable insights and proven strategies for creating and sustaining robust security frameworks. It covers theoretical and practical aspects of container security, guiding best practices.
Financial fraud detection plays a crucial role in maintaining financial security and risk control. Many types of financial data, such as transaction networks and entity relationship networks, can be represented as graph-structured data. Graph neural networks, exemplified by the Beta Wavelet Graph Neural Network (BWGNN), are instrumental in financial fraud detection. However, current research on adversarial attacks against graph neural networks primarily focuses on vanilla GNNs, with limited exploration into adversarial attacks targeting models like BWGNN used in financial fraud detection. This paper presents effective adversarial attack methods tailored to BWGNN. Leveraging node injection as an adversarial attack method, we construct surrogate models that closely resemble the structure of BWGNN, significantly enhancing the attack performance. Additionally, by incorporating dropout layers after the input layer of the surrogate model, we further enhance the attack effectiveness. This paper reveals the adversarial vulnerabilities of financial fraud detection models represented by BWGNN, which holds significant implications for enhancing the security of fraud detection models applied in critical financial security domains.
We designed a large language model evaluation system based on open-ended questions. The system accomplished multidimensional evaluation of LLMs using open-ended questions, and it presented evaluation results with evaluation reports. Currently, the evaluation of large-scale language models often exists with two prominent limitations: (1) The evaluation methods are often single-minded, resulting in less credible results. (2) Most evaluations are based on datasets with closed-ended questions, treating generative large language models as discriminative models, which fails to adequately reflect the high output flexibility characteristic of these models. For these two limitations, we proposed an evaluation system for LLMs based on open-ended questions. Our experiments on the adapted open-source datasets demonstrated the effectiveness of this system. The code of the system was released on https://github.com/JerryMazeyu/GreatLibrarian.
Adversarial training is generally regarded as one of the most effective methods to heighten the adversarial robustness of Deep Neural Networks. Until now, most existing methods have focused on enhancing the robustness of the overall model with fixed parameters. They treat each sample equally during the training and testing phases, all adversarial samples are generated with manually specified identical adversarial strategy, such as the well-known Projected Gradient Descent. To address the problem of the disparity in robustness among classes and the limited overall robustness improvement due to ignoring sample variability, we propose Adversarial Training with Sample-wise Individualized Adversarial Strategy (SIAS-AT). In our study, we confirm the differences of robustness between classes and the overall model and explore the reasons for this. First of all, we systematically explore the preferences of different samples for adversarial strategies, involving perturbation magnitude, correlation weights, and regularization. Then we conclude that the least iteration numbers of the data point can be used to individualize the strategy of the sample and propose formulas for calculating the strategies. Finally, empirical experiments on benchmark datasets show that the method proposed in this study significantly outperforms other popular methods in performance. Our approach can be further integrated with other research results as plug-and-play components to enhance model performance.
Data has become widely recognized as a new productive factor with a visible impact on the global economy. However, trust among entities involved in data transactions has been hindered by various risks related to interests, security, and privacy. The replicability and timeliness of data further complicate trust considerations, impeding the development of the data market. Although several technical solutions and management mechanisms have been proposed to address trust concerns, they often focus on specific issues rather than providing a comprehensive analysis or standardized explanation of trustworthiness. This paper investigates different definitions and approaches to trust in various fields. It explores general trust patterns among entities during the flow of data elements and proposes a general definition of trustworthy data circulation based on multidisciplinary theories. The study classifies data element flow into four categories of trustworthy circulation stages and analyzes each category to derive a comprehensive implementation paradigm for trustworthiness.
Supernumerary teeth (ST) not only commonly obstruct adjacent permanent teeth, causing ectopic eruption, rotation, and root absorption but also present the potential for cystic lesions extending into the nasal cavity. Early intervention is crucial to avoid severe complications like periodontal abscesses and severe dental caries. However, ST may occur in any oral region with variable shapes and growth directions, posing a significant challenge for image recognition. This prevalent dental condition in the Asian population (3-5%) lacks sufficient representation in AI-assisted systems. Given this, the study suggests a system reliant on Convolutional Neural Network (CNN) for identifying supernumerary teeth in occlusal radiographs. The algorithm incorporates feature enhancement and AI integration methods. Additionally, the study introduces a color mapping approach to address the variability in ST shape and growth direction, significantly improving recognition accuracy from 63.16% to 76.32%. The result of this research demonstrates an improvement of 18.43% in accuracy and 78.95% in recall rate for supernumerary tooth detection compared to existing technology. This study successfully addresses the challenge of identifying supernumerary teeth, which were previously difficult to recognize. To ensure compliance with ethical and regulatory standards, the proposal has obtained certification from the Institutional Review Board (IRB) with the reference number 202400084B0.
With the rapid development of the data trading market, the challenges to data security are increasingly prominent. This research begins with the entire process of data element circu1ation and transaction, analyzing the security needs of data production, storage, circulation, consumption, and other links, and proposes a comprehensive security cryptographic framework. This framework primarily covers five aspects: storage security, consumption security, transaction security, management security, and privacy security. The study not only thoroughly analyzes the security risks in the entire process of data element circulation and transaction but also proposes solutions based on cryptography, which is of significant importance for guiding practical data transaction security practices. Furthermore, the research delves into how to ensure the flexible use and value mining of data while protecting data security, providing theoretical support and technical guidance for the healthy development of data element circulation and transaction.