
随着数字经济的蓬勃发展,数据已经成为新时代的重要生产要素,并成为国家基础性战略资源.一方面,构建不同行业、领域规范化数据开发利用场景,提升各行业数据资源的价值,促进数字经济产业集群发展成为大势所趋;另一方面,数据安全和隐私保护问题愈发突出,数据流转过程中暴露面风险急剧加大,面临严峻的数据安全风险防护和合规监管要求形势.
Based on the status quo of email technology development,this paper summarizes and reviews the overall situation and hidden risks of email security in China.From the perspective of social engineering,it studies the methods,types and application techniques of mainstream phishing email attacks in recent years,and introduces the working principles of malicious Trojan horse,self-extracting file and dynamic link library side loading and other attack techniques commonly used in malicious attachments to emails.This paper analyzes the risks and hidden dangers of phishing email attacks aggravated by new information technologies such as generative AI robot and multi-fragment program coding confusion,and puts forward countermeasures and suggestions on how to prevent and deal with the new phishing email attacks based on theory and reality.
In recent years,with the development of big data and artificial intelligence technology,log data oriented intelligent fault prediction gradually attracts research attention.Conventional fault prediction methods based on log data only focus on a single requirement attribute,making it difficult to adapt to the multi-dimensional requirement prediction.To address this problem,this paper proposes Multi-Det,an intelligent fault prediction model with multi-channel fusion,which designs specific scheduling method that incorporates machine learning and deep learning.Through feature extraction and data fusion,the system model is well adapted to different user requirement attributes to optimize the accuracy and reliability of fault prediction in specific scenarios.To verify the effectiveness of Multi-Det,experimental comparisons of requirement parameters in multiple scenarios are carried out on public datasets.The results indicate that the proposed method can effectively adapt to different fault prediction requirements,intelligently adjust the prediction strategy in specific scenarios,and provide strong support for the maintenance and management of device in specialized fields.
Artificial intelligence(AI)technology is one of the most revolutionary emerging technologies in the world today.The development wave of AI big models triggered by ChatGPT leads a paradigm change in AI technology development,presenting a trend towards more intelligence,automation,efficiency and reliability.AI technology is widely and deeply applied in the power industry,which strongly promotes the digital development of power grid enterprises.However,the application of AI technology is a"Double-edged sword",which has the risks of data security,cyber attacks,technical defects and social engineering,and requires comprehensive,safe and reliable protection measures to better leverage the advantages and value of AI technology and promote the development of the power industry.
Conventional network security situation assessment provides a decision-making basis for enterprise security risk management.According to the basic principles of zero-trust security,this paper first analyzes the connotation,goal and significance of zero-trust security situation assessment,and then puts forward a zero-trust security access architecture based on continuous risk assessment.Around this architecture,it studies key technologies of zero-trust security situation assessment,focuses on context security assessment for user access,constructs and designs an extensible situation assessment index system as well as a quantitative assessment algorithm,provides continuous assessment capabilities for achieving dynamic fine-grained access control under the zero-trust paradigm,and finally summarizes the future development trend of zero-trust situation assessment.
The continued promotion of smart civil aviation construction further increases the importance of civil aviation data security.The civil aviation industry pays great attention to data security and releases a series of policy requirements,but the civil aviation industry has a large number of data,complex types and wide distribution,which brings many challenges to data security protection.Based on the GB/T 20984-2022 Information Security Technology-Risk Assessment Method for Information Security,in terms of data asset recognition,data security threats,security measure effectiveness recognition,vulnerability recognition,as well as civil aviation data security risk analysis and evaluation,and further combining with the characteristics of civil aviation data,this paper discusses the relevant models,methods and tools.Through the research on the risk assessment system of civil aviation data security,it lays the foundation for promoting the civil aviation data security protection work.
As a new type of infrastructure in the digital age,blockchain technology has broad application prospects.Currently,there are numerous open-source blockchain systems,but they lack standardization and interoperability,which pose certain obstacles to the construction of a unified national digital trust infrastructure.This paper conducts an analysis of open-source blockchain service platforms such as Ethereum 2.0,Hyperledger Fabric,and Fisco Bcos from the perspectives of network architecture,core process,and characteristic.It proposes a new general alliance chain architecture(SChain),which clarifies the system architecture,consensus selection,transaction consensus,and extension design,and conducts security analysis and performance testing.
The optical transmission network carries the data transmission of physical layer and link layer,which is the core foundation of all communication networks.Therefore,as an important component of digital information infrastructure security,the importance of optical transmission network security is self-evident.This paper introduces the hierarchical structure of optical transmission network,analyzes the security risks at different levels,studies the relevant security countermeasures for the possible security threats to each layer,and finally summarizes the key points of the construction of the optical transmission network security protection system.
The purpose of analyzing biometric information security technology for access control system is to explore how to ensure the security and effective use of personal privacy information in access control system.Through analyzing the structure,characteristics,and functions of access control system,as well as biometric information access control system technologies,this paper explores potential personal information security risks and privacy leakage threats in access control system,while involving the storage and management of biometric information.Based on this analysis,this paper proposes a method to implement biometric information security technology for access control system,which offers theoretical support and practical guidance for information security management in real-world applications.
Canada's space-based infrastructure is vulnerable to cyberattacks of the kind already executed by states and non-state actors.In order to address the exposure to space-cyber threats now,Canada should strengthen cooperation with industry to initiate national space cyber efforts in terms of capabilities and governance;introduce national policies and regulations;adopt the standards and best practices of the United States and Germany;develop and acquire its own defensive capabilities and train a skilled and diverse space-cyber security workforce;encourage the establishment of a space-cyber security sector;and support commercial space companies in defending against space-cyber threats.These measures may turn risks into opportunities and safeguard Canada's place among the leading space and cyber nations.
Connected vehicle chargers and charger management platforms are facing the issues of information security such as weak cipher mechanism and poor data communication security.This paper designs and implements an autonomous and trustworthy system of connected vehicle chargers.The system takes commercial cryptographic algorithms as the main body to achieve secure distribution of public keys and reliable authentication of server identities;it uses consortium blockchain Hyperledger Fabric as the underlying blockchain platform of the system to store and manage the keys used for data communication to achieve traceability of access information and non-repudiation of access entities.Compared with the conventional centralized charger system,the proposed system constructs a new security boundary centered on identity to assist China's smart transportation and Internet of Vehicles development.
网络安全的本质是对抗,针对当前高水平和快速变化的安全威胁,为适应央企在网络安全新形势下的应用以及业务体系快速叠加演进所带来的安全风险和威胁,须改变传统被动防护的安全管理和技术体系,使之更加智能、快速、弹性地应对突发的安全威胁,并在威胁处置过程中不断进行防御策略的优化、网络空间环境的塑造,将网络和信息安全防护工作从被动响应变为主动防御,能够对日趋复杂的网络攻击进行更为精准的发现与打击,形成统一闭环的动态安全防御体系.
沙特是"一带一路"倡议在中东北非地区的枢纽国家.由于沙特大力推进其"2030议程"以推动国内经济转型,降低对传统油气经济的依赖,其国内数字基础设施建设需求不断上升.而且由于中沙两国在产业结构上具有高度的互补性,以及中东地缘政治格局变迁的影响,使得中沙在数字基础设施领域的合作稳步发展.中国对沙特数字基础设施建设项目的参与主要聚焦 5G设施、数据中心以及智慧城市项目.随着双方在数字基础设施建设合作的不断深化,中沙两国在数字经济、网络安全以及数据治理等领域的合作将不断深化.
在移动互联网时代,安卓移动应用软件已经渗透到人们生产生活的方方面面,安卓代码签名的安全问题一直是黑灰产关注的重点.通过分析不同版本的安卓代码签名机制以及代码签名在证书算法、证书使用、软件权责、软件保护、证书更新等方面存在的风险挑战,从行业标准、企业内部、政策监管、产业链责任和义务等方面向产业相关方提出对策建议,为行业相关技术研究、标准制定和政策发布提供参考.
随着工业化与信息化的融合发展,工业控制网络面临的安全威胁日益增多,安全形势日益严峻.针对工控信息安全事件频发的现状,为防范相关安全风险,在研究工业网络结构与特点以及安全防护需求的基础上,设计了适用于不同场景、不同层次、不同设备,基于纵深防护和多策略协同的综合安全体系,并在典型行业工业网络中实现应用推进,形成了覆盖密码保障、多层防护、综合管控等多个维度的安全保障能力和整体解决方案.
公钥密码学是保障现代通信安全与数据安全的重要基础技术.介绍了当前量子计算发展对公钥密码学造成的威胁,以及密码标准化组织和密码学研究的应对措施,依据所使用的基础数学困难问题分类阐述基于格、编码、多变量、哈希函数、曲线同源的后量子密码及其优劣势等特点.以当前后量子密码标准进展为主线,从算法安全性分析、后量子迁移的技术路线、与量子通信技术结合、新的数学困难问题探索等方面提出后量子密码学的发展方向建议.
信息技术与现代生活及生产互相交融、不可分割,各国都把信息化作为本国重要的发展方向,依托信息化建设提高资源协作效率,推动技术创新,提高综合国力.在此背景下,云计算作为信息化基石,其安全性异常重要.由于传统的安全防护体系不再适用于云计算安全建设,因此,依据滑动标尺模型,结合等级保护制度,以软件定义安全、分层防御、区域自治、全面纳管的思想,从云环境识别、边界安全设计、云内安全设计、特权管理、安全管控 5 个方面对今后云计算安全防护提出理论指导.
网络空间是与陆、海、空、天并列的第五维空间领域.在当前全球网络空间安全形势日趋复杂的背景下,网络空间的安全问题深刻影响着政治、经济、军事、文化、科技等社会的各个领域.随着数字中国战略的深入推进,新型智能网络、新型业务形态、新型服务模式对网络空间安全提出了新的挑战.信任是安全的基础,构建新型网络空间下的信任体系是确保我国信息安全长远发展的重要环节.剖析了网络空间信任体系的内涵、特征和安全目标,基于国内外信任技术和信任体系发展现状,对架构和建设数字信任体系展开了研究.
在分组密码的差分攻击中,为了利用计算机搜索最佳差分路径,人们将问题转换为其S-盒的差分分布表的最佳线性不等式逼近问题.确切地说,给定向量空间F2n的一个非空点集A,寻找数目尽可能少的一次多项式的集合,使得满足所有多项式的值均大于或等于0 的点集恰好为给定的点集A.在文献中能看到的做法通常是利用计算机软件(例如SAGE数学软件)算出很多的多项式,再用线性规划的方法从中挑选出最小个数的多项式.研究一次多项式的产生方法,称F2n中的点集S是相容的,是指存在某个整系数一次多项式f(X),使得S={P∈F2n|f(P)<0}.主要有以下 3 个方面的结果:一是给定向量空间的维数n,对任意的 1≤k≤2n,一定存在k元相容点集S;二是利用多项式加法的技巧,构造出一批k元相容点集;三是对于小参数k=1,2,3,4,给出k元点集S是相容的充分必要条件,同时也给出相应的k元相容点集的计数公式.
进入算网融合时代,广域网产业面临更加广泛的安全性、移动性和算力分布挑战,现有网络架构和技术已经无法满足数字化企业所需的安全和访问控制需求,网络安全逐渐走向身份认证、弹性服务、融合业务的安全访问服务边缘新型安全架构.作为网络安全领域的创新性安全技术,安全访问服务边缘在工业互联网、5G网络、云化电信网络等应用场景先后成熟,针对安全访问服务边缘的产业发展现状进行阐明,并分析安全访问服务边缘的未来发展趋势.