当前,网络安全已成为国家安全重要基石.自"十三五"以来,我国在完善网络安全政策体系、提升网络安全技术水平、推动产业数字化安全和数字产业化安全发展等方面取得卓越成效.在百年变局与全球新冠肺炎疫情交织叠加的变革关键期,做大做强数字经济、全面强化网络安全意义深远.展望"十四五冶,我国将主动把握网络空间发展未来趋势,从前瞻谋划布局、防护演进升级、产业链可控强化、安全产业发展壮大等各方面提升网络安全综合保障能力,大力推动数字经济安全、高质量发展.通过对当前数字经济发展和国内外安全形势进行研判,梳理和展望我国网络安全发展成效及未来趋势.
The high-efficiency and security-guarantee of Industrial Internet of Things systems are critical in industry area. In this paper, the novel data collection procedure is established to monitor and classify the data flow in IIoT systems firstly. Then, a Q-learning algorithm based on reinforcement learning is introduced to detect the system fault and equipment error in IIoT systems. Simulation results show that the proposed data collection procedure and data analysis method can detect the equipment fault more efficiently than before.
Aiming at the problem that there is little research on firmware vulnerability mining and the traditional method of vulnerability mining based on fuzzing test is inefficient, this paper proposed a new method of mining vulnerabilities in industrial control system firmware. Based on taint analysis technology, this method can construct test cases specifically for the variables that may trigger vulnerabilities, thus reducing the number of invalid test cases and improving the test efficiency. Experiment result shows that this method can reduce about 23 % of test cases and can effectively improve test efficiency.
金融、能源、电力、通信、交通等领域的关键信息基础设施是经济社会运行的神经中枢,是网络安全的重中之重.为落实《网络安全法》要求,适应国家网络安全工作新形势新任务,《关键信息基础设施安全保护条例(征求意见稿)》(以下简称《条例》)于 2017年 7月 11日发布.
随着数据价值的不断提升,针对数据的安全威胁也与日俱增,给数据安全保障带来了严峻的挑战.国家基础数据的高价值导致数据泄露产生的影响加剧,甚至会影响社会稳定与国家安全.为了对国家基础数据进行更系统的保护,深入调研梳理了国内外数据保护政策及管理现状,明确了国家基础数据的定义、范畴及分类,提出了新形势下保护国家基础数据的政策建议.
以互联网与工业融合发展为重要切入点,新一代信息技术正在全球范围内驱动新一轮产业变革.与此同时,两化深度融合带来的网络安全问题日趋凸显,如何提升工业互联网安全保障能力,已成为推动互联网与工业融合创新发展的关键契机.本文基于传统工业向工业互联网的演进过程分析相应的安全风险与威胁,充分借鉴国外工业安全管理的先进经验,提出我国工业互联网安全发展的策略建议.
In recent years, network and information security standardization work in Chinese telecommunications industry has had achievements, done a lot of standardization work which covering the all research fields of network and information security. But, it has been lacked a scientific and reasonable standard architecture as guidance. To solve this problem, this paper put forward a set of system architecture of network and information security standards, that adapting Chinese telecommunications industry. Then, we used the architecture to comb network and information security standards status in Chinese communications industry, and gave some advice for the future standardization work.
This paper analyzes security issues with the tri-networks integration from the content, application, network and terminal aspects, and introduces current security schemes for the IPTV transmission. Then a security supervision solution for IPTV application is suggested based on the related analysis.
In response to the more and more serious situation of network security,and in order to improve the capability of the protection of national communication network security and to prevent networks from incidents,the Ministry of Industry and Information Technology has been carring out comprehensive initiatives in establishing standard and protection system around communication network security.
通过简要分析P2P网络的几种拓扑,确定了iCOSA基于DHT的层叠式拓扑,设计了方便实现iCOSA网络可管可控目标的分层编址和分层路由方案。
<正>随着我国信息化建设的日益深入和全面发展,网络与信息的安全已经成为关系国家安全、社会稳定以及公共利益的大事,成为信息化进程中的重大战略问题。《国家信息化领导小组关于加强信息安全保障工作的意见》(中办发[2003]27号)的发布,确立了进行信息安全等级保护的信息安全保障工作思路。为了将27号文的精神贯彻落实到
This article expounds the roots and characteristics of Internet security issues.Based on the analyses of the limitations of existing security solutions,the author puts forward new consideration for Internet security,namely the iPSPA.
针对电信网安全等级保护、安全风险评估和灾难备份及恢复三部分工作的基本概念以及实施步骤进行了说明,分析了在电信网安全防护体系中,这三者之间的关系,并介绍了相关标准的进展情况。
In large scale P2P networks, it is difficult to deal with different type of attacks issued by malicious peers. A novel trust model based on reputation and risk evaluation is proposed in this paper to solve this problem, in which the uncertainty between trust relationships is considered. The risk is quantified using information entropy and further trust degree and uncertainty degree are presented in a uniform form. The simulation results show that the proposed trust model can evidently enhance successful transaction ratio of system and efficiently help peers establish trust relationships in open P2P networks.
对P2P网络存在的问题进行了分析,阐述了建立P2P网络信任模型的需求。在对现有P2P网络中的任模型进行总结归纳后,指出了以后研究的方向。
In large scale P2P networks, it is difficult to establish the trust relationship between peers as it is less likely that repeat interactions will occur with the same peer. So the network is vulnerable to malicious peers. A group based hierarchical reputation model for P2P networks is proposed in this paper to solve this problem. In this model, the trust relationship is classified into three tiers: the trust relationship between groups, the trust relationship between groups and peers, and the trust relationship between peers. A peer evaluates the trust of the given peer by its local trust information or the reference from the group it belonging to. The simulation and analyses show that the proposed reputation model can distinguish good peers and make them happy with the high ratio of the success query.
对P2P网络的工作原理和典型应用进行了介绍,分析了P2P在商业应用和业务监管带来的挑战,提出了可管控P2P的思路,指出了需要研究的内容.
In file sharing P2P (peer-to-peer) networks, the service availability is seriously affected by peers’ voluntary actions. For example, there are many freeriders and malicious peers in P2P networks. However, the pure P2P networks don’t take the issue of freeriders and malicious peers as the inherent part of the topology design, and all the peers are symmetry in the topology. This paper proposes a reciprocal capacity based adaptive topology protocol for P2P networks, which takes account of the peer’s rational belief of maintaining connections. The simulation and analyses show that the resulting topology is incentive compatible to different types of peers. In addition, compared with the proposed similar scheme, it is also more efficient with less network cost.
A Reciprocal Capacity based Adaptive Topology Protocol (RC-ATP) for P2P networks is proposed in this paper. It is based on the rational belief that a peer is only willing to maintain connections with those which will benefit it in future. Reciprocal capacity is defined based on peers' capacity of providing services and of recommending service providers. As a result, reciprocal peers connect each other adequately. Therefore the resulting topologies are more efficient and resilient compared with Adaptive Peer-to-Peer Topologies (APT).
A Reciprocal Capacity based Adaptive Topology Protocol (RC-ATP) is proposed in this paper to construct efficient peer-to-peer networks. It is based on the rational belief that a peer is only willing to maintain connections with those which will benefit it in future. Reciprocal capacity is defined based on peers’ capacity of providing services and of recommending service providers. As a result, reciprocal peers connect each other adequately. Therefore, the resulting topologies are more efficient and resilient than Adaptive Peer-to-Peer Topologies (APT). Furthermore, RC-ATP has the intrinsic incentive to active peers as they are more advantaged and important in the network than freeriders and malicious peers. Although the overhead of the topology adaptation is a bit higher, RC-ATP works more efficiently with less cost compared with the Adaptive Peer-to-Peer Topologies Protocol (APTP).