With the rapid expansion of the Internet, the surge in data traffic, propelled by the exponential growth of network services and users, has heightened the risk of network congestion, security breaches, and system instability. Addressing these challenges presents stringent demands and novel complexities in queue management. However, prevailing solutions often rely heavily on average queue size thresholds while ignoring traffic variations. In this paper, CCD-AQM, an Adaptive Queue Management approach based on the Consecutive Change trend Detection in the queue size is proposed. Considering that today's programmable data plane offers promising ways for finer analysis of the queue in the hardware switches, we implement CCD-AQM on an RMT switch and analyze its resource usage. Large-scale simulations are conducted to evaluate CCD-AQM, showcasing its superior performance in queue management. The results demonstrate its ability to maintain low queue occupancy and high throughput while ensuring fairness among competing flows.
Quality-of-Service (QoS) guarantees are crucial for meeting the diverse performance requirements of applications in packet networks. The Proportional Delay Differentiation (PDD) model offers relative service differentiation based on the delay requirements of different traffic classes. However, implementing PDD on current hardware switches faces challenges due to the lack of inherent queuing behavior description in switch ASICs. This paper introduces FlexPDD, a dynamic and adaptive packet prioritization mechanism designed to implement the PDD model on programmable switches. FlexPDD leverages the flexibility of programmable switch to adjust the mapping between packet classes and output queues dynamically, ensuring precise control over delay differentiation. Our implementation of FlexPDD on a Barefoot Tofino switch and an NS3 simulator demonstrates its feasibility and effectiveness. The results indicate that FlexPDD successfully maintains approximate delay differentiation among service classes proportional to their delay weights, highlighting its potential as a practical solution for achieving advanced service differentiation in modern network infrastructures.
With the popularity of computers and mobile devices and the development of the Internet, browsers (applications used to retrieve and display information resources on the World Wide Web) are often included by default and have become an indispensable software. Therefore, research on browser security issues is essential for protecting information assets. Among many browsers in the industry, Chrome, as a cross-platform web browser developed by Google, occupies a large market share in desktop browsers, and its security risks are further amplified as its kernel is used by many other browsers. Therefore, the research on the security issues of Chrome browser is critical for browser security.This paper focuses on the vulnerability detection of the process communication interface in Chrome browser, and designs and implements a fuzzing framework, auto-mojo-fuzz (AMF). The fuzzing process mainly designs a sample optimization technique to ensure the effectiveness of input samples and improve the efficiency of fuzzing. After implementing the AMF solution, we evaluate the generated test samples to demonstrate the effectiveness of the sample optimization technique. We also prove the possibility of discovering more vulnerabilities with AMF, and tests it with the latest version of Chrome browser, finding five unique crashes, four of which are verified as security vulnerabilities, effectively proving the automatic and efficient ability of this framework to discover vulnerabilities in the process communication interfaces in browsers.
The topology discovery service in Software-Defined Networking (SDN) provides the controller with a global view of the substrate network topology, allowing for central management of the entire network. Unfortunately, emerging topology attacks can poison the network topology and result in unforeseeable disasters. Although researchers have made great efforts to mitigate this problem, security hazards still exist. In this paper, we propose Invisible Assailant Attack (IAA), the first combination topology attack capable of injecting and maintaining fake links even when 12 existing defense strategies are deployed simultaneously. IAA consists of 14 attack phases that apply multiple attack strategies. Attackers skillfully disguise the attack traffic in each phase so that it looks like normal network traffic, and perform these phases in a well-planned sequence, thereby bypassing existing defenses step by step. To mitigate this attack, we propose a Route Path Verification (RPV) mechanism that orchestrates multiple defense strategies to identify fake links. According to the experiments, RPV can successfully detect IAA with low overhead: its detection completes within 1 ms while its per-flow storage consumption is only a few KB.
采用高分辨飞行时间质谱和液质联用技术,研究酿酒酵母和植物乳杆菌混合发酵对金银花浸提液多酚的影响.结果 表明,经混合发酵后的金银花浸提液中黄酮和多酚含量明显增加.黄酮含量(以芦丁计)由72.04 mg/g提升到79.07 mg/g,提升率10%;多酚含量(以焦性没食子酸计)由47.74 mg/g提升到59.37 mg/g,提升率24.35%.发酵后的浸提液中绿原酸、槲皮素苷、阿魏酰奎尼酸、木犀草素等含量提升显著,特别是绿原酸含量由26.57 mg/g提升到31.34 mg/g,提升率17.95% (P <0.05).发酵后金银花浸提液的抗氧化性能提高,DPPH自由基清除率由55%提升到71%,ABTS阳离子自由基清除率由59%提高到64%,采用混菌发酵的方法能够提升金银花浸提液的品质.
The distributed network control in software-defined networking is greatly challenged by the design demands of evolving a running distributed control plane (DCP), and by the complexity of handling the control state dynamics. In this paper, we propose RIFFLE to address the problem using a distributed network operating system approach. RIFFLE enables the evolvability of control states of DCP deployed on a global scale. RIFFLE handles spatial and temporal dynamics that occur when updating and migrating the distributed control states, which overcomes the critical barrier to the evolvability. It fills the gap by enabling temporal reconfigurability in DCP. Moreover, RIFFLE reduces the complexities of building and maintaining network control services in DCP by enabling componentization and abstracting the underlying network dynamics. We evaluated the prototype RIFFLE through experiments running in PlanetLab. The results show that the prototype scales well for 135 nodes. We also validate that RIFFLE ensures the continuity and low content request delay for the supported the information-centric network supported during cache update periods owing to the enabled evolvability.
The unbalanced development status of network security was introduced.The main hazards and the mechanism model of penetration testing were described,and the inherent shortcomings of many existing traditional defense methods were analyzed.However,new method of the mimic defense model makes the attack information obtained invalid by dynamically selecting the executive set and adaptively changing the system composition.The same attack mode is difficult to be maintained or reproduced.Based on the attack chain model,the traditional defensetechnology and mimic defense technology were analyzed and compared,and it was demonstrated that it had a protective role in multiple stages of the attack chain.Finally,the effectiveness and superiority of the mimic defense was verified by experiments,and the model was summarized and prospected.
Resource Scheduling Strategy on heterogeneous executives, which is the “real” service provider, is studied in this paper based on Mimic Defense Theory. Since the redundancy and heterogeneity of executives, their response times differ. In order to mitigate the Bucket Effect on the response time of heterogeneous executives in the existing mimic defense methods, this paper proposes a method based on feedback control model that executive source allocation is adjusted dynamically to improve the response time of the executive set. The comparative experiment shows that this scheduling strategy has a great improvement in response process time, comparing with the existing scheduling strategy.
随着高职教育的实训教学与工程实践切合度越来越高,出现了课堂、设备、指导老师、教学内容的耦合度不高的现象.本文从课程改革的角度分析了将AR技术应用到高职计算机测配色实训教学中所需解决的问题,具体来说是从改革背景、意义、内容和方案等层面进行了分析.通过本文的分析可知,AR技术对高职教育中实训教学具有一定的辅助和促进作用.
本文提出了一种基于拟态理论的主动防御的新型框架.通过引入常微分动态系统来表述新型主动防御框架的动态化和结构化特点.通过常微分方程,将部分现实中的复杂网络攻防问题转化为简单的、准确定义的资源对抗模型.由此,可以对通过异构冗余和自修复性构建的主动防御系统的关键构造获得一种对抗模型分析.本框架可帮助实现对当前网络主动防御系统的有效性评估并通过选取有效的防御策略来加强系统安全性.
Cyberspace Mimicry Defense (CMD) has been widely used to achieve intrusion prevention against unknown system vulnerabilities or backdoors. The multi-ruling arbiter is a key part in CMD. This paper focuses on the problem of multi-ruling arbiter under data injection attack from the perspective of attacker and defender. We build a decentralized multi-ruling arbiter model for arbitration and introduced a standard iteration process to achieve consensus without attackers. We describe two data injection attack models for decentralized multi-ruling arbiter, namely random data injection attack and stealthy data injection attack. Further, we characterize the negative effect of the data injection attack on the performance of multi-ruling correctness. In order to mitigate the negative effect of random data injection attack, we propose a reliable multi-ruling arbitration approach based on adaptive threshold. By cutting future communication with the malicious neighbor, the decentralized multi-ruling arbiter is robust against random data injection attacks. Simulation results show that the proposed arbitration approach can effectively defend against random data injection attacks.
以γ-聚谷氨酸(γ-PGA)为原料,乙二醇缩水甘油醚为交联剂,采用溶液聚合法合成了新型γ-PGA水凝胶重金属吸附剂(γ-PGA-GDE),并研究γ-聚谷氨酸水凝胶对Cd2+、pb2的吸附特性.采用傅里叶红外光谱及扫描电镜对吸附材料进行表征,同时研究pH值、温度、吸附时间和重金属离子初始浓度对γ-聚谷氨酸水凝胶吸附特性的影响.结果表明,pH值为5利于γ-聚谷氨酸水凝胶对重金属离子的吸附,温度对其吸附重金属离子影响不大.γ-聚谷氨酸水凝胶对Cd2+、pb2重金属离子的吸附速率非常快,符合准二级动力学方程.其对重金属的吸附符合langmuir等温式,对pb2、Cd2饱和吸附量分别为526.22、255.54 mg/g,与试验值非常接近.γ-聚谷氨酸水凝胶经盐酸洗脱可再生,再生后可循环使用至少6次.
In this study,ARTP(atmospheric pressure and room temperature plasma,ARTP) method was used to obtain rapid mutagenesis of Bacillus subtilis E7 in atmospheric pressure and room temperature,to screen strain with high yield of surfactin.Several methods such as appearance screening,determination of diameter of hemolytic circle,culture in Microflask,detection by multifunctional enzyme standard detector,and shake flask test were combined to improve screening throughput and speed up screening process.A high-throughput screening system for mutant strain with high yield of surfactin was preliminarily built.High performance liquid chromatography (HPLC) was used to detect target product.After mutagenesis for 220 s,Bacillus subtillus strain SF90-5 with good genetic stability was obtained.Its surfactin yield increased to 0.8 g/L,which was 5 times of that of the original strain.Mutagenesis with ARTP resulted inreduced workload,effectively increased screening flux,and accelerated screening process.Desired target strain was obtained fleetly.This experiment provided a foundation for study of strain with high yield of surfactin.
When applying Software-Defined Networks (SDN) to WANs, the SDN flexibility enables the cross-domain control to achieve a better control scalability. However, the control consistence is required by all the cross-domain services, to ensure the data plane configured in consensus for different domains. Such consistence process is complicated by potential failure and errors of WANs. In this paper, we propose. a consistence layer to actively and passively snapshot the cross-domain control states, to reduce the complexities of service realizations. We implement the layer and evaluate performance in the PlanetLab testbed for the WAN emulation. The testbed conditions are extremely enlarged comparing to the real network. The results show its scalability, reliability and responsiveness in dealing with the control dynamics. In the normalized results, the active and passive snapshots are executed with the mean times of 1.873s and 105ms in 135 controllers, indicating its readiness to be used in the real network.
特征选择作为机器学习过程中的预处理步骤,是影响分类性能的关键因素.网络流量具有数据量大,特征维度高的特点,如何快速提取特征子集,并提高分类效率对于基于机器学习的流量分类方法具有重要意义.本文提出基于分治与投票策略的特征提取方法,将数据集分裂为多个子集,分别执行特征提取算法,利用投票方法获得最后的特征子集.实验表明可有效提高特征提取的时间效率,同时使分类器取得良好的分类准确率.
γ-聚谷氨酸产生菌枯草芽孢杆菌(Bacillus subtilis) HD 11经常压室温等离子体诱变处理,以不产生脂肽作为筛选标准之一,获得1株高产菌株HNCL1266,其γ-聚谷氨酸摇瓶发酵产量为26 g/L,较菌株HD11提高了30%,且遗传稳定.在5L发酵罐上,添加0.2 g/L的泡敌可有效抑制泡沫的产生,γ-聚谷氨酸产量达到30 g/L.
小麦纹枯病是由禾谷丝核菌引起的土传病害,生物防治具有重要的理论意义和应用前景。从发病小麦根系土壤中分离筛选出1株高效的拮抗菌株,电镜扫描结果显示菌体呈短杆状,大小一般在(1.7~2.1)μm×(0.5~0.8)μm。进一步通过生理生化鉴定及16S rRNA基因序列分析,确定为枯草芽孢杆菌。采用红外光谱分析将抗菌活性成分初步鉴定为酯肽类物质。
This paper analyzes the problems in bioengineering practice teaching of He'nan University. The analysis focuses on experiment teaching contents, industry practice teaching bases and graduation design. In the end, new teaching approach is formed and suggestions are put forward.
Twenty strains with petroleum as single carbon source were isolated from petroleum contaminated soil in Puyang petroleum field.The dominant bacteria KF-2 was identified as Alcaligenes xylosoxidans through morphological,physiological and biochemical identification,as well as 16S rRNA sequence analysis.With single factor and orthogonal experiment,the effects of carrier type and amount,pH,ratio of material to water,culture temperature,culture time and dry temperature on living bacteria count of bacterial agent from KF-2 were studied on 150 mm culture dish.The optimum conditions of bacterial agent preparation were wheat bran 10 g,pH 9,ratio of material to water 1∶3.6,cultivation at 25 ℃ for 3 d and dried at 30 ℃.The maximum living bacteria count of KF-2 agent attained 7.24×1010 CFU/g.
To alleviate dissolved oxygen limitation in inosine fermentation process,a new-style air distributor was used to establish Taylor vortex column in 50 m3 gas-liquid agitating fermentor.The results showed that Taylor vortex column could reduce the coalescence effect between bubbles and size of bubbles,improved oxygen supply capability of fermentor.The maximum value of OUR in the prophase of the fermentation attained 100 mol·m-3·h-1 increasing from 85 mol·m-3·h-1,the yield of inosine attained 36 g/L increasing from 32 g/L.Furthermore,the result in power saving test drew a conclusion of 54% electricity saving by reducing agitating electric current.