结合当前新时代、新形势下的网络安全和信息化要求,本文分析了电网企业信息化工作和信息人才队伍现状及人才培养存在的问题,从信息化能力、人才培养方式、考核激励机制等方面对信息人才规划及培养进行了浅析,对电网企业进一步建立信息人才培养体系起到了借鉴作用.
With more and more widespread use of smartphones, malwares have become increasingly complex and large-scalely. As a free and open source system, Android has currently surpassed other mobile platforms to become the most popular operating system, so that the number of the Android platform malware has also been significantly increased. Focusing on the security issues of the software for the Android platform, this paper proposes an Android malware detection method based on multifeature collaborative decision. This method mainly bases on the analysis of the Android application, and then the feature attributes are extracted, the models according to machine learning are built. Lastly the classification algorithms are used to determine whether the application is malware. Experimental results show that using the proposed method to classify Android application data set has better assessments indicators than the indicators using other classifiers. Therefore, the method based on multi-feature collaborative decision approach to detect malicious software on Android applications can be made effective for detecting unknown malicious nature of the applications, and can avoid damage caused by malicious applications for the users.
To model embedded systems with timed automata is a kind of effective approach due to high real-time and strong con-currency properties,and introducing the time dimension into an automaton brings about infinite state spaces in an automaton, which makes it more difficult to test embedded software systems.A compression algorithm of time automata,namely states com-pression method of constraint symbolization,was proposed.Consequentially,based on this method,a formalization of timed au-tomata was presented.The linear temporal logic (LTL)properties represented as bounded model checking (BMC)problem can be determined by satisfiability modulo theories (SMT)solving.Through these methods the problem of state explosion of time automata can be solved to some extent.
We thoroughly study the PHP-based vulnerability detection and classification technology for remote file inclusion,based on it we design and implement a vulnerability classification and detection tool for remote file inclusion,build a PHP language-based target system,and conduct an overall functional and performance test on the prototype of detection tool.The vulnerability classification and detection idea proposed in this article is to simulate the attacker to send the requests to web application system and then to determine the existence of the vulnerabilities and their levels through the returned information from the server.
With the rapid expansion of negative information in the Internet, the content rating technology is developed. This paper proposed a rating supervision model based on content rating considering trust model. We firstly analyze the behavior and reputation of network entities from the following dimensions: data dimension, time dimension and application dimension, and then applied artificial neural network to construct the trust model referred to the trust relationship in human society network. At last, we proposed the rating supervision model based on the trust model. It is proved that the rating supervision model can not only meet the standard of PICS, but also take the behavior and reputation of network entities into consideration. As a result, the rating supervision model can provide a variety of security services to enhance the credibility of the information by combination of rating label and network entity reputation.
Due to the problems resulting from the postponed security evaluation for an already deployed information system,this paper studies a security evaluation mechanism for a non-deployed information system using the PDCA process model.The detailed process that applies the PDCA to the whole evaluation process is described and the formula to measure the evaluation results is given.The proposed PDCA-based network access security evaluation management model embodies the idea of integrating techniques with management,and provides a good reference for the future information security management system constructions.
Information security risk assessment in power system gained more attention gradually. This paper proposed an information security risk assessment model based on ISO 27001 combine with experience of information security risk assessment work in Guangdong Power Grid of CSG. This new model basis on the information security management system——ISO 27001, draws trialism of information security into practice. This model could comprehensively assess the information security risk in aspect of management, operation and technology.