Fine grained vehicle recognition is a sub-category classification task, specifically for vehicles. It is faced with the problems of small inter-class differences and large intra-class variants, which is very challenging. In order to obtain better recognition accuracy, based on the network architecture searched by neural architecture search (NAS), this paper proposes a novel auxiliary learning method to help learn a more robust model for fine-grained vehicle recognition. Experimental results verify the effectiveness of the proposed method on the public Stanford-Cars and self-built FGVC_LAV datasets.
网站指纹攻击是对军事信息网络中加密流量实施监管与审查的基础技术.在对网站指纹攻击技术进行概述的基础上,介绍了基于流量特征的三种网站指纹攻击方法及其特点和不足,分析了当前基于深度学习的网站指纹攻击方法的优势和面临的挑战.阐述了针对网站指纹攻击的防御方法,并展望了下一步的研究方向.
SSH anonymous communication system is an effective means to protect information security and user’s privacy, but SSH anonymous communication may also be used for cybercrime activities. For the problem of SSH anonymous communication system being abuse is difficult to supervise, a website fingerprinting attack method against SSH anonymous traffic based on one-dimensional convolution neural network is proposed. The method integrates the feature engineering and the classification prediction step, and avoids the manual process of feature extraction, selection and combination in the traditional fingerprinting attack method. The method converts the downlink network stream into corresponding numeric values and normalizes them, then extracts the high-dimensional trafficfingerprint features and predicts the classification using the depth one-dimensional convolutional neural network. Through the experiment, using fingerprinting attack on 100 website targets, the accuracy rate reaches 92.03% and it indicates that the method can effectively attack the SSH anonymous communication.
For Network Function Virtualization (NFV) environment, the existing placement methods can not guarantee the mapping cost while optimizing the network delay, a service function chaining optimal placement algorithm is proposed based on the IQGA-Viterbi learning algorithm. In the training process of Hidden Markov Model (HMM) parameters, the traditional Baum-Welch algorithm is easy to fall into the local optimum, so the quantum genetic algorithm is proposed, which can better optimize the model parameters. In each iteration, the improved algorithm maintains the diversity of feasible solutions and expands the scope of the spatial search by replicating the best fitness population with equal proportion, thus improving the accuracy of the model parameters. In the process of solving Hidden Markov chain, to overcome the problem that can not be directly observed for hidden sequences, Viterbi algorithm can solve the implicit sequences exactly and solve the problem of optimal service paths in the directed graph. Experimental results show that the network delay and mapping costs are lower compared with the existing algorithms. In addition, the acceptance ratio of requests is raised.
Almost all of the encryption technology in the existing Internet of things system depends on the key,as the most im?portant means to ensure the communication among the nodes,it's security management can not be ignored. According to the high se?curity requirements of the military Internet of things,it combines with the navigation and measurement function of the Beidou navi?gation system,peoposing the military internet of things key's distribution,update and destruction management strategy based on the Beidou safety channel transmission and timing positioning function. The analysis shows that the strategy to effectively ensure the transmission of military security and real-time security of the Internet.
现实应用中的移动自组网大多具有群组移动的特性,如执行任务中的侦察分队、坦克分队、无人机机群等.根据目前的群组移动模型,按照基于点和基于区域两大类别,介绍了11种典型的群组移动模型,重点分析了每种模型的原理,并讨论了模型的特征与适用场景.
网络安全风险评估为准确评估网络的安全状态提供依据,是构建网络安全体系的基础和前提.在对网络安全风险评估进行概述的基础上,介绍了目前主流的网络安全风险评估方法,分析了其各自的优缺点,并对网络安全风险评估的发展趋势做出了预测.
当前网站采用HTTPS协议加密,对其实施监管与审查仅能识别站点,而不能进一步精细化识别子页面,针对这一问题,提出了一种针对HTTPS协议加密站点在使用内容分发网络(Content Distribute Network,CDN)分发资源情况下的精细化指纹攻击方法.首先利用CDN分发过程中将用户重定向到就近镜像服务器产生的域名系统(Domain Name System,DNS)查询序列作为页面指纹,然后使用支持向量机(Support Vector Machine,SVM)模型进行页面识别,最后采用在Internet中收集的数据集进行验证.结果表明:该方法获得了93%的站点子页面识别率,能有效精细化识别HTTPS加密站点的子页面.
为更加科学合理的对网络结构可控性进行定量分析,以较为普遍的无向网络作为研究对象,提出一种新的结构可控性定量分析方法.以PBH秩判据为基础,根据网络的邻接矩阵求解出最小控制输入节点的个数及对应的所有组数;结合网络节点总数、最小控制输入节点个数、最小控制输入节点组数3个参数,将结构可控的实现概率作为量化指标,实现结构可控性的定量分析.该方法可以更加合理有效地对结构可控性进行定量分析,为当前结构可控性的研究提供新的方法支撑.
Aiming at extracting traffic features using manual selection and feature combination methods in current network traffic feature engineering, it is difficult to accurately extract the features of common traffic characteristics. A network traffic feature extraction method based on autoencoder model is proposed. The method first converts the first 144 bytes of the network data packet into a numeric code, and then acts as an input to the stacked autoencoder, then outputs a 49-dimensional feature through a 4-layer network encode. Using the dataset collected in laboratory to verify the method, experiments show that the feature extracted by this method can effectively extract network traffic characteristics, the extracted features are representative, and can use low-dimensional data to represent high-dimensional data.
Aiming at the problem that the traditional fingerprinting attack feature extraction and attack method of HTTPS encrypted websites are difficult to effectively apply when using the CDN (Content Delivery Network) caching technology. In this paper, a fingerprinting attack method which uses the DNS resolution sequence in CDN as fingerprint and compares the fingerprint similarity of the websites using the longest common sub-sequence algorithm is proposed. The experimental results show that the average accuracy of the proposed method is 85.6%, and the standard fingerprint remains valid for a certain period of time, which can effectively identify HTTPS encrypted websites in CDN cache.
The dynamic characteristic of the equipment support information network is more and more obvious. The problem of lower controllability is urgently needed to be solved while meeting the weapon support task. According to the basic characteristics of equipment support information network, the basic network model is constructed. Based on quantitative analysis of controllability, a structure control method is proposed. This method is to eliminate the feature structure of row correlation in PBH matrix so that the minimum control input nodes would be reduced. Through the experiment and analysis, it is verified that the controllability of equipment support information network can be improved. The result of the study provides a new idea for improving the controllability of equipment support information network.
为解决物联网的安全漏洞凸显的问题,从军事物联网的高安全需求和节点终端负载能力考虑,提出了一种适用于军事物联网的身份认证方案.在优化一次性口令认证方案的基础上,通过北斗导航系统的授时、定位功能获得时间戳和位置坐标信息作为多因素认证因子,最终实现了节点间的双向认证.经过理论分析和基于SVO逻辑的协议形式化分析表明,该方案可实现预期的认证目标且不存在安全漏洞,具有良好的安全性和可靠性.
By using the BeiDou navigation Satellite System's RDSS business and integrating Shamir (t-n) threshold secret sharing scheme with key management scheme of Lite CA,this paper proposes a new asymmetric key management scheme method for the Internet of Things.The scheme uses a distributed Lite CA public key authentication framework,which does not require key management center for supporting.It can achieve the localization of the certification,solve the problem of the complexity of the certification,and effectively avoid the single point of failure of the certification.The analysis shows that the proposed scheme has better security and higher efficiency.
This paper, by taking the LTE communication network as the object of study and applying the discrete event simulation method and hierarchical modeling mechanism, analyzes the LTE protocol stack and classifies it at the simulation layer; designs the functions and parameters at each simulation layer following the "protocol-equipment-platform-network" modeling process and establishes UE and eNodeB node simulation models respectively; constructs the communication network simulation scenarios of LTE multi-node accession; and gets simulation data. Experiment shows that such simulation method is of high efficiency and produces reliable simulation data.
The tactic mobile ad hoc network is very important constituent part of the tactical Internet.This paper introduces three commonly used protocols of the MANET,designs the models of the device nodes and simulated-network,defines the parameters of the simulatedprotocol,builds the simulated scenarios of the three network protocols,and obtains the performance data of the network-simulation.The data analysis results have certain reference function for the construction of our tactic MANET.
Aiming at the problem of insufficient security protection in military internet of things under mobile state, a scheme of node key management on navigation system is proposed. By comparing the node-related data with the set strategy, it can complete the node's Key distribution, renewal and destruction. The analysis shows that the scheme has high security and survivability, and has played an important role in protecting the security of military internet of things.
针对日益严重的无线网络安全问题,从安全性和移动终端负载能力考虑,提出了一种WiFi环境下的轻量级双向身份认证方案.该方案基于挑战/应答机制,用户对认证服务器的认证通过基于异或运算的身份认证方式来实现;认证服务器对用户的认证通过基于公钥加密的身份认证方式实现.通过性能分析可知,该方案认证简洁,减轻了客户端的运算量和存储量,同时又能抵抗重放攻击、小数攻击、网络窃听和冒充攻击,适合应用到对安全性要求较高的WiFi环境下.
To meet new demands of equipment support information network in informatization construction,the paper has developed a scheme to build up a new-type equipment support information network.Starting from analysis on demand of equipment support information network in task and security,with the high flexibility of virtualization and software defined network (SDN),the paper develops an overall architecture scheme and a detailed architectural plan and illustrates that it is able to realize high management and operation efficiency and dynamic security capability.
介绍了传统TCP应用存在的不足,探讨了覆盖网络多路径与并行TCP的优势,并就覆盖网络多路径与并行TCP传输的应用进行研究和分析。将多路径与并行TCP结合起来能有效提高网络传输速度,为人们提供更为便捷的服务,实际工作中值得推广和应用。