随着我国经济进入"新常态"和"三期叠加",金融不良资产市场出现了不良资产处置模式发生变化、政策优惠将结束、参与主体多元化等新情况,同时,金融资产管理公司自身不良资产处置业务中也存在外部环境阻碍不良资产处置业务的良性发展、公司内部管理不完善、不良资产处置业务自身不足等问题,金融资产管理公司经营发展面临着严峻考验.为坚守主营的不良资产处置业务保持可持续发展,四家金融资产管理公司不仅要积极争取监管部门适度调整监管措施的政策支持,也急需寻求如:强化内部管理、创新不良资产业务运作模式等新的经营对策.
In this paper we developed a GPRS solution for remote visual monitoring lamp by using GPRS and GIS technology. Accord-ing to analyzing the data communication feature of GPRS,we establishes the format of transmission frame and the corresponding transmission protocol,at the same time,some key program of realizing monitoring lamp are referred. Practical application shows this scheme is simple and utility. Also,the reliable performance of communication accords with the field requirement and the scheme has a reference value to develop the same kind of the monitoring system.
为了克服基于"事后取证"理念而设计的计算机取证过程模型的不足,借鉴传统刑事案件侦查的"秘密侦查措施",在计算机取证技术体系中引入"跟踪"、"监控"、"网络渗透"等主动采集技术,提出了一个基于跟踪的计算机取证过程模型。介绍了该模型的工作流程,分析了该模型的特色,指出了该模型的适用范围。
Nowadays, firewall has become the most elementary network security device and the log recording and handling are the es- sential function of firewall. The paper proposed a scheme of log handling according to the characteristics of firewall log in high- speed network environment. The scheme can exhaustively and effectively record all communication log, which not only saves the stor- age room of communication log, but also improves the audit efficiency.
The paper investigates some problems on external sort and sort area of Oracle database. Based on analyzing the external sort efficiency affected by sort area size, the author offers an algorithm for setting sort area size. Experimental result shows that the algorithm can enhance the external sort efficiency and the query processing performance.
The confidentiality security service provided by IPSec for communication is dependent on the cipher algorithm and key used by the two parties of communication.Although the IPSec protocol specifies that the two parties of communication can ascertain the key in automatic or manual manner,no matter what manner is adopted,the result eventually is that both sides will use the invariable key to encrypt or decrypt a mass of packets in a period of time,which can't be suitable for the occasions which have especial demands for security.The paper proposed a scheme which can implement one-packet key in IPSec.In the scheme,when a IPSec entity needs to encrypt an IP packet,it derives the working key from a random number generated temporarily and the intersected key distributed in advance,which achieves the purpose that the two parties of communication use different key to encrypt or decrypt every IP packet.The paper also analyzed the correctness and security of the scheme and pointed out the appropriate application occasion for which the scheme is suitable.
This paper introduces the principals of several prevailing network penetration techniques.It focuses on the stack(overflow) technique to break through firewall's detection,and analyses the challenge and damage this technique bringing to information security protection.From the aspect of information security assurance,the paper also puts forward some security defense measures for the state.
The quantitative assessment method of network information risks is an important and basic study in the information security.In the risk analysis of information system,it is very difficult to effectively quantify the risks,because lots of risk factors are very vague to us.What these factors are and how they influence the risks are the problems.This paper provides a framework of the basic evaluation index system for the risks to solve these problems.With the index system,the results of risk evaluation will be consistent,comparable,and objective.
近年来,在很多领域出现了盲目投资和低水平的重复建设,这种现象同当前提倡的建设节约型社会很不相符。本文针对重复建设在中国特有的特点,从制度经济学的角度进行了分析,并提出了一些解决的办法。
To establish the resource monitoring architecture of secret-associated network, the internal deregulation operations in secret-associated network was analyzed, and the ways about leaking the secret information was introduced. Based on the research, the leaking of secret-associated information can be prevented by real time monitoring usage of software or hardware resource of secret-associated compute. The prototype system's components and software structure were designed and implemented, which are based on the resource monitoring architecture proposed. Specially, the establishment, assignability and application of the security policy were described in the paper.
功能性监管和面向过程监管在传统的金融监管模式基础上更加侧重金融安全与金融效率的协调,成为当代金融监管的两大趋势.这两大趋势对我国金融业也有重要的启示:建立合乎我国国情的功能性监管体系,强化金融业的功能性监管,引进监管评价制度.
Authors proposes the method about describing risk of information system security with probability,define risk intensity,and discussed the mathematical method for computing total probability of risk and individual probability of risk in network information system.It provided a new way for researching statistics characteristic of the probability of risk in network information system.
从系统可用性的一般定义出发,提出了防火墙可用性包括两个方面:一是"时间可用性",其衡量防火墙工作的持续性;二是"能力可用性",其衡量防火墙提供规定功能、性能的能力.并通过形式化数学方法对防火墙可用性进行了描述.之后进一步对由两台或两台以上防火墙构成的防火墙系统的高可用性进行了定义,并对提高防火墙系统高可用性的两种解决方案进行了定量分析和比较,结果表明"并联冗余"解决方案适用于对时间可用性要求特别高的应用场合,"旁联冗余"解决方案适用于对时间可用性要求比较高的应用场合,从而为解决适用于不同网络应用环境的防火墙系统高可用性问题提供了可行的理论依据和工程方法.
To settle the technical difficulty in network evidence-getting,referring to the label and Trojan horse technique in security theory,this paper puts forward a network evidence-getting technique scheme called GENBAD(Gathering Evidence by Network Based on Active Defence),which is based on tracking sensitive information.The paper introduces the architecture and work mechanism of GENBAD.GENBAD are partly implemented by prototype method.The paper also analyses the advantage of GENBAD and the idea to promote GENBAD.
MS-CHAP is usually embedded in other protocols,and used to verify the peer's identity in a three-way-handshake.The security of MS-CHAP was formally analyzed by a protocol-verifying way from the attacker's point of view.The result showed that the MS-CHAP protocol has vulnerabilities by which the attacker can pass the authentication without cracking the password and the corresponding attacking scenario was given.The MS-CHAP protocol has some deadly security flaw and can't achieve the desired security goal.
在基于IPsec的远程访问VPN中,由于NAT的存在,使得具有私有地址的移动用户无法进行远程访问,对此,本文提出了基于UDP封装的解决方案,能有效地解决这个问题.
传统的网络安全技术如密码技术、IPSec技术、访问控制等在维护网络安全方面虽然起到了重要的作用,但这种防范是被动的,而入侵检测技术是维护网络安全的一种积极主动的防范措施,是网络安全管理员的得力助手.