The exponential growth of information on the World Wide Web makes it increasingly difficult to discover relevant data about a specific topic. In this case, growing interest is emerging in focused crawler, a program that traverses the Internet by choosing relevant pages to a predefined topic and neglecting those out of concern. A new focused crawler based on Naive Bayes classifier was proposed here, which used an improved TF-IDF algorithm to extract the characteristics of page content and adopted Bayes classifier to compute the page rank. Then the crawler developed was compared with a BFS crawler and a PageRank crawler, and the results show that our crawler has better performance than the PageRank crawler and BFS crawler in harvest ratio.
In order to promote the security of multi-users access, the properties of the BLP model, Biba model and RBAC model were given, and the problems of data write/read operation and data transmission in the security architecture of application area boundary were described. To solve the problems, the rules of creating objects, creating subjects and sending/receiving data in transmission were presented, and the rationality and security of the rules were proved formally. It was showed that the security architecture model of application area boundary, which was made of the rules is security.
Separation of duty(SoD)is a fundamental means for prevention of fraud and errors.Based on the Chinese wall security policy,a model of history-based separation of duty is implemented and it tracks the history of user's previous permissions record,from which the current permissions assigned to can be determined.The formal description and analysis about the model has been done and the model has been proved a well in accordance with principle of SoD.The model inherits the advantage of Chinese Wall security policy and separation of duty,and provides a more perfect access control stratagem.
In this paper, we show that the scalable multicast key distribution protocol based on RSA, proposed by Molva, is insecure against key compromise attack and collusion attack.
This article attempts to research a comprehensive model to quantify the risk.At first,the hierarchy model for the probability of uncertain events and the severity of adverse effects are constructed.And then Artificial Neural Network(ANN) and Fuzzy Comprehensive Evaluation(FCE) method are applied to measure the weight coefficients and quantify the risk factors in the hierarchy model.At last a calculation example is illustrated to show the method how to work.And linear regression is applied to detect the model's performance.It is believed that the method put forward by this paper cannot only quantify the risk of information system,but also can effectively choose the strategy for risk management.
This issue discusses the relation between security probability and expenses cost of the network information systems;being appraisement rule,the systems security increment provides gist to select the best risk control project;in virtue of Lagrange's multiplication,distributing logically the cost increment,it makes the integer security of network information systems to tiptop.
Based on the conclusion of the project of 863 Program which was taken charge by the author, the paper analyzed the purpose and significance of the project, and presented the research contents and methods. Focused on the different demand levels of information security talent, a talent training program of constructive education and non-education architecture, and corresponding layout of teaching material construction have been put forward separately.
To formulate a model that can evaluate the effectiveness of information system safety measurements,the relativity between safety measures counting certain risks(1∶n or m∶1) was studied.Supposing that the effectiveness of different safety measures has abstract function relation,the function was extended into power series by normalization,introduced all possible mathematical relativity,and eliminated redundant relativity by F-statistic and Gram-Schmidt orthography algorithm.By regression analysis,we get the high precision evaluation model than the line evalution model.
The risk analysis method based on variable precision rough set (VPRS) was proposed. It used reduct functions and filtered risk regulations and combined quantitative measurement with qualitative analysis. So it not only reduced greatly the data, but also increased the validity of risk regulations. At last, we analyzed the data in the reference [4] and mined the risk regulations effectively among them by using this method.
Concerning the security problems occurred while introducing a new financial product(international real-time transfer system),the paper completes design and configuration of security strategy and safety precaution including access control,database security,user management,password encryption,credit control,menu management,mainframe security and firewall.The result shows that the security solution,which is based on the combination of technology and management,is fully satisfying the requirements for a reliable,orderly and secure business system.
According to serveral drawbacks of existing one-time passwords schemes, this paper analyses the principle and advantages of the new independent one-time passwords scheme, and apply it into the database encryption system to strenghen the security of identity distinguishment.
Based on a thorough research on the time-domain security of BLP(Bell-LaPadula) model,an incorrect understanding on the time-domain security of BLP model was pointed out,and a new theoretical proof about the time-domain security of BLP model was given.The BLP model accords well with the requirement of confidentiality was indicated.
Automatic topology discovery is very important for improving network management and increasing network availability. The traditional topology discovery algorithms are based on SNMP, which is not universally deployed. Based on the analysis of the rule of IP address distribution in the network, a new universally algorithm was proposed. It relied on the result of last probing IP address and the rule of IP address distribution in the network to actively probe the next goal, and improved the speed of probing. It exploited properties of routers to resolve several aliases for a single router. The algorithm can discover the network topology more rapidly and accurately.
从系统可用性的一般定义出发,提出了防火墙可用性包括两个方面:一是"时间可用性",其衡量防火墙工作的持续性;二是"能力可用性",其衡量防火墙提供规定功能、性能的能力.并通过形式化数学方法对防火墙可用性进行了描述.之后进一步对由两台或两台以上防火墙构成的防火墙系统的高可用性进行了定义,并对提高防火墙系统高可用性的两种解决方案进行了定量分析和比较,结果表明"并联冗余"解决方案适用于对时间可用性要求特别高的应用场合,"旁联冗余"解决方案适用于对时间可用性要求比较高的应用场合,从而为解决适用于不同网络应用环境的防火墙系统高可用性问题提供了可行的理论依据和工程方法.
Wireless PKI is an optimized extension of traditional PKI, which concerns the key management for the wireless environment. Authors introduce the architecture and security mechanisms of WPKI and discuss the services of key management, and then describe the scheme of identity authentication and digital signatures.
Through the research on the electronic payment security protocol, this paper describes the process flows for the electronic payment security protocol by referring to Petri nets. It makes use of the reachability tree to analyze the correctness, safety, fairness, reachability and liveliness of the Petri nets model of security electronic payment. The work on electronic payment security protocol based on Petri nets provides values in both theoretical analysis and practical applications to electronic payment security problems.
In allusion to the chosen ciphertext attack and the common modulus attack etc security matter consisted in RSA's Public Key cryptographics algorithm, the original utilizes two combinatorial identical equation and RSA's public key cryptographics algorithm, and the structure was come out one improved public key algorithm, and that algorithm is easy, and it can avoid or partially avoid this type security matter consisted in RSA's,then it still more haves secure quality than RSA.
MS-CHAP is usually embedded in other protocols,and used to verify the peer's identity in a three-way-handshake.The security of MS-CHAP was formally analyzed by a protocol-verifying way from the attacker's point of view.The result showed that the MS-CHAP protocol has vulnerabilities by which the attacker can pass the authentication without cracking the password and the corresponding attacking scenario was given.The MS-CHAP protocol has some deadly security flaw and can't achieve the desired security goal.
Risk assessment modeling starts with identifying assessment elements and their internal relationships.Some element relationship models based on ISO 13335 and ISO 15408 were analyzed and to overcome redundancy and static state of relationships in those models, directness consequence rule and time dynamic rule should be observed,and grading of protection requirements should be taken into account. With these rules, new elements were added to obtain a new relationship model for risk assessment. Meanwhile, a more comprehensive systemic figure of security elements relationships than that in ISO 13335 was formulated. Finally, we describe reciprocal relationships of security elements with a formal method, and present characteristics of different security states of information system.
Authors proposes the formal language description of the risk and risk set in modern network information system, established the risk evaluation model, discussed the association of the risk in different risk domains, and provided the viable mathematical method for the risk evaluation of network information system.