为了克服分布式拒绝服务(Distributed Denial of Service,DDo S)攻击效果评估指标体系方法中传统主、客观赋权法的不足,同时提高利用指标体系评估的准确度,文章利用集成学习的思想,将主观赋权法中的模糊层次分析法(Fuzzy-Analytic Hiera...为了克服分布式拒绝服务(Distributed Denial of Service,DDo S)攻击效果评估指标体系方法中传统主、客观赋权法的不足,同时提高利用指标体系评估的准确度,文章利用集成学习的思想,将主观赋权法中的模糊层次分析法(Fuzzy-Analytic Hierarchy Process,FAHP)和客观赋权法中的熵权法集成以确定指标权重,将逼近于理想解的排序方法 (Technique for Order Preference by Similarity to an Ideal Solution,TOPSIS)和灰色关联度分析法(Grey Relational Analysis,GRA)集成进行评估计算,提出一种新的评估模型——TOPSIS-GRA集成评估法。同时,针对DDo S攻击效果评估研究不成熟的现状,文章从指标体系、组合赋权、TOPSIS-GRA集成评估法3方面给出了完整可行的评估过程。仿真实验结果表明,文章提出的TOPSIS-GRA集成评估法对DDo S攻击效果评估具有较强的适用性,评估结果客观可靠。展开更多
为了评估Piccolo密码算法的功耗分析安全性,该文提出一种针对Piccolo末轮的攻击模型,基于SASEBO(Side-channel Attack Standard Evaluation BOard)实测功耗数据对该算法进行了相关性功耗分析攻击。针对Piccolo末轮运算中包含白化密钥的...为了评估Piccolo密码算法的功耗分析安全性,该文提出一种针对Piccolo末轮的攻击模型,基于SASEBO(Side-channel Attack Standard Evaluation BOard)实测功耗数据对该算法进行了相关性功耗分析攻击。针对Piccolo末轮运算中包含白化密钥的特点,将末轮攻击密钥(包括轮密钥RK24L,RK24R,WK2,WK3)分成4段子密钥,逐个完成各个子密钥的攻击,使80位种子密钥的搜索空间从280降低到(2×220+2×212+216),使种子密钥的恢复成为可能。攻击结果表明,在实测功耗数据情况下,3000条功耗曲线即可恢复80位种子密钥,证实了该攻击模型的有效性和Piccolo硬件面向功耗分析的脆弱性,研究并采取切实有效的防护措施势在必行。展开更多
Under the conditions of multiple hits and quadratic effects,the aircraft vulnerability assessment method is proposed by means of kill-tree diagram and state transition matrix.Four instances of the quadratic effects ar...Under the conditions of multiple hits and quadratic effects,the aircraft vulnerability assessment method is proposed by means of kill-tree diagram and state transition matrix.Four instances of the quadratic effects are investigated:non-redundant components to non-redundant components,non-redundant to redundant,redundant to non-redundant and redundant to redundant.The application of the proposed method to the calculation of quadratic effects is also studied.展开更多
文摘为了克服分布式拒绝服务(Distributed Denial of Service,DDo S)攻击效果评估指标体系方法中传统主、客观赋权法的不足,同时提高利用指标体系评估的准确度,文章利用集成学习的思想,将主观赋权法中的模糊层次分析法(Fuzzy-Analytic Hierarchy Process,FAHP)和客观赋权法中的熵权法集成以确定指标权重,将逼近于理想解的排序方法 (Technique for Order Preference by Similarity to an Ideal Solution,TOPSIS)和灰色关联度分析法(Grey Relational Analysis,GRA)集成进行评估计算,提出一种新的评估模型——TOPSIS-GRA集成评估法。同时,针对DDo S攻击效果评估研究不成熟的现状,文章从指标体系、组合赋权、TOPSIS-GRA集成评估法3方面给出了完整可行的评估过程。仿真实验结果表明,文章提出的TOPSIS-GRA集成评估法对DDo S攻击效果评估具有较强的适用性,评估结果客观可靠。
文摘为了评估Piccolo密码算法的功耗分析安全性,该文提出一种针对Piccolo末轮的攻击模型,基于SASEBO(Side-channel Attack Standard Evaluation BOard)实测功耗数据对该算法进行了相关性功耗分析攻击。针对Piccolo末轮运算中包含白化密钥的特点,将末轮攻击密钥(包括轮密钥RK24L,RK24R,WK2,WK3)分成4段子密钥,逐个完成各个子密钥的攻击,使80位种子密钥的搜索空间从280降低到(2×220+2×212+216),使种子密钥的恢复成为可能。攻击结果表明,在实测功耗数据情况下,3000条功耗曲线即可恢复80位种子密钥,证实了该攻击模型的有效性和Piccolo硬件面向功耗分析的脆弱性,研究并采取切实有效的防护措施势在必行。
文摘Under the conditions of multiple hits and quadratic effects,the aircraft vulnerability assessment method is proposed by means of kill-tree diagram and state transition matrix.Four instances of the quadratic effects are investigated:non-redundant components to non-redundant components,non-redundant to redundant,redundant to non-redundant and redundant to redundant.The application of the proposed method to the calculation of quadratic effects is also studied.