期刊文献+
共找到7,071篇文章
< 1 2 250 >
每页显示 20 50 100
关键信息基础设施物联网安全发展态势及展望 认领 引用 被引量:1
1
作者 徐文渊 程雨诗 +1 位作者 陈艳姣 冀晓宇 《中国工程科学》 EI CSCD 北大核心 2026年第2期125-136,共12页
随着关键信息基础设施物联网加速向规模化应用迈进,其在能源、交通、工业等关键领域的广泛部署,正带来前所未有的安全挑战。物联网技术在推动行业智能转型的同时,也带来了系统性安全隐患,直接关系国家安全、经济运行和社会稳定大局。本... 随着关键信息基础设施物联网加速向规模化应用迈进,其在能源、交通、工业等关键领域的广泛部署,正带来前所未有的安全挑战。物联网技术在推动行业智能转型的同时,也带来了系统性安全隐患,直接关系国家安全、经济运行和社会稳定大局。本文从通用风险与专属场景威胁两个维度切入,系统剖析传统物联网“云‒管‒边‒端”架构中的安全问题,并针对新兴趋势带来的风险展开探讨,覆盖具身智能等五大典型应用场景的安全议题。基于物联网安全现状与发展趋势,本文进一步阐释了关键信息基础设施物联网的安全内涵与核心风险,结合其架构特点与实际应用需求,提出“通域统一保障+专域定制增强”的防护理念,倡导构建覆盖全域、动态协同、智能自适应的新一代安全防护体系与治理路径,并从战略、制度、技术、人才与国际合作五个方面系统推进,以实现可持续演进的安全治理能力。 展开更多
关键词 关键信息基础设施 物联网 安全风险 安全防护
暂未订购 下载PDF
改进模糊推理的光纤通信网络安全域判定研究 认领 引用 被引量:2
2
作者 苟全登 李治国 张双 《激光杂志》 CAS 北大核心 2026年第2期159-164,共6页
为了提高光纤通信网络安全,提出改进模糊推理的光纤通信网络安全域判定方法。根据光纤通信网络数据特征的不确定性和模糊性确定高斯型隶属度函数,结合隶属度函数和双向相似度构建推理库规则,在推理库规则中加入遗忘因子,应用改进模糊推... 为了提高光纤通信网络安全,提出改进模糊推理的光纤通信网络安全域判定方法。根据光纤通信网络数据特征的不确定性和模糊性确定高斯型隶属度函数,结合隶属度函数和双向相似度构建推理库规则,在推理库规则中加入遗忘因子,应用改进模糊推理规则完成光纤通信网络异常检测。提取网络异常的光纤通信网络数据特征,采用经验模态分解方法对数据特征展开分解、获取数据特征拟合曲线,依据拟合曲线确定安全域判定门限值,实现光纤通信网络安全域判定。实验结果表明,所提方法可以精准实现光纤通信网络安全域判定,FMCE值低且波动小,AUC值更加接近1且稳定性强,同时异常检测率高达98.75%,误报率仅为1.21%,漏检率为2.34%和检测时延为2.1 s,确保了网络的安全运行。 展开更多
关键词 改进模糊推理 光纤通信网络 安全域判定 拟合曲线 门限值
暂未订购 下载PDF
融合信任值和身份标识验证的节点复制攻击检测策略 认领 引用
3
作者 滕志军 苗润升 +2 位作者 孙铭阳 李纪奇 赵立权 《哈尔滨工业大学学报》 EI CAS CSCD 北大核心 2026年第5期63-72,共10页
为抵御无线传感器网络中的节点复制攻击,保障网络的安全与稳定,本文提出了一种融合信任值和身份标识验证的节点复制攻击检测策略(node replication attack detection strategy integrating node creditworthiness and identity authenti... 为抵御无线传感器网络中的节点复制攻击,保障网络的安全与稳定,本文提出了一种融合信任值和身份标识验证的节点复制攻击检测策略(node replication attack detection strategy integrating node creditworthiness and identity authentication,NRADS-NC&IA)。该方法首先建立模糊综合信任评价模型,在直接信任模块中引入信誉维护函数、异常弱化因子及奖惩因子,综合通信属性、数据属性、网络属性和物理属性影响因素计算待评估节点的直接信任值,并采用滑动时间窗口机制实现节点信任值的动态更新,有效提升评估的时效性与准确性,在此基础上应用支持度函数评估节点可信度,从而有效过滤节点的欺骗行为得到更为可靠的节点间接信任值,最终的节点综合信任值由直接信任值与间接信任值加权求和得到;采用动态自适应阈值筛选可疑节点,并在可疑节点中进行节点ID比对,以确定副本节点。仿真实验表明,NRADS-NC&IA在无需依赖节点空间位置信息的情形下,静态和移动无线传感器网络的检测率保持在97%和94%以上,具有较强的环境适应性,可有效应对复杂动态环境中的无线传感器网络安全问题。 展开更多
关键词 无线传感器网络 信任值 身份标识验证 节点复制攻击 模糊权重
暂未订购 下载PDF
网络行为孪生驱动的物联网异常流量检测 认领 引用
4
作者 何高峰 田健峥 +4 位作者 李亚文 徐丙凤 朱海婷 张璐 郭乃瑄 《通信学报》 EI CSCD 北大核心 2026年第3期156-169,共14页
针对现有物联网异常流量检测主要依赖于机器学习或深度学习算法,不仅资源消耗高,还易产生大量误报的问题,提出一种基于网络行为孪生的异常流量检测方法。该方法利用大语言模型从设备源码中自动提取网络规则,构建物联网设备的网络行为数... 针对现有物联网异常流量检测主要依赖于机器学习或深度学习算法,不仅资源消耗高,还易产生大量误报的问题,提出一种基于网络行为孪生的异常流量检测方法。该方法利用大语言模型从设备源码中自动提取网络规则,构建物联网设备的网络行为数字孪生模型,并以此为基础实时模拟设备的正常网络行为,实现对异常流量的高效检测。实验结果表明,所提方法在拒绝服务攻击、命令与控制通信以及内网扫描等典型场景下的检测任务中,检测效果均显著优于现有检测方法。与最新的预训练模型TrafficFormer相比,模型大小由682 MB降至17 KB,计算和存储资源消耗分别降低85.44%和94.06%。所提方法兼具高检测精度与边缘部署能力,适用于资源受限的物联网环境,为物联网网络安全提供了虚实结合的动态防护新思路。 展开更多
关键词 数字孪生 大语言模型 异常流量检测 物联网安全 轻量化模型
暂未订购 下载PDF
CIDefuse:融合数据流分析与语义嵌入的命令注入漏洞检测系统 认领 引用
5
作者 陈霄 沙乐天 +3 位作者 潘家晔 孙瑞 董建阔 肖甫 《通信学报》 EI CSCD 北大核心 2026年第1期91-105,共15页
针对物联网设备中命令注入漏洞危害严重,而现有静态分析误报率高、动态分析覆盖率低及代码相似性检测难以处理跨函数漏洞的问题,提出一种融合数据流分析与语义嵌入的漏洞检测系统CIDefuse。首先,利用轻量级的反向可达定义分析,从固件二... 针对物联网设备中命令注入漏洞危害严重,而现有静态分析误报率高、动态分析覆盖率低及代码相似性检测难以处理跨函数漏洞的问题,提出一种融合数据流分析与语义嵌入的漏洞检测系统CIDefuse。首先,利用轻量级的反向可达定义分析,从固件二进制代码中快速剪枝并精确提取跨函数的漏洞候选路径。随后,通过层次化图嵌入网络捕捉代码的深层结构与语义信息,实现漏洞精准识别。实验结果表明,CIDefuse取得了0.93的曲线下面积(AUC)值、93.75%的精确率和90.91%的F1值,性能优于主流方法。此外,CIDefuse成功挖掘出3个未知漏洞,并均已获得国家信息安全漏洞共享平台(CNVD)的官方认证,证明了其有效性和实际应用价值。 展开更多
关键词 物联网安全 命令注入 数据流分析 语义嵌入 二进制分析
暂未订购 下载PDF
基于物联网的多元异构网络安全入侵检测技术 认领 引用 被引量:2
6
作者 林家全 《信息记录材料》 2026年第1期151-153,156,共3页
在物联网(IoT)环境下,多协议并存、设备类型多样导致网络安全检测面临延迟高、检测能力不足等挑战。本文提出一种基于边缘计算与自编码器与支持向量机(SVM)混合模型的分布式入侵检测技术,通过边缘侧多协议数据采集与预处理,统一生成流... 在物联网(IoT)环境下,多协议并存、设备类型多样导致网络安全检测面临延迟高、检测能力不足等挑战。本文提出一种基于边缘计算与自编码器与支持向量机(SVM)混合模型的分布式入侵检测技术,通过边缘侧多协议数据采集与预处理,统一生成流量特征,并在云端对正常流量进行无监督自编码器预训练,结合有监督SVM分类器完成模型训练。在线检测时,边缘实时计算重构误差并将疑似异常样本提交云端二次确认与告警,既能及时捕捉未知威胁,又能准确识别已知攻击,显著提升了多协议异构网络环境下的检测效率与响应速度。 展开更多
关键词 物联网 多元异构网络 入侵检测 分布式架构
暂未订购 下载PDF
A Graphical User Authentication with Compass Direction and Rotation-Based Dual-Derivation 认领 引用
7
作者 Chin Soon Ku Hui Yi Lim +5 位作者 Ana Nabilah Binti Sa’uadi Siew Cheng Lai Jit Theam Lim Pei Xuan Ku Zeng-Wei Hong Lip Yee Por 《Computers, Materials & Continua》 SCIE EI 2026年第9期1280-1296,共17页
In the expanding Internet of Things(IoT)ecosystem,billions of interconnected devices exchange sensitive data,making secure and usable authentication critical.IoT devices in public or shared environments are vulnerable... In the expanding Internet of Things(IoT)ecosystem,billions of interconnected devices exchange sensitive data,making secure and usable authentication critical.IoT devices in public or shared environments are vulnerable to shoulder-surfing and video recorded observation attacks.Traditional passwords and static graphical schemes remain susceptible due to predictable patterns and direct credential entry.This study presents a novel recognition-based graphical authentication scheme that combines pass-image selection with compass direction substitution and rotation logic to resist observation-based attacks.A prototype was evaluated with 58 participants over three days.Usability metrics included registration time,login time,success rate,and error rate.Memorability and resistance to shoulder-surfing were also assessed.Results showed that login times decreased from 43.62 to 37.78 s,while success rates increased from 40%to 53%,indicating rapid adaptation.Memorability scores improved from 2.05 to 2.19 on a 3-point scale,with perfect recall for five-image passwords by Day 3.Shoulder-surfing tests recorded a 0%attacker success rate.The preliminary results suggest that the scheme offers a useful balance of usability,memorability,and resistance to single session observation attacks.Future work will explore adaptive complexity and accessibility features to further enhance secure authentication. 展开更多
关键词 Graphical user authentication compass direction rotation pattern dual-derivation shoulder-surfing attack video recording attack
暂未订购 下载PDF
基于Transformer的域自适应物联网流量入侵检测方法 认领 引用
8
作者 朱枫 叶宗国 +1 位作者 李鹏 徐鹤 《计算机科学》 CSCD 北大核心 2026年第3期443-452,共10页
随着物联网(Internet of Things,IoT)设备的普及,使用入侵检测来保护IoT设备免受恶意攻击至关重要。但是,IoT的数据稀缺性限制了传统入侵检测方法的效果。同时,现有基于域自适应的入侵检测方法的对齐方式粗糙,忽略了内在语义属性的转移... 随着物联网(Internet of Things,IoT)设备的普及,使用入侵检测来保护IoT设备免受恶意攻击至关重要。但是,IoT的数据稀缺性限制了传统入侵检测方法的效果。同时,现有基于域自适应的入侵检测方法的对齐方式粗糙,忽略了内在语义属性的转移,降低了特征的可区分性。为解决上述问题,提出了一种基于Transformer的域自适应物联网入侵检测(Transformer-Based Domain-Adaptive IoT Intrusion Detection,TDAIID)模型,从域间、类间和样本间3个层次对齐互联网入侵(Network Intrusion,NI)域和物联网入侵(Internet of Things Intrusion,Ⅱ)域。交叉注意力机制聚焦于NI源域和Ⅱ目标域中相同类别样本之间的相似特征,实现样本级别的域特征对齐;多重几何语义对齐从域级和类级两个角度进行语义对齐,有助于交叉注意力机制学习更丰富、更准确的源NI域知识。此外,为了充分挖掘未标记Ⅱ目标域的潜力,从几何角度提出了一种动态中心感知伪标签算法,用于提高伪标签标记的准确性,有效降低错误分配伪标签造成的负迁移。在多个常用入侵检测数据集上的综合实验表明,TDAIID模型的性能优于当前先进的基线模型。 展开更多
关键词 域自适应 物联网 入侵检测 交叉注意力 迁移学习
暂未订购 下载PDF
Trust-Centric Security Architecture and Anomaly Analytics for Distributed Fog-IoT Systems 认领 引用
9
作者 Maram Fahaad Almufareh Mamoona Humayun +2 位作者 Sadia Din Khalid Haseeb Amr Munshi 《Computer Modeling in Engineering & Sciences》 SCIE EI 2026年第4期1413-1424,共12页
The real-time systems perform key functionalities in various fields to automate the communication and response in critical events.The Internet of Things(IoT),integrated with numerous physical objects,gathers environme... The real-time systems perform key functionalities in various fields to automate the communication and response in critical events.The Internet of Things(IoT),integrated with numerous physical objects,gathers environmental data,processes it at the edge,and provides intelligent decisions while routing health records to processing units.However,the dynamic and resource-constrained nature of IoT-based healthcare environments introduces significant challenges related to latency,transmission costs,and the reliable interaction of devices amid uncertain activities.In this work,we propose a framework for a consistent and trustworthy system that uses a weighted trust aggregation model to consider multiple parameters and support timely routing decisions in a Fog-driven healthcare environment.Furthermore,authorized access to critical and sensitive health data is achieved through mutual authentication among devices,ensuring data integrity.The analysis of trust scores dynamically enhances resilience and the timely detection of malicious actions,thereby improving the healthcare system’s performance across unpredictable channels.The performance of the proposed framework is tested and validated against CLCSR and FSRF,and performance results revealed the significance for energy consumption,response time,network throughput,trust level,and accuracy across varying fog node capacity and interference scenarios. 展开更多
关键词 Fog computing data privacy healthcare system intelligent decision network attackers
暂未订购 下载PDF
Performance Evaluation of Malicious Node Detection and Mitigation of IoT-Based Trust Model for Wireless Sensor Network 认领 引用
10
作者 Anil Kumar Abhay Bhatia +3 位作者 Amit Singh Preeti Rani Vincent Omollo Nyangaresi Mahendihasan S.Heera 《Computers, Materials & Continua》 SCIE EI 2026年第7期1921-1947,共27页
The Internet of Things(IoT)enables seamless real-time monitoring and data exchange across distributed and heterogeneous environments with wireless sensor networks(WSNs).The open architecture and resource constraints o... The Internet of Things(IoT)enables seamless real-time monitoring and data exchange across distributed and heterogeneous environments with wireless sensor networks(WSNs).The open architecture and resource constraints of wireless sensor networks(WSNs)make them highly vulnerable to internal security threats caused by malicious or compromised nodes,particularly in Internet of Things(IoT)environments.To address this issue,we proposed Dynamic Trust Evaluation Model(DTEM),designed to provide a secure,scalable,and efficient framework for IoT-based WSNs.The proposed model identifies the role of trust management in routing,data aggregation,and intrusion detection,including trust-based protocols.DTEM incorporates a lightweight elliptic curve cryptography(ECC)mechanism to ensure secure communication,protect trust information from manipulation,and enhance overall system reliability.In addition,machine learning techniques are employed to improve malicious node classification accuracy.Component-wise analysis demonstrates that the dynamic trust evaluation forms the core detection mechanism,while ECC enhances communication security and machine learning improves malicious node classification accuracy.A large-scale network simulation is conducted to evaluate DTEM’s performance under various attack scenarios.Results demonstrate improved malicious node detection accuracy,higher packet delivery ratios,reduced energy consumption,and lower communication overheads.The proposed DTEM framework proves to be a robust and scalable solution for securing IoT-based wireless sensor networks,making it suitable for real-world applications. 展开更多
关键词 Internet of Things node detection security threats security and protocols wireless sensor network
暂未订购 下载PDF
An Adaptive Federated Learning with XGBoost Ensembles for Intrusion Detection in Heterogeneous IoT Networks 认领 引用
11
作者 Abdulaziz A.Alsulami Qasem Abu Al-Haija +4 位作者 Rayed Alakhtar Ahmad J.Tayeb Badraddin Alturki Huda Alsobhi Rayan A.Alsemmeari 《Computers, Materials & Continua》 SCIE EI 2026年第9期1896-1927,共32页
The rapid growth of the Internet of Things(IoT)devices has increased the attack area of modern networks,which makes effective intrusion detection systems(IDSs)essential to detect attacks that target IoT infrastructure... The rapid growth of the Internet of Things(IoT)devices has increased the attack area of modern networks,which makes effective intrusion detection systems(IDSs)essential to detect attacks that target IoT infrastructures.Federated learning is a promising approach for collaborative model training in the absence of centralized raw data.Conventional federated approaches rely on fixed client participation and static training configurations,which ensure symmetric treatment of clients despite heterogeneous local data distributions.This can limit convergence and degrade detection performance in non-IID conditions.This paper proposes an Adaptive Action-Based Federated Learning(AAFL)framework for decentralized intrusion detection in heterogeneous IoT environments.The framework dynamically adjusts both participating clients and local training workload at each communication round using a Linear Upper Confidence Bound(LinUCB)contextual bandit controller.The proposed Adaptive-FL model is based on XGBoost boosters and uses quality-weighted server-side ensemble aggregation.At the same time,adaptation is guided by a multi-objective reward that balances classification performance,training latency,communication overhead,and computational cost.The framework is evaluated on CIC IoMT 2024 and RT-IoT2022 under realistic non-IID conditions using stratified 5-fold cross-validation and benchmarked against Static-FL,FedAvg-FL,and a centralized XGBoost upper bound.Experimental results demonstrate that Adaptive-FL outperforms all federated baselines across both datasets,achieving Macro-F1 scores of 98.27%on RT-IoT2022 and 94.21%on CIC IoMT 2024,with statistically significant improvements over Static-FL on both datasets.Adaptive-FL maintains superior classification stability while avoiding raw-data centralization.It remains within 0.67 and 0.35 percentage points of the centralized upper bounds on RT-IoT2022 and CIC IoMT 2024,respectively. 展开更多
关键词 Federated learning Internet of Things(IoT) intrusion detection systems(IDS) XGBoost adaptive federated learning
暂未订购 下载PDF
EDESC-IDS:An Efficient Deep Embedded Subspace Clustering-Based Intrusion Detection System for the Internet of Vehicles 认领 引用
12
作者 Lixing Tan Liusiyu Chen +2 位作者 Yang Wang Zhenyu Song Zenan Lu 《Computers, Materials & Continua》 SCIE EI 2026年第5期997-1020,共24页
Anomaly detection is a vibrant research direction in controller area networks,which provides the fundamental real-time data transmission underpinning in-vehicle data interaction for the internet of vehicles.However,ex... Anomaly detection is a vibrant research direction in controller area networks,which provides the fundamental real-time data transmission underpinning in-vehicle data interaction for the internet of vehicles.However,existing unsupervised learning methods suffer from insufficient temporal and spatial constraints on shallow features,resulting in fragmented feature representations that compromise model stability and accuracy.To improve the extraction of valuable features,this paper investigates the influence of clustering constraints on shallow feature convergence paths at the model level and further proposes an end-to-end intrusion detection system based on efficient deep embedded subspace clustering(EDESC-IDS).Following the standard learning approach,continuous messages are encoded into two-dimensional data frames via a frame builder,which are then input into an extended convolutional autoencoder for extracting shallow features from high-dimensional data.On this basis,the dual constraints of these output features and the embedding clustering module facilitate end-to-end training of the EDESC-IDS in various attack scenarios.Extensive experimental results show that such a system exhibits significant detection performance on four types of attack datasets,including DoS,Gear,Fuzzy,and RPM,with precision,recall,and F1 scores consistently above 97.79%,while maintaining a false negative rate(FNR)and an error rate(ER)below 2.22%. 展开更多
关键词 Internet of vehicles control area network anomaly detection unsupervised learning deep embedded subspace clustering extended convolutional autoencoder
暂未订购 下载PDF
An Efficient Certificateless Authentication Scheme with Enhanced Security for NDN-IoT Environments 认领 引用
13
作者 Feihong Xu Jianbo Wu +3 位作者 Qing An Fei Zhu Zhaoyang Han Saru Kumari 《Computers, Materials & Continua》 SCIE EI 2026年第4期1788-1801,共14页
The large-scale deployment of Internet of Things(IoT)technology across various aspects of daily life has significantly propelled the intelligent development of society.Among them,the integration of IoT and named data ... The large-scale deployment of Internet of Things(IoT)technology across various aspects of daily life has significantly propelled the intelligent development of society.Among them,the integration of IoT and named data networks(NDNs)reduces network complexity and provides practical directions for content-oriented network design.However,ensuring data integrity in NDN-IoT applications remains a challenging issue.Very recently,Wang et al.(Entropy,27(5),471(2025))designed a certificateless aggregate signature(CLAS)scheme for NDN-IoT environments.Wang et al.stated that their construction was provably secure under various types of security attacks.Using theoretical analysis methods,in this work,we reveal that their CLAS design fails to meet unforgeability,a core security requirement for CLAS schemes.In particular,we demonstrate that their scheme is vulnerable to amalicious public-key replacement attack,enabling an adversary to produce authentic signatures for arbitrary fraudulent messages.Therefore,Wang et al.’s design cannot achieve its goal.To address the issue,we systematically examine the root causes behind the vulnerability and propose a security-enhanced CLAS construction for NDN-IoT environments.We prove the security ofour improveddesignunder the standard security assumptionandalsoanalyze its practicalperformanceby comparing the computational and communication costs with several related works.The comparison results show the practicality of our design. 展开更多
关键词 IoT certificateless signature public-key replacement attack data integrity aggregation
暂未订购 下载PDF
A Secure and Efficient Distributed Authentication Scheme for IoV with Reputation-Driven Consensus and SM9 认领 引用
14
作者 Hui Wei Zhanfei Ma +2 位作者 Jing Jiang Bisheng Wang Zhong Di 《Computers, Materials & Continua》 SCIE EI 2026年第1期822-846,共25页
The Internet of Vehicles(IoV)operates in highly dynamic and open network environments and faces serious challenges in secure and real-time authentication and consensus mechanisms.Existing methods often suffer from com... The Internet of Vehicles(IoV)operates in highly dynamic and open network environments and faces serious challenges in secure and real-time authentication and consensus mechanisms.Existing methods often suffer from complex certificate management,inefficient consensus protocols,and poor resilience in high-frequency communication,resulting in high latency,poor scalability,and unstable network performance.To address these issues,this paper proposes a secure and efficient distributed authentication scheme for IoV with reputation-driven consensus and SM9.First,this paper proposes a decentralized authentication architecture that utilizes the certificate-free feature of SM9,enabling lightweight authentication and key negotiation,thereby reducing the complexity of key management.To ensure the traceability and global consistency of authentication data,this scheme also integrates blockchain technology,applying its inherent invariance.Then,this paper introduces a reputation-driven dynamic node grouping mechanism that transparently evaluates and groups’node behavior using smart contracts to enhance network stability.Furthermore,a new RBSFT(Reputation-Based SM9 Friendly-Tolerant)consensus mechanism is proposed for the first time to enhance consensus efficiency by optimizing the PBFT algorithm.RBSFT aims to write authentication information into the blockchain ledger to achieve multi-level optimization of trust management and decision-making efficiency,thereby significantly improving the responsiveness and robustness in high-frequency IoV scenarios.Experimental results show that it excels in authentication,communication efficiency,and computational cost control,making it a feasible solution for achieving IoV security and real-time performance. 展开更多
关键词 Internet of vehicles consensus mechanism blockchain SM9
暂未订购 下载PDF
An Adaptive Intrusion Detection Framework for IoT: Balancing Accuracy and Computational Efficiency 认领 引用
15
作者 Abdulaziz A.Alsulami Badraddin Alturki +2 位作者 Ahmad J.Tayeb Rayan A.Alsemmeari Raed Alsini 《Computers, Materials & Continua》 SCIE EI 2026年第6期1214-1241,共28页
Intrusion Detection Systems(IDS)play a critical role in protecting networked environments from cyberattacks.They have become increasingly important in smart environments such as the Internet of Things(IoT)systems.Howe... Intrusion Detection Systems(IDS)play a critical role in protecting networked environments from cyberattacks.They have become increasingly important in smart environments such as the Internet of Things(IoT)systems.However,IDS for IoT networks face critical challenges due to hardware constraints,including limited computational resources and storage capacity,which lead to high feature dimensionality,prediction uncertainty,and increased processing cost.These factors make many conventional detection approaches unsuitable for real-time IoT deployment.To address these challenges,this paper proposes an adaptive intrusion detection framework that intelligently balances detection accuracy and computational efficiency.The proposed framework integrates mutual information(MI)feature selection model,deep contextual embeddings,and an adaptive decision mechanism.The MI model identifies and retains the most informative features,which reduces dimensionality while maintaining high detection accuracy.The adaptive decision dynamically selects between multiple inference paths to ensure that additional computation is needed only when the uncertainty level is high.Experimental evaluations on benchmark IoT datasets namely RT-IoT-2022,CIC-IoT-2023 and CIC-IoMT-2024 show that the proposed framework achieves F1-score of 99.92%,96.66%,and 99.84%,respectively,with an average inference time of approximately 0.105 ms per sample.These results demonstrate that the framework effectively adapts inference complexity to data uncertainty,which provides an intelligent,interpretable and efficient solution for real-world IoT intrusion detection. 展开更多
关键词 Adaptive IDS cyberattack detection computational cost IoT security
暂未订购 下载PDF
A Knowledge-Distilled CharacterBERT-BiLSTM-ATT Framework for Lightweight DGA Detection in IoT Devices 认领 引用
16
作者 Chengqi Liu YongtaoLi +1 位作者 Weiping Zou Deyu Lin 《Computers, Materials & Continua》 SCIE EI 2026年第4期2049-2068,共20页
With the large-scale deployment of the Internet of Things(IoT)devices,their weak securitymechanisms make them prime targets for malware attacks.Attackers often use Domain Generation Algorithm(DGA)to generate random do... With the large-scale deployment of the Internet of Things(IoT)devices,their weak securitymechanisms make them prime targets for malware attacks.Attackers often use Domain Generation Algorithm(DGA)to generate random domain names,hiding the real IP of Command and Control(C&C)servers to build botnets.Due to the randomness and dynamics of DGA,traditional methods struggle to detect them accurately,increasing the difficulty of network defense.This paper proposes a lightweight DGA detection model based on knowledge distillation for resource-constrained IoT environments.Specifically,a teacher model combining CharacterBERT,a bidirectional long short-term memory(BiLSTM)network,and attention mechanism(ATT)is constructed:it extracts character-level semantic features viaCharacterBERT,captures sequence dependencieswith the BiLSTM,and integrates theATT for key feature weighting,formingmulti-granularity feature fusion.An improved knowledge distillation approach transfers the teacher model’s learned knowledge to the simplified DistilBERT student model.Experimental results show the teacher model achieves 98.68%detection accuracy.The student modelmaintains slightly improved accuracy while significantly compressing parameters to approximately 38.4%of the teacher model’s scale,greatly reducing computational overhead for IoT deployment. 展开更多
关键词 IoT security DGA detection knowledge distillation lightweight model edge computing
暂未订购 下载PDF
基于NTRU格上的高铁共生网络安全切换认证方案 认领 引用
17
作者 陈永 张冰旺 信召凤 《北京航空航天大学学报》 EI CAS CSCD 北大核心 2026年第4期1076-1087,共12页
针对高铁GSM-R无线通信系统向下一代5G-R网络演进过程中,共生网络垂直切换时存在身份泄露、不具备前后向安全性和认证开销大等问题,提出了一种基于NTRU格上的高铁共生网络安全切换认证方案。设计了基于NTRU格的双向认证机制,克服了身份... 针对高铁GSM-R无线通信系统向下一代5G-R网络演进过程中,共生网络垂直切换时存在身份泄露、不具备前后向安全性和认证开销大等问题,提出了一种基于NTRU格上的高铁共生网络安全切换认证方案。设计了基于NTRU格的双向认证机制,克服了身份信息SUPI明文传输易泄露的缺点;提出基于共享密钥的哈希链加密方法,设计共享密钥生成和共生网络切换令牌策略,实现切换认证密钥的预生成,确保了共享密钥的动态更新及前后向安全性;采用中国剩余定理及时间戳机制实现了会话密钥的机密性,完成了共生网络的切换认证。通过BAN逻辑形式化理论证明和TAMARIN协议仿真验证工具对所提方法进行安全性分析,结果表明:与同类方法相比,所提方法确保了身份的匿名性和密钥前后向安全性,可有效抵抗DoS攻击和中间人攻击等攻击,具有更低的切换开销,能够满足高铁共生网络安全无缝切换认证的需求。 展开更多
关键词 铁路无线通信 共生网络 切换认证 NTRU格加密 通信效率
暂未订购 下载PDF
基于污点流分析的物联网固件高可信度漏洞检测 认领 引用
18
作者 张光华 李国瑜 +2 位作者 王鹤 李珩 武少广 《信息网络安全》 CSCD 北大核心 2026年第2期325-337,共13页
随着物联网设备的普及,其内嵌固件的安全漏洞面临的挑战日益严峻。当前,主流的污点分析方案存在路径爆炸和误报率高的问题。为了克服现有方案的不足,文章提出基于污点流分析的物联网固件高可信度漏洞检测方案Laptaint。首先,融合了轻量... 随着物联网设备的普及,其内嵌固件的安全漏洞面临的挑战日益严峻。当前,主流的污点分析方案存在路径爆炸和误报率高的问题。为了克服现有方案的不足,文章提出基于污点流分析的物联网固件高可信度漏洞检测方案Laptaint。首先,融合了轻量化模型和模糊匹配进行相应的关键字匹配,通过精确识别输入源来减少因源点丢失而造成的假阴性问题;然后,构建了细粒度污点语义模型,利用定义可达性分析从危险函数调用点开始,迭代地向后追踪,到达污点源;最后,集成的消毒验证模块通过4种检查逻辑,对污点输入进行有效性验证。对30个真实设备固件进行测试,实验结果表明,Laptaint方案以82.02%的准确率来挖掘漏洞,性能优于同类方案。 展开更多
关键词 固件安全 漏洞检测 污点分析 消毒验证
暂未订购 下载PDF
天地一体化智能网络异常流量检测 认领 引用
19
作者 杨力 董晓冉 +1 位作者 戚耀文 潘成胜 《计算机应用与软件》 北大核心 2026年第1期112-120,192,共9页
天地一体化网络流量存在自相似性和重尾分布等特征,导致网络中的异常流量难以准确识别。针对这种情况,提出一种Entropy优化GA_LSTM的天地一体化智能网络异常流量混合检测方法。算法通过信息熵总结特定的流量特征分布来初步检测异常流量... 天地一体化网络流量存在自相似性和重尾分布等特征,导致网络中的异常流量难以准确识别。针对这种情况,提出一种Entropy优化GA_LSTM的天地一体化智能网络异常流量混合检测方法。算法通过信息熵总结特定的流量特征分布来初步检测异常流量,缩小异常流量的检测范围;利用遗传算法优化LSTM对熵检测后的网络流量进行二次判断,以提高网络异常流量检测的精确度。仿真结果表明,该混合检测算法相比于传统的信息熵和经典LSTM检测算法具有更好的收敛速度和准确性。 展开更多
关键词 天地一体化智能网络 信息熵 LSTM 遗传算法 异常流量检测
暂未订购 下载PDF
基于流量分析的物联网设备网络攻击探测 认领 引用
20
作者 陈荣君 黄笑笑 +2 位作者 王则扬 李小真 杨泽达 《电讯技术》 北大核心 2026年第7期1221-1227,共7页
针对物联网设备资源受限和部署环境复杂导致传统安全防护措施难以实施的问题,提出了一种基于流量分析的网络攻击探测方法。该方法通过实时监测和分析物联网设备的网络流量,识别异常流量模式,及时发现潜在攻击,保障设备安全运行。首先,... 针对物联网设备资源受限和部署环境复杂导致传统安全防护措施难以实施的问题,提出了一种基于流量分析的网络攻击探测方法。该方法通过实时监测和分析物联网设备的网络流量,识别异常流量模式,及时发现潜在攻击,保障设备安全运行。首先,通过分析物联网设备的网络流量特征,构建了一个流量特征提取模型。然后,采用机器学习算法对提取的流量特征进行分类,以实现对不同网络攻击类型的准确识别。在物联网数据集的试验结果表明,该方法可以有效检测多种网络攻击,实现97%以上的监测准确率。 展开更多
关键词 物联网 网络攻击检测 通信流量分析 机器学习
暂未订购 下载PDF
上一页 1 2 250 下一页 到第
在线咨询 使用帮助 返回顶部 意见反馈