One of the most pressing tasks in ensuring data protection in information systems is the classification and ranking of threat sources. All threat sources have varying degrees of danger to information system assets. Ranking allows you to prioritize when designing an information security system and allocate greater resources to prevent the most pressing and significant threats. This article discusses an algorithm for ranking threats based on the hierarchy analysis method.
Keywords: data protection, information technology, hierarchy process analysis, systems analysis, information systems, information security
This paper is devoted to the quantitative assessment of the information security system. The authors propose to build a system that combines components with the properties of dynamism and protection efficiency. The proposed information security system includes two types of antivirus components, three data leakage prevention systems, and four intrusion detection and prevention systems. For clarity, the article provides a theoretical and graphical interpretation of the information security system. Each possible path in the system represents its state. It is shown that adding new components or subsystems leads to an increase in all possible states of the system, complicating the analysis by an intruder. Within the framework of this multi-component approach, each element of the system interacts with others, which helps to achieve the optimal level of efficiency in ensuring information security. In addition, the proposed approach is characterized by scalability, which ensures seamless integration of both individual components and subsystems as a whole.
Keywords: recomposition, information security system, DLP system, IPS/IDS system
The article analyzes the current threats and vulnerabilities of web applications. Based on the analysis, approaches to protection and recommendations for ensuring the security of web applications are proposed, taking into account current challenges and problems. The article may be useful for information security specialists, software developers and heads of organizations interested in the security of web applications being developed or used.
Keywords: cyber threat, cyber attack, exploitation of web vulnerabilities, web application
The article analyzes the features of the protection of modern cloud systems and the distribution of responsibility between the interacting parties, and offers recommendations for improving the security of cloud resources. Based on the analysis, comprehensive protection measures and recommendations for improving the security of cloud resources are proposed, which can be useful to information security specialists and IT specialists to understand the features of protecting cloud systems, as well as in choosing a cloud provider and preparing for the transition to the cloud.
Keywords: cloud computing, cloud provider, shared responsibility model, cloud resource security
In the article, the authors propose an approach that allows assessing the relevance of using indicators of compromise for a particular industry. The current problems associated with the redundancy of indicators of compromise and the low level of trust in their sources are highlighted. An approach is proposed that allows quantifying the relationship between indicators and the source, as well as scoring sources.
Keywords: compromise indicator, feed of the compromise indicator, rating of feeds
This article considers the issues of guaranteed deletion of information on solid-state drives. A review of the requirements of the domestic regulatory framework in terms of formulating the requirements for guaranteed deletion of information is carried out. The analysis of domestic and foreign standards and methods of guaranteed deletion of information are carried out. The features of solid-state drives and the applicability of domestic and foreign standards of sanitizing data for such drives are also considered. The problem of guaranteed deletion of individual files on solid-state drives without the possibility of recovery is indicated. Key problems that arise during guaranteed deletion of individual files on a solid-state drive without taking it out of service are highlighted. Conclusions about the impossibility of effective implementation of guaranteed deletion of individual files on solid-state drives in the process of using the drive, without taking it out of service, are made.
Keywords: data recovery, solid state drive, wear leveling, garbage collection, guaranteed data destruction
Protecting the endpoints of an information system from cyber attacks determines the search and development of methods for detecting such attacks using artificial intelligence. The dynamics of the increase in the number of information threats of various types leads to the need to use machine learning methods to classify the functioning of automated control systems, including computing processes in automated control systems. The purpose of the study is to classify the computational processes of the created database for detecting illegitimate processes, taking into account minimizing the number of process parameters to achieve acceptable detection quality. Methods: as a mathematical tool, it is proposed to use a model trained on the created dataset and a correlation matrix based on Pearson coefficients to determine a group of parameters of computational processes. Results: an analysis of the data set based on Pearson correlation coefficients was carried out, which allows minimizing the number of parameters of the input data of the model. It is proposed to use the random forest method for the functioning of the model in solving the binary classification problem of detecting illegitimate computing processes in the automated control system. The effectiveness of the proposed model is evaluated by classification metrics: Precision, Recall, The developed model was tested at fixed volumes, training and testing samples. The work of the model was evaluated using the ROC curve and the PR curve.
Keywords: machine learning, binary classification, computational processes, database, data processing, model testing
In this paper, we present the implementation of a neural network approach to solving the problem of handwritten signature recognition. We analyzed the main approaches to handwritten signature recognition. We identified the features of using a handwritten signature as an identification method, including the variability of a handwritten signature and the possibility of forgery. We identified the relevance of using neural networks to solve the signature recognition problem. We developed a neural network model for recognizing handwritten signatures, presented its architecture containing convolutional and fully connected layers, and trained the neural network model based on handwritten signatures "Handwritten Signatures" containing 2263 signature samples. The accuracy of the developed model was 92% on the test sample. We developed a web application "Recognition of a static handwritten signature" based on the developed neural network model on the Amvera cloud hosting. The web application allows identifying users based on a handwritten signature sample.
Keywords: handwritten signature, neural networks, signature recognition, image processing, machine learning, web application, cloud hosting, identification, verification, artificial intelligence
The problem of personality recognition by voice using adaptive Kalman filter is considered. The extracted features of the acoustic signal are used as features of biometric authentication person. A comparative table of speaker separation errors and evaluation speaker separation system using Kalman filter is presented.
Keywords: biometric authentication, voice, neural network compilation, adaptive Kalman filter
Security vulnerabilities are always a burning issue that website administrators spend a lot of time on researching in order to keep the website running securely. These vulnerabilities allow hackers to exploit, attack, infiltrate and influence the data of any company's websites. For stable, smooth and secure website operation, it is necessary to know the basic information about website security vulnerabilities. This article analyses the methods of detecting website vulnerabilities and applying effective measures to ensure website security. The article provides current challenges in the field of information security, describes methods of vulnerability detection and gives recommendations for the application of specific measures to secure websites.
Keywords: website security, vulnerability, information security, code, software, security vulnerability scanning
The general characteristics of the innovative RAID-60 data storage system, which combines the best aspects of RAID-6 and RAID-0E technologies, as well as the reliability model of this data storage sys-tem, are presented. The main purpose of this connection is to provide outstanding performance with maximum data redundancy. The arti-cle discusses in detail the structural analysis, advantages and various scenarios for the use of the specified RAID-60 data storage system and the proposed model of its reliability. An important aspect is also the comparison of the RAID-60 system with other widespread vari-ants of data storage systems, such as RAID-0, RAID-1 and RAID-5, as well as with the reliability models of these systems. Particular at-tention is paid to the formula that allows you to calculate the average operating time to failure of a disk array. Also, for completeness of the analysis, attention is paid to plotting the probability of a RAID-60 failure (P(t)) over time (t). This graph is an important tool for visu-alizing the dynamics of reliability of data storage systems.
Keywords: RAID-60, reliability, disk array, data redundancy, manufacturer, parity blocks, data storage
The paper methodologically shows the identity of the mathematical problem of graph path searching with the technical problem of searching for various defects in software, in particular, bugs and undocumented features. The graph model of software functioning, which became the basis for the presented methodology, is briefly described. New research directions based on graph theory problems, which have not been previously used to search for defects in software, are stated.
Keywords: graph model, software, graph pathfinding, breadth-first search, meet-in-the-middle method, malicious software
The result of the research is a method of complex biometric authentication. The method is implemented in the form of a software complex consisting of a subsystem biometric authentication by face image and a subsystem biometric authentication by voice. The training sample consisting of stored files biometric images (facial images and audio recordings) allows to reduce the error rates of the first and second kind in user recognition. The proposed method of biometric authentication is designed to improve the efficiency user recognition processes.
Keywords: authentication, biometrics, neural network architecture, training sampling
The application of orthogonal matrices in information processing and transformation systems is considered. A method is proposed for assessing the results of protective masking of audio information using Walsh-structured quasi-orthogonal Mersenne matrices.
Keywords: orthogonal matrix, message masking, masking/unmasking algorithm, amplitude-frequency response, white noise, root mean square error, signal-to-noise ratio
The problem of vulnerabilities in the Robot Operating System (ROS) operating system when implementing a multi-agent system based on the Turtlebot3 robot is considered. ROS provides powerful tools for communication and data exchange between various components of the system. However, when exchanging data between Turtlebot3 robots, vulnerabilities may arise that can be used by attackers for unauthorized access or attacks on the system. One of the possible vulnerabilities is the interception and substitution of data between robots. An attacker can intercept the data, change it and resend it, which can lead to unpredictable consequences. Another possible vulnerability is unauthorized access to the commands and control of Turtlebot3 robots, which can lead to loss of control over the system. To solve these vulnerabilities, methods of protection against possible security threats arising during the operation of these systems have been developed and presented.
Keywords: Robotic operating system (ROS), multi-agent system, system packages, encryption, SSL, TLS, authentication and authorization system, communication channel, access restriction, threat analysis, Turtlebot3
The paper discusses a stegoalgorithm with localization of the embedding area in the YCbCr color space to protect images of a license plate, a vehicle from different angles, a traffic event, as well as issues of developing a software system that implements the stegoalgorithm. Image protection allows you to effectively implement the concept of multimodal interaction of socio-cyberphysical systems in an automotive self-organizing network. Evaluations of the effectiveness of the developed method are provided.
Keywords: VANET, intelligent transport networks, city traffic management system, steganography, information security, watermark
The problem of developing the architecture of a dynamic information security management system for an enterprise information system, based on the hierarchical organization of the management system, analysis of the state of the computer system in the information space, analysis of the spread of risk flow, as well as multi-agent organization of the processes of collecting, analyzing data and making decisions is considered.
Keywords: information protection, enterprise information system, security policy, information security management, risk analysis, zero trust architecture, multi-agent technologies, neural network forecasting
The article discusses issues related to the level of existing technological development and the role of information impacts in the modern world. The necessity of an interdisciplinary approach in training an information security specialist is substantiated. A number of examples are considered on the historical material, indicating the causal relationship between actions in the information space and the events of the material nature, the scale of the consequences has been noted. The process of forming a value system and the potential possibility of changing it are considered. The influence of the level of development of information delivery means on the effectiveness of information impact is noted. An example of using media content to transmit non-verbal signals is given. Using the example of cinematographic products, the principles of deformation of the system of traditional values through the introduction of a new term and a change in attitude towards it are considered. The need for additional measures to counter information threats is substantiated. Ways to reduce the risk of negative consequences from harmful information influences are proposed.
Keywords: information space, information security, information threat, information delivery tools, information impact, counteraction of the threat
The possibility of detecting false positive cybersecurity incidents using deep learning models - GRU, Bidirectional LSTM (Bi-LSTM), LSTM - has been studied. The results obtained demonstrate the effectiveness of solving the problem for Powershell scripts. The Bi-LSTM model showed the best classification results, demonstrating an accuracy of 98.50% on the test sample.
Keywords: machine learning, classification, cybersecurity, deep learning, Powershell
The subject of the study is the technical and economic characteristics of attack detection tools that affect the effectiveness of their use for the system for detecting, preventing and eliminating the consequences of computer attacks on critical information infrastructure facilities of the Russian Federation. An analysis of approaches to selecting the best solutions is presented, the result of which formed the basis of the proposed solution. The article contains a study of approaches to solving the problem of feasibility study of choice, formalizing the formulation of the problem and a mathematical model for solving the problem of choosing the optimal attack detection tool for implementing the corresponding tasks. The research methods used include systems analysis, modeling and peer review methods. The purpose of developing the methodology is to increase the level of validity of decision-making on choosing the best of the proposed attack detection tools. The research results presented in the article can be used to carry out a feasibility study of decisions made when choosing attack detection tools for the needs of monitoring centers of the Russian Federation. The proposed methodology for conducting competitive analysis can be used as the basis for conducting appropriate research for each means of the system for detecting, preventing and eliminating the consequences of computer attacks on the information resources of the Russian Federation.
Keywords: attack detection tools, intrusion detection tools, feasibility study, competitive analysis, information security tools, decision support system, information security system, optimization, integer linear programming
The features of designing security systems based on the zero trust model are considered. The problem of developing security policy patterns is considered. The problem of choosing the points of application of the security policy based on the analysis of the risk flow is discussed. An example of a security pattern in the DRAKON language is given.
Keywords: information security, zero trust architecture, enterprise architecture, security policy patterns
This paper considers the conditions and factors affecting the security of information systems functioning under network reconnaissance conditions. The developed model is based on the techniques that realize the dynamic change of domain names, network addresses and ports to the network devices of the information system and false network information objects functioning as part of them. The formalization of the research problem was carried out. The theoretical basis of the developed model is the theories of probability and random processes. The modeled target system is represented as a semi-Markov process identified by an oriented graph. The results of calculation of probabilistic-temporal characteristics of the target system depending on the actions of network reconnaissance are presented, which allow to determine the mode of adjustment of the developed protection measures and to evaluate the security of the target system under different conditions of its functioning.
Keywords: departmental information system, network intelligence, structural and functional characterization, false network information object
The possibility of detection of steganography in digital images based on the classification of stegocontainers is investigated. The obtained results demonstrate the effectiveness of using deep neural networks for solving this problem. The LSB method can be detected using EfficientNet b3 architecture. The achieved classification accuracy is above 97%. Using of steganography methods in frequency domain can be effectively detected by classifying their representation in the form of a digital YCrBr model, with augmentation (vertical and horizontal rotations). The classification accuracy is above 77%.
Keywords: Steganography, stegocontainer, machine learning, classification, digital image, deep learning, CNN, EfficientNet b3, confidentiality, information protection
This article describes development of a module which provides opportunity to extract text from images of modified text, which can be used to bypass existing information security software and spread sensitive information out of company. The developed module is based on Python programming language with additional libraries expanding basic functional. After creating a module, additional module allowing user to create modified text by themselves was made. Additional module uses a special dictionary that can change any letter to alternative and generate more modified texts in order to test and find the weak spots of a module. To integrate the module into company’s information infrastructure DLP-systems were chosen, because of their popularity and ease of the integration method. To integrate DLP-system and text extraction module we used a mail-server with BCC copies of a mail traffic to send text and images to our module local mail server, additional mechanisms extracts pictures and process them within the module, after what it sends back the image and the text from it. A few rounds of testing were done resulting in nearly 97% accuracy. Future development consider expanding for multi-row processing and adding new alternative symbols after first mention them in text by using a CNN or standard deviation of images pixel and pixel comparison.
Keywords: information security, data leakage, text analisys, image analisys, modified data analisys, protection against steganography
To optimize the life cycle of information systems, the design uses abstract models that describe the main elements of the system architecture. Zero trust architecture is a new concept of information security that takes into account the remote format of employee access to the assets of an enterprise information system. The main features of zero trust architecture are considered.
Keywords: information security, enterprise information system, zero trust architecture, security policy