Nowadays solving practical problems in various sectors using intelligent solutions, based on expert systems are becoming more and more widespread. In this paper an expert system method is proposed for assessment and prediction of destructive influences. All disadvantages of existing assessment systems are taken into account during the development and analysis phases. The most important estimated parameters are determined. This method is based on quantitative methods of expert evaluation, which gives the advantage: there is no need to collect large amounts of statistical data and clear formalization of the current situation.
The article discusses the solution to the problem of predicting the occurrence and dynamics of the development of information conflicts in cybernetic space. The frequency of occurrence of an analysis unit in the blogosphere was chosen as an indicator reflecting this process. The analysis of information threats is considered as a multifactorial process that reflects all spheres of society’s life. The superposition of multifactorial trends obtained by non-linear optimization convolution gives a model that can have bifurcation points. The developed technique is aimed at searching for bifurcation intervals for planning effective methods of counteracting negative information
Received Jan 14, 2019 Revised Apr 17, 2019 Accepted May 8, 2019 Nowadays solving practical problems in various sectors using intelligent solutions, based on expert systems are becoming more and more widespread. In this paper an expert system method is proposed for assessment and prediction of destructive influences. All disadvantages of existing assessment systems are taken into account during the development and analysis phases. The most important estimated parameters are determined. This method is based on quantitative methods of expert evaluation, which gives the advantage: there is no need to collect large amounts of statistical data and clear formalization of the current situation.
Today, the methods of incidents / potential crisis situations detecting and their criticality level assessing are proposed. However, these methods do not describe simultaneous occurrence of several crisis situations and determining of the average and total criticality level. In this paper the correlation issues of several events security incidents – are reviewed and the mechanism for calculating an average and total criticality level of incidents is proposed. A mechanism basis of events correlation, as well as crisis management methods itself, includes Delphi methods and fuzzy logic model. Proposed mechanism appliance will allow the simultaneous occurrence of several incidents to be taken into account and assess their average and total impact on the information system.
Software reliability is an actual problem caused with absence of software protection techniques, especially absence of software code protection from reverse engineering. Computer piracy and illegal software usage makes big damage for state economy. The development of new approaches and modification of existed obfuscation technologies is actual task directed to growing efficiency of secure coding and protection against reverse engineering. In this paper, authors present the obfuscation method for software protection, which ensures protection from reverse engineering. The method is based on a new sequence of obfuscation transformations. Also software tool StiK was developed, and based on the submitted sequence of operations, pseudocode for protection method was created. Experimental study was conducted according to the presented technique. Experimental results show the efficiency and generality of the proposed method (StiK obfuscator is 10% faster as well as 1.37 times more protected than analogues). Consequently, the developed technique can be used to prevent or at least hamper interpretation, decoding, analysis, or reverse engineering of software.
The development of information technologies, communication systems and information processing systems provide optimization of management processes for enterprises, institutions and organizations. However, with this increased dependence of organization effective functioning from the level of providing information services. The emergence of various types of information security incidents can seriously affect the business processes of any enterprise, and when the level of their influence on the information system reach certain critical value, possibility of crisis situation occurrence arises. Methods of identifying incidents/potential crisis situations and assessing their criticality are already proposed. However, these methods do not describe the procedures for coordinating the emergence of several crisis situations at the same time and determination of the average and total level of criticality. In this work, the issues of several events (crisis situations) correlation are considered and proposed mechanism for calculating the average and total level of criticality for incidents. This events correlation mechanism is based on methods of expert evaluation and fuzzy logic models. The application of the proposed mechanism will make it possible to take into account the simultaneous occurrence of several incidents and assess the average and total impact that they have on information system.
Ensuring the sustainable development of mankind and its safety aspects is closely related to the necessity of incidents/potential crisis situations governance. Particularly, the most significant aspect is timely identification, identification and evaluation different incident. Thus, the emergence of different information security incidents can seriously affect the business processes in enterprise, and, when a certain critical level of their influence on the information system is reached, a crisis situation is emergence. A special area of strategic management, which regulates the crisis management processes-their identification, identification, assessment, neutralization, prevention and liquidation of consequences – business continuity management dates back to the 80s of the last century. However, until recently, systems, the main functions of which were information technologies support in crisis conditions, neutralization or elimination of consequences, documentation support for the formation and implementation of business continuity plans had dominated in this sphere. And only now, attention on the procedure for early detection of crisis situations or an assessment of its destructive influence is focused. The modern crisis management systems mostly use mathematical models which based on probability theory, indicative and comparator models, and have a number of significant weaknesses. In the paper offers the software complex that implements the developed computer complex for the detection and evaluation of crisis situations in the information field, its work is based on the use of fuzzy weakly formalized models and methods using of expert approaches. Such complex allows to level out the main weakness of known similar solutions, including dependence on statistical data, speed of their processing, incompleteness and unclear initial data. In this paper describes the software implementation of the computer complex for detection and evaluation of crisis situations in the information field, its interface and functional, describes the operation modes and application features both in real time mode and for modeling various types of crisis situations.
The application of web technologies and forms of electronic document circulation in the process of information exchange between users though simplifies this process, however, generates a number of new threats to the confidentiality, integrity and availability of information and the appearance of previously unknown vulnerabilities. One of the most common methods of protection is the use of digital certificates that ensure the confidential exchange of data between a client and a server by encrypting and authenticating a digital certificate. A digital certificate is a public key, certified by the EDS of the certification center. However, a digital certificate is not just a public key with information, but a so-called signature of a server or web resource that is implemented using the hex functions. However, with the development of information technology and the emergence of new types of attacks, leads to an increase in the number of disadvantages of existing gash functions. Thus, in the paper a new heaching function was proposed, which was developed on the basis of the SHA-2 hex function. Improvements involved the introduction of a number of changes: increased the size of words and an increase in the message digest; At the pre-processing stage, the incoming message is supplemented by a pseudo-random sequence; the number of nonlinear functions is increased. The proposed changes allow to reduce the number of rounds in the compression function, which will guarantee at least similar stability indicators with simultaneous increase in data processing speed.
The development of information technologies, communication systems and information processing systems provide optimization of management processes for enterprises, institutions and organizations. However, with this increased dependence of organization effective functioning from the level of providing information services. The emergence of various types of information security incidents can seriously affect the business processes of any enterprise, and when the level of their influence on the information system reach certain critical value, possibility of crisis situation occurrence arises. Methods of identifying incidents/potential crisis situations and assessing their criticality are already proposed. However, these methods do not describe the procedures for coordinating the emergence of several crisis situations at the same time and determination of the average and total level of criticality. In this work, the issues of several events (crisis situations) correlation are considered and proposed mechanism for calculating the average and total level of criticality for incidents. This events correlation mechanism is based on methods of expert evaluation and fuzzy logic models. The application of the proposed mechanism will make it possible to take into account the simultaneous occurrence of several incidents and assess the average and total impact that they have on information system.
In today's complex security systems, a huge role is played by video monitoring systems. CCTV systems are the most informative for the user and they provide an opportunity for security personnel to make quick decisions, depending on the situation at the protected facility. The paper presents possible methods for describing color objects on complex scenes in a video surveillance system when lighting conditions change when images are acquired. The resulted results and practical conclusions are received after the analysis of a large number of different images in several color models, with most of the attention given to the HLS model. A criterion for estimating the difference in colors was developed and methods of histogram image processing were examined with the aim of improving their quality. Methods for selecting objects with their color designation may differ from traditional ones.
Cyber incidents can disrupt regular mode of information and telecommunication systems functioning and to cause the substantial material and image losses for the company. One of the approaches in incident management is the use of the theory of network-centric management for cyber incidents monitoring, but is not formalized stage of forming basic rules set. In this regard, in this work developed the method for rules set forming of cyber incidents extrapolation in network-centric monitoring, which allows to automate and increase accuracy operation of network-centric systems for information and telecommunication systems monitoring by determining possible types of cyber attacks and cyber incidents categories, forming vector-matrix of cyber incidents probability, cyber incidents ranging by their importance and determining limit values of probability, forming cyber incidents possibility indicators, and also development and establishment of cyber incidents extrapolation rules.
The concept of business continuity management as a promising area of operational and strategic management determines the importance of protecting information resources in conditions of crisis. Thus, the main element of this concept is the concept of "crisis", but that is not clearly defined and varies depending on the field of science and technology. This article analyzed the known definitions of the term "crisis", in particular in the fields of economics, politics, medicine, psychiatry, management and other areas, which formed the basis for the definition within the concept of business continuity management. As well as the basic approach to periodization process of crisis management, approaches to the classification of crisis situations covered in the standards, practices and regulations of business continuity management and leading researchers in this field. In addition, a valid assignment of crisis management to a class in the structure of the management system of information security and defined their functional relationships with other protective systems, such as detection systems and intrusion prevention systems, analysis and risk assessment system antivirus protection, management information security incidents.
The concept of business continuity management as a promising area of operational and strategic management determines the importance of protecting information resources in conditions of crisis. Thus, the main element of this concept is the concept of "crisis", but that is not clearly defined and varies depending on the field of science and technology. This article analyzed the known definitions of the term "crisis", in particular in the fields of economics, politics, medicine, psychiatry, management and other areas, which formed the basis for the definition within the concept of business continuity management. As well as the basic approach to periodization process of crisis management, approaches to the classification of crisis situations covered in the standards, practices and regulations of business continuity management and leading researchers in this field. In addition, a valid assignment of crisis management to a class in the structure of the management system of information security and defined their functional relationships with other protective systems, such as detection systems and intrusion prevention systems, analysis and risk assessment system antivirus protection, management information security incidents.
Today to ensure the effective information resources security it is needed not only to identify the crisis satiation, but also to identify and evaluate the level of information security threats, which were caused by it. Most of the known detection and prediction evaluation systems for crisis situations are based on the signature or comparator principles. Thus they can not be used in the fuzzy weakly-formalized environment. This creates obstacles for their functioning in real information systems. This problem is solved by using fuzzy logic application and expert approach. In this paper represented the basic architecture of a new structural solution: computer complex which consist of incidents / potential crises detection and situation criticality evaluation system. Complex architecture is represented as structural modules and blocks, which is associated by logically functional connections. Each system can be used separately and independently or together for the crisis situation management tasks in the information scope.
This paper reviewed studies on the information warfare theory and information-psychological influence from a practical point of view. This subject is widespread among scientists in the whole world. Models and implementation concepts of the information-psychological influences, security from it, models of detection psychological and information attacks, lifecycles of information warfare were analyzed. During this research were examined the scientific works of South African scientists B. Van Niekerk and M. Maharaj, in which studied the lifecycle of information and psychological warfare, Finns Yormakka I. and J. Mols, in which studied the information warfare from the perspective of game theory, Australians B. Hutchison M. Warren in which identified and described the tactics of information warfare, American S. Johnson with his information attack model, and US Council Scientific Research of monitoring and information-psychological influence detection project CEPA. Also studied works of Ukrainian scientists: A. Shiyan, who presented method of detection information-psychological influences and confrontation methods and R. Grischuk, who considered the technological aspects of information influences. Above-mentioned researchers have made a significant contribution in practical research of information-psychological influences. In this study developed a formalized informational-psychological influence model, define basic characteristics and design the method, and based on it the detection system and the identification information-psychological influences.
Concept of business continuity management is the prospective direction of operative and strategy management and it defines the importance of information resources security when crisis influences. Crisis management consists of its forecasting, identification, responding and emergency procedures, crisis assessment and also processes of decision support and personnel activity or systems operation. In this paper the analysis of modern crisis management systems and basic methods was carried out. The main aim of this analysis is defining of science and technique prospective directions and also disadvantages identification in existed systems. This study covers both domestic and foreign developments. The main attention is paid to crisis forecasting systems, decision support and personnel activity systems in uncertainty and weak formalized space. This study results can be used to choose future researches directions for crisis detection and assessment systems and it confirms the feasibility and validity for expert approaches and fuzzy logic methods using.
Crisis influence on the security level of state informationresources, different organizations and whole state is veryserious. Crisis can stop system development that comesunder its influence and also it can crush the system in thebud. To prevent this influence the adequate (to threatslevel) measures and security means must be taken and itdefines the importance of current situation criticality assessment.There is no generally accepted universal criteriaand integrated parameter for criticality level assessment ofcrisis. That’s why defining of criticality level assessmentfor incident is actual and important scientific task. In thepaper the set of parameters for criticality level assessmentof crisis was introduced and also method for defining thecriticality level of crisis with expert approach and fuzzysets theory was proposed. These don’t require the statisticaldata gathering and processing. Besides the defazificationprocedure for parameters was described and on itsbase indicator of criticality level was built.