The manipulative influence issue it is not a new topic for discussion but, only with the advent of the mass media concept it became popular and requires the intervention not only of scientists but also of the international community. The study mass media phenomena are equipping a mankind with a broader and deeper understanding of society and culture due to the fact that the texts produced by the mass media are the most socially significant messages and have a priority in the society over all other types of texts. Moreover, in in recent years, the concepts of mass consciousness influence and mass behavior influence had become increasingly popular. Frequently, mass media is the subject or instrument of such manipulation. The manipulation process (as the influencing process on a person or a social group) is the more effective (by the power of impact), when the deeper level of consciousness the manipulator employs. Additionally, the deeper the level of manipulation when the slower the «processing» of consciousness, but the stronger the transformation in all other levels, and the result of exposure is more prolonged. Currently, the mass media manipulative influence problem is being solved at the highest level: specialized regulation (EU GDPR) and laws are being developed and implemented. Since the advent the fact of the mass media manipulative influence on public opinion of individuals, scientists have thoroughly studied the notion of the mass media manipulative influence and the methods by which such influence can be effected. However, the process of quantitative evaluation of mass media manipulative influence remains insufficiently researched. It is known that the manipulation process with many factors that often depend on each other is laborious enough, the process of quantitative evaluation of mass media manipulative influence becomes even harder. In the article was developed the quantitative evaluation method of mass media manipulative influence on public opinion .The method by means of evaluating financial expenditures, defining goals, objectives and strategies for manipulating, selecting mass media and classified methods of manipulation, based on the generated databases of causes, goals of the criteria, focus groups and mass media, allows to calculate the quantitative parameters that characterize the magnitude of manipulative mass media influences on public opinion.
In the last few years, development of quantum cryptography has attracted the scientist’s attention. Researches passed from the theoretical level to introduction of ready commercial decisions. The main difference between the methods of quantum cryptography and traditional (symmetric and asymmetric) cryptography consists in use of absolutely different principles in the basis. The quantum cryptography does not depend on computing or other intruder opportunities, uses specific unique quantum particles properties and based on inviolability of quantum physics laws. Among the most developed technologies of quantum cryptography is worth noting quantum secure direct communication, which can transmit information by open channel without encryption - removing key distribution problem, but in these protocols each bit of information is confidential and intruder shouldn’t get it, that's why requirements for protocols stability is much higher and require security amplification methods. Such method was previously developed by authors, but its implementation requires the use of reliable trit pseudorandom sequences. In this context, this study presents an experimental research of trit pseudorandom sequence generating method for cryptographic applications. For evaluating the effectiveness of this method was developed experimental methodology, which confirms the possibility of using trit sequences generated by the method for ensuring the stability of quantum cryptography qutrit protocols to non-coherent attacks and for other crypto-graphic applications in modern information and communication technologies.
Lately, the leading countries of the world paid more attention to their critical infrastructure cyberdefence. Civil aviation is not an exception. In this area, modern information and communication technologies are widely implemented, so it generates a whole range of new vulnerabilities and potential threats. Known models allow formalizing processes of creating a complete set of requirements (according to relevant guidance documents) that should be done to ensure civil aviation cybersecurity and identifying their execution. However, the issue of fullness assessment of requirements fulfillment remains unresolved. In view of this, in this work a method of estimation is developed, which gives ability to determine the quantitative parameters, that characterized fulfillment of complete set of requirements for civil aviation cybersecurity and differentiated requirements of control authorities in accordance to defined cybersecurity model. This method can be used for fullness evaluation of requirements fulfillment for providing cybersecurity and in other sectors of the critical infrastructure of the state. Later, based on this method, it is planned to develop a software application to support decision-making on expert evaluation of fullness requirements fulfillment for civil aviation cybersecurity.
Critical infrastructure protection is one of the priorities for states. Particularly acute issue appears to states implementing new information and communication technologies in all critical areas. These technologies, among other things, generate a number of new vulnerabilities and potential cyberthreats. In the civil aviation criticality level substantially reinforced by communication and interaction between ground and aircraft systems. Well-known model of cybersecurity requirements in civil aviation allows to formalize the process of complete set of requirements creating that are necessary to ensure civil aviation security against cyberthreats. But there is no mechanism for determining the availability of certain modes of security because of the methods and tools declared in the request. With this in mind, is to develop relevant approach to defining security regimes that takes account of additional security features. In this paper a multilevel model database was proposed, which through the use of a basic model of requirements to ensure cybersecurity of civil aviation concatenation of binary sequences that characterize the security mode and binary-hexadecimal coded representation of performance security set security models and subsets of performance security (with the additional features), allows to formalize the process of security requirements identification and determine the mode of critical aviation information systems security. In further research the development of method for evaluating the completeness of compliance is planned as a result of appropriate security methods and means implementation.
In recent times all over the world the number of different emergency situations was increased. Every day mass media informs about natural and man-caused disasters, weapon conflicts, acts of terrorism, global crimes, acts of piracy that were committed by both crime organizations and single offenders. Increasingly frequently as a result of these events many people falls a victim and also state critical importance systems and resources can be damaged. By this means most of world leader states have attended to methods and means of identifying, systematization and security assurance for critical infrastructure objects. Loss or operational breakdown of these objects can cause significant or irreparably damage for national security of the state. However, as shown by the analysis of the domestic normative base, today in Ukraine an exhaustive list of objects of the critical information infrastructure of the state is not yet formed and there is no clear mechanism for the formation of this list. Given the above, the paper proposes a universal data model for the formation of critical information infrastructure of the state objects list and, on the basis of the developed model, a list of critical objects in the field of civil aviation is formed. In further works is planned to develop efficient methods and tools for identifying and ranking objects, the list of which is formed using the proposed model of data.
In recent times all over the world the number of different emergency situations was increased. Every day mass media informs about natural and man-caused disasters, weapon conflicts, acts of terrorism, global crimes, acts of piracy that were committed by both crime organizations and single offenders. Increasingly frequently as a result of these events many people falls a victim and also state critical importance systems and resources can be damaged. By this means most of world leader states have attended to methods and means of identifying, systematization and security assurance for critical infrastructure objects. Loss or operational breakdown of these objects can cause significant or irreparably damage for national security of the state. For adequacy security methods implementation it`s very important to determine the importance (criticality) level of state information infrastructure objects in some sector. In view of this the method of determination the level of the critical information infrastructure importance in the civil aviation was proposed and it gives a possibility to assess the importance level and rank critical aviation information systems both by both quantitative and qualitative parameters. Follow-up study contains proposed experimental technique and with help of this method adequacy was checked. It confirms ability to determine the importance level of different critical aviation information systems: information systems of air navigation service, aircraft board information systems, information systems of air companies and airports.
The process of rapid development of information and communication technologies caused considerable and sometimes revolutionary changes in all life spheres of most countries. It significantly increased the vulnerability of different networks, systems and facilities and was much complicated the ensuring of their reliable protection and security. All these factors led the fact that leading countries began to devote great attention to the protection of the most important means for the security of its citizens, society and the state; objects, systems and resources, and processes of critical objects identification, calculation of their criticality level and the assessment of the effects of possible interruptions. In this paper the formalize method of determination the level of the state critical infrastructure importance in the field of civil aviation is proposed that by introducing a basic set of system and sets of subsystems, components, functions, continuity disturbances (interruptions, functional loss), their characteristics and effects, and constructing a three-dimensional matrix of criticality and calculation of the additional weight criticality factors, makes it possible to assess (determine) the importance level and rank critical aviation information systems both by both quantitative and qualitative parameters. In further research study based on this method special software will allow for experimental research and confirm the possibility of determining the importance level of different categories of critical aviation information systems.
Providing of confidentiality of data is the important stage in the process of providing of cyber security of the critical aviation informative systems and aviation industry on the whole. Known methods do not allow to fully provide cyberattacks resistance to linear and differential cryptanalysis and the required speed of cryptographic data processing. Taking into account it, the cryptographic method of defence of the critical aviation information systems is in-process worked out. On the basis of this method, a block symmetric cipher Luna-2k17 was developed and its specification is given in the work. Also, the values of the upper estimates of parameters that characterize its practical stability to cyber attacks of linear and differential cryptanalysis are calculated. At equal terms, experimental studies are undertaken from the estimation of speed characteristics of ciphers, that showed that cipher Luna-2k17 more faster than a cipher GOST 28147-89 approximately in 3,11 times, than ciphers Kalina and AES in 1,271 times.
Providing of confidentiality of data is the important stage in the process of providing of cyber security of the critical aviation informative systems and aviation industry on the whole. Known methods do not allow to fully provide cyberattacks resistance to linear and differential cryptanalysis and the required speed of cryptographic data processing. Taking into account it, the cryptographic method of defence of the critical aviation information systems is in-process worked out. On the basis of this method, a block symmetric cipher Luna-2k17 was developed and its specification is given in the work. Also, the values of the upper estimates of parameters that characterize its practical stability to cyber attacks of linear and differential cryptanalysis are calculated. At equal terms, experimental studies are undertaken from the estimation of speed characteristics of ciphers, that showed that cipher Luna-2k17 more faster than a cipher GOST 28147-89 approximately in 3,11 times, than ciphers Kalina and AES in 1,271 times.
The problem of cyberterrorism is global and quite acute in today's information society. Leading world states are increasingly focused on critical infrastructures. In civil aviation criticality level is amplified by communication and interaction between ground systems and aircrafts. Modern information and communication technology implementation in one hand increases civil avia-tion operation efficiency and in the other hand generates a set of new vulnerabilities and potential threats. Existed solutions don’t take into account modern requirements from regulatory aviation security documents in full and civil aviation specific. Accordingly, basic model for cybersecurity requirements definition based on regulatory international aviation security documents were proposed. Besides, domestic requirements for civil aviation cybersecurity were formalized and it allows to provide state aviation cybersecurity system of Ukraine. Further papers will relate to effective methods and means development for providing requirements formed in this paper.
The problem of cyberterrorism is global and quite acute in today's information society. Leading world states are increasingly focused on critical information resources protection in different spheres. In civil aviation criticality level is amplified by communication and interaction between ground systems and aircrafts. Modern information and communication technology implementation in one hand increases civil aviation operation efficiency and in the other hand generates a set of new vulnerabilities and potential threats. Besides no one aviation security control document doesn’t include full list of critical aviation information systems, its functional features and criticality level. These make difficult the analysis of such systems, creation threat and intruder models, risk analysis and assessment and also not allow to formalize security methods against different cyberthreats. In the paper search and systematization of modern aviation information systems (information systems of aero navigation service, aircraft board information systems, information systems of air companies and airports) was carried out. Also critical aviation information systems analysis was fulfilled and basic features for its classification were defined. Given results should be used for further creation the extended classification and criticality level determining for critical aviation information systems.
The problem of cybersecurity is quite acuted in all states of the world in different levels of social life. Using of informational resources is necessary for normal functioning of various sectors of the economy. It is important to secure information that circulates in such systems, at the appropriate level. The research of level of cybersecurity in Ukraine and examples of its importance are presented in this paper. The analysis of cyber security strategies of the various states of Europe, America, Africa, Asia and Oceania, investigated the term «cybersecurity» from the context of these documents were done. The problems of modern national legislation regulating the activities in the sphere of cybersecurity were highlighted. Also the causes of the first cyber security strategy was studied, and also modern trends in the cyberspace security were analyzed. According to the results, practical recommendations for creating the national cyber security strategy of Ukraine were proposed.
Information and communication technologies implementation in many spheres of social live is directed on business processes efficiency improving. However vulnerabilities and cyberthreats generate cyberincidents. New effective methods of detection, identifying, processing and investigation are necessary for localization and counteraction. One of approaches is network-centric concept oriented on counteraction to cyberincidents beginning and emergency recovery by network combining unique system of measures. Based on this concept in the paper method for cyberincidents network-centric monitoring that realizes using 8 stages: cyberattack classification; cyberattack type detection; cyberincident categorization; forming of rules plurality for cyberincident extrapolation; security objects defining; cyberincident influence defining on information and communication systems components; most criticality components defining in information and communication systems; cyberincident danger level rating. This method allows to define most important security objects and also forecast cyberincidents categories resulted from cyberat-tacks and danger level (criticality). Besides this method and instrumentations based on it can be useful for cyberincidents response teams CERT / CSIRT to process cyberincidents (in particular dispatching) and response. As well as departments that assign functions to secure information and communication systems both in company and state.
Today acutely raises the issue of providing information confidentiality in conditions of growth quantity and quality of violations in cyberspace that are constantly improving and developing. Reliability of traditional methods for ensuring confidentiality is questionable taking into account contemporary threats. So look for alternative methods and means of security is urgent issue. Significant interest causes quantum cryptography, which do not depend on computing or other capabilities of offender, uses specific unique properties of quantum particles, and based on the inviolability of the laws of quantum physics. One of the most advanced technology of quantum cryptog-raphy is quantum secure direct communication, which can transmit information directly by open channel (without encryption – in this case there is no key distribution problem), but they have only asymptotic resistance to noncoherent attacks and, certainly requires some methods for amplification security. In this regard, developed a method of ensuring the stability of quantum cryptography protocols. To evaluate the effectiveness of this method was developed a methodology for conducting experimental research, according to which it is made comparing of its performance with known method. According to the obtained results, the proposed method has a speed in 1.52 times faster against analogs at the same level of resistance to noncoherent attacks.
The problem of cyberterrorism is global and quite acute in today's information society. Leading world states are increasingly focused on critical infrastructures. In civil aviation criticality level is amplified by communication and interaction between ground systems and aircrafts. Modern information and communication technology implementation in one hand increases civil avia-tion operation efficiency and in the other hand generates a set of new vulnerabilities and potential threats. Existed solutions don’t take into account modern requirements from regulatory aviation security documents in full and civil aviation specific. Accordingly, basic model for cybersecurity requirements definition based on regulatory international aviation security documents were proposed. Besides, domestic requirements for civil aviation cybersecurity were formalized and it allows to provide state aviation cybersecurity system of Ukraine. Further papers will relate to effective methods and means development for providing requirements formed in this paper.
Стрімке зростання обсягів інформації створює нагальну потребу створення масштабних місць зберігання та накопичення даних. Задачу накопичення та зберігання інформації успішно розв’язують дата-центри – інструменти, які здатні забезпечити та автоматизувати будь-яку бізнес-діяльність. Наразі майже всі постачальники послуг використовують дуже перспективну технологію побудови дата-центрів – Cloud Computing («хмарні» обчислення), яка має низку переваг перед традиційними аналогами. Але проблема захищеності даних, які довіряють постачальнику, є настільки значною, що майже завжди є ризик втратити дані у «хмарі» назавжди. У статті було проведено аналіз існуючих моделей дата-центрів на базі технології Cloud Computing, що дало змогу виявити проблему забезпечення інформаційної безпеки. Зважаючи на це, у статті запропоновано модель захищеного дата-центру на базі технології Cloud Computing, показано її теоретичне обґрунтування та проведено відповідні симуляції, результатом яких є той факт, що розроблена модель вирішує проблему інформаційної безпеки в дата-центрі та може бути використана для побудови центрів обробки даних на базі технології Cloud Computing у різних галузях.
The rapid growth of information creates an urgent need for the establishment of large-scale storage and accumulation of data. The task of information collecting and storing is successfully resolved by data centers – tools that are able to secure and automate any business activity. Currently, almost all the service providers use a very promising technology for data centers – Cloud Computing, which has several advantages over traditional data centers. The problem of data protection that is trusted to the vendor, is so great that usually the risk of losing data in the «cloud» forever. In this paper, there is an analysis of existing models of data center technology based on Cloud Computing, which helped to identify the problem of information security. Therefore, in the paper there is proposed the model of secure data center based on technology of Cloud Computing, showed its theoretical foundation and conducted appropriate simulation, the result of which is the fact that the developed model solves the problem of information security in the data center and can be used in creation data centers based on technology Cloud Computing in different spheres.
In this paper the aspects of information-psychological impact in a cybersecurity strategy for Ukraine are analyzed. The possible ways of impact individual, society, state and ways and means of protection against it, which provides document, are shown.
Процес впровадження інформаційно-комунікаційних технологій у більшості сфер сьогоденного суспільного життя спрямований на підвищення ефективності бізнес-процесів. Проте наявність уразливостей та кіберзагроз породжує кіберінциденти, для локалізації та нейтралізації яких необхідні ефективні методи виявлення, ідентифікації, оброблення та розслідування. Одним із підходів є застосування мережево-центричної концепції, яка орієнтована на протидію виникненню та ліквідації наслідків кіберінцидентів за допомогою засобів, об'єднаних інформаційними мережами в єдину сис-тему. У роботі, на базі цієї концепції, запропоновано метод мережево-центричного моніторингу кіберінцидентів, який реалізується у 8 етапів: класифікація кібератак, виявлення типу кібератаки, категоризація кіберінцидентів, формування множини правил екстраполяції кіберінцидентів, визначення об’єктів захисту, визначення впливу кіберінцидентів на складові інформаційно-телекомунікаційних систем, визначення найбільш критичних складових інформаційно-телекомунікаційних систем, ранжування ступенів небезпеки кіберінцидентів. Цей метод дозволяє визначити найбільш важ-ливі об’єкти захисту, а також прогнозувати категорії кіберінцидентів, які виникнуть внаслідок реалізації кібератаки, та їх рівень небезпеки (критичності). Крім того, цей метод та сформовані на його основі інструментальні засоби будуть корисними для команд реагування на кіберінциденти типу CERT/CSIRT для ефективної обробки кіберінциден-тів (зокрема диспетчеризації) та адекватного на них реагування, а також для підрозділів, на які покладаються обов’язки щодо захисту інформаційно-телекомунікаційних систем як в межах підприємства, так і в межах держави.
Сучасні тенденції розвитку інформаційних технологій спричинили феноменальну залежність суспільства від послуг, які надають різноманітні галузі інфраструктури. Нині, якість та доступність таких послуг є одним з головних показників розвитку інфраструктури держави, а забезпечення їх захисту та стабільного функціонування є найважливішою і обов’язковою складовою національної безпеки розвинених держав. Збільшення концентрації засобів та ресурсів для захисту електронних інфраструктур різних типів зумовило необхідність ранжування інфраструктурних об’єктів, виділення найважливіших з них та появи поняття критична інфраструктура. З огляду на це, у роботі проведено багатокритеріальний аналіз підходів до виявлення критично важливих об’єктів для оцінювання їх можливостей щодо виявлення та ідентифікації найбільш важливих об’єктів критичної інформаційної інфраструктури. Встановлено, що найбільш ефективними для інформаційної інфраструктури є підходи, що базуються на теорії графів та імітаційному моделюванні, проте більшість існуючих підходів не враховують повної множини параметрів та інформаційної складової – це зумовлює необхідність розроблення універсального методу ідентифікації об’єктів критичної інформаційної інфраструктури.