The intensification of military and terrorist threats leads to the constant updating and modernization of the state system for the protection of restricted access information for any country in the world. With the beginning of military aggression on the territory of Ukraine, its system for the protection of state secrets is constantly under the influence of significant risks of the threat of leakage of secret information, especially in the military sphere. The consequences of the occupation of the territory of its individual regions, the capture of citizens who have access to state secrets and/or the destruction of critical infrastructure facilities that are subjects of regime-secret activities, create the need to determine the amount of damage caused to the national security of Ukraine in the event of the disclosure of state secrets or the loss of material carriers of secret information. The implementation of this task is entrusted to the state expert on secrets, who prepares a conclusion on the amount of such damage. It is obvious that for the efficiency of its preparation, an automated workplace with appropriate methodological and software support is necessary. The existing methodological recommendations to state experts on secrets regarding the determination of the grounds for classifying information as a state secret and the degree of their secrecy and the previously developed method of analysis and assessment of the amount of possible damage to the national security of the state in the field of state secret protection do not take into account the actual data regarding the above-mentioned challenges, and therefore require improvement. Unlike the existing one, the improved method proposed in the work for assessing the damage to the national security of Ukraine in the event of a leak of a state secret based on an updated and supplemented set of parameters from the report on the state of ensuring the protection of state secrets for a subject of regime-secret activity, criteria for determining the degree of secrecy of information constituting a state secret, assessment of the reduction in the efficiency of the object of use of this information, including classification of levels of terrorist threats etc., has the ability to assess the amount of total damage caused, obtained by the value of economic damage and damage from other serious consequences, calculated separately in the event of disclosure of a state secret and/or loss of material carriers of classified information. Approbation of the work of the improved method was carried out for each parameter on the example of a specific individual subject based on conditional data of its report on the state of state secret protection. The obtained value of the magnitude of this damage both for such an individual subject and for all other such subjects of regime-secret activity according to the generalized report, where a state secret was leaked, makes it possible to further calculate the generalized magnitude of the total damage to the national security of Ukraine and assess the consequences of its impact on the sphere of state secret protection for the country as a whole.
Protection of information with limited access, especially state secrets, is an important task in the sphere of national and information security of the state. To minimize the possible damage to the national security of Ukraine from violations in the sphere of protection of state secrets) and to reduce the negative international rating and other serious consequences at the state level, the task of creating specialized databases, and developing and improving existing methods and models that implement relevant assessments is urgent. That is why, the theoretical-multiple presentation of the parameters of the generalized report and the report on the state of state secret protection in tuple models allow solving the actual scientific and practical task of formalizing the process of assessing the negative consequences of leaking a state secret, its disclosure or loss of material carriers of secret information, violation of the secrecy regime, etc. Previously, a tuple model of primary parameters was developed, and currently, as its continuation, a model of internal parameters and its hierarchical structure has already been proposed, due to the integrated theoretical-multiple representation of sets characterizing the information about the availability of the employees of the reporting subject of admission and access to of state secrets and the number of material carriers of secret information, allows, under the requirements of current legislation, to determine a set of input and output parameters for the formation of special databases and the formalization of the process of assessing the damage caused to national security from the leakage of state secrets. In the future, to implement the above-mentioned process, it is necessary to develop an appropriate model of formalization and processing of the database of secondary parameters of the subject of regime-secret activity.
The changes brought by informatization to society have a qualitative effect on the process of modernization of medical care. At the same time, the digitization of big data in healthcare creates numerous risks from the point of view of ensuring the confidentiality, integrity, and availability of information. Inadequate security is due to both objective and subjective reasons. Among them: are the lack of a sufficient number of qualified specialists in the field of information protection; budget restrictions; software conflict; lack of training in information security rules and skills of medical personnel; non-compliance with traditional cyber security practices; legal and ethical issues related to patient data. Determining the minimum and maximum possible degrees of risk of security breaches in information and telecommunication medical systems is the key to ensuring the protection of medical information. This confirms the significance and timeliness of this research, which is based on a risk-oriented approach. The analysis of the scientific literature, having allowed the designation of the components, is how the information-telecommunication system and the links between them are put together. For each asset, the source of the threat, the threat itself, and the variants of reaction to it are identified. The following violations are most common: theft of the patient’s medical information (confidentiality threats); modification of the patient’s medical information (threats to integrity); failure of individual components of the medical system (availability threat). A graphic and quantitative approach to the assessment of information security risks and methods and means of processing these risks are proposed. This study can serve cyber security specialists for modeling information protection in medical systems and be used in the educational process of students of 125 Cyber Security specialties.
In this paper, the models and methods of using information with limited access are analyzed, the model of identification of restricted information is developed. An experimental study of the developed software module for identifying restricted information is conducted. The developed model can be used to identify information to restricted information by both common users and employees of companies to prevent leakage of restricted information.
Захист інформації з обмеженим доступом, особливо державної таємниці, є важливим завданням у сфері національної та інформаційної безпеки держави. Для мінімізації можливої шкоди національній безпеці України від порушень у сфері охорони державної таємниці та зменшення негативного міжнародного рейтингу та інших тяжких наслідків на рівні держави актуальною є задача створення спеціалізованих баз даних, розробка і удосконалення існуючих методів і моделей, що реалізують відповідні оцінювання. Саме тому, теоретико-множинне представлення параметрів Узагальненого звіту та Звіту про стан забезпечення охорони державної таємниці у кортежні моделі дозволяють вирішити актуальну науково-практичну задачу формалізації процесу оцінювання негативних наслідків витоку державної таємниці, її розголошенням або втратою матеріальних носіїв секретної інформації, порушенням режиму секретності тощо. Розроблені кортежна модель первинних параметрів та її ієрархічна структура за рахунок інтегрованого теоретико-множинного представлення множин, що характеризують суб’єкт режимно-секретної діяльності, специфіку, характер та вид порушення, витрати на заходи охорони державної таємниці, відомості про режимно-секретний орган, дотримання режиму секретності і нормативних рекомендації дозволяє відповідно до вимог чинного законодавства визначити множини вхідних та вихідних параметрів для формування спеціальних баз даних і формалізації процесу оцінювання завданої шкоди національній безпеці від витоку державної таємниці. В подальшому, для реалізації зазначеного процесу необхідно розробити відповідні моделі для внутрішніх і вторинних параметрів.
The lack of registers of critical infrastructure of the state and their information and telecommunication systemsleads to uncertainty in the amount of resources needed to protect them from possible cyberattacks. Given the limitations of© Dreis Y., Derkach L., Basic set of generalized criteria for assigning objects to the critical infrastructure of state // Ukrainian Scientific Journal ofInformation Security, 2021, vol. 27, issue 1, pp. 13-20.20such resources, an important and relevant scientific and practical task is to determine the completeness and priority of cyberprotection of these objects. The formation of such registers is based on the method of assigning objects to the critical infrastructure of the state, including on the relevant criteria that will determine the affiliation of a particular object to one that iscritical to the state. The analysis of the existing criteria for classifying objects as critical infrastructure of the state shows thatin Ukraine there are a number of other criteria (and which should also be taken into account) involved in the formation ofregisters of important objects for the state, such as "State Register of Potentially Dangerous Objects". Therefore, it is proposed to form a list of such generalized criteria for classifying objects as critical infrastructure of the state in the form of abasic set, which integrates ten features with the possibility of further expansion. This set can be used to determine the priorityof cyber protection of information and telecommunications systems (critical information infrastructure facilities) of criticalinfrastructure facilities of the state.
The main requirement for modern systems of intrusion detection is the possibility of identifying deviations in information processes in order to detect unknown attack types. An overview of existing approaches to identifying network deviations based on multifractal analysis methods is given. The results of the calculation of the Hurst exponent for the time series of CPU usage for different types of user activity are presented.
На сьогодні, одними із розповсюджених систем захисту інформації є системи виявлення кібератак та системи виявлення вторгнень, останні з яких становлять особливий практичний та науковий інтерес. Також, функціональність сучасних систем виявлення та блокування вторгнень у значній мірі залежить від їх можливостей щодо виявлення нових кібератак у режимі реального часу. Для виявлення відповідних атакуючих дій використовуються спеціальні методи, моделі, засоби, програмне забезпечення і комплексні технічні рішення для систем виявлення вторгнень, які можуть залишатись ефективними при появі нових або модифікованих кіберзагроз. Однак, як показує практика при появі нових загроз та аномалій, породжених атакуючими діями з невстановленими або нечітко визначеними властивостями, відповідні засоби не завжди залишаються ефективними. Отже, розробка засобів верифікації та проведення експериментальних досліджень відповідних технічних рішень, засобів і програмного забезпечення виявлення кібератак, зловживань та аномалій в інформаційних системах для підтвердження адекватності їх роботи є актуальним науковим завданням. Є низка робіт, таких як кортежна модель формування атакуючих середовищ, низка методів для виявлення аномальних станів, методологія побудови системи виявлення вторгнень, а також структурна модель обчислювальної системи для створення засобів виявлення кібератак та її алгоритмічне і програмне забезпечення. Для її верифікації необхідний спеціалізований емулятор кіберзагроз, оскільки відомі не підтримують необхідні формати даних, що застосовуються у авторській розробці. Виходячи з цього, метою роботи є розробка емулятора для проведення експериментального дослідження для підтвердження достовірності отриманих теоретичних положень, практичних результатів та адекватності роботи програмного модуля розробленої системи виявлення кібератак, що дозволить удосконалити функціональні властивості сучасних систем виявлення вторгнень для режиму реального часу.
Proposes a method for fuzzy classification of information according to established criteria based on the theory of fuzzy sets and complex oriented information network "List of classified information" during the examination of material media for the presence of such information.
Дедалі частіше фізичні особи надають доступ до персональної інформації громадськості. Ризик для прав і свобод фізич-них осіб може стати результатом обробки персональних даних (випадкове чи навмисне знищення, втрата, модифіка-ція, несанкціоноване розкриття або доступ тощо.), що може призвести до фізичної, матеріальної та нематеріальної шкоди. Для мінімізації втрат від порушення організацією Регламенту GDPR та зменшення негативного рейтингу на рівні держави актуальною задачею є розробка методів та моделей, що реалізують відповідні оцінювання. Саме тому, те-оретико-множинне представлення параметрів Регламенту GDPR у кортежній моделі дозволяє вирішити актуальну науково-практичну задачу формалізації процесу оцінювання негативних наслідків витоку персональних даних, заподія-них їх обробкою. Розроблена GDPR-модель та її ієрархічна структура за рахунок інтегрованого теоретико-множинного представлення величини річного обігу, множин, що характеризують рівень, специфіку, характер та рецидив порушення, зниження шкоди, відповідність заходам, визначаючий чинник, ступінь відповідальності, рівень співпраці, категорії да-них, спосіб виявлення, дотримання кодексів і превентивні рекомендації дозволяє відповідно до положень Регламенту GDPR визначити множини вхідних та вихідних параметрів для формалізації процесу оцінювання збитків від втра-ти персональних даних. В подальшому, для реалізації зазначеного процесу необхідна розробка методу оцінювання негати-вних наслідків від витоку персональних даних відповідно до положень регламенту GDPR, що дозволить визначити ма-ксимальний та фактичний збитки для організації.
Providing the process automation services in all spheres of human, society and state life support has led to increased demands for the information protection in information and telecommunication systems (ITS) of potentially dangerous objects of critical infrastructure of the state. In accordance with the existing legal and regulatory framework related to the objects of critical infrastructure, there is an incomplete-ness regarding the possibility of their proper classification, there is also no list of ITS of such objects and there are no criteria for the negative consequences assessment. Solving these issues will generate the formation of such objects clas-sifier of critical information infrastructure, which will enable the creation of conditions to increase their resilience to cyber attacks. Accordingly, a tool is proposed for classifying ob-jects of critical information infrastructure. The basis of its construction is a tuple model, the components of which are ordered identifiers of critical infrastructure objects that re-flect: the sector of the critical information infrastructure of the state; administrative territorial unit of Ukraine; name or identification number of the legal entity; form of ownership of the organization-owner / manager of ITS; the type of in-formation processed in the ITS; registration numbers of documents certifying the availability of certified/licensed systems or information security means; the negative conse-quences of cyber attacks on ITS. With the help of the pro-posed model, examples of objects classification of critical in-formation infrastructure of the state are presented, and it will give an opportunity to form a list of relevant ITS to ensure their priority protection against cyber attacks in future.
Today, more and more attention is paying on cybersecurity of critical information infrastructure by leading world state. Ukraine, which has critical infrastructure facilities in information and telecommunication systems of which the information that constitutes a state secret information, is not an exception. Extensive use of modern information and telecommunication technologies in critical infrastructure objects leading a lot of new vulnerabilities and potential cyberattacks. Therefore, the negative consequences for national security in case of a leak the state secret should be evaluated. Well-known approach allows to determine the damage from disclosure or loss of state secret in the score equivalent as well as monetary value, but only on one subject of regime-secret activity without taking into account the information and telecommunication system. Consequently, the question remains about the assessment of the negative consequences of the leakage of information with limited access from cyberattacks to information and telecommunication systems for a complex of critical infrastructure in a given rayon or for the state as a whole. In view of this, was developed the consequence evaluation model of leak the state secret from cyberattack directing on critical information infrastructure of the state which take into account the determined numerous of potential violation, typical threats, secrecy degree, a set of information constituting state secrets, indicators of economic damage, severe consequences and others (included in the corresponding list), affording to create the method of evaluating negative consequences of SS from cyberattacks to the critical information infrastructure of the state.
Автоматизація процесів надання послуг в усіх сферах забезпечення життєдіяльності людини, суспільства і держави призвела до посилення вимог до захисту інформації в інформаційно-телекомунікаційних системах (ІТС) потенційно небезпечних об’єктів критичної інфраструктури. Відповідно до існуючого нормативно-правового забезпечення, пов’язаного з об’єктами критичної інфраструктури, прослідковується неповнота щодо можливості їх коректної класифікації, також не сформований перелік ІТС таких об’єктів, відсутні критерії щодо оцінювання негативних наслідків від кібератак. Вирішення зазначених питань дозволить сформувати такий класифікатор об’єктів критичної інформаційної інфраструктури, який дасть можливість створити умови для підвищення їх стійкості до кібератак. Відповідно до цього пропонується засіб класифікації об’єктів критичної інформаційної інфраструктури. В основу його побудови закладена кортежна модель, складовими якої є упорядковані ідентифікатори об’єктів критичної інфраструктури, що відображають: сектор критичної інформаційної інфраструктури держави; адміністративно-територіальну одиницю України; назву або ідентифікаційний номер юридичної особи; форму власності організації-власника/розпорядника ІТС; вид інформації, що обробляється в ІТС; реєстраційні номери документів, що засвідчують наявність атестованих/ліцензованих систем чи засобів захисту інформації; негативні наслідки кібератак на ІТС. За допомогою запропонованої моделі представлені приклади класифікації об’єктів критичної інформаційної інфраструктури держави, а в подальшому вона дасть можливість сформувати перелік відповідних ІТС для забезпечення їх першочергового захисту від кібератак.
The article analyzes the basic terminology and variety of negative consequences to which cyber attack can lead to information and telecommunication systems of critical infrastructure objects in various countries of the world, including. and in Ukraine, for example, in case of leakage of information with limited access or state information resources that are processed in these systems. It has been shown that it is necessary to take into account other severe consequences for national interests from disclosure of information that constitutes state secrets as a result of the possible implementation of cyber attacks in the formation of a list of information and telecommunications systems for critical infrastructure of the state. Proposals to the for-mation of a single classifier of the negative consequences of cyber attacks on information and telecommunications systems of critical infrastructure facilities of the state, taking into account the processing in these systems and other types of information with limited access as confidential (including personal data) and service information.
The article is devoted to the study of Ukraine the critical information infrastructure in order to increase the efficiency of use and protection of state information resources circulating in the information and telecommunication systems of critical infrastructure objects. The analysis of international experience and current domestic regulation of this field have revealed such basic problems as: the lack of basic terminology, the need to create a system for critical infrastructure protection and crisis management, the formation and development of a system of public-private partnership, the absence of sectors and elements in Ukraine critical infrastructure and of criteria attribution of objects to critical infrastructure, the lack of criteria for assessing the negative consequence of cyberattacks on the information telecommunicative system of the object of critical infrastructure, as well as the need for legislative changes. To resolve some of them, the authors introduce new concepts in this article, propose sectors of Ukraine the critical infrastructure with the definition of those relating to critical information infrastructure, unification of the negative consequence of cyberattacks on the infor-mation and telecommunication system of the critical infrastructure object in order to further evaluate the damage inflicted on the national security of Ukraine in the event of the leakage of state information resources.
The article is devoted to the study of Ukraine the critical information infrastructure in order to increase the efficiency of use and protection of state information resources circulating in the information and telecommunication systems of critical infrastructure objects. The analysis of international experience and current domestic regulation of this field have revealed such basic problems as: the lack of basic terminology, the need to create a system for critical infrastructure protection and crisis management, the formation and development of a system of public-private partnership, the absence of sectors and elements in Ukraine critical infrastructure and of criteria attribution of objects to critical infrastructure, the lack of criteria for assessing the negative consequence of cyberattacks on the information telecommunicative system of the object of critical infrastructure, as well as the need for legislative changes. To resolve some of them, the authors introduce new concepts in this article, propose sectors of Ukraine the critical infrastructure with the definition of those relating to critical information infrastructure, unification of the negative consequence of cyberattacks on the infor-mation and telecommunication system of the critical infrastructure object in order to further evaluate the damage inflicted on the national security of Ukraine in the event of the leakage of state information resources.
The question of the need to protect personal data created and processed by application software in automated systems. Analysis of the existing legislation indicates mandatory protection of state information resources or classified information, protection of which is defined by law. Since personal data can be attributed to confidential information about a person, they need protection at the application of the integrated system of information security. Its implementation involves a risk assessment of threats during the development of security policy in the definition of necessary measures and information security. A basic model presenting risk parameters defined criteria in the legislation in the field of personal data protection. The method of risk assessment which resulted in recommendations for selecting the policy of personal data protection, addition of standard functional profile protection security services as required, determination of the damage caused to a person, society and state in case of loss this personal data.
Часто перед фахівцями відповідних підприємств, для підвищення ефективності вирішення завдань захисту інформації, виникає питання про вибір існуючих або розробку нових засобів оцінювання ризиків безпеки ресурсів інформаційних систем. Перш ніж здійснювати такий вибір або розробку необхідно мати достатньо повне відображення характеристик ризику в аспекті інформаційної безпеки. У зв'язку з цим, в роботі визначені множини базових характеристик ризику для галузі інформаційної безпеки. На підставі цього пропонується відображати задані ідентифікуючи і оціночні характеристики у вигляді бістабільної (біфіксованої) інтегрованої кортежної моделі. На практиці таку модель пропонується використовувати у вигляді відображення на два частних кортежі – аналітичний і синтетичний, які застосовуються відповідно для реалізації вибору існуючих засобів і для допомоги розробникам при створенні нових систем оцінювання ризиків
Often experts of corresponding companies in order to increase the efficiency of information security decision making, put the question on the choice of existing or development of new means of security risks assessment of information systems resources. For the effective organization of appropriate process of a choice or development it is necessary to have a complete display of risk characteristics. In this regard, the most of the basic characteristics of risk for the information security sphere are defined in the work. According to this, it is proposed to display the characteristics of identification and assessment as a bistable integrated model of a tuple. In practice such model is offered to be used as a display on two particular tuples – analytical and synthetic, applied according to the choice implementation of existing means and to assist developers at creation of new risk assessment systems