Особливістю повільної DDoS-атаки є використання вразливості в протоколі TCP/IP, де навмисно чи ненавмисно можуть бути викликані переривання в результаті затримки в каналах зв'язку. У статті розглядається проблема виявлення повільної розподіленої атаки відмови в обслуговуванні. Відомо, що виявлення повільних DDoS-атак відрізняється від атак на основі обсягу трафіку, оскільки вони не збільшують інтенсивність трафіку в мережі. Замість створення раптового надлишку тра[1]фіку, повільні малопотужні атаки проводяться з мінімальною активністю і не реєструються сис[1]темами. Вони спрямовані на те, щоб вивести об'єкт з ладу непомітно, створюючи мінімальну кіль[1]кість підключень та залишаючи їх незавершеними якомога довше. Як правило, зловмисники відправ[1]ляють часткові запити HTTP і невеликі пакети даних або повідомлення для перевірки активності, щоб підключення залишалося активним. Подібні атаки важко заблокувати, і складно виявити. У зв'язку з малим обсягом трафіку, а також з тим, що атаки можуть виглядати як стандартні підк[1]лючення, потрібна інша технологія запобігання. Джерела атак необхідно блокувати, виходячи з осо[1]бливостей виконання запитів, а не на основі їх репутації. Тому було зроблено припущення про залеж[1]ність успішної повільної DDoS-атаки залежить та поведінки користувача. На основі моделювання методу виявлення повільних атак було проведено дослідження та прогнозування поведінки особис[1]тості, запропоновано траєкторію поведінки конкретного користувача. Можливості застосування такого методу підтверджено моделюванням атак RUDY на HTTP-сервіси. Отримані характерис[1]тики точності прогнозування залежно від відображуваного накопиченого трафіку і статистики атак. Дослідження доводить, такий метод можна використовувати для виявлення різних типів по[1]вільних DDoS-атак
Результативне рішення задач аналізу і синтезу систем управління інформаційною безпекою не може бути забезпечено одними лише способами простого опису їх поведінки в різних умовах – системотехніка видвигає проблеми, які потребують кількісні оцінки характеристик. На сьогоднішній момент створення систем управління інформаційною безпекою не можливе без дослідження й узагальнення світового досвіду побудови інформаційних систем та їх складових підсистем, одними з ключових яких є системи захисту інформації та протидії вторгненням в інформаційну систему. Складовими математичного забезпечення таких систем є моделі процесів нападу на механізми захисту та блокування або знищення самих кіберзагроз. Базою таких моделей є математичний апарат, який повинен Dr. habil, Prof. забезпечити адекватність моделювання процесів захисту інформації для будь-яких умов впливу кіберзагроз. При визначенні математичного апарату необхідно чітко розуміти як будуються ті або інші множини кіберзагроз, та як здійснюються взаємовідносини самих множин кіберзагроз, множин елементів системи захисту та множин систем виявлення кібератак, які повинні контролювати правильність роботи процесу захисту інформації. У статті аналізуються різні варіанти побудови моделей системи управління інформаційною безпекою та створена математична модель, яка враховує внутрішні взаємозв’язки різних підмножин складових системи захисту інформації під час впливу кіберзагроз.
The article examines methods for increasing the stability of a steganographic container to attacks when it is transmitted through the channels of communication. The main characteristics of a fixed container, namely a bitmap image, are defined. The most common color models of the image are analyzed. A method for rounding the values of image elements for modifying the lowest bit in steganographic protection problems is proposed. The results of a study to justify the choice of color scheme are presented as an image of the model in case of increased stability of the steganographic system.
Every year, global IT companies present new modern software, but what is the evidence of its development. Empirical software engineering deals with the problem of determining the efficiency and calculation of quantitative indicators of software product development. In order to qualitatively determine the effectiveness, you need to follow the evolution of software. Software evolution refers to the dynamic behavior of software systems as they are maintained and improved throughout the life cycle. From this task arises the main question of this work to investigate and analyze information about the stages of evolution of empirical software engineering. This article presents the evolution of philosophical and methodological considerations on empiricism and presents information in a clear and systematic way. The works of foreign and domestic scientists were considered, their activity was analyzed and what conclusions they made. In the works of domestic scientists mostly considered modern systems and methods that determine the complexity of the system, structure and from this conclusion were drawn about the competitiveness and wear of the program. In the works of domestic authors, the description of classical systems and their development in accordance with the use of empirical methods were studied. In this study, we trace the most important current events in the history of the impact on empirical engineering. Based on the collected information, a table was created, which presents in chronological order the scientists who have made their contribution to the development of empirical engineering. As a result of the study, it was determined that the empirical methods used in accordance with the scope of application have a single purpose to determine: to identify depreciation, competitiveness, economic fairness and relevance of the system.
The article proposes, shows and analyzes the main stages of implementing software for group assessment of a functional profile and determining or agreeing the level of guarantees for the correct implementation of functional security services in information security tools of information of telecommunication systems from unauthorized access in Ukraine based on theoretical studies previously conducted. The necessary regulatory documents on technical protection of information governing the procedure of evaluating and determining the level of guarantees of automated systems against unauthorized access in Ukraine are covered. The program was designed using the Data Flow Diagram, namely, a contextual diagram of the group definition process and a decomposed diagram of the process of group determination of the functional security profiles and the level of guarantees. More detailed flowcharts of software and algorithms are constructed. A prototype of the software is implemented; examples of work on each of the main blocks of work that were previously designed in the diagrams and flowcharts of the algorithms are given. Certain advantages and disadvantages of the developed software for group determination of the functional security profile and the level of guarantees are defined. The developed program allows to carry out group estimation and to compare the results sent to the server. This approach reduces the time spent by the security administrator to determine the security profiles and security levels of the information being processed against unauthorized access and to detect whether a specified functional profile coincides with a standard one (provided this match the user is provided with information about that standard functional profile) or determine another level of warranty. By conducting a group examination, the reliability of the obtained results increases DOI : https://doi.org/10.17721/ISTS.2019.1.11-18
An analysis of problem of the fragmentation of distributed database data showed that the formal model is the so-called integer linear programming problem with Boolean variables. Unfortunately, the task of the ILP with the BP belongs to the class NP (non-deterministic polynomial), which can easily be solved even with the use of modern computers.The proposed method of parallel computing for fragmentation of distributed database data is based on the ranking approach to its solutions, the principles of optimization in the direction and strategies, for cutting off non-prospective solutions. The method allows us to determine the local extrema at the vertices of the graph and determine the global extremum on their basis.
The article proposes method optimizing the search of the optimal path in the graph by rejecting extra nodes based on cluster analysis using the transitive closure of the matrix of the relation. The existing methods of optimizing the search of the path have been analyzed, which resulted in the proposed method, which implements the idea of reducing the number of nodes in the current calculation, as a result of which there is a decrease in the number of resources. The application of the method in practice is considered, and conclusions are made regarding further research in this direction. To test performance and evaluate the effectiveness of the method the software was developed on the programming language of high-level C++. The results of the research indicate rather high efficiency of optimization for static nodes that do not change their properties for a certain period of time.
The article defines the purpose, direction and objectives of analysis of the main methods of identification of risks of information security information and telecommunication systems. The basis of the system of information security in information and telecommunication systems is based on the risk management process, which involves such main processes as analysis and evaluation. There are a large numbers of assessment methods and tools of information risk management nowadays. This article describes the application of expert systems, which hold a higher risk assessment of information security for different models of information and telecommunication systems and help to avoid violations of the confidentiality, integrity and availability of information. The analysis of the working methods of reporting and the reasons for the occurrence of risks with the economic effectiveness of possible countermeasures is made. The main stages of the assessment and mitigation of information risks in the information infrastructure systems are considered. The procedure of assessment of information risks in accordance with basic international standards is analyzed.
The article suggests, shows and analyzes the theoretical basis for determining the level of guarantees of automated systems from unauthorized access. The necessary normative documents of technical protection of information that regulate the procedure for assessing and determining the level of guarantees of automated systems from unauthorized access in Ukraine are reflected. The algorithm of the expert's actions is considered. On the basis of these documents, formalization of the basis for determining the level of guarantees of automated systems against unauthorized access was carried out for the first time. The authors proposed theoretical foundations that make it possible to further improve the expert system that will automatically determine the functional profile of security and the level of guarantees of the automated system from unauthorized access. This will facilitate the work of experts regarding the definition of the security profile, the level of guarantees and the creation of the necessary set of protective equipment, as well as reduce the spent resource of time and material resources.
In the article basic stages of implementation of software of determination or concordance of level of guarantees of correctness of realization of functional services of safety phases in facilities of security of information of automated systems from an unauthorized access in Ukraine on the basis of undertaken by authors earlier theoretical studies of determination or concordance of level of guarantees are shown. Planning of work of the program is carried out by means of diagrams of Data Flow Diagram. More detailed flow-charts of work of software and algorithms are built. The prototype of software is realized and examples of work on each of basic blocks of work, that were preliminary projected in diagrams and flow-charts of algorithms are made. Certain advantages and drawbacks of the worked out software of functional profile of security and of level of guarantees are determined. The further steps of continuation of research in this direction are indicated.
In the article basic stages of implementation of software of determination or concordance of level of guarantees of correctness of realization of functional services of safety phases in facilities of security of information of automated systems from an unauthorized access in Ukraine on the basis of undertaken by authors earlier theoretical studies of determination or concordance of level of guarantees are shown. Planning of work of the program is carried out by means of diagrams of Data Flow Diagram. More detailed flow-charts of work of software and algorithms are built. The prototype of software is realized and examples of work on each of basic blocks of work, that were preliminary projected in diagrams and flow-charts of algorithms are made. Certain advantages and drawbacks of the worked out software of functional profile of security and of level of guarantees are determined. The further steps of continuation of research in this direction are indicated.
In the article the methodology of analysis of risks of tree of identifiers of state informative resources is shown. The actually place of analysis of risks of the informative safety at the state level is not certain, that stipulates the actuality of the realization of researches after this subject. This methodology is built on the basis of the first offered by the author two methods : the method of determination of level of risk of application of certain countermeasures in relation to certain resources, which will realize the methodology of “double three of defence” presented by the author before; the method of clusterization of risks on the basis of the transition shorting of binary relation of assets, which allows by division after corresponding α- by levels to get the clusters of state informative resources, which are grouped after the levels of risk. After that there is a possibility to trace the order of association in the clusters of state informative resources for their further analysis that can be conducted by the further receipt of optimal α- level, below which a risk is possible. The second method is logical addition of the first, thus at the evaluation of risks of informative safety a sufficient condition is the use only of the first method.
A system of terms and determinations of methodology of defence of state informative resources in comparison that in leading documents on the questions of defence of informative resources and that introduced by the authors in previous researches is presented in the article. To such terms and determinations the authors apply the following ones: state informative resources, threat to the state informative resources, national informative resources, national electronic informative resources, system of national informative resources, system of state informative resources, state electronic informative resources, register of electronic state informative resources, depositary of electronic state informative resources, attack on state informative resources, method of double three of defence, threat of normatively-legal aspiration, threat of organizational aspiration, threat of technical aspiration, object identifier, objects of threats to the state informative resources, source of threats to the state informative resources, vulnerability of state informative resource, risk realization threat state informative resource, aim source threat state informative resource, source information about state informative resource, method illegal capture state informative resource (methods of access are to the state informative resources), direction defence state informative resource, method defence state informative resource, facility defence state informative resource, complex system defence state informative resource. These terms and determinations are offered to be put in the basis of forming of a normative document in the matter of defence of state informative resources.
The theoretical bases of determination of standard types of security of automatic system from the unauthorized access is shown, analysed and offered in the article. The necessary normative documents of technical security information, which regulate the order of estimation and determination of standard functional types of security of information from an unauthorized access in Ukraine, are reflected. On the basis of these documents, formalization of the bases of determination of standard types of security of automatic system from an unauthorized access is carried out for the first time. An example of determination of standard type of security is made after the presented formalized model. Theoretical bases offered by the authors enable in future to work out a consulting model which will determine the standard types of security of automatic system automated from an unauthorized access. It will facilitate the work of administrators of safety in relation to determination of type of security and creation of necessary complex of facilities of security, and also will decrease the spent resource of time.
In the article the analysis of methods of determination of standard functional types of security of theinformation-telecommunication system from an unauthorized access is conducted. The existence of fewof the presented methods, five of which are numbered by the authors, is shown: the first one is astandard method, the second one is a method of verification of uncontradiction and completeness, thethird one is a method of construction of taxonomy, the fourth one is a method of pareto-optimalfunctional types of security, the fifth one is an improved method of determination of functional types ofsecurity of junction of the information-telecommunication system of the tree of identifiers of the stateinformative resources. Their comparison between themselves after such basic parameters as level ofcharges, possibility of the use of both standard and non-standard functional types of security, accountof qualification of experts is carried out. Certain advantages and defects on each of the presentedmethods with further formulation of requirements in relation to the increase of efficiency ofdetermination of standard functional types of security are determin
In the article a goal, a subject, an object, direction and tasks of research of features of administration and management in the public control of state informative resources are defined for the first time. Determination of the concept of state informative resources and their classification are specified; determination of the concept of the public informative system is given. A model of security of the management system by means of public state informative resources on the basis of the method of «double three of security» is worked out. Thus, a common scientific task is formed in relation to determination of normatively-legal and organizational decisions, including technical ones directed to the creation of the common system of public control of state informative resources. The scientifically-applied direction of research is defined. It consists in organization of the system of public management of organs of state administration on the platform of modern methods and models of construction and the rise of effectiveness of the system of administration and public management of the state informative resources.
In the article a technology of construction and defence of the Ukrainian segment of the tree of identifiers of state in-formative resources on the basis of risk management is pre-sented for the first time. This technology is based on re-searches that were conducted by the authors before and are related to the first worked out methodology of construc-tion of a classifier of threats to the state informative re-sources; to the conducted analysis of the world tree of iden-tifiers of informative resources and to the place of the Ukrainian segment of identifiers of objects in it; to the structural-logical model of organization of hierarchical branch of codes-knots of the Ukrainian segment of identi-fiers of objects of public organs; to models and principles of informative safety worked out by the authors, methods and models of realization of control system of informative safety of the state informative resources; to worked out theoretical bases and methodology of analysis of risks of the tree of identifiers of state informative resources, to other works that are bound by the only aim - the develop-ment of the methodology of construction and defence of the Ukrainian segment of the tree of identifiers of the state informative resources. Introduction of this technology must become a unifying factor for generalization of expe-rience of construction of defence of the state informative resources in the country on the basis of risk management and approaches that do not conflict with international standards.
In the article the theoretical bases of analysis of risks of tree of identifiers of state informative resources are expounded. The authors show the absence of effective mechanism of realization of risk process of management in Ukraine on the state level. According to the previous researches a concept of the cube of Yudina-Buchyka is entered, on the basis of it the authors built the actually methodology of construction of classifier of threats to the state informative resources (the authors enter a concept «methodology of double three of security»). In continuation of subjects of security of state informative resources the authors certain the methodology of estimation of risks of safety of the information-telecommunications systems and networks in the context of international standards. Raising of task of determination of level of risk of state informative resources taking into account basic descriptions, that characterize him, is carried out: assets (state informative resources behave to that), threats, to vulnerability, counter-measures, from that a decision is determined in relation to security of certain state informative resource in case of possible realization on him of attack, list of attacks that can be realization on assets.
In the article the continued subjects of construction of classifier of threats to the state informative resources, methodology of construction of which by authors was offered before. Some modern theoretical and practical approaches to the decision of normatively-legal, organizational and technical tasks for realization of the process of defence of the state informative resources are the objects of research in the previous works . The conducted analysis of publications on the subjects of the article shows that the considerable attention was always paid for research of technical direction of defence of informative resources, but in the classifier of threats offered by authors the technical aspiration was not distinguished in the separate phenomenon. Certain threats of technical aspiration and an example of their classification is made. The result of the further improvement and expansion of methodology of construction of classifier of threats of the state informative resources is the development of classifier of next wide class of threats – threats of technical aspiration. Completion of creation of classifier of threats is carried out to the state informative resources, which on the whole contains the threats of normatively-legal, organizational and technical aspiration.