Several state institutions deal with the providing of national cybersecurity. Each of them solvs its own number of tasks on critical information infrastructure protection from cyberattacks and cyberincidents. For example, the State Service of Special Communication and Information Protection, units of technical protection are responsible for cyberprotection of information resources and data processing infrastructure from cyberattacks of any origin. The Security Service of Ukraine defends national critical information infrastructure from cyberattacks of foreign intelligence services and cyberterrorists, and the National Police protects legal rights and interests of cityzens and society from cybercrimes. For solving their tasks, all of them use cyberattacks detection and prevention instruments. But these specific tasks, solved by both institutions, have to be affected on functional possibilities and characteristics of these means. Taking this into account, the article contains results of studying the foreign experience of creation the cyberattacks detection and prevention systems for cyberprotection and cybercounterintelligence, is determined key characteristics of the mentioned systems of different functions, which we need to conside in practical activity of building national cybersecurity system.
Concept of business continuity management is the prospective direction of operative and strategy management and it defines the importance of information resources security when crisis influences. Crisis management consists of its forecasting, identification, responding and emergency procedures, crisis assessment and also processes of decision support and personnel activity or systems operation. In this paper the analysis of modern crisis management systems and basic methods was carried out. The main aim of this analysis is defining of science and technique prospective directions and also disadvantages identification in existed systems. This study covers both domestic and foreign developments. The main attention is paid to crisis forecasting systems, decision support and personnel activity systems in uncertainty and weak formalized space. This study results can be used to choose future researches directions for crisis detection and assessment systems and it confirms the feasibility and validity for expert approaches and fuzzy logic methods using.
Issues related to the prediction, monitoring and detection of critical situations in the information and communication systems, are of great scientific and practical importance. These processes occupy central positions in the concept of business continuity management, defining the capabilities of all the mechanisms use dint here assumption of business processes and the protection of information resources under the conditions of crisis situations. Any crisis is a consequence of the aggregate incidents or attacks. Based on this definition and formalization of the main parameters that can be used for detection and identification of cyber attacks are certainly an urgent task. This study is devoted to these issues. Thus, a clear definition of a set of parameters, as filmed on a network and local level, will allow to take into account the particularities of each crisis, attack or information security incident and, as a consequence, increase the effectiveness of preventive protection systems and equipment. The main results can be used to construct a system for forecasting, detection and identification of computer attacks in the information and communication systems based on fuzzy logic methods.