Актуальність. Розвиток інформаційних технологій та обмін даними створюють нові загрози кібербезпеці, зокрема кібератаки та шахрайство. Соціальні мережі та штучний інтелект сприяють вдосконаленню соціотехнічних методів. Аналізуючи дані провідних досліджень, виділяють певні методи, які використовуються найчастіше соціотехніками, але в цих публікаціях не сформовані множини ознак, які характеризують підходи до реалізації відповідних атак, що дасть можливість з системних позицій формалізувати процес їх класифікації. З огляду на це аналіз та класифікація сучасних підходів реалізації соціотехнічних атак є важливою складовою стратегії кібербезпеки для забезпечення захисту від постійно зростаючих загроз та є актуальним науковим завданням. Мета. З урахуванням вищезазначеного метою роботи є аналіз та розробка за ознаковим принципом узагальненої класифікації сучасних підходів реалізації соціотехнічних атак. Методологія. У статті проведено дослідження сучасних підходів та методів реалізації соціотехнічних атак, для систематизації та інтеграції існуючих класифікацій відповідних методів та їх розширення новими ознаковими характеристиками. На базі яких сформована критеріальна (ознакова) класифікація сучасних підходів до реалізації соціотехнічних атак, що використовують різні техніки.Наукова новизна. Запропоновано класифікацію сучасних підходів реалізації соціотехнічних атак за наступними критеріями, як от: часовий аспект, галузева афіліація, взаємодія з політикою безпеки, ініціалізація, тип звернення, інструментарій, порушення характеристик, ступінь важкості, реляційні ознаки, тип атакованого джерела, тип доступу, дистанційність, маніпулювання, тип соціотехніка, масштаб, що дозволяє з системних позицій вибирати та розробляти відповідні засоби протидії соціотехнічним атакам.З урахуванням відповідної класифікації, розглянуто приклад проведення соціотехнічної атаки, на таких кроках їх реалізації як от: дослідження цілі, підготовка соціотехнічної атаки, виконання атаки, експлуатація отриманої інформації, приховування слідів. Висновки. Отримані результати дозволяють з системних позицій вибирати та розробляти відповідні засоби протидії соціотехнічним атакам. Також на базі отриманих критеріїв, можна розробити метод оцінювання готовності персоналу до протидії різним класам соціотехнічних атак.
Актуальність. Стрімкий розвиток інформаційних технологій та інтенсивний обмін даними суттєво змінюють сучасне середовище кібербезпеки, створюючи нові загрози у вигляді кібератак та шахрайства. Особливу небезпеку становлять соціотехнічні атаки, які використовують психологічні маніпуляції для отримання конфіденційної інформації або доступу до захищених систем. Мета. З огляду на це, метою роботи є комплексний огляд існуючих рішень, технологій і методів, які можуть допомогти організаціям та приватним користувачам у боротьбі з соціотехнічними загрозами. Методологія. У статті проведено дослідження сучасних методів виявлення соціотехнічних атак, що використовують маніпулятивні техніки. Розглянуті різні підходи до детектування відповідних атак, включаючи сигнатурні, поведінкові, методи машинного навчання, аналіз метаданих, а також соціальні та психологічні підходи. Особливу увагу приділено інтерактивним і симуляційним методам, які дозволяють організаціям перевіряти свою готовність до атак шляхом моделювання реальних умов. Наукова новизна. Описані апаратні та програмні засоби за дев’ятьма критеріями (високий рівень захисту, централізоване управління, простота використання, інтеграція з іншими платформами, штучний інтелект, адаптивність, можливості роботи в офлайн-режимі, висока вартість, складність налаштування) для виявлення та блокування соціотехнічних атак, які надають багаторівневий захист від соціотехнічних загроз. Висновки. Отримані результати показують, що освітні та організаційні заходи залишаються ключовими для підвищення обізнаності користувачів та зменшення ризику успішних атак, а сучасні підходи до захисту від соціотехнічних загроз мають бути комплексними і включати як технічні рішення, так і навчання персоналу. Також є важливим, постійне вдосконалення існуючих заходів забезпечення безпеки і впровадження новітніх технологій для підвищення ефективності захисту інформаційних систем від соціотехнічних атак.
The primary objective of this investigation revolves around streamlining the operational workflow within the Cybersecurity Operation Center (CSOC). It is no secret that the CSOC faces a significant challenge due to the influx of signals originating from a multitude of cybersecurity tools, each demanding precise processing. These tools encompass Intrusion Detection Systems (IDS), Endpoint Detection and Response (EDR), Next-Generation Firewalls (NGFW), Data Loss Prevention (DLP), Cloud Access Security Brokers (CASB), and more. Furthermore, a substantial volume of raw information, including event logs from diverse systems and applications, necessitates analysis and decision-making. This cumulative workload places immense pressure on CSOC analysts, resulting in an upsurge in poorly processed events, longer response times, extended event processing durations, and inevitably, an increase in the number of false positives. To address these challenges, two viable options emerge: 1.Augment CSOC funding by recruiting additional analysts. However, this approach is not without its hurdles, including a scarcity of qualified specialists in the job market and the potential for inflated financial costs, which may not align with optimal business decisions. 2.Develop an integrated system designed to detect malicious actions comprehensively. A key component of such a system involves the sophisticated detection of anomalies and responding not solely to individual events but to the anomalies themselves.
Криптографічий захист інформації (КЗІ) є важливою складовою інформаційної безпеки держави, безпосередньо пов’язаною з подоланням сучасних проблем та викликів в кібернетичному просторі України, нових загроз інформаційній безпеці в критичних інфраструктурах в оборонній та сфері безпеки, промисловості, банківському секторі, економіці тощо. Особливу небезпеку в цьому змісті становлять нові ризики, пов’язані з розробкою та стрімким впровадженням сучасних та перспективних інформаційних технологій, здатних докорінно змінити архітектуру інформаційних систем, існуючі парадигми, сталі принципи побудови та математичні основи сучасних засобів КЗІ. Зокрема, поява та стрімке удосконалення нових обчислювальних засобів, заснованих на принципах та ефектах квантової фізики (т.з. універсальних квантових комп’ютерів) ставить під загрозу саме існування діючих нині та стандартизованих на національному та міжнародному рівнях механізмів (протоколів, алгоритмів та засобів) асиметричної криптографії.
На сьогоднішній день рівень інформаційних атак, які включають в себе людський чинник значно збільшується. Велику їх частку складає збір інформації за допомогою фішингових і інсайдерських атак, соціального інжинірингу та інших видів кібератак. Ключова проблема ефективного виявлення відповідних атак, полягає в тому, що параметри, якими можна описати певні процеси мають велику кількість складно описуваних понять, відношень та специфічних особливостей. Також, як слідство, простежується відсутність необхідних методів і систем, орієнтованих на оцінку пов’язаних загроз і ризиків та виявлення відповідних атак. З урахуванням цього відбувається зростання зазначених атак, та потреба в системах оцінки загроз та ризиків, пов’язаних з людським чинником. А розробка відповідних засобів формування функціональних обов’язків для оцінки загроз є однією із складових даної теми, яка дозволить розглянути загрози в соціотехнічних системах з позицій функціональних обов’язків персоналу певної системи є актуальним науковим завданням. Виходячи з цього, метою роботи є розробка методу формування параметрів функціональних обов’язків для оцінки загроз в соціотехнічних системах. В статті визначено базову структуру профіля співробітника та ключові позиції запропонованого підходу, що включають загальні характеристики співробітника та специфічні компонент профіля. А з урахуванням базової структури профіля сформувано параметри, що відображають певні функціональні обов’язки для подальшої оцінки загроз в соціо-технічних системах.
На сьогоднішній день рівень інформаційних атак, які включають в себе людський чинник значно збільшується. Велику їх частку складає збір інформації за допомогою фішингових і інсайдерських атак, соціального інжинірингу та інших видів кібератак. Ключова проблема ефективного виявлення відповідних атак, полягає в тому, що параметри, якими можна описати певні процеси мають велику кількість складно описуваних понять, відношень та специфічних особливостей. Також, як слідство, простежується відсутність необхідних методів і систем, орієнтованих на оцінку пов’язаних загроз і ризиків та виявлення відповідних атак. З урахуванням цього відбувається зростання зазначених атак, та потреба в системах оцінки загроз та ризиків, пов’язаних з людським чинником. А розробка відповідних засобів формування функціональних обов’язків для оцінки загроз є однією із складових даної теми, яка дозволить розглянути загрози в соціотехнічних системах з позицій функціональних обов’язків персоналу певної системи є актуальним науковим завданням. Виходячи з цього, метою роботи є розробка методу формування параметрів функціональних обов’язків для оцінки загроз в соціотехнічних системах. В статті визначено базову структуру профіля співробітника та ключові позиції запропонованого підходу, що включають загальні характеристики співробітника та специфічні компонент профіля. А з урахуванням базової структури профіля сформувано параметри, що відображають певні функціональні обов’язки для подальшої оцінки загроз в соціо-технічних системах.
Збільшення та удосконалення кібератак на інформаційні системи зростає щорічно, а використання сучасних систем виявлення вторгнень дозволяє швидко реагувати на нові види кібератак та вдосконалювати існуючі засоби захисту. Такі системи достатньо розвинуті, але для їх ефективної роботи необхідна інформація у режимі реального часу, з використанням якої можливо виявляти підозрілу активність неавторизованої сторони. Таку інформацію можна проаналізувати з використанням експертних підходів. Експертні методи можуть допомогти виявляти нові неочікувані кібератаки. Використання методів, моделей і систем на основі теорії нечітких множин при побудові засобів виявлення аномалій, породжених реалізацією нових кіберзагроз, дозволить удосконалити та зробити більш ефективними існуючі системи виявлення вторгнень. А розробка відповідних технічних рішень, що працюють в нечітких умовах, дозволить виявляти раніше не відомі та модифіковані види кібератак. Також є досить ефективні розробки, які використовуються для вирішення завдань виявлення кібератак, наприклад, низка методів формування еталонного субдовкілля для системи виявлення вторгнень, але вони не орієнтовані на фішингові підходи. Однак, як показує практика, при появі нових загроз та відповідних аномалій, породжених атакуючими діями з невстановленими або нечітко визначеними властивостями, відповідні засоби не завжди залишаються ефективними, тому розробка методів, що дозволяють удосконалити процес отримання нового еталонного субдовкілля для системи виявлення вторгнень, є актуальним завданням. Одним із небезпечних засобів, який направлений на збір конфіденційної інформації, такої як логіни, паролі, фінансові реквізити та інші особисті дані є фішинг. Для цього розроблений метод формування еталонного субдовкілля для виявлення фішингових URL-адрес за рахунок сформованого набору параметрів: кількість країн за IP-адресою, вік домену та експертного оцінювання стану субдовкілля інформаційної системи дозволить формалізувати процес формування параметрів еталонного субдовкілля для вирішення задач, щодо виявлення фішингових URL-адрес.
One of the pressing areas that is developing in the field of information security is associated with the use of Honeypots (virtual decoys, online traps), and the selection of criteria for determining the most effective Honeypots and their further classification is an urgent task. The main products that implement virtual decoy technologies are presented. They are often used to study the behavior, approaches and methods that an unauthorized party uses to gain unauthorized access to information system resources. Online hooks can simulate any resource, but more often they look like real production servers and workstations. A number of fairly effective developments are known that are used to solve the problems of detecting attacks on information system resources, which are based on the apparatus of fuzzy sets. They showed the effectiveness of the appropriate mathematical apparatus, the use of which, for example, to formalize the approach to the formation of a set of reference values that will improve the process of determining the most effective Honeypots. For this purpose, many characteristics have been formed (installation and configuration process, usage and support process, data collection, logging level, simulation level, interaction level) that determine the properties of online traps. These characteristics became the basis for developing a method for the formation of standards of linguistic variables for further selection of the most effective Honeypots. The method is based on the formation of a Honeypots set, subsets of characteristics and identifier values of linguistic estimates of the Honeypot characteristics, a base and derived frequency matrix, as well as on the construction of fuzzy terms and reference fuzzy numbers with their visualization. This will allow classifying and selecting the most effective virtual baits in the future.
To effectively protect critical infrastructure facilities (CIF), it is important to understand the focus of cybersecurity efforts. The concept of building security systems based on a variety of models describing various CIF functioning aspects is presented. The development of the concept is presented as a sequence of solving the following tasks. The basic concepts related to cyberattacks on CIF were determined, which make it possible to outline the boundaries of the problem and determine the level of formalization of the modeling processes. The proposed threat model takes into account possible synergistic/emergent features of the integration of modern target threats and their hybridity. A unified threat base that does not depend on CIF was formed. The concept of modeling the CIF security system was developed based on models of various classes and levels. A method to determine attacker's capabilities was developed. A concept for assessing the CIF security was developed, which allows forming a unified threat base, assessing the signs of their synergy and hybridity, identifying critical CIF points, determining compliance with regulatory requirements and the state of the security system. The mathematical tool and a variety of basic models of the concept can be used for all CIFs, which makes it possible to unify preventive measures and increase the security level. It is proposed to use post-quantum cryptography algorithms on crypto-code structures to provide security services. The proposed mechanisms provide the required stability (230–235 group operations), the rate of cryptographic transformation is comparable to block-symmetric ciphers (BSC) and reliability (Perr 10–9–10–12).
The article analyzes the parameters of social networks. The analysis is performed to identify critical threats. Threats may lead to leakage or damage to personal data. The complexity of this issue lies in the ever-increasing volume of data. Analysts note that the main causes of incidents in Internet resources are related to the action of the human factor, the mass hacking of IoT devices and cloud services. This problem is especially exacerbated by the strengthening of the digital humanistic nature of education, the growing role of social networks in human life in general. Therefore, the issue of personal information protection is constantly growing. To address this issue, let’s propose a method of assessing the dependence of personal data protection on the amount of information in the system and trust in social networks. The method is based on a mathematical model to determine the protection of personal data from trust in social networks. Based on the results of the proposed model, modeling was performed for different types of changes in confidence parameters and the amount of information in the system. As a result of mathematical modeling in the MatLab environment, graphical materials were obtained, which showed that the protection of personal data increases with increasing factors of trust in information. The dependence of personal data protection on trust is proportional to other data protection parameters. The protection of personal data is growing from growing factors of trust in information. Mathematical modeling of the proposed models of dependence of personal data protection on trust confirmed the reliability of the developed model and proved that the protection of personal data is proportional to reliability and trust
Abstract. The article deals with issues related to the processing of aerial photographs, which were obtained while using emergency aerial monitoring systems. It shows the actual involvement of unmanned aerial monitoring systems to prevent, as well as localization of emergency. Here, the key information is aerial images having different properties, syntactic and semantic components, and also a plurality of landscaped areas, both of natural origin and man-made objects. With the help of aerial photos of various processing methods highlighted important information about the characteristics of semantic objects. A study is an informative description of aerial photographs as well as processing techniques justified selection of aerial photographs, at which manage to retrieve images from the most critical information, thereby reducing the flow of processed and transmitted over the communication channels. It is proved that dedicated key information from aerial photographs provides operator-interpreter in a timely manner, accurately make decisions to prevent crises and emergencies. The article deals with issues related to the processing of aerial photographs, which were obtained while using emergency aerial monitoring systems. It shows the actual involvement of unmanned aerial monitoring systems to prevent, as well as localization of emergency. Here, the key information is aerial images having different properties, syntactic and semantic components, and also a plurality of landscaped areas, both of natural origin and man-made objects. With the help of aerial photos of various processing methods highlighted important information about the characteristics of semantic objects. A study is an informative description of aerial photographs as well as processing techniques justified selection of aerial photographs, at which manage to retrieve images from the most critical information, thereby reducing the flow of processed and transmitted over the communication channels. It is proved that dedicated key information from aerial photographs provides operator-interpreter in a timely manner, accurately make decisions to prevent crises and emergencies.
На теперішній час в умовах широкого впровадження в економіку, оборонну і безпекову сфери цифрових технологій в усіх провідних державах світу гостро стоїть проблема забезпечення безпеки їх кіберпростору, особливо в умовах нових загроз, що породжуються використанням квантових комп’ютерів. Тому створення в Україні відповідної системи безпеки кіберпросторового довкілля національної критичної інформаційної інфраструктури, зокрема комплексів та засобів виявлення вторгнень, криптографічного та стеганографічного захисту інформації, є сучасною та актуальною проблематикою, що безпосередньо стосується пост-квантової інформаційної та кібербезпеки нашої держави, а також має важливе загальнодержавне та оборонне значення і суттєво впливає на забезпечення національної безпеки України в умовах ведення інформаційних і гібридних війн. Виходячи з актульності проблеми забезпечення національної безпеки України в умовах ведення інформаційних і гібридних війн, метою є удосконалення систем спеціального призначення за рахунок побудови комплексів криптографічного захисту інформації пост-квантової безпеки Державних електронних інформаційних ресурсів. Реалізовано проекти з розробки та впровадження програмно-технічних комплексів та апаратних засобів КЗІ для надавачів електронних довірчих послуг Збройних сил України, Міністерства внутрішніх справ, Державної прикордонної служби, Державної податкової служби України, Національного банку України, Приватбанку, Укрсіббанку, Альфа банку тощо, включно по два технологічні центри сертифікації ключів для Центрального засвідчувального органу України та засвідчувального центру Національного банку України. Таким чином, розроблені програмно-технічні комплекси та апаратні засоби КЗІ створили безпечне пост-квантове довкілля для державних електронних інформаційних ресурсів.
На сьогодні, одними із розповсюджених систем захисту інформації є системи виявлення кібератак та системи виявлення вторгнень, останні з яких становлять особливий практичний та науковий інтерес. Також, функціональність сучасних систем виявлення та блокування вторгнень у значній мірі залежить від їх можливостей щодо виявлення нових кібератак у режимі реального часу. Для виявлення відповідних атакуючих дій використовуються спеціальні методи, моделі, засоби, програмне забезпечення і комплексні технічні рішення для систем виявлення вторгнень, які можуть залишатись ефективними при появі нових або модифікованих кіберзагроз. Однак, як показує практика при появі нових загроз та аномалій, породжених атакуючими діями з невстановленими або нечітко визначеними властивостями, відповідні засоби не завжди залишаються ефективними. Отже, розробка засобів верифікації та проведення експериментальних досліджень відповідних технічних рішень, засобів і програмного забезпечення виявлення кібератак, зловживань та аномалій в інформаційних системах для підтвердження адекватності їх роботи є актуальним науковим завданням. Є низка робіт, таких як кортежна модель формування атакуючих середовищ, низка методів для виявлення аномальних станів, методологія побудови системи виявлення вторгнень, а також структурна модель обчислювальної системи для створення засобів виявлення кібератак та її алгоритмічне і програмне забезпечення. Для її верифікації необхідний спеціалізований емулятор кіберзагроз, оскільки відомі не підтримують необхідні формати даних, що застосовуються у авторській розробці. Виходячи з цього, метою роботи є розробка емулятора для проведення експериментального дослідження для підтвердження достовірності отриманих теоретичних положень, практичних результатів та адекватності роботи програмного модуля розробленої системи виявлення кібератак, що дозволить удосконалити функціональні властивості сучасних систем виявлення вторгнень для режиму реального часу.
Nowadays, one of the relevant areas that is developing in the field of information security is associated with the use of Honeypot (virtual lures, online traps), and the selection of criteria for determination of the most effective Honeypot and their further classification is an urgent task. There are presented the main products in which virtual lures technology is implemented. Often they are used to study the behavior, approaches and methods that an unauthorized party uses for unauthorized access to information system resources. Online traps can imitate any resource, but more often they look like real production servers and workstations. There are known a number of fairly effective developments that are used to solve the problems of identifying attacks on the information systems resources, which are based on the fuzzy sets apparatus. They showed the effectiveness of using the appropriate mathematical apparatus, the use of which, for example, to formalize the approach for the formation of a set of criteria, will improve the process of determining the most effective Honeypot. For this purpose, there have been proposed criteria that characterize online traps, with the use of which there has been developed a method of linguistic variable standards formation for choosing the most effective Honeypot. The method is based on the formation of a set of Honeypot, subsets of characteristics and identifier values of linguistic estimates of Honeypot characteristics, a base and derivative frequency matrix, as well as on the construction of fuzzy terms and standard fuzzy numbers with their visualization. This will allow further classification and selection of them osteffective virtual lures.
There are many ways to organize authentication and authorization in information systems. Typically, authentication is used to provide login, and authentication is primarily a security tool for personal user data. It is the first level of protection against receiving any system information. In turn, authorization helps ensure data integrity when running multiple different users with different permissions. The security of information and communication systems includes the protection of information circulating in computer systems designed for storing, searching and processing information (databases, application programs, control systems for various devices, etc.) and computer systems intended for disseminating information (Internet, local control and wireless networks, mobile communications, radio communications, satellite communications, etc.), from unauthorized access, counterfeiting and destruction. In our time, the information and communication revolution is the most urgent task, the solution of which is important for security in various areas of human activity that use computer technology and telecommunications. This article considered the existing mechanisms of authentication and authorization, and their advantages and disadvantages that affect the cybersecurity of informational systems. Theoretical and methodological requirements for the use of standardized methods of information systems log in are stated.
The vast majority of intrusion detection systems are becoming an integral part of the protection of any network security, they are used to monitor suspicious activity in the system and to detect the attacking actions of unauthorized side. Activation of cyber attacks initiates the creation of special technical solutions that can remain effective when new or modified types of cyber threats appear with unidentified or indistinctly defined properties. Most of these systems are aimed at identifying suspicious activity or interfering to the network in order to take adequate measures to prevent cyber attacks. Actual intrusion detection systems are those that are focused on identifying anomalous states but they have several disadvantages. More effective are expert approaches based on the use of knowledge and experience of specialists of the relevant subject area. Creation of technical solutions and special tools (for example, software for attack detection systems, which allow to detect previously unknown cyber attacks by monitoring the current state of indistinct parameters in a weakly formalized environment), based on expert approaches, is a promising area of research. Based on the well-known cyber attack detection system, which is based on an anomaly detection methodology (generated by cyber attacks) and a variety of relevant methods and models of the proposed software, which, due to the basic algorithm and a set of developed procedures (coordinate grid configuration; initialization of values based on a set of databases data and modules; graphical formation of parameters; search for common points according to the basic rules and graphical interpretation of the result) allow to automate the parameter standards formation process for modern intrusion detection systems and to reflect the results of the detection of anomalous state in a predetermined time interval.
Due to the intensive development of the digital business, malicious software and other cyber threats are becoming more common. In order to increase the level of security there are needed appropriate special countermeasures, which are able to remain effective when new types of threats occur and which allow to detect cyber attacks targeting on a set of information system resources in fuzzy conditions. Different attacking effects on the corresponding resources generate various sets of anomalies in a heterogeneous parametric environment. There is known a tuple model of the formation of a set of basic components that allow to identify cyber attacks. For its effective application a formal implementation of the approach to the formation of sets of basic detection rules is necessary. For this purpose, there has been developed a method that focuses on solving problems of cyber attacks detection in computer systems, which is implemented through three basic steps: formation of anomaly identifiers subsets; formation of decisive functions; formation of conditional detection expressions. Using this method, it is possible to form the necessary set of detection rules, which determine the level of anomalous state of values in a heterogeneous parametric environment, characteristic for the impact of a certain type of attack. The use of this method at the creation intrusion detection systems will expand their functionality regarding the cyber attacks detection in a weakly formalized fuzzy environment.
With the development of information technologies, the amount of vulnerabilities and threats to various data processing systems is increasing, therefore specialized means of security are required to ensure their normal operation and to prevent intrusions, and a promising area that is actively developing in the field of information security is the detection of cyber attacks and the prevention of intrusions in information systems from the unauthorized side. In order to detect network intrusions there are used modern methods, models, tools and complex technical solutions for intrusion detection and prevention systems, which can remain effective when new or modified types of cyber threats appear. Therefore, there was conducted a generalized analysis of the intrusion detection systems software based on a certain basic set of characteristics («Cyber Attack Class», «Adaptability», «Detection Methods», «System Control», «Scalability», «Observation Level», «Reaction to Cyber Attack», «Security» and «Operating System Support»). It will give certain opportunities for choosing such tools and for developing the most effective security mechanisms during cyber attacks.
Due to the development of digital business and the Internet, malicious software and other cyber threats are becoming more prevalent and pervasive. In this regard, the necessary means to detect cyberattacks on various resources of information systems. For this purpose, special means of combating that is able to remain effective when new types of threats, characterized by unknown or vaguely defined criteria. Apply required methods and models of information security based on fuzzy sets for building detection of anomalies generated by the corresponding offensive environment [1], is the basis for successful response to cyberattacks. Important in detecting anomalies, generated by cyberattacks, is the formation of fuzzy standards [1]. On this basis, the development of methods that improve the process of formalization of receiving linguistic standards of the parameters for the intrusion detection systems, there is actual scientific task. A number of famous, quite effective developments used to solve these problems, detect cyberattacks, such as: the tuple model to form the basic component for the detection of cyberattacks [1], fuzzy approaches to intrusion detection and detecting anomalies, as well as other developments that are used for solving problems in fuzzy environment [2]. For effective application of known models [1], [3] the formal implementation of the process of formation of fuzzy (linguistic) standards that will allow in a given linguistic variable identifies the search term [4]. On this term by using the corresponding sets of rules to determine the level of abnormal condition created by the impact of the corresponding class of cyberattacks. Based on the analysis of existing research and the relevance of the task the aim of this work is to develop an improved (generalized) method of formation of linguistic standards (MFLS) for intrusion detection systems, operating in formalized fuzzy environment.
The intensive development of information systems has led to an increase in destructive software, many of which are aimed at obtaining confidential information, which is directly related to the emergence of attacks like 0-day and non-signature types of cyber attacks. Expanding the impact of cyber attacks directed at various resources of information systems initiates the creation of special counter-measures that can remain effective when new types of threats emerge with undefined or indistinctly defined properties. There are known, quite effective developments used to solve problems of detecting cyber attacks, for example, the method of forming linguistic etalons for intrusion detection systems, in which the mechanism of the process of forming parameter etalons for attack sniffing is not disclosed. For this purpose, a model of linguistic variables has been developed to detect sniffing attacks, which is due to the evaluation of the state of the information system and the process of forming parameter standards: the number of incoming packets in the network, the speed of processing packets on the receiver side, the timing of packets in the channel, will allow to formalize the process of obtaining parameter etalons for given linguistic variables of a particular environment in solving problems of detecting attacks in computer systems. Such models can be used to improve the effectiveness of information security tools aimed at countering sniffing attacks in computer networks.