Purpose of reseach. In the tasks of authenticating groups of messages encoded in the mode of chaining blocks, there is a need for the formation and processing of specific tree-like structures. The contents of such structures, in addition to information about the placement of data in the internal memory of the calculators, describes the relative location of messages in the data stream between subscribers of a peer-to-peer network. This information is necessary to isolate a structured set from the entire message stream to the receiver, for which its source is uniquely determined. Using approaches to segmentation of tree structures allows you to parallelize the processes of adding elements to it and searching for areas corresponding to an authentication error.Methods. The division of the tree structure into areas subject to modification and areas for analysis is based on a metric dynamically formed from message authentication codes – the position of a specific message in a structured set of messages transmitted from the source to the receiver. The value of this metric determines the distance from the root of the tree, which defines the boundary between the two named areasResults. By isolating the modified and analyzed sections of the tree structure, races of processes implementing independent algorithms for working with it are excluded. The possibility of detecting authentication errors before receiving the last message in a structured set of messages is shown. As a result, there is no need to transmit those group messages that were supposed to be sent after the error was detected. Formulas for estimating the average transmission time of multiple messages with sequential and parallel implementation of procedures for the formation and processing of a tree structure containing descriptors of incoming messages to the receiver are given.Conclusion. The paper shows that the parallel implementation of algorithms for adding elements to the tree structure and the algorithm for searching for areas corresponding to an error reduces the average transmission time of a group of messages by 5-12% compared with the sequential implementation of these algorithms. This reduces the load on the communication channel for the target class of systems using block coupling encoding for authentication.
The purpose of the research is to analyze the efficiency of the U-net neural network architecture in decision support systems for glioma diagnostics and segmentation of brain areas affected by it on MRI images.Methods. To conduct experimental studies, a training dataset was generated and the data was normalized. A software implementation of the U-Net neural network architecture was performed using the Keras framework in the Python programming language. The neural network model was trained.Results. A series of experiments were conducted, during which error and classification matrices were obtained, the efficiency of classification of the trained neural network model for the "Tumor" and "No tumor" classes was assessed using metrics such as Recall, Precision and F1-measure, and the quality of segmentation of glioma-affected areas on the test data set was assessed. The quality of segmentation was assessed using the IoU metric, which reflects the ratio of the areas of the bounding boxes and is used to assess the accuracy of the spatial correspondence of the predicted segmented areas highlighted on the masks. Based on the results of testing the neural network model in solving the problem of segmenting brain areas affected by glioma, the average value of the IoU metric was 0.812, which is an acceptable result.Conclusion. The testing results showed that the neural network model based on the U-net architecture is able to effectively diagnose the presence of glioma with acceptable values of the classification and segmentation quality metrics, which indicates the possibility of using this neural network model in medical decision support systems for glioma diagnostics, as well as its segmentation on MRI images. However, it is advisable to refine this neural network model to reduce the number of false negative classification results, which is critically important in medical diagnostics.
Purpose of research is to create a method for determining the source of messages in the receiver, which allows, based on the analysis of the characteristics of the distribution of the time of receipt of messages, to increase the reliability of determining the source. Methods. Authentication of the message source is based on statistical analysis of metadata values, which in this study are the time intervals between messages. The metadata processing model is based on the well-known model of receiving messages from the target source in LoRaWAN networks. At the same time, the source was determined using coding methods in the block coupling mode, which provide higher identification reliability for short-length messages characteristic of the specified type of networks. With the help of numerical modeling, the patterns of changes in the characteristics of the time of receipt of messages in the event of an identification error were determined. The decision-making rule is also formulated in case of impossibility of authentication based on processing the contents of identification fields. Studies have shown the effectiveness of the application of the source detection model in various ranges of parameters for the formation of message sequences. Results. The result of the conducted research is the development of an authentication method based on the analysis of the time of receipt of messages to the receiver, which differs in that it uses the characteristics of the distribution of moments of high orders for a series of time delays as the analyzed data. Its use in combination with coding methods in the message concatenation mode reduces the probability of a single message replacement error in a sequence by 4-6 times, compared with methods that perform identification only based on the results of processing the identifiers of the messages themselves. Conclusion. The result of experimental studies has shown the possibility of using the developed method to increase the reliability of determining the authenticity of the source of messages, the possibility of reducing the number of reinquiries that occur when errors are detected, the possibility of reducing the size of additional identifier fields in each message. The resulting effect will be expressed in a general increase in the bandwidth of the communication channel between remote components of a distributed system.
Purpose of research. In some classes of information systems, it is impossible to use well-known algorithms for the identification and the authentication the data blocks sources. The reason for this is the duration of the full data processing cycle. The article considers the original algorithm for determining sources for a group of data blocks. It allows you to detect errors faster than the usual iterative algorithm for forming tree structures of blocks by changing the order of base operations. The purpose of the work is to reduce the computational and resource costs for the receiver to perform identification the sources of blocks, each of them has a size not exceeding a few bytes.Methods. The identification method based on the forming a tree structure of incoming information blocks and subsequent analysis of tree branches. It allows selecting a chain of blocks formed by the target source. In the article the formal description of the algorithm is given. The results of the simulation of the procedures for determining the source are presented. In this case, the characteristics of the recursive algorithm were compared with those obtained for the known iterative one.Results. The relationships between the average number of typical hash comparison operations, the average number of tree structure branches, and the number of accepted blocks obtained as a result of simulation modeling. This made it possible to determine the conditions for applying the recursive and iterative algorithms.Conclusion. It is shown that the using of a recursive algorithm for forming a tree structure of frames can reduce the average number of base operations performed by the receiver by 5-10 % and reduce the memory cost for storing tree structure branches by up to 30%.
In order to increase the reliability of legal data and for the proper operation of the hardware and software systems, it is necessary that the hardware component receives data only from the corresponding software. Otherwise, the data received from extraneous programs can lead to errors in the operation of the device or even a complete loss of its functionality or data. In order to identify the challenges of the transfer of blocks, this study focuses on a comprehensive study of the problems arising from the transmission of information in the form of separate data blocks and of the influence of the number of unauthorized blocks on the probability of collisions. In this study, we describe a method for distinguishing legal software data from data sent by unauthorized software sources. The analysis of the methods of reducing the probability of errors occurring at the receiver is done through the use of a buffer to store and a set of mathematical equations. The same way the analysis of the methods of possibility of reducing the reception of the unauthorized blocks when receiving individual blocks of information is done as well. Finally, we measure the extent of the effect of intensity of receiving unauthorized blocks and hash field length.
In this paper we describe the method which allows the separation of legal software data from the data that is sent by extraneous software sources in order to increase the reliability of legal software data. This is done through the use of a buffer to store legal software data by using a set of mathematical equations. The combination of reversible and irreversible transformations is the basis of secure data messages formation algorithm. Having finished the reception, the receiver starts the analysis of the data written in the buffer and makes chains of words. We also describe the mathematical models which allow us to get the numerical values of the presented method. The article show the size of the buffer influences the security of data transmission system. The best correlations between the parameters of formation of secure data transmission algorithm are determined. At the same time the article reveals the problem of collisions during the transmission of secure messages. By collision in this work we understand situation, when hardware selects two or more different chains from buffer. It is shown that by variation of parameters of secure data analysis algorithm we can reduce the possibility of authentication mistakes by a factor a 10.
Purpose of research is to build a model of a system for effective authentication of mobile users based on public data of the user and his behavioral factors as well as to study algorithms for calculating the threshold value at which the authentication of a mobile device user is considered successful.Methods. When analyzing the behavioral factors of a user who needs to be authenticated when interacting with mobile devices, application of the following methods for calculating the threshold value are proposed: dynamic methods for determining the threshold value of user authentication based on the standard deviation and the calculation of the aggregate mean score; the method based on the standard when the system divides the aggregate flow of estimates into several blocks of the same length, where the first block is used for training, and the calculated threshold is used in the second block (this sequence of actions is repeated continuously, that is, the previous block provides training results for calculating the threshold for the current block); a method for calculating the aggregate mean score, where instead of using a single total score as input, the system uses the mean value of the current block, and the new calculated threshold is used as the threshold for decision making for the next block. A mathematical model that balances the speed and reliability of mobile users authentication is proposed.Results. The result of the research is the development of an effective system for calculating the threshold value of successful authentication of a mobile device user based on behavioural features which adapts to changes of the user's behavioural factors. Experimental studies and comparisons with analogs confirming the completeness and correctness were carried out as well as various variants of the proposed solutions.Conclusion. The proposed method of implicit authentication for mobile access control is easy to implement, easy to use, and adaptive to changes in input data. Options for calculating the threshold value at which implicit authentication is considered successful are also proposed.
Context. For the proper operation of the hardware and software systems, it is necessary that the hardware component receives data only from the corresponding software. Otherwise, the data received from extraneous programs that can be perceived and processed by the device, which can lead to errors in the operation of the device or even a complete loss of its functionality or data. Objective. In order to increase the reliability of legal software data and identify the challenges of the transfer of blocks, this article focuses on a comprehensive study of the problems arising from the transmission of information in the form of separate data blocks. Method. The methods of integrity control in modes of transmission are described. The method based on hashes and block delivery time is analyzed in detail, analysis the methods of reducing the probability of errors occurring in the receiver and the possibility of reducing the reception of the extraneous blocks when receiving individual blocks of information. This is done by using a set of mathematical equations. And measure the extent of the effect of intensity of receiving extraneous blocks and hash field length. Results. In the process of analyzing systems in which information is transmitted by block, when using the method of formation of information chains based on the method the hashes and the delivery time of the block, where we note, when the value of the hash field is equal to 6 or more, the probability of occurrence of duplicate branches is acceptably low. Where, when hash field more then 6, the parameter of length of a chain practically does not affect the final probability of constructing a chain from the extraneous blocks. The very same value of the probability of constructing a false chain, the length exceeding the chain of legal blocks at hash field more 6 is aboutl 10-3, which it's acceptable for real information transmission systems. Conclusions. Based on the analysis, we can conclude that in systems in which information is transmitted block by block, when using the method of generating information chains based on the hash and block arrival time, with a hash field of 6 or more, the probability of occurrence of duplicate branches is acceptably low.
Purpose of research. Currently, various technologies and methods are used to control the integrity and authenticity of data transmitted through open communication channels. One of them is the technology for transmitting sequences of information packets connected to each other in chains using certain cryptographic algorithms. Similar approaches are used in the well-known blockchain technology and are focused on large volumes of transmitted and protected information and large sizes of additional service information fields. The purpose of this article is to study the characteristics of systems, transmission of small information packets in comparison with traditional size frames of TCP/IP stack, in which the broken packet sequence order is restored using the chain method, by analyzing hash sequences available in each of such packets.Methods. In this article, simulation modeling, system analysis method, method of systematization and ranking of the obtained results are used.Results. It is shown that increasing the size of the additional field with the hash of the previous message from 4 to 6 bits has a significant effect on reducing the probability of erroneous restore of the order of information packets. Further increasing the length of the hash field reduces the probability of error by only 2 to 5 % for each additional bit of the hash field for any length of the chain being restored. It is shown that the coefficient of the usage of the communication channel (the ratio of useful chain of packets to the volume of information transmitted through the communication channel) is maximum when the length of the hash field is 6 in the whole range of sizes of the field information part of the data packet.Conclusion. The paper shows that the chain method is applicable for restoring the original sequence of information packets transmitted from the source to the receiver in systems where the preservation of the sequence of packets is not guaranteed. The obtained values of the transmission system parameters allow us to ensure acceptable reliability of data transmission with a minimum amount of additional service information, and achieve information redundancy less than that in similar ones by 10-15.
Purpose of reseach is to develop a model of the system for effective collection of information about the network access object based on modern information protection methods as well as to create a kind of the reconfiguration environment in the event of a failure of computer network elements or the need to redistribute the server load. Methods. A flexible, controlled version of developing a system has been proposed for the process of collecting information about the object under study; it makes it possible to automatically identify potential vulnerabilities in the field of information security [1]. It is proposed to use the analysis of the state of an object based on the black box technique, since it makes it possible to reproduce the actions of an external intruder who does not have any information about the object at the initial stage of preparation (which is the most common scenario when adding new services) and conduct typical attacks with subsequent security evaluation [2]. A mathematical model that improves system fault-tolerance and real-time load balancing is proposed. Results. The result of the research is the development of an effective construction of a system for assessing the state of object security. A mathematical model that makes it possible to reconfigure the environment of computing modules in real time has been developed. Experimental studies confirming the completeness and correctness of the proposed solutions have been carried out. Conclusion. The proposed system is designed to analyze the compliance of the protection object with the requirements of an information security policy; it includes the stages of system analysis using the black box technique and performs the tasks of an automated testing process, system components distributions, system modules interchangeability. Together with the developed mathematical model for improving fault-tolerance and redistributing the load on computational power in the event of equipment malfunctions and bypasses in the case of complete load of the elements, the system demonstrated a decrease in the time for conducting a comprehensive assessment of the information security state of the network access object.
Рurpose of research is to develop a multithread processing system based on an encryption algorithm using cellular automata and to study statistical performance indicators depending on the hardware components and the size of the input block, and to develop recommendations for improving the cryptostrength of the method. Methods . A mathematical model of the encryption method using a floating window based on cellular automata was considered [3]. To study the speed of confidential data processing, there was developed a variant of the organization of the structure of the software module with an extended block of setting parameters that determine the dimension of the matrix, the line of activation of the bit neighborhood of the processed elements, the number of parallel computations (threads) and the rule of expansion of the boundary elements of the matrix. A method for the development of the dependence curve of the processing time and inital parameters that can be applied both to process individual files and continuous network subscriber data flow, is proposed. Results. The cryptographic module implementing the encryption method on the basis of cellular automata, which specific feature is a multithread mode of operation and dynamic control of the block of initial parameters, was developed. Recommendations for setting the neighborhood of the active elements of the matrix and the number of threads taking into account the architecture of the CPU were formulated. Experimental studies were conducted to confirm the completeness and correctness of the proposed solutions. The expediency of using high-speed hard disk drives and saving the results of encryption in asynchronous segmented mode with working thread-bind results was revealed. Conclusion. The proposed version of the organization of the confidential data processing system in the form of a software module, taking into account the features of the hardware, allows optimization of the processing speed, and the compliance with the recommendations for the expansion of the neighborhood in the block transformation can improve the cryptographic algorithm based on cellular automata with a floating window.
The one-time password method is one of the most common and effective methods of authentication of the source and receiver of information. The main threat to the trusted communication channel of exchange information is a potential attacker who randomly generates and transmits messages to the receiver, that may be mistakenly perceived as an authenticated source. This article discusses an authentication method based on a modified one-time password method, in which the decision on the legality of the received message is made not only on the basis of the content of its verification sequence but also on the basis of the history of the received verification messages. The parameters of the algorithm for generating authenticated data are analyzed, the influence of these parameters on the probability of authentication errors in the communication channel is investigated.
The problem of the impact of destructive programs on hardware information protection systems is analyzed. Methods for monitoring the legality of commands of the software controlling protection hardware are proposed.