We consider a problem of socially significant behavior rate estimates in terms of probabilistic graphical models. Such formal description of the problem allows applying powerful methods and developed algorithms of the theory of Bayesian belief networks. We can use existing software to make computational simulations and apply the model to solve practical tasks. We describe a simple model based on the incomplete data about time intervals between behavior episodes and propose ways of its development.
The paper offers an improved method for respondents' behavior parameters estimates based on data about several last episodes. We try to avoid an assumption (which often is not correct) that the next behavior episode happens at the same time as the moment of interview does. The paper outlines some disadvantages of previous method and proposes modeling and processing of uncertainty related to a correct representation of the interview time moment and the next episode. The developed software calculates estimates according to the considered models and supports making numerical experiment.rate estimaterate estimaterate estimate
Article is devoted to the results of sociological research, held by the SPIIRAN laboratory's employees. This research was devoted to the revealing interrelations between psychological features, vulnerabilities and possible actions of information system's users, who are under the threat of socio-engineering attacks. Structuring the user's vulnerability profile is based on this research. Moreover, this research is experimental intermediate level between user's psychological features profile and user's vulnerability profile. Further direction of research phases are based on the current paper.
The prototype of the program complex, used for demonstration of basic possibility for estimation the protection of personnel of information system from socioengineering attacks on the base of generalized approach, focused on analysis of trees of attacks, is described. The representation of information system and its personnel in the specified program complex is based on hierarchy of information models, which consist of information model of the user, information model of the users group, information model of control area, information model of hardware and software complex, information model of critical information objects (system of documents), information model of information system itself and links between corresponding objects. The list of technologies, used during the development of this product, the reasons for using this technologies and brief substantiation of some technical solutions are worked out. The example of proceeding of program complex prototype during editing the information about socioengineering attack, as well as during the imitation of socioengineering attack on the recompensation type on the personnel of this system is considered.
Current paper is devoted to the review of the results of researches on psychology, concerned characteristics of person-user vulnerability, and forming demands, based on this researches, to informative model of the user, which can be integrated to the informative system for analyzing the protection of this system from socioengineering attacks. Intended and unintended actions of the user was examined, and on this base requirements to the informative model of the user has been made, which includes critical user properties, which influences more than others on the rate of success of socioengineering attack, made on this user. information gained from modeling will help to prognoses (imitate) reaction of the user like an answer to the attack action.
The prototype of the program complex, used for demonstration of basic possibility for estimation the protection of personnel of informative system from socioengineering attack on the base of generalized approach, focused on analyze of trees of attacks, is described. The representation of informative system and its personnel in the specified program complex is based on hierarchy of information models, which consists of information model of the user, information model if the users group, information model of control area, information model of hardware and software complex, informative model of critical information objects (system of documents), information model of informative system itself and links between corresponded objects. The list of technologies, used during the development of this product, the reasons for using this technologies and brief substantiation of some technical solutions is resulted. The example of proceeding of program complex prototype during editing the information about socioengineering attack, as well as during the imitation of socioengineering attack on the recompensation type on the personnel of this system is considered.
The paper presents results of a stage of research devoted to approaches to an estimation of rate of risky behavior. The paper contains the description of ways of formation of the specified estimation of the rate on the basis of the maximum and minimum interval, and also an median interval between the behavior episodes. A solution of the problem is based on formation and the analysis of formulas for distribution (and joint distribution) functions corresponding to ordinal statistics, distribution density, and also on a choice of values of their parameters. Several approaches to the analysis of quality of the received estimations are offered.
This paper is devoted to developed description of informative model of the user, who may be under the threat of socioengineering attack, and some other models, which is connected to the first one: users group model, model of control area, informative objects (documents) model. Specified informative model are included into the base for analyzing of the protection of users of informative system from socioengineering attack. Informative model of the user allows to consider name and surname of the user, his post in the organization, belongings of user to user group, and vulnerability of the user on socioengineering attacks. informative model of user group allows to consider name of user group, it's description, allows for different atomic actions which user can perform with informative objects, type of access to information objects and information objects, which this group of users can use. Informative model of control area allows to consider name of control area and it's description. Information model of information objects includes damage estimation of losses of confidentially, losses of integrity and losses of sufficiency. The example of socioengineering attack is brought. Development of this attack is described through suggested informative models.
The paper offers a method for respondents' behavior modeling based on data about last episodes adjacent to interview and proposes improved techniques of modeling and processing of initial data uncertainty based on hybrid probabilistic and fuzzy approaches. This paper provides analytical (including asymptotic) analysis of these estimates and numerical behavior rate estimates according to the model. Software supplements enabling to fulfill numerical experiments realizing the proposed processing procedures were worked out.
We describe a technique that improves the beta-prime models fitted for the last episodes of risky behavior. Regression models show interconnections between rate parameters and respondents’ demographic and psychological trades. We examine these models using such criteria as jackknife and test of overdispersion. Also we develop a method for uncertainty processing in case of a special type of respondents’ answers (―today‖ answers) about the time of their last behavior episode.
An improved approach to behavior rate estimates on the base of data about minimum, maximum and usual interval between behavior episodes is considered. The mathematical model of this behavior is a Poisson stochastic process; the observations are respondents’ natural language answers about mentioned intervals. The considered method takes account of data granularity; it is based on the analysis of ordinal statistics and method of randomization. In the paper, there are several examples of the estimates applications to some other types of socially significant behavior, including risky behavior.
Developed description of informative models of the component of complex “in-formative system – personnel”, which is under threat of socioengineering attack is being presented in this paper. Informative model of user, users group, controlling areas, information objects (system of documents), hardware-software maintenance and information system itself are considered. Specified informative models are included into the base for analyzing protection of informative system under the threat of socioengineering attacks. Hierarchy of these models allows to describe scene (context), in which socioengineering attack developes, to touch possible attacks (trees of attacks), and, on the base of gained results, study possible approaches to estimation the degree of protection of complex “information system – personnel” from socioengineering attack.
The paper presents estimations of intensity of risky behavior and risk, with it connected are deduced. The approach to check of a coordination of estimations of the specified indicators received in the various ways under the various initial data is offered.
The article developed a model calculation of the relative frequencies of events count processes based on the use of Bayesian networks of trust. Use of the ratio of risk and the associated transition matrix is a convenient and intuitive tool for tracking changes in the processes associated with risk. Describes the need for and approaches to sampling random variables. Parameterization of the network considered for the cumulative risk of relative frequencies. Numerical examples are considered as implemented in GeNIe&SMILE which allows to design and implement graphical models probabilistic inference.
We develop a technique for quantitative estimates of respondents’ behavior that uses respondents’ answers about the time interval since the last episode. The paper provides the block of questions and formalized set of answers to be used in a questionnaire as well as the mathematical approach for data processing and making the estimates. The respondents’ behavior mathematical model under discussion belongs to the class of generalized Gamma-Poisson stochastic process and takes into account the length bias inherent to the data collected from the respondents’ answers about the last episodes of their behavior.
The paper is devoted to the theoretical consideration of psychological traits underlying user’s vulnerability under the threat of socio-engineering attack, their properties and features. For the convenience of the subsequent studying of socio-engineering attacks and their prevention a detailed classification of psychological traits on various parameters is presented, including the way of proceeding, character of caused action of the user, etc. While constructing classification 2 main classes have been allocated: psychological characteristics and social and personal factors influencing the vulnerability of a person. Also, the further subdivision of these classes to subclasses is presented, vulnerabilities’ interrelations have been determined and corresponding block diagrams and tables reflecting these characteristics are presented. What is more, indicators and scales of the users’ vulnerabilities have been presented, their core parameters were revealed and summarized in the users’ vulnerabilities complete list. The conclusion about the further direction of research based on the fulfilled work has been made in the end of the article