Анотація. Процес проведення державних експертиз комплексних систем захисту інформації (КСЗІ) та організація електронного обігу документів, створених на етапі проектних робіт мають низку проблем, а саме: уразливість інформації, яка зберігається на постійних носіях пам’яті; велику ентропію невизначеності інформації, що збільшує ризики помилок експерта при проведенні державних експертиз КСЗІ; проблема обігу паперових документів, які були створені на етапі предпроектних робіт, що збільшує ризики розкриття інформації з обмеженим доступом. Для вирішення зазначених проблем необхідно здійснити автоматизацію окремих процесів. Поставлена мета здійснюється шляхом розробки структурної моделі системи підтримки прийняття рішень (СППР) для реалізації експертиз КСЗІ, яка формується із взаємопов’язаних баз даних смислових змінних, множини критеріїв та шаблонів документів, а також модулів виокремлення смислових змінних, ідентифікації функціонального профілю захисту та взаємодії з експертом. Для реалізації структурної моделі був розроблений програмний застосунок, що підтримує два основних процеси: перший – пов’язаний з перевіркою відповідності функціонального профілю захисту (ФПЗ) вимогам НД ТЗІ; другий – орієнтований на виділення смислових змінних з вхідних документів та їх збереження у базі даних смислових змінних (БДСЗ). Зазначені рішення дозволяють розширити функціональні можливості сучасних СППР пов’язаних з реалізацією експертиз технічного захисту інформації.
To date, an increase in the key length inevitably leads to an increase in computational volumes to protect information flows using asymmetric cryptosystems, where the most common operations there is the modular multiplication and modular exponentiation. Existing methods and algorithms for performing above-mention operations are based on positional numerical systems that are characterized by considerable time complexity due to the limited possibilities of parallelizing the computation process, which leads to a decrease in their performance. Using of new approaches, in particular, the vector-modular method of modular multiplication and exponential, as well as the system of residual classes, will allow expanding the functionality of computing systems to encrypt / decrypt information. To this goal, a methodology which allows to increase the speed of asymmetric cryptosystems is proposed, and the basic mechanism of which is grounded on the eight stages: the formation of a plurality of open-ended blocks, the formation of requirements for cryptosystem parameters and information security, the choice of an asymmetric cryptosystem, the formation of a set of basic operations, the choice of the method of operations execution , the choice of the form of the system of residual classes, the choice of methods for constructing perfect and modified perfect forms of the system of residual classes, the implementation of basic asymmetries cryptosystems based on these approaches. The proposed methodology can reduce the temporal complexity, increase the speed of algorithms, specialized software and hardware during the processing of multi-digit numbers in asymmetric cryptosystems.
As information technologies progress further, the number of vulnerabilities and threats to various data processing systems increases, creating a need for specialized security tools to ensure proper systems functioning and intrusion prevention. A promising area of rapid growth within the field of information security is cyberattack detection and information systems intrusion prevention of unauthorized party access. To identify network intrusions, intrusion detection and prevention systems use modern methods, models, controls and integrated technical solutions that can remain effective when new or modified types of cyberthreats occur. In general, whenever new threats and anomalies are generated by attacks with unidentified or vaguely defined properties, these tools do not always remain effective and require extended time resources to adapt to aforementioned security gaps. Thus, intrusion detection systems must be continuously researched and refined to ensure their effective operational continuity. Such systems include specialized software that is designed to detect suspicious activities or information system intrusions and take sufficient measures to prevent cyberattacks. Source analysis has shown that the issue of rapid detection of exploits and anomalies is a major concern for modern information systems and networks. Most papers only include a partial analysis and classification of intrusion detection systems, and provide a general description of corresponding controls that does not address their wide variety and does not include a required set of characteristics needed for an integrated assessment of such systems. Therefore, the paper presents a generalized analysis of intrusion detection software using a defined basic set of characteristics ("Cyberattack Category", "Adaptivity", "Detection Methods", "System Management", "Scalability", "Observation Level", "Cyberattack Response", "Security"and" Operating System Support"), which will provide certain options when choosing such tools and developing for them the most efficient security mechanisms possible for mitigating cyberattack impacts.
In the article the method of expert evaluations and especially its application as an example the evaluation of information risks of higher education. The main feature of this method is that it is used in cases where the solution of the complicated mathematical methods. Due to the lack of reliable information static or even its absence on information security threats, the most common method of risk assessment information is the method of expert evaluations. Schematically presented action sequences according to the method of expert ratings formulating research objectives, the selection of experts and the formation of a task force drafting questionnaires, surveys, processing and analysis of expert opinion. A statistical tools for processing and analysis of the results of questioning of experts.
In the article the method of expert evaluations and especially its application as an example the evaluation of information risks of higher education. The main feature of this method is that it is used in cases where the solution of the complicated mathematical methods. Due to the lack of reliable information static or even its absence on information security threats, the most common method of risk assessment information is the method of expert evaluations. Schematically presented action sequences according to the method of expert ratings formulating research objectives, the selection of experts and the formation of a task force drafting questionnaires, surveys, processing and analysis of expert opinion. A statistical tools for processing and analysis of the results of questioning of experts.
The known information security assessment risk system (developed by authors) is based on processing methods of linguis-tic variables. These variables are based on the standard parametric trapezoidal fuzzy numbers with a fixed number of term sets. Eta-lons are defined by experts at the stage of base units initialization during setting-up system. Efficiency of its use would increase if it is available to correct etalons without the involvement of appropriate experts. To solve this problem authors propose a method of function realization for linguistic variables etalons transformation based on a single incrementation the terms number using expert estimates made during system setting-up. This will simplify the procedure for correcting etalons, by implementing a single process incrementation the number of terms for trapezoidal fuzzy numbers.
The known information security assessment risk system(developed by authors) is based on processing methods oflinguistic variables. These variables are based on thestandard parametric trapezoidal fuzzy numbers with afixed number of term sets. Etalons are defined by expertsat the stage of base units initialization during setting-upsystem. Efficiency of its use would increase if it isavailable to correct etalons without the involvement ofappropriate experts. To solve this problem authorspropose a method of function realization for linguisticvariables etalons transformation based on a singleincrementation the terms number using expert estimatesmade during system setting-up. This will simplify theprocedure for correcting etalons, by implementing asingle process incrementation the number of terms fortrapezoidal fuzzy numbers.
The construction of information security management system (ISMS), complex system of information security and other security systems require carrying out the analysis and security risk assessment. The existing assessment tools in its majority are based on statistical approaches. In many countries, both at the enterprise level and at the State level such statistics is not conducted. This limits the ability of existing tools, such as the use of different input data types for assessment. A known tool gives no the administration opportunity for risks analysis and risk assessment of a wide range of initial parameters. On t he basis of the proposed risk analysis and assessment method, which based on the use of the integrated model representation of the risk parameters allow to conduct an assessment in the deterministic and fuzzy conditions using ten parameters, which can be represented as numeric and linguistic form, it was implemented the software system of risk analysis and assessment of information resources losses. To verify the developed software product there were designed various situations connected with the information security resources. The received results confirm the adequacy of software response on value changes of estimated component under different environment conditions, while the risk value does not change significantly when the basis of estimated components is changed.
The construction of information security management system requires providing the analysis and security risk assessment that are often characterized by high fuzzy conditions. The existing assessment tools do not provide opportunities for risk analysis and risk assessment of a wide range of initial parameters. On the basis of the proposed risk analysis and assessment method it was implemented an appropriate software system. It allows making assessment in fuzzy conditions using the established assessment components, which are displayed by the model of the integrated concept of risk parameters and can be represented in both numerical and linguistic forms. To verify the developed software product it was implemented the modeling under a number of different environmental conditions. The received results confirm the adequacy of software response on value changes of estimated component under different environment conditions, while the risk value does not change significantly when the basis of estimated components is changed.
To implement the process of analysis and information risk assessment based on the expert judgments it is required to use some methods and means that make possible to handle with fuzzy input data, for example, presented in the linguistic form. There is a system where an assessment is based on the parametric trapezoidal fuzzy numbers. A practical implementation of this system requires an application of other types of fuzzy numbers. The development of capabilities of such system can be achieved through additional use of another type of parametric fuzzy numbers-triangular. To solve the task this paper suggests the conversion method of reference parameters, which provides an analytic function what enables to transform (the equivalent conversion) the terms of linguistic variables. Such a decision would make it possible to improve flexibility of developed means of analysis and information security risk assessment, which are based on the linguistic approach and use to describe the linguistic variables the triangular fuzzy numbers.
The providing of state information resources security is inextricably connected with information security intruder's activity in information & communication systems where restricted data is circulating. The modern intruder detection systems, based on heuristic principle of information security violation detection, have a disadvantage because these are basically oriented on mathematical models which require much time to prepare statistic data. Mathematical models based on expert approach are more effective in this way. The method proposed in paper allows to solve the problem of intruder detection and identifying in information & communication systems and networks, which are weakly-formalized fuzzy environment. In the method elements of fuzzy logic are used to the previous decision of the violation & the intruder identification and precise basis of conventional logic that provides clarifying identification. The method consists of such stages: selection of the method for determining the importance of factors, the formation of categories sets of intruder and parameters, forming standards of fuzzy parameters, forming the set of heuristic rules, forming connections of intruder category with parameters, phasing of fuzzy parameters and definition clear parameters, processing and forming of parameters corteges, results formation. The method's work is organized in three phases: preparation, work with fuzzy parameters and work with clear parameters. On the basis of this method can be synthesized heuristic type intruder detection & identification system with high performance in fuzzy terms by the use of expert methods.
The detailed analysis of problem is conducted and the method of estimation of size of quantitative and high-quality parameters of possible harm national safety of the state is developed in the case of disclosure of information which make a state secret or losses of financial carriers of secret data.
The paper represents the basic criteria for the selection of the analysis methods and Information security risk assessment. Based on these criteria and models for the integrated risk parameters presentation, it was created a structural diagram of the analysis methods and risk assessment selection. The proposed structural solution has become the basis for program implementation of the corresponding system. It provides the opportunity for practicing experts in the information security sphere, to carry out a choice of suitable toolkit more effectively, that in turn will significantly simplify the risk analysis and assessment problem solving.