Анотація. Процес проведення державних експертиз комплексних систем захисту інформації (КСЗІ) та організація електронного обігу документів, створених на етапі проектних робіт мають низку проблем, а саме: уразливість інформації, яка зберігається на постійних носіях пам’яті; велику ентропію невизначеності інформації, що збільшує ризики помилок експерта при проведенні державних експертиз КСЗІ; проблема обігу паперових документів, які були створені на етапі предпроектних робіт, що збільшує ризики розкриття інформації з обмеженим доступом. Для вирішення зазначених проблем необхідно здійснити автоматизацію окремих процесів. Поставлена мета здійснюється шляхом розробки структурної моделі системи підтримки прийняття рішень (СППР) для реалізації експертиз КСЗІ, яка формується із взаємопов’язаних баз даних смислових змінних, множини критеріїв та шаблонів документів, а також модулів виокремлення смислових змінних, ідентифікації функціонального профілю захисту та взаємодії з експертом. Для реалізації структурної моделі був розроблений програмний застосунок, що підтримує два основних процеси: перший – пов’язаний з перевіркою відповідності функціонального профілю захисту (ФПЗ) вимогам НД ТЗІ; другий – орієнтований на виділення смислових змінних з вхідних документів та їх збереження у базі даних смислових змінних (БДСЗ). Зазначені рішення дозволяють розширити функціональні можливості сучасних СППР пов’язаних з реалізацією експертиз технічного захисту інформації.
The development of information systems in the modern world is inextricably linked with the improvement of destructive software, which is aimed at the various resources of information systems. Among the various ways to influence the user, the most dangerous are those that masking by under the really existing software or web service and are trying to access the personal data of the user, or use its resources or software for fraudulent purposes. The activation of such attacks requires the creation of specialized means of detection and counteraction, which will be equally effective against both present and future cyber threats with unidentified or unclearly defined properties. That is, similar means can function in a fuzzy, poorly formalized environment. Modern methods, models and systems based on fuzzy sets can be used to construct and improve existing tools for detecting intrusions and anomalies in information systems that arise as a result of the implementation of cyber threats. There are a number of developments that are used when they are detected, one of which is the method of forming linguistic etalons for intrusion detection systems. In the described method, the mechanism of the process of forming parameters etalons for email spoofing attacks is not disclosed. With this in mind, a model of linguistic variables etalons was developed for detecting email spoofing attacks, which would formalize the process of obtaining parameter benchmarks. (the number of detected IP addresses in spam bases, the number of spam words in the topic, the number of spam messages in the message) for given linguistic variables of the selected environment when solving problems, in relation to detection of attacks. Similar models can be used to increase the effectiveness of information security measures aimed at countering email spoofing attacks in information systems.
As information technologies progress further, the number of vulnerabilities and threats to various data processing systems increases, creating a need for specialized security tools to ensure proper systems functioning and intrusion prevention. A promising area of rapid growth within the field of information security is cyberattack detection and information systems intrusion prevention of unauthorized party access. To identify network intrusions, intrusion detection and prevention systems use modern methods, models, controls and integrated technical solutions that can remain effective when new or modified types of cyberthreats occur. In general, whenever new threats and anomalies are generated by attacks with unidentified or vaguely defined properties, these tools do not always remain effective and require extended time resources to adapt to aforementioned security gaps. Thus, intrusion detection systems must be continuously researched and refined to ensure their effective operational continuity. Such systems include specialized software that is designed to detect suspicious activities or information system intrusions and take sufficient measures to prevent cyberattacks. Source analysis has shown that the issue of rapid detection of exploits and anomalies is a major concern for modern information systems and networks. Most papers only include a partial analysis and classification of intrusion detection systems, and provide a general description of corresponding controls that does not address their wide variety and does not include a required set of characteristics needed for an integrated assessment of such systems. Therefore, the paper presents a generalized analysis of intrusion detection software using a defined basic set of characteristics ("Cyberattack Category", "Adaptivity", "Detection Methods", "System Management", "Scalability", "Observation Level", "Cyberattack Response", "Security"and" Operating System Support"), which will provide certain options when choosing such tools and developing for them the most efficient security mechanisms possible for mitigating cyberattack impacts.
The overwhelming majority of intrusion detection systems become an integral part of the protection of any network security, they are used to monitor suspicious activity in the system and detect an attack by an unauthorized party. Ac-tivating of cyberattacks initiates the creation of special technical solutions that can remain effective when new or modified types of cyber threats appear with unidentified or unclearly defined properties. The majority of such systems are aimed to detect suspicious activity or interfering in the network to take adequate measures to prevent cyber at-tacks. Current systems for detecting intrusions are those that are aimed to identify abnormal states, but they have a number of disadvantages. More effective in this regard are expert approaches based on the use of knowledge and experience of specialists in the relevant subject field. The construction of technical solutions and the creation of special tools (for example, software for detection systems that allow detection of previously unknown cyber attacks by controlling the current state of unclear parameters in a poorly formalized environment, based on expert approaches, is a promising area of research. Based on the well-known cyberattack detection system which is based on the methodology for detecting anomalies generated by cyber attacks and the set of appropriate methods and models, software provided by the basic algorithm and a number of developed procedures (grid construction, initialization of values based on a set of databases and modules; graphic forming of parameters, search of common points in ac-cordance with the basic rules and graphic interpretation of the result) allows to automate the process of forming parameters etalons for modern attack detection systems and display the results of detecting abnormal states at a given time interval.
Ongoing advances in information technology affect all areas of society. One of the most promising areas of rapid growth within the field of information security is cyberattack detection and intrusion prevention. Massive cyberattacks initiate the development of specific technical solutions, tools and cyber countermeasures systems. To identify network intrusions, intrusion detection and prevention systems use modern methods, models, tools and integrated technical solutions that can remain effective when new or modified types of cyberthreats occur. In practice, however, with the emergence of new threats and anomalies, these tools do not always remain effective. Thus, intrusion detection systems must be continuously researched and improved. Such systems include specialized software that is designed to detect suspicious activity or information system intrusions and take sufficient measures to prevent cyberattacks. These systems and tools tend to be rather expensive, closed source, and require periodic support from their developers for improvement and appropriate adaptation to certain organizations' environments. Taking into account the results of well-known research, the paper presents a generalized analysis of intrusion detection systems software using a defined basic set of characteristics ("Cyberattack Category", "Adaptivity", "Detection Methods", "System Management", "Scalability", "Observation Level", "Cyberattack Response", "Security" and "Operating System Support"). This will provide the developers and users with certain options when selecting the appropriate modern information systems protection software.
Concept of business continuity management is the prospective direction of operative and strategy management and it defines the importance of information resources security when crisis influences. Crisis management consists of its forecasting, identification, responding and emergency procedures, crisis assessment and also processes of decision support and personnel activity or systems operation. In this paper the analysis of modern crisis management systems and basic methods was carried out. The main aim of this analysis is defining of science and technique prospective directions and also disadvantages identification in existed systems. This study covers both domestic and foreign developments. The main attention is paid to crisis forecasting systems, decision support and personnel activity systems in uncertainty and weak formalized space. This study results can be used to choose future researches directions for crisis detection and assessment systems and it confirms the feasibility and validity for expert approaches and fuzzy logic methods using.
Crisis influence on the security level of state informationresources, different organizations and whole state is veryserious. Crisis can stop system development that comesunder its influence and also it can crush the system in thebud. To prevent this influence the adequate (to threatslevel) measures and security means must be taken and itdefines the importance of current situation criticality assessment.There is no generally accepted universal criteriaand integrated parameter for criticality level assessment ofcrisis. That’s why defining of criticality level assessmentfor incident is actual and important scientific task. In thepaper the set of parameters for criticality level assessmentof crisis was introduced and also method for defining thecriticality level of crisis with expert approach and fuzzysets theory was proposed. These don’t require the statisticaldata gathering and processing. Besides the defazificationprocedure for parameters was described and on itsbase indicator of criticality level was built.
The information technology development with increasingdependence of human society from them is also thedanger of a sharp increase in information securityincidents in the absence of control over them can causecrises. The higher the level of incident/potential crisiscriticality causes the serious damage and it requires amuch more serious security. Major aspects thatdetermines the security effectiveness is the automation,timely detection and identification of incidents. In thispaper method of incidents/potential crisis identifyingbased on the application of fuzzy sets theory and expertapproaches was proposed. Thus the method can be usedin conditions of weakly-formalized environment, likeinformation and communication systems or networks.This method consists of 6 phases: forming sets ofincidents/potential crisis and identifying parameters;forming ties incident – identifying the set of fuzzyparameters; formation of standards fuzzy parameters;forming sets of heuristic rules for detection andidentification of incidents; phasing parameters monitoredto identify incident; processing parameters and formationresult. The proposed method can be used single or incombination with the method of assessing the criticalitylevel of the situation due to the influence of theincident/potential crisis.
One of the information security solutions are the intrusion detection systems based on the principle of anomaly. To develop such a kind of systems the anomaly detection method generated by cyberattacks in information systems is used. In this method, the process of formation of various standards is quite complicated and practically is not formalized, that reduces the efficiency of its use. In order to compensate for this drawback it is proposed the method which is based on mathematical models and methods of fuzzy logic and is implemented through the six basic stages: formation of subsets of linguistic assessments identifiers, formation of the basic matrix of frequencies, formation of a derivative matrix of frequencies, the formation of fuzzy terms, formation of fuzzy numbers, the visualization of linguistic standards. The method enables to improve the process of formalization of linguistic standards to increase the efficiency of the corresponding detection intrusion systems.
Computer systems are increasingly exposed to threats, new types of which generate new types of cyberattacks on their resources. To increase the security level there were developed special systems focus on detecting abnormal condition in computer networks and formation of fuzzy measurement standards of the network parameters and the formation of heuristic rules for network activity assessment. The basis of these systems is the method of anomalies detection caused by cyber attacks. In this method, the detection process of terms identification is not accompanied by sufficient level of formalisation for its effective use. In order to eliminate this shortcoming, the detection method of terms identification, which is based on mathematical models and fuzzy logic methods is developed. The method is implemented through three basic stages: formation of multitude features; raiting the subsets of features; defining the number of term identification. It makes possible to search in a given linguistic variable the reference term according to which, with a help of heuristic rules, it can be possible to define the level of abnormal conditions specific to a particular type of cyber-attacks. This will increase the efficiency of the intrusion detection systems.
One of the basic tasks related to the field of information security is the development of network and system resources protection systems based on the abnormal principle. To develop and extend the functionality of such systems the method of anomaly detection caused by cyber attacks in the information systems is used. In this method the parameters fuzzification process is not formalized, that reduces the efficiency of its use. With this objective the method which is based on linguistic standards, mathematical models, methods of indistinct logic is offered and is realized by means of three basic stages: occurrence and parameters of frequency formation; the formation of correction standards; the development of fuzzy parameters. Through these stages it is carried out the fuzzification of current values at the decision of problems of cyber attacks detection in computer systems that will increase the efficiency of construction of intrusion detection systems.
Based on the well-known anomaly detection techniques caused by the cyber —attacks, it was developed an appropriate system which requires the implementation of fuzzy standards focused on the measurement of current parameter value of the network traffic in order to identify suspicious activity in the Knvironment. To solve this task it was suggested a new structural decision of the corresponding system, consisting of the register of standards, attacks and parameters, as well as blocks of switching parameters, linking the attack to the parameter, die development of set of terms, the development of standards, register of standards and the processor of standards visualization. This development can be implemented through the software or firmware, hardware and focused on die measurement of current values of parameters in the network traffic in order to identify an abnormal condition.
The providing of state information resources security is inextricably connected with information security intruder's activity in information & communication systems where restricted data is circulating. The modern intruder detection systems, based on heuristic principle of information security violation detection, have a disadvantage because these are basically oriented on mathematical models which require much time to prepare statistic data. Mathematical models based on expert approach are more effective in this way. The method proposed in paper allows to solve the problem of intruder detection and identifying in information & communication systems and networks, which are weakly-formalized fuzzy environment. In the method elements of fuzzy logic are used to the previous decision of the violation & the intruder identification and precise basis of conventional logic that provides clarifying identification. The method consists of such stages: selection of the method for determining the importance of factors, the formation of categories sets of intruder and parameters, forming standards of fuzzy parameters, forming the set of heuristic rules, forming connections of intruder category with parameters, phasing of fuzzy parameters and definition clear parameters, processing and forming of parameters corteges, results formation. The method's work is organized in three phases: preparation, work with fuzzy parameters and work with clear parameters. On the basis of this method can be synthesized heuristic type intruder detection & identification system with high performance in fuzzy terms by the use of expert methods.
Efficient detection of information security intruder in information and communication networks and systems is a complex task that requires the use of special security means – intruder detection systems. Most of these systems are based on the use of signature methods and have several disadvantages, including the demands on resources and costs of various kinds (e.g., sampling statistics, systems studying, their adaptation and others). Expert approaches based on the use of knowledge and experience of specialists in some sector are more effective in this viewpoint. The paper presents a structural solution of intruder detection and identification system based on fuzzy logic. The system consists of preprocessing subsystem for clear and fuzzy parameters forming, fuzzy standards and heuristic rules forming (according to fuzzy and clear controlled parameters) and modules of cortege forming, linguistic output and visualization that can detect and identify the intruder. The result of the system work is represented in linguistic and graphical forms
Based on the known method for anomalies detection caused by the cyberattacks the corresponding system has been developed. The implementation of this system requires the realization phase of multiple set of heuristic rules formation. They are intended to create the appropriating critical rules directed on truth verification of reference and current parameters interrelations when the network activity is being assessed in a specific environment. This paper suggests a new structural solution of the corresponding system based on the critical rules and containing switching units, the formation of linguistic variables, rules ranking and initialization, as well as registers of standards, current values, linguistic identifiers and rules. The proposed solution can be implemented through software or hardware and to be used as the basis of systems for anomalies detection.
Most of existed intruder detection systems based on heuristic principle of information security violation detection and oriented on using mathematical models which need a lot time for statistical data preparation. Mathematical models based on expert approach are more effective but they need adequate rules for decision making. For this problem solving in die paper the model of heuristic rules based on fuzzy logic was proposed. This model uses plurals "intruder influence - parameter", "intruder influence — set of logical & linguistic connection" and universal model of parameter etalons and allows to display in information system some anomaly generated by influence of some category intruder. On the basis of this model were developed the examples of rules for detection the activity of such categories of intruders as misinformer, hacker, cracker, spammer, bot-braker and spamm-bot. These can be used in practice for the perfection of real intruder detection systems in information systems.