В статті окреслено методи соціального інжинірингу, зокрема використання методів комп’ютерної графіки як ключового аспекту психологічного впливу на людську свідомість і одного із можливих засобів ведення інформаційної війни, інструменту ведення гібридних війн на міждержавному рівні та в сфері бізнес послуг, фінансового шахрайства. Проаналізовано міжнародний досвід технік і технологій соціального інжинірингу в інформаційних технологіях. Визначено особливості реалізації інструментарію соціального інжинірингу на базі інформаційно-комунікаційних технологій.
An integrated approach to the justification and implementation of the system of domestic and international standards, as well as regulatory and legal aspects of the formation of the information security audit system at critical infrastructure facilities and in the systems of state information resources is presented. It is determined that the information security management system is part of the overall management system of the enterprise and is designed to improve the state of information security. System "processing" and "risk-oriented" approach, which means that the main idea and the main task of the information security management system are the processes of analysis and management of information risks in the creation, implementation, operation, monitoring and support of the state of security of information resources of the company. The European approach to the audit system is based on a comparative analysis of the current state of the information system and ensuring the desired level of its effectiveness. In our country, is determined by the analysis and control of the information security management system of the enterprise on the model requirements of ISO 27001 \ ISO 270xx and a set of state standards of Ukraine ISO / IEC. Thus, a variety of standards in the field of information technology and information security management provides organizations with the opportunity to choose the methodology, the approach that best suits the features of business processes and the service market. Current criteria of quality assessment, as a set of requirements assessment of the effectiveness of the security features information; the methods and models of assessing the effectiveness of security features information as well as the presentation of the results of the processes of audit and control of information security are defined the methodology of the system of processing and analysis of information audit of information security in the critical infrastructure and treatment systems of the state information resources.
The article analyzes the specifics of the formation of training for the specialists in information technologies and cyber security in accordance with the world system of standardization of the information technology industry (IT) and national requirements of the state. A comparative analysis was carried out and the content of competence creation based on the American industrial model and the European competence framework of information and communication technology specialists is disclosed. The nowadays specifics and trends of development and formation of educational standards of academic and professional orientation are determined. It is shown that these trends are characterized by the requirements of the IT industry services, and also determine the requirements of industry, necessary knowledge, skills and capacities of specialists in the labor market. The main features of the formation of competencies of information technology and cybersecurity specialists are revealed. The conceptual issues of the possibility of using the European competence framework for information and communication technology (ICT) specialists, in particular, the European e-Competence Framework (e-CF) and the American platform model as a system-based foundation for training personnel in IT and cybersecurity, are considered. Close attention is paid to the international general-purpose approaches of standardization of educational services, levels of competences in accordance with professional requirements for specialists in the system of classification of positions. The classification of academic and professional competencies of specialists who must ensure a high level of quality of a wide range of services in the field of information technology and cyber security, information and communication systems or directly organizations or institutions is determined. It is shown that this approach of forming the basis of skills and abilities allows using the fundamental professional knowledge and the multilevel principle of classification of the basic competencies in accordance with world standardization system in the development of domestic educational and professional programs and qualification requirements. The perspectives of research, that consist of the determination of integrity in career development, personnel management in the field of information technologies, monitoring of demand and supply in the labor market, are outlined; along with the correspondence of national and corporate competencies, qualifications, professional certification, etc. A comparative analysis was carried out and it was shown that the above mentioned conceptual principles of training for specialists should become the basis for the formation of the national classification of the positions in the sector of information technology and cybersecurity It has been determined that the classification of positions should be based on the specific clusters of competencies in the field of information and communication technologies and the industrial model of the USA. On the basis of the conducted researches, perspectives and approaches have been defined, concerning the methodology of forming the competencies of specialists for the educational branch of information technologies and cybersecurity. The above-mentioned conceptual approach will allow the domestic education system and the universities of the country that train IT professionals to successfully realize and implement the educational processes of integration into the service market, as well as to ensure the creation of common educational standards and competency classes, in order to improve the quality of education and the results of training.
The article proposes, shows and analyzes the main stages of implementing software for group assessment of a functional profile and determining or agreeing the level of guarantees for the correct implementation of functional security services in information security tools of information of telecommunication systems from unauthorized access in Ukraine based on theoretical studies previously conducted. The necessary regulatory documents on technical protection of information governing the procedure of evaluating and determining the level of guarantees of automated systems against unauthorized access in Ukraine are covered. The program was designed using the Data Flow Diagram, namely, a contextual diagram of the group definition process and a decomposed diagram of the process of group determination of the functional security profiles and the level of guarantees. More detailed flowcharts of software and algorithms are constructed. A prototype of the software is implemented; examples of work on each of the main blocks of work that were previously designed in the diagrams and flowcharts of the algorithms are given. Certain advantages and disadvantages of the developed software for group determination of the functional security profile and the level of guarantees are defined. The developed program allows to carry out group estimation and to compare the results sent to the server. This approach reduces the time spent by the security administrator to determine the security profiles and security levels of the information being processed against unauthorized access and to detect whether a specified functional profile coincides with a standard one (provided this match the user is provided with information about that standard functional profile) or determine another level of warranty. By conducting a group examination, the reliability of the obtained results increases DOI : https://doi.org/10.17721/ISTS.2019.1.11-18
Оцінюється ефективність розроблених методів ефективної ширини спектра та найбільшої інформаційної ваги основного тону в задачі ідентифікації диктора при наявних завадах. Визначено, що в результаті впливу хаотичних імпульсних завад можливість ідентифікації диктора в бігатоальтернативних задачах прийняття рішення різко знижується при збіганні частоти основного тону мовленнєвого сигналу і початкової частоти імпульсної завади для методу найбільшої інформаційної ваги основного тону. Метод ефективної ширини спектра забезпечує високі показники ідентифікації в умовах впливу такого типу завад для текстозалежної ідентифікації.
Аналізується структура інформаційних потоків в інтегрованій інформаційній системі прикордонного відомства та формується їх узагальнена структура. Основою методу раціоналізації процесу модернізації елементів інформаційної системи довільної структури за обраною стратегією модернізації є розроблена модель інформаційних потоків інформаційної системи на стадії модернізації. Наводиться структурна модель методу визначення послідовності модернізації елементів інформаційної системи. Результатом її роботи визначається послідовність, при дотриманні якої ймовірність порушення надійності інформації протягом всього періоду модернізації буде відповідати обраній стратегії.
As a tool of information technology, a quantum-spatial-pixel-based method (MAP) for embedding secret information in digital images has been developed, which provides more, compared with existing methods, the bandwidth of the latent channel and simplifies the system of data extraction, due to the use of spatial filtration The developed method is based on the change in the intensity of the brightness of the digital image pixels in the color RGB model. The change of intensity is carried out according to the developed set of rules and conditions through which the secret information (message) is embedded into the spatial area of the digital image used as a container. Also, in order to reduce the probability of uncovering the existence of a message, it is proposed to embed pixel-only messages that are at intersection points with various functions that are superimposed on a digital image. The results of the research of the developed method in the software environment for digital images of different classes.
Based on the analysis of modern methods of speaker identification, it was determined that to date there are no systems which would define speaker identity in conditions of high level of interference in the data channel, which makes this research very relevant. In this paper, we developed the Method of Effective Spectrum Width based on of the multialternative decision rules for a particular class of biometric characteristics to improve the function efficiency of distributed information systems. Using the developed method enables identify of the speaker even in the case where the information noise exceeds the signal by 1,5 times.
The analysis of existing systems of control of access control is conducted, types and levels of network interaction between its blocks are given. Classification of automated access control systems according to different criteria is given. The four classes of ACS are given depending on the degree of delimitation and access security required by the company. The recommendations for using different types of interfaces are given. It has been discovered that control and access control systems can be effectively used not only as access control for the enterprise, but also as a means for the accumulation of information important for decision-making.
Different methods of filtration and digital image classes are investigated in this work. Thefrequency filtering method for digital imaging was implemented and the degree of distortionof the digital image was investigated depending on the class of the image, separately for eachcomponent of the color model. The research was conducted on digital static images ofdifferent classes using frequency filtering methods that were implemented in applicationsoftware. The procedure for removing segments of the spectrum of three color gamut hasbeen obtained and it has been proved that the functional dependencies of distortion of imagequality (realistic, artificial, monochrome, etc.) are different for the red, green and bluecomponents of the color model. It is shown that the above statistics may be the basis forfurther research for the development of modern effective methods of steganography andsteganalization
The article deals with the study of modern steganographic methods and tools for processing digital images using software tools that are freely available through the Internet and available to the ordinary citizen. During the study, was performed identify the structural changes in graphics files which are the results, as well as, the result's images and the original's images. Was performed such comparisons: changes the size of graphics files; counting the number of modified pixel values of the images; study of the modification of the color image components and their respective bit planes; comparison of the structure of the received files. On the basis of the conducted researches were the results of relatively modern implementation methods hide information by steganography software that can be used in the future to improve the efficiency of steganographic system or steganographic analysis.
At the modernization, stage of information and telecommunication systems of the national security subjects of Ukraine there is a problem of information reliability when ones use the sharing data. For estimating the probability of violation of the information, properties need to determine the quantity of information provided into component of the system. The article presents the method of determining the quantity of information that flows into the telecommunications system with factor of aging.
The article suggests, shows and analyzes the theoretical basis for determining the level of guarantees of automated systems from unauthorized access. The necessary normative documents of technical protection of information that regulate the procedure for assessing and determining the level of guarantees of automated systems from unauthorized access in Ukraine are reflected. The algorithm of the expert's actions is considered. On the basis of these documents, formalization of the basis for determining the level of guarantees of automated systems against unauthorized access was carried out for the first time. The authors proposed theoretical foundations that make it possible to further improve the expert system that will automatically determine the functional profile of security and the level of guarantees of the automated system from unauthorized access. This will facilitate the work of experts regarding the definition of the security profile, the level of guarantees and the creation of the necessary set of protective equipment, as well as reduce the spent resource of time and material resources.
The article analyzes the existing approaches to ensuring the functional security of information systems. The relationship between the compliance with the functional criteria of the information resource and the functional security of the integrated information system of the border authority as a whole is determined. The contradiction between the existing theoretical basis for the provision of functional security and the need for the continuous modernization of information systems as part of an integrated information system is shown. The technology for ensuring the functional security of information systems at the stage of modernization is developed and its main stages are described. Reasonable modernization strategies depend on the importance of the normative level of functional security and the peculiarities of the functioning of the information system. Recommendations on choosing modernization strategies according to the peculiarities of the functioning of the information system are described. The influence of normative values of the observance of the properties of information in the investigation of the probability of a violation of the functioning of the functional security system is determined.
It is determined that identification by voice contributes to the reliability of the use of protection systems critical information. The analysis of existing methods of determining the fundamental tone frequency that you selected the most convenient method for the determination of the fundamental frequency, namely the method of spectral harmonic analysis. An evaluation of the effectiveness of the developed methods effective spectral width and the largest scales the information of the fundamental tone in the tasks of identification of audio signals. As a result of the experiment for three groups of speech signals, was determined that the method for effective spectrum width allows to identify the speaker with a probability of 100%, where a value SNR of 4.27 dB for extensibility identification and of 5.29 dB for textualizing in conditions, when the input signal belongs to one of the subsets of the database; if the input signal belongs to a database, not divided into subsets, the value of SNR 5.22 dB is amount of 5.26 dB, respectively.
The article deals with the definition of the possibilities of using steganographic methods, namely, methods of information hiding and steganography analysis, in problems of protection of state information resources. During the work was identified the opportunity of the application of steganographic techniques to meet the requirements of protection’s services of information in information telecommunication systems where information is processed, with the aim of the implementation of protection’s systems in the integrated systems of information protection or protection mechanisms in the software or technical means of information protection. It was the research of the implementation of the steganographic methods of information hiding and steganographic analysis, their characteristics and applications. Based on the conducted research identified services of the information security, implementation of which can be used steganography techniques information hiding and steganographic analysis.
A significant role in the formation of the voice characteristics of the information signals given to the speaker system represents a language group, which is responsible for basic voice parameters such as pitch frequency of the signal, information frames and properties frequency range, volume, frequency and rate of speech, intonation, etc. The main criteria features of voice were identified. The basic characteristics of audio signals generated by a person of a certain language group were analyzed. The methods and models to identify the fundamental frequency, which further gave the opportunity to determine the period of the fundamental tone were analyzed. In the current research, the determination of the fundamental frequency, there are problems such as the complexity of the implementation methods, and low probability of error in determination process; low resistance methods to external interference. Methods of determination of fundamental frequency with the plane of their implementation were classified.
The use of biometric protection of information resources becomes more and more developeddue to the rapid society informatization, the development of new technologies and increasingcyberattacks on the information system of the state. The increasing risk of unauthorizedaccess to critical information requires the development of reliable systems and methods ofaccess control. The voice recognition system of a person depending on the task wereanalyzed. The main stages of recognition of the speaker were depended. Structural andlogical scheme of the process of identification and verification user's voice were developed.The classification of modern methods of speech signals processing in problems ofidentification and verification
At the modernization, stage of information and telecommunication systems of the national security subjects of Ukraine there is a problem of information reliability when ones use the sharing data. For estimating the probability of violation of the information, properties need to determine the quantity of information provided into component of the system. The article presents the method of determining the quantity of information that flows into the telecommunications system with factor of aging.