Анотація. Процес проведення державних експертиз комплексних систем захисту інформації (КСЗІ) та організація електронного обігу документів, створених на етапі проектних робіт мають низку проблем, а саме: уразливість інформації, яка зберігається на постійних носіях пам’яті; велику ентропію невизначеності інформації, що збільшує ризики помилок експерта при проведенні державних експертиз КСЗІ; проблема обігу паперових документів, які були створені на етапі предпроектних робіт, що збільшує ризики розкриття інформації з обмеженим доступом. Для вирішення зазначених проблем необхідно здійснити автоматизацію окремих процесів. Поставлена мета здійснюється шляхом розробки структурної моделі системи підтримки прийняття рішень (СППР) для реалізації експертиз КСЗІ, яка формується із взаємопов’язаних баз даних смислових змінних, множини критеріїв та шаблонів документів, а також модулів виокремлення смислових змінних, ідентифікації функціонального профілю захисту та взаємодії з експертом. Для реалізації структурної моделі був розроблений програмний застосунок, що підтримує два основних процеси: перший – пов’язаний з перевіркою відповідності функціонального профілю захисту (ФПЗ) вимогам НД ТЗІ; другий – орієнтований на виділення смислових змінних з вхідних документів та їх збереження у базі даних смислових змінних (БДСЗ). Зазначені рішення дозволяють розширити функціональні можливості сучасних СППР пов’язаних з реалізацією експертиз технічного захисту інформації.
Стандартний функціональний профіль захисту є переліком мінімально необхідних рівнів послуг, які повинен реалізовувати комплекс засобів захисту обчислювальної системи автоматизованої системи, щоб коректно задовольняти визначені вимоги щодо захищеності інформації, яка обробляється в даній автоматизованій системі. Таким чином, виникає необхідність у створенні методу, який дозволить автоматизувати процес генерування функціонального профілю захисту та перевірку його коректності щодо функцій захисту (послуг безпеки) та гарантій. Для вирішення поставленого завдання пропонується метод ідентифікації функціонального профіля захищеності, який за рахунок процедури формування: множин первинних та вторинних функціональних послуг безпеки; множин об’єднання первинних і вторинних функціональних послуг безпеки у функціональний профіль захищеності; множин порядку за індексами елементів; базового функціонального профіля захищеності дозволив формалізувати процес генерування функціонального профіля захищеності та верифікації експертом його вимог щодо функцій захисту (послуг безпеки) та гарантій.
The article is devoted to the biometric authentication of users, namely authentication by handwriting. In this paper, the relevance of creating a biometric authentication system of information systems users by their handwriting was argued. After that, there were determined a lot of characteristics of handwriting for their further use for authentication. Based on the analysis of the selected characteristics, there was determined their suitability for further use during user recognition. The method of authentication of information systems users by their handwriting and the method of the necessary primary processing of handwriting samples of information systems users were developed. Primary processing need is caused by the specific use, for the dynamic transfer of images to a computer, a graphic tablet (or other touch screen device). This processing is to remove erroneous data and correction of data to be used for recognition. There are five types of errors and three types of data correction in the work. To improve the recognition process, the image of the written key phrase, for further use, is divided into images of individual characters. Accordingly, the user is forced by the condition that the characters of the key phrase entered should be written separately from each other. During the recognition, the parameters of not all points of the image, but only the most significant, control points are analyzed. There are three types of control points in the work and the reasoned significance of using the most optimal algorithm for this. One of the types of neural networks, namely the probabilistic neural network, was chosen as the recognition mechanism. On the basis of the proposed methods, the software was developed, using which, first, a database of training samples handwriting of information systems was formed. Then, a series of experiments was conducted to determine the effectiveness of the application of the developed methods and to identify the most significant, for proper recognition, user authentication system settings. In the end, it was concluded that, despite the fact that the methods proposed in this paper allow to achieve a sufficiently high probability of correct recognition of users of information systems, the search for more efficient recognition mechanisms and other parameters that significantly affect the probability of correct recognition remains very actual objective.
State expertise is a lengthy process and is associated with possible errors both at the stage of the design work and during the examination itself. Therefore, the actual scientific task is to create an information system that would help the expert in building output documents, and also allow the expert to check the functional protection profile (FPP). The paper proposes a decomposition model, which, due to the formed sets of input and output documents of the p-th project, as well as plural semantic blocks, semantic constants and variables of the p-th project, allows automating the process of identifying the FPP. To do this, we decomposed the output documents, taking into account the stages of the formation of sets of examination documents, the structure of semantic blocks, the semantic variables of output documents. Analyze the principles of the organization of the structure of documents that are created at the stage of state examination of integrated information protection systems (IIPS). Introduce the concept of semantic blocks, semantic constants, semantic variables. The semantic block is a permanent semantic construction that has a complete semantic meaning. The semantic constant is a stable semantic construction, the existence of which goes beyond the framework of the state expert review of the IIPS. In turn, the semantic variable is a semantic construction, the time of its existence is equal to the time of the state examination of the IIPS. All this has allowed to speed up the process of creating output documents of state expert reviews of the IIPS. The development of these works is the development of the method of identification of the FPP. This will allow to formalize the requirements of the regulatory document in relation to its properties, which will be done in future articles
One of the key tasks during the state examination is the identification of the functional security profile (FSP). During the examination, the types of information that is processed and the risks of its loss, modification or disclosure are evaluated. For this, the FSP is being built, which contains the lists and levels of functional security services (FSS) required to ensure an acceptable level of information security. To determine the completeness and consistency, the rules for the construction of the FSP should be taken into account, and the automation of this process is linked to the relevant rules. The FSP itself is a key element in conducting state examinations, and its analysis of compliance with a regulatory document is one of the most important tasks. To solve the problem of identifying the FSP, it is necessary to: determine the levels of FSS, implemented integrated information security systems (IISS) of the object of examination; determination of the completeness and consistency of the profile; identification of the description of the FSS in the source documents. With this in mind, a model of parameters was proposed for the identification of the FSP in computer systems (СS) which due to the theoretical and multiple representation of certain sets of criteria for information security, their elements and corresponding levels, allowed to formally form the necessary set of values for the implementation of the process of identification of FSP in the CS. A definition is given for the sets of criteria, their elements and levels. All this made it possible in a formal form to form the necessary set of quantities for the implementation of the identification of FSP in the CS. The development of these works is the development of a method for identifying FSP. This will automate the process of determining of the requirements of the regulatory document regarding the protection functions (security services) and guarantees.
В роботи розглянуто системи надання повноважень, які можуть мати різноманітну інтерпретацію, починаючи від представлення їх у вигляді матриць повноважень до представлення їх у вигляді приписування тих чи інших ролей користува-чам, що звертаються за наданням повноважень. А саме проведено аналіз параметрів, що характеризують інформаційні системи типу з метою вибору найбільш адекватних формальних засобів для їх опису. Сформульовано ряд положень та визначень, які спрощують подібний аналіз в подальшому та визначена низка обов’язкових вимог щодо проведення цього аналізу. А саме дане визначення важливостіданих як параметру, який характеризує частоту використання даних за заданий період, на протязі якого відповідні дані використовуються. Також визначено мірутаємності даних через міру небезпеки, до якої може привести не санкціоноване використання даних при розв’язуванні задачі. Розглянуто поняття ано-малії і доведено взаємозв’язок предметної області інтерпретації деякої системи на структурному рівні.
У роботі викладені загальні підходи до побудови плану забезпечення технічного захисту конфіденційної інформації на всіх етапах життєвого циклу інформаційної системи та запропонуємо комп'ютерний варіант форми плану.
У роботі викладені загальні підходи з використанням результатів опублікованих праць, нормативних матеріалів, сучасних стандартів до нормування праці працівникам підрозділу захисту інформації з обмеженим доступом, організація робочого місця працівників, обгрунтовання вибору типів і кількості технічних засобів призначених для роботи з метеріальними носіями інформації з обмеженим доступом та рівені використання технічних засобів.
У роботі розглянуто підхід до визначення політики створення системи електронного документообігу. Запропонована спрощена структурна схема системи електронного документообігу.
В статті розглянуто проблеми контролю стану забезпечення захисту інформації з обмеженим доступом, перепускного і внутрішньооб'єктового режиму та запропоновані підходи до його оптимізації.