State University of Telecommunications Open Journals System
Not a member yet
    2308 research outputs found

    МОДЕЛІ ОЦІНЮВАННЯ ЗАЛИШКОВОГО РИЗИКУ В ІНФОРМАЦІЙНИХ СИСТЕМАХ

    No full text
    The article considers new models for assessing residual risk in information systems. The proposed models allow for amore accurate assessment of the state of cybersecurity by taking into account various risk factors and mechanisms of theirinfluence. The practical application of the models to increase the effectiveness of information protection systems is described.The results obtained can be used to improve the cyber protection of organizations and critical information systems. New modelsfor assessing residual risk were presented, which take into account the impact of different types of threats, the level of IS securityand the dynamics of changes in the cyber threat environment.Keywords: cybersecurity, information system, residual risk, assessment models, cyber protection. References1.ISO/IEC 27005:2018. Information security risk management.2.NIST Special Publication 800-30. Guide for Conducting Risk Assessments.3.Ransbotham S., Mitra S., Ramsey J. "Security risk management: frameworks and best practices." Journal ofCybersecurity, 2022.4.ENISA Threat Landscape Report 2023.У статті розглянуто нові моделі оцінювання залишкового ризику в інформаційних системах. Запропонованімоделі дозволяють більш точно оцінювати стан кібербезпеки шляхом урахування різних факторів ризику тамеханізмів їх впливу. Описано практичне застосування моделей для підвищення ефективності систем захистуінформації. Отримані результати можуть бути використані для вдосконалення кіберзахисту організацій такритичних інформаційних систем. Було представлено нові моделі оцінювання залишкового ризику, яківраховують вплив різних типів загроз, рівень захищеності ІС та динаміку змін у середовищі кіберзагроз.Ключові слова: кібербезпека, інформаційна система, залишковий ризик, моделі оцінювання, кіберзахист Список використаних джерел1.ISO/IEC 27005:2018. Information security risk management.2.NIST Special Publication 800-30. Guide for Conducting Risk Assessments.3.Ransbotham S., Mitra S., Ramsey J. "Security risk management: frameworks and best practices." Journal ofCybersecurity, 2022.4.ENISA Threat Landscape Report 2023

    АНАЛІЗ МЕТОДІВ МОНІТОРИНГУ СТАНУ БЕЗПЕКИ В ХМАРНОМУ СЕРЕДОВИЩІ

    No full text
    The rapid spread of cloud computing is leading to new challenges in the field of information security. Organizations arefaced with the need to ensure reliable protection of data and applications in dynamic, multi-cloud environments. The articleexamines the current issues of ensuring data security in cloud environments, taking into account the growing number of incorrectconfigurations, which constitute the main share of security incidents. Three key approaches are considered: cloud securityposture management (CSPM), cloud workload protection (CWPP), and cloud application protection platforms (CNAPP). Thefunctional capabilities, advantages, and limitations of each approach are described in detail, and examples of their practicalapplication are provided. Special attention is paid to the role of artificial intelligence and machine learning in the monitoringprocess. It is demonstrated how AI/ML help to detect hidden threats and anomalies, accelerate the processing of large volumesof logs, and implement automated response. Examples of cloud services (Amazon GuardDuty, Azure Defender, Google SecurityCommand Center) that already implement advanced ML modules to detect complex multi-stage attacks and atypical patterns inuser behavior are provided. The key challenges of implementing these solutions are analyzed - from the excessive number ofnotifications in CSPM, the complexity of deploying agents in CWPP, and the risks of dependence on a single vendor in CNAPP.At the same time, it is emphasized that a properly configured monitoring system combined with human expertise cansignificantly strengthen cloud security and minimize the risks of incidents. The article emphasizes the need for a comprehensiveapproach that covers different layers of protection and demonstrates how the involvement of AI/ML contributes to the formationof proactive, dynamic security strategies in cloud environments.Keywords: cloud security, artificial intelligence (AI), machine learning (ML), CSPM, CWPP, CNAPP, cybersecurity. References1. 2021 state of cloud security posture management report. Cloud Security Alliance. URL:https://cloudsecurityalliance.org/articles/2021-state-of-cloud-security-posture-management-report (дата звернення20.12.2024).2. Cloud misconfiguration. UpGuard. URL: https://www.upguard.com/blog/cloud-misconfiguration (датазвернення 21.12.2024).3. Guffey, J., & Li, Y. (2023). Cloud service misconfigurations: Emerging threats, enterprise data breaches andsolutions. In 2023 IEEE 13th Annual Computing and Communication Workshop and Conference (CCWC) (pp. 806–812). IEEE. https://doi.org/10.1109/CCWC57344.2023.100992964. Jimmy, F. (2023). Cloud security posture management: Tools and techniques. Journal of Knowledge Learningand Science Technology, 2(3). https://doi.org/10.60087/jklst.vol2.n3.p6225. Coppola, G., Varde, A. S., & Shang, J. (2023). Enhancing cloud security posture for ubiquitous data accesswith a cybersecurity framework-based management tool. In 2023 IEEE 14th Annual Ubiquitous Computing, Electronics& Mobile Communication Conference (UEMCON) (pp. 590–594). IEEE. https://doi.org/10.1109/UEMCON59035.2023.103160036. What is CNAPP? Microsoft. URL: https://www.microsoft.com/en-us/security/business/security-101/what-iscnapp (дата звернення 15.01.2025).7. Choubey, R. (2023). Machine Learning Algorithms for Cloud Computing Security: A Review. TuijinJishu/Journal of Propulsion Technology, 44(4), 7372–7375. https://doi.org/10.52783/tjjpt.v44.i4.25648. Proactively harden your cloud security posture in the age of AI with CSPM INNOVA. Microsoft DefenderCloud Blog. URL: https://techcommunity.microsoft.com/blog/MicrosoftDefenderCloudBlog/proactively-harden-yourcloud-security-posture-in-the-age-of-ai-with-cspm-innova/4297079 (дата звернення 15.01.2024).9. GuardDuty features. Amazon Web Services. URL: https://aws.amazon.com/guardduty/features (датазвернення 01.10.2024).10. Cloud security glossary. Cloud Security Alliance. URL: https://cloudsecurityalliance.org/cloud-securityglossary (дата звернення 15.01.2024).11. What is CNAPP? Microsoft. URL: https://www.microsoft.com/en-us/security/business/security-101/what-iscnapp (дата звернення 02.02.2024).12. Vanitha, M., Navya Patel, M., Madhumitha, K., & Sathvika, J. (2024). Enhancing insider threat detection incloud environments through ensemble learning. International Journal of Communication Networks and InformationSecurity (IJCNIS), 16(5), 638–647. Retrieved from https://www.ijcnis.org/index.php/ijcnis/article/view/7870Стрімке поширення хмарних обчислень зумовлює появу нових викликів у сфері інформаційної безпеки.Організації стикаються з необхідністю забезпечення надійного захисту даних і додатків у динамічних,мультихмарних середовищах. У статті розглянуто актуальні питання забезпечення безпеки даних у хмарнихсередовищах із урахуванням зростаючої кількості некоректних конфігурацій, які становлять основну часткуінцидентів безпеки. Розглянуто три ключові підходи: управління станом безпеки хмарних середовищ (CSPM),захист хмарних робочих навантажень (CWPP) та платформи захисту хмарних додатків (CNAPP). Детальноописано функціональні можливості, переваги та обмеження кожного підходу, наведено приклади їх практичногозастосування. Окрему увагу приділено ролі штучного інтелекту та машинного навчання у процесі моніторингу.Продемонстровано, як ШІ/МН допомагають виявляти приховані загрози й аномалії, прискорювати обробкувеликих обсягів журналів, а також впроваджувати автоматизоване реагування. Наведено приклади хмарнихсервісів (Amazon GuardDuty, Azure Defender, Google Security Command Center), що вже реалізують розвинені MLмодулі для виявлення складних багатоступеневих атак і нетипових патернів у поведінці користувачів.Проаналізовано ключові виклики впровадження цих рішень — від надмірної кількості сповіщень у CSPM,складності розгортання агентів у CWPP і ризиків залежності від одного постачальника в CNAPP. Водночаснаголошується, що правильно налаштована система моніторингу у поєднанні з людською експертизою можеістотно зміцнити хмарну безпеку та мінімізувати ризики інцидентів. У статті підкреслюється необхідністькомплексного підходу, що охоплює різні рівні захисту та демонструється, як залучення ШІ/МН сприяєформуванню проактивних, динамічних стратегій безпеки у хмарних середовищахКлючові слова: безпека хмарних обчислень, штучний інтелект (ШІ/AI), машинне навчання (МН/ML),CSPM, CWPP, CNAPP, кібербезпека. Список використаних джерел1. 2021 state of cloud security posture management report. Cloud Security Alliance. URL:https://cloudsecurityalliance.org/articles/2021-state-of-cloud-security-posture-management-report (дата звернення20.12.2024).2. Cloud misconfiguration. UpGuard. URL: https://www.upguard.com/blog/cloud-misconfiguration (датазвернення 21.12.2024).3. Guffey, J., & Li, Y. (2023). Cloud service misconfigurations: Emerging threats, enterprise data breaches andsolutions. In 2023 IEEE 13th Annual Computing and Communication Workshop and Conference (CCWC) (pp. 806–812). IEEE. https://doi.org/10.1109/CCWC57344.2023.100992964. Jimmy, F. (2023). Cloud security posture management: Tools and techniques. Journal of Knowledge Learningand Science Technology, 2(3). https://doi.org/10.60087/jklst.vol2.n3.p6225. Coppola, G., Varde, A. S., & Shang, J. (2023). Enhancing cloud security posture for ubiquitous data accesswith a cybersecurity framework-based management tool. In 2023 IEEE 14th Annual Ubiquitous Computing, Electronics& Mobile Communication Conference (UEMCON) (pp. 590–594). IEEE. https://doi.org/10.1109/UEMCON59035.2023.103160036. What is CNAPP? Microsoft. URL: https://www.microsoft.com/en-us/security/business/security-101/what-iscnapp (дата звернення 15.01.2025).7. Choubey, R. (2023). Machine Learning Algorithms for Cloud Computing Security: A Review. TuijinJishu/Journal of Propulsion Technology, 44(4), 7372–7375. https://doi.org/10.52783/tjjpt.v44.i4.25648. Proactively harden your cloud security posture in the age of AI with CSPM INNOVA. Microsoft DefenderCloud Blog. URL: https://techcommunity.microsoft.com/blog/MicrosoftDefenderCloudBlog/proactively-harden-yourcloud-security-posture-in-the-age-of-ai-with-cspm-innova/4297079 (дата звернення 15.01.2024).9. GuardDuty features. Amazon Web Services. URL: https://aws.amazon.com/guardduty/features (датазвернення 01.10.2024).10. Cloud security glossary. Cloud Security Alliance. URL: https://cloudsecurityalliance.org/cloud-securityglossary (дата звернення 15.01.2024).11. What is CNAPP? Microsoft. URL: https://www.microsoft.com/en-us/security/business/security-101/what-iscnapp (дата звернення 02.02.2024).12. Vanitha, M., Navya Patel, M., Madhumitha, K., & Sathvika, J. (2024). Enhancing insider threat detection incloud environments through ensemble learning. International Journal of Communication Networks and InformationSecurity (IJCNIS), 16(5), 638–647. Retrieved from https://www.ijcnis.org/index.php/ijcnis/article/view/787

    ПРОБЛЕМИ КІБЕРБЕЗПЕКИ В ОРГАНІЗАЦІЯХ З ДИСТАНЦІЙНОЮ ФОРМОЮ ПРАЦІ

    No full text
    The rapid spread of remote work in the world creates new challenges for ensuring effective and secure digital interactionin organizations. The purpose of this study is a comprehensive analysis of modern approaches, tools and organizational andlegal means used to organize secure digital interaction in remote work. To achieve this goal, the method of analyzing literarysources was used, which allowed to systematize information on technological solutions, management practices and regulatoryrequirements related to remote work.The main key aspects were analyzed: digital platforms and services for communication and collaboration, user devicemanagement and the Bring Your Own Device (BYOD) concept, as well as legal regulation of the field of cybersecurity andprivacy. The study results found that the use of unified platforms for managing corporate services reduces the fragmentation ofthe digital environment and the risks of data leakage; providing employees with secure corporate devices or implementing clearBYOD policies minimizes the main cyber threats; Compliance with international standards and national legislation in the fieldof information protection ensures the legal compliance of the activities of a distributed team. A comprehensive approach that combines modern technological tools, effective management and compliance with legal norms allows you to increase the levelof information security and the efficiency of remote work, minimizing potential risks.Keywords: cybersecurity, cloud security, remote work, BYOD, legal regulation. References1. Radha P., Sayyed N., Fathima Y. The new normal: navigating cyber security challenges in remote work policies.NPRC journal of multidisciplinary research. 2024. Vol. 1, no. 8. P. 106–118. URL: https://doi.org/10.3126/nprcjmr.v1i8.73042 (date of access: 30.04.2025).2. Office I. L., Messenger J. C. Telework in the 21st century: an evolutionary perspective. International LabourOrganisation (ILO), 2019.3. Sabin J. The future of security in a remote-work environment. Network security. 2021. Vol. 2021, no. 10. P.15–17. URL: https://doi.org/10.1016/s1353-4858(21)00118-5 (date of access: 30.04.2025).4. Rhodes C., Bettany A. Automating windows deployment with zero touch. Windows installation and updatetroubleshooting. Berkeley, CA, 2016. P. 119–137. URL: https://doi.org/10.1007/978-1-4842-1827-3_5 (date of access:30.04.2025).5. AlShalaan M. R., Fati S. M. Enhancing organizational data security on employee-connected devices usingBYOD policy. Information. 2023. Vol. 14, no. 5. P. 275. URL: https://doi.org/10.3390/info14050275 (date of access:30.04.2025).6. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection ofnatural persons with regard to the processing of personal data and on the free movement of such data, and repealingDirective 95/46/EC (GDPR). URL: https://eur-lex.europa.eu/eli/reg/2016/679/oj.7. Jarrahi M. H., Reynolds R., Eshraghi A. Personal knowledge management and enactment of personal knowledgeinfrastructures as shadow IT. Information and learning sciences. 2020. Ahead-of-print, ahead-of-print. URL:https://doi.org/10.1108/ils-11-2019-0120 (date of access: 08.05.2025).8. Bonderud D. Cost of a data breach 2024: Financial industry | IBM. IBM - United States. URL:https://www.ibm.com/think/insights/cost-of-a-data-breach-2024-financial-industry (date of access: 07.05.2025).9. Public Company Accounting Reform and Investor Protection Act of 2002, 15 U.S.C. § 7201 et seq. (2002).https://www.govinfo.gov/content/pkg/PLAW-107publ204/pdf/PLAW-107publ204.pdf.10. Nwankpa J. K., Datta P. M. Remote vigilance: the roles of cyber awareness and cybersecurity policies amongremote workers. Computers & security. 2023. P. 103266. URL: https://doi.org/10.1016/j.cose.2023.103266 (date ofaccess: 30.04.2025).11. Das S., Dingman A., Camp L. Why Johnny doesn’t use two factor: A two-phase usability study of the FIDOU2F security key. 2018. P. 160–179. URL: https://doi.org/10.1007/978-3-662-58387-6_9.12. Repetto M. Adaptive monitoring, detection, and response for agile digital service chains. Computers &Security. 2023. Vol. 132. P. 103343. URL: https://doi.org/10.1016/j.cose.2023.103343 (date of access: 08.05.2025).13. Haag S., Eckhardt A., Schwarz A. The Acceptance of Justifications among Shadow IT Users and Nonusers –An Empirical Analysis. Information & Management. 2019. Vol. 56, no. 5. P. 731–741. URL: https://doi.org/10.1016/j.im.2018.11.006 (date of access: 08.05.2025).14. Waelchli S., Walter Y. Reducing the risk of social engineering attacks using SOAR measures in a real worldenvironment: A case study. Computers & Security. 2024. P. 104137. URL: https://doi.org/10.1016/j.cose.2024.104137(date of access: 09.05.2025).15. Ratchford M., Wang P., Sbeit R. O. BYOD Security Risks and Mitigations. Advances in Intelligent Systemsand Computing. Cham, 2017. P. 193–197. URL: https://doi.org/10.1007/978-3-319-54978-1_27 (date of access:09.05.2025).16. Lim Y. Z., Rahman H. B. A., Sikdar B. False sense of security on protected wi-fi networks. Cryptography andsecurity. URL: https://arxiv.org/abs/2501.13363.17. Al Jutail M., Al-Akhras M., Albesher A. Associated risks in mobile applications permissions. Journal ofInformation Security. 2019. Vol. 10, no. 02. P. 69–90. URL: https://doi.org/10.4236/jis.2019.102004 (date of access:09.05.2025).18. Outdated software | OWASP foundation. OWASP Foundation, the Open Source Foundation for ApplicationSecurity | OWASP Foundation. URL: https://owasp.org/www-project-top-10-infrastructure-security-risks/docs/2024/ISR01_2024-Outdated_Software (date of access: 09.05.2025).19. Adascalitei D., Riso S. Effects of employee monitoring on remote work. An empirical study from Germanyand Spain using AMPWork survey data (2021-2022). Sinappsi. 2024. Vol. XIV. P. 93–112.20. Bring your own device (BYOD): organizational control and justice perspectives / H. Lam et al. EmployeeResponsibilities and Rights Journal. 2024. URL: https://doi.org/10.1007/s10672-024-09498-1 (date of access:09.05.2025).21. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protectionof natural persons with regard to the processing of personal data and on the free movement of such data, and repealingDirective 95/46/EC (GDPR). URL: https://eur-lex.europa.eu/eli/reg/2016/679/oj.22. J. G. Balancing employee privacy and cyber security in remote work: ethical and legal challenges. URL:https://www.researchgate.net/publication/389711296_BALANCING_EMPLOYEE_PRIVACY_AND_CYBER_SECURITY_IN_REMOTE_WORK_ETHICAL_AND_LEGAL_CHALLENGES.23. Swire P., Kennedy-Mayo D. The risks to cybersecurity from data localization – organizational effects. Arizonalaw journal of emerging technologies. 2025. Vol. 8, no. 1. URL: https://doi.org/10.2458/azlawjet.7523 (date of access:09.05.2025).24. Golubock D. Remote workers, ever-present risk: employer liability for data breaches in the era of hybridworkplaces. Journal of law, technology, & the internet. 2024. Vol. 15, no. 2. URL: https://scholarlycommons.law.case.edu/jolti/vol15/iss2/4 (date of access: 09.05.2025).25. Nwosu O. Monitoring productivity vis-a-vis employee privacy: legal and ethical considerations: thesis. 2022.32 p. URL: https://doi.org/10.2139/ssrn.4095627 (date of access: 09.05.2025).26. Simutina Y. Remote work in Ukraine: problems and prospects of improving its legal regulation. Yearly journalof scientific articles “Pravova derzhava”. 2023. No. 34. P. 431–444. URL: https://doi.org/10.33663/1563-3349-2023-34-431-444 (date of access: 09.05.2025).Стрімке поширення віддаленої роботи у світі створює нові виклики для забезпечення ефективної табезпечної цифрової взаємодії в організаціях. Метою даного дослідження є комплексний аналіз сучасних підходів,інструментів та організаційно-правових засобів, що використовуються для організації захищеної цифровоївзаємодії в умовах віддаленої праці. Для досягнення поставленої мети застосовано метод аналізу літературнихджерел, який дозволив систематизувати інформацію про технологічні рішення, управлінські практики танормативні вимоги, пов’язані з віддаленою роботою.Проаналізовано основні ключові аспекти: цифрові платформи та сервіси для комунікації й спільної роботи,управління користувацькими пристроями та концепцію Bring Your Own Device (BYOD), а також правоверегулювання сфери кібербезпеки та приватності. За результатами дослідження встановлено, що використанняуніфікованих платформ для управління корпоративними сервісами зменшує фрагментацію цифровогосередовища та ризики витоку даних; надання співробітникам захищених корпоративних пристроїв абозапровадження чітких політик BYOD мінімізує основні кіберзагрози; дотримання міжнародних стандартів інаціонального законодавства у сфері захисту інформації забезпечує правову відповідність діяльностірозподіленого колективу. Комплексний підхід, який поєднує сучасні технологічні інструменти, ефективнеуправління та виконання правових норм, дозволяє підвищити рівень інформаційної безпеки та ефективностідистанційної роботи, мінімізуючи потенційні ризики.Ключові слова: кібербезпека, безпека хмарних технології, віддалена робота, BYOD, правоверегулювання. Перелік посилань1. Radha P., Sayyed N., Fathima Y. The new normal: navigating cyber security challenges in remote work policies.NPRC journal of multidisciplinary research. 2024. Vol. 1, no. 8. P. 106–118. URL: https://doi.org/10.3126/nprcjmr.v1i8.73042 (date of access: 30.04.2025).2. Office I. L., Messenger J. C. Telework in the 21st century: an evolutionary perspective. International LabourOrganisation (ILO), 2019.3. Sabin J. The future of security in a remote-work environment. Network security. 2021. Vol. 2021, no. 10. P.15–17. URL: https://doi.org/10.1016/s1353-4858(21)00118-5 (date of access: 30.04.2025).4. Rhodes C., Bettany A. Automating windows deployment with zero touch. Windows installation and updatetroubleshooting. Berkeley, CA, 2016. P. 119–137. URL: https://doi.org/10.1007/978-1-4842-1827-3_5 (date of access:30.04.2025).5. AlShalaan M. R., Fati S. M. Enhancing organizational data security on employee-connected devices usingBYOD policy. Information. 2023. Vol. 14, no. 5. P. 275. URL: https://doi.org/10.3390/info14050275 (date of access:30.04.2025).6. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection ofnatural persons with regard to the processing of personal data and on the free movement of such data, and repealingDirective 95/46/EC (GDPR). URL: https://eur-lex.europa.eu/eli/reg/2016/679/oj.7. Jarrahi M. H., Reynolds R., Eshraghi A. Personal knowledge management and enactment of personal knowledgeinfrastructures as shadow IT. Information and learning sciences. 2020. Ahead-of-print, ahead-of-print. URL:https://doi.org/10.1108/ils-11-2019-0120 (date of access: 08.05.2025).8. Bonderud D. Cost of a data breach 2024: Financial industry | IBM. IBM - United States. URL:https://www.ibm.com/think/insights/cost-of-a-data-breach-2024-financial-industry (date of access: 07.05.2025).9. Public Company Accounting Reform and Investor Protection Act of 2002, 15 U.S.C. § 7201 et seq. (2002).https://www.govinfo.gov/content/pkg/PLAW-107publ204/pdf/PLAW-107publ204.pdf.10. Nwankpa J. K., Datta P. M. Remote vigilance: the roles of cyber awareness and cybersecurity policies amongremote workers. Computers & security. 2023. P. 103266. URL: https://doi.org/10.1016/j.cose.2023.103266 (date ofaccess: 30.04.2025).11. Das S., Dingman A., Camp L. Why Johnny doesn’t use two factor: A two-phase usability study of the FIDOU2F security key. 2018. P. 160–179. URL: https://doi.org/10.1007/978-3-662-58387-6_9.12. Repetto M. Adaptive monitoring, detection, and response for agile digital service chains. Computers &Security. 2023. Vol. 132. P. 103343. URL: https://doi.org/10.1016/j.cose.2023.103343 (date of access: 08.05.2025).13. Haag S., Eckhardt A., Schwarz A. The Acceptance of Justifications among Shadow IT Users and Nonusers –An Empirical Analysis. Information & Management. 2019. Vol. 56, no. 5. P. 731–741. URL: https://doi.org/10.1016/j.im.2018.11.006 (date of access: 08.05.2025).14. Waelchli S., Walter Y. Reducing the risk of social engineering attacks using SOAR measures in a real worldenvironment: A case study. Computers & Security. 2024. P. 104137. URL: https://doi.org/10.1016/j.cose.2024.104137(date of access: 09.05.2025).15. Ratchford M., Wang P., Sbeit R. O. BYOD Security Risks and Mitigations. Advances in Intelligent Systemsand Computing. Cham, 2017. P. 193–197. URL: https://doi.org/10.1007/978-3-319-54978-1_27 (date of access:09.05.2025).16. Lim Y. Z., Rahman H. B. A., Sikdar B. False sense of security on protected wi-fi networks. Cryptography andsecurity. URL: https://arxiv.org/abs/2501.13363.17. Al Jutail M., Al-Akhras M., Albesher A. Associated risks in mobile applications permissions. Journal ofInformation Security. 2019. Vol. 10, no. 02. P. 69–90. URL: https://doi.org/10.4236/jis.2019.102004 (date of access:09.05.2025).18. Outdated software | OWASP foundation. OWASP Foundation, the Open Source Foundation for ApplicationSecurity | OWASP Foundation. URL: https://owasp.org/www-project-top-10-infrastructure-security-risks/docs/2024/ISR01_2024-Outdated_Software (date of access: 09.05.2025).19. Adascalitei D., Riso S. Effects of employee monitoring on remote work. An empirical study from Germanyand Spain using AMPWork survey data (2021-2022). Sinappsi. 2024. Vol. XIV. P. 93–112.20. Bring your own device (BYOD): organizational control and justice perspectives / H. Lam et al. EmployeeResponsibilities and Rights Journal. 2024. URL: https://doi.org/10.1007/s10672-024-09498-1 (date of access:09.05.2025).21. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protectionof natural persons with regard to the processing of personal data and on the free movement of such data, and repealingDirective 95/46/EC (GDPR). URL: https://eur-lex.europa.eu/eli/reg/2016/679/oj.22. J. G. Balancing employee privacy and cyber security in remote work: ethical and legal challenges. URL:https://www.researchgate.net/publication/389711296_BALANCING_EMPLOYEE_PRIVACY_AND_CYBER_SECURITY_IN_REMOTE_WORK_ETHICAL_AND_LEGAL_CHALLENGES.23. Swire P., Kennedy-Mayo D. The risks to cybersecurity from data localization – organizational effects. Arizonalaw journal of emerging technologies. 2025. Vol. 8, no. 1. URL: https://doi.org/10.2458/azlawjet.7523 (date of access:09.05.2025).24. Golubock D. Remote workers, ever-present risk: employer liability for data breaches in the era of hybridworkplaces. Journal of law, technology, & the internet. 2024. Vol. 15, no. 2. URL: https://scholarlycommons.law.case.edu/jolti/vol15/iss2/4 (date of access: 09.05.2025).25. Nwosu O. Monitoring productivity vis-a-vis employee privacy: legal and ethical considerations: thesis. 2022.32 p. URL: https://doi.org/10.2139/ssrn.4095627 (date of access: 09.05.2025).26. Simutina Y. Remote work in Ukraine: problems and prospects of improving its legal regulation. Yearly journalof scientific articles “Pravova derzhava”. 2023. No. 34. P. 431–444. URL: https://doi.org/10.33663/1563-3349-2023-34-431-444 (date of access: 09.05.2025)

    АНАЛІЗ МОДЕЛЕЙ ТА АЛГОРИТМІВ АВТЕНТИФІКАЦІЇ НА ОСНОВІ БІОМЕТРИЧНИХ ДАНИХ

    No full text
    User authentication is one of the key aspects of information security, which provides access control to resources andprotection of confidential data. Traditional authentication methods, such as passwords and PIN codes, have a number ofshortcomings, in particular, vulnerability to attacks such as brute force, phishing, and interception. In this regard, there isgrowing interest in biometric authentication methods that provide a higher level of security and ease of use. The article considersmodern models and algorithms of biometric authentication, their advantages and disadvantages. The features of the use ofunimodal and multimodal systems are analyzed. Special attention is paid to promising methods for increasing the accuracy ofauthentication and the security of biometric data storage. An analysis of modern research in this area is presented. The mainalgorithms used in biometric authentication systems are also considered, including image processing methods, neural networks,machine learning, and cryptographic technologies. The possibilities of using multi-factor authentication, which combinesbiometric parameters with other methods of identity verification, which significantly increases the level of security, areanalyzed. The prospects for the development of biometric authentication systems are considered, in particular, the introduction of new technologies, such as artificial intelligence, blockchain and quantum cryptography. An analysis of possible risksassociated with biometric authentication is carried out. It is concluded that the use of biometric methods allows to significantlyincrease the efficiency of authentication, reduce the risks of data compromise and ensure convenience for users, however, theirimplementation requires taking into account issues of confidentiality, reliability and legal regulation. An authentication systembased on artificial intelligence, blockchain, quantum cryptography is proposed and its effectiveness is analyzed.Keywords: biometric authentication, unimodal systems, multimodal systems, artificial intelligence, cryptography,steganography. References1. Ганін, І. В., & Ковальчук, О. П. (2021). Сучасні методи біометричної ідентифікації. ВісникНаціонального технічного університету України "КПІ". Серія: Інформаційна безпека, (3), 26-32. Отримано зhttps://ela.kpi.ua/bitstream/123456789/9839/1/26.pdf.2. Коваленко, Р. С., & Ігнатенко, Т. В. (2022). Вибір переважного методу біометричної автентифікації.Інформаційна безпека та кіберзахист, 5(12), 44–57. Отримано з https://isg-journal.com/isjea/article/download/444/246/457.3. Руда, Х., Сабодашко, Д., Микитин, Г., Швед, М., Бордуляк, С., & Коршун, Н. (2024). Порівнянняметодів цифрової обробки сигналів та моделей глибинного навчання у голосовій аутентифікації. Кібербезпека:освіта, наука, техніка, 1(25), 140–160. https://doi.org/10.28925/2663-4023.2024.25.140160.4. Kaur, P., Sharma, M., & Sharma, N. (2020). A robust multimodal biometric authentication system using deeplearning. Expert Systems with Applications, 157. https://doi.org/10.1016/j.eswa.2020.113486.5. Liu, X., Yin, F., Wang, L., & Xu, W. (2023). Deep Learning in Biometrics: A Review. Pattern RecognitionLetters, 45(3), 128–140. https://doi.org/10.1016/j.patrec.2022.10.015.6. Goodfellow, I., Bengio, Y., & Courville, A. (2016). Deep Learning. MIT Press.7. He, K., Zhang, X., Ren, S., & Sun, J. (2016). Deep Residual Learning for Image Recognition. Proceedings ofthe IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 770–778. https://doi.org/10.1109/CVPR.2016.90.8. Smith, P., & Jones, R. (2021). Spoofing Attacks in Biometric Systems: Detection and Prevention. Journal ofCybersecurity, 8(3), 210–225. https://doi.org/10.1093/cybsec/tyab012.9. Скорик, Ю., & Безрук, В. (2023). Вибір переважного методу біометричної автентифікації. InternationalScience Journal of Engineering & Agriculture, 2(4), 28–34.10. Іосіфов, Є., & Соколов, В. (2024). Порівняльний аналіз методів, технологій, сервісів та платформ длярозпізнавання голосової інформації в системах забезпечення інформаційної безпеки. Кібербезпека: освіта, наука,техніка, 1(25), 468-486.11. Ledig, C., et al. (2017). Photo-realistic single image super-resolution using a generative adversarial network.Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR), 4681-4690.https://doi.org/10.1109/CVPR.2017.19.Автентифікація користувачів є одним із ключових аспектів інформаційної безпеки, що забезпечуєконтроль доступу до ресурсів та захист конфіденційних даних. Традиційні методи автентифікації, такі як пароліта PIN-коди, мають низку недоліків, зокрема вразливість до атак типу перебору, фішингу та перехоплення. Узв’язку з цим зростає інтерес до біометричних методів автентифікації, які забезпечують вищий рівень безпеки тазручності використання. У статті розглянуто сучасні моделі та алгоритми біометричної автентифікації, їхніпереваги та недоліки. Проаналізовано особливості використання унімодальних та мультимодальних систем.Особливу увагу приділено перспективним методам підвищення точності автентифікації та безпеки зберіганнябіометричних даних. Представлено аналіз сучасних досліджень у цій галузі. Також розглянуто основніалгоритми, що застосовуються у біометричних системах автентифікації, включаючи методи обробки зображень,нейронні мережі, машинне навчання та криптографічні технології. Проаналізовано можливості використаннябагатофакторної автентифікації, яка поєднує біометричні параметри з іншими методами перевірки особи, щозначно підвищує рівень безпеки. Розглянуто перспективи розвитку біометричних систем автентифікації, зокремавпровадження нових технологій, таких як штучний інтелект, блокчейн та квантова криптографія. Проведеноаналіз можливих ризиків, пов’язаних із біометричною автентифікацією. Зроблено висновок, що використаннябіометричних методів дозволяє суттєво підвищити ефективність автентифікації, зменшити ризики компрометаціїданих і забезпечити зручність для користувачів, проте їх впровадження потребує врахування питаньконфіденційності, надійності та правового регулювання. Запропоновано автентифікаційну систему на основіштучного інтелекту, блокчейну, квантової криптографії та проведено аналіз її ефективності.Ключові слова: біометрична автентифікація, унімодальні системи, мультимодальні системи, штучнийінтелект, криптографія, стеганографія. Перелік посилань1. Ганін, І. В., & Ковальчук, О. П. (2021). Сучасні методи біометричної ідентифікації. ВісникНаціонального технічного університету України "КПІ". Серія: Інформаційна безпека, (3), 26-32. Отримано зhttps://ela.kpi.ua/bitstream/123456789/9839/1/26.pdf.2. Коваленко, Р. С., & Ігнатенко, Т. В. (2022). Вибір переважного методу біометричної автентифікації.Інформаційна безпека та кіберзахист, 5(12), 44–57. Отримано з https://isg-journal.com/isjea/article/download/444/246/457.3. Руда, Х., Сабодашко, Д., Микитин, Г., Швед, М., Бордуляк, С., & Коршун, Н. (2024). Порівнянняметодів цифрової обробки сигналів та моделей глибинного навчання у голосовій аутентифікації. Кібербезпека:освіта, наука, техніка, 1(25), 140–160. https://doi.org/10.28925/2663-4023.2024.25.140160.4. Kaur, P., Sharma, M., & Sharma, N. (2020). A robust multimodal biometric authentication system using deeplearning. Expert Systems with Applications, 157. https://doi.org/10.1016/j.eswa.2020.113486.5. Liu, X., Yin, F., Wang, L., & Xu, W. (2023). Deep Learning in Biometrics: A Review. Pattern RecognitionLetters, 45(3), 128–140. https://doi.org/10.1016/j.patrec.2022.10.015.6. Goodfellow, I., Bengio, Y., & Courville, A. (2016). Deep Learning. MIT Press.7. He, K., Zhang, X., Ren, S., & Sun, J. (2016). Deep Residual Learning for Image Recognition. Proceedings ofthe IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 770–778. https://doi.org/10.1109/CVPR.2016.90.8. Smith, P., & Jones, R. (2021). Spoofing Attacks in Biometric Systems: Detection and Prevention. Journal ofCybersecurity, 8(3), 210–225. https://doi.org/10.1093/cybsec/tyab012.9. Скорик, Ю., & Безрук, В. (2023). Вибір переважного методу біометричної автентифікації. InternationalScience Journal of Engineering & Agriculture, 2(4), 28–34.10. Іосіфов, Є., & Соколов, В. (2024). Порівняльний аналіз методів, технологій, сервісів та платформ длярозпізнавання голосової інформації в системах забезпечення інформаційної безпеки. Кібербезпека: освіта, наука,техніка, 1(25), 468-486.11. Ledig, C., et al. (2017). Photo-realistic single image super-resolution using a generative adversarial network.Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR), 4681-4690.https://doi.org/10.1109/CVPR.2017.19

    ПІДВИЩЕННЯ ЕФЕКТИВНОСТІ СТЕГАНОГРАФІЇ ЧЕРЕЗ ЗАСТОСУВАННЯ МЕТОДІВ ПОКРАЩАННЯ ЗОБРАЖЕНЬ ТА МОДЕЛЕЙ ШТУЧНОГО ІНТЕЛЕКТУ

    No full text
    The article investigates the problem of increasing the efficiency of steganographic methods through the use of modernapproaches to image enhancement. Particular attention is paid to preprocessing methods, as well as the use of deep neuralnetworks, such as ESRGAN, U-Net, and SteganoGAN. The results of experiments using adaptive contrast enhancement andsmoothing are presented, which allows increasing the hidden capacity of the container and reducing the probability of detectinghidden data. The paper investigates the influence of preprocessing methods on the results of steganographic message hiding. Itwas experimentally established that preprocessing of images significantly affects the efficiency of LSB steganography. The beststealth (high PSNR and SSIM) and resistance to JPEG compression was demonstrated by the approach with adaptive texturesegmentation. Conversion to YCbCr also allows increasing stability without losing bandwidth. At the same time, histogramequalization worsens stability due to increased contrast. Thus, adaptive preprocessing methods are advisable to use to improvethe security and quality of information hiding. A comparison of artificial intelligence models for steganography tasks wasconducted. In the course of the work, artificial intelligence models used in steganography tasks were analyzed. It was found thatthe effectiveness of a specific architecture (for example, U-Net or SteganoGAN) significantly depends on the tasks, the type ofinput data, the requirements for channel bandwidth, and the available computing resources. It was concluded that the adaptiveuse of deep learning and image preprocessing methods allows to increase both the stability of hidden messages and theirinvisibility, which is critically important for modern digital steganography.Keywords: steganography, image enhancement, ESRGAN, deep learning, information protection, neural networks. References1. Zhou J., Liu J., et al. "An Image Preprocessing Framework for Steganography". Journal of VisualCommunication and Image Representation, 2020.2. Wang H., Chen Y. "Color Space Transformations for Enhanced Steganography". IEEE Transactions onInformation Forensics, 2021.3. Wang X., Yu K., Wu S., et al. "ESRGAN: Enhanced Super-Resolution Generative Adversarial Networks".ECCV Workshops, 2018.4. Ronneberger O., Fischer P., Brox T. "U-Net: Convolutional Networks for Biomedical Image Segmentation".MICCAI, 2015.5. Zhu J., Kaplan R., Johnson J., Fei-Fei L. "HiDDeN: Hiding Data With Deep Networks". NeurIPS, 2018.6. Xiao Y., Zhang L., Qian Z. "Robust Steganography via Contrast Limited Adaptive Histogram Equalization".Signal Processing: Image Communication, 2019.7. Baluja S. "Hiding Images in Plain Sight: Deep Steganography". NeurIPS, 2017.8. Liu Y., Huang Y., et al. "A Survey on Deep Learning Based Steganography and Steganalysis". ACM ComputingSurveys, 2021.9. Tang W., Li Y., et al. "An Overview of Deep-Learning-Based Image Steganography". IEEE Access, 2022.10. Kim J., Park H. "Lightweight Deep Learning Models for Real-Time Steganography". Pattern RecognitionLetters, 2022.У статті досліджено задачу підвищення ефективності стеганографічних методів через застосуваннясучасних підходів до покращання зображень. Особливу увагу приділено методам попередньої обробки, а такожзастосуванню глибоких нейронних мереж, таких як ESRGAN, U-Net та SteganoGAN. Представлено результатиекспериментів із використанням адаптивного покращання контрасту та згладжування, що дозволяє збільшитиприховану ємність контейнера і зменшити вірогідність виявлення прихованих даних. У роботі досліджено впливметодів попередньої обробки на результати стеганографічного приховування повідомлень. Експериментальновстановлено, що попередня обробка зображень суттєво впливає на ефективність LSB-стеганографії. Найкращунепомітність (високі PSNR та SSIM) і стійкість до JPEG-компресії продемонстрував підхід із адаптивноюсегментацією текстур. Перетворення у YCbCr також дозволяє підвищити стійкість без втрати пропускноїздатності. Водночас вирівнювання гістограми погіршує стійкість через підвищення контрастності. Таким чином,адаптивні методи попередньої обробки доцільно використовувати для підвищення безпеки і якості приховуванняінформації. Проведено порівняння моделей штучного інтелекту для задач стеганографії. У ході роботипроаналізовано моделі штучного інтелекту, які застосовуються у задачах стеганографії. Встановлено, щоефективність конкретної архітектури (наприклад, U-Net чи SteganoGAN) суттєво залежить від поставленихзавдань, типу вхідних даних, вимог до пропускної здатності каналу, а також доступних обчислювальних ресурсів.Зроблено висновок, що адаптивне застосування методів глибокого навчання та попередньої обробки зображеньдозволяє підвищити як стійкість прихованих повідомлень, так і їх непомітність, що є критично важливим длясучасної цифрової стеганографії.Ключові слова: стеганографія, покращання зображень, ESRGAN, глибоке навчання, захист інформації,нейронні мережі. Перелік посилань 1. Zhou J., Liu J., et al. "An Image Preprocessing Framework for Steganography". Journal of VisualCommunication and Image Representation, 2020.2. Wang H., Chen Y. "Color Space Transformations for Enhanced Steganography". IEEE Transactions onInformation Forensics, 2021.3. Wang X., Yu K., Wu S., et al. "ESRGAN: Enhanced Super-Resolution Generative Adversarial Networks".ECCV Workshops, 2018.4. Ronneberger O., Fischer P., Brox T. "U-Net: Convolutional Networks for Biomedical Image Segmentation".MICCAI, 2015.5. Zhu J., Kaplan R., Johnson J., Fei-Fei L. "HiDDeN: Hiding Data With Deep Networks". NeurIPS, 2018.6. Xiao Y., Zhang L., Qian Z. "Robust Steganography via Contrast Limited Adaptive Histogram Equalization".Signal Processing: Image Communication, 2019.7. Baluja S. "Hiding Images in Plain Sight: Deep Steganography". NeurIPS, 2017.8. Liu Y., Huang Y., et al. "A Survey on Deep Learning Based Steganography and Steganalysis". ACM ComputingSurveys, 2021.9. Tang W., Li Y., et al. "An Overview of Deep-Learning-Based Image Steganography". IEEE Access, 2022.10. Kim J., Park H. "Lightweight Deep Learning Models for Real-Time Steganography". Pattern RecognitionLetters, 2022

    ДОСЛІДЖЕННЯ ЕФЕКТИВНОСТІ XDR РІШЕНЬ ДЛЯ ВИЯВЛЕННЯ ТА УСУВАННЯ ЗАГРОЗ

    No full text
    In the context of digital transformation, when organizations’ dependence on IT infrastructure is rapidly increasing, thelevel of cyber threats is also increasing. According to current data, the number of cyberattacks on organizations in 2024 increasedby 75% compared to the previous year, reaching 1876 incidents per week. In response to these challenges, the evolution ofprotection tools is taking place - traditional solutions are being replaced by comprehensive XDR (Extended Detection andResponse) systems. The study focuses on a comparative analysis of XDR and EDR (Endpoint Detection and Response)solutions, revealing their fundamental differences and practical effectiveness. XDR platforms provide advanced data collectionand analysis from various sources (network events, cloud services, email) instead of being limited to only end devices, whichallows you to form a holistic picture of the organization’s security. Special attention is paid to mechanisms for automatingmemory forensics in XDR systems: it was investigated that modern platforms are capable of automating data collection fromRAM and deploying specialized DFIR utilities through the "remediation" mechanism. A practical comparison of the detectionof the same EDR and XDR threats was conducted using the example of a multi-phase phishing attack using LOLBINs, whichdemonstrated the significant advantages of XDR in response speed and accuracy. It was established that XDR solutionsdemonstrate higher efficiency due to the correlation of events from different sources, the use of machine learning and behavioralanalytics. The main XDR solutions on the market (CrowdStrike Falcon, SentinelOne Singularity, Microsoft Defender, ElasticSecurity) and their features in the implementation of protection mechanisms were analyzed. The results of the study confirmthat the integration of XDR with additional systems (network devices, cloud services, authentication systems) creates a comprehensive protection system, significantly increasing the ability of organizations to counter modern complex cyber threats.Additionally, the study found that XDR systems effectively detect hidden fileless attacks and rootkits, which traditionally posethe greatest challenge for conventional defenses. Another important aspect is the ability of XDR solutions to reduce the numberof false positives through contextual analysis of events, which reduces the burden on security teams and increases the overallefficiency of SOC operations. Despite the significant advantages of XDR, the study emphasizes that for full-fledged protectionof critical infrastructure, it is necessary to combine automated XDR solutions with deep expertise of DFIR specialists, especiallywhen analyzing new and unknown threats.Keywords: XDR, EDR, CrowdStrike Falcon, Microsoft Defender, malware, memory forensics, LOLBINs, filelessattacks, cybersecurity, integration of defense systems. References1. Check Point Research Reports Highest Increase of Global Cyber Attacks Seen in Last Two Years – a 30%Increase in Q2 2024 Global Cyber Attacks. URL: https://blog.checkpoint.com/research/check-point-research-reportshighest-increase-of-global-cyber-attacks-seen-in-last-two-years-a-30-increase-in-q2-2024-global-cyber-attacks (датазвернення: 10.05.2025).2. Microsoft Digital Defense Report: 600 million cyberattacks per day around the globe. URL:https://news.microsoft.com/en-cee/2024/11/29/microsoft-digital-defense-report-600-million-cyberattacks-per-dayaround-the-globe/ (дата звернення: 10.05.2025).3. «XDR: The Evolution of Endpoint Security Solutions – Superior Extensibility and Analytics to Satisfy theOrganizational Needs of the Future» [Електронний ресурс]. Режим доступу: https://www.researchgate.net/ publication/354190628 _ XDR _ The_ Evolution_ of_ Endpoint_ Security_ Solutions_ Superior_ Extensibility_ and_ Analytics_to_Satisfy_the_Organizational_Needs_of_the_Future.4. «Performance Evaluation of Open-Source Endpoint Detection and Response Combining Google RapidResponse and Osquery for Threat Detection» [Електронний ресурс]. Режим доступу: https://www.researchgate.net/publication / 358697816 _ Performance _Evaluation_of_Open-Source_Endpoint_Detection_and_Response_Combining_Google_Rapid_Response_and_Osquery_for_Threat_Detection.5. «Evolution of Endpoint Detection and Response (EDR) in Cyber Security: A Comprehensive Review»[Електронний ресурс]. Режим доступу: https: // www.e3s-conferences.org / articles / e3sconf / pdf / 2024/86/e3sconf_rawmu2024_01006.pdf.6. Demystifying Behavior-Based Malware Detection at Endpoints» [Електронний ресурс]. Режим доступу:https://arxiv.org/html/2405.06124v1.7. XDR: The Evolution of Endpoint Security Solutions -Superior Extensibility and Analytics to Satisfy theOrganizational Needs of the Future [Електронний ресурс]. Режим доступу: https://www.researchgate.net/publication/354190628 _ XDR _ The _ Evolution_of_Endpoint _ Security _ Solutions _ Superior _ Extensibility_and_Analytics_to_Satisfy_the_Organizational_Needs_of_the_Future#:~:text=XDR%3A%20The%20Evolution%20of%20Endpoint,Organizational.8. Antivirus vs EDR vs XDR: Key Differences and Benefits. URL: https://www.threatintelligence.com/blog/antivirus-vs-edr-vs-xdr (дата звернення: 10.05.2025).9. Extended Detection and Response (XDR). CrowdStrike. URL: https: // www.crowdstrike.com/en-us/cybersecurity-101/endpoint-security/extended-detection-and-response-xdr/ (дата звернення: 10.05.2025).10. Microsoft 365 Defender integration with Microsoft Sentinel. Microsoft Learn. URL: https://learn.microsoft.com / en-us / azure / sentinel / microsoft-365-defender-sentinel-integration?tabs=defender-portal (дата звернення:10.05.2025).11. Block C2 communication with Defender for Endpoint. URL: https://jeffreyappel.nl/block-c2-communicationwith-defender-for-endpoint/ (дата звернення: 10.05.2025).12. Fake CAPTCHA websites hijack your clipboard to install information stealers. Malwarebytes. URL:https://www.malwarebytes.com/blog/news/2025/03/fake-captcha-websites-hijack-your-clipboard-to-install-informationstealers (дата звернення: 10.05.2025).13. Fileless malware threats: Recent advances, analysis approach through memory forensics and researchchallenges: [Електронний ресурс]. Режим доступу: https: // www.researchgate.net/publication/364769363_Fileless_malware_threats_Recent_advances_analysis_approach_through_memory_forensics_and_research_challenges.14. A Malware Detection Approach Based on Deep Learning and Memory Forensics: [Електронний ресурс].Режим доступу: https://www.mdpi.com/2073-8994/15/3/758.15. Microsoft Detection Tools Sniff Out Fileless Malware: [Електронний ресурс]. Режим доступу: https://www.trendmicro.com / vinfo / us /security/news/cybercrime-and-digital-threats/microsoft-detection-tools-sniff-out-fileless-malware.16. The Role of Anomaly Detection in XDR: Enhancing Threat Visibility and Response: [Електронний ресурс].Режим доступу: https://fidelissecurity.com/cybersecurity-101/xdr-security/anomaly-detection-in-xdr-solutions/.17. Cortex XDR IOC rule details: [Електронний ресурс]. Режим доступу: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Cloud-Documentation/IOC-rule-details.18. XDR Threat Investigation: [Електронний ресурс]. Режим доступу: https: // docs.trendmicro.com/en-us/documentation/article/trend-vision-one-xdr-threat-investigation-whatsnew.19. Perks of Sigma and YARA rules in an EDR: [Електронний ресурс]. Режим доступу: https://harfanglab.io/blog/product/perks-sigma-yara-edr/.20. What Are SIGMA Rules: [Електронний ресурс]. Режим доступу: https://socprime.com/blog/sigma-rulesthe-beginners-guide/.21. What is a C2 server? [Електронний ресурс]. Режим доступу: https://www.portnox.com/cybersecurity101/what-is-a-c2-server/.22. Offensive WMI – Active Directory Enumeration [Електронний ресурс]. Режим доступу: https://0xinfection.github.io/posts/wmi-ad-enum/.23. DKIM, SPF and DMARC Guid [Електронний ресурс]. Режим доступу: https: // www.mimecast.com/content/dkim-spf-dmarc-explained/.24. Block C2 communication with Defender for Endpoint: [Електронний ресурс]. Режим доступу: https://jeffreyappel.nl/block-c2-communication-with-defender-for-endpoint/.25. How Cortex XDR Global Analytics Protects Against Supply Chain Attacks: [Електронний ресурс]. Режимдоступу: https://www.paloaltonetworks.com/blog/security-operations/how-cortex-xdr-global-analytics-protects-againstsupply-chain-attacks/.26. Antimalware Scan Interface (AMSI): [Електронний ресурс]. Режим доступу: https://learn.microsoft.com/windows/win32/amsi/antimalware-scan-interface-portal.У контексті цифрової трансформації, коли залежність організацій від ІТ-інфраструктури стрімко зростає,збільшується і рівень кіберзагроз. Згідно з актуальними даними, кількість кібератак на організації у 2024 роцізросла на 75% у порівнянні з попереднім роком, досягнувши 1876 інцидентів на тиждень. У відповідь на цівиклики відбувається еволюція засобів захисту — на зміну традиційним рішенням приходять комплексні системиXDR (Extended Detection and Response). Дослідження фокусується на порівняльному аналізі XDR та EDR(Endpoint Detection and Response) рішень, розкриваючи їх фундаментальні відмінності та практичнуефективність. XDR-платформи забезпечують розширене збирання та аналіз даних з різноманітних джерел(мережеві події, хмарні сервіси, електронна пошта) замість обмеження лише кінцевими пристроями, що дозволяєформувати цілісну картину безпеки організації. Особливу увагу приділено механізмам автоматизації memoryforensics в XDR-системах: досліджено, що сучасні платформи здатні автоматизувати збір даних з оперативноїпам'яті та розгортати спеціалізовані DFIR-утиліти через механізм "remediation". Проведено практичне порівняннявиявлення однакових загроз EDR та XDR на прикладі багатофазної фішингової атаки з використанням LOLBINs,що продемонструвало суттєві переваги XDR у швидкості та точності реагування. Встановлено, що XDR-рішеннядемонструють вищу ефективність завдяки кореляції подій з різних джерел, застосуванню машинного навчаннята поведінкової аналітики. Проаналізовано основні XDR-рішення на ринку (CrowdStrike Falcon, SentinelOneSingularity, Microsoft Defender, Elastic Security) та їх особливості в реалізації механізмів захисту. Результатидослідження підтверджують, що інтеграція XDR з додатковими системами (мережевими пристроями, хмарнимисервісами, системами аутентифікації) створює комплексну систему захисту, значно підвищуючи спроможністьорганізацій протидіяти сучасним складним кіберзагрозам. Додатково, дослідження виявило, що XDR-системиефективно виявляють приховані fileless-атаки та руткіти, які традиційно становлять найбільшу проблему длязвичайних засобів захисту. Важливим аспектом є також здатність XDR-рішень зменшувати кількість хибнихспрацювань завдяки контекстуальному аналізу подій, що знижує навантаження на команди безпеки та підвищуєзагальну ефективність операцій SOC. Незважаючи на значні переваги XDR, дослідження підкреслює, що дляповноцінного захисту критично важливої інфраструктури необхідне поєднання автоматизованих XDR-рішень зглибокою експертизою DFIR-фахівців, особливо при аналізі нових та невідомих загроз.Ключові слова: XDR, EDR, CrowdStrike Falcon, Microsoft Defender, шкідливе програмне забезпечення,memory forensics, LOLBINs, безфайлові атаки, кібербезпека, інтеграція систем захисту. Перелік посилань1. Check Point Research Reports Highest Increase of Global Cyber Attacks Seen in Last Two Years – a 30%Increase in Q2 2024 Global Cyber Attacks. URL: https://blog.checkpoint.com/research/check-point-research-reportshighest-increase-of-global-cyber-attacks-seen-in-last-two-years-a-30-increase-in-q2-2024-global-cyber-attacks (датазвернення: 10.05.2025).2. Microsoft Digital Defense Report: 600 million cyberattacks per day around the globe. URL:https://news.microsoft.com/en-cee/2024/11/29/microsoft-digital-defense-report-600-million-cyberattacks-per-dayaround-the-globe/ (дата звернення: 10.05.2025).3. «XDR: The Evolution of Endpoint Security Solutions – Superior Extensibility and Analytics to Satisfy theOrganizational Needs of the Future» [Електронний ресурс]. Режим доступу: https://www.researchgate.net/ publication/354190628 _ XDR _ The_ Evolution_ of_ Endpoint_ Security_ Solutions_ Superior_ Extensibility_ and_ Analytics_to_Satisfy_the_Organizational_Needs_of_the_Future.4. «Performance Evaluation of Open-Source Endpoint Detection and Response Combining Google RapidResponse and Osquery for Threat Detection» [Електронний ресурс]. Режим доступу: https://www.researchgate.net/publication / 358697816 _ Performance _Evaluation_of_Open-Source_Endpoint_Detection_and_Response_Combining_Google_Rapid_Response_and_Osquery_for_Threat_Detection.5. «Evolution of Endpoint Detection and Response (EDR) in Cyber Security: A Comprehensive Review»[Електронний ресурс]. Режим доступу: https: // www.e3s-conferences.org / articles / e3sconf / pdf / 2024/86/e3sconf_rawmu2024_01006.pdf.6. Demystifying Behavior-Based Malware Detection at Endpoints» [Електронний ресурс]. Режим доступу:https://arxiv.org/html/2405.06124v1.7. XDR: The Evolution of Endpoint Security Solutions -Superior Extensibility and Analytics to Satisfy theOrganizational Needs of the Future [Електронний ресурс]. Режим доступу: https://www.researchgate.net/publication/354190628 _ XDR _ The _ Evolution_of_Endpoint _ Security _ Solutions _ Superior _ Extensibility_and_Analytics_to_Satisfy_the_Organizational_Needs_of_the_Future#:~:text=XDR%3A%20The%20Evolution%20of%20Endpoint,Organizational.8. Antivirus vs EDR vs XDR: Key Differences and Benefits. URL: https://www.threatintelligence.com/blog/antivirus-vs-edr-vs-xdr (дата звернення: 10.05.2025).9. Extended Detection and Response (XDR). CrowdStrike. URL: https: // www.crowdstrike.com/en-us/cybersecurity-101/endpoint-security/extended-detection-and-response-xdr/ (дата звернення: 10.05.2025).10. Microsoft 365 Defender integration with Microsoft Sentinel. Microsoft Learn. URL: https://learn.microsoft.com / en-us / azure / sentinel / microsoft-365-defender-sentinel-integration?tabs=defender-portal (дата звернення:10.05.2025).11. Block C2 communication with Defender for Endpoint. URL: https://jeffreyappel.nl/block-c2-communicationwith-defender-for-endpoint/ (дата звернення: 10.05.2025).12. Fake CAPTCHA websites hijack your clipboard to install information stealers. Malwarebytes. URL:https://www.malwarebytes.com/blog/news/2025/03/fake-captcha-websites-hijack-your-clipboard-to-install-informationstealers (дата звернення: 10.05.2025).13. Fileless malware threats: Recent advances, analysis approach through memory forensics and researchchallenges: [Електронний ресурс]. Режим доступу: https: // www.researchgate.net/publication/364769363_Fileless_malware_threats_Recent_advances_analysis_approach_through_memory_forensics_and_research_challenges.14. A Malware Detection Approach Based on Deep Learning and Memory Forensics: [Електронний ресурс].Режим доступу: https://www.mdpi.com/2073-8994/15/3/758.15. Microsoft Detection Tools Sniff Out Fileless Malware: [Електронний ресурс]. Режим доступу: https://www.trendmicro.com / vinfo / us /security/news/cybercrime-and-digital-threats/microsoft-detection-tools-sniff-out-fileless-malware.16. The Role of Anomaly Detection in XDR: Enhancing Threat Visibility and Response: [Електронний ресурс].Режим доступу: https://fidelissecurity.com/cybersecurity-101/xdr-security/anomaly-detection-in-xdr-solutions/.17. Cortex XDR IOC rule details: [Електронний ресурс]. Режим доступу: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Cloud-Documentation/IOC-rule-details.18. XDR Threat Investigation: [Електронний ресурс]. Режим доступу: https: // docs.trendmicro.com/en-us/documentation/article/trend-vision-one-xdr-threat-investigation-whatsnew.19. Perks of Sigma and YARA rules in an EDR: [Електронний ресурс]. Режим доступу: https://harfanglab.io/blog/product/perks-sigma-yara-edr/.20. What Are SIGMA Rules: [Електронний ресурс]. Режим доступу: https://socprime.com/blog/sigma-rulesthe-beginners-guide/.21. What is a C2 server? [Електронний ресурс]. Режим доступу: https://www.portnox.com/cybersecurity101/what-is-a-c2-server/.22. Offensive WMI – Active Directory Enumeration [Електронний ресурс]. Режим доступу: https://0xinfection.github.io/posts/wmi-ad-enum/.23. DKIM, SPF and DMARC Guid [Електронний ресурс]. Режим доступу: https: // www.mimecast.com/content/dkim-spf-dmarc-explained/.24. Block C2 communication with Defender for Endpoint: [Електронний ресурс]. Режим доступу: https://jeffreyappel.nl/block-c2-communication-with-defender-for-endpoint/.25. How Cortex XDR Global Analytics Protects Against Supply Chain Attacks: [Електронний ресурс]. Режимдоступу: https://www.paloaltonetworks.com/blog/security-operations/how-cortex-xdr-global-analytics-protects-againstsupply-chain-attacks/.26. Antimalware Scan Interface (AMSI): [Електронний ресурс]. Режим доступу: https://learn.microsoft.com/windows/win32/amsi/antimalware-scan-interface-portal

    AGILE ПІДХІД ДО ВПРОВАДЖЕННЯ МЕТОДОЛОГІЇ ЗБОРУ, ОБРОБКИ, ЗБЕРІГАННЯ ТА КЛАСИФІКАЦІЇ ДАНИХ У ВІДПОВІДНОСТІ ДО ВИМОГ SOC2 TYPE2

    No full text
    The issues related to compliance with the SOC 2 Type 2 standard when managing data in cloud environments areconsidered. The work focuses on such key aspects as building a Medallion architecture, implementing access control, andautomating data classification processes. It is studied that one of the main requirements is the complexity of integrating SOC 2with Agile processes and the high threshold of entry for organizations without deep expertise in AI and DevOps. In addition,the dangers are posed by the shortcomings of traditional classification methods, which do not always take into account thesemantic context and require significant resources for scaling. It is also important to obtain the risks associated with theinconsistency of encryption policies and the lack of effective monitoring. The use of LLM models integrated into MicrosoftAzure Fabric allows you to automate classification, increase the accuracy of entity detection, and provide multi-level accesscontrol. The proposed architecture is due to the flexibility of Agile and the strictness of the SOC 2 Type 2 regulatoryrequirements, which ensures constant compliance with the standard even in dynamic environments. Additionally, the use of theScrum approach allows for increased implementation of architecture components with regular auditing and processtransparency. Based on the most common problems that companies face when preparing for a SOC 2 audit, the main threats andways to minimize them were analyzed. The study considered both technological aspects (ETL, OneLake, Power BI, DataActivator) and organizational ones (role distribution, sprint management). The analysis showed that the key difficulties areassociated with ensuring continuous monitoring, compliance with access policies and audit transparency. Taking thesechallenges into account, recommendations have been developed for implementing databases on Azure Fabric and Azure AIFoundry using Agile-praktic. Using iterative approaches, regular testing of controls, and integration of automated tools cansignificantly reduce the risk of SOC 2 Type 2 non-compliance. In addition, an organization can improve data managementefficiency and provide customer trust to account for process transparency, continuous auditing, and adaptive architecture.Keywords: SOC 2 Type 2, Agile, Scrum, Microsoft Azure, Medallion Architecture, OneLake, Fabric Data Factory,Power BI, Data Activator, LLM, data classification, encryption, auditing, access control. References1. The Art of Service, SOC 2 Type 2 Report: A Complete Guide, 2020 Edition, 2020.2. Deineka O., Harasymchuk O., Partyka A., Obshta A., Application of LLM for assessing the effectiveness andpotential risks of the information classification system according to SOC 2 type II, CEUR Workshop Proceedings, 2025.3. Deineka O., Harasymchuk O., Partyka A., Kozachok V., Information classification framework according to SOC2 Type II, CEUR Workshop Proceedings, 2024.4. Deineka O., Harasymchuk O., Partyka A., Obshta A., Korshun N., Designing Data Classification and SecureStore Policy According to SOC 2 Type II, CEUR Workshop Proceedings, 2024.5. Ozdemir S., Quick Start Guide to Large Language Models: Strategies and Best Practices, 2023.6. Armbrust M., Ghodsi A., Xin R., Zaharia M., Lakehouse: A New Generation of Open Platforms that Unify DataWarehousing and Advanced Analytics, CIDR, 2021.10. Martseniuk Y., et al.: Shadow IT risk analysis in public cloud infrastructure // CEUR Workshop Proceedings.2024, 3800, pp. 22-31.11. Martseniuk Y., et al.: Universal centralized secret data management for automated public cloud provisioning //CEUR Workshop Proceedings. – 2024, 3826, pp. 72–81.12. Shevchuk D., et al.: Designing Secured Services for Authentication, Authorization, and Accounting of Users //CEUR Workshop Proceedings, 2023, 3550. pp. 217-225.13. Microsoft, Azure Documentation, [Online]. Available: https://docs.microsoft.com/en-us/azure/.14. Microsoft, SharePoint Documentation, [Online]. Available: https://learn.microsoft.com/en-us/sharepoint.15. Microsoft, OneDrive Documentation, [Online]. Available: https://learn.microsoft.com/en-us/onedrive.16. Microsoft, Power BI Documentation, [Online]. Available: https://learn.microsoft.com/en-us/power-bi/.17. Schwaber, K., & Sutherland, J. The Scrum Guide: The Definitive Guide to Scrum. Scrum.org, 2020.https://scrumguides.org/download?utm_source=chatgpt.com.18. Cohn, M. Succeeding with Agile: Software Development Using Scrum. Addison-Wesley, 2009. ISBN-10:0321579364; ISBN-13: 978-0321579362.19. Beck, K. et al. Manifesto for Agile Software Development. Agile Alliance, 2001.20. Rubin, K. S. Essential Scrum: A Practical Guide to the Most Popular Agile Process. Addison-Wesley, 2012.21.Kniberg, H. Scrum and XP from the Trenches. InfoQ, 2007. https://scrumexpansion.org/scrum-guideexpansion-pack/?utm_source=chatgpt.com.Розглянуті проблеми, пов’язані з відповідністю стандарту SOC 2 Type 2 під час управління даними вхмарних середовищах. Праця зосереджена на таких ключових аспектах, як побудова Medallion-архітектури,впровадження контролів доступу та автоматизація процесів класифікації даних. Досліджено, що одними зголовних викликів є складність інтеграції вимог SOC 2 з Agile-процесами та високий поріг входу для організаційбез глибокої експертизи в AI та DevOps. Крім того, небезпеку становлять недоліки традиційних методівкласифікації, які не завжди враховують семантичний контекст і потребують значних ресурсів длямасштабування. Важливо також враховувати ризики, пов’язані з невідповідністю політик шифрування тавідсутністю ефективного моніторингу. Використання LLM-моделей, інтегрованих у Microsoft Azure Fabric,дозволяє автоматизувати класифікацію, підвищити точність виявлення сутностей і забезпечити багаторівневийконтроль доступу. Запропонована архітектура поєднує гнучкість Agile та суворість регуляторних вимог SOC 2Type 2, що забезпечує постійну відповідність стандарту навіть у динамічних середовищах. Додатково,застосування Scrum-підходу дозволяє поступово впроваджувати компоненти архітектури з регулярним аудитомі прозорістю процесів. На основі найпоширеніших проблем, з якими стикаються компанії під час підготовки доSOC 2 аудиту, було проаналізовано основні загрози та шляхи їх мінімізації. У ході дослідження розглядалися яктехнологічні аспекти (ETL, OneLake, Power BI, Data Activator), так і організаційні (розподіл ролей, управлінняспринтами). Аналіз показав, що ключові труднощі пов’язані із забезпеченням безперервного моніторингу,відповідністю політик доступу та прозорістю аудиту. З урахуванням цих викликів були розроблені рекомендаціїщодо впровадження архітектури на базі Azure Fabric і Azure AI Foundry із використанням Agile-практик.Використання ітеративних підходів, регулярного тестування контролів та інтеграції автоматизованихінструментів дозволяє значно зменшити ризики невідповідності SOC 2 Type 2. Крім того, організація можепідвищити ефективність управління даними та забезпечити довіру клієнтів за рахунок прозорості процесів,безперервного аудиту та адаптивної архітектури..Ключові слова: SOC 2 Type 2, Agile, Scrum, Microsoft Azure, Medallion Architecture, OneLake, Fabric DataFactory, Power BI, Data Activator, LLM, класифікація даних, шифрування, аудит, контроль доступу. Перелік посилань1. The Art of Service, SOC 2 Type 2 Report: A Complete Guide, 2020 Edition, 2020.2. Deineka O., Harasymchuk O., Partyka A., Obshta A., Application of LLM for assessing the effectiveness andpotential risks of the information classification system according to SOC 2 type II, CEUR Workshop Proceedings, 2025.3. Deineka O., Harasymchuk O., Partyka A., Kozachok V., Information classification framework according to SOC2 Type II, CEUR Workshop Proceedings, 2024.4. Deineka O., Harasymchuk O., Partyka A., Obshta A., Korshun N., Designing Data Classification and SecureStore Policy According to SOC 2 Type II, CEUR Workshop Proceedings, 2024.5. Ozdemir S., Quick Start Guide to Large Language Models: Strategies and Best Practices, 2023.6. Armbrust M., Ghodsi A., Xin R., Zaharia M., Lakehouse: A New Generation of Open Platforms that Unify DataWarehousing and Advanced Analytics, CIDR, 2021.10. Martseniuk Y., et al.: Shadow IT risk analysis in public cloud infrastructure // CEUR Workshop Proceedings.2024, 3800, pp. 22-31.11. Martseniuk Y., et al.: Universal centralized secret data management for automated public cloud provisioning //CEUR Workshop Proceedings. – 2024, 3826, pp. 72–81.12. Shevchuk D., et al.: Designing Secured Services for Authentication, Authorization, and Accounting of Users //CEUR Workshop Proceedings, 2023, 3550. pp. 217-225.13. Microsoft, Azure Documentation, [Online]. Available: https://docs.microsoft.com/en-us/azure/.14. Microsoft, SharePoint Documentation, [Online]. Available: https://learn.microsoft.com/en-us/sharepoint.15. Microsoft, OneDrive Documentation, [Online]. Available: https://learn.microsoft.com/en-us/onedrive.16. Microsoft, Power BI Documentation, [Online]. Available: https://learn.microsoft.com/en-us/power-bi/.17. Schwaber, K., & Sutherland, J. The Scrum Guide: The Definitive Guide to Scrum. Scrum.org, 2020.https://scrumguides.org/download?utm_source=chatgpt.com.18. Cohn, M. Succeeding with Agile: Software Development Using Scrum. Addison-Wesley, 2009. ISBN-10:0321579364; ISBN-13: 978-0321579362.19. Beck, K. et al. Manifesto for Agile Software Development. Agile Alliance, 2001.20. Rubin, K. S. Essential Scrum: A Practical Guide to the Most Popular Agile Process. Addison-Wesley, 2012.21.Kniberg, H. Scrum and XP from the Trenches. InfoQ, 2007. https://scrumexpansion.org/scrum-guideexpansion-pack/?utm_source=chatgpt.com

    МЕТОДИКА ОПИСУ ВЗАЄМОЗВ’ЯЗКІВ МІЖ МНОЖИНАМИ ПРОГРАМНОГО ЗАБЕЗПЕЧЕННЯ, ДЕФЕКТІВ, СПОСОБІВ ЇХ ВИЯВЛЕННЯ У ПРОЦЕСІ ДІАГНОСТУВАННЯ ПОШКОДЖЕНОГО ПРОГРАМНОГО ЗАБЕЗПЕЧЕННЯ

    No full text
    The article considers the current scientific and applied problem of diagnosing damaged software that has been affectedby cyberattacks in the context of increasing the cyber resilience of modern information systems. The purpose of the study is toformalize the process of diagnosing damaged software as a result of cyberattacks, which provides a systematic representationof the relationships between sets of software modules, defects, methods for their detection and recovery methods. To achievethis goal, the methods of system analysis, mathematical modeling, set theory and formal logic were used, which alloweddescribing the technological process of diagnosing in the form of a set of interconnected formal relations. The developedformalized methodology makes it possible to proceed to automated diagnostics of damaged software. It provides systematizationof information about defects, increases the accuracy of localization of violations, reduces the complexity of analysis and reducesthe recovery time after incidents. The mathematical apparatus proposed in the work allows us to reflect not only the fact of theappearance of a defect, but also its properties, relationships with other defects, conditions of occurrence and possible methodsof elimination. The results of the study have theoretical and practical significance. The proposed methodology contributes toincreasing the efficiency of software recovery after cyberattacks, minimizing financial and reputational losses, as well asimproving the quality and reliability of information systems. It creates the prerequisites for further research in the direction ofdeveloping intelligent diagnostic systems based on machine learning and logical modeling of relationships between defects.Keywords: automation of diagnostics, system recovery, software diagnostics, cybersecurity, cyberattacks, mathematicalmodeling, formalized model. References1. Hamretskyi, R. M., & Hnatiuk, V. O. (2024). Огляд та аналіз методів та моделей оцінки якостіпрограмного забезпечення в інформаційно-комунікаційних системах. Інформаційні технології, кібербезпека,64(4), 445–447. https://doi.org/10.18372/2310-5461.63.19752.2. Meng, X., Jing, B., Wang, S., Pan, J., Huang, Y., & Jiao, X. (2023). Fault knowledge graph construction andplatform development for aircraft PHM. Sensors (Basel), 24(1), 231. https://doi.org/10.3390/s24010231.3. Agrawal, T., Walia, G. S., & Anu, V. K. (2024). Development of a software design error taxonomy: Asystematic literature review. SN Computer Science, 5, 467. https://doi.org/10.1007/s42979-024-02797-2.4. Verma, A., Agarwal, A., Rathore, M., Bisht, S., & Singh, D. (2023). Preferential selection of software qualitymodels based on a multi-criteria decision-making approach. International Journal of Software Innovation (IJSI), 11(1),1–13. https://doi.org/10.4018/IJSI.315739.5. Kordunova, Yu. S. (2023). Analysis and development of a conceptual model for lifecycle management ofspecialized safety-oriented software. Ukrainian Journal of Information Technology, 5(2), 72–78. https://doi.org/10.23939/ujit2023.02.072.6. Duarte, B. B., Falbo, R. A., Guizzardi, G., Guizzardi, R., & Souza, V. E. S. (2021). An ontological analysis ofsoftware system anomalies and their associated risks. Data & Knowledge Engineering, 134, 101892. https://doi.org/10.1016/j.datak.2021.101892.7. Hu, X., Chen, J. M., & Li, H. (2024). Software security vulnerability patterns based on ontology. Journal ofBeijing University of Aeronautics and Astronautics, 50(10), 3084–3099. https://doi.org/10.13700/j.bh.1001-5965.2022.0783.8. Yakovyna, V. S., & Symets, I. I. (2021). Прогнозування дефектів програмного забезпечення ансамблемнейронних мереж. Науковий вісник НЛТУ України, 31(6), 104–111.9. Biletskyi, T. P., & Fedasiuk, D. V. (2021). Прогнозування дефектів у програмному забезпеченніалгоритмами глибинного навчання CNN та RNN. Науковий вісник НЛТУ України, 31(2), 114–120.10. Khil, O. S., & Yakovyna, V. S. (2023). Аналіз проблеми застосування методів машинного навчання дляоцінювання та прогнозування дефектів програмного забезпечення. Науковий вісник НЛТУ України, 33(3), 110–116.11. Yehorov, S. V., & Shkvarnytska, T. Yu. (2020). Розширений метод аналізу шкідливого програмногозабезпечення з метою створення сигнатур. Вісник Університету «Україна», 1(24), 161–169.12. Alshazly, A. A., Elfatatry, A. M., & Abougaba, M. S. (2024). Detecting defects in software requirementsspecification. Alexandria Engineering Journal, 53(3), 513–527.13. Rumbutis, L., Slotkene, A., & Pliuskuviene, B. (2024). Визначення атрибутів якості програмногозабезпечення на основі прогнозування дефектів коду: систематичний огляд літератури. Нові тенденції вкомп’ютерних науках, 2(1), 57–68. https://doi.org/10.3846/ntcs.2024.21305.14. Oivo, M., Abrahamsson, P., Corral, L., & Russo, B. (Eds.). (2020). Product-Focused Software ProcessImprovement – 16th International Conference, PROFES 2015: Proceedings (pp. 380–396). Springer Verlag.https://doi.org/10.1007/978-3-319-26844-6_28.У статті розглянуто актуальну науково-прикладну проблему діагностування пошкодженого програмногозабезпечення, що зазнало впливу кібератак, у контексті підвищення кіберстійкості сучасних інформаційнихсистем. Метою дослідження є формалізація процесу діагностування пошкодженого програмного забезпеченнявнаслідок дії кібератак, що забезпечує системне представлення взаємозв’язків між множинами програмнихмодулів, дефектів, способів їх виявлення та методів відновлення. Для досягнення поставленої мети застосованометоди системного аналізу, математичного моделювання, теорії множин і формальної логіки, які дозволилиописати технологічний процес діагностування у вигляді сукупності взаємопов’язаних формальних відношень.Розроблена формалізована методика дає можливість перейти до автоматизованого діагностування пошкодженогопрограмного забезпечення. Вона забезпечує систематизацію відомостей про дефекти, підвищує точністьлокалізації порушень, знижує трудомісткість аналізу та скорочує час відновлення після інцидентів.Математичний апарат, що запропонований у роботі, дозволяє відображати не лише факт появи дефекту, але ййого властивості, взаємозв’язки з іншими дефектами, умови виникнення та можливі способи усунення.Результати дослідження мають теоретичне і практичне значення. Запропонована методика сприяє підвищеннюефективності відновлення працездатності програмного забезпечення після кібератак, мінімізації фінансових ірепутаційних втрат, а також покращенню якості та надійності функціонування інформаційних систем. Вонастворює передумови для подальших досліджень у напрямі розробки інтелектуальних діагностичних систем,заснованих на машинному навчанні та логічному моделюванні взаємозв’язків між дефектами.Ключові слова: автоматизація діагностики, відновлення працездатності систем, діагностуванняпрограмного забезпечення, кібербезпека, кібератаки, математичне моделювання, формалізована модель. Перелік посилань1. Hamretskyi, R. M., & Hnatiuk, V. O. (2024). Огляд та аналіз методів та моделей оцінки якостіпрограмного забезпечення в інформаційно-комунікаційних системах. Інформаційні технології, кібербезпека,64(4), 445–447. https://doi.org/10.18372/2310-5461.63.19752.2. Meng, X., Jing, B., Wang, S., Pan, J., Huang, Y., & Jiao, X. (2023). Fault knowledge graph construction andplatform development for aircraft PHM. Sensors (Basel), 24(1), 231. https://doi.org/10.3390/s24010231.3. Agrawal, T., Walia, G. S., & Anu, V. K. (2024). Development of a software design error taxonomy: Asystematic literature review. SN Computer Science, 5, 467. https://doi.org/10.1007/s42979-024-02797-2.4. Verma, A., Agarwal, A., Rathore, M., Bisht, S., & Singh, D. (2023). Preferential selection of software qualitymodels based on a multi-criteria decision-making approach. International Journal of Software Innovation (IJSI), 11(1),1–13. https://doi.org/10.4018/IJSI.315739.5. Kordunova, Yu. S. (2023). Analysis and development of a conceptual model for lifecycle management ofspecialized safety-oriented software. Ukrainian Journal of Information Technology, 5(2), 72–78. https://doi.org/10.23939/ujit2023.02.072.6. Duarte, B. B., Falbo, R. A., Guizzardi, G., Guizzardi, R., & Souza, V. E. S. (2021). An ontological analysis ofsoftware system anomalies and their associated risks. Data & Knowledge Engineering, 134, 101892. https://doi.org/10.1016/j.datak.2021.101892.7. Hu, X., Chen, J. M., & Li, H. (2024). Software security vulnerability patterns based on ontology. Journal ofBeijing University of Aeronautics and Astronautics, 50(10), 3084–3099. https://doi.org/10.13700/j.bh.1001-5965.2022.0783.8. Yakovyna, V. S., & Symets, I. I. (2021). Прогнозування дефектів програмного забезпечення ансамблемнейронних мереж. Науковий вісник НЛТУ України, 31(6), 104–111.9. Biletskyi, T. P., & Fedasiuk, D. V. (2021). Прогнозування дефектів у програмному забезпеченніалгоритмами глибинного навчання CNN та RNN. Науковий вісник НЛТУ України, 31(2), 114–120.10. Khil, O. S., & Yakovyna, V. S. (2023). Аналіз проблеми застосування методів машинного навчання дляоцінювання та прогнозування дефектів програмного забезпечення. Науковий вісник НЛТУ України, 33(3), 110–116.11. Yehorov, S. V., & Shkvarnytska, T. Yu. (2020). Розширений метод аналізу шкідливого програмногозабезпечення з метою створення сигнатур. Вісник Університету «Україна», 1(24), 161–169.12. Alshazly, A. A., Elfatatry, A. M., & Abougaba, M. S. (2024). Detecting defects in software requirementsspecification. Alexandria Engineering Journal, 53(3), 513–527.13. Rumbutis, L., Slotkene, A., & Pliuskuviene, B. (2024). Визначення атрибутів якості програмногозабезпечення на основі прогнозування дефектів коду: систематичний огляд літератури. Нові тенденції вкомп’ютерних науках, 2(1), 57–68. https://doi.org/10.3846/ntcs.2024.21305.14. Oivo, M., Abrahamsson, P., Corral, L., & Russo, B. (Eds.). (2020). Product-Focused Software ProcessImprovement – 16th International Conference, PROFES 2015: Proceedings (pp. 380–396). Springer Verlag.https://doi.org/10.1007/978-3-319-26844-6_28

    ІНТЕГРОВАНИЙ ПІДХІД ДО АНАЛІЗУ ІНВЕСТИЦІЙ У ЦИФРОВУ ІНФРАСТРУКТУРУ НА ОСНОВІ КЛАСТЕРИЗАЦІЇ ТА РЕГРЕСІЙНИХ МОДЕЛЕЙ

    No full text
    This article proposes an integrated approach to analysing investments in digital infrastructure based on the combineduse of clustering algorithms and regression modelling. The relevance of the study is driven by the increasing importance ofdigital infrastructure in regional economic competitiveness and the need to optimize investment decisions under resourceconstraints. The methodology applies the K-Means and DBSCAN algorithms to segment regions according to their levels ofdigital maturity, IT employment, internet penetration, and the availability of digital public services. For each identified cluster,a separate multiple linear regression model is constructed to quantify the impact of key digital indicators on investment volumes.Model performance is evaluated using R², RMSE, and MAE metrics with the application of k-fold cross-validation to ensurerobustness. The integration of clustering results with regression analysis enables the development of an analytical assessmentmatrix that compares actual and predicted investment levels and identifies priority areas for investment policy. The proposedapproach enhances the evidence-based nature of managerial decision-making, allows the identification of efficient and inefficient regions, and supports the formulation of recommendations for optimising the allocation of resources in digitalinfrastructure. The findings may be applied by government institutions, analytical centres, and ICT enterprises for strategicplanning and forecasting within the framework of digital transformation initiatives.Keywords: digital infrastructure; investments; clustering; K-Means; DBSCAN; regression analysis; digital economy;machine learning. References1. Brynjolfsson E., McAfee A. The Second Machine Age: Work, Progress, and Prosperity in a Time of BrilliantTechnologies. New York: W.W. Norton & Company, 2014. 306 p. URL: https://wwnorton.com/books/the-secondmachine-age/2. Goldfarb A., Tucker C. Digital Economics // Journal of Economic Literature. 2019. Vol. 57, No. 1. P. 3-43.DOI: 10.1257/jel.201714523. Montgomery D. C., Peck E. A., Vining G. G. Introduction to Linear Regression Analysis. 6th ed. Hoboken:Wiley, 2021. 704 p. URL: https: // www.wiley.com /en-us/Introduction+to+Linear+Regression+Analysis%2C+6th+Edition-p-97811195787274. Jain A. K. Data Clustering: 50 Years Beyond K-Means // Pattern Recognition Letters. 2010. Vol. 31, No. 8. P.651-666. DOI: 10.1016/j.patrec.2009.09.0115. Ester M., Kriegel H.-P., Sander J., Xu X. A Density-Based Algorithm for Discovering Clusters in Large SpatialDatabases with Noise // Proceedings of the Second International Conference on Knowledge Discovery and Data Mining(KDD’96). Portland, 1996. P. 226-231. URL: https://file.biolab.si/papers/1996-DBSCAN-KDD.pdf.6. Галузов С. Ю., Бондарчук А. П., Бажан Т. О., Корецька В. О. Застосування методів Data Science дляпрогнозування попиту в ритейлі // Телекомунікаційні та інформаційні технології. 2023. № 3. С. 56-62. DOI:10.31673/2412-4338.2023.035965.7. Бажан Т. О. Порівняльний аналіз методів машинного навчання для побудови прогнозів // Сучаснийзахист інформації.2024.Т. 4 (60). С. 125-130. DOI: 10.31673/2409-7292.2024.040013.8. Бажан Т. О. Інструменти очищення даних для прогнозування інвестицій за допомогою машинногонавчання // Інновації: Збірник наукових праць Державного університету інформаційно-комунікаційнихтехнологій. Київ: ДУІКТ, 2024. С. 45-50. URL: https://duikt.edu.ua/uploads/p_2779_56719466.pdf.Стаття присвячена розробці інтегрованого підходу до аналізу інвестицій у цифрову інфраструктуру наоснові поєднання алгоритмів кластеризації та методів регресійного моделювання. Актуальність дослідженнязумовлена зростаючою роллю цифрової інфраструктури у забезпеченні економічної конкурентоспроможностірегіонів та необхідністю оптимізації інвестиційних рішень в умовах обмежених ресурсів. У роботі використаноалгоритми K-Means і DBSCAN для сегментації регіонів за показниками цифрової зрілості, рівнем ІТ-зайнятості,інтернет-покриття та доступності цифрових сервісів. Для кожного отриманого кластера побудовано окремумножинну лінійну регресійну модель, що дає змогу оцінити вплив ключових цифрових факторів на обсягінвестицій. Якість моделей оцінено за метриками R², RMSE та MAE із застосуванням k-fold cross-validation.Інтеграція результатів кластеризації та регресійного аналізу дозволила сформувати матрицю аналітичної оцінки,яка порівнює фактичні та прогнозні інвестиції і визначає пріоритетні напрями інвестиційної політики.Запропонований підхід забезпечує підвищення обґрунтованості управлінських рішень, дозволяє виявлятиефективні та неефективні регіони, а також формувати рекомендації щодо оптимізації фінансування цифровоїінфраструктури. Отримані результати можуть бути використані органами влади, аналітичними центрами та ІКТкомпаніями для підтримки стратегічного планування цифрового розвитку.Ключові слова: цифрова інфраструктура; інвестиції; кластеризація; K-Means; DBSCAN; регресійнийаналіз; цифрова економіка; машинне навчання. Перелік посилань1. Brynjolfsson E., McAfee A. The Second Machine Age: Work, Progress, and Prosperity in a Time of BrilliantTechnologies. New York: W.W. Norton & Company, 2014. 306 p. URL: https://wwnorton.com/books/the-secondmachine-age/2. Goldfarb A., Tucker C. Digital Economics // Journal of Economic Literature. 2019. Vol. 57, No. 1. P. 3-43.DOI: 10.1257/jel.201714523. Montgomery D. C., Peck E. A., Vining G. G. Introduction to Linear Regression Analysis. 6th ed. Hoboken:Wiley, 2021. 704 p. URL: https: // www.wiley.com /en-us/Introduction+to+Linear+Regression+Analysis%2C+6th+Edition-p-97811195787274. Jain A. K. Data Clustering: 50 Years Beyond K-Means // Pattern Recognition Letters. 2010. Vol. 31, No. 8. P.651-666. DOI: 10.1016/j.patrec.2009.09.0115. Ester M., Kriegel H.-P., Sander J., Xu X. A Density-Based Algorithm for Discovering Clusters in Large SpatialDatabases with Noise // Proceedings of the Second International Conference on Knowledge Discovery and Data Mining(KDD’96). Portland, 1996. P. 226-231. URL: https://file.biolab.si/papers/1996-DBSCAN-KDD.pdf.6. Галузов С. Ю., Бондарчук А. П., Бажан Т. О., Корецька В. О. Застосування методів Data Science дляпрогнозування попиту в ритейлі // Телекомунікаційні та інформаційні технології. 2023. № 3. С. 56-62. DOI:10.31673/2412-4338.2023.035965.7. Бажан Т. О. Порівняльний аналіз методів машинного навчання для побудови прогнозів // Сучаснийзахист інформації.2024.Т. 4 (60). С. 125-130. DOI: 10.31673/2409-7292.2024.040013.8. Бажан Т. О. Інструменти очищення даних для прогнозування інвестицій за допомогою машинногонавчання // Інновації: Збірник наукових праць Державного університету інформаційно-комунікаційнихтехнологій. Київ: ДУІКТ, 2024. С. 45-50. URL: https://duikt.edu.ua/uploads/p_2779_56719466.pdf

    КОМПЛЕКСНА СИСТЕМА ДЕРЖАВНОЇ ПОЛІТИКИ АДАПТАЦІЇ РИНКУ ПРАЦІ ДО ТЕХНОЛОГІЧНИХ ЗМІН

    Get PDF
    The fourthindustrial revolution fundamentally transforms global labor markets, creating unprecedentedchallenges for employment systems and social protection mechanisms. Technological innovationslead to massive reduction of traditional jobs while simultaneously creating new professional nichesrequiring fundamentally different competencies. Existing social protection and professional trainingsystems prove insufficiently adaptive to rapid technological changes, actualizing the need forcomprehensive approaches to state employment policy. The study aims to develop a comprehensivestate policy system ensuring effective labor market adaptation to technological innovations throughintegration of retraining instruments, social protection, and stimulation of new job creation. The research analyzed international experience of adaptation policy formation in fifteen countries,conducted comparative analysis of different state policy system effectiveness, and developed anintegrated worker support system concept. Main results include identification of active state policysystem advantages combining preventive and reactive support instruments, substantiation of earlywarning system necessity for labor market changes, development of comprehensive system structurewith four interconnected components, and determination of financing and coordination mechanisms.The study demonstrated critical importance of systematic approach to labor market adaptation,effectiveness of personalized professional development approaches through individual learningaccounts, and feasibility of social protection system modernization considering technologicalunemployment specifics. Research showed that most effective are systems with high active labormarket policy expenditures, personalized professional development approaches, and adaptive socialprotection systems. Further research should focus on detailed elaboration of proposed systemcomponent implementation mechanisms considering economic effects of element interactions.Keywords: technological transformation of employment, labor market policy, worker retraining,social protection, economic digitalization, workplace automation, professionaldevelopment, technological adaptation. References1. Acemoglu, D., & Restrepo, P. (2020). Robots and Jobs: Evidence from US Labor Markets.Journal of Political Economy, 128(6), 2188-2244.2. Arntz, M., Gregory, T., & Zierahn, U. (2016). The Risk of Automation for Jobs in OECDCountries: A Comparative Analysis. Paris: OECD Publishing. 3. Degryse, C. (2016). Digitalisation of the Economy and Its Impact on Labour Markets. Brussels:European Trade Union Institute.4. Frey, C. B., & Osborne, M. A. (2017). The Future of Employment: How Susceptible are Jobs toComputerisation? Technological Forecasting and Social Change, 114, 254-280.5. International Labour Organization. (2024). World Employment and Social Outlook: Trends2024. Geneva: ILO Publications.6. Mazur, G. (2018). European Approaches to Digital Skills and Competences Development.European Journal of Education, 53(4), 503-515.7. OECD. (2024). OECD Employment Outlook 2024: The Future of Work in the Digital Age.Paris: OECD Publishing.8. OECD. (2023). OECD Skills Outlook 2023: Skills and Labour Market Resilience. Paris: OECDPublishing.9. Balakireva, O. M., & Dmytruk, D. A. (2020). Tsyfrova transformatsiya ekonomiky Ukrayiny:bazovi skladovi ta pereshkody. [Digital transformation of Ukraine's economy: basic components andobstacles] Ekonomika i prohnozuvannya, 1, 37-53.10. Derzhavna sluzhba statystyky Ukrayiny. (2024). Obstezhennya robochoyi syly v Ukrayini u2023 rotsi. [Labor force survey in Ukraine in 2023] Kyiv: Derzhstat Ukrayiny.11. Kolot, A. M., & Herasymenko, O. O. (2019). Sfera pratsi v umovakh hlobalnoyi sotsioekonomichnoyi realnosti 2020: vyklyky dlya Ukrayiny. [Labor sphere in the conditions of globalsocio-economic reality 2020: challenges for Ukraine] Ekonomika Ukrayiny, 3, 3-23.12. Libanova, E. M. (2019). Maybutnye sfery pratsi: hlobalni vyklyky ta natsionalni vidpovidi.[Future of the labor sphere: global challenges and national responses] Demohrafiya ta sotsialnaekonomika, 3(37), 11-26.13. Ministerstvo tsyfrovoyi transformatsiyi Ukrayiny. (2023). Zvit pro stan tsyfrovizatsiyi vUkrayini 2023. [Report on the state of digitalization in Ukraine 2023] Kyiv: Mintsyfry.14. Petrova, I. L. (2020). Profesiyno-tekhnichna osvita Ukrayiny v konteksti yevropeyskykhtendentsiy rozvytku lyudskoho kapitalu. [Vocational and technical education of Ukraine in the contextof European trends in human capital development] Demohrafiya ta sotsialna ekonomika, 2(40), 182-195.15. Skilskyy, O. I., & Zhulkanych, O. M. (2021). Transformatsiya rynku pratsi v umovakhtsyfrovizatsiyi ekonomiky. [Labor market transformation in the conditions of economicdigitalization] Innovatsiyna ekonomika, 5-6, 41-47.16. European Commission. (2023). Digital Economy and Society Index (DESI) 2023. Brussels:European Commission.17. McKinsey Global Institute. (2023). The Age of AI: Work, Progress, and Prosperity in a Timeof Brilliant Technologies. New York: McKinsey & Company.18. Singapore Workforce Development Agency. (2024). SkillsFuture Annual Report 2023.Singapore: WDA.19. World Bank. (2024). Ukraine: Digital Economy Development Project – Implementation StatusReport. Washington, D.C.: World Bank Group.20. World Economic Forum. (2023). Future of Jobs Report 2023. Geneva: WEF.Метою дослідження є розробка комплексної системи державної політики, що забезпечуєефективну адаптацію ринку праці до технологічних інновацій через інтеграцію інструментівперекваліфікації, соціального захисту та стимулювання створення нових робочих місць.Проаналізовано міжнародний досвід формування політики адаптації до технологічних змін уп'ятнадцяти країнах, проведено порівняльний аналіз ефективності різних систем державноїполітики, розроблено концепцію інтегрованої системи підтримки працівників. Основнимирезультатами є виявлення переваг активних систем державної політики, обґрунтуваннянеобхідності створення механізмів раннього попередження змін на ринку праці, розробкаструктури комплексної системи з чотирма взаємопов'язаними компонентами. Дослідженняпоказало доцільність модернізації систем соціального захисту з урахуванням специфікитехнологічного безробіття.Ключові слова: технологічна трансформація зайнятості, державна політика ринку праці,перекваліфікація працівників, соціальний захист, цифровізація економіки, автоматизаціяробочих місць, професійний розвиток, адаптація до технологічних змін. Список використаних джерел1. Acemoglu, D., & Restrepo, P. (2020). Robots and Jobs: Evidence from US Labor Markets.Journal of Political Economy, 128(6), 2188-2244.2. Arntz, M., Gregory, T., & Zierahn, U. (2016). The Risk of Automation for Jobs in OECDCountries: A Comparative Analysis. Paris: OECD Publishing. 3. Degryse, C. (2016). Digitalisation of the Economy and Its Impact on Labour Markets. Brussels:European Trade Union Institute.4. Frey, C. B., & Osborne, M. A. (2017). The Future of Employment: How Susceptible are Jobs toComputerisation? Technological Forecasting and Social Change, 114, 254-280.5. International Labour Organization. (2024). World Employment and Social Outlook: Trends2024. Geneva: ILO Publications.6. Mazur, G. (2018). European Approaches to Digital Skills and Competences Development.European Journal of Education, 53(4), 503-515.7. OECD. (2024). OECD Employment Outlook 2024: The Future of Work in the Digital Age.Paris: OECD Publishing.8. OECD. (2023). OECD Skills Outlook 2023: Skills and Labour Market Resilience. Paris: OECDPublishing.9. Balakireva, O. M., & Dmytruk, D. A. (2020). Tsyfrova transformatsiya ekonomiky Ukrayiny:bazovi skladovi ta pereshkody. [Digital transformation of Ukraine's economy: basic components andobstacles] Ekonomika i prohnozuvannya, 1, 37-53.10. Derzhavna sluzhba statystyky Ukrayiny. (2024). Obstezhennya robochoyi syly v Ukrayini u2023 rotsi. [Labor force survey in Ukraine in 2023] Kyiv: Derzhstat Ukrayiny.11. Kolot, A. M., & Herasymenko, O. O. (2019). Sfera pratsi v umovakh hlobalnoyi sotsioekonomichnoyi realnosti 2020: vyklyky dlya Ukrayiny. [Labor sphere in the conditions of globalsocio-economic reality 2020: challenges for Ukraine] Ekonomika Ukrayiny, 3, 3-23.12. Libanova, E. M. (2019). Maybutnye sfery pratsi: hlobalni vyklyky ta natsionalni vidpovidi.[Future of the labor sphere: global challenges and national responses] Demohrafiya ta sotsialnaekonomika, 3(37), 11-26.13. Ministerstvo tsyfrovoyi transformatsiyi Ukrayiny. (2023). Zvit pro stan tsyfrovizatsiyi vUkrayini 2023. [Report on the state of digitalization in Ukraine 2023] Kyiv: Mintsyfry.14. Petrova, I. L. (2020). Profesiyno-tekhnichna osvita Ukrayiny v konteksti yevropeyskykhtendentsiy rozvytku lyudskoho kapitalu. [Vocational and technical education of Ukraine in the contextof European trends in human capital development] Demohrafiya ta sotsialna ekonomika, 2(40), 182-195.15. Skilskyy, O. I., & Zhulkanych, O. M. (2021). Transformatsiya rynku pratsi v umovakhtsyfrovizatsiyi ekonomiky. [Labor market transformation in the conditions of economicdigitalization] Innovatsiyna ekonomika, 5-6, 41-47.16. European Commission. (2023). Digital Economy and Society Index (DESI) 2023. Brussels:European Commission.17. McKinsey Global Institute. (2023). The Age of AI: Work, Progress, and Prosperity in a Timeof Brilliant Technologies. New York: McKinsey & Company.18. Singapore Workforce Development Agency. (2024). SkillsFuture Annual Report 2023.Singapore: WDA.19. World Bank. (2024). Ukraine: Digital Economy Development Project – Implementation StatusReport. Washington, D.C.: World Bank Group.20. World Economic Forum. (2023). Future of Jobs Report 2023. Geneva: WEF

    1,003

    full texts

    2,308

    metadata records
    Updated in last 30 days.
    State University of Telecommunications Open Journals System
    Access Repository Dashboard
    Do you manage Open Research Online? Become a CORE Member to access insider analytics, issue reports and manage access to outputs from your repository in the CORE Repository Dashboard! 👇