State University of Telecommunications Open Journals System
Not a member yet
    2308 research outputs found

    Метод оцінки розповсюдження неправдивої інформації за допомогою спеціальних програм та технологій на базі середовища Інтернет

    No full text
    Information struggle is an integral part of relations and a form of struggle between the parties, each of which strives to inflict defeat (damage) on the enemy in the form of information influences in his information sphere. Any component or segment of the informational-psychological space can become the object of information struggle, including the following types: mass and individual consciousness of citizens; socio-political systems and processes; information infrastructure; informational and psychological resources. The main method of information struggle is the dissemination of false information. It should be noted that technologies alone cannot win the information war. The battlefield goes beyond algorithms and code, reaching into the very fabric of our societies. The analysis of existing methods of reliable protection of the process of forming public opinion on the Internet showed that there are no such methods and technologies today and cannot be. The article deals with the actual issue of disseminating false information. A method of assessing the spread of false information using special programs and technologies based on the Internet environment is proposed. The given expressions: to evaluate the effectiveness of applied disinformation and to evaluate the openness of the false information management system. This makes it possible to make a quantitative assessment of the impact of false information on the population of the state and on the formation of public opinion in general. Keywords: false information, method, disinformation, distribution, fake, astroterfing.Інформаційне протиборство складова частина відносин і форма боротьби сторін, кожна з яких прагне завдати противнику поразку (збитки) у вигляді інформаційних впливів в його інформаційну сферу. Об’єктом інформаційного протиборства може стати будь-який компонент чи сегмент інформаційно-психологічного простору, у тому числі такі види: масова та індивідуальна свідомість громадян; соціально-політичні системи та процеси; інформаційна інфраструктура; інформаційні та психологічні ресурси. Головним методом інформаційного протиборства є розповсюдження неправдивої інформації. Слід звернути увагу, що самі по собі технології не можуть виграти інформаційну війну. Поле бою виходить за межі алгоритмів і коду, сягаючи самої тканини наших суспільств. Аналіз існуючих методів надійного захисту процесу формування громадської думки в мережі Інтернет, показав, що на сьогоднішній день таких методів та технологій немає і бути не може. У статті розглядається актуальне питання розповсюдження неправдивої інформації. Запропоновано метод оцінки розповсюдження неправдивої інформації за допомогою спеціальних програм та технологій на базі середовища інтернет. Наведені вирази: для оцінки ефективності застосованої дезінформації та для оцінки відкритості системи управління неправдивої інформації. Це дозволяє зробити кількісну оцінку впливу неправдивої інформації на населення держави та на формування громадської думки взагалі. Ключові слова: неправдива інформація, метод, дезінформація, розповсюдження, фейк, астротерфінг. Перелік посилань1. Savchenko, V., Ilin, O., Hnidenko, N., Tkachenko, O., Laptiev, O., Lehominova, S. Detection of Slow DDoS Attacks based on User’s Behavior Forecasting. International Journal of Emerging Trends in Engineering Research (IJETER) Volume 8. No. 5, May 2020. Scopus Indexed - ISSN 2347 – 3983. pp.2019 – 2025.2. Гнатієнко, Г. М., Снитюк, В. Є. Експертні технології прийняття рішень. − К.: McLaut, 2008. − 444 с.3. Schefer-Wenzl, S., Strembeck, M. Modeling support for role-based delegation in process-aware information systems. Business and Information Systems Engineering. 6 (4). 2014. pp. 215-237. DOI: 10.1007/s12599-014-0343-34. Лаптєва, Т. Алгоритм визначення міри існування недостовірної інформації в умовах інформаційного протиборства. Кібербезпека: освіта, наука, техніка. No 2 (14), 2021, с. 15-25. DOI 10.28925/2663-4023.2021.14.1525, ISSN 2663-4023.5. Лукова-Чуйко, Н., Лаптєва, Т. Виділення та відбір ознак для визначення неправдивої інформації. V Міжнародна науково-практична конференція. “Проблеми кібербезпеки інформаційно-телекомунікаційних систем” (PCSIТS)”27-28 жовтня 2022 р. Київ, Україна. Збірник матеріалів доповідей та тез. С 13-15.6. Лаптєв, О. А., Бабенко, Р. В., Правдивий, А. М., Зозуля, С. А., Стефурак, О. Р. Удосконалена методика вибору послідовності пріоритетів обслуговання потоків інформації. Науково-практичний журнал «Зв'язок». К.: ДУТ, 2020. №4 (146), С.27 – 31.7. Наконечний, В., Лаптєв, О., Погасій, С., Лазаренко, С., Мартинюк, Г. Відбір джерел з неправдивою інформацію методом бджолиної колонії. Наукоємні технології. Інформаційні технології, кібербезпека. Том 52 № 4 (2021) С.330-337. DOI: https://doi.org/10.18372/2310-5461.52.163798. Laptiev, O., Sobchuk, V., Sobchuk, A., Laptiev, S., Laptieva, T. Удосконалена модель оцінювання економічних витрат на систему захисту інформації в соціальних мережах. Кібербезпека: освіта, наука, техніка. Том 4 № 12 (2021): рр.19-28.9. Citron, D. K. Cyber mobs, disinformation, and death videos: the Internet as it is (and as it should be) Michigan Law Review. – Ann Arbor, 2020. – Vol. 118, N 6. pp. 1073–1094.10. Лаптєва, Т. О. Методика виявлення неправдивої інформації для безпеки Держави. Всеукраїнській науково-практичній конференції студентів, аспірантів та молодих вчених «Об’єднані наукою: перспективи міждисциплінарних досліджень» 23-24 листопада 2023 р. Київ. Україна. С.131–132.11. Pesetski, A. Deepfakes: a new content category for a digital age. William & Mary bill of rights journal. – Lexington, 2020. – Vol. 29, N 2. pp. 503–532

    Дослідження в галузі квантово-безпечної криптографії

    No full text
    Quantum computing, based on the principles of quantum mechanics, is rapidly gaining momentum as a promising field of information technology. However, with the growing capabilities of quantum computing comes a new level of cybersecurity. Quantum-secure cryptography is emerging as a response to the potential threats posed by quantum computers to traditional cryptographic methods. The main goal of quantum-secure cryptography is to ensure the security of data in information systems, as quantum computing becomes more and more accessible. In this study, we thoroughly studied the essence of quantum-secure cryptography, its fundamental principles and applications. We have explored the advantages and limitations of this new cryptographic paradigm and discussed the potential challenges that arise in the context of its implementation. In addition, we analyzed the current state of research in the field of quantum-secure cryptography and highlighted the prospects for further development of this intriguing technology. We have researched potential threats and possible ways to solve them. Additionally, we reviewed a quantum risk assessment methodology that helps identify and manage threats in the context of quantum security. Finally, we trace existing examples and recent developments in the field of quantum-secure cryptography, revealing their potential to improve information security in the future. Overall, the research allows for a better understanding of the importance and prospects of quantum-secure cryptography in today’s digital world. Keywords: Quantum computing, cryptography, encryption, Quantum Key Distribution. References1. What is Cryptography? https://aws.amazon.com/what-is/cryptography/2. Brett, Daniel. (2021). Symmetric vs. Asymmetric Encryption: What’s the Difference? https://www.trentonsystems.com/en-us/resource-hub/blog/symmetric-vs-asymmetric-encryption3. Nikita, Gupta. (2022). Symmetric vs. Asymmetric Encryption – What are differences? https://www.ssl2buy.com/wiki/symmetric-vs-asymmetric-encryption-what-are-differences4. What Are The Differences between Classical, Quantum and Post-Quantum Cryptography? https://www.quantropi.com/differences-between-classical-quantum-post-quantum-cryptography/5. Quantum Resistance and the Signal Protocol. https://signal.org/blog/pqxdh/6. Post-Quantum Cryptography in Blockchain Security. https://www.gate.io/uk/learn/articles/post-quantum-cryptography-in-blockchain-security/10617. Strategy: Quantum Risk Assessment And Data Protection. https://cybersecurityventures.com/strategy-quantum-risk-assessment-and-data-protection/8. Michele Mosca, John Mulholland. A Methodology for Quantum Risk Assessment. (2017) https://globalriskinstitute.org/publication/a-methodology-for-quantum-risk-assessment/9. Secure socket layer application program apparatus and method. https://patents.google.com/patent/US565739010. iMessage with PQ3: The new state of the art in quantum-secure messaging at scale. (2024) https://security.apple.com/blog/imessage-pq3/11. Trond, Andersen, Yuri, Lensky. (2023). An important step towards improved quantum computers. https://blog.google/technology/research/an-important-step-towards-improved-quantum-computers/12. Jason, Zander. (2024). Advancing science: Microsoft and Quantinuum demonstrate the most reliable logical qubits on record with an error rate 800x better than physical qubits. https://blogs.microsoft.com/blog/2024/04/03/advancing-science-microsoft-and-quantinuum-demonstrate-the-most-reliable-logical-qubits-on-record-with-an-error-rate-800x-better-than-physical-qubits/Квантові обчислення, засновані на принципах квантової механіки, стрімко набирають обертів як перспективна галузь інформаційних технологій. Однак із зростанням можливостей квантових обчислень з’являється новий рівень кібербезпеки. Квантово-захищена криптографія з’являється як відповідь на потенційні загрози, створені квантовими комп’ютерами для традиційних криптографічних методів. Основною метою квантово-захищеної криптографії є забезпечення безпеки даних в інформаційних системах, оскільки квантові обчислення стають все більш доступними. У цьому дослідженні ми детально вивчили сутність квантово-захищеної криптографії, її фундаментальні принципи та застосування. Ми дослідили переваги та обмеження цієї нової криптографічної парадигми та обговорили потенційні проблеми, які виникають у контексті її впровадження. Крім того, ми проаналізували поточний стан досліджень у галузі квантово-захищеної криптографії та висвітлили перспективи подальшого розвитку цієї інтригуючої технології. Ми дослідили потенційні загрози та можливі способи їх вирішення. Крім того, ми переглянули методологію квантової оцінки ризиків, яка допомагає ідентифікувати загрози та керувати ними в контексті квантової безпеки. Нарешті, ми простежуємо наявні приклади та останні розробки в галузі квантово-захищеної криптографії, розкриваючи їхній потенціал для покращення інформаційної безпеки в майбутньому. Загалом дослідження дозволяє краще зрозуміти важливість і перспективи квантово-захищеної криптографії в сучасному цифровому світі. Ключові слова: квантові обчислення, криптографія, шифрування, квантовий розподіл ключів

    Аналіз використання алгоритмів штучного інтелекту для глибокого аналізу фінансових даних

    No full text
    It is difficult to imagine the modern world without the use of artificial intelligence. This seemingly futuristic technology has already become an integral part of our reality. Neural networks are so accessible that they can be used not only by large corporations like Microsoft or Google, but also by ordinary users in their daily activities. Artificial intelligence is now being used to teach, assist in work, and perform boring and routine tasks. That is, such a tool can support the user in any activity, even in the forecasting and analysis of his financial situation both in the present and in the future. The paper analyzes the potential possibility of using different types of neural models to solve problems related to work with personal finances. Artificial intelligence systems are capable of processing large amounts of data, identifying patterns and making fairly accurate predictions that will allow users to make informed decisions about their finances. This approach will provide an opportunity to analyze costs, revenues and other financial aspects, helping to optimize budgets, foresee potential risks and opportunities for growth. This article examines artificial intelligence models and algorithms capable of analyzing financial data and providing analytics based on it. In particular, neural networks such as recurrent neural networks RNNs and long short-term memory LSTMs are considered, which efficiently process time series of financial indicators. Generative-competitive GANs are used to generate synthetic data and detect anomalies. Machine learning methods, including regression, decision trees, random forest and gradient boosting, that allow forecasting and classification of financial indicators and metrics. Also, clustering algorithms such as k-means and DBSCAN, which can help in customer segmentation and anomaly detection, will be considered. Natural language processing models such as Llama 3 8B and GPT-3 to analyze users' text financial data and help generate insights. Keywords: artificial intelligence, forecasting, financial analysis, budget optimization, machine learning, regression, decision trees, random forests, clustering, natural language processing, Llama 3 8B.Сучасний світ важко уявити без використання штучного інтелекту. Ця, здавалося б, технологія майбутнього вже стала невід’ємною частиною нашої реальності. Нейронні мережі настільки доступні, що їх можуть використовувати не лише великі корпорації на кшталт Microsoft чи Google, а й звичайні користувачі у своїх повсякденних справах. Штучний інтелект зараз застосовують для навчання, допомоги в роботі та виконання нудних та рутинних завдань. Тобто такий інструмент може підтримати користувача у будь-якій діяльності, навіть у прогнозуванні та аналізі його фінансового стану як у теперішньому часі, так і на майбутнє. В роботі проаналізовано потенційну можливість використання різних видів нейронних моделей для вирішення проблем щодо роботи з особистими фінансами. Системи штучного інтелекту здатні обробляти великі обсяги даних, виявляти закономірності та робити доволі точні прогнози, що дозволить користувачам приймати обґрунтовані рішення щодо своїх фінансів. Такий підхід надасть можливість аналізувати витрати, доходи та інші фінансові аспекти, допомагаючи оптимізувати бюджети, передбачати потенційні ризики та можливості для зростання. У цій статті розглядаються моделі та алгоритми штучного інтелекту, здатні аналізувати фінансові дані та надавати аналітику на їх основі. Зокрема, розглядаються нейронні мережі, такі як рекурентні нейронні мережі RNN та довга короткочасна пам'ять LSTM, які ефективно обробляють часові ряди фінансових показників. Генеративно-змагальні мережі GAN використовуються для генерації синтетичних даних та виявлення аномалій. Методи машинного навчання, включаючи regression, decision trees, random forest та gradient boosting, що дозволяють здійснювати прогнозування та класифікацію фінансових показників та метрик. Також, будуть розглянуті алгоритми кластеризації, такі як k-means та DBSCAN, що можуть допомогти у сегментації клієнтів та виявленні аномалій. Моделі обробки природної мови, такі як Llama 3 8B та GPT-3, для аналізу текстових фінансових даних користувачів та допоможуть у генерації інсайтів. Ключові слова: штучний інтелект, прогнозування, аналіз фінансового стану, оптимізація бюджету, машинне навчання, регресія, дерева рішень, випадкові ліси, кластеризація, обробка природної мови, Llama 3 8B.   Перелік посилань Hochreiter, S., & Schmidhuber, J. (1997). Long Short-Term Memory. Neural Computation, 9(8), 1735-1780. https://www.bioinf.jku.at/publications/older/2604.pdf Goodfellow, I., Bengio, Y., & Courville, A. (2016). Deep Learning. MIT Press. http://www.deeplearningbook.org Chollet, F. (2018). Deep Learning with Python. Manning Publications. Link https://tanthiamhuat.wordpress.com/wp-content/uploads/2018/03/deeplearningwithpython.pdf Goodfellow, Ian & Pouget-Abadie, Jean & Mirza, Mehdi & Xu, Bing & Warde-Farley, David & Ozair, Sherjil & Courville, Aaron & Bengio, Y. (2014). Generative Adversarial Networks. Advances in Neural Information Processing Systems. 3. https://doi.org/1145/3422622. Kingma, D. P., & Welling, M. (2013). Auto-Encoding Variational Bayes. arXiv preprint arXiv:1312.6114. https://doi.org/10.48550/arXiv.1312.6114 Brown, T., Mann, B., Ryder, N., Subbiah, M., Kaplan, J., Dhariwal, P., ... & Amodei, D. (2020). Language Models are Few-Shot Learners. arXiv preprint arXiv:2005.14165. Llama 3 [Електронний ресурс] – Режим доступу до ресурсу: https://llama.meta.com/llama3/ - 19.05.2024 Radford, A., Narasimhan, K., Salimans, T., & Sutskever, I. (2018). Improving Language Understanding by Generative Pre-Training. OpenAI. https://paperswithcode.com/paper/improving-language-understanding-by Калинюк, Б.С., Замрій І.В. (2023) Методологія використання агентів штучного інтелекту в системах виявлення злочинів у банківських транзакціях. Міжнародна науково-практична конференція молодих вчених та студентів “Інженерія програмного забезпечення і передові інформаційні технології” (SoftTech-2023), присвячена 125-тій річниці КПІ імені І.Сікорського, 19-21 грудня 2023 року, Київ, Україна. с. 151-154. Understanding RNN, LSTM, and GRU: Architectures and Challenges in Processing Long Sequences [Електронний ресурс] – Режим доступу до ресурсу: https://medium.com/@ayeshashabbirshabbirahmad/understanding-rnn-lstm-and-gru-architectures-and-challenges-in-processing-long-sequences-71cf62b300b2. - 20.05.2024 Customers clustering: K-Means, DBSCAN and AP [Електронний ресурс] – Режим доступу до ресурсу: https://www.kaggle.com/code/datark1/customers-clustering-k-means-dbscan-and-ap. - 20.05.2024 Top 10 AI Forecast for 2024 by Analytics Vidhya [Електронний ресурс] – Режим доступу до ресурсу: https://www.analyticsvidhya.com/blog/2023/12/top-10-ai-forecast-for-2024-by-analytics-vidhya/#. - 21.05.202

    Розробка безпілотного робота на базі штучного інтелекту

    No full text
    The development of unmanned robots based on artificial intelligence (AI) is an extremely relevant topic in today's world, as AI is used to create a variety of autonomous systems capable of performing tasks without direct human intervention. One of the key aspects of such systems is the robot's ability to capture targets with the help of AI. The development of an AI-based unmanned robot for target capture includes several main stages. First, the theoretical foundations of AI and machine learning are studied, in particular image processing and object recognition algorithms. This phase involves analyzing the scientific literature, patents and technical documentation to understand the current state of affairs in the field of unmanned robots and to determine the most effective approaches to capture targets. This article is devoted to a detailed description of the development of an unmanned robot capable of autonomously capturing targets with the help of AI. After theoretical analysis, algorithms are developed for target detection and tracking using Convolutional Neural Networks (CNN) and Recurrent Neural Networks (RNN). Models are trained on large image datasets containing a variety of target variants. The drone's AI will work on the basis of Convolutional Neural Networks (CNN) for object recognition and Recurrent Neural Networks (RNN) for target tracking. The model will learn to recognize and capture objects using large data sets that include images of objects from different angles and lighting conditions. The software tools were analyzed, the architecture of the navigation system of the unmanned robot was developed, including the interaction of sensors, planning and control algorithms. Keywords: unmanned robot, artificial intelligence, target capture, object recognition, machine learning, depth sensors, manipulator, capture trajectory, autonomous robotics, sensor data integration.Розробка безпілотних роботів на основі штучного інтелекту (ШІ) є надзвичайно актуальною темою в сучасному світі, оскільки ШІ застосовується для створення різноманітних автономних систем, здатних виконувати завдання без прямого втручання людини. Одним з ключових аспектів таких систем є здатність робота до захоплення цілей за допомогою ШІ. Розробка безпілотного робота на базі ШІ для захоплення цілі включає кілька основних етапів. Спочатку вивчаються теоретичні основи ШІ та машинного навчання, зокрема алгоритми обробки зображень і розпізнавання об'єктів. Цей етап передбачає аналіз наукової літератури, патентів та технічної документації, щоб зрозуміти поточний стан справ у сфері безпілотних роботів і визначити найефективніші підходи до захоплення цілей. Ця стаття присвячена детальному опису розробки безпілотного робота, що здатний самостійно захоплювати цілі за допомогою ШІ. Після теоретичного аналізу розробляються алгоритми для виявлення та відстеження цілі, використовуючи згорткові нейронні мережі (CNN) та рекурентні нейронні мережі (RNN). Моделі тренуються на великих наборах даних зображень, що містять різноманітні варіанти цілей. ШІ безпілотного робота працюватиме на основі згорткових нейронних мереж (CNN) для розпізнавання об'єктів і рекурентних нейронних мереж (RNN) для відстеження цілей. Модель навчатиметься розпізнавати та захоплювати об'єкти за допомогою великих наборів даних, що включають зображення об'єктів з різних ракурсів та умов освітлення. Проаналізовано програмні інструменти, розроблено архітектуру системи навігації безпілотного робота, включаючи взаємодію сенсорів, алгоритмів планування та контролю. Ключові слова: безпілотний робот, штучний інтелект, захват цілі, розпізнавання об'єктів, машинне навчання, глибинні сенсори, маніпулятор, траєкторія захвату, автономна робототехніка, інтеграція сенсорних даних.   Перелік посилань Жеребух, О., Фармага, І. Використання нейронних мереж для визначення об’єктів на зображенні. Computer Design Systems. Theory And Practice. Vol. 6, No. 1, 2024. р. 232-240. https://science.lpnu.ua/sites/default/files/journal-paper/2024/apr/34361/42.pdf Коваль, О., Сарибога, Г. (2023). Система розпізнавання 3D об’єктів для безпілотних літальних апаратів на базі KINECT та ML. Measuring And Computing Devices In Technological Processes, (4), 74–81. https://doi.org/10.31891/2219-9365-2023-76-9 Géron, Hands-On Machine Learning with Scikit-Learn, Keras, and TensorFlow: Concepts, Tools, and Techniques to Build Intelligent Systems. O'Reilly Media, 2019, p. 1-400. https://powerunit-ju.com/wp-content/uploads/2021/04/Aurelien-Geron-Hands-On-Machine-Learning-with-Scikit-Learn-Keras-and-Tensorflow_-Concepts-Tools-and-Techniques-to-Build-Intelligent-Systems-OReilly-Media-2019.pdf Aggarwal, C. Neural Networks and Deep Learning: Springer, 2018. p. 120-300. https://warin.ca/ressources/books/2018_Book_NeuralNetworksAndDeepLearning.pdf Sutton, S., Barto A. G. Reinforcement Learning: An Introduction, 2nd Edition. 2018. p. 100-450. http://incompleteideas.net/book/bookdraft2017nov5.pdf Krizhevsky,, Sutskever, I., Hinton, G. E. ImageNet Classification with Deep Convolutional Neural Networks. Communications of the ACM, 2019. [Електронний ресурс]. URL: https://dl.acm.org/doi/10.1145/3065386 . NVIDIA Corporation. NVIDIA Jetson Platform for AI [Електронний ресурс]. URL: https://developer.nvidia.com/embedded-computin

    Дослідження методів та моделей оцінювання кіберзахисту критичної інфраструктури держави

    No full text
    The study "Methods and models for assessing the cyber protection of the state's critical infrastructure" focuses on the analysis of various methods of assessing cyber security risks with the aim of applying them to the protection of the national critical infrastructure. The work assesses the suitability of existing methods based on criteria such as risk identification, cyber incident response, cyber security recovery, cyber security and cyber resilience. Techniques such as FMEA, HAZOP, Checklist, SWIFT and others are considered, analyzing their ability to identify potential threats, respond to actual cyber incidents, ensure rapid recovery of operations and strengthen the overall resilience of the system against future attacks. In addition to the theoretical overview, the work includes a practical aspect, where the effectiveness of various methods and strategies is analyzed using a case study on real critical infrastructure systems. The study also suggests new approaches and models that could improve the integration and implementation of cybersecurity measures, given the complex nature of cyber threats. Thanks to the multifaceted analysis, the work highlights critical aspects in risk assessment and management, which allows for the formulation of recommendations for improving critical infrastructure protection measures. This study is of great importance to policymakers, cybersecurity experts, and critical infrastructure managers, as it provides an in-depth analysis and benchmarking of risk assessment methods, pointing out their strengths and weaknesses in the context of various aspects of cybersecurity. Keywords: Cyber ​​security, cyber resilience, critical infrastructure, information protection, cyber attack, cyber risks, cyber threat, cyber incidents, methods and models.Дослідження “Методи та моделі оцінювання кіберзахисту критичної інфраструктури держави” зосереджується на аналізі різних методів оцінки ризиків кібербезпеки з метою їх застосування до захисту національної критичної інфраструктури. Робота оцінює придатність існуючих методів на основі критеріїв, таких як ідентифікація ризиків, реагування на кіберінциденти, відновлення стану кібербезпеки, кіберахист та кіберстійкість. Розглядаються методики як FMEA, HAZOP, Checklist, SWIFT та інші, аналізуючи їх здатність ідентифікувати потенційні загрози, реагувати на актуальні кіберінциденти, забезпечувати швидке відновлення операцій та зміцнювати загальну стійкість системи до майбутніх атак. Крім теоретичного огляду, робота включає практичний аспект, де за допомогою кейс-стаді на реальних системах критичної інфраструктури аналізується ефективність різних методів і стратегій. Дослідження також пропонує нові підходи та моделі, що могли б покращити інтеграцію та виконання заходів кібербезпеки, враховуючи комплексний характер кіберзагроз. Завдяки багатогранному аналізу, робота висвітлює критичні аспекти в оцінці та управлінні ризиками, що дозволяє формулювати рекомендації для поліпшення заходів захисту критичної інфраструктури. Це дослідження має велике значення для розробників політик, експертів у галузі кібербезпеки та керівників критичних інфраструктур, оскільки надає глибокий аналіз та порівняльну оцінку методів оцінки ризиків, вказуючи на їхні сильні та слабкі сторони в контексті різних аспектів кібербезпеки. Ключові слова: Кібербезпека, кіберстійкість, критична інфраструктура, захист інформації, кібератака, кіберризики, кіберзагроза, кіберінциденти, методи та моделі.   Перелік посилань1. Barrett, M. (2018), Framework for Improving Critical Infrastructure Cybersecurity. Version 1.1, NIST Cybersecurity Framework, [online], https://doi.org/10.6028/NIST.CSWP.04162018, https://www.nist.gov/cyberframework (Accessed April 18, 2024)2. European Union Agency for Cybersecurity (ENISA), “Threat Landscape Report 2020,” режим доступу https://www.enisa.europa.eu/news/enisa-news/enisa-threat-landscape-20203. The Cybersecurity and Infrastructure Security Agency (CISA), “GuidelinesforSecuringtheCyberInfrastructure,” режим доступу: https://www.cisa.gov/resources-tools/programs/chemical-facility-anti-terrorism-standards-cfats/laws-and-regulations/cybersecurity-and-infrastructure-security-agency-guidance4. Schneier, Bruce, “Data and Goliath: The Hidden Battles to Collect Your Data and Control Your World” (W.W. Norton & Company, 2015).5. IBM X-Force Threat Intelligence Index 2024. https://www.ibm.com/reports/threat-intelligence6. Наказ Адміністрації Держспецзв’язку від 06.10.2021 № 601 “Про затвердження Методичних рекомендацій щодо підвищення рівня кіберзахисту критичної інформаційної інфраструктури” (зі змінами)7. Гончар, С. Ф. Оцінювання ризиків кібербезпеки інформаційних систем об’єктів критичної інфраструктури: монографія / С.Ф. Гончар. – К.: Альфа Реклама, 2019. – 176 с. ISBN 978-966-288-263-6 8. ISO/IEC 27005:2022 URL https://www.iso.org/standard/80585.html9. Patton, Michael Quinn. QualitativeResearchandEvaluationMethods. 3 ed, SagePublications, 2002.10. Gene Rowe, George Wright, The Delphi technique as a forecasting tool: issues and analysis, International Journal of Forecasting, Volume 15, Issue 4, 1999, Pages 353-375, ISSN 0169-207011. Linstone, Harold & Turoff, Murray. (1975). The Delphi Method: Techniques and Applications. 10.2307/3150755. 12. NIST SP 800-53 Rev. 5 URL https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final13. ISO/IEC 27001:2022 URL https://www.iso.org/standard/2700114. Roland, Harold E., and Brian. Moriarty. System Safety Engineering and Management / Harold E. Roland, Brian Moriarty. 2nd edition. NewYork: Wiley, 1990. Web.15. Fthenakis, Vasilis & Trammell, Steven. (2003). Reference Guide for Hazard Analysis in PV Facilities. 16. Pasman, Hans. (2015). Risk Analysis and Control for Industrial Processes – Gas, Oiland Chemicals; A System Perspective for Assessing and Avoiding Low-Probability, High-Consequence Events. 17. A. Alahmari and B. Duncan, “CybersecurityRiskManagementinSmallandMedium-SizedEnterprises: A SystematicReviewofRecentEvidence,” 2020 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (Cyber SA), Dublin, Ireland, 2020, pp. 1-5, doi: 10.1109/CyberSA49311.2020.9139638.18. Guidelines for Hazard Evaluation Procedures (3rd ed.). Wiley. Retrievedfrom https://www.perlego.com/book/1008408/guidelines-for-hazard-evaluation-procedures-pdf (Рublished 2011)19. Hassani, Bertrand K. Scenario Analysis in Risk Management: Theory and Practice in Finance, 2016. Internet resource.20. Schneider, H. (1996). Failure Mode and Effect Analysis: FMEA From Theory to Execution. Technometrics, 38(1), 80. https://doi.org/10.1080/00401706.1996.1048442421. Rausand, Marvin and Høyland, Arnljot. System Reliability Theory: Models, Statistical Methods and Applications. Hoboken, NJ: Wiley-Interscience, 2004.22. Bahr, N.J. (2015). System Safety Engineering and Risk Assessment: A Practical Approach, Second Edition (2nd ed.). CRC Press. https://doi.org/10.1201/b1785423. Murphy, John & Chastain, Wayne & Bridges, William. (2009). CCPS Guidelines for Independent Protection Layers and Initiating Events. Process Safety Progress. 28. 374 - 378. 10.1002/prs.10356. 24. Han, Jiawei & Kamber, Micheline & Pei, Jian. (2012). Data Mining: Concepts and Techniques. 10.1016/C2009-0-61819-5. 25. Boyless, James. (1988). Human reliability: Analysis, prediction, and prevention of human errors. International Journal of Industrial Ergonomics - INT J IND ERGONOMIC. 2. 165-166. 10.1016/0169-8141(88)90048-0. 26. Clothier, Reece & Walker, Rodney. (2014). The Safety Risk Management of Unmanned Aircraft Systems. 10.1007/978-90-481-9707-1_39. 27. Nan Chenand L. Jeff Hong. 2007. Monte Carlo simulation in financial engineering. In Proceedings of the 39th conference on Wintersimulation: 40 years! The best is yet to come (WSC '07). IEEE Press, 919–931.28. Pritchard, PMP, PMI-RMP, EVP, C.L. (2015). Risk Management: Concepts and Guidance, Fifth Edition (5th ed.). Auerbach Publications. https://doi.org/10.1201/978042943896729. Boardman, Anthony & Greenberg, David & Vining, Aidan & Weimer, David. (2018). Cost-Benefit Analysis: Concepts and Practice, 5th edition. 30. Glaser, Bodo. (2002). Multiple Objectives in Dynamic Decision Making. 10.1007/978-3-642-56100-9_7. 31. Steven Noel, Sushil Jajodia, Lingyu Wang, Anoop Singhal. Measuring security risk of networks using attack graphs. International Journal of Next-Generation Computing. 2010/7/14, P 135-147.32. Survey of Attack Graph Analysis Methods from the Perspective of Data and Knowledge Processing Jianping Zeng, Shuang Wu, Chengrong Wu. Published in Secur. Commun. Networks 26 December 2019.33. Yuri Diogenes Erdal Ozkaya Cybersecurity – Attack and Defense Strategies// Published by Packt Publishing Ltd. Livery Place 35 Livery Street Birmingham B3 2PB, UK, 2018, P 368.34. Dawood Behbehani, Nikos Komninos, Khalid Al-Begain, Muttukrishnan Rajarajan Journalof Cloud Computing, volume12, Articlenumber: 79 (2023).35. Helger Lipmaa, Aikaterini Mitrokotsa, Raimundas Matulevičius Cloud Enterprise Dynamic Risk Assessment (CEDRA): a dynamic risk assessment using dynamic Bayesian networks for cloud environment, Bayesian Network Models in Cyber Security: A Systematic Review, November 2017, DOI:10.1007/978-3-319-70290-2_7, Inbook: Secure IT Systems (pp.105-122), Chapter: 7, Publisher: Springer.36. Optimal monitoring and attack detection of networks modeled by Bayesian attack graphs, Armita Kazeminajafabadi & Mahdi Imani, Cybersecurity volume 6, Articlenumber: 22 (2023).37. Bayesian Network Models in Cyber Security: A Systematic Review, November 2017, DOI:10.1007/978-3-319-70290-2_7, Inbook: Secure IT Systems (pp.105-122), Chapter: 7, Publisher: Springer, Editors: Helger Lipmaa, Aikaterini Mitrokotsa, Raimundas Matulevičius.38. Tuxcare URL https://tuxcare.com/blog/the-transition-to-cvss-v4-0-what-you-need-to-know/39. Attack.mitre URL https://attack.mitre.org/40. Ravdeep Kour, Ramin Karim, Pierre Dersin Game Theory and Cyber Kill Chain: A Strategic Approach to Cybersecurity January 2024, DOI:10.1007/978-3-031-39619-9_33, In book: International Congress and Workshop on Industrial AI and eMaintenance 2023 (pp.451-463).41. Paul A Gagniuc, “Markov Chains: From Theory to Implementation and Experimentation”, 2017, p 235.42. Information Technology LaboratoryNationalVulnerabilityDatabase URL https://nvd.nist.gov/ 43. Іванченко, Є. В., Корченко, О. Г., Бакалинський, О. О., Мялковський, Д. В., Верба, Д. В., Зубков, Д. А., Юдіна, Д. О. Модель системи характеристик даних для оцінювання заходів кіберзахисту в Україні. Український науковий журнал інформаційної безпеки: том. 30 № 1, (2024), 95-99 с. 44. CIA triad (confidentiality, integrityandavailability) https://www.techtarget.com /whatis/definition/Confidentiality-integrity-and-availability-CIA.45. Теорія мотивації захисту. URL https://open.ncl.ac.uk/theories/10/protection-motivation-theory (дата звернення 08.07.2024).46. Critical Security Controls (CIS Controls). URL: www.cisecurity.org/47. Nessus Professional. URL: www.tenable.com (дата звернення 08.07.2024) 48. OpenVAS. URL:www.openvas.org. (дата звернення 08.07.2024) 49. The Qualys Enterprise Tru Risk TM Platform. URL: www.qualys.com. (дата звернення 08.07.2024).50. Іванченко, Є., Корченко, О., Заріцький, О., Зибін, С., Вишневська, Н. Аналіз поняття кіберстійкості критичної інфраструктури. Захист інформації. Том 25, №4, жовтень-грудень 2023, 221-233

    Алгоритм генерування ключів шифрування в симетричній криптографічній системі захисту мовної інформації на основі диференціальних перетворень

    No full text
    The rapid evolutionary development of information technologies and the creation of quantum computers have become harbingers of the onset of the post-quantum cryptoperiod, during which classical symmetric and asymmetric cryptographic systems become particularly vulnerable. In the first case, Grover algorithms are used quite effectively to compromise symmetric cryptographic systems in the post-quantum period, in the second - Shor algorithms, respectively. Thus, potential vulnerabilities of known cryptographic systems can lead to a significant decrease in the level of security of protected objects, especially those of them that are classified as critical infrastructure objects or included in the national security and defense management circuit. Therefore, in order to develop guaranteed secure cryptographic information protection systems based on differential transformations, the cryptographic algorithms of which are based on Fredholm integral equations of the first kind, the article has developed a corresponding algorithm for generating encryption keys. It is proposed to use elementary functions as the initial data for generating encryption keys. For typical algebraic functions that meet the requirements for encryption keys based on differential transformations, their differential spectra have been constructed, and model examples have been given. The absence of similar solutions in the scientific literature for constructing an algorithm for generating encryption keys in a symmetric cryptographic system for protecting speech information based on differential transformations determines the priority of the scientific results obtained in the article. Keywords: generation algorithm, encryption key, symmetric cryptographic system, differential transformations, differential spectrum, discrete.Стрімкий еволюційний розвиток інформаційних технологій та створення квантових комп’ютерів стали провісниками настання постквантового криптоперіоду під час якого класичні симетричні та асиметричні криптографічні системи стають особливо вразливими. У першому випадку для компрометації симетричних криптографічних систем в постквантовий період достатньо результативно використовуються алгоритми Гровера, у другому – алгоритми Шора відповідно. Таким чином, потенційні вразливості відомих криптографічних систем можуть призвести до значного зниження рівня захищеності об’єктів захисту, особливо тих з них, які віднесені до категорії об’єктів критичної інфраструктури або включені до контуру управління національною безпекою та обороною держави. Тому з метою розроблення гарантовано захищених криптографічних систем захисту інформації на основі диференціальних перетворень в основу криптографічних алгоритмів яких покладено інтегральні рівняння Фредгольма першого роду в статті розроблено відповідний алгоритм генерування ключів шифрування. В якості вихідних даних для генерування ключів шифрування запропоновано використовувати елементарні функції. Для типових алгебричних функцій, які відповідають вимогам, що висуваються до ключів шифрування на основі диференціальних перетворень побудовано їх диференціальні спектри, приведено модельні приклади. Відсутність у науковій літературі подібних рішень щодо побудови алгоритму генерування ключів шифрування в симетричній криптографічній системі захисту мовної інформації на основі диференціальних перетворень визначає пріоритетність одержаних в статті наукових результатів. Ключові слова: алгоритм генерування, ключ шифрування, симетрична криптографічна система, диференціальні перетворення, диференціальний спектр, дискрета

    Аналіз закодованих облікових даних в Android додатках

    No full text
    This paper presents the results of a large-scale study of the prevalence of encoded secrets, such as API keys and credentials, in 6165 Android applications obtained from the Google Play Store. Using the MobSF and Trufflehog tools, it was found that a significant number of applications contain sensitive data in the code, which poses serious security risks. In particular, encoded credentials of cloud providers such as Amazon Web Services and Google Cloud Platform were found, which can lead to unauthorized access, compromise of confidential information, resource abuse and financial losses. The analysis showed that the “Health and Fitness” category has the highest frequency of embedded secrets, followed by “News and Magazines”, “Music and Audio”, “Photography” and “Social Networks”. In applications in the “Communications” category that handle sensitive information, such as personal messages and multimedia, encrypted credentials create additional risks, including data interception, compromise of communication integrity, and denial-of-service attacks. The study also found issues with secret management and rotation, which hinders developers from implementing security best practices. This indicates the need to increase automation of secret discovery and update processes in mobile applications. The results also highlight the need to implement centralized solutions for managing sensitive information, such as secret management systems. To mitigate risks, the integration of DevSecOps solutions is proposed, which will ensure security at all stages of software development. In addition, the study emphasizes the importance of adhering to security standards, such as the OWASP Mobile Top 10, to minimize vulnerabilities in mobile applications. Keywords: mobile application security, android security, data privacy, static analysis, improper credentials usage, OWASP Mobile, MobSF, Trufflehog.У даній роботі представлено результати масштабного дослідження поширеності закодованих секретів, таких як API-ключі та облікові дані, у 6165 Android-додатках, отриманих із Google Play Store. Використовуючи інструменти MobSF і Trufflehog, було виявлено, що значна кількість додатків містить в коді чутливі дані, які створюють серйозні ризики для безпеки. Зокрема, виявлено закодовані облікові дані хмарних провайдерів, таких як Amazon Web Services і Google Cloud Platform, що можуть призводити до несанкціонованого доступу, компрометації конфіденційної інформації, зловживання ресурсами та фінансових втрат. Аналіз показав, що категорія “Здоров’я та фітнес” має найвищу частоту вбудованих секретів, за нею йдуть “Новини та журнали”, “Музика та аудіо”, “Фотографія” та “Соціальні мережі”. У додатках з категорії “Комунікації”, які обробляють чутливу інформацію, такі як особисті повідомлення та мультимедіа, закодовані облікові дані створюють додаткові ризики, зокрема перехоплення даних, компрометацію цілісності комунікацій та атаки на відмову в обслуговуванні. В результаті дослідження також виявлено проблеми в управлінні й ротації секретів, що перешкоджає впровадженню розробниками найкращих практик безпеки. Це свідчить про необхідність посилення автоматизації процесів виявлення та оновлення секретів у мобільних додатках. Отримані результати також підкреслюють потребу у впровадженні централізованих рішень для управління конфіденційною інформацією, таких як системи управління секретами. Для зменшення ризиків пропонується інтеграція рішень типу DevSecOps, що забезпечить безпеку на всіх етапах розробки програмного забезпечення. Крім того, дослідження акцентує увагу на важливості дотримання стандартів безпеки, таких як OWASP Mobile Top 10, для мінімізації вразливостей у мобільних додатках. Ключові слова: безпека мобільних додатків, android security, data privacy, static analysis, improper credentials usage, OWASP Mobile, MobSF, Trufflehog

    Моделювання спрямованого ациклічного графа для причинного висновку

    No full text
    The paper proposes an algorithm for causal inference based on a set of input data with compliance with the proposed restrictions. This article is presents assumptions about the data set that affect the choice and accuracy of the causal method. The algorithm for constructing the structure of a directed acyclic graph is given. The adequacy of the algorithm was checked on a test mathematical model, which allowed the analysis to be carried out without a randomized experiment. The proposed algorithm allows extrapolation to reveal a causal model with specified assumptions and the possibility of stricter restrictions on the input data set. Keywords: causal inference, causal graph, causal relationships, data set, modeling causal inference.В роботі запропоновано алгоритм причинного висновку на базі набору вхідних даних з відповідністю запропонованих обмеженням. У статті наведено припущення щодо набору даних, які мають вплив на вибір та точність причинного методу. Наведено алгоритм побудови структури спрямованого ациклічного графа. Перевірка адекватності алгоритму проводилась на тестовій математичній моделі, що дозволило провести аналіз без рандомізованого експерименту. Запропонований алгоритм допускає екстраполяцію для виявлення причинної моделі з вказаними припущеннями та можливістю більш строгих обмежень для набору вхідних даних. Ключові слова: причинний висновок, моделювання причинного висновку, причинний граф, причинно-наслідкові зв’язки, великий набір даних. Список використаної літератури:1. Discovering causal signals in images / D. Lopez-Paz et al. Proceedings of the IEEE conference on computer vision and pattern recognition. 2017. P. 6979–6987.2. Srinivasan R., Uchino K. Biases in generative art: A causal look from the lens of art history. Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency, 1 March 2021.3. Sridhar D., Blei D. M. Causal inference from text: A commentary. Science Advances. 2022. Vol. 8, no. 42.4. Беспала О. М. Інструментарій причинно-наслідкового висновку: огляд та перспективи. Control Systems and Computers. 2020. Т. 5. С. 52–63. URL: https://doi.org/10.15407/csc.2020.05.052 5. Raghu V. K., Poon A., V. Benos P. Evaluation of causal structure learning methods on mixed data types. Proceedings of 2018 ACM SIGKDD Workshop on Causal Discovery, 2018.6. Rabbitt M. P. Causal inference with latent variables from the Rasch model as outcomes. Measurement. 2018. Vol. 120. P. 193–205. URL: https://doi.org/10.1016/j.measurement.2018.01.044 7. Strobl E., Lasko T. A. Sample-specific root causal inference with latent variables. Conference on Causal Learning and Reasoning. 2023. P. 895–915.8. Discovering causal signals in images / D. Lopez-Paz et al. Proceedings of the IEEE conference on computer vision and pattern recognition. 2017. P. 1-11.9. Stoetzer, L., Zhou, X., & Steenbergen, M. R.Causal Inference with Latent Outcomes. 2022, July 13 https://doi.org/10.31219/osf.io/g6skh.10. Structure learning for Bayesian networks. URL: https://ermongroup.github.io/cs228-notes/learning/structure/ (date of access: 28.10.2023).11. Methods and tools for causal discovery and causal inference / A. R. Nogueira et al. WIREs Data Mining and Knowledge Discovery. 2022. Vol. 12, no. 2. URL: https://doi.org/10.1002/widm.144912. Про затвердження Методики оцінки збитків від наслідків надзвичайних ситуацій техногенного і природного характеру: Постанова Каб. Міністрів від 15.02.2002 р. № № 175.13. Perl J. Causality. Cambridge university press, 2009

    Адаптивний метод і алгоритм оперативного оцінювання параметрів трафіка у високошвидкісний корпоративних мультисервісних мережах зв'язку

    No full text
    The article develops an adaptive method and an algorithm for operational evaluation of traffic characteristics and parameters in high-speed corporate multi-service communication networks, which implements it. This algorithm works in real time. High-speed corporate multi-service networks are characterized by high dynamics of changes in their state, including changes in the characteristics of transmitted traffic. Under these conditions, the automated network management system must ensure the required quality of services and communication services provided to users. The relevance of this study is determined by the need to implement network management processes in a mode close to real time, with a given quality in conditions of dynamic, unknown changes in network characteristics. The basis of the proposed method is the concept of conditional nonlinear Pareto-optimal filtering, which consists in the fact that the estimation of traffic parameters takes place in two stages: at the beginning, the forecast of parameter values is estimated, and then, with the receipt of subsequent parameter observations, their adjustment takes place. The proposed method and algorithm belong to the class of methods and algorithms with prior training. The average relative error of the estimation of traffic parameters does not exceed 7%, which is a sufficient value for the implementation of operational network management tasks. Key words: Corporate multiservice network, new generation network, traffic, method, network, data transfer, random sequence.У статті розроблено адаптивний метод і алгоритм оперативного оцінювання характеристик і параметрів трафіку у високошвидкісних корпоративних мультисервісних мережах зв'язку, що його реалізує. Цей алгоритм функціонує в режимі реального часу. Високошвидкісні корпоративні мультисервісні мережі характеризуються високою динамікою зміни свого стану, включно зі змінами характеристик переданого трафіку. У цих умовах автоматизована система управління мережею повинна забезпечити необхідну якість надаваних користувачам послуг і сервісів зв'язку. Актуальність цього дослідження визначається необхідністю реалізації процесів управління мережею в режимі, близькому до реального часу, із заданою якістю в умовах динамічних невідомих змін мережевих характеристик. Основою пропонованого методу є концепція умовної нелінійної Парето-оптимальної фільтрації, яка полягає в тому, що оцінювання параметрів трафіку відбувається у два етапи: на початку оцінюється прогноз значень параметрів, а потім, з отриманням наступних спостережень параметрів, відбувається їхнє коригування. Запропонований метод та алгоритм відносяться до класу методів та алгоритмів із попереднім навчанням. Середня відносна похибка оцінки параметрів трафіку не перевищує 7%, що є достатнім значенням для реалізації завдань оперативного мережевого керування. Ключові слова: Корпоративна мультисервісна мережа, мережа нового покоління, трафік, метод, мережа, передача даних, випадкова послідовність. Список використаної літератури:1. ITU-T: General overview of NGN. Recommendation Y.2001. Geneva, 2004.2. ITU-T Recommendation G.1000, Communications quality of service: A framework and definitions. Geneva, 2001.3. Adaptive method of detecting traffic anomaliesin high-speed multi-service communication networks /S. Ageev, V. Karetnikov, E. Ol’khovik, A. Privalov // E3S Webof Conferences. Key Trendsin Transportation Innovation,KTTI 2019. 2020. P. 040274. Takagi T., Sugeno M. Fuzzy Identification of Systemsand Its Applications to Modeling and Control // IEEE Trans.on System, Man and Cybernetics. 1985. Vol. 15, No. 1.pp. 11−132.5. Amitabh Mishra. Security and Quality of Service in Ad Hoc Wireless Networks, Cambridge press, 2008, 95-97с.6. Tanenbaum, A.S. and Wetherall, D.J. (2011) Computer Networks. 5th Edition, Prentice Hall, Inc., United States of America.7. C. S. R. Murthy and B. S. Manoj, “Ad-Hoc Wireless Networks Architectures and Protocols,” Prentice Hall Communications Engineering and Emerging Technologies Series, Pearson Education, Upper Saddle River, 200

    Розробка API для онлайн-магазину

    No full text
    The article examines contemporary approaches to developing online stores, with a primary focus on crafting APIs to ensure the effective operation of the store in the online realm. A survey of prevalent solutions and literature in the field has enabled the identification of key challenges and unresolved issues.Through the analysis, it was discerned that many small online stores encounter speed and scaling issues attributed to non-optimized API development. The article underscores the significance of leveraging modern technologies, such as Node.js, JavaScript, and PostgreSQL, to streamline development and enhance productivity.The article outlines the work's objective—creating an efficient API for an online store—and defines the research task. It elucidates the importance of utilizing Node.js, JavaScript, and other tools to secure endpoints with Guards, thereby improving system security and reliability.In the Development Environment and Tooling section, a range of tools, including JavaScript, Node.js, Nest.js, PostgreSQL, Git, and WebStorm, are detailed for implementing the online store's API. Emphasis is placed on how these tools contribute to ensuring system reliability and speed. The adoption of the Nest.js framework is highlighted as pivotal in crafting a secure and efficient API for the online store. The incorporation of Guards effectively segregates controllers and provides robust protection for endpoints. Consequently, this integration has simplified the enhancement of the store's functionality, rendering it more reliable and flexible for future developments. Keywords: online store, API, Nest.js, JavaScript, Node.js, PostgreSQL, Endpoints, Guards, JWT token, Security, Reliability.У статті розглядаються сучасні підходи до розробки інтернет-магазинів, при цьому основна увага приділяється розробці API для забезпечення ефективної роботи магазину в онлайн-сфері. Огляд поширених рішень і літератури в цій галузі дозволив визначити ключові проблеми та невирішені проблеми.Під час аналізу було виявлено, що багато невеликих онлайн-магазинів стикаються зі швидкістю та проблемами масштабування, пов’язаними з неоптимізованою розробкою API. У статті підкреслюється важливість використання сучасних технологій, таких як Node.js, JavaScript і PostgreSQL, для оптимізації розробки та підвищення продуктивності.У статті окреслено мету роботи — створення ефективного API для інтернет-магазину — та визначено завдання дослідження. Він пояснює важливість використання Node.js, JavaScript та інших інструментів для захисту кінцевих точок за допомогою Guards, тим самим покращуючи безпеку та надійність системи.У розділі «Середовище розробки та інструменти» детально описано низку інструментів, включаючи JavaScript, Node.js, Nest.js, PostgreSQL, Git і WebStorm, для реалізації API онлайн-магазину. Акцент робиться на тому, як ці інструменти сприяють забезпеченню надійності та швидкості системи. Прийняття фреймворку Nest.js виділяється як ключове у створенні безпечного та ефективного API для онлайн-магазину. Включення Guards ефективно відокремлює контролери та забезпечує надійний захист для кінцевих точок. Таким чином, ця інтеграція спростила вдосконалення функціональності магазину, зробивши його більш надійним і гнучким для майбутніх розробок. Ключові слова: онлайн-магазин, API, Nest.js, JavaScript, Node.js, PostgreSQL, Endpoints, Guards, JWT-token, безпека, надійність. Список використаної літератури:1. Що таке API? URL: https://qalight.ua/baza-znaniy/shho-take-api/2. Безпека даних – Шифрування критично важливих даних URL: https://www.kingston.com/ua/solutions/data-security3. Сайт Node.js URL: https://nodejs.org/en/about4. JavaScript. Основи веб-програмування URL: https://w3schoolsua.github.io/js/index.html#gsc.tab=0.5. Сайт PostgreSQL URL: https://www.postgresql.org/about/6. Сайт NestJS URL: https://docs.nestjs.com/7. Що таке SQL та Бази даних?https://acode.com.ua/sql-intro/8. Олексій Васильєв Програмування мовою Java – Тернопіль, Видавництво Богдан, 2019. – 696 с.9. Сайт NestJS URL: https://docs.nestjs.com/guards10. Сайт JWT.IO URL: https://jwt.io/introduction11. Мельник Р.А. Програмування веб-застосувань (фронт-енд та бек-енд). – Львів: Львівська політехніка, 2018. –248 с

    1,003

    full texts

    2,308

    metadata records
    Updated in last 30 days.
    State University of Telecommunications Open Journals System
    Access Repository Dashboard
    Do you manage Open Research Online? Become a CORE Member to access insider analytics, issue reports and manage access to outputs from your repository in the CORE Repository Dashboard! 👇