State University of Telecommunications Open Journals System
Not a member yet
2308 research outputs found
Sort by
Метод багатокритеріального вибору оптимального варіанта системи захисту інформації для інформаційно-комунікаційної системи підприємства
The development of any complex technical system is usually associated with solving an optimization problem. In the case of designing an information protection system for an information and communication system of an enterprise, it is a search for the optimal variant of a set of protection means from the entire set of possible ones. Like any complex system, the information protection system of the information and communication system of the enterprise is characterized by a set of performance indicators that characterize the protection system from the point of view of countermeasures: the intrusion of intruders into the system; threats to confidentiality, integrity and availability of information; malicious software, etc. The article considers the method of multi-criteria selection of the optimal version of the information protection system for the information and communication system of the enterprise. 5 approaches to choosing the architecture of a complex system are offered. The approaches under consideration are illustrated on a model example of choosing one of the four options for the information protection system of the information and communication system of the enterprise. A simple and fairly visual method of choosing the optimal variant of the information protection system for the information and communication system of the enterprise from a set of possible options is proposed. This method allows you to solve the problem directly on the set of quality indicators without collapsing the criteria into a complex indicator. The prospects for the development of the proposed method are its improvement in order to realize the possibility of giving preference to certain criteria.
Keywords: information protection, information and communication system, optimal option, multi-criteria selection.Розробка будь-якої складної технічної системи як правило пов’язується з вирішенням оптимізаційної задачі. У випадку проектування системи захисту інформації для інформаційно-комунікаційної системи підприємства – це пошук оптимального варіанта комплекту засобів захисту з усієї множини можливих. Як і всяка складна система, система захисту інформації інформаційно-комунікаційної системи підприємства характеризується множиною показників функціонування, які характеризують систему захисту з точки зору протидії: вторгненням зловмисників до системи; загрозам конфіденційності, цілісності та доступності інформації; шкідливим програмним засобам та ін. У статті розглядається метод багатокритеріального вибору оптимального варіанта системи захисту інформації для інформаційно-комунікаційної системи підприємства. Запропоновано 5 підходів щодо вибору архітектури складної системи. Підходи, що розглядаються проілюстровані на модельному прикладі вибору одного з чотирьох варіантів системи захисту інформації інформаційно-комунікаційної системи підприємства. Запропоновано простий та досить наглядний метод вибору оптимального варіанта системи захисту інформації для інформаційно-комунікаційної системи підприємства з множини можливих. Цей метод дозволяє розв’язувати задачу безпосередньо по сукупності показників якості без згортання критеріїв у комплексний показник. Перспективами розвитку запропонованого методу є його удосконалення з метою реалізації можливості надання переваги окремим критеріям.
Ключові слова: захист інформації, інформаційно-комунікаційна система, оптимальний варіант, багатокритеріальний вибір.
Перелік посилань1. Sun, N. et al. Defining Security Requirements With the Common Criteria: Applications, Adoptions, and Challenges, in IEEE Access, vol. 10, pp. 44756-44777, 2022, doi: 10.1109/ACCESS.2022.3168716.2. Хорошко, В., Шелест, М., Ткач, Ю. Багатокритеріальна оцінка ефективності проєктів із забезпечення кібербезпеки. Технічні науки та технології. 2020. № 1 (19). С. 114-123. DOI: 10.25140/2411-5363-2020-1(19)-114.3. Гулак, Г. М., Лахно, В. А. Модель процесу інвестування в розвиток кібербезпеки для побудови системи підтримки прийняття рішень. Кібербезпека: освіта, наука, техніка, №2 (6), 2019. 154-163. DOI: 10.28925/2663-4023.2019.6.154163.4. Hamza, A., Gharakheili, H. H., & Sivaraman, V. (2020). IoT Network Security: Requirements, Threats, and Countermeasures. ArXiv, abs/2008.09339.5. Козубцов, І. М., Черноног, О. О., Козубцова, Л. М., Артемчук, М. В., Нещерет, І. Г. Вибір окремих показників оцінювання здатності функціонування системи захисту інформації і кібербезпеки інформації в інформаційно-комунікаційних системах спеціального зв’язку. Кібербезпека: освіта, наука, техніка, № 4 (16), 2022. 19-27. DOI 10.28925/2663-4023.2022.16.1927.6. Cremer F, Sheehan B, Fortmann M, Kia AN, Mullins M, Murphy F, Materne S. Cyber risk and cybersecurity: a systematic review of data availability. Geneva Pap Risk Insur Issues Pract. 2022;47(3):698-736. doi: 10.1057/s41288-022-00266-6. Epub 2022 Feb 17. PMID: 35194352; PMCID: PMC8853293.7. Borky, J. M., Bradley, T. H. Protecting Information with Cybersecurity. Effective Model-Based Systems Engineering. 2018 Sep 9:345–404. doi: 10.1007/978-3-319-95669-5_10. PMCID: PMC7122347. 8. Tariq, U.; Ahmed, I.; Bashir, A.K.; Shaukat, K. A Critical Cybersecurity Analysis and Future Research Directions for the Internet of Things: A Comprehensive Review. Sensors 2023, 23, 4117. https://doi.org/10.3390/s23084117.9. Szczepaniuk, E. K., Szczepaniuk, H. Analysis of cybersecurity competencies: Recommendations for telecommunications policy, Telecommunications Policy, Volume 46, Issue 3, 2022, 102282, ISSN 0308-5961, https://doi.org/10.1016/j.telpol.2021.102282.10. Савченко, В. А., Машков, О. А., Кравченко, Ю. В., Власенко, Г. М. Метод багатокритеріального вибору оптимального варіанта системи радіонавігаційного забезпечення. Зб. наук. праць інституту проблем моделювання в енергетиці. Моделювання та інформаційні технології. – К.: ІПМЕ, 2003. – №22. – С.37–41
Удосконалена модель дифузії інновацій Басса для прогнозування зміни громадської думки під час реалізації наративу в соціальних мережах
During the writing of the article, the complex dynamics of forecasting public opinion based on the implementation of narratives in social networks were analyzed using Bass's innovation diffusion model. Recognizing the important role of narratives in the formation of collective views provides a basis for using Bass's innovation diffusion model to predict and understand changes in public attitudes during the introduction and implementation of narratives in social networks. On the basis of the above, the research task was set: improvement of the Bass innovation diffusion model for predicting changes in public opinion in social networks, which will directly contribute to the development of quality content by determined forces and means to create favorable conditions during the use of troops (forces) and in peacetime due to entering the coefficient of coverage of the target audience. During the writing of the article, theoretical methods were applied, namely, the analysis of research and publications on the topic of development in relation to the use of diffusion of innovations, which describes the process of how innovations are accepted by the population, the analysis of statistical data of public opinion, comparisons to identify development trends in the consumption of information in social networks, as well as synthesis to achieve the goal of the study. The article presents a mathematical apparatus that incorporates the Bass diffusion model into network behavior for modeling the spread of narratives and predicting changes in public opinion. For the first time, an approach to simulation modeling of the introduction and implementation of a narrative in a social network based on the Bass diffusion model was substantiated, which made it possible to investigate the consumer behavior of social network users under the influence of information and interpersonal communication in a social network. Integrating concepts from Bass's model, such as innovation adoption and imitative behavior, the proposed model aims to predict the dynamics of public attitudes in response to the spread of narratives.
Key words: influence, information influence, informing, narrative, target audience, monitoring, social networks, strategic communications, public relations, civil-military cooperation, model, modeling, Bass diffusion models.Під час написання статті проаналізовано складну динаміку прогнозування громадської думки на основі реалізації наративів у соціальних мережах, використовуючи модель дифузії інновацій Басса. Визнаючи важливу роль наративів у формуванні колективних поглядів дає основу використати модель дифузії інновацій Басса для прогнозування та розуміння змін у суспільних настроях під час впровадження та реалізації наративів в соціальних мережах. На основі викладеного поставлено завдання дослідження: удосконалення моделі дифузії інновацій Басса для прогнозування змін громадської думки в соціальних мережах, що безпосередньо буде сприяти розробленню якісного контенту визначеними силами та засобами для створення сприятливих умов під час застосування військ (сил) так і в мирний час за рахунок введення коефіцієнта охоплення цільової аудиторії. Під час написання статті застосовано теоретичні методи, а саме аналіз досліджень і публікацій за тематикою розвитку стосовно використання дифузії інновацій, що описує процес того, як інновації приймаються населенням, аналізу статистичних даних громадської думки, порівняння для виявлення тенденцій розвитку щодо споживання інформацією в соціальних мережах, а також синтезу для досягнення мети дослідження. У статті представлено математичний апарат, який включає модель дифузії Басса в мережеву поведінку для моделювання розповсюдження наративів і прогнозування змін у громадській думці. Вперше обґрунтовано підхід до імітаційного моделювання впровадження та реалізації наративу в соціальній мережі на основі моделі дифузії Басса, що дало змогу дослідити споживчу поведінку користувачів соціальної мережі під впливом інформування та міжособистісного спілкування в соціальній мережі. Інтегруючи концепції моделі Басса, такі як прийняття інновацій та імітаційна поведінка, запропонована модель має на меті передбачити динаміку суспільних настроїв у відповідь на поширення наративів.
Ключові слова: вплив, інформаційний вплив, інформування, наратив, цільова аудиторія, моніторинг, соціальна мережі, стратегічні комунікації, зв’язки з громадськістю, цивільно-військове співробітництво, модель, моделювання, моделі дифузії Басса.
Перелік посилань1. Горбулін, В. П. Світова гібридна війна: український фронт : монографія / за заг. ред. В. П. Горбуліна. – К. : НІСД, 2017. – 496 с.2. Про Стратегію національної безпеки України Указ Президента України №392/2020 Про рішення Ради національної безпеки і оборони України від 14.09.2020. URL: https://www.president.gov.ua/documents/3922020-35037. (дата звернення: 15.02.2024).3. Watts, D. J., (2003). “Six Degrees: The Science of a Connected Age” W.W. Norton & Company, Reprint edition (February 17, 2004). 384 p.4. Berger, J. “Contagious: How to Build Word of Mouth in the Digital Age,” Simon & Schuster, 2016. 244 p.5. Aral, S. “The Hype Machine: How Social Media Disrupts Our Elections, Our Economy, and Our Health-and How We Must Adapt,” Currency, 2020.6. Radas, S. Diffusion Models in Marketing: How to Incorporate the Effect of External Influence? The Institute of Economics, Zagreb Privredna kretanja i ekonomska politika, Vol. 15 No. 105, 2005. Р. 30-51.7. Bass, F. M. (1969). “A new product growth for model consumer durables.” Manag. Science, 15(5), 215–227.8. Kermack, W. O., & McKendrick, A. G. (1927). "A contribution to the mathematical theory of epidemics." Proceedings of the Royal Society of London. Series A, Papers of a Math. and Phys. Character, 115(772), 700–721.9. Войтко, О. В, Солонніков, В. Г, Полякова, О. В. SIR-модель розповсюдження та врахування результатів негативного впливу інформаційних каналів на громадську думку населення. Сучасні інформаційні технології у сфері безпеки та оборони No 1 (43)/2022. С. 115-120.10. Theoretical and applied aspects of Russian-Ukrainian war: hybrid aggression and national resilience: monograph / M. Koval and others. – Kharkiv: PC Technology Center, 2023. – p. 232-243.11. Rogers, E. M. Diffusion of Innovations. 3th ed. New York: Free Press; 2003. 236 р.12. Роджерс, Е. М. Дифузія інновацій /. Пер. З англ. Василя Старка. – К.:Вид. дім “Києво-Могилянстка акдемія”, 2009. – 591 с.13. Kijek, A, Kijek, T. Modelling of Innovation Diffusion. (2010) Op. Research and Decisions 20(3) 53-68.14. Прокопенко, Л. С. Українська бібліотечна енциклопедія, Національна бібліотека України імені Ярослава Мудрого, https://ube.nlu.org.ua/. (дата звернення: 15.02.2024).15. Про інформацію: Закон України від 02.10.1992 N 2658-XII URL: http://zakon4.rada.gov.ua/laws/show/2657-12. (дата звернення: 15.02.2024).16. Дригайло, С. В. Бібліотечно-інформаційні продукти і послуги для користувачів наукових бібліотек / С. В. Дригайло // Бібліотекознавство. Документознавство. Інформологія. – 2010. – № 4. – С. 79-86.17. ВКП 10-00(49).01. Доктрина зі стратегічних комунікацій Збройних Силах України. Управління стратегічних комунікацій Апарату Головнок. ЗС України, 2020. URL:https://sprotyvg7.com.ua/wp-content/uploads/2022/04/ВКП-10-0049.01-Доктрина-зі-стратегічних-комунікацій.pdf. (дата звернення: 15.02.2024).18. Grubler, A. Diffusion: Long-Term Patterns and Discontinuities. Technological Forecasting and Social Change. Technological forecast social change. 39. 159-180.19. Freeman, C., Soete, L. Perez, C. Dosi, G. Nelson, R. Structural Crises of Adjustment, Business Cycles and Investment Behaviour, in Technical Change and Economic Theory: Pinter. London 1988, С. 38-66.20. Global social media statistics research summary 2023. URL:Smart Insights https://www.smartinsights.com/social-media-marketing/social-media-strategy/new-global-social-media-research/.21. Богуш, В. М., Богуш, В. В., Бровко, В. Д., Настрадiн, В. П. Основи кiберпростору, кiбербезпеки та кiберзахисту. /; пiд. ред. В. М. Богуша. – К.: Видавництво Ліра-К, 2020. – 554 с.22. Mahajan, V., Muller, E., and Bass, F. M. New Product Diffusion Models in Marketing: A Review and Directions for Research. Journal of MarketingVolume 54, Issue 1, January 1990, Pages 1-26.23. Рейтинг моніторинг, 26-та хвиля: суспільно-політичні настрої населення (10-11 лютого 2024). URL: https://ratinggroup.ua/files/ratinggroup/reg_files/rg_rating_monitoring_moods_1000_19022024.pdf.24. Laptiev, O., Tkachev, V., Maystrov, O., Krasikov, O., Open’ko, P., Khoroshko, V., Parkhuts, L. The method of spectral analysis of the determination of random digital signals. International Journal of Communication Networks and Information Security (IJCNIS). Vol 13, No 2, August 2021 Р.271-277. ISSN: 2073-607X (Online). DOI: 10.54039/ijcnis.v13i2.5008 https://www.ijcnis.org/index.php/ijcnis/article/view/5008.25. Kyrychok, R., Laptiev, O., Lisnevsky, R., Kozlovsky, V., Klobukov, V. Development of a method for checking vulnerabilities of a corporate network using bernstein transformations. Eastern-European journal of enterprise technologies. Vol.1№9 (115), 2022 Р. 93–101. ISSN (print)1729 - 3774. ISSN (on-line) 1729-4061. DOI: 10.15587/1729-4061.2022.253530.26. Petrivskyi, V., Shevchenko, V., Yevseiev, S., Milov, O., Laptiev, O., Bychkov, O., Fedoriienko, V., Tkachenko, M., Kurchenko, O., Opirsky, I. Development of a modification of the method for constructing energy-efficient sensor networks using static and dynamic sensors. Eastern-European journal of enterprise technologies. Vol.1№9 (115), 2022 рр. 15–23. ISSN (print) 1729 - 3774. ISSN (on-line) 1729-4061. DOI: 10.15587/1729-4061.2022.252988
Аналіз методів криптографічної автентифікації та виявлення маніпуляцій для великих даних
The emergence of Big Data has made it possible to obtain more information about the customer and competitive base, as well as about market trends. Therefore, the desire of criminals to gain unauthorized access to this data also increases in direct proportion. However, not enough attention is paid to security issues of Big Data systems and their creation does not take into account the information security component. The purpose of the article is to develop approaches to the cyber protection of Big Data, which are stored and transmitted by telecommunication communication channels when responding to a request, namely their integrity and authentication. The main problems when working with Big Data are analyzed. Based on the results of the analysis of Big Data protection problems, a cryptographic transformation of data indexes when they are stored in the database and when transmitted in the form of hash codes is proposed to increase the efficiency of search by user requests. The expediency of using crypto-code constructions on elliptic curves of various types of modifications to form a pseudo-random substrate in order to increase the crypto-resistance of transmitted messages is proven. When forming hash codes, it is advisable to use modified elliptical codes, and under stricter conditions, the level of cryptographic resistance of authentication codes can be increased due to hybrid crypto-code constructions. A pseudo-random substrate can be represented by varieties that must equally ensure the necessary transformations and preservation of universality properties by the UMAC algorithm.
Keywords: Big Data, crypto-code constructions, hybrid crypto-code constructions, elliptic curves, pseudo-random layer, damaged codes.
References1. Hordienko, N. Protect big data and minimize the risk of information loss, 2022, URL: https://www.ukrlogos.in.ua /10.11232-2663-4139.04.32.html.2. Iluk, А. Risks associated with the protection of personal data in context Big Data. 2017, vol. 42 (592). URL: https://yur-gazeta.com /publications/practice /inshe/riziki-povyazani -iz-zahistom-personalnih-danih-v-konteksti-big-data.html.3. NIST Special Publication 1500-1. NIST Big Data Interoperability Framework, 2020, URL: https://bigdatawg.nist.gov/_upload files/NIST.SP.1500-1.pdf.4. Big Data Taxonomy, Cloud Security Alliance, 2021, URL: https:// downloads. cloudsecurityalliance. org/initiatives/bdwg /Big_Data_Taxonomy.pdf.5. Big Data Security and Privacy Handbook: 100 Best Practices in Big Data Security and Privacy. Cloud Security Alliance, URL: https://downloads. cloudsecurityalliance.org/ assets/research/big-data/BigData_Security_ and_Privacy_Handbook. pdf.6. Havrylova, A. A., Korol, O. H., Milevskyi, S. V., Bakirova, L. R. Mathematical model of authentication of a transmitted message based on a McEliece scheme on shorted and extended modified elliptic codes using UMAC modified algorithm, Кібербезпека: освіта, наука, техніка, 2019, No 1(5), pp. 40 – 51.7. Yevseiev, S., Havrylova, A., Korol, O., Dmitriiev, O., Nesmiian, O. [and etc.]. Research of collision properties of the modified UMAC algorithm on crypto-code constructions, EUREKA: Physics and Engineering, Talli, Osauhing "Scientific Route", 2022, Number 1 (38), pp. 34 – 43.8. Korol, O., Havrylova, A. Mathematical models of hybrid crypto-code constructions in the UMAC algorithm Przetwarzanie, transmisja i bezpieczenstwo informacji, Bielsko-Biala, Wydawnictwo naukowe Akademii Techniczno-Humanistycznej w Bielsku-Bialej, 2020, Vol. 12, pp. 125 – 134.9. Yevseiev, S., Havrylova, A. Improved UMAC algorithm with crypto-code McEliece’s scheme, Modern Problems Of Computer Science And IT-Education : collective monograph / [editorial board K. Melnyk, O. Shmatko], Vienna, Premier Publishing s.r.o., 2020, pp. 79 – 92.10. Korol, O., Havrylova, A., Yevseiev, S. Practical UMAC algorithms based on crypto code designs, Przetwarzanie, transmisja I bezpieczenstwo informacji, Bielsko-Biala, Wydawnictwo naukowe Akademii Techniczno-Humanistycznej w Bielsku-Bialej, 2019, Tom 2, pp. 221-232.11. Evseev, S., Kotz, H., Korol, O. Analysis of the legal framework for the information security management system of the nsmep, Eastern-European Journal of Enterprise Technologies, 2015, 5(3), pp. 48–59.12. Evseev, S., Abdullayev, V. Monitoring algorithm of two-factor authentication method based on passwindow system. Eastern-European Journal of Enterprise Technologies, 2015, 2(2), pp. 9–16.13. Yevseiev, S., Tsyhanenko, O., Ivanchenko, S., Milov, O., Shmatko, O. Practical implementation of the Niederreiter modified crypto-code system on truncated elliptic codes, Eastern-European Journal of Enterprise Technologies, 2018, 6(4-96), pp. 24–31.14. Yevseiev, S., Kots, H., Liekariev, Y. Developing of multi-factor authentication method based on Niederreiter Mc-Еliece modified crypto-code system. Eastern-European Journal of Enterprise Technologies, 2016, 6(4), pp. 11–23.15. Yevseiev, S., Korol, O., Kots, H. Construction of hybrid security systems based on the cryptocode structures and flawed codes, Eastern-European Journal of Enterprise Technologies, 2017, 4(9-88), pp. 4–21.16. Milov, O., Yevseiev, S., Ivanchenko, Y., Tiurin, V., Yarovyi, A. Development of the model of the antagonistic agents behavior under a cyber conflict. Eastern-European Journal of Enterprise Technologies, 2019, 4(9-100), pp. 6–10.17. Rukhin, J. Soto. A Statistical Test Suite for Random and Pseudorandom Number Generators for Cryptographic Applications. NIST Special Publication 800-22, 2000.18. Yevseiev, S., Ponomarenko, V., Laptiev, O., Milov, O. Synergy of building cybersecurity systems: monograph, Kharkiv: PC Technology Center, 2021, 188 p.19. Yevseiev, S., Tsyhaneko, O., Gavrilova, A., Guzhva, V., Milov, O., Moskalenko, V., Opirskyy, I., Roma, O., Tomashevsky, B., Shmatko, O. Development of Niederreiter hybrid crypto-code structure on flawed codes, Eastern-European Journal of Enterprise Technologies, 2019, № 1/9 (97), pp. 27 –38.20. Gavrilova, A., Volkov, I., Kozhedub, Yu., Korolev, R., Lezik, O., Medvediev, V., Milov, O., Tomashevsky, B., Trystan, A., Chekunova, O. Development of a modified UMAC Algorithm based on crypto-code constructions, Eastern-European Journal of Enterprise Technologies, 2020, № 4/9 (106), pp. 45 –63.21. Havrylova, A., Tkachov, A., Shmatko, A. Development of a pseudo-random substrate for the UMAC algorithm on crypto-code constructions, Information Protection and information systems security 2021, november 11–12, 2021, Lviv, Ukraine: Materials of the VІII Intern. sci.-tech. conf., Lviv: Education of the Lviv Polytechnic, 2021, pp. 49 - 50. URL: https://drive.google.com/drive/folders/18xwh1 x6hp2ggE14Znhf4Cknl1164FRyi?usp=sharing.22. Yevseiev, S., Milevskyi, S., Bortnik, L., Voropay, A., Bondarenko, K., and Pohasii, S.,“Socio-Cyber-Physical Systems Security Concept”, 2022 International Congress on Human-Computer Interaction, Optimization and Robotic Applications (HORA), 09-11 June 2022, Ankara, Turkey DOI: 10.1109/HORA55278.2022.9799957.23. Laptiev, O., Tkachev, V., Maystrov, O., Krasikov, O., Open’ko, P., Khoroshko, V., Parkhuts, L. The method of spectral analysis of the determination of random digital signals. International Journal of Communication Networks and Information Security (IJCNIS). Vol 13, No 2, August 2021 Р.271-277. ISSN: 2073-607X (Online). DOI : 10.54039/ijcnis.v13i2.5008 https://www.ijcnis.org/index.php/ijcnis/article/view/5008 .24. Kyrychok, R., Laptiev, O., Lisnevsky, R., Kozlovsky, V., Klobukov, V. Development of a method for checking vulnerabilities of a corporate network using bernstein transformations. Eastern-European journal of enterprise technologies. Vol.1№9 (115), 2022 Р. 93–101. ISSN (print)1729 - 3774. ISSN (on-line) 1729-4061. DOI: 10.15587/1729-4061.2022.253530.25. Petrivskyi, V., Shevchenko, V., Yevseiev, S., Milov, O., Laptiev, O., Bychkov, O., Fedoriienko, V., Tkachenko, M., Kurchenko, O., Opirsky, I. Development of a modification of the method for constructing energy-efficient sensor networks using static and dynamic sensors. Eastern-European journal of enterprise technologies. Vol.1№9 (115), 2022 рр. 15–23. ISSN (print) 1729 - 3774. ISSN (on-line) 1729-4061. DOI: 10.15587/1729-4061.2022.252988.Поява Big Data дозволила отримати більше інформації про клієнтів і конкурентну базу, а також про тенденції ринку. Тому прямо пропорційно зростає і бажання злочинців отримати несанкціонований доступ до цих даних. Проте питанням безпеки систем Big Data приділяється недостатньо уваги і при їх створенні не враховується складова інформаційної безпеки. Метою статті є розробка підходів до кіберзахисту великих даних, які зберігаються та передаються телекомунікаційними каналами зв’язку при відповіді на запит, а саме їх цілісності та автентифікації. Проаналізовано основні проблеми при роботі з Big Data. За результатами аналізу проблем захисту великих даних запропоновано криптографічне перетворення індексів даних при їх зберіганні в БД та при передачі у вигляді хеш-кодів для підвищення ефективності пошуку за запитами користувачів. Доведено доцільність використання криптокодових конструкцій на еліптичних кривих різного типу модифікацій для формування псевдовипадкової підкладки з метою підвищення криптостійкості повідомлень, що передаються. При формуванні хеш-кодів доцільно використовувати модифіковані еліптичні коди, а за більш жорстких умов рівень криптостійкості кодів автентифікації можна підвищити за рахунок гібридних криптокодових конструкцій. Псевдовипадковий субстрат може бути представлений різновидами, які однаково повинні забезпечувати необхідні перетворення та збереження властивостей універсальності алгоритмом UMAC.
Ключові слова: великі дані, криптокодові конструкції, гібридні криптокодові конструкції, еліптичні криві, псевдовипадковий шар, пошкоджені коди.
Перелік посилань1. Hordienko, N. Protect big data and minimize the risk of information loss, 2022, URL: https://www.ukrlogos.in.ua /10.11232-2663-4139.04.32.html.2. Iluk, А. Risks associated with the protection of personal data in context Big Data. 2017, vol. 42 (592). URL: https://yur-gazeta.com /publications/practice /inshe/riziki-povyazani -iz-zahistom-personalnih-danih-v-konteksti-big-data.html.3. NIST Special Publication 1500-1. NIST Big Data Interoperability Framework, 2020, URL: https://bigdatawg.nist.gov/_upload files/NIST.SP.1500-1.pdf.4. Big Data Taxonomy, Cloud Security Alliance, 2021, URL: https:// downloads. cloudsecurityalliance. org/initiatives/bdwg /Big_Data_Taxonomy.pdf.5. Big Data Security and Privacy Handbook: 100 Best Practices in Big Data Security and Privacy. Cloud Security Alliance, URL: https://downloads. cloudsecurityalliance.org/ assets/research/big-data/BigData_Security_ and_Privacy_Handbook. pdf.6. Havrylova, A. A., Korol, O. H., Milevskyi, S. V., Bakirova, L. R. Mathematical model of authentication of a transmitted message based on a McEliece scheme on shorted and extended modified elliptic codes using UMAC modified algorithm, Кібербезпека: освіта, наука, техніка, 2019, No 1(5), pp. 40 – 51.7. Yevseiev, S., Havrylova, A., Korol, O., Dmitriiev, O., Nesmiian, O. [and etc.]. Research of collision properties of the modified UMAC algorithm on crypto-code constructions, EUREKA: Physics and Engineering, Talli, Osauhing "Scientific Route", 2022, Number 1 (38), pp. 34 – 43.8. Korol, O., Havrylova, A. Mathematical models of hybrid crypto-code constructions in the UMAC algorithm Przetwarzanie, transmisja i bezpieczenstwo informacji, Bielsko-Biala, Wydawnictwo naukowe Akademii Techniczno-Humanistycznej w Bielsku-Bialej, 2020, Vol. 12, pp. 125 – 134.9. Yevseiev, S., Havrylova, A. Improved UMAC algorithm with crypto-code McEliece’s scheme, Modern Problems Of Computer Science And IT-Education : collective monograph / [editorial board K. Melnyk, O. Shmatko], Vienna, Premier Publishing s.r.o., 2020, pp. 79 – 92.10. Korol, O., Havrylova, A., Yevseiev, S. Practical UMAC algorithms based on crypto code designs, Przetwarzanie, transmisja I bezpieczenstwo informacji, Bielsko-Biala, Wydawnictwo naukowe Akademii Techniczno-Humanistycznej w Bielsku-Bialej, 2019, Tom 2, pp. 221-232.11. Evseev, S., Kotz, H., Korol, O. Analysis of the legal framework for the information security management system of the nsmep, Eastern-European Journal of Enterprise Technologies, 2015, 5(3), pp. 48–59.12. Evseev, S., Abdullayev, V. Monitoring algorithm of two-factor authentication method based on passwindow system. Eastern-European Journal of Enterprise Technologies, 2015, 2(2), pp. 9–16.13. Yevseiev, S., Tsyhanenko, O., Ivanchenko, S., Milov, O., Shmatko, O. Practical implementation of the Niederreiter modified crypto-code system on truncated elliptic codes, Eastern-European Journal of Enterprise Technologies, 2018, 6(4-96), pp. 24–31.14. Yevseiev, S., Kots, H., Liekariev, Y. Developing of multi-factor authentication method based on Niederreiter Mc-Еliece modified crypto-code system. Eastern-European Journal of Enterprise Technologies, 2016, 6(4), pp. 11–23.15. Yevseiev, S., Korol, O., Kots, H. Construction of hybrid security systems based on the cryptocode structures and flawed codes, Eastern-European Journal of Enterprise Technologies, 2017, 4(9-88), pp. 4–21.16. Milov, O., Yevseiev, S., Ivanchenko, Y., Tiurin, V., Yarovyi, A. Development of the model of the antagonistic agents behavior under a cyber conflict. Eastern-European Journal of Enterprise Technologies, 2019, 4(9-100), pp. 6–10.17. Rukhin, J. Soto. A Statistical Test Suite for Random and Pseudorandom Number Generators for Cryptographic Applications. NIST Special Publication 800-22, 2000.18. Yevseiev, S., Ponomarenko, V., Laptiev, O., Milov, O. Synergy of building cybersecurity systems: monograph, Kharkiv: PC Technology Center, 2021, 188 p.19. Yevseiev, S., Tsyhaneko, O., Gavrilova, A., Guzhva, V., Milov, O., Moskalenko, V., Opirskyy, I., Roma, O., Tomashevsky, B., Shmatko, O. Development of Niederreiter hybrid crypto-code structure on flawed codes, Eastern-European Journal of Enterprise Technologies, 2019, № 1/9 (97), pp. 27 –38.20. Gavrilova, A., Volkov, I., Kozhedub, Yu., Korolev, R., Lezik, O., Medvediev, V., Milov, O., Tomashevsky, B., Trystan, A., Chekunova, O. Development of a modified UMAC Algorithm based on crypto-code constructions, Eastern-European Journal of Enterprise Technologies, 2020, № 4/9 (106), pp. 45 –63.21. Havrylova, A., Tkachov, A., Shmatko, A. Development of a pseudo-random substrate for the UMAC algorithm on crypto-code constructions, Information Protection and information systems security 2021, november 11–12, 2021, Lviv, Ukraine: Materials of the VІII Intern. sci.-tech. conf., Lviv: Education of the Lviv Polytechnic, 2021, pp. 49 - 50. URL: https://drive.google.com/drive/folders/18xwh1 x6hp2ggE14Znhf4Cknl1164FRyi?usp=sharing.22. Yevseiev, S., Milevskyi, S., Bortnik, L., Voropay, A., Bondarenko, K., and Pohasii, S.,“Socio-Cyber-Physical Systems Security Concept”, 2022 International Congress on Human-Computer Interaction, Optimization and Robotic Applications (HORA), 09-11 June 2022, Ankara, Turkey DOI: 10.1109/HORA55278.2022.9799957.23. Laptiev, O., Tkachev, V., Maystrov, O., Krasikov, O., Open’ko, P., Khoroshko, V., Parkhuts, L. The method of spectral analysis of the determination of random digital signals. International Journal of Communication Networks and Information Security (IJCNIS). Vol 13, No 2, August 2021 Р.271-277. ISSN: 2073-607X (Online). DOI : 10.54039/ijcnis.v13i2.5008 https://www.ijcnis.org/index.php/ijcnis/article/view/5008 .24. Kyrychok, R., Laptiev, O., Lisnevsky, R., Kozlovsky, V., Klobukov, V. Development of a method for checking vulnerabilities of a corporate network using bernstein transformations. Eastern-European journal of enterprise technologies. Vol.1№9 (115), 2022 Р. 93–101. ISSN (print)1729 - 3774. ISSN (on-line) 1729-4061. DOI: 10.15587/1729-4061.2022.253530.25. Petrivskyi, V., Shevchenko, V., Yevseiev, S., Milov, O., Laptiev, O., Bychkov, O., Fedoriienko, V., Tkachenko, M., Kurchenko, O., Opirsky, I. Development of a modification of the method for constructing energy-efficient sensor networks using static and dynamic sensors. Eastern-European journal of enterprise technologies. Vol.1№9 (115), 2022 рр. 15–23. ISSN (print) 1729 - 3774. ISSN (on-line) 1729-4061. DOI: 10.15587/1729-4061.2022.252988
Сучасні підходи до захисту від розподілених атак на відмову в обслуговувані
The article discusses the problems associated with protection against DDoS attacks, which lead to significant financial losses for private companies that use Web technologies to provide their services in the Internet environment. The rapid growth of Internet-dependency of the business of the corporate sector makes protection against denial-of-service attacks one of its main problems, the difficulty of combating which is explained by the ability of their organizers to hide the address of the source of the attack and the addresses of all network entities involved in the attack scenario. The article provides an analysis of approaches to combating threats from distributed network attacks and shows that effective protection is determined by timely detection of the attack, analysis of false network traffic and its filtering while simultaneously blocking attack sources. Describes the problems solved by IDS intrusion detection systems and IPS intrusion prevention systems, as well as their components and methods of use, based on the analysis of NIST Special Publication 800-94. In addition, the procedures for managing protection against distributed network attacks and determining risks from the implementation of threats of this type are described, based on the Open Group industry standards, which describe risk taxonomy (O-РТ) and risk analysis (O-RA) focused on the use of factor analysis methodology information risks FAIR.
Keywords: DDoS attack, Web technologies, IDS, IPS, IDPS, FAIR.У статті розглядаються проблеми, пов’язані із захистом від DDoS-атак, що приводять до значних фінансових втрат приватних компаній, які використовують Web-технології для надання своїх послуг у Internet-середовищі. Швидке зростання Internet-залежності бізнесу корпоративного сектора, робить одною з головних його проблем захист від атак типу “відмова в обслуговуванні”, складність боротьби з якими пояснюється можливістю їх організаторів приховувати адресу джерела нападу та адреси усіх мережних суб’єктів, задіяних в сценарії атаки. В статті надано аналіз підходів до боротьби з загрозами від розподілених мережних атак і показано, що ефективний захист визначається своєчасним виявленням нападу, аналізом хибного мережного трафіку та його фільтрацією з одночасним блокуванням джерел атаки. Описано задачі, що вирішуються системами виявлення вторгнень IDS та системами запобігання вторгненням IPS, а також їх складові частини та способи використання на основі аналізу стандарту NIST Special Publication 800-94. Додатково описано процедури управління захистом від розподілених мережних атак, та визначення ризиків від реалізації загроз такого типу, на основі галузевих стандартів Open Group, що описують таксономію ризиків (O-РT) та аналіз ризиків (O-RA), орієнтованих на використання методології факторного аналізу інформаційних ризиків FAIR.
Ключові слова: DDoS атака, Web-технології, IDS, IPS, IDPS, FAIR.
Перелік посилань1. Netscout. DDoS Threat Intelligence Report / Findings from 1st half 2023. Internet Traffic and Slipstreamed Threats. DOI:10.30534/ijatcse/2019/12812019. URL: https://www.netscout.com/threatreport/internet-traffic-slipstreamed-threats/2. Alashhab, Z. R., Anbar, M., Singh, M. M., Alieyan, K. “Detection of HTTP Flooding DDoS Attack using Hadoop with MapReduce: A Survey”. February 2019. International Journal of Advanced Trends in Computer Science and Engineering 8(1) URL: https://www.warse.org/IJATCSE/static/pdf/file/ijatcse12812019.pdf3. Tripathi, S., Gupta, B., Almomani, A., Mishra, A., Veluru, S. “Hadoop Based Defense Solution to Handle Distributed Denial of Service (DDoS) Attacks”. Journal of Information Security. Vol. 4 No. 3 Article ID: 34629, 2013, 150-164 p. DOI:10.4236/jis.2013.43018. URL: https://www.scirp.org/pdf/JIS_2013071615001745.pdf4. Prasad, K., Reddy, A. and Rao, K. DoS and DDoS attacks: defense, detection and traceback mechanisms-a survey. Global Journal of Computer Science and Technology, 2014. URL: https://www.researchgate.net/publication/283894681_Detection_of_known_and_unknown_DDoS_attacks_using_Artificial_Neural_Networks5. Mahajan, D., Sachdeva, M. DDoS attack prevention and mitigation techniques – a review. Int. J. Comput. Appl., 2013, vol. 67, no. 19, 21–24 p. DOI: 10.5120/11504-7221 URL: https://research.ijcaonline.org/volume67/number19/pxc3887221.pdf.6. Tiwari, M., Kumar, R., Bharti, A., Kishan, J. Intrusion Detection Systems. International Journal of Technical Research and Applications e-ISSN: 2320-8163, www.ijtra.com, Volume 5, Issue 2 (March – April 2017), 38-44 p. URL: https://www.researchgate.net/publication/316599266_INTRUSION_DETECTION_SYSTEM.7. Abdelkarim, A. A., Nasereddin, H. H. O. Intrusion prevention system. International Journal of Academic Research Vol. 3. No.1. January, 2011, Part II. 432-434 p. URL: https://www.researchgate.net/publication/281120779_INTRUSION_PREVENTION_SYSTEM.8. Guide to Intrusion Detection and Prevention Systems (IDPS). Recommendations of the National Institute of Standards and Technology. NIST Special Publication 800-94. February 2007 URL: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-94.pdf9. The Open Group Risk Taxonomy (O-RT) Standard, Version 3.0.1. https://pubs.opengroup.org/security/o-rt/10. The Open Group Risk Analysis (O-RA) Standard, Version 2.0.1. URL: https://pubs.opengroup.org/security/o-ra/#:~:text=The%20objective%20of%20the%20Risk,to%20perform%20effective%20risk%20analysis.11. Sharifi, A., Zad, F. F., Farokhmanesh, F., Noorollahi, A., Sharifi, J. An Overview of Intrusion Detection and Prevention Systems (IDPS) and Security Issues. IOSR Journal of Computer Engineering (IOSR-JCE). e-ISSN: 2278-0661, p-ISSN: 2278-8727. Volume 16, Issue 1, Ver. I (Jan. 2014), 47-52 p. URL: https://www.researchgate.net/publication/273720500_An_Overview_of_Intrusion_Detection_and_Prevention_Systems_IDPS_and_Security_Issues.12. Rajamannar, K., Paravel, A., Rangasamy, S., Pandi, V. Classifications of DDoS Attack – A Survey. ISSN: 0193-4120 Page No. 12926 – 12932. March-April 2020. URL: https://www.researchgate.net/publication/341190040_Classifications_of_DDoS_Attack_-_A_Survey13. Open FAIR™ Risk Analysis Process Guide. Document Number: G180. Published by The Open Group, January 2018. URL: https://pubs.opengroup.org/security/openfair-process-guide
Метод оцінювання кіберзахищеності хмарних сервісів об’єктів інформаційної інфраструктури
In the work, a method based on a mathematical model was developed, which is intended for mathematical calculation of the assessment of the state of cyber security of cloud services of information infrastructure objects. To build the evaluation method, the results of the model development, evaluation criteria of cloud services, as well as answer options, for which the number of points for each option is determined, were used. The evaluation method consists of 11 stages, where the last one is directly calculating the criticality of the cloud service. Based on the results of the calculations, a recommendation is provided regarding the use or non-use of the cloud service, which allows you to make informed decisions based on the received data. The article also presents the calculated maximum possible number of points that can be obtained within the evaluated cloud service. This method can be used during the development of a network application, which will be a useful tool for the auditor. It will help to assess the state of security of the used cloud service at the customer company, as well as before purchasing or using such services. The application of this method allows you to significantly increase the level of awareness of the potential risks associated with the use of cloud technologies and ensure an appropriate level of cyber security. The developed approach can become the basis for further research in the field of cyber security assessment, contributing to the development of more comprehensive models and tools for analyzing risks in cloud environments. This, in turn, will contribute to the growth of trust in cloud services and their security in the conditions of modern information challenges.
Keywords: cyber security, information security, evaluation, mathematical model, mathematical method, audit, CSP, Cloud Service Provider, IaaS, PaaS, CaaS, FaaS, SaaS.У роботі розроблено метод на базі математичної моделі, що призначений для математичного обчислення оцінки стану кіберзахищеності хмарних сервісів об’єктів інформаційної інфраструктури. Для побудови методу оцінювання були використані результати розробки моделі, критерії оцінювання хмарних сервісів, а також варіанти відповідей, для яких визначено кількість балів за кожен варіант. Метод оцінювання складається з 11 етапів, де останнім є безпосередньо обчислення критичності хмарного сервісу. За результатами обчислень надається рекомендація щодо використання або не використання хмарного сервісу, що дозволяє приймати обґрунтовані рішення на основі отриманих даних. У статті також представлено обчислені максимально можливі кількості балів, які можуть бути отримані в межах оцінюваного хмарного сервісу. Цей метод може бути використаний під час розробки мережевого застосунку, що стане корисним інструментом для аудитора. Він допоможе оцінити стан захищеності використовуваного хмарного сервісу в компанії-замовника, а також перед придбанням чи використанням таких сервісів. Застосування даного методу дозволяє значно підвищити рівень обізнаності щодо потенційних ризиків, пов’язаних з використанням хмарних технологій, і забезпечити належний рівень кібербезпеки. Розроблений підхід може стати основою для подальших досліджень у сфері оцінки кіберзахищеності, сприяючи розвитку більш комплексних моделей та інструментів для аналізу ризиків у хмарних середовищах. Це, в свою чергу, сприятиме зростанню довіри до хмарних сервісів і їх безпеки в умовах сучасних інформаційних викликів.
Ключові слова: кібербезпека, інформаційна безпека, оцінка, математична модель, математичний метод, аудит, CSP, Cloud Service Provider, IaaS, PaaS, CaaS, FaaS, SaaS.
Перелік посилань
Pedchenko, Analysis of modern cloud services to ensure cybersecurity [Electronic resource] / Y.Pedchenko, Y. Ivanchenko, I. Ivanchenko, I. Lozova, D. Jancarczyk, P. Sawicki // Procedia Computer Science. – 2022. – Vol. 207. – P. 110-117. – Mode of access: https://www.sciencedirect.com/science/article/pii/S1877050922009164 (date of access: 17.08.2024). – Analysis of modern cloud services to ensure cybersecurity.
Cloud Security [Electronic resourse]: Proofpoint. – Mode of access: https://www.proofpoint.com/us/threat-reference/cloud-security (date of access: 15.08.2024). – Cloud Security.
What is Cyber Espionage? [Electronic resourse]: CrowdStrike. – Mode of access: https://www.crowdstrike.com/cybersecurity-101/cyberattacks/cyber-espionage/ (date of access: 15.08.2024). – What is Cyber Espionage?
Top 15 Cloud Security Issues, Threats and Concerns [Electronic resourse]: Check Point. – Mode of access: https://www.checkpoint.com/cyber-hub/cloud-security/what-is-cloud-security/top-cloud-security-issues-threats-and-concerns/ (date of access: 15.08.2024). — Top 15 Cloud Security Issues, Threats and Concerns.
All You Need to Know About Top 10 Security Issues in Cloud Computing [Electronic resource]: Veritis. – Mode of access: https://www.veritis.com/blog/top-10-security-issues-in-cloud-computing/ (date of access: 14.08.2024). – All You Need to Know About Top 10 Security Issues in Cloud Computing.
ISO/IEC 27001. Electronic resourse] Information security management systems. – Mode of access: https://www.iso.org/standard/27001 (date of access: 14.08.2024). – Information security, cybersecurity and privacy protection.
Morgan, P. Cloud Spending Curtailed, On Premises Spending Heading Into Recession [Electronic resource] / T.P. Morgan // TheNextPlatform. – Mode of access: https://www.nextplatform.com/2023/04/03/cloud-spending-curtailed-on-premises-spending-heading-into-recession/ (date of access: 20.08.2024). – Cloud Spending Curtailed, On Premises Spending Heading Into Recession.
Корченко,О. Г. Системи захисту інформації: Монографія. – К.: НАУ, 2004. – 264 с.
Потій, О. В., Шульга, В. П., Корченко, О. Г., Іванченко, Є. В., Бакалинський, О. О., Мялковський, Д.В, Верба, Д. В., Зубков, Д. А., Юдіна, Д. О. Модель системи характеристик даних для оцінювання стану кіберзахисту в Україні. Збірник наукових праць Центрального науково-дослідного інституту Збройних Сил України №4 (107), 2023 – С. 313-329.
Roger, S. IaaS vs. CaaS vs. PaaS vs. FaaS vs. SaaS – What’s the difference? [Electronic resource] / S. Roger // Medium. – Mode of access: https://stample.com/link/stamples/5ff3d43b60b2acfb9eb5ceb6/iaas-vs-caas-vs-paas-vs-faas-vs-saas-whats-the-difference (date of access: 10.07.2024). – IaaS vs. CaaS vs. PaaS vs. FaaS vs. SaaS – What’s the difference
Динамічний варіант повідомлення в адаптивному методі журналювання
Observability is an essential part of software systems. As the scale and outreach of modern technologies grow, it becomes increasingly important to be able to pinpoint and diagnose software issues in a timely manner. One approach that is commonly used by developers involves utilizing a technique called “logging”, most likely in a form that is based on the idea of outputting log messages coupled with level of severity. This combination helps to group and categorize different reporting messages for processing afterwards. But sometimes this is not enough as some applications might be so complex and sophisticated that severity-only categorization does not scale properly. To solve this issue an adaptive logging method was introduced. It adds the concept of “log tags” and a special configuration that allows to include or exclude specific tags or their combinations. This article takes the idea of adaptive logging a step further and introduces a new plane of adaptability with dynamic message variants: a specific type of log messages with the ability to override reporting information “on the fly” without changing the source code. At first the motivation and necessity for such functionality is described in abstract terms, then a formalized model of proposed change is presented. A detailed explanation and reasoning behind certain data structures that make dynamic messages possible is presented, providing a reasonable amount of architectural considerations to make implementation in different environments and programming languages more achievable. At the end special attention is paid to some important aspects and requirements that should be carefully considered by implementers when writing their own version of adaptive logging method. The results of applying the proposed update to adaptive logging method would allow developers to have even more tools to extract information about system’s execution and incorrect behaviors easier and with greater detail.
Keywords: information security, cyber threats, observability, adaptive logging, dynamic execution.
References
Khan, N.A., Brohi, S.N., & Zaman, N. (2020). Ten deadly cyber security threats amid Covid-19 pandemic. TechRxiv, 1-7. DOI: 36227/techrxiv.12278792.v1.
Alawida M., Omolara A.E., Abiodun O.I., Al-Rajab A. (2022). A deeper look into cybersecurity issues in the wake of Covid-19: A survey. Journal of King Saud University - Computer and Information Sciences,Volume 34, Issue 10, Part A. Pages 8176-8206, ISSN 1319-1578. https://doi.org/10.1016/j.jksuci.2022.08.003.
Kumar R., Sharma S., Vachhani C., Yadav N. What changed in the cyber-security after COVID-19? Computers & Security, Volume 120, 102821, ISSN 0167-4048. https://doi.org/10.1016/j.cose.2022.102821.
Karpowicz, M.P. (2021). Covid-19 pandemic and internet traffic in Poland: Evidence from selected regional networks. Journal of Telecommunications and Information Technology, 3, 86-91. DOI: 10.26636/jtit.2021.154721.
Baz, M., Alhakami, H., Agrawal, A., Baz, A., Khan, R.A. (2021). Impact of COVID-19 pandemic: A cybersecurity perspective. Intelligent Automation & Soft Computing, 27(3), 641-652. https://doi.org/10.32604/iasc.2021.015845.
A. Shaji George. (2024). When Trust Fails: Examining Systemic Risk in the Digital Economy from the 2024 CrowdStrike Outage. Partners Universal Multidisciplinary Research Journal, 1(2), 134–152. https://doi.org/10.5281/zenodo.12828222.
Routavaara I. (2020). Security monitoring in AWS public cloud. Bachelor’s Thesis. Technology Information and Communication Technology. JAMK University of Applied Sciences.
Li Y., Huo Y., Zhong R., Jiang Z., Liu J., Huang J., Gu J., He P., Lyu M.R. (2024). Go Static: Contextualized Logging Statement Generation. ACM International Conference on the Foundations of Software Engineering. https://doi.org/10.48550/arXiv.2402.12958.
Suprunenko, I., & Rudnytskyi, V. (2024). On specifics of adaptive logging method implementation. Bulletin of Cherkasy State Technological University, 29(1), 36-42. https://doi.org/10.62660/bcstu/1.2024.36.
Rehman B. (2023). A Blend of Intersection Types and Union Types. Abstract of thesis for the degree of Doctor of Philosophy at The University of Hong Kong.
Algebraic data type – HaskellWiki. Retrieved from https://wiki.haskell.org/Algebraic_data_type (last accessed at 03 of August, 2024).
Wirfs-Brock A, Eich B. (2020). JavaScript: the first 20 years. Proc. ACM Program. Lang. 4, HOPL, Article 77, 189 pages. https://doi.org/10.1145/3386327.
Built-in Functions — Python 3.12.4 documentation. Retrieved from https://docs.python.org/3/library/functions.html#exec (last accessed at 04 of August, 2024).Спостережливість є важливою частиною програмних систем. Зі зростанням масштабів і охоплення сучасних технологій стає дедалі важливішим мати можливість своєчасно виявляти та діагностувати проблеми програмного забезпечення. Один із підходів, який зазвичай використовують розробники, передбачає використання техніки під назвою «реєстрація», швидше за все, у формі, яка базується на ідеї виведення повідомлень журналу разом із рівнем серйозності. Ця комбінація допомагає групувати та класифікувати різні звітні повідомлення для подальшої обробки. Але іноді цього недостатньо, оскільки деякі програми можуть бути настільки складними та витонченими, що категоризація лише за серйозністю не масштабується належним чином. Для вирішення цієї проблеми було запроваджено адаптивний метод журналювання. Він додає концепцію «тегів журналу» та спеціальну конфігурацію, яка дозволяє включати або виключати певні теги або їх комбінації. Ця стаття просуває ідею адаптивного журналювання на крок далі та представляє нову площину адаптивності з динамічними варіантами повідомлень: певний тип журнальних повідомлень із можливістю перевизначати звітну інформацію «на льоту» без зміни вихідного коду. Спочатку мотивація та необхідність такої функціональності описуються в абстрактних термінах, потім представляється формалізована модель запропонованої зміни. Представлено детальне пояснення та аргументацію певних структур даних, які роблять можливими динамічні повідомлення, надаючи достатню кількість архітектурних міркувань, щоб зробити впровадження в різних середовищах і мовах програмування більш досяжним. Наприкінці особлива увага приділяється деяким важливим аспектам і вимогам, які слід ретельно враховувати розробникам під час написання власної версії методу адаптивного журналювання. Результати застосування запропонованого оновлення до адаптивного методу журналювання дозволять розробникам мати ще більше інструментів для легшого та детальнішого отримання інформації про виконання системи та неправильну поведінку.Ключові слова: інформаційна безпека, кіберзагрози, спостережливість, адаптивне журналювання, динамічне виконання
Модель виявлення шкідливої активності в інформаційній системі організації на основі гібридної класифікації
The article is devoted to the study of methods for detecting malicious processes in an organization’s information system using machine learning methods. The number of attacks, which according to statistics, increases every year, indicates that intrusion detection methods require further development. The use of machine learning can increase the ability of protection systems to detect malicious processes. To solve the problem of detecting malicious processes in work, a hybrid classification model for detecting intrusions in an organization’s information system is proposed. The proposed model is built on the use of several machine learning methods. These methods include the support vector method, decision trees, and k-nearest neighbors. The description of the main stages of applying the specified methods of the proposed model provides a generalized understanding of the features of the work. The CSE-CIC-IDS2018 datasets of the Canadian Institute of Cybersecurity were used. The main stages necessary for the correct operation of the proposed model are proposed for processing the data set. It is expected that this approach will reduce the model’s runtime and improve the quality and accuracy of detecting malicious activity in the organization’s information system. The hybrid classification is based on the assembly learning method - stacking, which involves training several models on the same data set, and then using another classifier, which is trained on the output data of these models and determines how to combine them to obtain the final forecast. Therefore, the proposed malicious activity detection model will allow obtaining forecast results that will be compared with the results of the model based on each selected machine learning algorithm.
Keywords: cybersecurity, cyberattack, malicious activity, botnet, machine learning, classification.Стаття присвячена дослідженню методів виявлення шкідливих процесів в інформаційній системі організацій з використанням методів машинного навчання. Кількість атак, які згідно з статистикою, збільшуються з кожним роком, свідчить про те, що методи виявлення вторгнень потребують подальшого розвитку. Застосування машинного навчання може підвищити здатність систем захисту щодо виявлення шкідливих процесів. Для вирішення проблеми виявлення шкідливих процесів в роботі запропоновано модель гібридної класифікації виявлення вторгнень в інформаційній системі організації. Запропонована модель побудована на використанні декількох методів машинного навчання. До складу цих методів було включено метод опорних векторів, дерева рішень та k-найближчих сусідів. Опис основних етапів застосування визначених методів запропонованої моделі надає узагальнене розуміння особливостях роботи. Було використано набори даних CSE-CIC-IDS2018 Канадського інституту кібербезпеки. Для обробки набору даних запропоновано основні етапи, які необхідні для коректної роботи запропонованої моделі. Очікується, що такий підхід дозволить скоротити час роботи моделі та покращити показники якості та точності виявлення шкідливої активності в інформаційній системі організації. В основу гібридної класифікації покладено метод асамблевого навчання - стекінг, який передбачає навчання кількох моделей однаковому наборі даних, а потім використання ще одного класифікатора, який навчається на вихідних даних цих моделей та визначає, як їх комбінувати для отримання кінцевого прогнозу. Отже, запропонована модель виявлення шкідливої активності дозволить отримувати результати прогнозів, які будуть порівнюватися з результатами моделі на основі кожного окремого обраного алгоритму машинного навчання.
Ключові слова: кібербезпека, кібератака, шкідлива активність, ботнет, машинне навчання, класифікація
Новий підхід до архітектури систем управління сервісами в інформаційних системах
The article solves the scientific task of researching new principles of service management architecture based on the distribution of subject and identification data flows using the tool of the digital object identification register and the service register. The main task of the integration of information systems related to different areas is the management of the processes of providing services according to customer requests. The risks that have arisen are related to the large amount of data that the integration bus (platform) must pass through itself, including security risks and increased transaction processing costs. An additional factor restraining development is the poorly resolved task of integrating several information systems that use different ecosystems of services with different telecommunication and subject protocols, data request and processing methods, data structures and formats.
Keywords: architecture, computer system, identification, service, service, digital object, information technology.У статті вирішується наукове завдання дослідження нових принципів архітектури управління сервісами на основі розподілу потоків предметних та ідентифікаційних даних із використанням інструменту реєстру ідентифікації цифрових об'єктів та реєстру сервісів. Основним завданням інтеграції інформаційних систем, що стосуються різних областей є управління процесами надання послуг за запитами клієнтів. Виниклі ризики пов'язані з великим обсягом даних, які інтеграційна шина (платформа) повинна пропускати через себе, у тому числі ризики безпеки та збільшення витрат на обробку транзакцій. Додатковим фактором, що стримує розвиток, є завдання, що погано вирішується щодо інтеграції декількох інформаційних систем, що використовують різні екосистеми сервісів з різними телекомунікаційними та предметними протоколами, методами запиту і обробки даних, структурами і форматами даних.
Ключові слова: архітектура, комп’ютерна система, ідентифікація, сервіс, послуга, цифровий об’єкт, інформаційна технологія.
Список використаної літератури:1. Recommendation ITU-T Y.4403 (07/2012). Functional requirements and architecture of the next generation network for support of ubiquitous sensor network applications and services.2. Recommendation ITU-T X.1252 (04/2021). Baseline identity management terms and definitions.3. Recommendation ITU-T Y.2342 (12/2019). Scenarios and capability requirements of blockchain in next generation network evolution4. ETSI TS 103 486: "CYBER; Identity Management and Discovery for IoT5. ETSI TS 132 362 V16.0.0 (2020-08) Digital cellular telecommunications system (Phase 2+) (GSM); Universal Mobile Telecommunications System (UMTS); LTE; Telecommunication management; Entry Point (EP) Integration Reference Point (IRP); Information Service (IS) (3GPP TS 32.362 version 16.0.0 Release 16)6. RFC 3482. Number Portability in the Global Switched Telephone Network (GSTN): An Overview7. RFC 7642. System for Cross-domain Identity Management: Definitions, Overview, Concepts, and Requirements. September, 20158. 3GPP TS 24.382 V13.1.0 (2016-06) Technical Specification. 3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Mission Critical Push To Talk (MCPTT) identity management; Protocol specification (Release 13).9. 3GPP Specification #: 33.924. Identity management and 3GPP security interworking; Identity management and Generic Authentication Architecture (GAA) interworking. Technical Report. (Release 9
Методика оцінки ефективності управління тунелюванням у магістральних мережах
The article deals with the method of evaluating the effectiveness of tunneling management in trunk networks with a focus on improving efficiency and optimizing data transmission. The relevance of creating a tunneling management technique in the context of growing traffic volumes and expanding the functionality of IP/MPLS networks is substantiated. It is noted that traditional control methods may be ineffective in the given environment, and the use of specialized models of network construction is a key factor for optimal use of tunnel resources. The main requirements for the trunk network technology are high bandwidth, speed of information transfer and scalability. The current state of the market and the needs of users require access to integrated network services, and the organization of virtual private networks, the provision of intelligent services. The growing demand for additional services implemented on top of simple IP access requires the development of backbone network architectures with virtually unlimited scaling capabilities, increased traffic processing speed, and unprecedented flexibility in terms of the organization of additional services. The MPLS technology allows for network integration, due to which service providers will not only be able to save the means invested in asynchronous transmission equipment, but also get additional benefits from the compatible use of protocols. It is proposed to use a specialized model to determine and optimize tunnel resources aimed at maintaining a high level of service quality. It is shown that with an increase in the load with an unchanged number of nodes, the time the packet stays in the tunnel increases, since the load served by each node increases, and therefore the total time the packet stays in the tunnel.
Key words: network, tunneling, router, management, traffic, packet, switching.У статті розглядається методика оцінки ефективності управління тунелюванням у магістральних мережах з фокусом на підвищення ефективності та оптимізації передачі даних. Обґрунтовується актуальність створення методики управління тунелюванням в контексті зростання обсягів трафіку та розширення функціональності мереж IP/MPLS. Зазначається, що традиційні методи управління можуть бути неефективними у зумовленому швидким розвитком середовищі, а використання спеціалізованих моделей побудови мереж є ключовим чинником для оптимального використання тунельних ресурсів. Головними вимогами, що пред’являються до технології магістральної мережі є висока пропускна здатність, швидкість передачі інформації і масштабованість. Сучасний стан ринку і потреби користувачів, вимагають доступу до інтегрованих сервісів мереж, і організацію віртуальних приватних мереж, надання інтелектуальних послуг. Попит на додаткові послуги, що реалізовуються поверх простого IP-доступу, що зростає, вимагає розробки архітектури магістральних мереж, що мають практично необмежені можливості масштабування, підвищену швидкість обробки трафіка і безпрецедентну гнучкість з погляду організації додаткових сервісів. Технологія MPLS дає змогу інтегрувати мережі, за рахунок чого постачальники послуг зможуть не тільки зберегти засоби, інвестовані в устаткування асинхронної передачі, але і отримати додаткову вигоду із сумісного використання протоколів. Пропонується використання спеціалізованої моделі для визначення та оптимізації тунельних ресурсів, спрямованої на підтримку високого рівня якості обслуговування. Показано, що із збільшенням навантаження при незмінній кількості вузлів час перебування пакету в тунелі зростає, так як зростає навантаження, що обслуговується кожним вузлом, а отже, і сумарний час перебування пакета в тунелі.
Ключові слова: мережа, тунелювання, маршрутизатор, управління, трафік, пакет, комутація.
Список використаної літератури:1. В.Б. Толубко, Л. Н. Беркман, Л. П. Крючкова, А. Ю. Ткачов. Підвищення показників якості системи управління послугами мережами майбутнього / В // Наукові записки Українського науково-дослідного інституту зв'язку. - 2018. - № 3. - С. 5-11.2. Воробієнко П. П., Нікітюк Л. А., Резніченко П. І. Телекомунікаційні та інформаційні мережі. К.: САММІТ-Книга, 2010. 708 с.: іл. 3. Довгий С.О., Савченко О.Я., Воробієнко П.П. та ін. Сучасні телекомунікації: мережі, технології, економіка, управління, регулювання / За ред. С.О. Довгого. – К.: Український Видатничій Центр, 2002. – 520 с. 4. Аулін В. В., Гриньків А. В., Головатий А. О., Лисенко С. В., Голуб Д. В., Кузик О.В., Тихий А. А. Методологічні основи проектування та функціонування інтелектуальних транспортних і виробничих систем: монографія під заг. ред. д.т.н., проф. Ауліна В.В. Кропивницький: Видавець Лисенко В.Ф., 2020. 428с. ISBN 978-617-7813-27-8. 5. Швець А. В. Мультиагентна система управління транспортними ресурсами. Сучасні проблеми науки. Тези доп. XXI Міжнар. наук.-практ. конф. здобувачів вищ. освіти і молодих учених (5-9 квіт. 2021 р. м. Київ.). С. 128-130. 6. Литвин В. В. Мультиагентні системи підтримки прийняття рішень, що базуються на прецедентах та використовують адаптивні онтології. Радіоелектроніка. Інформатика. Управління. 2009. № 2 (21). С. 120–126. 7. Теоретичні основи телекомунікаційних мереж: навч. посіб. М.М. Климаш, Б.М.Стрихалюк, М.В.Кайдан. – Львів : вид-во УАД, 2011. – 496 с. 8. X. Zhou, M. Sun, G. Y. Li, and B.-H. F. Juang, “Intelligent wireless communications enabled by cognitive radio and machine learning,” China Commun., vol. 15, no. 12, pp. 16-48, Dec. 2018
Математична модель автоматизованої системи сейсмоакустичного моніторингу об’єктів критичної інфраструктури
The article considers the mathematical model of the automated system of seismoacoustic monitoring of critical infrastructure objects. In the monitoring approach, the object is identified with a point in the multidimensional space of free model parameters. Thus, the forecast about the state of the object is a forecast of a significant shift in the position of the parameter vector in the parameters space. When choosing a mathematical model, it is necessary to select a space of informative parameters to reduce the probability of errors of two types. First of all, it is necessary to build a mathematical model of the dynamics of the OKI, which reflects the most significant moments of the monitoring process, including both the process itself and the disturbances accompanying this process and the noise background superimposed on the process of the dynamics of the state of the OKI. A priori knowledge of the interference of an arbitrary process will significantly weaken its influence on obtaining estimates of the parameters of the process, which is perceived as a useful signal. This attenuation is achieved by optimizing processing procedures that take into account the a priori statistics of the random interference process. A new mathematical model in the form of a superposition of Berlasi pulses in the seismoacoustic frequency range and constructive algorithms for its implementation are proposed. The mathematical properties of the model were studied. Thus, the state of OKI is reflected in the vector of free parameters of the above model. To evaluate the informative parameters of the proposed model of the automated seismo-acoustic monitoring system, the work solves the problem of nonlinear regression, considering them as the point of the criterion optimum in the n-dimensional space. In the situation that has developed in our country, related to the conduct of military operations on its territory and missile attacks, the creation of automated seismo-acoustic monitoring systems of critical infrastructure objects is a necessary task.
Keywords: monitoring, critical infrastructure, acoustic signal, information parameters, automated system.
References1. Dahlman O., Israelson H. Monitoring Underground Nuclear Explosions. Amsterdam-Oxford-New York, 1977, 440 p.2. Savarensky, E.F., Proskurjakova, T. A. & Voronina, E.V., 1967. On microseisms phase velocities and the direction to the exitation source. In: Papers presented at the 9th Assembly of the European Seismological Commission. Akademisk Forlag, Copenhagen, pp. 347—356.3. Fix, J., 1972. Ambient earth motion in the period range from 0.01 – 2560 s. Dull.Seism. Soc. Amer., 62: 1753-1760.4. Bungum, H. & Ringdahl, F., 1974. Diurnal variation of seismic noise and its effect on detectability. NTNF/NORSAR, Kjeller, Scientific Report No. 5.5. Robinson, E.A., 1967. Statistical communication and detection with special reference to digital data processing of radar and seismic signals. Charles Griffin and Co. Ltd., London, 362 pp.6. Van Trees, H.L., 1969. Detection, estimation and modulation theory. Part I.John Wiley & Sons Inc., New York, 647 pp.7. Frasier, C.W., 1974. Single-channel event detector in real time. In: Seismic Discrimination, Semiannual Technical Summary to the Advanced Research Projects Agency 1 January—30 June 1974. Massachusetts Institute of Technology, Lincoln Laboratory, pp. 51.8. Capon, J. & Greenfield, R.J., 1967. Matched filtering of long period Rayleigh-waves. In: Seismic Discrimination, Semiannual Technical Summary Report to the Advanced Research Projects Agency 1 January—30 June 1967. Massachusetts Institute of Technology, Lincoln Laboratory, pp. 21—23.9. Toksoz, M.N., 1970. Crustal effects on long period chirp filters. In: Copies of papers presented at Woods Hole Conference on Seismic discrimination, Laboratories of Teledyne Geotech, Alexandria, Virginia.10. Peacock, K.L. & Treitel, S., 1969. Predictive deconvoiution. Theory and practice. Geophysics, 34:155-169.11. Gjoystdahl, H. & Husebye, E.S., 1972. A comparison of performance between prediction error and bandpass filters. NTNF/NORSAR, Kjeller, Technical Report No, 43.12. Capon, J., Greenfield, R.J., Kolker, R.J. & Lacoss, R.T., 1968. Short period signal processing results for the large aperture seismic arrays. Geophysics, 33:452—472.13. Mostovoy S.V., Mostovoy V.S. Models of optimization of dynamic parameters of object in passive monitoring. Geophysical Journal. – 2007. – 28, № 5. – C. 112-123.14. Addison Paul S. The illustrated wavelet transform handbook. Institute of Physic Publishing, Bristol and Philadelphia, 2002, 353p.15. Мостовий В. Моделі геофізичних полів систем моніторингу. Дисертація на здобуття наукового ступеня «доктор фізико-математичних наук», Київ, 2013, 233 с.16. Plessix R.-E. A review of the adjoint-state method for computing the gradient of a functional with geophysical applications - Geophys. J. Int. (2006) 167, 495-503.17. Mostovyy S., Mostovyy V., Osadchuk A. Processing of seismic signals under coastal background noise. Application of artificial intelligence techniques in seismologic and engineering seismology Consel de l’Europe Cahiers Europeen de Geodinamiqueet de seismologie, Luxembourg, 1996, Vol. 12, p. 297-299. 18. Ermakov S.M. Monte-Carlo method and related matters. Science. М. 1975. 471 с.В статті розглядається математична модель автоматизованої системи сейсмоакустичного моніторигу обєктів критичної інфраструктури. У моніторинговому підході об'єкт ототожнюється з точкою у багатовимірному просторі вільних параметрів моделі. Таким чином, прогноз про стан об'єкта є прогнозом істотного зміщення положення вектора параметрів у просторі ознак.Запропоновано нову математичну модель у вигляді суперпозиції імпульсів Берлазі, у сейсмоакустичному діапазоні частот, та конструктивні алгоритми її реалізації. Досліджено математичні властивості моделі. Таким чином стан обєкта критичної інфраструктури (ОКІ) відображається у векторі вільних параметрів вищевказаної моделі. Для оцінки інформативних параметрів запропонованої моделі автоматизованої системи сейсмоакустичного моніторингу у роботі вирішується завдання нелінійної регресії, розглядаючи їх як точку оптимуму критерію в n- мірному просторі. У ситуації, що склалася в нашій країні, пов’язаної з проведенням військових дій на її території, та ракетних атак створення автоматизованих систем сейсмоакустичного моніторингу обєктів критичної інфраструктури являється необхідною задачею.
Ключові слова: моніторинг, критична інфраструктура, акустичний сигнал, інформаційні параметри, автоматизована система