Status and Prospects of Development Methodological Support for Technical Protection of Information in Information systems

S. Soloviev, Mikhail Tarelkin, Vasily Tekunov, Yuri Yazov
{"title":"Status and Prospects of Development Methodological Support for Technical Protection of Information in Information systems","authors":"S. Soloviev, Mikhail Tarelkin, Vasily Tekunov, Yuri Yazov","doi":"10.21681/2311-3456-2023-1-41-57","DOIUrl":null,"url":null,"abstract":"The goal of article is determine the main areas for development, composition and structure of prospective methodological support for the organization and maintenance of technical protection of information in information systems.The method of research: is summary and analysis the existing methodological support for organization and maintenance of the technical protection of information from unauthorized access and its development trends in the interests of the conversion from qualitative to quantitative procedures of substantiation requirements and selection process to build information security system in information systems. The result of the research: The factors defining the need to develop methodological support for the organization and maintenance of technical protection of information have been identified, including subject area extension of information protection, the need to move to quantitative research methods, algorithms and procedures for assessment the possibilities of implementing information security threats, the need to justify the requirements for technical protection of information and select protection measures and means. Data volume has increased dramatically and processes of information gathering and analysis are impossible without the use of corresponding special software tools and complexes. The composition and structure of prospective methodological support have been developed, including using modern methods of artificial intelligence theory (machine learning, artificial neural networks (ANNs)), the apparatus of composite Petri-Markov nets, risk theory, etc., for the tasks of categorizing the information systems and the information processed in them, identifying information security threats and vulnerabilities, as well as threat risk assessment considering time factor. It was noted that the introduction of such support into practice is impossible without the creation of software systems that automate categorization processes, quantitative risk assessments of implementing threats and building information protection systems. Scientific novelty: a systematic idea of the composition, structure and prospects of development methodological support has been identified for the organization and maintenance of technical protection of information to solve problems of categorizing the information systems and the information processed in them, forecasting, assessment the possibilities and consequences of implementing information security threats. Author contributions: Soloviev S.V. - assessment of the status and research of the prospects of development methodological support for the categorization the information system and the information processed in them; Tarelkin M.A. - study of methods of threats forecasting for information security and their prospective applications in the management of the Data Bank of information security threats of FSTEC of Russia; V.V. Tekunov - ways to build a promising system for threat forecasting to information security based on the monitoring publications results about them on the Internet; Yazov Yu.K. - general guidance, assessment of the states and prospects of development methodological support for risk assessment of implementing information security threats.","PeriodicalId":422818,"journal":{"name":"Voprosy kiberbezopasnosti","volume":"598 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Voprosy kiberbezopasnosti","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.21681/2311-3456-2023-1-41-57","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The goal of article is determine the main areas for development, composition and structure of prospective methodological support for the organization and maintenance of technical protection of information in information systems.The method of research: is summary and analysis the existing methodological support for organization and maintenance of the technical protection of information from unauthorized access and its development trends in the interests of the conversion from qualitative to quantitative procedures of substantiation requirements and selection process to build information security system in information systems. The result of the research: The factors defining the need to develop methodological support for the organization and maintenance of technical protection of information have been identified, including subject area extension of information protection, the need to move to quantitative research methods, algorithms and procedures for assessment the possibilities of implementing information security threats, the need to justify the requirements for technical protection of information and select protection measures and means. Data volume has increased dramatically and processes of information gathering and analysis are impossible without the use of corresponding special software tools and complexes. The composition and structure of prospective methodological support have been developed, including using modern methods of artificial intelligence theory (machine learning, artificial neural networks (ANNs)), the apparatus of composite Petri-Markov nets, risk theory, etc., for the tasks of categorizing the information systems and the information processed in them, identifying information security threats and vulnerabilities, as well as threat risk assessment considering time factor. It was noted that the introduction of such support into practice is impossible without the creation of software systems that automate categorization processes, quantitative risk assessments of implementing threats and building information protection systems. Scientific novelty: a systematic idea of the composition, structure and prospects of development methodological support has been identified for the organization and maintenance of technical protection of information to solve problems of categorizing the information systems and the information processed in them, forecasting, assessment the possibilities and consequences of implementing information security threats. Author contributions: Soloviev S.V. - assessment of the status and research of the prospects of development methodological support for the categorization the information system and the information processed in them; Tarelkin M.A. - study of methods of threats forecasting for information security and their prospective applications in the management of the Data Bank of information security threats of FSTEC of Russia; V.V. Tekunov - ways to build a promising system for threat forecasting to information security based on the monitoring publications results about them on the Internet; Yazov Yu.K. - general guidance, assessment of the states and prospects of development methodological support for risk assessment of implementing information security threats.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
信息系统信息技术保护方法支持的现状与展望
本文的目标是确定为组织和维持信息系统中的信息技术保护提供前瞻性方法支持的发展、组成和结构的主要领域。研究的方法:是总结和分析现有的方法支持组织和维护的技术保护信息免受未经授权的访问及其发展趋势的利益从定性到定量的转换程序的实质要求和选择过程,以建立信息系统中的信息安全体系。研究结果:确定了需要为组织和维护信息技术保护制定方法支持的因素,包括信息保护的主题领域扩展,转向定量研究方法、算法和程序以评估实施信息安全威胁的可能性的需要,证明信息技术保护要求的必要性以及选择保护措施和手段的需要。数据量急剧增加,如果不使用相应的特殊软件工具和复合物,信息收集和分析过程是不可能的。发展了前瞻性方法学支持的组成和结构,包括使用人工智能理论(机器学习、人工神经网络(ann))、复合Petri-Markov网络装置、风险理论等现代方法,对信息系统及其处理的信息进行分类,识别信息安全威胁和漏洞,以及考虑时间因素的威胁风险评估。有人指出,如果不建立软件系统,使分类过程自动化、对实施威胁进行定量风险评估和建立信息保护系统,就不可能将这种支助付诸实施。科学新颖性:对信息技术保护的组成、结构和发展前景的系统思想,确定了组织和维护信息技术保护的方法支持,以解决对信息系统及其处理的信息进行分类、预测、评估实施信息安全威胁的可能性和后果等问题。作者贡献:索洛维耶夫S.V. -现状评估与发展前景研究:信息系统分类及其处理信息的方法支持;Tarelkin硕士-研究信息安全威胁预测方法及其在俄罗斯FSTEC信息安全威胁数据库管理中的应用前景;V.V. Tekunov -基于互联网上有关威胁的监测出版物结果建立一个有前途的信息安全威胁预测系统的方法;Yazov Yu.K。-对实施信息安全威胁的风险评估的一般指导、状态评估和发展前景的方法支持。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Model for Building Competencies of a Computer Crime Investigator ASSESSMENT AND PREDICTION OF THE COMPLEX OBJECTS STATE: APPLICATIOIN FOR INFORMATION SECURITY Cellular Automata and Their Generalizations in Cryptography. Part 1 A METHOD OF PARAMETRIC SYNTHESIS OF CRYPTO-CODE STRUCTURES FOR MONITORING AND RESTORING THE INTEGRITY OF INFORMATION Application of Methods of Theory of Fuzzy Sets to Assess the Risk of Violations of Critical Properties Protected Resources Automated Control System
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1