METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGER

The paper considers a methodological approach to an analysis and estimation of information security in the information systems which is based on the analysis of vulnerabilities and an extent of their hazard. By vulnerability hazard it is meant a complexity of its operation as a part of an informatio...

Full description

Saved in:
Bibliographic Details
Main Authors: Y. M. Krotiuk, V. A. Kamliuk
Format: Article
Language:Russian
Published: Belarusian National Technical University 2008-12-01
Series:Наука и техника
Online Access:https://sat.bntu.by/jour/article/view/743
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1846144770732195840
author Y. M. Krotiuk
V. A. Kamliuk
author_facet Y. M. Krotiuk
V. A. Kamliuk
author_sort Y. M. Krotiuk
collection DOAJ
description The paper considers a methodological approach to an analysis and estimation of information security in the information systems which is based on the analysis of vulnerabilities and an extent of their hazard. By vulnerability hazard it is meant a complexity of its operation as a part of an information system. The required and sufficient vulnerability operational conditions  have  been  determined in the paper. The paper proposes a generalized model for attack realization which is used as a basis for construction of an attack realization model for an operation of a particular vulnerability. A criterion for estimation of information protection in the information systems which is based on the estimation of vulnerability hazard is formulated in the paper. The proposed approach allows to obtain a quantitative estimation of the information system security on the basis of the proposed schemes on realization of typical attacks for the distinguished classes of vulnerabilities.The methodical approach is used for choosing variants to be applied for realization of protection mechanisms in the information systems as well as for estimation of information safety in the operating information systems.
format Article
id doaj-art-211d598ada3945e3a82d5c2b17cfb1c6
institution Kabale University
issn 2227-1031
2414-0392
language Russian
publishDate 2008-12-01
publisher Belarusian National Technical University
record_format Article
series Наука и техника
spelling doaj-art-211d598ada3945e3a82d5c2b17cfb1c62024-12-02T06:52:48ZrusBelarusian National Technical UniversityНаука и техника2227-10312414-03922008-12-01064146736METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGERY. M. Krotiuk0V. A. Kamliuk1Объединенный институт проблем информатики НАН БеларусиЛаборатория КасперскогоThe paper considers a methodological approach to an analysis and estimation of information security in the information systems which is based on the analysis of vulnerabilities and an extent of their hazard. By vulnerability hazard it is meant a complexity of its operation as a part of an information system. The required and sufficient vulnerability operational conditions  have  been  determined in the paper. The paper proposes a generalized model for attack realization which is used as a basis for construction of an attack realization model for an operation of a particular vulnerability. A criterion for estimation of information protection in the information systems which is based on the estimation of vulnerability hazard is formulated in the paper. The proposed approach allows to obtain a quantitative estimation of the information system security on the basis of the proposed schemes on realization of typical attacks for the distinguished classes of vulnerabilities.The methodical approach is used for choosing variants to be applied for realization of protection mechanisms in the information systems as well as for estimation of information safety in the operating information systems.https://sat.bntu.by/jour/article/view/743
spellingShingle Y. M. Krotiuk
V. A. Kamliuk
METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGER
Наука и техника
title METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGER
title_full METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGER
title_fullStr METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGER
title_full_unstemmed METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGER
title_short METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGER
title_sort methodological approach to analysis and evaluation of information protection in information systems based on vulnerability danger
url https://sat.bntu.by/jour/article/view/743
work_keys_str_mv AT ymkrotiuk methodologicalapproachtoanalysisandevaluationofinformationprotectionininformationsystemsbasedonvulnerabilitydanger
AT vakamliuk methodologicalapproachtoanalysisandevaluationofinformationprotectionininformationsystemsbasedonvulnerabilitydanger