METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGER
The paper considers a methodological approach to an analysis and estimation of information security in the information systems which is based on the analysis of vulnerabilities and an extent of their hazard. By vulnerability hazard it is meant a complexity of its operation as a part of an informatio...
Saved in:
| Main Authors: | , |
|---|---|
| Format: | Article |
| Language: | Russian |
| Published: |
Belarusian National Technical University
2008-12-01
|
| Series: | Наука и техника |
| Online Access: | https://sat.bntu.by/jour/article/view/743 |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1846144770732195840 |
|---|---|
| author | Y. M. Krotiuk V. A. Kamliuk |
| author_facet | Y. M. Krotiuk V. A. Kamliuk |
| author_sort | Y. M. Krotiuk |
| collection | DOAJ |
| description | The paper considers a methodological approach to an analysis and estimation of information security in the information systems which is based on the analysis of vulnerabilities and an extent of their hazard. By vulnerability hazard it is meant a complexity of its operation as a part of an information system. The required and sufficient vulnerability operational conditions have been determined in the paper. The paper proposes a generalized model for attack realization which is used as a basis for construction of an attack realization model for an operation of a particular vulnerability. A criterion for estimation of information protection in the information systems which is based on the estimation of vulnerability hazard is formulated in the paper. The proposed approach allows to obtain a quantitative estimation of the information system security on the basis of the proposed schemes on realization of typical attacks for the distinguished classes of vulnerabilities.The methodical approach is used for choosing variants to be applied for realization of protection mechanisms in the information systems as well as for estimation of information safety in the operating information systems. |
| format | Article |
| id | doaj-art-211d598ada3945e3a82d5c2b17cfb1c6 |
| institution | Kabale University |
| issn | 2227-1031 2414-0392 |
| language | Russian |
| publishDate | 2008-12-01 |
| publisher | Belarusian National Technical University |
| record_format | Article |
| series | Наука и техника |
| spelling | doaj-art-211d598ada3945e3a82d5c2b17cfb1c62024-12-02T06:52:48ZrusBelarusian National Technical UniversityНаука и техника2227-10312414-03922008-12-01064146736METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGERY. M. Krotiuk0V. A. Kamliuk1Объединенный институт проблем информатики НАН БеларусиЛаборатория КасперскогоThe paper considers a methodological approach to an analysis and estimation of information security in the information systems which is based on the analysis of vulnerabilities and an extent of their hazard. By vulnerability hazard it is meant a complexity of its operation as a part of an information system. The required and sufficient vulnerability operational conditions have been determined in the paper. The paper proposes a generalized model for attack realization which is used as a basis for construction of an attack realization model for an operation of a particular vulnerability. A criterion for estimation of information protection in the information systems which is based on the estimation of vulnerability hazard is formulated in the paper. The proposed approach allows to obtain a quantitative estimation of the information system security on the basis of the proposed schemes on realization of typical attacks for the distinguished classes of vulnerabilities.The methodical approach is used for choosing variants to be applied for realization of protection mechanisms in the information systems as well as for estimation of information safety in the operating information systems.https://sat.bntu.by/jour/article/view/743 |
| spellingShingle | Y. M. Krotiuk V. A. Kamliuk METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGER Наука и техника |
| title | METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGER |
| title_full | METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGER |
| title_fullStr | METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGER |
| title_full_unstemmed | METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGER |
| title_short | METHODOLOGICAL APPROACH TO ANALYSIS AND EVALUATION OF INFORMATION PROTECTION IN INFORMATION SYSTEMS BASED ON VULNERABILITY DANGER |
| title_sort | methodological approach to analysis and evaluation of information protection in information systems based on vulnerability danger |
| url | https://sat.bntu.by/jour/article/view/743 |
| work_keys_str_mv | AT ymkrotiuk methodologicalapproachtoanalysisandevaluationofinformationprotectionininformationsystemsbasedonvulnerabilitydanger AT vakamliuk methodologicalapproachtoanalysisandevaluationofinformationprotectionininformationsystemsbasedonvulnerabilitydanger |