Models for assessing threats of documentary information leakage in the process of developing a secure information system

DOI: 10.21293/1818-0442-2025-28-2-116-129

Download article in PDF format

JATS xml

Abstract: The paper considers the issues of assessing the threats to the leakage of information contained in the documents developed in the process of creating a secure information system, with the aim of its certification for compliance with information security requirements. Descriptive models of the processes for creating such documents are developed. Timing diagrams illustrating a general overview of these processes are constructed. The application of the flow theory and Poisson's formula for calculating the probability of their implementation is justified. In order to assess to the leakage of information contained in the developed documents, a general description of these threats is given, taking into account not only the temporal factor in their implementation, but also the specific features of the document development processes using computers. Descriptive and functional models of scenarios for the realization of information leakage threats contained in the documents under development by internal and external intruders are developed. Analytical relations for calculating the probabilities of realization of these threats in the absence of protection measures are obtained. The possibility of increasing the security of information contained in the documents under development against leakage through the application of organizational and technical measures based on a security monitoring system has been substantiated. To assess the impact of these measures, as well as the security of information against leakage with their application, appropriate descriptive and functional models are required, as well as indicators and analytical models for their calculation, taking into account the time factor and logical conditions that determine the dynamics of the realization of the processes under study. For this purpose, it is advisable to use the apparatus of composite Petri-Markov nets. Functional models developed in the article and the constructed timing diagrams can be used as a basis for the application of this apparatus.

Keywords: secure information system, documentary information, document development process, information leakage threat, conditions and factors, threat realization scenario

For citation:
Avsentiev O. S., Butov V. V., Tomilova E. A. Models for assessing threats of documentary information leakage in the process of developing a secure information system. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2025, vol. 28, no. 2, pp. 116–129. DOI: 10.21293/1818-0442-2025-28-2-116-129

Authors and copyright holders:

  • Avsentiev O. S. , Voronezh Institute of the Ministry of Internal Affairs of the Russian Federation (Voronezh, Russia)
  • Butov V. V. , Voronezh Institute of the Ministryof Internal Affairs of the Russian Federation (Voronezh, Russia)
  • Tomilova E. A. , Voronezh Institute of the Ministry of Internal Affairs of the Russian Federation (Voronezh, Russia)

  • 1. Ob utverzhdenii trebovaniy o zashchite informatsii, ne sostavlyayushchei gosudarstvennuyu tainu, soderzhashcheisya v gosudarstvennykh informatsionnykh sistemakh [On the approval of requirements for protection of information not constituting a state secret, contained in state information systems]. Order of the FSTEC of Russia dated February 11, 2013, no. 17. Available at: https://base.garant.ru/70391358 (in Russ).
  • 2. GOST R 51583–2014. Zashhita informatsii. Poryadok sozdaniya avtomatizirovannykh sistem v zashhishhennom ispolnenii. Obshhie polozheniya [Information Security. Procedure for Creating Automated Systems in a Secure Configuration. General Provisions]. M., Standartinform, 2014, 15 p. (in Russ.)
  • 3. Avsentiev O.S., Butov V.V., Valde A.G. [Models of the justification of organizational and technical support for activities on creation of SIS informatization objects]. Proceedings of Telecommunication Universities, 2024, vol. 10, no. 5, pp. 93–108. DOI 10.31854/1813-324X-2024-10-5-92-107 (in Russ.).
  • 4. Avsentyev O.S., Tomilova E.A. Models of adaptive management of information protection in the process of creation of the state information system. Proceedings of TUSUR University, 2024, vol. 27, no. 4, pp. 61–73.
  • 5. GOST R 50922–2006. Zashhita informacii. Osnovny`e terminy` i opredeleniya. Gosstandart Rossii [Information security. Basic terms and definitions. State standard of Russia]. M., Standartinform, 2008. 8 p. (in Russ.).
  • 6. Guidance document. Methodology for assessing threats to information security. Approved by FSTEC of on February 5, 2021 (in Russ.).
  • 7. Yazov Y.K., Anishchenko A.V. [Petri-Markov networks and their application for modeling the processes of realization of threats to information security in information systems]. Monograph, Voronezh, Kvarta, 2020, 173 p. (in Russ.).
  • 8. GOSTR 56546–2015. Zashhita informatsii. Uyazvimosti informatsionnykh sistem. Klassifikatsiya uyazvimostej informacionnykh sistem [Information security. Vulnerabilities of information systems. Classification of information system vulnerabilities]. M., Standardinform, 2015 (in Russ.).
  • 9. Information Security Threat Database. Available at: https://bdu.fstec.ru/threat/ (Аccessed: 5 May 2025)
  • 10. Menshakov Yu.K. Teoreticheskie osnovy tekhnicheskikh razvedok [Theoretical foundations of technical intelligence]. Moscow, Bauman Moscow State Technical University Publishing House, 2008, 738 p. (in Russ.).
  • 11. Avsentiev O.S., Avsentiev A.O, Krugov A.G., Yazov Yu.K. Simulation of processes to protect information of informatization objects against leakage through technical channels using an apparatus of Petri–Markov nets. Bulletin of the South Ural State University. Ser. Mathematical Modelling, Programming & Computer Software (Bulletin SUSU MMCS), 2021, vol. 14, no. 4, pp. 46–62.
  • 12. Yazov Yu.K., Avsentiev O.S., Rudtsоvа I.О. On the issue of evaluating the effectiveness of information protection in electronic document management systems. Cybersecurity issues, 2019, vol. 1(29), pp. 25–34.
  • 13. Tikhonov V.I. Statisticheskaya radiotekhnika [Statistical radio engineering]. Moscow, Sov. radio, 1966, 680 p. (in Russ.)
  • 14. Yazov Yu.K., Solov'ev S.V. Zashhita informatsii v informacionnykh sistemakh ot nesanktsionirovannogo dostupa [Information protection in information systems from the unauthorized access]. Voronezh, Kvarta, 2015, 440 p. (in Russ.)
  • 15. GOST R 53114–2008. Zashhita informatsii. Obespechenie informatsionnoi bezopasnosti v organizatsii. Osnovny`e terminy i opredeleniya [Information protection. Ensuring information security in the organization. Basic terms and definitions]. Applied since 01.10.2009. National Standard of the Russian Federation (in Russ.).
  • 16. Avsentyev O.S., Krugov A.G., Shelupanova P.A. Functional models of the processes of the information leakage threats realization due to the side electro-magnetic emissions of the informatization objects. Proceedings of TUSUR University, 2020, vol. 22, no. 1, pp. С. 29–39.
  • 17. Avdeev V.B., Katrusha A.N. Raschyot koeffitsienta oslableniya pobochnykh elektromagnitnykh izluchenii [Calculation of the attenuation coefficient of side electromagnetic radiations]. Spetsial`naya tekhnika, 2013, no. 2, pp. 18–27 (in Russ.)
  • 18. Antipov D.A., Shelupanov A.A. Investigation of the directionality of the side electromagnetic radiation from a personal computer. Proceedings of TUSUR University, 2018, vol. 21, no. 2, pp. 33–37.
Editorial office address

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 701-582

  journal@tusur.ru

 

Viktor N. Maslennikov

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02

Subscription for updates