Methods and algorithms to assess the destructive impact of violators on elements of distributed information systems

DOI: 10.21293/1818-0442-2024-27-4-49-60

Download article in PDF format

JATS xml

Abstract: The paper substantiates the relevance of the development of methods and algorithms to assess the destructive impact of violators on elements of distributed information systems. The analysis of scientific works and research in this field is carried out. The target functions of simple computer attacks have been identified and the objects of destructive influence (DI) to which they are directed have been identified. The goals, objectives and stages of complex computer attacks (CCAs) are structured. An algorithm and a graph object-oriented model for the formation of CCAs scenarios have been developed. Ontological structural and functional models (OS-FM) of components of distributed information systems (DIS) at the levels of the OSI\ISO model, represented as objects of destructive influence (DI), have been compiled, and a methodology to determine their vulnerabilities and consequences of destructive influence has been developed. A methodology has been developed to determine the preference of CCAs scenarios and the degree of their criticality based on digital security maps reflecting the topology and functional processes of the DIS elements, allowing to assess the possibil-ity of information security threats and their preferred scenarios.

Keywords: ontological modeling, methods for assessing destructive effects, vulnerabilities, scenarios, tactics, techniques of computer attacks, digital security maps

For citation:
Baranov V. V., Shelupanov A. A. Methods and algorithms to assess the destructive impact of violators on elements of distributed information systems. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2024, vol. 27, no. 4, pp. 49–60. DOI: 10.21293/1818-0442-2024-27-4-49-60

Authors and copyright holders:

  • Baranov V. V. , South Russian State Polytechnic University (NPI) named after M.I. Platov (Novocherkassk, Russia)
  • Shelupanov A. A. , Tomsk State University of Control Systems and Radioelectronics (Tomsk, Russia)

  • 1. CAPEC (Common Attack Pattern Enumeration and Classification) is a standard for describing classes of attacks and their hierarchical relationships, a catalog of known cyber-attacks. Available at: https://capec.mitre.org, free, (Accessed: August 12, 2024) (in Russ.)
  • 2. MITRE ATT & CK Matrix-a formal description of techniques and tactics for implementing cyber-attacks. Available at: https://atac.mitre.org, free (Accessed: August 12, 2024) (in Russ.)
  • 3. List of common disadvantages. A list of types of software and hardware vulnerabilities developed by the community. Available at: https:// cwe.mitre.org/data/ definitions/1194.html, free (Accessed: August 12, 2024) (in Russ.)
  • 4. Common vulnerabilities and risks. Available at: https://cve.mitre.org, free (Accessed: September 10, 2024) (in Russ.)
  • 5. The General Vulnerability Assessment System (CVSS). Available at: https://www.first.org/cvss/v3.0/specification-document for CVSS version 3.0, free (Accessed: August 24, 2024) (in Russ.)
  • 6. Baranov V.V., Shelupanov A.A. Cognitive model for assessing the security of information systems for various purposes. Symmetry, 2022, vol. 14, no. 12, pp. 2631.
  • 7. Baranov V.V., Shelupanov A.A. Methods and algorithms for calculating the security of elements of distributed information systems in conditions of destructive influence. Proceedings of TUSUR University. 2022, vol. 25, no. 4, pp. 88–100.
  • 8. Hu Z, Mukhin V., Kornaga [et al.] Analytical assessment of the security level of distributed and scalable computer systems. International Journal of Intelligent Systems and Applications. 2016, no. 12. DOI: https://doi.org/10.5815/ijisa.2016.12.07 (Accessed: September 08, 2024).
  • 9. Figueira P., Bravo-Lopez K., Lopez-Rivas D.L. Improving information security risk analysis by including threat-occurrence predictive models. Computers and Security Volume. 2020. No 88 (101609). DOI: https://doi.org/10.1016/j.cose.2019.101609 (Accessed: July 30, 2024).
  • 10. Vasiliev V.I., Vulfin A.M., Kirillova A.D., Kuchkarova N.V. Methodology for assessing current threats and vulnerabilities based on cognitive modeling and Text Mining technologies. Management, Communication and Security Systems, 2021, no. 3, pp. 110–133.
  • 11. Massel L., Massel A. Intelligent support tools for making strategic decisions on the development of intelligent networks, E3S Web of Conferences 2018. Access mode: https://doi.org/10.1051/e3sconf/20186902009, free (Accessed: September 08, 2024) (in Russ.)
  • 12. Zikratov I.A., Odegov S.V. Assessment of information security in cloud computing based on a Bayesian approach. Scientific and Technical Bulletin of Information Technologies, Mechanics and Optics, 2012, no. 4 (80), pp. 121–126.
  • 13. Baranov V.V. Complex model of functioning of distributed information systems in conditions of destructive influence. Electronic Network Polythematic Journal «Scientific Works of the Kuban State Technological University», 2022, no. 5. pp. 51–67.
  • 14. Skvortsov N.A. Issues of coordination of different ontological models and ontological contexts. Ontological modeling. Edited by L.A. Kalinichenko: Seminar proceedings. M.: IPI RAS. 2008. pp. 149–166 (in Russ.)
  • 15. Abramov E.S., Andreev A.V., Mordvin D. Application of attack graphs to simulate malicious network impacts. Proceedings of the Southern Federal University. Technical Sciences. 2012, vol. 126, no. 1, pp. 165–174.
  • 16. Singhal A. Security risk analysis of corporate networks using probabilistic attack graphs. Network Security Indicators. Cham, 2017, pp. 53–73.
  • 17. Radanliev P., De Ruhr D. Improving the cybersecurity of the healthcare system with the help of self-optimizing and self–adapting artificial intelligence. Part 2. Healthcare Technology, 2022, vol. 12, pp. 923–929. Available at: https://doi.org/10.1007/s12553-022-00691-6, free (Accessed: September 12, 2024).
  • 18. Jaxen F. Bayesian networks and decision-making graphs. M.: Springer, 2001, pp. 54–120.
  • 19. Moreira M.L., Gomez K.F.S., dos Santos M., dos Carmo M.S., Araujo J.V.G.A. PROMETHE-SAPEVO-M1 hybrid modeling proposal: Multi-criteria evaluation of unmanned aerial vehicles for use in naval warfare, Proceedings of the International Joint Conference in Industrial Engineering and Operations Management, 2020, vol. 337, pp. 381–393. DOI: 10.1007/978-3-030-56920-4-31.
  • 20. Herzog A. Ontology of Information Security. International Journal of Information Security and Confidentiality. 2007, vol. 1 (4). pp. 1–23.
  • 21. Baranov V.V., Tsygulev I.N. Improvement of models and methods for assessing the security of elements of distributed information systems. The state and prospects of development of modern science in the field of Information technology in the Armed Forces of the Russian Federation. The Third All-Russian Scientific and Technological Conference «Contemporary Problems of Spacecraft Attitude Determination and Control». Anapa, 2024, pp. 194–197.
  • 22. Baranov V.V., Korchagina A.P., Shelupanov A.A. Development of digital security maps of elements of distributed information systems. Information Security of the Digital Economy. Proceedings of the XIX Scientific and Practical Conference (under the Xth Plenum of the regional branch of the Federal Educational and Methodological Association in the higher education system for the major 10.00.00 «Information security» in the Siberian and Far Eastern Federal Districts). Novosibirsk, 2023, pp. 11–23.
  • 23. Labutin N.G., Kostin P.V. Modeling the actions of a specialist in assessing threats to information security in information systems and networks in accordance with the new methodology of the FSTEC of Russia. Transactions of NNSTU named after R.Е. Alekseev. 2022, no. 3 (138). pp. 22–31.
Editorial office address

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 701-582

  journal@tusur.ru

 

Viktor N. Maslennikov

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02

Subscription for updates