Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

Information protection in digital communication systems. Textbook

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
311
there will be 3 600 000 packets. It can be assumed that almost all of them are not malicious. And only once the active audit system has the right to mistake “its own” for a “stranger”, that is, the probability of a false alarm
should in this case be no more than 3 × 10
7
.
2. The ability to explain the cause of anxiety. Fulfilling this requirement, firstly, helps to distinguish a justified alarm from a false one, and secondly, it helps to determine the root cause of the incident, which is important for assessing its consequences and preventing repeated violations. Even if the response to a violation is carried out automatically, there should be the possibility of subsequent analysis of the situation by specialists.
3. Integration with the control system and other security services. Integration with the control system has two sides. First, the active audit tools themselves must be managed (installed, configured, monitored) on a par with other infrastructure services. Second, active auditing can (and should) contribute data to the overall management database. Integration with security services is necessary both for better analysis of the situation (for example, using integrity monitoring tools) and for prompt response to violations (using applications, operating systems or firewalls).
4. Availability of technical capabilities for remote monitoring of the information system. This is a controversial requirement, since not all organizations will want to be under someone elses control. However, from a technical point of view, such a measure is quite justified, since most organizations do not have qualified information security specialists. Remote monitoring can also be used for undisputed purposes, such as monitoring the work of remote branches from headquarters.
The formulated demands can be considered maximalist. Apparently, no modern commercial system or supplier satisfies them fully, but without their implementation, active audit turns from a serious defensive weapon into an alarm to scare away primary school children. Will customers want to pay money for such toys? No, of course, if only they are sufficiently versed in the subject.
Active audit systems belong to the field of high technology. They have a developed mathematical base, advanced architecture, and have absorbed
312
knowledge of information security. Few distributors understand how what they sell works; they can only retell the manufacturers advertising brochures, where, of course, everything looks great. Customers dont have to go into detail either, but they should know what to ask suppliers. They won’t always be able to answer, but silence will tell the customer a lot.
7.2.7. Possible criteria for evaluating active audit systems [15]
The proposed criteria have much in common with the criteria for evaluating management systems. This is no coincidence, since active auditing and management are essentially close.
Suspicious activity refers to the behavior of a user or component of an information system that is atypical for a given user (component) or (in accordance with predetermined criteria) malicious.
The systems covered in these criteria must detect suspicious activity and provide the means to automatically respond to unusual or malicious activity. In addition, they must meet the general requirements for information security services.
The main indicators characterizing active audit systems are:
1) range of controlled objects;
2) the range and degree of detail of the characteristics being monitored;
3) system expandability;
4) system customizability;
5) degree of automation of the system’s functioning;
6) the ability to work within distributed systems;
7) the ability to work in real time;
8) manufacturability of the system.
Indicators used to evaluate active audit systems:
1. Tracking the behavior of users and information system components.
2. Ensuring the confidentiality and integrity of registration
information.
3. Detection of malicious behavior.
4. Identification of atypical behavior.
313
5. Administration.
6. Integrity control.
7. Scalability.
8. Availability.
9. Recovery.
10. Documentation.
11. Testing.
Tracking the behavior of users and information system components:
the ability to track a basic set of characteristics of user behavior and
information system components;
the ability to change (including add to) the set of monitored
characteristics;
• ability to track characteristics in distributed systems;
the ability to track the behavior of individual users and information
system components in real time;
the ability to specify a method for informing the security
administrator when monitored characteristics exceed acceptable limits;
the ability to specify a method for automatically responding to
monitored characteristics going beyond acceptable limits.
Ensuring the confidentiality and integrity of registration information:
protection of registration information from unauthorized access
within individual systems;
monitoring the integrity (mutual consistency) of registration
information within distributed systems;
protection of registration information from unauthorized access
within distributed systems;
the ability to set a method for informing the security administrator about a violation of the integrity and/or confidentiality of registration information;
the ability to specify a method for automatically responding to violations of the integrity and/or confidentiality of registration information.
Detecting malicious behavior:
• the ability to identify a basic set of malicious actions;
314
• the ability to replenish the base of rules describing malicious actions;
the ability to customize the rule base for specific information
services;
• the ability to detect malicious actions distributed over time;
• the ability to detect malicious actions in distributed systems;
• the ability to detect malicious actions in real time;
the ability to specify a method for informing the security
administrator about detected malicious actions;
the ability to set the level of detail of information confirming the presence of malicious actions;
the ability to specify a method for automatically responding to detected malicious actions;
availability of means for automatically checking the consistency of the rule base within a distributed configuration;
availability of tools for analyzing malicious actions with issuing recommendations to prevent similar actions in the future;
• availability of means for predicting malicious actions.
Identifying atypical behavior:
availability of a statistical analysis subsystem to identify atypical behavior;
the ability to identify atypical behavior when using a basic set of information services;
the ability to replenish and/or change the set of controlled aspects of behavior;
• the ability to configure specific information services;
availability of means for changing the parameters of statistical
analysis in order to ensure a given ratio between errors of the first type (lack of response to atypical behavior) and errors of the second type (false positive);
• the ability to identify atypical behavior within a distributed system;
• the ability to identify atypical behavior in real time;
315
the ability to specify a method for informing the security administrator about identified atypical behavior;
the ability to set the level of detail of information confirming the presence of atypical behavior;
the ability to set a method for automatically responding to identified atypical behavior;
availability of means for automatically checking the consistency of statistical parameters within a distributed configuration;
availability of means for automatically assessing the relationship between errors of the first and second types for given statistical parameters.
Administration:
identification and authentication of administrators within local systems;
identification and authentication of administrators within distributed systems;
• registration of administrative actions within local systems;
• registration of administrative actions within distributed systems;
the ability to centrally detect suspicious activity within distributed
systems;
the possibility of centralized administration of distributed active audit systems.
Integrity control:
availability of means of monitoring the integrity of the software and information parts of the active audit system (local, distributed, using certified algorithms).
Scalability:
availability of scaling tools based on the number of tracked users and information system components: the ability to group users (components) with homogeneous characteristics;
availability of means of scaling according to the size of the serviced information system, the ability to vary between distributed and centralized processing of registration information, the ability to organize a hierarchy of processing centers.
316
Availability:
availability of high availability means: errors and failures of individual subsystems or components of the active audit system should not disrupt the functionality of other subsystems (components).
Recovery:
availability of recovery tools after errors and failures, including failures of individual elements of a distributed system.
Documentation:
active audit system administrators guide (local, distributed, using certified integrity control algorithms);
programmers guide (description of software interfaces with the system for collecting and analyzing registration information);
• design (project) documentation;
• test documentation.
Testing:
ensuring the possibility of routine testing of registration information collection tools, subsystems for detecting malicious and atypical behavior, integrity monitoring tools, administration tools, and recovery tools.
7.2.8. Audit results
The results of an organizations IS audit can be divided into three
main groups:
1. Organizational: planning, management, document flow of IS functioning.
2. Technical: failures, malfunctions, optimization of the operation of IS elements, continuous maintenance, infrastructure creation, etc.
3. Methodological: approaches to solving problem situations, management and control, general orderliness and structuring.
The audit will allow you to reasonably create the following
documents:
• Long-term IS development plan;
• Organization’s IS security policy;
• Methodology for working and fine-tuning the organizations IS;
IS recovery plan in an emergency situation.
317
CONCLUSION
Information protection is currently one of the leading areas of ensuring the security of the state, organization, and individual. Problems of various aspects of security are increasingly occupying the minds of specialists, since from their own experience people come to the conclusion that it is impossible to ensure the effective functioning of the state and organization,
as well as a decent “quality” of human life, fighting off threats like
mosquitoes in a swampy place a lot of efforts, but little sense.
The path to solving a security problem, like other problems, begins with a systematic approach to it and its system analysis.
In the practice of systems analysis, the opinion has taken root that 50 % of success in solving a complex problem is its correct formulation.
The more clearly the sources of protected information, the places and conditions of their location, the methods and means of obtaining information by an attacker are defined, the more specifically the protection tasks and requirements for the appropriate means can be formulated. Specificity of tasks and requirements is a necessary condition for the targeted and rational use of allocated resources.
Sources of information are determined as a result of structuring the protected information, and the places and conditions of their location are determined based on the results of modeling the objects of protection.
The increase in the number and types of threats to information security, accompanying the increasing importance of information in the life of society and people, is a trend that cannot be ignored.
An example of this is the impact of widespread adoption of mobile telephony. Along with the great advantages for users of this relatively new type of communication for Russia compared to traditional wired telephone communications, a very serious problem has arisen in ensuring the confidentiality of the conversation. If to unauthorized eavesdropping on a telephone conversation in a wired channel an attacker needs to take a number of rather complex and criminally punishable actions by law, then to
318
eavesdrop on a conversation over a cellular connection it is enough to have a small amount of money to buy a scanning receiver. Using such a receiver, you can comfortably and safely listen to and record conversations of subscribers of this communication system.
Therefore, the study of threats, knowledge of their potential capabilities in relation to specific conditions, the ability to evaluate threats in quantitative terms and, finally, the formulation of requirements for methods and means of protection are necessary and consistently implemented processes at the stage of setting tasks for information protection. Ignoring these processes can lead to a discrepancy between the methods and means of protecting information and its threats and, as a result, to large costs from the theft of information and unjustified expenses for its protection.
The difficulty of identifying and analyzing the information security threats discussed in the book is due to the variety of methods and means of obtaining information, the high dynamics of their changes and the multivariate actions of attackers. As a result, a necessary condition for competently setting the task of protecting information is constant monitoring by specialists of the state of development of the relevant fields of science and technology, as well as modeling threats to specific protected information. The more accurately and more fully potential threats are taken into account in the requirements, the higher the effectiveness of information protection can be ensured. Gross errors in threat analysis cannot be corrected at subsequent stages.
No less important and complex tasks arise when directly choosing rational methods and means of protection, i.e. those that provide the required level of protection at minimal cost, not exceeding the damage from the theft of information. Finding rational options that satisfy these conditions is the main problem at the stage of determining methods and means of protecting information. Despite the variety of possible methods of engineering and technical protection, their methods can be reduced to two groups: information and energy concealment of information. Regardless of the type and carrier of information, information concealment comes down to
319
camouflage and misinformation, and energy concealment comes down to
reducing the carrier’s energy or increasing the level of interference at the input of the attacker’s receiver. This general approach to information
security allows us to consider from a unified perspective the whole variety of methods and means of ensuring information security that implement them and creates the basis for transforming a set of empirical recommendations on engineering and technical information security into an appropriate theory.
The main directions for further development of engineering and technical information protection are:
in theoretical terms development of the theory of engineering and technical information security as a component of the theory of information security;
in methodological terms automation of processes for rationally solving information security problems within the framework of an expert system for information security;
in practical terms the integration of methods and means of information protection into a single security system for a specific organizational structure.
Progress in the development of computer technology, software and network technologies gives a strong impetus to the development of security tools, which largely requires the scientific paradigm of information security. Information security theory is one of the most developing natural sciences.
The main provisions of information security are:
1. Research and analysis of the causes of security violations of
information systems.
2. Development of effective security models that are adequate to the current level of development of software and hardware, as well as to the capabilities of attackers and destructive software.
3. Creation of methods and means for the correct implementation of security models in existing systems, with the possibility of flexible security management depending on the requirements put forward, the permissible risk and the consumption of resources.
320
4. The need to develop tools for analyzing the security of information systems using test actions.
Computer security centers play a special role in the development of information security theory, both science and industry. These include government, public and commercial organizations, as well as informal associations, the main activity of which is coordinating efforts aimed at updating information security problems, conducting theoretical research and developing specific practical solutions in the field of security, analytical activities and forecasting.
In the Russian Federation, such centers are the State Technical Commission under the President of the Russian Federation, the Institute of Cryptography, Communications and Informatics of the Academy of the Federal Security Service, and the Academy of Cryptography of the Russian Federation.