Добавил:
ivanov666
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз:
Предмет:
Файл:Information protection in digital communication systems. Textbook
.pdf
311
there will be 3 600 000 packets. It can be assumed that almost all of them
are not malicious. And only once the active audit system has the right to
mistake “its own” for a “stranger”, that is, the probability of a false alarm
should in this case be no more than 3 × 10
–7
.
2. The ability to explain the cause of anxiety. Fulfilling this
requirement, firstly, helps to distinguish a justified alarm from a false one,
and secondly, it helps to determine the root cause of the incident, which is
important for assessing its consequences and preventing repeated violations.
Even if the response to a violation is carried out automatically, there should
be the possibility of subsequent analysis of the situation by specialists.
3. Integration with the control system and other security services.
Integration with the control system has two sides. First, the active audit tools
themselves must be managed (installed, configured, monitored) on a par
with other infrastructure services. Second, active auditing can (and should)
contribute data to the overall management database. Integration with
security services is necessary both for better analysis of the situation (for
example, using integrity monitoring tools) and for prompt response to
violations (using applications, operating systems or firewalls).
4. Availability of technical capabilities for remote monitoring of the
information system. This is a controversial requirement, since not all
organizations will want to be under someone else’s control. However, from
a technical point of view, such a measure is quite justified, since most
organizations do not have qualified information security specialists. Remote
monitoring can also be used for undisputed purposes, such as monitoring
the work of remote branches from headquarters.
The formulated demands can be considered maximalist. Apparently,
no modern commercial system or supplier satisfies them fully, but without
their implementation, active audit turns from a serious defensive weapon
into an alarm to scare away primary school children. Will customers want
to pay money for such toys? No, of course, if only they are sufficiently
versed in the subject.
Active audit systems belong to the field of high technology. They have
a developed mathematical base, advanced architecture, and have absorbed

312
knowledge of information security. Few distributors understand how what
they sell works; they can only retell the manufacturers’ advertising
brochures, where, of course, everything looks great. Customers don’t have
to go into detail either, but they should know what to ask suppliers. They
won’t always be able to answer, but silence will tell the customer a lot.
7.2.7. Possible criteria for evaluating active audit systems [15]
The proposed criteria have much in common with the criteria for
evaluating management systems. This is no coincidence, since active
auditing and management are essentially close.
Suspicious activity refers to the behavior of a user or component of
an information system that is atypical for a given user (component) or (in
accordance with predetermined criteria) malicious.
The systems covered in these criteria must detect suspicious activity
and provide the means to automatically respond to unusual or malicious
activity. In addition, they must meet the general requirements for
information security services.
The main indicators characterizing active audit systems are:
1) range of controlled objects;
2) the range and degree of detail of the characteristics being monitored;
3) system expandability;
4) system customizability;
5) degree of automation of the system’s functioning;
6) the ability to work within distributed systems;
7) the ability to work in real time;
8) manufacturability of the system.
Indicators used to evaluate active audit systems:
1. Tracking the behavior of users and information system components.
2. Ensuring the confidentiality and integrity of registration
information.
3. Detection of malicious behavior.
4. Identification of atypical behavior.

313
5. Administration.
6. Integrity control.
7. Scalability.
8. Availability.
9. Recovery.
10. Documentation.
11. Testing.
Tracking the behavior of users and information system components:
• the ability to track a basic set of characteristics of user behavior and
information system components;
• the ability to change (including add to) the set of monitored
characteristics;
• ability to track characteristics in distributed systems;
• the ability to track the behavior of individual users and information
system components in real time;
• the ability to specify a method for informing the security
administrator when monitored characteristics exceed acceptable limits;
• the ability to specify a method for automatically responding to
monitored characteristics going beyond acceptable limits.
Ensuring the confidentiality and integrity of registration information:
• protection of registration information from unauthorized access
within individual systems;
• monitoring the integrity (mutual consistency) of registration
information within distributed systems;
• protection of registration information from unauthorized access
within distributed systems;
• the ability to set a method for informing the security administrator
about a violation of the integrity and/or confidentiality of registration
information;
• the ability to specify a method for automatically responding to
violations of the integrity and/or confidentiality of registration information.
Detecting malicious behavior:
• the ability to identify a basic set of malicious actions;

314
• the ability to replenish the base of rules describing malicious actions;
• the ability to customize the rule base for specific information
services;
• the ability to detect malicious actions distributed over time;
• the ability to detect malicious actions in distributed systems;
• the ability to detect malicious actions in real time;
• the ability to specify a method for informing the security
administrator about detected malicious actions;
• the ability to set the level of detail of information confirming the
presence of malicious actions;
• the ability to specify a method for automatically responding to
detected malicious actions;
• availability of means for automatically checking the consistency of
the rule base within a distributed configuration;
• availability of tools for analyzing malicious actions with issuing
recommendations to prevent similar actions in the future;
• availability of means for predicting malicious actions.
Identifying atypical behavior:
• availability of a statistical analysis subsystem to identify atypical
behavior;
• the ability to identify atypical behavior when using a basic set of
information services;
• the ability to replenish and/or change the set of controlled aspects of
behavior;
• the ability to configure specific information services;
• availability of means for changing the parameters of statistical
analysis in order to ensure a given ratio between errors of the first type (lack
of response to atypical behavior) and errors of the second type (false
positive);
• the ability to identify atypical behavior within a distributed system;
• the ability to identify atypical behavior in real time;

315
• the ability to specify a method for informing the security
administrator about identified atypical behavior;
• the ability to set the level of detail of information confirming the
presence of atypical behavior;
• the ability to set a method for automatically responding to identified
atypical behavior;
• availability of means for automatically checking the consistency of
statistical parameters within a distributed configuration;
• availability of means for automatically assessing the relationship
between errors of the first and second types for given statistical parameters.
Administration:
• identification and authentication of administrators within local
systems;
• identification and authentication of administrators within distributed
systems;
• registration of administrative actions within local systems;
• registration of administrative actions within distributed systems;
• the ability to centrally detect suspicious activity within distributed
systems;
• the possibility of centralized administration of distributed active
audit systems.
Integrity control:
• availability of means of monitoring the integrity of the software and
information parts of the active audit system (local, distributed, using
certified algorithms).
Scalability:
• availability of scaling tools based on the number of tracked users and
information system components: the ability to group users (components)
with homogeneous characteristics;
• availability of means of scaling according to the size of the serviced
information system, the ability to vary between distributed and centralized
processing of registration information, the ability to organize a hierarchy of
processing centers.

316
Availability:
• availability of high availability means: errors and failures of
individual subsystems or components of the active audit system should not
disrupt the functionality of other subsystems (components).
Recovery:
• availability of recovery tools after errors and failures, including
failures of individual elements of a distributed system.
Documentation:
• active audit system administrator’s guide (local, distributed, using
certified integrity control algorithms);
• programmer’s guide (description of software interfaces with the
system for collecting and analyzing registration information);
• design (project) documentation;
• test documentation.
Testing:
• ensuring the possibility of routine testing of registration information
collection tools, subsystems for detecting malicious and atypical behavior,
integrity monitoring tools, administration tools, and recovery tools.
7.2.8. Audit results
The results of an organization’s IS audit can be divided into three
main groups:
1. Organizational: planning, management, document flow of IS
functioning.
2. Technical: failures, malfunctions, optimization of the operation of
IS elements, continuous maintenance, infrastructure creation, etc.
3. Methodological: approaches to solving problem situations,
management and control, general orderliness and structuring.
The audit will allow you to reasonably create the following
documents:
• Long-term IS development plan;
• Organization’s IS security policy;
• Methodology for working and fine-tuning the organization’s IS;
• IS recovery plan in an emergency situation.

317
CONCLUSION
Information protection is currently one of the leading areas of ensuring
the security of the state, organization, and individual. Problems of various
aspects of security are increasingly occupying the minds of specialists, since
from their own experience people come to the conclusion that it is
impossible to ensure the effective functioning of the state and organization,
as well as a decent “quality” of human life, fighting off threats like
mosquitoes in a swampy place — a lot of efforts, but little sense.
The path to solving a security problem, like other problems, begins
with a systematic approach to it and its system analysis.
In the practice of systems analysis, the opinion has taken root that
50 % of success in solving a complex problem is its correct formulation.
The more clearly the sources of protected information, the places and
conditions of their location, the methods and means of obtaining information
by an attacker are defined, the more specifically the protection tasks and
requirements for the appropriate means can be formulated. Specificity of
tasks and requirements is a necessary condition for the targeted and rational
use of allocated resources.
Sources of information are determined as a result of structuring the
protected information, and the places and conditions of their location are
determined based on the results of modeling the objects of protection.
The increase in the number and types of threats to information
security, accompanying the increasing importance of information in the life
of society and people, is a trend that cannot be ignored.
An example of this is the impact of widespread adoption of mobile
telephony. Along with the great advantages for users of this relatively new
type of communication for Russia compared to traditional wired telephone
communications, a very serious problem has arisen in ensuring the
confidentiality of the conversation. If to unauthorized eavesdropping on a
telephone conversation in a wired channel an attacker needs to take a
number of rather complex and criminally punishable actions by law, then to

318
eavesdrop on a conversation over a cellular connection it is enough to have
a small amount of money to buy a scanning receiver. Using such a receiver,
you can comfortably and safely listen to and record conversations of
subscribers of this communication system.
Therefore, the study of threats, knowledge of their potential
capabilities in relation to specific conditions, the ability to evaluate threats
in quantitative terms and, finally, the formulation of requirements for
methods and means of protection are necessary and consistently
implemented processes at the stage of setting tasks for information
protection. Ignoring these processes can lead to a discrepancy between the
methods and means of protecting information and its threats and, as a result,
to large costs from the theft of information and unjustified expenses for its
protection.
The difficulty of identifying and analyzing the information security
threats discussed in the book is due to the variety of methods and means of
obtaining information, the high dynamics of their changes and the
multivariate actions of attackers. As a result, a necessary condition for
competently setting the task of protecting information is constant
monitoring by specialists of the state of development of the relevant fields
of science and technology, as well as modeling threats to specific protected
information. The more accurately and more fully potential threats are taken
into account in the requirements, the higher the effectiveness of information
protection can be ensured. Gross errors in threat analysis cannot be corrected
at subsequent stages.
No less important and complex tasks arise when directly choosing
rational methods and means of protection, i.e. those that provide the required
level of protection at minimal cost, not exceeding the damage from the theft
of information. Finding rational options that satisfy these conditions is the
main problem at the stage of determining methods and means of protecting
information. Despite the variety of possible methods of engineering and
technical protection, their methods can be reduced to two groups:
information and energy concealment of information. Regardless of the type
and carrier of information, information concealment comes down to

319
camouflage and misinformation, and energy concealment comes down to
reducing the carrier’s energy or increasing the level of interference at the
input of the attacker’s receiver. This general approach to information
security allows us to consider from a unified perspective the whole variety
of methods and means of ensuring information security that implement them
and creates the basis for transforming a set of empirical recommendations
on engineering and technical information security into an appropriate
theory.
The main directions for further development of engineering and
technical information protection are:
• in theoretical terms — development of the theory of engineering and
technical information security as a component of the theory of information
security;
• in methodological terms — automation of processes for rationally
solving information security problems within the framework of an expert
system for information security;
• in practical terms — the integration of methods and means of
information protection into a single security system for a specific
organizational structure.
Progress in the development of computer technology, software and
network technologies gives a strong impetus to the development of security
tools, which largely requires the scientific paradigm of information security.
Information security theory is one of the most developing natural sciences.
The main provisions of information security are:
1. Research and analysis of the causes of security violations of
information systems.
2. Development of effective security models that are adequate to the
current level of development of software and hardware, as well as to the
capabilities of attackers and destructive software.
3. Creation of methods and means for the correct implementation of
security models in existing systems, with the possibility of flexible security
management depending on the requirements put forward, the permissible
risk and the consumption of resources.

320
4. The need to develop tools for analyzing the security of information
systems using test actions.
Computer security centers play a special role in the development of
information security theory, both science and industry. These include
government, public and commercial organizations, as well as informal
associations, the main activity of which is coordinating efforts aimed at
updating information security problems, conducting theoretical research and
developing specific practical solutions in the field of security, analytical
activities and forecasting.
In the Russian Federation, such centers are the State Technical
Commission under the President of the Russian Federation, the Institute of
Cryptography, Communications and Informatics of the Academy of the
Federal Security Service, and the Academy of Cryptography of the Russian
Federation.
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]
