| 10.14489/vkit.2025.04.pp.039-044 |
|
DOI: 10.14489/vkit.2025.04.pp.039-044 Мохорев Д. Е. Аннотация. Представлен анализ ключевых объектов информационной системы в качестве источников данных для построения универсального метода прогнозирования поведения этих объектов. Определены основные характеристики российских информационных систем. Построена типовая информационная архитектура российской организации, которая служит основой для исследования. Для каждого элемента данной архитектуры проведен анализ сложности построения базовой модели поведения и оценена возможность выявления угроз безопасности информации при регистрации отклонений от типичного поведения рассматриваемых объектов. В результате анализа выявлены ключевые объекты информационной системы, применение методов поведенческого анализа к которым позволит наиболее эффективно обнаруживать потенциальные угрозы. Результаты исследования могут быть использованы как для теоретических разработок в области информационных технологий, так и для практического применения при создании средств защиты информации, основанных на поведенческом анализе. Ключевые слова: поведенческий анализ; прогнозирование поведения; информационные системы; uba/ueba; информационная безопасность.
Abstract. The article presents an analysis of key objects in the information system as data sources for developing a universal method to predict their behavior. Particular attention is paid to the advantages of behavioral analysis over traditional methods of threat detection under conditions where Russian organizations have limited access to up-to-date vulnerability information from external knowledge bases. The study covers two main areas: the operation of modern information systems and human interaction with these systems. In the first part of the article, the main characteristics of Russian information systems are defined. A typical information architecture of a Russian organization is then constructed, which serves as the basis for further research. For each element of this architecture, a detailed analysis of the complexity of building a basic behavioral model is conducted, and the potential for detecting information security threats by registering deviations from typical object behaviors is assessed. As a result f the analysis, key objects within the information system were identified, to which applying behavioral analysis methods would most effectively detect potential threats. The article emphasizes the importance of developing threat detection methods that are independent of external data sources. The results of the study can be used both for theoretical developments in the field of information technology and for practical applications in creating information protection tools based on behavioral analysis. Keywords: Behavioral analysis; Behavior forecasting; Information systems; Uba/ueba; Information security.
РусД. Е. Мохорев (Российский экономический университет имени Г. В. Плеханова, Москва, Россия) E-mail: Этот e-mail адрес защищен от спам-ботов, для его просмотра у Вас должен быть включен Javascript EngD. E. Mokhorev (Plekhanov Russian University of Economics, Moscow, Russia) E-mail: Этот e-mail адрес защищен от спам-ботов, для его просмотра у Вас должен быть включен Javascript
Рус1. Léargas Security: сайт. 2023. The Perils of Threat Intelligence Feed Poisoning: The Importance of Proper Curation and Validation of Artifacts. URL: https://leargassecurity.com/2023/04/14/the-perils-of-threat-intelligence-feed-poisoning-the-importance-of-proper-curation-and-validation-of-artifacts/ (дата обраще¬ния: 12.09.2024). Eng1. Léargas Security (2023). The Perils of Threat Intelligence Feed Poisoning: The Importance of Proper Curation and Validation of Artifacts. Retrieved From https://leargassecurity.com/2023/04/14/the-perils-of-threat-intelligence-feed-poisoning-the-importance-of-proper-curation-and-validation-of-artifacts/
РусСтатью можно приобрести в электронном виде (PDF формат). DOI: 10.14489/vkit.2025.04.pp.039-044 Скопируйте DOI статьи и перейдите по ссылке https://id-spektr.ru/product/pokupka-elektronnoy-stati-iz-zhurnala-vestnik-kompyuternyh-i-informatsionnyh-tehnologiy В комментарии к заказу обязательно укажите DOI статьи. .
EngThis article is available in electronic format (PDF). DOI: 10.14489/vkit.2025.04.pp.039-044 Copy the article DOI and follow the link https://id-spektr.ru/product/pokupka-elektronnoy-stati-iz-zhurnala-vestnik-kompyuternyh-i-informatsionnyh-tehnologiy Please specify the article DOI in the order comments.
.
|
Архив номеров
Разработка концепции и создание сайта - ООО «Издательский дом «СПЕКТР»