|
This article is cited in 2 scientific papers (total in 2 papers)
Identifying anomalies using metadata
A. A. Grushoa, E. E. Timoninaa, N. A. Grushoa, I. Yu. Teryokhinab a Institute of Informatics Problems, Federal Research Center “Computer Sciences and Control” of the Russian Academy of Sciences, 44-2 Vavilov Str., Moscow 119133, Russian Federation
b Faculty of Computational Mathematics and Cybernetics, M. V. Lomonosov Moscow State University, 1-52 Lenin- skiye Gory, GSP-1, Moscow 119991, Russian Federation
Abstract:
The paper discusses the problem of information technology security control based on computer audit data. These data are the sequence of small samples, each of which describes the transmission of information from one transformation to another. Information technologies are represented by mathematical models in the form of oriented acyclic graphs. In the article, such graphs describing data transmission are called metadata. In integrated computer audit data, there may be at the same time traces of the execution of several information technologies described by their graphs. This makes it difficult to recognize information flows that correspond to arcs of different graphs. The concept of legal information flow is introduced in the paper, which corresponds to the transfer of data of all information technologies being performed. Information flows that do not correspond to the execution of existing information technologies are called illegal or anomalies. Such information flows can occur due to hostile activities of insiders or due to errors in user actions. The article solves the problem of effective identification of legal information flows and anomalies on the basis of metadata.
Keywords:
information security, information flow, anomalies, metadata, systems of different representatives.
Received: 15.07.2020
Citation:
A. A. Grusho, E. E. Timonina, N. A. Grusho, I. Yu. Teryokhina, “Identifying anomalies using metadata”, Inform. Primen., 14:3 (2020), 76–80
Linking options:
https://www.mathnet.ru/eng/ia682 https://www.mathnet.ru/eng/ia/v14/i3/p76
|
|