Trudy SPIIRAN
RUS  ENG    JOURNALS   PEOPLE   ORGANISATIONS   CONFERENCES   SEMINARS   VIDEO LIBRARY   PACKAGE AMSBIB  
General information
Latest issue
Archive

Search papers
Search references

RSS
Latest issue
Current issues
Archive issues
What is RSS



Informatics and Automation:
Year:
Volume:
Issue:
Page:
Find






Personal entry:
Login:
Password:
Save password
Enter
Forgotten password?
Register


Trudy SPIIRAN, 2019, Issue 18, volume 5, Pages 1182–1211
DOI: https://doi.org/10.15622/sp.2019.18.5.1182-1211
(Mi trspy1078)
 

This article is cited in 1 scientific paper (total in 1 paper)

Information Security

Automated detection of assets and calculation of their criticality for the analysis of information system security

A. V. Fedorchenko, E. V. Doynikova, I. V. Kotenko

St. Petersburg Institute for Informatics and Automation of Russian Academy of Sciences (SPIIRAS)
Abstract: The research aims to develop the technique for an automated detection of information system assets and comparative assessment of their criticality for farther security analysis of the target infrastructure. The assets are all information and technology objects of the target infrastructure. The size, heterogeneity, complexity of interconnections, distribution and constant modification of the modern information systems complicate this task. An automated and adaptive determination of information and technology assets and connections between them based on the determination of the static and dynamic objects of the initially uncertain infrastructure is rather challenging problem. The paper proposes dynamic model of connections between objects of the target infrastructure and the technique for its building based on the event correlation approach. The developed technique is based on the statistical analysis of the empirical data on the system events. The technique allows determining main types of analysed infrastructure, their characteristics and hierarchy. The hierarchy is constructed considering the frequency of objects use, and as the result represents their relative criticality for the system operation. For the listed goals the indexes are introduced that determine belonging of properties to the same type, joint use of the properties, as well as dynamic indexes that characterize the variability of properties relative to each other. The resulting model is used for the initial comparative assessment of criticality for the system objects. The paper describes the input data, the developed models and proposed technique for the assets detection and comparison of their criticality. The experiments that demonstrate an application of the developed technique on the example of analyzing security logs of Windows operating system are provided.
Keywords: assets, asset types, asset criticality, statistical data analysis, security event correlation, impact, security assessment.
Funding agency Grant number
Russian Foundation for Basic Research 19-07-01246_а
16-29-09482_офи_м
18-37-20047_Стабильность
18-07-01488_а
18-29-22034_мк
Ministry of Education and Science of the Russian Federation СП-751.2018.5
Russian Academy of Sciences - Federal Agency for Scientific Organizations АААА-А16-116033110102-5
This work was partially supported by grants of RFBR (projects No. 19-07-01246, 16-29-09482, 18-37-20047, 18-07-01488 and 18-29-22034), grant of the President of the Russian Federation SP-751.2018.5 and by the budget (the project No. AAAA-A16-116033110102-5).
Received: 25.12.2018
Bibliographic databases:
Document Type: Article
UDC: 004.056
Language: Russian
Citation: A. V. Fedorchenko, E. V. Doynikova, I. V. Kotenko, “Automated detection of assets and calculation of their criticality for the analysis of information system security”, Tr. SPIIRAN, 18:5 (2019), 1182–1211
Citation in format AMSBIB
\Bibitem{FedDoyKot19}
\by A.~V.~Fedorchenko, E.~V.~Doynikova, I.~V.~Kotenko
\paper Automated detection of assets and calculation of their criticality for the analysis of information system security
\jour Tr. SPIIRAN
\yr 2019
\vol 18
\issue 5
\pages 1182--1211
\mathnet{http://mi.mathnet.ru/trspy1078}
\crossref{https://doi.org/10.15622/sp.2019.18.5.1182-1211}
\elib{https://elibrary.ru/item.asp?id=40938369}
Linking options:
  • https://www.mathnet.ru/eng/trspy1078
  • https://www.mathnet.ru/eng/trspy/v18/i5/p1182
  • This publication is cited in the following 1 articles:
    Citing articles in Google Scholar: Russian citations, English citations
    Related articles in Google Scholar: Russian articles, English articles
    Informatics and Automation
     
      Contact us:
     Terms of Use  Registration to the website  Logotypes © Steklov Mathematical Institute RAS, 2025