| 10.14489/vkit.2021.05.pp.028-034 |
|
DOI: 10.14489/vkit.2021.05.pp.028-034 Павличева Е. Н., Федин Ф. О., Чискидов А. С., Глыбин Н. Ф. Аннотация. Представлен подход к формированию строковой модели нарушителя информационной безопасности объектов критической информационной инфраструктуры торговых площадок транспортных услуг. Эта модель основана на оценке возможностей нарушителя по физическому и логическому доступу к информации, его компетенции, оснащенности и мотивации. Рассмотрены предпосылки появления нарушителя информационной безопасности таких объектов. Описано, какие субъекты могут выступать в роли нарушителей объектов информационной безопасности критической информационной инфраструктуры (КИИ) торговой площадки транспортных услуг. Показано, как инструментальное CASE-средство структурного анализа и моделирования CA ERW in Process Modeler, работающее в режиме использования стандарта IDEF3, применяется для построения модели нарушителя информационной безопасности. Ключевые слова: критическая информационная инфраструктура; торговая площадка; нарушитель информационной безопасности; модель; потенциал.
Pavlicheva E. N., Fedin F. О., Chiskidov A. S., Glybin N. F. Abstract. The paper presents an approach to the formation of a string model of an intruder of information security of objects of critical information infrastructure of trading platforms for transport services, based on an assessment of the violator's capabilities for physical and logical access to information, an assessment of his competence, equipment and motivation. The prerequisites for the appearance of an infringer of information security of objects of critical information infrastructure are considered. It is described which subjects can act as violators of information security objects of the critical information infrastructure of the transport services trading platform. It is presented as a CASE tool for structural analysis and modeling of CA ERWin Process Modeler, operating in the mode of using the IDEF3 standard to build a model of an information security intruder. Opportunities for physical and logical access, as well as competence, based on the predicted values of the general technical knowledge of the information security violator, were assessed. Methods for assessing motivation and equipment are considered, classifications of the information security violator of the critical information infrastructure of the transport services trading platform are given, in accordance with these assessments. The developed model of information security of the CII facility of the transport services trading platform is presented, the use of which will allow as quickly and clearly as possible to assess the potential of an infringer of information security of the critical information infrastructure of the object in question. Keywords: Critical information infrastructure; Trading platform; Information security intruder; Model; Potential.
РусЕ. Н. Павличева (Московский государственный технологический университет «СТАНКИН», Москва, Россия)
EngE. N. Pavlicheva (Moscow State University of Technology “STANKIN”, Moscow, Russia)
Рус1. Зайниева В. С. Модель процесса категорирования объекта критической информационной инфраструктуры // Информационные технологии в науке, бизнесе и образовании: сборник трудов XI Междунар. науч.-практ. конф. студентов, аспирантов и молодых ученых (Москва, 28–29 ноября 2019 г.). 2020. С. 88 – 94. Eng1. Zaynieva V. S. (2020). Critical Information Infrastructure Object Categorization Process Model. Information technologies in science, business and education: collection of works of the XI International scientific-practical conference of students, graduate students and young scientists, pp. 88 – 94. [in Russian language]
РусСтатью можно приобрести в электронном виде (PDF формат). DOI: 10.14489/vkit.2021.05.pp.028-034 Скопируйте DOI статьи и перейдите по ссылке https://id-spektr.ru/product/pokupka-elektronnoy-stati-iz-zhurnala-vestnik-kompyuternyh-i-informatsionnyh-tehnologiy В комментарии к заказу обязательно укажите DOI статьи. .
EngThis article is available in electronic format (PDF). DOI: 10.14489/vkit.2021.05.pp.028-034 Copy the article DOI and follow the link https://id-spektr.ru/product/pokupka-elektronnoy-stati-iz-zhurnala-vestnik-kompyuternyh-i-informatsionnyh-tehnologiy Please specify the article DOI in the order comments.
.
|
Archive
Разработка концепции и создание сайта - ООО «Издательский дом «СПЕКТР»