Abstract

The article is devoted to the problem of developing an analytical data processing system for monitoring information security within the information security management system of modern companies conducting their main activities in cyberspace and using cloud infrastructure. Based on the analysis of modern information technologies related to ensuring information security of cloud infrastructure and the most popular products for ensuring information security of cloud infrastructures, as well as existing scientific approaches, a formalized approach to the synthesis of an analytical data processing system for monitoring the information security of an informatization object using cloud infrastructure is proposed. This approach takes into account the usefulness of the used information technologies from the viewpoint of information security. A general model of the structure of information support of an analytical data processing system for monitoring information security, as well as a model of the dependence of the usefulness of information technology on time and the ratio of the skill level of an information security specialist and an attacker are presented. The quality of the information security monitoring system is used as a criterion in the first optimization model. The following limitations are suggested: limitation on the time of making a decision on an incident; limitation on the degree of quality of analysis of information security events by the analytical data processing system and limitation on the compatibility of data analysis functions with data types about information security events. The cited results of the study of the second model show a logically consistent dependence of the usefulness of information technology on time and the ratio of the skill level of an information security specialist to the skill level of an attacker. The particular models of the structure of the information support of ASOD are presented. They make it possible to determine the rational structure information support of ASOD according to particular criteria. The following particular criteria are used: the maximin criterion of the usefulness of the information support of ASOD for monitoring the information security of an informatization object in the cloud infrastructure; the criterion for the maximum relevance of information support distributed over the nodes of the cloud infrastructure for systems with a low degree of centralization of management.

Highlights

  • Financial disclosure: The authors have no a financial or property interest in any material or method mentioned

  • The article is devoted to the problem of developing an analytical data processing system for monitoring information security within the information security management system of modern companies conducting their main activities in cyberspace and using cloud infrastructure

  • Based on the analysis of modern information technologies related to ensuring information security of cloud infrastructure and the most popular products for ensuring information security of cloud infrastructures, as well as existing scientific approaches, a formalized approach to the synthesis of an analytical data processing system for monitoring the information security of an informatization object using cloud infrastructure is proposed

Read more

Summary

НАУЧНАЯ СТАТЬЯ

Разработка моделей аналитической системы обработки данных для мониторинга ИБ объекта информатизации, использующего облачную инфраструктуру. Статья посвящена разработке аналитической системы обработки данных (АСОД) для мониторинга информационной безопасности (ИБ) в рамках системы менеджмента ИБ современных компаний, ведущих свою основную деятельность в киберпространстве и использующих облачную инфраструктуру. Представлена общая модель структуры информационного обеспечения АСОД для мониторинга ИБ, а также модель зависимости полезности ИТ от времени и соотношения уровня квалификации специалиста по ИБ и злоумышленника. В качестве частных критериев используются следующие: максиминный критерий полезности информационного обеспечения АСОД для мониторинга ИБ объекта информатизации в облачной инфраструктуре и критерий максимума актуальности информационного обеспечения, распределенного по узлам облачной инфраструктуры для систем с невысокой степенью централизации управления.

Наименование ИТ
Cisco Cloud Security
CheckPoint CloudGuard
ПОСТАНОВКА ЗАДАЧИ
АНАЛИТИЧЕСКОЙ СИСТЕМЫ ОБРАБОТКИ ДАННЫХ ДЛЯ МОНИТОРИНГА ИБ
РАЗРАБОТКА МОДЕЛИ ЗАВИСИМОСТИ ПОЛЕЗНОСТИ ИНФОРМАЦИОННОЙ
Полезность информационной технологии
ИНФОРМАТИЗАЦИИ В ОБЛАЧНОЙ ИНФРАСТРУКТУРЕ
СПИСОК ЛИТЕРАТУРЫ
Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.