<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">sibsutis</journal-id><journal-title-group><journal-title xml:lang="ru">Вестник СибГУТИ</journal-title><trans-title-group xml:lang="en"><trans-title>The Herald of the Siberian State University of Telecommunications and Information Science</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">1998-6920</issn><publisher><publisher-name>СибГУТИ</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.55648/1998-6920-2022-16-3-3-13</article-id><article-id custom-type="elpub" pub-id-type="custom">sibsutis-146</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>Статьи</subject></subj-group></article-categories><title-group><article-title>Особенности формирования вектора современных сетевых атак</article-title><trans-title-group xml:lang="en"><trans-title>Vector formation features of modern network attacks</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Ветров</surname><given-names>И. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Vetrov</surname><given-names>I. A.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Ветров Игорь Анатольевич – кандидат технических наук, доцент, образовательно-научный кластер «Институт высоких технологий».</p><p>236041, Калининград, ул. Александра Невского, 14.</p></bio><bio xml:lang="en"><p>Igor A. Vetrov - Candidate of Technical Sciences, Associate Professor, Institute of Physical and Mathematical Sciences and Information Technologies, I. Kant Baltic Federal University.</p><p>14 Alexander Nevsky Str., Kaliningrad, 236041.</p></bio><email xlink:type="simple">vetrov.gosha2009@yandex.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Подтопельный</surname><given-names>В. В.</given-names></name><name name-style="western" xml:lang="en"><surname>Podtopelny</surname><given-names>V. V.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Подтопельный Владислав Владимирович - старший преподаватель, Институт цифровых технологий КГТУ.</p><p>236022, Калининград, Советский пр., 1.</p></bio><bio xml:lang="en"><p>Vladislav V. Podtopelny - senior lecturer, Institute of Digital Technologies of KSTU.</p><p>236022, Sovetsky ave., 1, Kaliningrad, Kaliningrad region.</p></bio><email xlink:type="simple">ionpvv@mail.ru</email><xref ref-type="aff" rid="aff-2"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Балтийский федеральный университет им. И. Канта</institution><country>Россия</country></aff><aff xml:lang="en"><institution>I. Kant Baltic Federal University</institution><country>Russian Federation</country></aff></aff-alternatives><aff-alternatives id="aff-2"><aff xml:lang="ru"><institution>Калининградский государственный технический университет</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Kaliningrad State Technical University</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2022</year></pub-date><pub-date pub-type="epub"><day>30</day><month>09</month><year>2022</year></pub-date><volume>0</volume><issue>3</issue><fpage>3</fpage><lpage>13</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Ветров И.А., Подтопельный В.В., 2022</copyright-statement><copyright-year>2022</copyright-year><copyright-holder xml:lang="ru">Ветров И.А., Подтопельный В.В.</copyright-holder><copyright-holder xml:lang="en">Vetrov I.A., Podtopelny V.V.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://vestnik.sibsutis.ru/jour/article/view/146">https://vestnik.sibsutis.ru/jour/article/view/146</self-uri><abstract><p>Рассмотрены проблемы, возникающие при постановке задачи определения вектора сетевой атаки в корпоративной информационной сети. Приведены и охарактеризованы разновидности методик, упрощающих построение вектора сетевой атаки, применяемых при анализе надежности информационных систем, рассмотрена их пригодность для различных процедур определения параметров вектора. При построении вектора сетевой атаки определяется специфика проявления параметра времени как характеристики, указывающей на более эффективный путь распространения компрометации. Формирование вектора рассматривается с учетом специфики многоуровневой организации сетей. Определяется специфика упрощенной модели вычисления вектора, которая включает процедуры, ориентированные на различные подходы.</p></abstract><trans-abstract xml:lang="en"><p>The problems that arise when setting tasks for determining the vector of a network attack in a corporate information network are considered. The varieties of various techniques that simplify the construction of a network  attack vector used  in the analysis of the reliability of information systems are presented and characterized. The suitability for various procedures for determining vector parameters is considered. When constructing a network attack vector, the specificity of the manifestation of the time parameter was determined as a characteristic indicating a more effective way of spreading compromise. The formation of the vector is considered taking into account the specifics of the networks multilevel organization. The specifics of the simplified vector calculation model including procedures focused on various approaches are determined.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>вектор сетевой атаки</kwd><kwd>информационная система</kwd><kwd>корпоративная информационная сеть</kwd><kwd>уязвимость</kwd></kwd-group><kwd-group xml:lang="en"><kwd>vectors of network attack</kwd><kwd>information systems</kwd><kwd>corporate information network</kwd><kwd>vulnerability</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Методика оценки угроз безопасности информации // Методический документ ФСТЭК России: утв. ФСТЭК России России 5 февраля 2021 г.</mixed-citation><mixed-citation xml:lang="en">Metodika otsenki ugroz bezopasnosti informatsii Metodicheskii dokument FSTEK Rossii: utv. FSTEK Rossii 5 fevralya 2021. [Methodology for assessing threats to information security Methodological document of the FSTEC of Russia]. Moscow, 2021.</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">ГОСТ Р 56546-2015 Национальный стандарт российской федерации. Защита информации. Уязвимости информационных систем. Классификация уязвимостей информационных систем. М.: Стандартинформ, 2018.</mixed-citation><mixed-citation xml:lang="en">GOST R 56546-2015 Natsional'nyi standart rossiiskoi federatsii. Zashchita informatsii. Uyazvimosti informatsionnykh sistem. Klassifikatsiya uyazvimostei informatsionnykh system [National Standard of the Russian Federation. Data protection. Vulnerabilities of information systems. Classification of vulnerabilities of information systems]. Moscow, Standartinform, 2018.</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Горбачев И. Е., Глухов А. П. Моделирование процессов нарушения информационной безопасности критической инфраструктуры // Труды СПИИРАН. 2015. Вып. 1 (38). С. 112–135.</mixed-citation><mixed-citation xml:lang="en">Gorbachev I. E., Glukhov A. P. Modelirovanie protsessov narusheniya informatsionnoi bezopasnosti kriticheskoi infrastruktury [Modeling the processes of violation of information security of critical infrastructure]. Trudy SPIIRAN, Moscow, 2015, iss. 1(38), pp. 112 – 135.</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Котенко И. В. Многоагентные технологии анализа уязвимостей и обнаружения вторжений в компьютерных сетях // Новости искусственного интеллекта. 2004. № 1. С. 56–72.</mixed-citation><mixed-citation xml:lang="en">Kotenko I. V. Mnogoagentnye tekhnologii analiza uyazvimostei i obnaruzheniya vtorzhenii v komp'yuternykh setyakh [Multi-agent technologies for vulnerability analysis and intrusion detection in computer networks]. Novosti iskusstvennogo intellekta, 2004, no. 1, pp. 56–72.</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Щеглов А. Ю. Защита компьютерной информации от несанкционированного доступа. СПб.: Наука и Техника, 2004. 384 с.</mixed-citation><mixed-citation xml:lang="en">Shcheglov A.Yu. Zashchita komp'yuternoi informatsii ot nesanktsionirovannogo dostupa [Protection of computer information from unauthorized access]. Saint Petersburg, Science and Technology, 2004, 384 p.</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Галатенко В. А. Управление рисками: обзор употребительных подходов (часть 2) // Jet Info. 2018. № 12.</mixed-citation><mixed-citation xml:lang="en">Galatenko V.A. Upravlenie riskami: obzor upotrebitel'nykh podkhodov (chast' 2) [Risk management: a review of common approaches (part 2)]. Jet Info, no. 12, 2018, available at: https://www.jetinfo.ru/upravlenie-riskami-obzor-upotrebitelnykh-podkhodov-chast-2/ (accessed: 29.01.2022).</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Астахов А. Введение в аудит информационной безопасности // GlobalTrust Solutions [Электронный ресурс]. 2018. URL: http://globaltrust.ru (дата обращения: 29.01.2018).</mixed-citation><mixed-citation xml:lang="en">Astakhov A. Vvedenie v audit informatsionnoi bezopasnosti [Introduction to information security audit [Report]], GlobalTrust Solutions, 2018, available at: http://globaltrust.ru (accessed: 29.01.2018).</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Аверченков В. И., Рытов М. Ю., Гайнулин Т. Р Оптимизация выбора состава средств инженерно-технической защиты информации на основе модели Клементса–Хоффмана // Вестник Брянского государственного технического университета. 2008. № 1 (17).</mixed-citation><mixed-citation xml:lang="en">Averchenkov V.I., Rytov M.Yu., Gainulin T.R Optimizatsiya vybora sostava sredstv inzhenerno-tekhnicheskoi zashchity informatsii na osnove modeli Klementsa–Khoffmana [Optimization of the choice of the composition of the means of engineering and technical protection of information based on the Clements–Hoffman model]. Vestnik Bryanskogo gosudarstvennogo tekhnicheskogo universiteta, Bryansk, 2008, no. 1(17).</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Марковские процессы в дискретном времени: [сайт]. URL: https://proproprogs.ru/dsp/markovskie-processy-v-diskretnom-vremeni.</mixed-citation><mixed-citation xml:lang="en">Markovskie protsessy v diskretnom vremeni [Markov processes in discrete time], available at: https://proproprogs.ru/dsp/markovskie-processy-v-diskretnom-vremeni (accessed: 29.01.2022).</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
