<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">sibsutis</journal-id><journal-title-group><journal-title xml:lang="ru">Вестник СибГУТИ</journal-title><trans-title-group xml:lang="en"><trans-title>The Herald of the Siberian State University of Telecommunications and Information Science</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">1998-6920</issn><publisher><publisher-name>СибГУТИ</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.55648/1998-6920-2023-17-4-49-61</article-id><article-id custom-type="elpub" pub-id-type="custom">sibsutis-820</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>Статьи</subject></subj-group></article-categories><title-group><article-title>Формирование вектора сетевых атак  с учетом специфики связей техник и тактик</article-title><trans-title-group xml:lang="en"><trans-title>Formation of the network attack vector taking into account the connections specifics of techniques and tactics</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-3189-9085</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Ветров</surname><given-names>И. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Vetrov</surname><given-names>I. A.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Ветров Игорь Анатольевич, кандидат технических наук, доцент, ОНК «Институт высоких технологий»</p><p>236041, Калининград, ул. Александра Невского, 14</p></bio><bio xml:lang="en"><p>Vetrov Igor A., Cand. of Sci. (Engineering), Associate Professor, Institute of High Technologies</p><p>236041, Kaliningrad, Alexander Nevsky Str., 14</p></bio><email xlink:type="simple">vetrov.gosha2009@yandex.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-7618-3224</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Подтопельный</surname><given-names>В. В.</given-names></name><name name-style="western" xml:lang="en"><surname>Podtopelny</surname><given-names>V. V.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Подтопельный Владислав Владимирович, старший преподаватель, Институт цифровых технологий </p><p>236022, Калининград, Советский пр., 1</p></bio><bio xml:lang="en"><p>Podtopelny Vladislav V., Senior lecturer, Institute of Digital Technologies </p><p>236022, Kaliningrad, Sovetsky ave., 1</p></bio><email xlink:type="simple">ionpvv@mail.ru</email><xref ref-type="aff" rid="aff-2"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Балтийский федеральный университет им. И. Канта</institution></aff><aff xml:lang="en"><institution>Immanuel Kant Baltic Federal University (IKBFU)</institution></aff></aff-alternatives><aff-alternatives id="aff-2"><aff xml:lang="ru"><institution>Калиниградский государственный технический университет</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Kaliningrad State Technical University (KSTU)</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2023</year></pub-date><pub-date pub-type="epub"><day>23</day><month>07</month><year>2023</year></pub-date><volume>17</volume><issue>4</issue><fpage>49</fpage><lpage>61</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Ветров И.А., Подтопельный В.В., 2023</copyright-statement><copyright-year>2023</copyright-year><copyright-holder xml:lang="ru">Ветров И.А., Подтопельный В.В.</copyright-holder><copyright-holder xml:lang="en">Vetrov I.A., Podtopelny V.V.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://vestnik.sibsutis.ru/jour/article/view/820">https://vestnik.sibsutis.ru/jour/article/view/820</self-uri><abstract><p>Рассмотрены проблемы, возникающие при решении задачи построения вектора атаки в сетевой инфраструктуре. Приведены и охарактеризованы разновидности различных тактик и техник методик ФСТЭК, применяемых при построении вектора сетевой атаки, а также рассмотрена специфика их взаимосвязей с использованием марковских цепей при моделировании атакующих воздействий, рассмотрена их пригодность для различных процедур определения параметров вектора. При построении вектора сетевой атаки приводятся особенности определения вероятностей переходов системы в различные состояния компрометации сети. Формирование вектора атаки изучается в контексте эксплуатации многоуровневой корпоративной информационной системы. Определяются особенности построения упрощенного вектора атаки с учетом специфики связей тактик (состояний).</p></abstract><trans-abstract xml:lang="en"><p>The problems arising with the tasks of constructing an attack vector in a network infrastructure are considered. The varieties of various tactics and techniques of FSTEC techniques used in the construction of a network attack vector are presented and characterized as well as the specifics of their interrelations with the use of Markov chains in the modeling of attacking influences, their suitability for various procedures for determining vector parameters. When constructing a network attack vector, the features of determining the probabilities of system transitions to various states of network compromise are considered. The formation of the attack vector is studied taking into account the specifics of the multilevel organization of the corporate information system. The features of the construction of a simplified vector are determined taking into account the specifics of tactical relationships (states).</p></trans-abstract><kwd-group xml:lang="ru"><kwd>вектор атаки</kwd><kwd>информационная система</kwd><kwd>корпоративная сеть</kwd><kwd>уязвимость</kwd><kwd>марковские процессы</kwd><kwd>злоумышленник</kwd><kwd>тактики</kwd></kwd-group><kwd-group xml:lang="en"><kwd>attack vector</kwd><kwd>information system</kwd><kwd>corporate network</kwd><kwd>vulnerability</kwd><kwd>Markov processes</kwd><kwd>intruder</kwd><kwd>tactics</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Методика оценки угроз безопасности информации Методический документ ФСТЭК России: утв. ФСТЭК России 5 февраля 2021 г.</mixed-citation><mixed-citation xml:lang="en">Metodika otsenki ugroz bezopasnosti informatsii Metodicheskii dokument FSTEK Rossii: utv. FSTEK Rossii 5 fevralya 2021. [Methodology for assessing threats to information security Methodological document of the FSTEC of Russia]. Moscow, 2021.</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">ГОСТ Р 56546-2015 Национальный стандарт российской федерации. Защита информации. Уязвимости информационных систем. Классификация уязвимостей информационных систем. М.: Стандартинформ, 2018 г.</mixed-citation><mixed-citation xml:lang="en">GOST R 56546-2015 Natsional'nyi standart rossiiskoi federatsii. Zashchita informatsii. Uyazvimosti informatsionnykh sistem. Klassifikatsiya uyazvimostei informatsionnykh system [National Standard of the Russian Federation. Data protection. Vulnerabilities of information systems. Classification of vulnerabilities of information systems]. Moscow, Standartinform, 2018.</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Горбачев И. Е., Глухов А. П. Моделирование процессов нарушения информационной безопасности критической инфраструктуры// Труды СПИИРАН. 2015. Вып. 1 (38). С. 112–135.</mixed-citation><mixed-citation xml:lang="en">Gorbachev I. E., Glukhov A. P. Modelirovanie protsessov narusheniya informatsionnoi bezopasnosti kriticheskoi infrastruktury [Modeling the processes of violation of information security of critical infrastructure]. Trudy SPIIRAN, Moscow, 2015, iss. 1(38), pp. 112 – 135.</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Котенко И. В., Саенко И. Б., Лаута О. С., Крибель А. М. Метод раннего обнаружения кибератак на основе интеграции фрактального анализа и статистических методов // Первая миля. 2021. № 6. С. 64–71.</mixed-citation><mixed-citation xml:lang="en">Kotenko I. V., Saenko I. B., Lauta O. S., Kribel' A. M. Metod rannego obnaruzheniya kiberatak na osnove integracii fraktal'nogo analiza i statisticheskih metodov [Method for early detection of cyber-attacks based on the integration of fractal analysis and statistical methods]. Pervaya milya, 2021, no. 6, pp. 64-71.</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Добрышин М. М. Модель разнородных компьютерных атак, проводимых одновременно на узел компьютерной сети связи // Телекоммуникации. 2019. № 12. С. 31–35.</mixed-citation><mixed-citation xml:lang="en">Dobryshin M. M. Model' raznorodnyh komp'yuternyh atak, provodimyh odnovremenno na uzel komp'yuternoj seti svyazi [Model of heterogeneous computer attacks carried out simultaneously on a computer communication network node]. Telekommunikacii, 2019, no. 12, pp. 31-35.</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Канаев А. К., Опарин Е. В., Опарина Е. В. Обобщенная модель действий злоумышленника при манипулировании сообщениями, содержащими сигналы точного времени // T-Comm. 2022. Т. 16, № 6.</mixed-citation><mixed-citation xml:lang="en">Kanaev A. K., Oparin E. V., Oparina E. V. Obobshchennaya model' dejstvij zloumyshlennika pri manipulirovanii soobshcheniyami, soderzhashchimi signaly tochnogo vremeni [A generalized model of an attacker’s actions when manipulating messages containing precise time signals]. T-Comm, vol.16, no. 6, 2022.</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Петров М. Ю., Фаткиева Р. Р. Модель синтеза распределенных атакующих элементов в компьютерной сети // Труды учебных заведений связи. 2020. Т. 6, № 2. С. 113–120. DOI:10.31854/1813-324X-2020-6-2-113-120.</mixed-citation><mixed-citation xml:lang="en">Petrov M. YU., Fatkieva R. R. Model' sinteza raspredelennyh atakuyushchih elementov v komp'yuternoj seti [Model for the synthesis of distributed attack elements in a computer network]. Trudy uchebnyh zavedenij svyazi. 2020, vol. 6, no. 2, pp. 113-120. DOI:10.31854/1813-324X-2020-6-2-113-120.</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Щеглов А. Ю. Защита компьютерной информации от несанкционированного доступа. СПб.: Наука и Техника, 2004. 384 с.</mixed-citation><mixed-citation xml:lang="en">Shcheglov A. YU. Zashchita komp'yuternoj informacii ot nesankcionirovannogo dostupa [Protecting computer information from unauthorized access]. Saint Petersburg, Nauka i Tekhnika, 2004. 384 p.</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Галатенко В. А. Управление рисками: обзор употребительных подходов (часть 2) // Jet Info. 2018. № 12.</mixed-citation><mixed-citation xml:lang="en">Galatenko V. A. Upravlenie riskami: obzor upotrebitel'nykh podkhodov (chast' 2) [Risk management: a review of common approaches (part 2)]. Jet Info, no. 12, 2018, available at: https://www.jetinfo.ru/upravlenie-riskami-obzor-upotrebitelnykhpodkhodovchast-2/ (accessed: 29.01.2022).</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Canadian Institute for Cybersecurity: NSL-KDD dataset [Электронный ресурс]. URL: https://www.unb.ca/cic/datasets/nsl.html (дата обращения: 17.05.2020).</mixed-citation><mixed-citation xml:lang="en">Canadian Institute for Cybersecurity: NSL-KDD dataset, 2009. available at: https://www.unb.ca/cic/datasets/nsl.html (accessed: 17.05.2020).</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
