METHOD OF CLASSIFICATION OF PSEUDO-RANDOM SEQUENCES OF COMPRESSED AND ENCRYPTED DATA TO PREVENT INFORMATION LEAKAGE
DOI:
https://doi.org/10.17721/2519-481X/2024/82-09Keywords:
pseudorandom sequences, functional model, information security, classification accuracy, encrypted, compressed dataAbstract
The considered task of developing a method for classifying pseudo-random sequences of protection against the leakage of confidential information based on the division of compressed and encrypted data can be used to detect network attacks on data transmission networks, in means of prevention and detection of information leakage, as well as in software products that implement services of electronic mail.
It is shown that data security threats are characterized by a set of qualitative and quantitative vector indicators, and their formalization requires the application of fuzzy set theory and discrete mathematics. It is shown that it is impossible to use expert traditional assessment methods to determine most of the considered indicators. To minimize the risk of leakage of confidential information, it is suggested to form groups of employees and calculate the risk of leakage of confidential data for each of them.
Modern means of preventing and detecting information leaks use various methods of data flow analysis. The main ones include contextual and content methods. The above methods are not able to detect a data leak in compressed and encrypted form, and the addition of digital signatures allows you to mask encrypted data as compressed in a simple way, in the field of information security, behavioral methods of data flow analysis and machine learning algorithms have found wide use. One of the main difficulties in this situation is the construction of data models, processing and search of the feature space.
The proposed method of classifying pseudo-random sequences takes into account the discriminating ability of statistical features, it can be implemented into existing means of preventing and detecting information leaks in order to eliminate the mentioned shortcomings. An encrypted data stream can be transmitted from employee workstations, various information systems, and network storage.
To evaluate the effectiveness of the proposed method of protection against leakage of confidential data, experiments were conducted to determine the accuracy of binary classification of compressed and encrypted data depending on the types of input sequences subjected to compression procedures.
In the course of practical implementation, a quantitative assessment of the classification accuracy of pseudorandom sequences was carried out depending on the parameters of the proposed classifier. The choice of the subsequence length of nine bits is justified as the most rational value, which allows to achieve classification of pseudo-random sequences with high accuracy and minimal time for the classification procedure. The choice of the optimal scanning window of the classifier with a size of 500 kb is justified. Depending on the requirements for accuracy and speed of data analysis, two modes of operation are proposed: scanning of a randomly selected fragment of a file with a size of 500 kb; scanning the entire file with a 500 KB scanning window.
A description of the places of implementation of the proposed method of classifying pseudo-random sequences into e-mail protection subsystems, network attack detection systems, means of preventing and detecting information leaks is given. A comparative evaluation of the proposed algorithm with known analogues in the subject area of research was carried out.
References
1. Doktryna informatsiinoi bezpeky Ukrainy, zatverdzhenoi Ukazom Prezydenta Ukrainy vid 25 liutoho 2017 roku № №47/2017, 15s.
2. Derzhavnyi standart Ukrainy Zakhyst informatsii. Tekhnichnyi zakhyst informatsii. Osnovni polozhennia. DSTU 3396.0-96 [Elektronnyi resurs]. – Rezhym dostupu: http://www.dsszzi.gov.ua/dsszzi/control/uk/publish/article?art_id=38883&cat_id =38836
3. Bem, M. V. (2018) Standarty zakhystu personalnykh danykh v sotsialnii sferi. / M. V.Bem, I. M. Horodyskyi -Lviv - 110 s.
4. Bohush,V.M. (2015). Informatsiina bezpeka derzhavy/V.M.Bohush,O.K.Yudin.– MK-Pres, – 432 s.
5. Holubiev, O.V. (2018) Prohramno-tekhnichni zasoby zakhystu danykh vid kompiuternykh zlochyniv / O. V. Hoshubiev– Zaporizhzhia : «Pavel» – 145 s.
6. Horbulin, P.V. (2019) Problemy zakhystu informatsiinoho prostoru Ukrainy / M.M. Bachenok, P.V. Horbulin – K.: Intertekhnolohiia – 138 s.
7. Lenkov, S.V.(2024), Funktsionalna model klasyfikatsii psevdovypadkovykh poslidovnostei zashyfrovanykh ta styslykh danykh zapobihanniu vytoku konfidentsiinoi informatsii / S.V. Lienkov, V.M. Dzhulii, I.V. Muliar, I.V. Pampukha // Zbirnyk naukovykh prats Viiskovoho instytutu Kyivskoho natsionalnoho universytetu imeni Tarasa Shevchenka. – K.: VIKNU, 2024. – Vyp. №80. – C. 85-97.
8. Lenkov, S.V.(2023), Metod prohnozuvannia vrazlyvostei informatsiinoi bezpeky na osnovi analizu danykh tematychnykh internet-resursiv / S.V. Lienkov, V.M. Dzhulii, A.M. Bernaz, I.V. Muliar, I.V. Pampukha // Zbirnyk naukovykh prats Viiskovoho instytutu Kyivskoho natsionalnoho universytetu imeni Tarasa Shevchenka. – K.: VIKNU -. №78. – C. 123-134.
9. Lenkov, S.V.(2022) Metod protydii poshyrenniu ta vyiavlennia shkidlyvoi informatsii v sotsialnykh merezhakh/ S.V. Lenkov, V.M. Dzhulii, L.V. Solodieieva // Zbirnyk naukovykh prats Viiskovoho instytutu Kyivskoho natsionalnoho universytetu imeni Tarasa Shevchenka. – K.: VIKNU. – Vyp. №77. – C. 103-117.
10. Lenkov, S.V. (2020), Model bezpeky poshyrennia zaboronenoi informatsii v informatsiino-telekomunikatsiinykh merezhakh / S.V. Lenkov, V.M. Dzhulii, V.S. ORLENKO, O.V. Sieliukov, A.V. Atamaniuk // Zbirnyk naukovykh prats Viiskovoho instytutu Kyivskoho natsionalnoho universytetu imeni Tarasa Shevchenka. – K.: VIKNU. – №68. – pp. 53-64.
11.Dzhulii, V.M. (2023) Alhorytmy prohnozuvannia vrazlyvostei ta zahroz informatsiinoi bezpeky naosnovi tematychnykh internet-resursiv/ Maior Ye., Dzhulii V., Cheshun V., Petliak N. Mizhnarodnyi naukovo-tekhnichnyi zhurnal «Vymiriuvalna ta obchysliuvalna tekhnika v tekhnolohichnykh protsesakh». Vypusk 4. S.49-56.
12.Lienkov, S.V. (2023) Informatsiino-analitychna systemy prohnozuvannia vrazlyvostei ta zahrozinformatsiinoi bezpeky/ S.V. Lienkov, V.M. Dzhulii, O.V. Miroshnichenko, V.O. Braun, S.I. Prokhorskyi // Zbirnyk naukovykh prats Viiskovoho instytutu Kyivskoho natsionalnoho universytetu imeni Tarasa Shevchenka. – Kyiv: VIKNU, 2023. – Vyp. № 79. – C. 114-127
13.Yemelianov, S.L. (2019) Osnovy informatsiinoi bezpeky./S.L.Yemelianov– Odesa: Feniks – 357s.
14.Kudinov, V.A. (2016) Osnovy protydii kiberzlochynnosti. / V. M. Smahliuk, V. H. Khakhanovskyi,V.A. Kudinov. – K. : NAVS – 104 s.
15.Lukianov, B. V. (2017) Kompiuternyi analiz danykh / B. V. Lukianov – K. : Akademiia – 345 s.
16.Cotsialni merezhi – realni zahrozy virtualnoho svitu. [Elektronnyi resurs]. – Rezhym dostupu :http://ogo.ua/ articles/view/011– 02–23/26490.htm
17.Ostapov, S. E. (2016) Tekhnolohii zakhystu informatsii: navchalnyi posibnyk / S.E. Ostapov, S.P.Yevseiev, O.H. Korol–Kharkiv : Vyd-vo KhNEU. – 476 s.
18.Lenkov, S.V. (2017), AnalIz Isnuyuchih metodiv ta algoritmiv viyavlennya atak v bezdrotovihmerezhah peredachI danih / S.V. Lenkov, V.M. Dzhuliy, N.M. Bernaz, S.O. Bozhuk // Zbirnik naukovih prats Viyskovogo Institutu Kiyivskogo natsionalnogo universitetu imeni Tarasa Shevchenka. – K.: VIKNU. – Vip. No 56. – p.124-132
19.Buriachok, V. L. (2016) Informatsiinyi ta kiberprostory: problemy bezpeky, metody ta zasobyborotby : posibnyk / V. L. Buriachok, S. V. Toliupa, V. V. Semko – K. : DUT-KNU – 178 s.
20.Rybalchenko, L.V., Kosychenko, O.O. (2019) Problemy bezpeky personalnykh danykh v Ukraini /Rehionalna ekonomika / Zaporizhzhia – s.57-62
21.Dzhulii, V.M. (2022), Metod klasyfikatsii dodatkiv trafika kompiuternykh merezh na osnovimashynnoho navchannia v umovakh nevyznachenosti / V.M. Dzhulii, O.V. Miroshnichenko, L.V. Solodieieva // Zbirnyk naukovykh prats Viiskovoho instytutu Kyivskoho natsionalnoho universytetu imeni Tarasa Shevchenka. – K.: VIKNU. – Vyp. №74. – pp. 73-82.
22.Lavrov, Ye. A. (2017.), Matematychni metody doslidzhennia operatsii : pidruchnyk / Ye. A. Lavrov,L.P. Perkhun, V. V. Shendryk – Sumy : Sumskyi derzhavnyi universytet – 212 p
23.Honchar, S. F. (2019) Otsiniuvannia ryzykiv kiberbezpeky informatsiinykh system obiektivkrytychnoi infrastruktury : monohrafiia. / S. F. Honchar. – Kyiv – 175 s.
24.Flakh, P. Mashynne navchannia. Nauka ta mystetstvo pobudovy alhorytmiv, yaki vyluchaiut znanniaz danykh / P. Flakh. — Litres, 2019r.-534s.
25.Khoroshko, V.O. Zakhyst system elektronnykh komunikatsii: navch. posib. / V.O. Khoroshko, O.V.Kryvoruchko, M.M. Brailovskyi - Kyiv., 2019r. 164 s.
26.Yemchuk L. Organizational Network Analysis as a Tool for Leadership Assessment in SoftwareDevelopment Team. Zhylinska O.; Chornyi A.; Dzhuliy V. – Institute of Electrical and Electronics Engineers (30 September 2020); INSPEC Accession Number: 20008165; DOI: 10.1109/ACIT49673.2020.
27.Syhnatura ataky. Wikipedia [Elektronnyi resurs] – Rezhym dostupu do resursu:https://uk.wikipedia.org/wiki/Syhnatura_ataky.
28.OPWNAI: Cybercriminals Starting to Use ChatGPT, January 6, 2023 [Elektronnyi resurs] – Rezhymdostupu do resursu: https://research.checkpoint.com/2023/opwnai-cybercriminals-starting-to-usechatgpt.






