SIMULATION MODEL OF THE GENERATION AND IMPLEMENTATION OF THE MEANS OF «PENETRATION TESTING»
Journal Title: Телекомунікаційні та інформаційні технології - Year 2018, Vol 123, Issue 2
Abstract
During simulation of the process generation of cyberattacks of various formats was performed using the specialized IxChariot 9 package and software developed during the research. The collection of incoming information about the download of the network device was carried out using the standard software traffic analyzer ("Wireshark"). As a result of the simulation, the hypothesis has been tested for the possibility of using the Pearson Xi-square criterion and studies of the reliability of the results of mathematical formalization have been carried out. It is shown that the use of only the principles of secure architectures in the development of secure software is not enough. Must use templates. The main templates of safe programs are considered in which the developed complex of mathematical models of technologies of generation and realization of "penetration test" methods and the method of allocation of the algorithm from binary code for software security analysis can be used. Two main variants of use and improvement of the developed model are considered. The first option has a single centralized security element, which becomes the middle of the queries for all resources in the system. The second option shares the security element's responsibilities, so that there is a separate instance of the security element for each individual resource type. The security of software in the modern world is becoming more and more difficult and difficult, since the value of information resources is constantly increasing. Ensuring the quality of software is a complex matter. The changing one of the characteristics of a computer system or software can easily lead to changes or create a need for change in other parts of the system. Practical recommendations on the use of methods and tools for testing software security of the temporary computer system are given.
Authors and Affiliations
Serhiy Kozelkov, Dmytro Lysytsia, Serhii Semenov, Alina Lysytsia
A method for synthesizing a quality function to optimize data about process and product parameters when implementing a «Quality by Design» strategy
The subject of the article is the area (space) of product quality development – Design Space (QbDstrategy), when a certain combination of several process parameters affecting the desired property (quality) of the product...
ANALYSIS OF INTERACTION OF RISK DAMAGE IN THE CASE OF TECHNOGENIC ACCIDENTS IN THE CONCEPT OF ACCEPTABLE RISK
The methods of estimating the damage from the occurrence of an industrial accident considered. For the quantitative description of the consequences of an accident, the notion of damage is used, which is considered as an...
INTERFERENCE MODELING OF MILLIMETER-WAVE CELLULAR COMMUNICATIONS SYSTEMS
To implement the bandwidth requirements for mobile communication systems of the fifth generation, it is assumed to use the millimeter wavelength range. However, the use of this range is significantly different from the l...
Modern approach to the glimmer discharge elementary processes mechanism of radio-techical devices functional elements
It was shown an innovative approach to the glimmer discharge elementary processes mechanism aimed to improve the functioning of the devices in radio engineering and telecommunication systems. A row of contradictions in t...
Modern mechanisms of cloud technologies construction as a priority to improve distributed data processing system
The modern mechanisms of development of cloud technologies as a priority direction of improvement of distributed data processing systems are considered. There are three main types of cloud computing. The advantages and d...