{"title":"Improving the Methods for Protecting Information from Unauthorized Access","authors":"A. Rodionov, V. Belyanin, A. Gorbunov","doi":"10.15688/NBIT.JVOLSU.2018.2.6","DOIUrl":null,"url":null,"abstract":"The research relevance is conditioned by the constantly growing technical capabilities for unauthorized access to protected information in the local area networks (LAN), the development of methods of attacks, and therefore, the need to improve methods of information protection. The paper describes the peculiarities of using the system of collecting and correlating information security events SIEM (Security Information and Event Management), which detects and notifies about the emergence of threats to leakage of protected information. In the modern world, due to the ever-growing technical capabilities of attackers for unauthorized access to LAN, improving the ways of carrying out attacks on them, there is a need to improve the existing methods of information protection and to develop new ones. In addition to the technical component, an important risk factor is the human factor, due to which up to 52 % of information leaks (intentional and unintended) occur around the world. They are distributed by categories of information: 62.3 % – personal data, 31.0 % – payment documents, 3.9 % – state secrets, 2.8 % – trade secrets.","PeriodicalId":205855,"journal":{"name":"NBI Technologies","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"NBI Technologies","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.15688/NBIT.JVOLSU.2018.2.6","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
The research relevance is conditioned by the constantly growing technical capabilities for unauthorized access to protected information in the local area networks (LAN), the development of methods of attacks, and therefore, the need to improve methods of information protection. The paper describes the peculiarities of using the system of collecting and correlating information security events SIEM (Security Information and Event Management), which detects and notifies about the emergence of threats to leakage of protected information. In the modern world, due to the ever-growing technical capabilities of attackers for unauthorized access to LAN, improving the ways of carrying out attacks on them, there is a need to improve the existing methods of information protection and to develop new ones. In addition to the technical component, an important risk factor is the human factor, due to which up to 52 % of information leaks (intentional and unintended) occur around the world. They are distributed by categories of information: 62.3 % – personal data, 31.0 % – payment documents, 3.9 % – state secrets, 2.8 % – trade secrets.
对局域网(LAN)中受保护信息的未经授权访问的技术能力不断增长,攻击方法的发展,因此需要改进信息保护方法,这是研究相关性的条件。介绍了信息安全事件收集和关联系统SIEM (security information and Event Management)的特点,该系统能够检测和通知受保护信息泄露威胁的出现。在现代世界,由于攻击者对局域网的未经授权访问的技术能力不断增强,对其进行攻击的方式不断改进,需要改进现有的信息保护方法并开发新的信息保护方法。除了技术因素外,一个重要的风险因素是人为因素,全球多达52%的信息泄露(有意和无意)都是由人为因素造成的。它们按信息类别分布:62.3%是个人数据,31.0%是支付文件,3.9%是国家机密,2.8%是商业秘密。