The 26th International Scientific and Practical Seminar Combinatorial Configurations and Their Applications, was held from June 13 to 15, 2024, in Kropyvnytskyi, Zaporizhzhia and Kyiv, Ukraine.
During the event, the TELEMETRY publication Assessment of the Vulnerability of the Information System Based on Fuzzy Mathematics was presented. The paper was authored by Vasyl Lytvyn, Anna Bakurova, Oleh Zaritskyi, Anatoliy Gritskevich, Pavlo Hrynchenko, Elina Tereschenko and Dmytro Shyrokorad.
Abstract
A fuzzy-mathematics approach for assessing the vulnerability of information systems has been proposed. This approach is based on systems analysis, viewing the information system as an interaction between subjects and objects governed by access control policies. The key elements are Assessing the vulnerability of objects, Monitoring anomalies, Evaluating risk levels, and Adjusting access policies. This approach allows for dynamic responses to changes in the system and adaptation of security policies, thereby enhancing the overall level of protection. The methodology entails the deployment of advanced tools and software, including Intrusion Detection Systems (IDS), fuzzy testing, User and Entity Behavior Analytics (UEBA), User Activity Monitoring (UAM), Software Bill of Materials (SBOM), and machine learning techniques. Integral to the methodology are relevant libraries and databases such as the CIS Benchmark, Common Vulnerabilities and Exposures (CVEs), Common Platform Enumeration (CPE) Dictionary, and Common Vulnerability Scoring System (CVSS). These components ensure the standardization and integration of the methodology with other approaches and methods for the control and monitoring of information systems. In this article, the example of calculation of vulnerability estimation for model Object-Subject was considered.
Read the full publication here.
