<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">vdgtu</journal-id><journal-title-group><journal-title xml:lang="ru">Вестник Дагестанского государственного технического университета. Технические науки</journal-title><trans-title-group xml:lang="en"><trans-title>Herald of Dagestan State Technical University. Technical Sciences</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">2073-6185</issn><issn pub-type="epub">2542-095X</issn><publisher><publisher-name>Daghestan State Technical University</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.21822/2073-6185-2024-51-2-128-136</article-id><article-id custom-type="elpub" pub-id-type="custom">vdgtu-1528</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>ИНФОРМАЦИОННЫЕ ТЕХНОЛОГИИ И ТЕЛЕКОММУНИКАЦИИ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>INFORMATION TECHNOLOGY AND TELECOMMUNICATIONS</subject></subj-group></article-categories><title-group><article-title>Алгоритм функционирования программного комплекса анализа и оценки защищенности программного обеспечения автоматизированных систем органов внутренних дел</article-title><trans-title-group xml:lang="en"><trans-title>Algorithm for the functioning of the analysis and evaluation software package security of software of automated systems internal affairs bodies</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Попова</surname><given-names>А. Д.</given-names></name><name name-style="western" xml:lang="en"><surname>Popova</surname><given-names>A. D.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Попова Арина Дмитриевна, адъюнкт кафедры автоматизированных информационных систем органов внутренних дел</p><p>394065, г. Воронеж, пр. Патриотов, 53</p></bio><bio xml:lang="en"><p>Arina D. Popova, Adjunct, Department of Automated Information Systems of Internal Affairs Bodies</p><p>53 Patriotov Ave., Voronezh 394065</p></bio><email xlink:type="simple">arnpva@mail.ru</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Воронежский институт МВД России</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Voronezh Institute of the Ministry of Internal Affairs of Russia</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2024</year></pub-date><pub-date pub-type="epub"><day>25</day><month>07</month><year>2024</year></pub-date><volume>51</volume><issue>2</issue><fpage>128</fpage><lpage>136</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Попова А.Д., 2024</copyright-statement><copyright-year>2024</copyright-year><copyright-holder xml:lang="ru">Попова А.Д.</copyright-holder><copyright-holder xml:lang="en">Popova A.D.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://vestnik.dgtu.ru/jour/article/view/1528">https://vestnik.dgtu.ru/jour/article/view/1528</self-uri><abstract><p>Цель. Целью исследования является построение алгоритма функционирования программного комплекса, автоматизирующего процесс анализа и оценки защищенности используемого программного обеспечения и осуществляющего выбор его наиболее защищенной версии для эксплуатации на объектах информатизации органов внутренних дел.Метод. В ходе исследования использованы: метод системного подхода к определению показателей защищенности программного обеспечения, метод математической формализации и алгоритмизации процесса анализа и оценки защищенности программного обеспечения для разработки программного кода.Результат. Предложен алгоритм функционирования программного комплекса, позволяющий осуществлять анализ и количественную оценку защищенности программного обеспечения автоматизированных систем органов внутренних дел в отношении текущих уязвимостей в режиме реального времени. Алгоритм носит комплексный характер, включая в себя пять составляющих алгоритмов. Описана работа основных блоков алгоритма.Вывод. Практическая значимость реализации разработанного алгоритма в виде программного комплекса состоит в возможности выбора оптимальной (наиболее защищенной) версии программного обеспечения для эксплуатации на объектах информатизации органов внутренних дел с целью повышения реальной защищенности служебной информации ограниченного распространения.</p></abstract><trans-abstract xml:lang="en"><p>Objective. The purpose of the study is to construct an algorithm for the functioning of a software package that automates the process of analyzing and assessing the security of the software used and selecting its most secure version for use at informatization facilities of internal affairs bodies.Method. During the study, we used: a method of a systematic approach to determining software security indicators, a method of mathematical formalization and algorithmization of the process of analyzing and assessing software security for developing program code.Result. An algorithm for the functioning of a software complex is proposed that allows for analysis and quantitative assessment of the security of software of automated systems of internal affairs bodies in relation to current vulnerabilities in real time. The algorithm is complex in nature, including five component algorithms. The operation of the main blocks of the algorithm is described.Conclusion. Conclusions are drawn about the importance of the practical implementation of the developed algorithm in the form of a software package that selects the optimal (most secure) version of software for operation at informatization facilities of internal affairs bodies in order to increase the actual security of limited-distribution official information.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>автоматизированная система</kwd><kwd>программное обеспечение</kwd><kwd>защищенность программного обеспечения</kwd><kwd>анализ и количественная оценка уровня защищенности</kwd><kwd>алгоритм</kwd><kwd>программный комплекс</kwd></kwd-group><kwd-group xml:lang="en"><kwd>automated system</kwd><kwd>software</kwd><kwd>software security</kwd><kwd>analysis and quantitative assessment of security level</kwd><kwd>algorithm</kwd><kwd>software package</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Вопросы организации информационно-правового обеспечения деятельности органов внутренних дел Российской Федерации: приказ МВД России от 25 августа 2017 г. № 680 (в ред. приказа МВД России от 23.03.2018 № 155) [Электронный ресурс]. – Режим доступа: https://base.garant.ru/72617376/?ysclid=lmduxlmjdz739176488 (дата обращения: 10.04.2024).</mixed-citation><mixed-citation xml:lang="en">Issues of organizing information and legal support for the activities of internal affairs bodies of the Russian Federation: order of the Ministry of Internal Affairs of Russia dated August 25 2017 No. 680 (as amended by order of the Ministry of Internal Affairs of Russia dated March 23, 2018 No. 155) [Electronic resource]. – Access mode: https://base.garant.ru/72617376/?ysclid=lmduxlmjdz739176488 (date of access: 04/10/2024). ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Об утверждении Доктрины информационной безопасности Российской Федерации : указ Президента Российской Федерации от 5 декабря 2016 г. № 646 // Собрание законодательства Российской Федерации от 2016 г. – № 50. – С. 7074 – 12 с.</mixed-citation><mixed-citation xml:lang="en">On approval of the Information Security Doctrine of the Russian Federation: Decree of the President of the Russian Federation dated December 5, 2016 No. 646 // Collection of Legislation of the Russian Federation of 2016 - No. 50. Art. 7074; 50:12. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">ГОСТ Р ИСО/МЭК 9126-93. Информационная технология. Оценка программной продукции. Характеристики качества и руководства по их применению [Электронный ресурс]. – Режим доступа: http://docs.cntd.ru/document/gost-r-iso-mek-9126-93 (дата обращения: 15.04.2024).</mixed-citation><mixed-citation xml:lang="en">GOST R ISO/IEC 9126-93. Information technology. Evaluation of software products. Quality characteristics and guidelines for their use [Electronic resource]. – Access mode: http://docs.cntd.ru/document/gost-riso-mek-9126-93 (access date: 04/15/2024). ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">ГОСТ Р 56939-2016. Защита информации. Разработка безопасного программного обеспечения. Общие требования. – Москва: Стандартинформ, 2016. – 24 с.</mixed-citation><mixed-citation xml:lang="en">GOST R 56939-2016. Data protection. Secure software development. General requirements. – Moscow: Standardinform, 2016;24. ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">ГОСТ Р ИСО/МЭК 25051-2017. Информационные технологии. Системная и программная инженерия. Требования и оценка качества систем и программного обеспечения. – Москва: Стандартинформ, 2017. – 32 с.</mixed-citation><mixed-citation xml:lang="en">GOST R ISO/IEC 25051-2017. Information Technology. System and software engineering. Requirements and quality assessment of systems and software. Moscow: Standardinform, 2017; 32. ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Щеглов К.А. Математические модели и методы формального проектирования систем защиты информационных систем: учебное пособие / К.А. Щеглов, А.Ю. Щеглов. – Санкт-Петербург: СПбГУ ИТМО, 2014. – 83 с.</mixed-citation><mixed-citation xml:lang="en">Shcheglov K.A. Mathematical models and methods of formal design of information systems protection systems: textbook. K.A. Shcheglov, A.Yu. Shcheglov. – St. Petersburg: St. Petersburg State University ITMO, 2014; 83. ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Щеглов А.Ю. Элементы теории эксплуатационной информационной безопасности: учебное пособие / А.Ю. Щеглов. – Санкт-Петербург: СПбГУ ИТМО, 2014. – 59 с.</mixed-citation><mixed-citation xml:lang="en">Shcheglov A.Yu. Elements of the theory of operational information security: textbook / A.Yu. Shcheglov. – St. Petersburg: St. Petersburg State University ITMO, 2014; 59. ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Ефимов А.О. Концептуальные основы оценки уровня защищенности автоматизированных систем на основе их уязвимости / А.О. Ефимов, И.И. Лившиц, Т.В. Мещерякова, Е.А. Рогозин // Безопасность информационных технологий = IT Security. – Том 30. – № 2(2023). – С. 63–79.</mixed-citation><mixed-citation xml:lang="en">Efimov A.O. Conceptual basis for assessing the level of security of automated systems based on their vulnerability / A.O. Efimov, I.I. Livshits,T.V. Meshcheryakova, E.A. Rogozin. Information technology security =IT Security. 2023; 30 (2): 63–79. ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Карты источников, содержащих сведения об уязвимостях программного обеспечения / А.Л. Сердечный [и др.]. Информация и безопасность. – 2019. – Т. 22. – № 3. – С. 411-422. – EDN ZOUMGN.</mixed-citation><mixed-citation xml:lang="en">Maps of sources containing information about software vulnerabilities A.L. Heart [and others]. Information and security. 2019; 22(3): 411-422. – EDN ZOUMGN. ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Дровникова И.Г. Способы оценки уровня защищенности программного обеспечения автоматизированных систем органов внутренних дел и направления их совершенствования / И.Г. Дровникова, А.Д. Попова // Вестник Дагестанского государственного технического университета. Технические науки. – 2023. – Т. 50. – № 4. – С. 85–92.</mixed-citation><mixed-citation xml:lang="en">Drovnikova I.G. Methods for assessing the level of security of software of automated systems of internal affairs bodies and directions for their improvement/ I.G. Drovnikova, A.D. Popova. Herald of the Dagestan State Technical University. Technical Sciences. 2023; 50( 4): 85–92. ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Дровникова И.Г. Показатели защищенности программного обеспечения, используемого на объектах информатизации органов внутренних дел / И.Г. Дровникова, А.Д. Попова // Вестник Воронежского института МВД России. – 2024. – № 1. – С. 50–59.</mixed-citation><mixed-citation xml:lang="en">Drovnikova I.G. Indicators of security of software used at informatization facilities of internal affairs bodies / I.G. Drovnikova, A.D. Popova. Herald of the Voronezh Institute of the Ministry of Internal Affairs of Russia. 2024;1: 50–59. ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Дровникова И.Г. Теоретические аспекты расчета показателей защищенности программного обеспечения автоматизированных систем органов внутренних дел / И.Г. Дровникова, А.Д. Попова // Вестник Воронежского института ФСИН России. – 2024. – № 2.</mixed-citation><mixed-citation xml:lang="en">Drovnikova I.G. Theoretical aspects of calculating security indicators of software of automated systems of internal affairs bodies /Drovnikova, A.D. Popova. Bulletin of the Voronezh Institute of the Federal Penitentiary Service of Russia. 2024; 2. ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">Дровникова И.Г. Аналитические модели расчета показателей защищенности программного обеспечения автоматизированных систем органов внутренних дел / И.Г. Дровникова, А.Д. Попова // Вестник Воронежского института МВД России. – 2024. – № 2 –22-33.</mixed-citation><mixed-citation xml:lang="en">Drovnikova I.G. Analytical models for calculating security indicators of software of automated systems of internal affairs bodies /Drovnikova, A.D. Popova // Bulletin of the Voronezh Institute of the Ministry of Internal Affairs of Russia. 2024; 2: 22-33. ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit14"><label>14</label><citation-alternatives><mixed-citation xml:lang="ru">Попова А.Д. Методика анализа и оценки уровня защищенности программного обеспечения, используемого на объектах информатизации органов внутренних дел / А.Д. Попова, И.Г. Дровникова // Безопасность информационных технологий = IT Security, Том 31, № 2 (2024).- С.51-64.</mixed-citation><mixed-citation xml:lang="en">Popova A.D. Methodology for analyzing and assessing the level of security of software used at informatization facilities of internal affairs bodies /HELL. Popova, I.G. Drovnikova. Information technology security = IT Security, 2024; 31(2):51-64. ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit15"><label>15</label><citation-alternatives><mixed-citation xml:lang="ru">Методика тестирования обновлений безопасности программных, программно-аппаратных средств: Методический документ от 28 октября 2022 г. // ФСТЭК России [Электронный ресурс]. – Режим доступа:https://fstec.ru/dokumenty/vse-dokumenty/spetsialnye-normativnye-dokumenty/metodicheskijdokument-ot-28-oktyabrya-2022-g (дата обращения: 24.04.2024).</mixed-citation><mixed-citation xml:lang="en">Methodology for testing security updates of software, firmware and hardware: Methodological document dated October 28, 2022//FSTEC of Russia [Electronic resource]. – Access mode: https://fstec.ru/dokumenty/vse-dokumenty/spetsialnye-normativnye-dokumenty/metodicheskij-dokumentot-28-oktyabrya-2022-g (date of access: 04/24/2024). ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit16"><label>16</label><citation-alternatives><mixed-citation xml:lang="ru">Common Vulnerability Scoring System version 4.0: Specification Document [Электронный ресурс]. – Режим доступа: https://www.first.org/cvss/v4.0/specification-document (дата обращения: 28.04.2024).</mixed-citation><mixed-citation xml:lang="en">Common Vulnerability Scoring System version 4.0: Specification Document [Electronic resource]. – Access mode: https://www.first.org/cvss/v4.0/specification-document (access date: 04/28/2024).</mixed-citation></citation-alternatives></ref><ref id="cit17"><label>17</label><citation-alternatives><mixed-citation xml:lang="ru">Common Vulnerability Scoring System version 4.0: User Guide [Электронный ресурс]. – Режим доступа: https://www.first.org/cvss/v4.0/user-guide (дата обращения: 28.04.2024).</mixed-citation><mixed-citation xml:lang="en">Common Vulnerability Scoring System version 4.0: User Guide [Electronic resource]. – Access mode: https://www.first.org/cvss/v4.0/user-guide (access date: 04/28/2024).</mixed-citation></citation-alternatives></ref><ref id="cit18"><label>18</label><citation-alternatives><mixed-citation xml:lang="ru">Common Vulnerability Scoring System version 4.0: Examples [Электронный ресурс]. – Режим доступа: https://www.first.org/cvss/v4.0/examples (дата обращения: 28.04.2024).</mixed-citation><mixed-citation xml:lang="en">Common Vulnerability Scoring System version 4.0: Examples [Electronic resource]. – Access mode: https://www.first.org/cvss/v4.0/examples (access date: 04/28/2024).</mixed-citation></citation-alternatives></ref><ref id="cit19"><label>19</label><citation-alternatives><mixed-citation xml:lang="ru">CVSS 4.0: аналитический обзор новой версии популярного стандарта [Электронный ресурс]. – Режим доступа: https://www.habr.com&gt;ru/companies/pt/articles/ 788310/ (дата обращения: 28.04.2024).</mixed-citation><mixed-citation xml:lang="en">CVSS 4.0: analytical review of the new version of the popular standard [Electronic resource]. – Access mode: https://www.habr.com&gt;ru/companies/pt/articles/ 788310/ (date of access: 04/28/2024). ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit20"><label>20</label><citation-alternatives><mixed-citation xml:lang="ru">Методика оценки уровня критичности уязвимостей программных, программно-аппаратных средств: Методический документ от 28 октября 2022 г. // ФСТЭК России [Электронный ресурс]. – Режим доступа: https://fstec.ru/dokumenty/vse-dokumenty/spetsialnye-normativnye-dokumenty/metodicheskijdokument-ot-28-oktyabrya-2022-g-2 (дата обращения: 30.04.2024).</mixed-citation><mixed-citation xml:lang="en">Methodology for assessing the level of criticality of software, software and hardware vulnerabilities: Methodological document dated October 28, 2022 // FSTEC of Russia [Electronic resource]. – Access mode:https://fstec.ru/dokumenty/vse-dokumenty/spetsialnye-normativnye-dokumenty/metodicheskijdokument-ot-28-oktyabrya-2022-g-2 (date of access: 04/30/2024). ( In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit21"><label>21</label><citation-alternatives><mixed-citation xml:lang="ru">Common Vulnerability Scoring System Version 4.0: Calculator [Электронный ресурс]. – Режим доступа: https://www.first.org/cvss/calculator/4.0 (дата обращения: 30.04.2024).</mixed-citation><mixed-citation xml:lang="en">Common Vulnerability Scoring System Version 4.0: Calculator [Electronic resource]. – Access mode: https://www.first.org/cvss/calculator/4.0 (access date: 04/30/2024).</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
