Анализ угроз и уязвимостей в защищенных информационных системах
Журнал: НБИ технологии @nbi-technologies
Рубрика: Информационные технологии в безопасности и телекоммуникациях
Статья в выпуске: 2 т.19, 2025 года.
Бесплатный доступ
В статье рассматриваются проблемы в области информационной безопасности, связанные с ростом цифровизации и увеличением числа киберугроз. Проанализированы ключевые аспекты защиты информационных систем, включая классификацию угроз, уровни защиты и методологии анализа (OCTAVE, EBIOS, STRIDE). Особое внимание уделено современным типам атак – вирусам, DoS/DDoS и Advanced Persistent Threats (APT).
Короткий адрес: https://sciup.org/149151789
IDS: 149151789 | УДК: 004.056.5 | DOI: 10.15688/NBIT.jvolsu.2025.2.1
Analysis of threats and vulnerabilities in secure information systems
This article conducts a comprehensive analysis of threats and vulnerabilities within secure information systems, a critical issue exacerbated by the increasing pace of digitalization and the proliferation of sophisticated cyber threats. The study systematically examines the foundational aspects of information security, beginning with a classification of information systems based on their usage, licensing, and operational models. It further delineates a multi-layered defense strategy encompassing physical, network, application, and organizational levels to ensure robust protection. The core of the analysis focuses on comparing prominent threat assessment methodologies – OCTAVE, EBIOS, and STRIDE – highlighting their unique processes, applications, and inherent limitations for evaluating system risks and vulnerabilities. The research provides a detailed typology of threats, distinguishing between external and internal sources, and analyzes prevalent attack vectors, including viruses/malware, Denial-of- Service (DoS/DDoS) attacks, and complex Advanced Persistent Threats (APTs). The conclusion emphasizes the necessity of a continuous, adaptive, and multi-faceted security approach. It underscores that regular threat analysis, coupled with the ongoing refinement of protective measures and personnel training, is indispensable for maintaining data integrity and confidentiality in the evolving digital landscape.