RUS  ENG
Full version
JOURNALS // Informatics and Automation // Archive

Tr. SPIIRAN, 2012 Issue 22, Pages 31–44 (Mi trspy529)

This article is cited in 5 papers

SQL representation of relational and probabilistic models of socio-engineering attacks in problems of calculation of the aggregated of information system’s personnel’s security estimation

A. A. Azarovab, A. L. Tulupyevba, T. V. Tulupyevaacb

a St. Petersburg Institute for Informatics and Automation of RAS
b St. Petersburg State University, Department of Mathematics and Mechanics
c Northwestern State Services University

Abstract: Risk analysis of information security is now extremely important topic, due to the fact that as insurance companies want to have probably more exact characteristics about the probable size of a damage and the necessary sum of insurance, and the company, wishing to insure the information risks, also want to understand, for what and as far as these or those sums are reasonably paid at the conclusion of the contract of insurance. Besides, any of the called parties doesn't want to lose own resources. Thus, it is necessary to learn to receive adequate, but at the same time the complex, aggregated estimates of security of information systems. The purpose of the present article is consideration of option of a task of the main relations in a complex «the personnel information system – critical documents» at socio-engineering attack of the malefactor, and then to illustrate work of principles of a likelihood and relational approach on simplified (for availability and brevity of a statement) an example. Let's use the mixed terminology borrowed from the theory of the relations and the theory of relational DB.

Keywords: socio-engineering attack, informational system, user, user's vulnerabilities profile.

UDC: 614.8 + 002.6:004.89

Received: 11.07.2012



© Steklov Math. Inst. of RAS, 2024