СЦЕНАРНАЯ ОЦЕНКА ПРИМЕНИМОСТИ ИНСТРУМЕНТОВ МОНИТОРИНГА ЦЕЛОСТНОСТИ И АНАЛИЗА ПОВЕРХНОСТИ АТАКИ В ОС ASTRA LINUX
Аннотация
Ключевые слова
Полный текст:
PDFЛитература
1. Howard, M., Pincus, J., Wing, J.M. (2005). Measuring Relative Attack Surfaces. In: Lee, D.T., Shieh, S.P., Tygar, J.D. (eds) Computer Security in the 21st Century. Springer, Boston, MA. DOI: https://doi.org/10.1007/0-387-24006-3_8.
2. Manadhata P.K., Wing J.M. An attack surface metric. IEEE Transactions on Software Engineering v. 37, no. 3, pp. 371-386, May-June 2011. DOI: https://doi.org/10.1109/TSE.2010.60.
3. Theisen C. et al. Attack surface definitions: A systematic literature review. Information and Software Technology. 2018, v. 104, pp. 94-103. DOI: https://doi.org/10.1016/j.infsof.2018.07.008.
4. Loscocco P., Smalley S. Integrating flexible support for security policies into the Linux operating system. Proceedings of the FREENIX Track: USENIX Annual Technical Conference. 2001. ACM: https://dl.acm.org/doi/10.5555/647054.715771 (accessed: 01.04.2026).
5. Wright C. et al. Linux security modules: General security support for the Linux kernel. 11th USENIX Security Symposium (USENIX Security 02). 2002. ACM: https://dl.acm.org/doi/10.5555/647253.720287 (accessed: 01.04.2026).
6. Девянин П.Н. и др. Проектирование и развитие механизма мандатного контроля целостности в операционной системе Astra Linux. Труды Института системного программирования РАН. 2025, т. 37, № 2, с. 62-78. DOI: https://doi.org/10.15514/ISPRAS-2025-37(2)-5. EDN: BXHFDI.
Devyanin P.N., Starostin A.A., Panov D.S., Usachev S.V. Design and Development of Mandatory Integrity Control in Astra Linux OS. Proceedings of ISP RAS. 2025, v. 37, no. 2, pp. 62-78. DOI: https://doi.org/10.15514/ISPRAS-2025-37(2)-5. EDN: BXHFDI (in Russian).
7. Девянин П.Н. Результаты переработки уровней ролевого управления доступом и мандатного контроля целостности формальной модели управления доступом ОС Astra Linux. Труды Института системного программирования РАН. 2023, т. 35, № 5, с. 8-22. DOI: https://doi.org/10.15514/ISPRAS-2023-35(5)-1. EDN: OVDQUI.
Devyanin P.N. The Results of Reworking the Levels of Role-Based Access Control and Mandatory Integrity Control of the Formal Model of Access Control in Astra Linux. Proceedings of ISP RAS. 2023, v. 35, no. 5,
pp. 8-22. DOI: https://doi.org/10.15514/ISPRAS-2023-35(5)-1. EDN: OVDQUI (in Russian).
8. Девянин П.Н., Жиляков С.С., Смирнов А.И. Тестирование подсистемы безопасности ОС Astra Linux на основе формализованного описания модели управления доступом. Труды Института системного программирования РАН. 2025, т. 37, № 6(2), с. 21-36. DOI: https://doi.org/10.15514/ISPRAS-2025-37(6)-17. EDN: QXTAGB.
Devyanin P.N., Zhiliakov S.S., Smirnov A.I. Testing the Astra Linux OS Security Subsystem Based on a Formalized Description of the Access Control Model. Proceedings of ISP RAS. 2025, v. 37, no. 6(2), pp. 21-36. DOI: https://doi.org/10.15514/ISPRAS-2025-37(6)-17. EDN: QXTAGB (in Russian).
9. Девянин П.Н., Леонова М.А. Приёмы описания модели управления доступом ОС СН Astra Linux Special Edition на формализованном языке метода Event-B для обеспечения её верификации инструментами Rodin и ProB. Прикладная дискретная математика. 2021, № 52, с. 83-96. DOI: https://doi.org/10.17223/20710410/52/5. EDN: EXXYJQ.
Devyanin P.N., Leonova M.A. The Techniques of Formalization of OS Astra Linux Special Edition Access Control Model Using Event-B Formal Method for Verification Using Rodin and ProB. Prikladnaya Diskretnaya Matematika, 2021, no. 52, pp. 83-96. DOI: https://doi.org/10.17223/20710410/52/5. EDN: EXXYJQ (in Russian).
10. Девянин П.Н. О разработке проекта национального стандарта ГОСТ Р «Защита информации. Формальная модель управления доступом. Часть 3. Рекомендации по разработке». Труды Института системного программирования РАН. 2024;36(3):63-82. DOI: https://doi.org/10.15514/ISPRAS-2024-36(3)-5.
Devyanin P.N. On the Development of the Draft Standard GOST R “Information Protection. Formal Access Control Model. Part 3. Recommendations on Development”. Proceedings of the Institute for System Programming of the RAS (Proceedings of ISP RAS). 2024;36(3):63-82. DOI: https://doi.org/10.15514/ISPRAS-2024-36(3)-5 (in Russian).
11. Kim G. H., Spafford E. H. Experiences with tripwire: The evaluation and writing of a security tool. USENIX 1994 UNIX Applications Development Symposium. 1994. URL: https://docs.lib.purdue.edu/cstech/1115/ (accessed: 01.04.2026).
12. Peddoju S.K., Upadhyay H., Lagos L. File Integrity Monitoring Tools: Issues, Challenges, and Solutions. Concurrency and Computation: Practice and Experience. 2020, v. 32, no. 22. DOI: https://doi.org/10.1002/cpe.5825.
13. Radack S., Kuhn D. R. Managing Security Using the Security Content Automation Protocol. IT Professional, v. 13, no. 1, pp. 9-11, Jan.-Feb. 2011. DOI: https://doi.org/10.1109/MITP.2011.11.
14. Payá A., Cotarelo A., Redondo J.M. Egida: Automated Security Configuration Deployment Systems with Early Error Detection. Computers & Security. 2022, v. 116, Art. 102638. DOI: https://doi.org/10.1016/j.cose.2022.102638.
15. Satılmış H., Akleylek S., Tok Z.Y. A Systematic Literature Review on Host-Based Intrusion Detection Systems. IEEE Access, v. 12, pp. 27237-27266, 2024. DOI: https://doi.org/10.1109/ACCESS.2024.3367004.
16. Bringhenti D., Marchetto G., Sisto R., Valenza F. Automation for Network Security Configuration: State of the Art and Research Trends. ACM Computing Surveys. 2023, v. 56, no. 3, Art. 57. DOI: https://doi.org/10.1145/3616401.
17. Sailer R. et al. Design and implementation of a TCG-based integrity measurement architecture. USENIX Security Symposium. 2004, v. 13, pp. 223-238. ACM: https://dl.acm.org/doi/10.5555/1251375.1251391 (accessed: 01.04.2026).
18. Aslam M., Gehrmann C., Björkman M. ASArP: automated security assessment & audit of remote platforms using TCG-SCAP synergies. Journal of Information Security and Applications. 2015, v. 22, pp. 28-39. DOI: https://doi.org/10.1016/j.jisa.2014.09.001.
DOI: http://dx.doi.org/10.26583/bit.2026.4.11
Ссылки
- На текущий момент ссылки отсутствуют.

Это произведение доступно по лицензии Creative Commons «Attribution» («Атрибуция») 4.0 Всемирная.





