Method of Grouping Subjects and Objects in Information Systems

The paper considers the problem of dividing users and information systems into groups in organizations of an arbitrary scale. Modern methods do not consider specifics of the organization, business priorities and actual attacking techniques. Two feature sets for subjects and information systems are p...

Descripción completa

Guardado en:
Detalles Bibliográficos
Autores principales: Anastasiya Bondareva, Ilya Shilov
Formato: article
Lenguaje:EN
Publicado: FRUCT 2021
Materias:
Acceso en línea:https://doaj.org/article/90744cf9854940d5b0d5083388b2f064
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
Descripción
Sumario:The paper considers the problem of dividing users and information systems into groups in organizations of an arbitrary scale. Modern methods do not consider specifics of the organization, business priorities and actual attacking techniques. Two feature sets for subjects and information systems are presented. The features are selected by analysis of dispersion, correlation coefficients and linear regression models built on pairs of features. An evaluation of clustering algorithms applicability to the problem of dividing users and information systems into groups is performed. An algorithm applying the results to real world organizations is constructed. The output of the algorithm can be used for network information security evaluation, access rights management and for designing requirements for network segmentation.