<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Application of Open Data in Accordance With Information Security Requirements*</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Aleksandr V. Dorofeev</string-name>
          <email>a.dorofeev@npo-echelon.com</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alexey S. Markov</string-name>
          <email>a.markov@bmstu.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>ntin L. Tsirlov</string-name>
          <email>v.tsirlov@bmstu.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Bauman Moscow State Technical University</institution>
          ,
          <addr-line>Moscow</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>NPO Echelon</institution>
          ,
          <addr-line>Moscow</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <fpage>36</fpage>
      <lpage>46</lpage>
      <abstract>
        <p>The paper discusses the existing inconsistency between information security requirements and requirements for government data accessibility. The paper provides the classification of open and public government data. It specifies generally accessible data sources that can be used for information security management. Completes and adequate measures to protect open resources in public information systems in Russia are provided. A conclusion is made on the adequacy and completeness of taxonomies in the area of web resource security. The authors conducted a comparative analysis of individual Internet portals on open data. The paper points out information security problems in relation to open data usage and some ways to solve them.</p>
      </abstract>
      <kwd-group>
        <kwd>Open Government Data</kwd>
        <kwd>Public Information Systems</kwd>
        <kwd>Publicly Available Information</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        The development of the paradigms of electronic and open governments has brought
attention to so-called open government data (hereinafter - OD) [
        <xref ref-type="bibr" rid="ref10 ref11 ref15 ref18 ref6">6, 10, 11, 15, 18</xref>
        ], which
should be made available to the public by the Internet portals of various systems of
government authorities for further processing in various information systems. Due to
this, two factors of society informatization should be distinguished:
*
      </p>
      <p>Copyright 2019 for this paper by its authors. Use permitted under Creative Commons License
Attribution 4.0 International (CC BY 4.0).
 As for OD processing, the following can be mentioned:
 Regulatory requirements for the integrity and accessibility of shared public
information resources are being developed in the country;
 Confronting threats of denial of service (accessibility of resources) in cyberspace is
the most difficult task to ensure the safe operation of Internet portals.</p>
      <p>The above determines the scientific interest in the notion of OD information security
itself. It should be noted than in terms of everyday life, from the point of an outdated
view of ensuring information security (as securing privacy and confidentiality of the
information), an open data security procedure seems to come into apparent conflict with
the very notions of openness and general accessibility. However, this is certainly not
the case, if we consider the notion of information security in the generally accepted
international understanding, when all open resources of information systems can have
a wide range of threats in the area of information, primarily with respect to threats to
integrity and accessibility.</p>
      <p>The research of the OD information security assurance is the subject matter of this
paper.
2</p>
    </sec>
    <sec id="sec-2">
      <title>The notion of open data and classification</title>
      <p>Open government data normally include publicly available data in electronic format,
officially provided by government authorities for further free use. For example, the
server of government authorities of the Russian Federation provides these data as
information on the activities of government authorities and local governments placed
on the Internet in a format that allows its automatic processing for reuse without any
prior human modification (machine-readable format) and can be freely used in any
lawful purposes by any persons irrespective of the form of its placement.</p>
      <p>
        The basic principles of OD are identified, such as primacy, completeness, relevance,
machine readability, lack of discrimination on access, lack of proprietary formats, clean
license, etc. [
        <xref ref-type="bibr" rid="ref1 ref22 ref24">1, 22, 24</xref>
        ].
      </p>
      <p>
        In technical terms, OD sets have the property of interoperability, since such data
should be free of any access or implementation restrictions, and have open-ended
formats and interfaces [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>According to the guidelines of the Russian Federal Agency for Scientific
Organizations, the types of open data are classified by the following main criteria: data domain,
data format, a data structure (linear, hierarchical, etc.), data volume, publication
method, storage method, updating frequency, data relevance.</p>
      <p>As mentioned above, the notion of OD is defined by attributing data sets to the
governmental resource subject to placing them on the Internet for general use in the
specified formats (see Fig 1). Thus, OD is a subset of public government data (PD)
characterized by additional restrictions, mainly in interfaces and presentation format on the
Internet portal:
.</p>
      <p>(1)</p>
      <p>At the same time, there are no technical obstacles both for converting public data to
the open data format and for further conversion of OD.</p>
      <p>It is easy to see (Fig. 1) that in terms of legislation there are two categories of public
data covered by the state information security (IS) requirements:
 Public personal data in personal data processing information systems (PDIS);
 Public data in public information systems (PIS), which are actually OD (see below).
In terms of purposes, two subclasses of public data sets in the area of information
security can be distinguished:
1. OD sets related to the official activities of public authorities;
2. Other sets of public government data which can be used in the IS management
systems.</p>
      <p>As for public authorities, there are three regulators in the area of IS in the Russian
Federation. The most useful and complete IS information can be obtained on the official
Internet portal - www.fstec.ru, in the Open Data section (Table 1).</p>
      <p>No
1
2
3
4
5
6
7
8
9
10
Plan of scheduled inspections on licensing control issues
Plan of scheduled inspections on export control issues
Register of information security means licenses
Register of technical protection of confidential information licenses</p>
      <p>You can certainly find other publicly available IS data on the IS portal, such as the
register of expert organizations, register of educational institutions and centers,
regulations, guidelines, specific, anti-corruption, tender information, etc. Particular attention
should be certainly paid to the Information Security Threats Data Bank.</p>
      <p>
        Other sets of publicly available data can easily be obtained using competitive
intelligence methods [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] from publicly available government sources (Table 2).
      </p>
      <p>
        It should be noted that the use of OD and open data of non-governmental
corporations and associations give a powerful synergetic effect [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
3
      </p>
    </sec>
    <sec id="sec-3">
      <title>Threats to open data in the information environment</title>
      <p>
        Information security of open government data can be defined as a property of OD
security against threats in the information area. These threats can be divided into possible
violations of technical requirements to OD and data abuse [
        <xref ref-type="bibr" rid="ref20 ref27">20, 27</xref>
        ]. In the legal
framework, three current areas of OD threats are normally pointed out:
1. IS threats related to the OD life cycle and organizational and technical support
systems for OD;
2. Threats related to the protection of personal and family secrets or privacy (personal
data);
3. Threats related to national (state) security.
      </p>
      <p>
        Threats related to national security are certainly the most controversial. As is known,
open resources are the main source of modern intelligence, regardless of the fact
whether it refers to business intelligence or has a national status. The facts of using the
potential of open data for criminal purposes are fairly well known [
        <xref ref-type="bibr" rid="ref12 ref17">12, 17</xref>
        ]. OD, among
other things, can be used to robotize the process of collecting and conducting a
cognitive analysis of intelligence data. These issues are described in the professional
literature and even in the standards [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ].
      </p>
      <p>
        Threats related to private secrets refer to the protection of the rights of subjects of
personal data, which is now sufficiently developed [
        <xref ref-type="bibr" rid="ref13 ref19 ref23 ref9">9, 13, 19, 23</xref>
        ]. The intersection of
interests can occur when disclosing, say, the incomes of public officers for
anti-corruption purposes.
      </p>
      <p>As for IS, we can single out the following threats:
 Threats to the integrity and accessibility of OD themselves;
 Threats to information security (integrity, accessibility, and confidentiality), which
are associated with support systems (information, software, technical support, etc.)
for PIS.</p>
      <p>
        For example, if we imagine that documents on the website are recorded in the OD
format, then there are threats to their integrity and accessibility. If a web portal has the
functions of registering users and supporting correspondence, this requires the
additional protection of this information against the disclosure threats. Similar tasks need
to be solved for the protection of internal portal structure when the access to the
resources is differentiated once the administrator and user privileges are differentiated.
Modern PIS are connected to the interagency electronic interaction system (IEIS) and
support the Unified Identification and Authentication System (UIAS), and some of
them also include payment components. It should be realized that modern OD can have
a distributed form (for example, link open data [
        <xref ref-type="bibr" rid="ref1 ref21 ref28 ref8">1, 8, 21, 28</xref>
        ]), - this requires that not
only physical but also logical (semantic) integrity of open resources, etc. should be
maintained.
      </p>
      <p>Next, we consider regulatory requirements for these systems.
4</p>
    </sec>
    <sec id="sec-4">
      <title>Regulatory information security requirements</title>
      <p>
        It is fair to say that Russia has a regulatory framework both for informatization objects
(information systems) that process OD, and for the OD protection means [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>Requirements for information security in information systems that process OD are
established by the Decree of the Government of the Russian Federation dated May 18,
2009 N 424. According to this order, two classes of public information systems (PIS)
are introduced.</p>
      <p>Currently, for the protection of PIS, several classes of information security tools
have been defined, namely: cryptographic protection means, antivirus, firewalls,
intrusion detection systems, and access control systems.</p>
      <p>
        As to the requirements for the information security tools (except for cryptographic),
the FSTEC of Russia is currently preparing them based on the same open methodology
Common Criteria [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Nowadays, PIS-2 uses information security means of the 4th
security class, which corresponds to the 3rd increased Evaluation Assurance Level
EAL3+ (Table 3).
      </p>
      <p>It should be understood that the FSTEC of Russia additionally determines
requirements (in terms of non-cryptographic methods) for state information systems (SIS) and
for personal data processing information systems (PDIS) (see Table 4.). These orders
adhere to a quasi-risk-based approach, i.e. they allow a reasonable reduction in the
number of security measures, depending on the limited IT architecture of the system.</p>
      <p>Currently, verification of vulnerabilities is a mandatory procedure for the design and
certification of secure systems, as well as the certification of information security tools.
Therefore, to give a complete picture, we briefly treat a security control issue for web
portals as a basic platform to organize PIS.</p>
    </sec>
    <sec id="sec-5">
      <title>Vulnerabilities and attacks on web portal resources</title>
      <p>
        Web portals are currently most often exposed to computer attacks from various types
of violators. So, according to WhiteHat Security, the percentage of computer attacks on
web resources is 40 % of all registered attacks over the past year [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ].
      </p>
      <p>
        An example of a typical secure web portal is shown in Fig. 2. The figure shows the
main components of the web portal (web server, user application server, database
management system, including OD), and standard information security means. Despite the
security tools (for a known reason of extreme complexity and dynamism of software
subsystems), the web portal needs constant checking for vulnerabilities and checking
the threats of their implementation (the possibility of computer attacks) [
        <xref ref-type="bibr" rid="ref29">29</xref>
        ].
      </p>
      <p>However, similarly to the Russian regulatory framework (see above), it can be stated
that the expertise of the web portal security has been globally developed, and there are
relevant registers and standards for describing vulnerabilities, threats and attacks on
web resources.</p>
      <p>
        First of all, we can mention the classification of the Web Application Security
Consortium on security threats and attacks on web resources - WASC Threat Classification
[
        <xref ref-type="bibr" rid="ref25">25</xref>
        ], statistics of the OWASP open project on the ten most dangerous violations and
attacks on web applications - OWASP Top 10 Application Security Risks [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ], as well
as the templates of attacks of MITRE organization – CAPEC [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], including on-web
resources.
      </p>
      <p>
        The Information Security Threats Database (TDB) of the FSTEC of Russia currently
supports the known threats to web resources and contains the actual vulnerabilities of
relevant applications and platforms [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. An example of the TDB threats and
vulnerabilities fragment of the FSTEC of Russia is shown in Table 5.
      </p>
      <p>The vulnerability of the Apache HTTP Server, which allows an
intruder to bypass existing access restrictions.</p>
      <p>The vulnerability of the Nginx proxy server, which allows an intruder
to cause a denial of service.</p>
      <p>The vulnerability of the SAUTER module Vision controller
visualization web server via BACnet/IP networks, which allows an intruder
to obtain confidential information.</p>
      <p>Vulnerabilities of IniNet Solutions GmbH's SCADA Web Server,
which allows an intruder to implement arbitrary code.</p>
      <p>The vulnerability of the SAUTER module Vision controller
visualization web server via BACnet/IP networks, which allows an intruder
to introduce arbitrary web or HTML code.
6</p>
    </sec>
    <sec id="sec-6">
      <title>Conclusions</title>
      <p>Based on the analysis of the open government data use in the area of information
security in the Russian Federation we can draw the following conclusions:
1. OD is an example of open technological initiatives aimed not only at improving the
efficiency of public administration but also at improving the efficiency of research
and production of products and systems, as well as in the area of information
security.
2. In technical terms, OD allows us not only to ensure compliance with the key
management requirement in the area of information security (according to ISO/IEC
27001) in terms of awareness but also to automate this process through public
interfaces and formats.
3. The main threats to OD are the threats to accessibility and integrity, but the
government web portals have a wide range of modern threats to information, and the
number of computer attacks on web portals is steadily growing.
4. The development tendency of a regulatory framework of modern information
processing systems for OD and OD security means, as well as the standards and registers
of threats and vulnerabilities of web resources, is generally determined, which
facilitates the activities of developers of these systems.
5. At present, OD for IS (with the possible exception of the publicly available data of
the FSTEC of Russia) is presented in Russian Cyberspace very modestly. For
example, there is no OD relating to the work of state security operation centers yet, and
even there is no territorial statistics on cybercrime and cybersecurity.
6. It can be assumed that the use of formatted publicly available data in IS will develop.</p>
      <p>The objective reason for this is the emergence of new information conveniences
(hence, economic benefits), accompanying the informatization of society and the
formation of secure virtual cyberspace.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Attard</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Orlandi</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Scerri</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Auer</surname>
            ,
            <given-names>S.A.</given-names>
          </string-name>
          :
          <article-title>Systematic Review of Open Government Data Initiatives</article-title>
          .
          <source>Government Information Quarterly</source>
          .
          <volume>32</volume>
          (
          <issue>4</issue>
          ), pp.
          <fpage>399</fpage>
          -
          <lpage>418</lpage>
          (
          <year>2015</year>
          ). DOI:
          <volume>10</volume>
          .1016/j.giq.
          <year>2015</year>
          .
          <volume>07</volume>
          .006.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Barabanov</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Modern Trends in The Regulatory Framework of the Information Security Compliance Assessment in Russia Based on Common Criteria</article-title>
          .
          <source>In: The 8th International Conference on Security of Information and Networks (SIN '15)</source>
          , pp.
          <fpage>30</fpage>
          -
          <lpage>33</lpage>
          . ACM New York (
          <year>2015</year>
          ).
          <source>DOI: 10.1145/2799979</source>
          .2799980.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <given-names>Common</given-names>
            <surname>Attack</surname>
          </string-name>
          <article-title>Pattern Enumeration and Classification: A Community Resource for Identifying and Understanding Attacks, The MITRE Corporation</article-title>
          , https://capec.mitre.org,
          <source>last accessed</source>
          <year>2019</year>
          /05/05.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Dorofeev</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          :
          <article-title>Structured Approach to the Social Network Analysis of Information about a Certain Individual</article-title>
          .
          <source>In: 2nd International Conference on Electronic Governance and Open Society: Challenges in Eurasia</source>
          , pp.
          <fpage>174</fpage>
          -
          <lpage>178</lpage>
          . ACM, New York (
          <year>2015</year>
          ).
          <source>DOI: 10.1145/2846012</source>
          .2846017.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Dorofeev</surname>
            ,
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            ,
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            ,
            <given-names>V.L.</given-names>
          </string-name>
          :
          <article-title>Social Media in Identifying Threats to Ensure Safe Life in a Modern City</article-title>
          .
          <source>Communications in Computer and Information Science</source>
          .
          <volume>674</volume>
          , pp.
          <fpage>441</fpage>
          -
          <lpage>449</lpage>
          (
          <year>2016</year>
          ). DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -49700-6_
          <fpage>44</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Hohlov</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Styrin</surname>
          </string-name>
          , E.:
          <article-title>E-government in Russia: Strategies of formation and development</article-title>
          .
          <source>In: Global Strategy and Practice of E-Governance: Examples from Around the World</source>
          , pp.
          <fpage>286</fpage>
          -
          <lpage>303</lpage>
          . IDI Publishing,
          <string-name>
            <surname>Hershey</surname>
          </string-name>
          (
          <year>2011</year>
          ).
          <source>DOI: 10.4018/978-1-60960-489-9</source>
          .
          <year>ch016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <given-names>Information</given-names>
            <surname>Security</surname>
          </string-name>
          <article-title>Threats Database of the FSTEC of Russia</article-title>
          , FSTEC of Russia, http://bdu.fstec.ru/threat, last accessed
          <year>2019</year>
          /05/05.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Janssen</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Estevez</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Janowski</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          : Interoperability in Big, Open, and
          <string-name>
            <given-names>Linked</given-names>
            <surname>Data-Organizational</surname>
          </string-name>
          <string-name>
            <surname>Maturity</surname>
          </string-name>
          , Capabilities,
          <string-name>
            <given-names>and Data</given-names>
            <surname>Portfolios</surname>
          </string-name>
          .
          <source>Computer</source>
          .
          <volume>47</volume>
          ,
          <issue>10</issue>
          , pp.
          <fpage>44</fpage>
          -
          <lpage>49</lpage>
          (
          <year>2014</year>
          ). DOI:
          <volume>10</volume>
          .1109/
          <string-name>
            <surname>MC</surname>
          </string-name>
          .
          <year>2014</year>
          .
          <volume>290</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Kagawa</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Saiki</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nakamura</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Developing personalized security information service using open data</article-title>
          .
          <source>In: 2017 18th IEEE/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD)</source>
          , pp.
          <fpage>465</fpage>
          -
          <lpage>470</lpage>
          . IEEE (
          <year>2017</year>
          ). DOI:
          <volume>10</volume>
          .1109/SNPD.
          <year>2017</year>
          .
          <volume>8022763</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Kokkinakos</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Koutras</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markaki</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Koussouris</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Trutnev</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Glikman</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          :
          <article-title>Assessing Governmental Policies' Impact through Prosperity Indicators and Open Data</article-title>
          .
          <source>In: Proceeding EGOSE '14 Proceedings of the 2014 Conference on Electronic Governance and Open Society: Challenges in Eurasia</source>
          , pp.
          <fpage>70</fpage>
          -
          <lpage>74</lpage>
          . ACM,
          <string-name>
            <surname>NY</surname>
          </string-name>
          (
          <year>2014</year>
          ).
          <source>DOI: 10.1145/2729104</source>
          .2729134.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Koznov</surname>
            ,
            <given-names>D.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Andreeva</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nikula</surname>
            ,
            <given-names>U.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Maglyas</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Muromtsev</surname>
            ,
            <given-names>D.I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Radchenko</surname>
            ,
            <given-names>I.A.</given-names>
          </string-name>
          :
          <article-title>Survey of Open Government Data in Russian Federation</article-title>
          .
          <source>In: IC3K 2016 - Proceedings of the 8th International Joint Conference on Knowledge Discovery, Knowledge Engineering and Knowledge Management</source>
          <volume>8</volume>
          , pp.
          <fpage>173</fpage>
          -
          <lpage>180</lpage>
          (
          <year>2016</year>
          ). DOI:
          <volume>10</volume>
          .5220/0006049201730180.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Larsen</surname>
            ,
            <given-names>H.L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Blanco</surname>
            ,
            <given-names>J.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pastor</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yager</surname>
            ,
            <given-names>R.R</given-names>
          </string-name>
          . (Eds.):
          <article-title>Using Open Data to Detect Organized Crime Threats</article-title>
          .
          <source>Factors Driving Future Crime</source>
          . Springer (
          <year>2017</year>
          ). DOI:
          <volume>10</volume>
          .1007/978- 3-
          <fpage>319</fpage>
          -52703-1.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Meijer</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Conradie</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Choenni</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Reconciling Contradictions of Open Data Regarding Transparency, Privacy, Security and Trust</article-title>
          .
          <source>Journal of Theoretical and Applied Electronic Commerce Research</source>
          .
          <volume>9</volume>
          (
          <issue>3</issue>
          ), pp.
          <fpage>45</fpage>
          -
          <lpage>58</lpage>
          (
          <year>2014</year>
          ). DOI:
          <volume>10</volume>
          .4067/S0718-18762014000300004.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Mendel</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Blanton</surname>
            ,
            <given-names>T.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wadham</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          , and etc.:
          <article-title>National Security and Open Government: Striking the Right Balance</article-title>
          . Preface by Alasdair Roberts. Campbell Public Affairs Institute. Maxwell School of Citizenship and Public Affairs, Syracuse University (
          <year>2003</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Olifirov</surname>
            ,
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Makoveichuk</surname>
            ,
            <given-names>K.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhytnyy</surname>
            ,
            <given-names>P.Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Filimonenkova</surname>
            ,
            <given-names>T.N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petrenko</surname>
            ,
            <given-names>S.A.</given-names>
          </string-name>
          :
          <article-title>Models of Processes for Governance of Enterprise IT and Personnel Training for Digital Economy</article-title>
          .
          <source>In Proceedings of 2018 17th Russian Scientific</source>
          and
          <article-title>Practical Conference on Planning and Teaching Engineering Staff for the Industrial and Economic Complex of the Region</article-title>
          , IEEE, PTES, pp.
          <fpage>216</fpage>
          -
          <lpage>219</lpage>
          (
          <year>2018</year>
          ). DOI:
          <volume>10</volume>
          .1109/PTES.
          <year>2018</year>
          .
          <volume>8604166</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16. OWASP Top 10-2017
          <string-name>
            <given-names>Application Security</given-names>
            <surname>Risks. The Open Web Application Security Project</surname>
          </string-name>
          (
          <year>2017</year>
          ), https://www.owasp.org/index.php/Top_
          <fpage>10</fpage>
          -
          <lpage>2017</lpage>
          _Application_Security_Risks, last accessed
          <year>2019</year>
          /05/05.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Pastor</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Blanco</surname>
            ,
            <given-names>J.M.:</given-names>
          </string-name>
          <article-title>The ePOOLICE Project: Environmental scanning against organised crime</article-title>
          .
          <source>European Police Science and Research Bulletin</source>
          .
          <volume>16</volume>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>19</lpage>
          (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>Petrenko</surname>
            ,
            <given-names>S.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Makoveichuk</surname>
            ,
            <given-names>K.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chetyrbok</surname>
            ,
            <given-names>P.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petrenko</surname>
            ,
            <given-names>A.S.</given-names>
          </string-name>
          :
          <article-title>About Readiness for Digital Economy</article-title>
          .
          <source>In Proceedings of the 2017 IEEE II International Conference on Control in Technical Systems</source>
          , IEEE, CTS, pp.
          <fpage>96</fpage>
          -
          <lpage>99</lpage>
          (
          <year>2017</year>
          ). DOI:
          <volume>10</volume>
          .1109/CTSYS.
          <year>2017</year>
          .
          <volume>8109498</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Pingo</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Narayan</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>When Personal Data Becomes Open Data: An Exploration of Lifelogging, User Privacy, and Implications for Privacy Literacy</article-title>
          .
          <source>Lecture Notes in Computer Science</source>
          .
          <volume>10075</volume>
          , pp.
          <fpage>3</fpage>
          -
          <lpage>9</lpage>
          (
          <year>2016</year>
          ).
          <source>DOI 10</source>
          .1007/978-3-
          <fpage>319</fpage>
          -49304-
          <issue>6</issue>
          _
          <fpage>1</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <string-name>
            <surname>Priyadarshy</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Big data, smart data, dark data, and open data: eGovernment of the future</article-title>
          .
          <source>In: 2015 Second International Conference on eDemocracy &amp; eGovernment (ICEDEG)</source>
          , p.
          <fpage>16</fpage>
          .
          <string-name>
            <surname>IEEE</surname>
          </string-name>
          (
          <year>2015</year>
          ). DOI:
          <volume>10</volume>
          .1109/ICEDEG.
          <year>2015</year>
          .
          <volume>7114483</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <surname>Radchenko</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sakoyan</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>The View on Open Data and Data Journalism: Cases, Educational Resources</article-title>
          and
          <string-name>
            <given-names>Current</given-names>
            <surname>Trends</surname>
          </string-name>
          .
          <source>Communications in Computer and Information Science</source>
          .
          <volume>436</volume>
          , pp.
          <fpage>47</fpage>
          -
          <lpage>54</lpage>
          (
          <year>2014</year>
          ). DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -12580-
          <issue>0</issue>
          _
          <fpage>4</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <surname>Sashinskaya</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Open Data: All You Want to Know About Open Data (Big Data, Transparency</article-title>
          , Urbanism, Transportation, Sustainable Cities, Innovations, Smart Governance, eGovernment).
          <source>CreateSpace Independent Publishing Platform</source>
          (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <surname>Scassa</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          : Privacy and
          <string-name>
            <given-names>Open</given-names>
            <surname>Government</surname>
          </string-name>
          .
          <source>Future Internet. 6</source>
          ,
          <issue>2</issue>
          , pp.
          <fpage>397</fpage>
          -
          <lpage>413</lpage>
          (
          <year>2014</year>
          ). DOI:
          <volume>10</volume>
          .3390/fi6020397.
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>Tauberer</surname>
          </string-name>
          , J.: Open Government Data: 2nd Ed. Kindle
          <string-name>
            <surname>E-Book</surname>
          </string-name>
          (
          <year>2014</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          25.
          <string-name>
            <given-names>WASC</given-names>
            <surname>Threat Classification</surname>
          </string-name>
          . V.
          <volume>2</volume>
          .
          <issue>00</issue>
          (
          <issue>1</issue>
          .
          <fpage>01</fpage>
          .
          <year>2010</year>
          ), Web Application Security Consortium (
          <year>2010</year>
          ). http://projects.webappsec.org/f/WASC-TC-v2_
          <fpage>0</fpage>
          .pdf,
          <source>last accessed</source>
          <year>2019</year>
          /05/05.
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          26.
          <source>Web Applications Security Statistics Report, WhiteHat Security</source>
          (
          <year>2016</year>
          ), https://www.whitehatsec.com/info/website-stats
          <string-name>
            <surname>-report-</surname>
          </string-name>
          2016-wp/,
          <source>last accessed</source>
          <year>2019</year>
          /05/05.
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          27.
          <string-name>
            <surname>Xu</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jiang</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yuan</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ren</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          :
          <article-title>Information Security in Big Data: Privacy and Data Mining</article-title>
          .
          <source>IEEE Access. 2</source>
          , pp.
          <fpage>1149</fpage>
          -
          <lpage>1176</lpage>
          . IEEE (
          <year>2014</year>
          ). DOI:
          <volume>10</volume>
          .1109/ACCESS.
          <year>2014</year>
          .
          <volume>2362522</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          28.
          <string-name>
            <surname>Zhukov</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Komarov</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Semantic Control Method of the Internet of Things Based on Linked Open Data</article-title>
          .
          <source>In: 2017 IEEE 19th Conference on Business Informatics (CBI)</source>
          .
          <volume>02</volume>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          . IEEE (
          <year>2017</year>
          ). DOI:
          <volume>10</volume>
          .1109/CBI.
          <year>2017</year>
          .
          <volume>5</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          29.
          <string-name>
            <surname>Zubarev</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Radin</surname>
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>The Basic Information Security Threats in the Virtual Environments</article-title>
          and
          <string-name>
            <given-names>Cloud</given-names>
            <surname>Platforms</surname>
          </string-name>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          .
          <volume>2</volume>
          (
          <issue>3</issue>
          ), pp.
          <fpage>40</fpage>
          -
          <lpage>45</lpage>
          . (
          <year>2014</year>
          ). [In Russ].
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>