<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Method for Identification of Functional Security</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Anatolii Davydenko</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oleksandr Korchenko</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Olena Vysotska</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Ihor Ivanchenko</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Pukhov Institute for modeling in energy engineering of NAS of Ukraine</institution>
          ,
          <addr-line>General Naumov str. 15, Kyiv, 03164</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>One of the key tasks during the state examination is the identification of the functional security profile. During the examination, the types of information that is processed and the risks of its loss, modification or disclosure are evaluated. For this, the functional security profile is being built. To solve the problem of identifying the functional security profile, it is necessary to: determine the levels of functional security services, implemented comprehensive information security systems of the object of examination; determination of the completeness and consistency of the profile; identification of the description of the functional security services in the source documents. The paper proposes a model of parameters for identifying the functional security profile in computer systems. A definition is given for the sets of criteria, their elements and levels. All this made it possible in a formal form to form the necessary set of quantities for the implementation of the identification of functional security profile in the computer systems. The development of these works is the development of a method for identifying functional security profile. This will automate the determination of the requirements of the regulatory document regarding the protection functions (security services) and guarantees, which will be done in subsequent articles.</p>
      </abstract>
      <kwd-group>
        <kwd>1 comprehensive information security systems state examinations</kwd>
        <kwd>functional security profile</kwd>
        <kwd>information security criteria</kwd>
        <kwd>computer systems</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>One of the key tasks during the state examination
is to identify the functional security profile. During
examination evaluated the types of information [1-8],
which is processed in the system and the risk of its
loss, modification or disclosure. For this purpose, a
functional security profile (FSP) is built which
contains the lists of functional security service (FSS)
and levels that are needed to ensure an acceptable
level of information security.</p>
      <p>Exactly FSP is the key element of public
examinations and its analysis on accordance to the
normative document is one of major tasks.</p>
      <p>For the decision of task of FSP authentication, it is
necessary to carry out: determination of FSS levels,
implemented FSP examination object; determine
completeness and consistency profile; FSS describe the
identification in the original documents. To determine
the completeness and consistency of rules to consider
construction of FSP (see [9]), and automation of this
process contacts with corresponding rules.</p>
      <p>For the decision of task proposed model
parameters for identifying the FSP in computer
system (CS) and FSP identification method.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Determining the criteria set</title>
      <p>As it’s known [9], the criteria reflect
methodological framework for determining
requirements of information security in of
computer systems against unauthorized access,
the creation of protected CS and protection
against unauthorized access, evaluation of
information security in the CS and its suitability
for the treatment of critical information
(information that requires defense).</p>
      <p>
        Given the above, let’s form the set of all
criteria for information security
МК =  w МКq  = МК1, МК2 ,.., МКw ,
q=1
(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )
where МКq  МК ( q = 1,w ) – q -th element of set
of criteria МК, and w - its count.
      </p>
    </sec>
    <sec id="sec-3">
      <title>3. Determining of element of the criteria set</title>
      <p>
        Next, on the basis of (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) we define the elements
of the МКq -th set of criteria
      </p>
      <p>
         wq
МКq = 
e=1


МКq,e  = МКq,1, МКq,2 ,.., МКq,wq ,


(
        <xref ref-type="bibr" rid="ref2">2</xref>
        )
where
      </p>
      <p>МКq,e  МКq ( e = 1,wq ) – e -th element
МКq - th set of criteria, and wq its count.</p>
      <p>
        Thus, (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) with respect to (
        <xref ref-type="bibr" rid="ref2">2</xref>
        ) we present in the
following form:
      </p>
      <p> w
МК = 
q=1</p>
      <p>  w  wq
МКq  =  
 q=1 e=1</p>
      <p>
        
МКq,e  =

= МК1,1, МК1,2 ,..., МК1,w1 ,
МК2,1, МК2,2 ,..., МК2,w2 ,...,
МКw,1, МКw,2 ,..., МКw,ww .
(
        <xref ref-type="bibr" rid="ref3">3</xref>
        )
      </p>
    </sec>
    <sec id="sec-4">
      <title>4. Determination of levels of elements of the set criteria</title>
      <p>
        Next, on the basis of (
        <xref ref-type="bibr" rid="ref3">3</xref>
        ) we define the level of
each element МКq,e - th element
criteria.
      </p>
      <p>wq,e
МКq,e = 
 y=1


МКq,e,y  = МКq,e,1, МКq,e,2 ,.., МКq,e,wq,e ,

</p>
      <p>
        (
        <xref ref-type="bibr" rid="ref4">4</xref>
        )
where МКq,e,y  МКq,e ( y = 1,wq,e ) – y -th level
МК q,e -th element МК q - th set criteria and w q,e
its maximum level.
      </p>
      <p>
        Thus, (
        <xref ref-type="bibr" rid="ref3">3</xref>
        ) with respect to (
        <xref ref-type="bibr" rid="ref4">4</xref>
        ) has the form:
МКq - th set
      </p>
      <p> w   w  wq 
МК =  МКq  =   МКq,e  =</p>
      <p>q=1  q=1 e=1 
=  w wq wq,e  =
q=1 e=1 y=1 МКq,e,y 
 w  wq 
=   МКq,e,1,МКq,e,2 ,...,МКq,e,wq,e  =</p>
      <p>
        q=1 e=1 
 w
 МКq,1,1 ,МКq,1,2 ,. .,МКq,1,wq,1 МКq,2,1 ,МКq,2,2 ,. .,МКq,2,wq,2 , (
        <xref ref-type="bibr" rid="ref5">5</xref>
        )
q=1
. ., МКq,wq,1 ,МКq,wq,2 ,. .,МКq,wq,wq,wq  =
= МК1,1,1 ,МК1,1,2 ,. .,МК1,1,w1,1,МК1,2,1 ,МК1,2,2 ,. .,МК1,2,w1,2 ,. .,
 МК1,w1,1 ,МК1,w1,2 ,. .,МК1,w1,w1,w1 ,МК2,1,1 ,МК2,1,2 ,. .,МК2,1,w2,1,
МК2,2,1 ,МК2,2,2 ,. .,МК2,2,w2,2 ,. ., МК2,w2,1 ,МК2,w2,2 ,. .,МК2,w2,w2,w2 ,
...,МКw,1,1 ,МКw,1,2 ,. .,МКw,1,ww,1,МКw,2,1 ,МКw,2,2 ,. .,МКw,2,ww,2 ,
. ., МКw,ww,1 ,МКw,ww,2 ,. .,МКw,ww,ww,ww .
      </p>
    </sec>
    <sec id="sec-5">
      <title>5. Formation of the identification of FSP method of</title>
      <p>Step 1. Formation of the primary set of
functional security services.</p>
      <p>As previously described, the levels of the
elements of the sets of criteria are determined by
МКq,e,y</p>
      <p>where y = 1,wq,e – y -th level of МКq,e -th
element of МК q - th set criteria аnd wq,e its
maximum level. Thus, we define the primary set
(PS) of functional security services (FSS) as the
union of elements of sets of criteria defined by the
expert:</p>
      <p>
         k 
ПМp =  ПМp,f  = ПМp,1,ПМp,2...,ПМp,k  , (
        <xref ref-type="bibr" rid="ref6">6</xref>
        )
f =1
where k - the number of primary projects [2]
identified by the expert.
      </p>
      <p>Step 2. Formation of secondary sets of
functional security services.</p>
      <p>Next, we form an FSSSS, which consists
elements of a set of criteria МК , that have levels
that characterize the FSS according to [9]. In turn,
the FFP function is intended to display from a set
of PS into one or more elements of the set МК by
means of which can form a set of all possible
functions from the elements, ПМf , f = 1,k . We
define the number of SS of the FSS:</p>
      <p>
         k   k 
ВМp =  ВМp,f  =  ФВП(ПМp,f ) =
f =1 f =1
= ВМp,1, ВМp,2 ,..., ВМp,k  =
= ФВП(ПМp,1), ФВП(ПМp,2 ),..., ФВП(ПМp,k ),
(
        <xref ref-type="bibr" rid="ref7">7</xref>
        )
where k − respectively, the number of secondary
functional security services of the project and
mapping from the set of PS to one or more elements
of the МК set of the project.
      </p>
      <p>Step 3. Formation of a basic FSP.</p>
      <p>The Basic Functional Security Profile (FSP),
given the expertise and facility requirements to
ensure the safe flow of information, consists of a
set of primary (PS) and secondary (SS) FSS. Let
us define the FSP:</p>
      <p> k
БЗp = 
f =1</p>
      <p>  k
ФВП(ПМp,f ), 
 f =1</p>
      <p>
ВМp,f  =
= ФВП (ПМp,1), ФВП (ПМp,2 ),.., ФВП (ПМp,k ),
ВМp,1 , ВМp,2 ,.., ВМp,k ,
where БЗp − basic functional profile of protection
of the project.</p>
      <p>Step 4. Forming a set of order by element
indices МКq,e,y</p>
      <p>
        Using (
        <xref ref-type="bibr" rid="ref6">6</xref>
        ), taking into account [9], we form a
set of order by indices:
БЗІПМЕ = МК1,1,4 , МК1,2,4 , МК1,3,2 , МК2,1,4 , МК2,2,4 ,
МК2,3,2 , МК2,4,3 , МК3,1,3 , МК3,2,3 , МК3,3,3 ,МК3,4,3 ,
МК4,1,5 , МК4,2,2 , МК4,3,2 , МК4,4,3 , МК4,5,3 , МК4,6,2 ,
МК4,8,1, МК4,9,1 = КД-4, КА-4, КО-1, КК-2, КВ-4,
ЦД-4, ЦА-4, ЦО-2,ЦВ-3, ДР-3, ДС-3, ДЗ-3, ДВ-3,
НР-5, НИ-2, НК-2, НО-3, НЦ-3,НТ-2, НА-1,
НП-1, НВ-2, НА-1, НП-1}
      </p>
      <p>Step 5. Minimizing the basic FSP</p>
      <p>
        Using (
        <xref ref-type="bibr" rid="ref7">7</xref>
        ) taking into account [9] we minimize the
basic FPP by the highest y-th index:
      </p>
      <p> w  wq wq,e 
БЗpmin =   VМКq,e,y  =</p>
      <p>q=1 e=1  y=1 
 w  wq
=  
q=1 e=1
 w
= 
q=1
МКq,1,1 ,МКq,1,2 ,...,  МКq,1,wq,1 

МКq,e,1 ,МКq,e,2 ,...,  МКq,e,wq,e  =

МКq,2,1 ,МКq,2,2 ,...,  МКq,2,wq,2 ,...,
 МКq,wq ,1 ,МКq,wq ,2 ,...,  МКq,wq ,wq,wq  =
= МК1,1,1 ,МК1,1,2 ,...,  МК1,1,w1,1 ,
МК1,2,1 ,МК1,2,2 ,...,  МК1,2,w1,2 ,...,
 МК1,w1,1 ,МК1,w1,2 ,...,  МК1,w1,w1,w1 ,
МК2,1,1 ,МК2,1,2 ,...,  МК2,1,w2,1 ,
МК2,2,1 ,МК2,2,2 ,...,  МК2,2,w2,2 ,...,
 МК2,w2,1 ,МК2,w2,2 ,  ...,  МК2,w2,w2,w2 ,...,
МКw,1,1 ,МКw,1,2 ,...,  МКw,1,ww,1 ,
МКw,2,1 ,МКw,2,2 ,...,  МКw,2,ww,2 ,...,
 МКw,ww ,1 ,МКw,ww ,2 ,...,  МКw,ww ,ww,ww ,</p>
      <p>As a result, I have developed a system that
analyzes the input documents for the presence of a
FSP and its identification by the formal
characteristics of the [9].</p>
      <p>In case of errors, corrects FSP. The system is
implemented on the .NET platform in C#
programming language using the Microsoft Visual
Studio development environment.</p>
      <p>The implementation of a software module for
identifying a functional security profile is intended
to assist the expert in identifying the FSP in a
Microsoft Word document, and to assist the expert
in the analysis of the FSP. The main purpose of this
software module is to assist the expert in the creation
of the FSP and to control compliance with the
conditions set out in the regulatory document [9],
namely: determination of integrity control;
takeovers by the highest FSS of lower ones;
checking the correlation of the FSS.</p>
      <p>
        The software module is written in C#
programming language in VisualStudio 2005. In
the written code technology used
MSOffice'sCOMInterop, namely
Microsoft.Office.Interop.Word library and basic
libraries of programming language C#.
(
        <xref ref-type="bibr" rid="ref8">8</xref>
        )
      </p>
      <p>The interface of the program module (Fig. 1) is a
window application, which is implemented in the
form of a GUI program, in which there are the
following controls: a window box type "Listbox"
search for a functional security profile; buttons:
"Find", "Stop", "Clear"; the right part of the screen
has a window of type "ListView", which displays
the paragraph number where the FPP was found and
the security profile found; three buttons to search for
compliance of the FPP with the terms of the
regulatory document [9]; two textboxes of type
"TextBox" in one of which the total number of
paragraphs of the document is displayed, and in the
other field the current paragraph when processing
the document; a «statusStrip» type window with
three positions: "Pending", "Search started", "Search
is complete"; two window boxes of the type
"СheckedBox" in one of which there is a possibility
to deselect or select the search of the FSP, and in the
other field there is an opportunity to go to the
specified part of the FSP search text; window menu
type "menuStrip", which contains two tabs: "File",
"Help".</p>
      <p>Microsoft Word is a specialized hierarchical,
COM-oriented data warehouse - Structured
Storage. A document can contain different types
of data: structured text, graphics, mathematical
expressions, organizational charts, etc. The
concept of structured repository is an integral part
of the modern programming paradigm based on
the Component Object Model (COM). In fact,
structured storage is the technology of combining
objects (files) of objects with different nature and
properties into one logical unit of storage. COM
technology offers the standard implementation of
the concept of structured storage in the form of a
compound file (Compound File): a file system
inside the file. The COM repository is a
hierarchical structure of collections of objects of
two types: Storage and Stream, to which
directories and files correspond in the traditional
file system. This approach can significantly
reduce the storage costs in a single file of objects
of different nature.</p>
      <p>The implementation of the program includes
methods of regular expressions: comparison of
strings; suffix tree; approximating patterns;
patterns with which multiple choices can be made,
partial patterns. It is shown that technologies that
combine the properties of approximating patterns
and patterns by which multiple choice can be made,
solve the problems of FSP analysis and can be used
to build a system.</p>
      <p>Testing of the program module was carried out
in the process of the state examination of the CISS
Grid site. The work of the software module
resulted in the fulfillment of the tasks for the
search of the FSP and analysis of the FSP for
compliance with the three conditions.
Performance analysis using the software module
showed a multiple increase in the speed of
document processing in the absence of errors,
namely - the software module eliminated the
repetition of the FSS, performed a check of
integrity and completeness. The analysis of
execution with the help of the program showed
many increase of speed of processing of the
document at 100% absence of errors, namely, the
program excluded inclusion in the FPP of the
same type of services, performed the check of
integrity and completeness. Approximate time of
processing of documents was: Technical task - 17
sec; Explanatory note to the technical project - 43
seconds; Act of inspection - 7 sec .; Information
Security Policy - 12 sec. The program was run on
a workstation with the following specifications:
Intel Core i5-4670 CPU with 3.4 GHz; RAM - 8
GB.</p>
      <p>The volume of the document is 8635 words.
The average speed of reading in Ukrainian in an
adult is within 150-200 words per minute [10],
according to experimental studies, the average
speed is 201 words per minute (with scatter of
values from 60 to 378) with an average percentage
of mastering 52 words per minute. Table 1
summarizes the time required for the expert to
process the standard inputs of the CISS
examination. It is only 43 minutes to read the
“Terms of Reference”. Analysis time depends on
the experience of the expert and can not be less
than reading time. Therefore, the acceleration of
processing will be at about fifteen thousand
percent.</p>
      <p>Let’s consider software features. Software
Components:
1. Knowledge base;
2. User interface;
3. Software module "Meaning constants";
4. Software module "FSP Identification";
5. Software module “Determination of FSP";
Meaning Constants module. The module
should ensure that semantic constants are
extracted from the input documents by forming a
set of defined constants in the knowledge base and
inserting these constants into the output document
templates by a defined algorithm.</p>
      <p>The Subsystem of Meaning Constants module
performs the following functions:
• selection of semantic constants from input
documents;</p>
      <p>• formation of knowledge base of semantic
constants;
• Completing source document templates.</p>
      <p>Module « FSP Determination» ensures that the
FSP complies with the three criteria of RD STPI
2.5.004-99 [9]. The subsystem "Determination of
FSP" ensures the following functions:</p>
      <p>The FSP is obliged to include the control of the
integrity of the STPI:</p>
      <p>• the connection of the FSP to each other
according to the RD STPI 2.5.004-99;</p>
      <p>• if the service has any too FSS or more, then
FSP can include only one functional security
service.</p>
      <p>FSP Identification Module</p>
      <p>The module should ensure the formal
compliance of the PSP with the format of the FSS
description, as well as give the expert, in an
interactive mode, the possibility to analyze the FSP
in accordance with the normative document of the
RD STPI 2.5.004-99.</p>
      <p>The subsystem "Determination of FSP" must
ensure the following functions:
• check the description of the FSP;
• provide the expert with the opportunity to
receive extended information about the service in
an interactive mode at events of type mouse focus.</p>
      <p>According to testing methods, one can
classify, for example, as black box testing or
behavioral testing - a strategy (method) for testing
the functional behavior of an object (program,
system) from the point of view of the outside
world, in which knowledge about the internal
structure of the tested object is not used. Strategy
refers to systematic methods for selecting and
creating tests for a test suite. The behavioral test
strategy is based on technical requirements and
their specifications [2,11,12]. The "black box"
refers to the object of study, the internal structure
of which is unknown. The concept of a “black
box” was proposed by Ashby, William Ross. In
cybernetics, it allows you to study the behavior of
systems, that is, their reactions to a variety of
external influences and at the same time abstract
from their internal structure. Manipulating only
with inputs and outputs, it is possible to conduct
certain studies. In practice, the question always
arises of how the black box homomorphism
reflects the adequacy of its studied model, that is,
how fully the basic properties of the original are
reflected in the model. The description of any
control system in time is characterized by a
picture of the sequence of its states in the process
of moving toward its goal. The transformation in
the control system can be either one-to-one and
then it is called isomorphic, or only unambiguous,
in one direction. In this case, the transformation is
called homomorphic. The “black” box is a
complex homomorphic model of a cybernetic
system in which diversity is respected. It is only
then a satisfactory system model when it contains
such an amount of information that reflects the
diversity of the system. It can be assumed that the
greater the number of perturbations acting on the
inputs of the system model, the greater the variety
the regulator should have. Currently, two types of
"black" boxes are known. The first type includes
any “black” box, which can be considered as an
automaton, called finite or infinite. The behavior
of such "black" boxes is known. The second type
includes such "black" boxes, whose behavior can
be observed only in the experiment. In this case, a
hypothesis is expressed explicitly or implicitly
about the predictability of the behavior of the
black box in a probabilistic sense. Without a
preliminary hypothesis, any generalization is
impossible, or, as they say, it is impossible to draw
an inductive conclusion based on experiments
with the black box. To designate the model of the
“black” box, N. Wiener proposed the concept of a
“white” box. The “white” box consists of known
components, that is, known X, Y, δ, λ. Its contents
are specially selected to implement the same
dependence of the output on the input as the
corresponding "black" box. In the process of
research and generalizations, hypotheses and
establishing patterns, it becomes necessary to
adjust the organization of the “white” box and
change models. In this regard, when modeling, the
researcher must necessarily repeatedly refer to the
scheme of relations “black” - “white” box.
Creating a mathematical description of a black
box is a kind of art. In some cases, it is possible to
form an algorithm in accordance with which the
“black” box responds to an arbitrary input signal.
The main methods of testing a black box are: −
equivalent partition; − analysis of boundary
values; − analysis of cause and effect
relationships; − assumption of error. A tester with
extensive experience seeks out errors without any
methods, but at the same time, he unconsciously
uses the method of assuming an error. This
method is largely based on intuition. The main
idea of the method is to make a list that lists
possible errors and situations in which these errors
could occur. Then, based on the list, tests are
compiled.It’s possible that it’s more correct to talk
about different degrees of transparency, and
maybe even generally about different colors of the
box, rather than testing using the black method
and the white box method. The only important
thing is what information we take into account
when designing tests. Either we use information
about the internal structure of the program, or we
do not use it. The following CISS components
were subject to testing:
1) OS protection and administration tools;
2) security features (security services) of middleware;
3) means of increasing accessibility;
4) organizational measures to protect information,
software and hardware;</p>
      <p>5) documentation on CISS according to the list
defined by the requirements of TR.</p>
      <p>The purpose of the CISS tests are:
- verification of the implementation and
sufficiency of organizational measures of
protection given in the documentation;</p>
      <p>- verification of compliance with the
requirements of section 10 “Criteria of
guarantees” RD STPI 2.5-004-99 for the level of
guarantees of the correct implementation of the
G2 security functions in relation to the CIS
architecture, CIS development environment, CIS
development sequence, CIS functioning
environment, documentation and tests of CIS.</p>
      <p>Verification of compliance with the conditions
for the implementation of information security
services is carried out in accordance with the FSP:
3.КЦД = {КА-2, КД-2, КВ-1, ЦА-1 , ЦД-1,
ЦВ-1, ДС-1, ДЗ-2, ДВ-1, НР-2, НИ-2, НК-1,
НО-1, НЦ-2, НТ-2, НВ-1}</p>
    </sec>
    <sec id="sec-6">
      <title>6. Conclusion</title>
      <p>The paper offers a model of parameters which
due to the theoretical and multiple representation
of certain sets of criteria for information security,
their elements and corresponding levels, allowed
to formally form the necessary set of values for
the implementation of the identification of FSP in
the CS. In addition, a method for identifying the
FSP was developed which made it possible to
automate the process of determining requirements
[9] for security features (security services) and
guarantees. As a result, a software module was
created that eliminates the repetition of the FSS,
performed integrity and completeness checks.</p>
    </sec>
    <sec id="sec-7">
      <title>7. References</title>
      <p>Lazarenko, Anna Korchenko, Іryna
Manzhul. Modeling the protection of
personal data from trust and the amount of
information on social networks. Number 1
(2021), «EUREKA: Physics and
Engineering» pp.24–31.</p>
      <p>DOI:10.21303/2461-4262.2021.001615
[9] Korchenko, A., Breslavskyi, V., Yevseiev,
S., ...Sievierinov, O., Tkachuk, S.
Development of a Method for Constructing
Linguistic Standards for Multi-Criteria
Assessment of Honeypot
Efficiency.EasternEuropean Journal of Enterprise
Technologiesthis link is disabled, 2021,
1(2(109)), pp. 14–23
[10] Serhii Yevseiev, Roman Korolyov, Andrii
Tkachov, Oleksandr Laptiev, Ivan Opirskyy,
Olha Soloviova. Modification of the
algorithm (OFM) S-box, which provides
increasing crypto resistance in the
postquantum period. International Journal of
Advanced Trends in Computer Science and
Engineering (IJATCSE) Volume 9. No. 5,
September-Oktober 2020, pp 8725-8729.</p>
      <p>DOI: 10.30534/ijatcse/2020/261952020.
[11] RD STPI 2.5-004-99 Criteria for evaluation
of information security in computer systems
against unauthorized access, approved by the
Order of the Department of Special
Telecommunication Systems and
Information Protection of the Security
Service of Ukraine dated April 28, 1999, No.
22. (in Ukrainian).
[12] Korchenko O.G., Davydenko A.M., Shaban
M.R.: A decomposition model for the
representation of semantic constants and
variables for the implementation of expertise
in the field of STPI. Information Security,
vol. 21, No.2, pp. 88-96 (2019). (in
Ukrainian). DOI: https://doi.org/
10.18372/2410-7840.21.13766</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <source>[1] About information: Law of Ukraine of October 2</source>
          , 1992 No.
          <fpage>2657</fpage>
          -XII, ed.
          <source>Law No. 2938 - VI of 13.01</source>
          .
          <year>2011</year>
          . OVR, №
          <volume>32</volume>
          ,
          <string-name>
            <surname>Art</surname>
          </string-name>
          .
          <volume>313</volume>
          (
          <year>2011</year>
          .)
          <article-title>(in Ukrainian)</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Zegzhda</surname>
            <given-names>D.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ivashko</surname>
            <given-names>A.M.:</given-names>
          </string-name>
          <article-title>Fundamentals of security of information systems</article-title>
          .
          <source>Textbook manual for universities</source>
          , p.
          <volume>451</volume>
          (
          <year>2000</year>
          ).
          <article-title>(in Russian)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Korchenko</surname>
            <given-names>O.G</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Davydenko</surname>
            <given-names>A</given-names>
          </string-name>
          .M,
          <string-name>
            <surname>Shaban</surname>
            <given-names>M.R.</given-names>
          </string-name>
          :
          <article-title>Model of parameters for identification of functional protection profile in computer systems</article-title>
          .
          <source>Security of Information</source>
          . vol.
          <volume>25</volume>
          , No.
          <issue>2</issue>
          , pp.
          <fpage>122</fpage>
          -
          <lpage>126</lpage>
          (
          <year>2019</year>
          ).
          <article-title>(in Ukrainian)</article-title>
          . DOI: https://doi.org/10.18372/
          <fpage>2225</fpage>
          -
          <lpage>5036</lpage>
          .
          <fpage>25</fpage>
          .13844
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Vysotska</surname>
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Davydenko</surname>
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Keystroke Pattern Authentication of Computer Systems Users as One of the Steps of Multifactor Authentication</article-title>
          . In: Hu Z.,
          <string-name>
            <surname>Petoukhov</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dychka</surname>
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>He</surname>
            <given-names>M</given-names>
          </string-name>
          . (eds).
          <source>Advances in Computer Science for Engineering and Education II. ICCSEEA 2019. Advances in Intelligent Systems and Computing</source>
          , vol.
          <volume>938</volume>
          , pp.
          <fpage>356</fpage>
          -
          <lpage>368</lpage>
          (
          <year>2019</year>
          ). DOI: https://doi.org/10.1007/978-3-
          <fpage>030</fpage>
          -16621- 2_
          <fpage>33</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Kazmirchuk</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ilyenko</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ilyenko</surname>
            <given-names>S.:</given-names>
          </string-name>
          <article-title>Digital signature authentication scheme with message recovery based on the use of elliptic curves In: Hu Z</article-title>
          .,
          <string-name>
            <surname>Petoukhov</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dychka</surname>
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>He</surname>
            <given-names>M</given-names>
          </string-name>
          . (eds).
          <source>Advances in Computer Science for Engineering and Education II. ICCSEEA 2019. Advances in Intelligent Systems and Computing</source>
          , vol.
          <volume>938</volume>
          , pp.
          <fpage>279</fpage>
          -
          <lpage>288</lpage>
          (
          <year>2019</year>
          ). DOI: https://doi.org/10.1007/978-3-
          <fpage>030</fpage>
          -16621-2_
          <fpage>26</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Lakhno</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kazmirchuk</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kovalenko</surname>
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Myrutenko</surname>
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhmurko</surname>
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Design of adaptive system of detection of cyberattacks, based on the model of logical procedures and the coverage matrices of features</article-title>
          .
          <source>Eastern-European Journal of Enterprise Technologies</source>
          , vol.
          <volume>3</volume>
          ,
          <source>Issue</source>
          <volume>9</volume>
          (
          <issue>81</issue>
          ), pp.
          <fpage>30</fpage>
          -
          <lpage>38</lpage>
          (
          <year>2016</year>
          ). DOI: https://doi.org/10.15587/
          <fpage>1729</fpage>
          -
          <lpage>4061</lpage>
          .
          <year>2016</year>
          .71769
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>Oleg</given-names>
            <surname>Barabash</surname>
          </string-name>
          , Oleksandr Laptiev, Valentyn Sobchuk, Ivanna Salanda, Yulia Melnychuk,
          <string-name>
            <given-names>Valerii</given-names>
            <surname>Lishchyna</surname>
          </string-name>
          .
          <article-title>Comprehensive Methods of Evaluation of Distance Learning System Functioning</article-title>
          .
          <source>International Journal of Computer Network and Information Security (IJCNIS)</source>
          . Vol.
          <volume>13</volume>
          , No. 3,
          <string-name>
            <surname>Jun</surname>
          </string-name>
          .
          <year>2021</year>
          . рр.
          <volume>62</volume>
          -
          <fpage>71</fpage>
          , DOI: 10.5815/ijcnis.
          <year>2021</year>
          .
          <volume>03</volume>
          .06.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>Serhii</given-names>
            <surname>Yevseiev</surname>
          </string-name>
          , Oleksandr Laptiev, Sergii
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>