FIELD: information security.
SUBSTANCE: invention relates to the field of information security. A method for automated documentation of security threats and vulnerabilities related to an information resource includes: initializing an information resource profile; expanding the profile of an information resource by adding new vertices and edges to its knowledge graph in an automated and interactive mode; clarification of the profile of the information resource by classifying the components of the profile and/or enriching the profile; determination of security threats and vulnerabilities related to the information resource by establishing relationships between the vertices of the profile graph and the corresponding threats and vulnerabilities, moreover, information about the components of the information resource that are obtained during the initialization, expansion and refinement of the profile of the information resource, and certain security threats and vulnerabilities related to the information resource are recorded in the documenting file of security threats and vulnerabilities.
EFFECT: increasing the reliability of the information received about threats and vulnerabilities related to the information resource.
11 cl, 4 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD OF CONTROLLING PROTECTION SURFACE OF CORPORATE COMMUNICATION NETWORK | 2023 |
|
RU2824314C1 |
SYSTEM AND METHOD OF AUTOMATIC INVESTIGATION OF SAFETY INCIDENTS IN AUTOMATED SYSTEM | 2017 |
|
RU2664018C1 |
CONTROL SYSTEM FOR SECURITY POLICY OF ELEMENTS OF CORPORATE COMMUNICATION NETWORK | 2023 |
|
RU2813469C1 |
SYSTEM AND METHOD OF CREATING AND USING USER SEMANTIC DICTIONARIES FOR PROCESSING USER TEXT IN NATURAL LANGUAGE | 2015 |
|
RU2584457C1 |
SYSTEM AND METHOD OF CREATING AND USING USER ONTOLOGY-BASED PATTERNS FOR PROCESSING USER TEXT IN NATURAL LANGUAGE | 2015 |
|
RU2596599C2 |
AUTOMATED SAFETY ASSESSMENT OF BUSINESS-CRITICAL COMPUTER SYSTEMS AND RESOURCES | 2011 |
|
RU2657170C2 |
SUPERCOMPUTER COMPLEX FOR DESIGNING NANOSYSTEMS | 2009 |
|
RU2432606C2 |
INTELLIGENT TRAINING SYSTEM | 2006 |
|
RU2310237C1 |
DATA ANALYSIS SYSTEM IN THE FIELD OF TELEMEDICINE | 2003 |
|
RU2251965C2 |
METHOD OF DETERMINING POTENTIAL THREATS TO INFORMATION SECURITY BASED ON INFORMATION ON VULNERABILITIES OF SOFTWARE | 2019 |
|
RU2705460C1 |
Authors
Dates
2023-02-14—Published
2022-06-01—Filed