<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">sapi</journal-id><journal-title-group><journal-title xml:lang="ru">Системный анализ и прикладная информатика</journal-title><trans-title-group xml:lang="en"><trans-title>«System analysis and applied information science»</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">2309-4923</issn><issn pub-type="epub">2414-0481</issn><publisher><publisher-name>Belarusian National Technical University</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.21122/2309-4923-2017-3-76-82</article-id><article-id custom-type="elpub" pub-id-type="custom">sapi-179</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>Защита информации</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>Information security</subject></subj-group></article-categories><title-group><article-title>DLP: СНИЖЕНИЕ РИСКА УТЕЧКИ КОНФИДЕНЦИАЛЬНОЙ ИНФОРМАЦИИ БАНКА</article-title><trans-title-group xml:lang="en"><trans-title>DLP: REDUCED RISK OF LEAKAGE OF CONFIDENTIAL INFORMATION OF THE BANK</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Андриянова</surname><given-names>Т. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Andryianava</surname><given-names>T. A.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Aспирант</p></bio><bio xml:lang="en"><p>Post-graduate</p></bio><email xlink:type="simple">rezistka@gmail.com</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Саломатин</surname><given-names>С. Б.</given-names></name><name name-style="western" xml:lang="en"><surname>Salomatin</surname><given-names>S. B.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Кандидат технических наук, доцент</p></bio><bio xml:lang="en"><p>Associate Professor, PhD in Engineering</p></bio><email xlink:type="simple">kafsiut@bsuir.by</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Белорусский государственный университет информатики и радиоэлектроники</institution><country>Беларусь</country></aff><aff xml:lang="en"><institution>Belarusian State University of Informatics and Radioelectronics</institution><country>Belarus</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2017</year></pub-date><pub-date pub-type="epub"><day>02</day><month>11</month><year>2017</year></pub-date><volume>0</volume><issue>3</issue><fpage>76</fpage><lpage>82</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Андриянова Т.А., Саломатин С.Б., 2017</copyright-statement><copyright-year>2017</copyright-year><copyright-holder xml:lang="ru">Андриянова Т.А., Саломатин С.Б.</copyright-holder><copyright-holder xml:lang="en">Andryianava T.A., Salomatin S.B.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://sapi.bntu.by/jour/article/view/179">https://sapi.bntu.by/jour/article/view/179</self-uri><abstract><p>Исследуется применение DLP-системы для защиты конфиденциальной информации, предлагается методика адаптации DLP-системы к специфике деятельности организации, проводится сравнительный анализ результатов работы стандартной и адаптированной DLP-систем в Банке. Разработаны: методика анализа событий информационной безопасности, алгоритм реагирования на выявленные события, а также методика и процедуры адаптации стандартной DLP-системы к специфике деятельности Банка. Методика адаптации стандартной DLP-системы к специфике работы Банка состоит из следующих мероприятий: определение категорий критичной корпоративной информации, аудит информационных систем, описание актуальных рисков и их оценка, введение регламентов обращения с информацией ограниченного распространения и настройку DLP-системы в соответствии со спецификой работы Банка. Модернизация конфигурации стандартной DLP-системы включает в себя следующие процедуры: селекцию конфиденциальной информации Банка по критерию принадлежности, настройку детектирования, создание периметров и разработку алгоритма реагирования на выявленные события информационной безопасности в Банке. Алгоритм предназначен для повышения эффективности реагирования сотрудниками службы информационной безопасности в случаях выявления инцидентов и описывает этапы последующих действий. Результаты исследований доказывают, что использование адаптированной DLP-системы значительно снижает количество ложных срабатываний, повышая точность детектирования конфиденциальной информации и снижая риск утечки критичной информации за пределы корпоративной сети. Применение адаптированной DLP-системы в Банке позволило повысить быстродействие реагирования специалистов службы информационной безопасности на выявленные адаптированной DLP-системой события информационной безопасности в Банке, а также позволило осуществить переход работы DLP-системы из режима копирования в режим блокирования нелегитимной передачи информации.</p></abstract><trans-abstract xml:lang="en"><p>Research application of DLP-system for protection of confidential information, a methodology for adapting the DLP-system to the specific activities of the organization, comparative analysis of the results of standard and adapted DLP-systems in the Bank. Developed: a technique for analyzing information security events, algorithm for responding to identified events, methodology and procedures for adapting the standard DLP-system to the specifics of the Bank’s activities. The methodology for adapting a standard DLP-system to the specifics of the Bank’s work consists of the following activities: identification of critical corporate information categories, audit of information systems, description of current risks and their assessment, introduction of rules for Bank’s critical information and setting up a DLP system in accordance with the specifics of the Bank’s work. Modernization of the configuration of a standard DLP-system includes the following procedures: selection of confidential information of the Bank based on membership criteria, setting up detection, creating perimeters and developing an algorithm for responding to identified information security events in the Bank. The algorithm is designed to improve the efficiency of the response of information security officers in cases of incident detection and describes the stages of the subsequent actions. The results of the research prove that using an adapted DLP-system significantly reduces the number of false positives, increasing the accuracy of detecting confidential information and reducing the risk of leakage of critical information outside the corporate network. The application of the adapted DLP-system in the Bank allowed to increase the speed of response of information security specialists to the information security events detected by the DLP-system adapted to the Bank, and also allowed the DLP-system to transition from the copy mode to the blocking mode of illegitimate transfer of information.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>Информационная безопасность</kwd><kwd>DLP-система</kwd><kwd>система мониторинга</kwd><kwd>событие информационной безопасности</kwd><kwd>утечка конфиденциальной информации</kwd><kwd>детектирование информации</kwd><kwd>алгоритм реагирования на инциденты</kwd></kwd-group><kwd-group xml:lang="en"><kwd>Information Security</kwd><kwd>DLP-system</kwd><kwd>monitoring system</kwd><kwd>an information security event</kwd><kwd>leakage of confidential information</kwd><kwd>detection of information</kwd><kwd>incident response algorithm</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Данкевич, А. DLP в эпоху корпоративной мобильности / А. Данкевич / Директор информационной службы № 03 [Электронный ресурс]. – 2013. – Режим доступа: https://www.osp.ru/text/print/article/13034662.html?isPdf=1. – Дата доступа:15.08.2017.</mixed-citation><mixed-citation xml:lang="en">Dankevich, А. DLP v jepohu korporativnoj mobil’nosti A. Dankevich / Direktor informacionnoj sluzhby № 03 [Electronic resource]. – 2013. – Mode of access: https://www.osp.ru/text/print/article/13034662. html?isPdf=1). – Date of access: 15.08.2017.</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Внуков, А. А. Защита информации в банковских системах: учеб. пособие для бакалавриата и магистратуры / А. А. Внуков; М.: Издательство Юрайт, 2017. – 246 с.</mixed-citation><mixed-citation xml:lang="en">Vnukov, А. А. Zashhita informacii v bankovskih sistemah: ucheb. posobie dlja bakalavriata i magistratury / А. А. Vnukov. М.: Izdatel’stvo Jurajt, 2017. – 246 s.(in Russ).</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Технологическое лидерство InfoWatch Traffic Monitor / InfoWatch [Электронный ресурс]. – 2017. – Режим доступа: https://www.infowatch.ru/products/traffic_monitor. – Дата доступа: 04.07.2017.</mixed-citation><mixed-citation xml:lang="en">Tehnologicheskoe liderstvo InfoWatch Traffic Monitor / InfoWatch [Electronic resource]. – 2017. – Mode of access: https:// www.infowatch.ru/products/traffic_monitor. – Date of access: 04.07.2017.</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Васильев, В. DLP-системы: что нужно заказчику /В. Васильев / PC Week № 3–4 [Электронный ресурс]. – 2017. – Режим доступа: https://www.itweek.ru/security/article/detail.php?ID=192940. – Дата доступа: 02.08.2017.</mixed-citation><mixed-citation xml:lang="en">Vasil’ev, V. DLP-sistemy: chto nuzhno zakazchiku / V. Vasil’ev / PC Week № 3–4 [Electronic resource]. – 2017. – Mode of access: https://www.itweek.ru/security/article/detail.php?ID=192940. – Date of access: 02.08.2017.</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Зегжда, Д. П. Основы безопасности информационных систем / Зегжда, Д. П., Ивашко, А. М. – М.: Горячая линия – Телеком, 2000. – 452 с.</mixed-citation><mixed-citation xml:lang="en">Zegzhda, D. P. Osnovy bezopasnosti informacionnyh sistem / Zegzhda, D. P., Ivashko, A. М. – М.: Gorjachaja linija – Telekom, 2000. – 452 s.</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Корт, С. С. Теоретические основы защиты информации: учеб. пособие. – М.: Гелиос АРВ, 2004. – 240 с.</mixed-citation><mixed-citation xml:lang="en">Kort, S. S. Teoreticheskie osnovy zashhity informacii: ucheb. posobie. – М.: Gelios АРВ, 2004. – 240 s.</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Батаронов, И. Л. Оценка и регулирование рисков, обнаружение и предупреждение компьютерных атак на инновационные проекты / И. Л. Батаронов, А. В. Паринов, К. В. Симонов // Информация и безопасность. – 2013. – Т. 16. – Вып. 2. – С. 243–246 c.</mixed-citation><mixed-citation xml:lang="en">Bataronov, I. L. Ocenka i regulirovanie riskov, obnaruzhenie i preduprezhdenie komp’juternyh atak na innovacionnye proekty / I. L. Bataronov, A. V. Parinov, K. V. Simonov // Informacija i bezopasnost’. – 2013. – Т. 16. – Vyp. 2. – S. 243–246 s.</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Бутузов, В. В. К вопросу обоснования функции ущерба атакуемых систем / В. В. Бутузов, А. В. Заряев // Информация и безопасность. – 2013. – Т. 16. – Вып. 1.– С. 47–54.</mixed-citation><mixed-citation xml:lang="en">Butuzov, V. V. K voprosu obosnovanija funkcii ushherba atakuemyh sistem / V. V. Butuzov, A. V. Zarjaev // Informacija i bezopasnost’. – 2013. – T. 16. – Vyp. 1.– S. 47–54.</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
