Degree
|
Ph. D. (Eng.), Associate Professor of Computer Systems and Technologies Department, National Research Nuclear University MEPhI |
---|---|
E-mail
|
ds@silnov.pro |
Location
|
Moscow |
Articles
|
Classification of the defense software for remote monitoring of computational resourcesAn approach to remote monitoring software for protecting from false positive actions of antiviruses and firewalls is described. Modern defense techniques classification is suggested. Read more...Defense Software eEfficiency Estimation for Remote Monitoring SystemsTechnique for efficiency estimation of remote monitoring systems protection is proposed. The approach uses T. Saati method and is based on selecting the main criteria with further significance evaluating. Read more...Problems of antivirus software false alarmsAdvanced anti-virus tools developers do not pay attention to the type 1 and type 2 errors while identifying malware as a potential threat to stability. Lack of attention to the false alarms self-defense mechanisms creates a breach in security, allowing malware to manipulate antivirus tools. Read more... About erroneous outcomes of data protection softwareDevelopers of modern data protection software do not pay enough attention to false positive problem
while calculating checksum of its files and other data delivered using insecure data transport.
That leads to major problem, if attacker can replace checksum or replace process of getting data
from file, then most of antiviruses and other very important software will be compromised. Authors
of that article developed software for assessing the stability of data protection against different attacks.
Method that shows possibility to compromise large amount of systems based on specific of
operation system’s file request operations. Software was also developed and tests show that many
important utilities such as md5, sha256 (for FreeBSD) and cverify. exe, vipnethashcalc-tool. exe (both
of them certified in Russia as data protection software) are not protected against false errors while
calculating checksums. Errors appear in 100% test cases. In addition, tests were made for software
called «FIKS 2.0.1» witch have special license from Federal Service for Technical and Export Control
of Russia (FSTEC). That software also unprotected against false errors and tests proves that.
Read more...
|