Bài viết

Giải pháp đánh giá và quản lý rủi ro an toàn thông tin trong Chính phủ điện tử

Từ khóadò quét lỗ hổng hệ thốngquản lý rủi rođánh giá rủi rodò quét mã nguồn

Tóm tắt

Tóm tắt— Bài báo này trình bày kết quả nghiên cứu xây dựng giải pháp đánh giá và quản lý rủi ro an toàn hệ thống thông tin trong Chính phủ điện tử. Trong bài toán này, chúng tôi tập chung vào xây dựng (i) quy trình đánh giá, quản lý rủi ro an toàn thông tin (ATTT), và (ii) hệ thống phần mềm UET.SRA (Security Risk Assessment System)  hỗ trợ đánh giá, quản lý rủi ro theo quy trình đã xây dựng. Việc quản lý và đánh giá rủi ro ATTT được kết hợp theo các tiêu chuẩn trong nước và quốc tế bao gồm các quy trình trong ISO/IEC 27005:2011 và NIST SP 800-39, nhưng được tuỳ biến để phù hợp với thực tiễn của các cơ quan chính phủ. Hệ thống phần mềm UET.SRA đánh giá rủi ro ATTT dựa theo phương pháp kiểm tra các lỗ hổng và sự phơi nhiễm phổ biến (Common Vulnerabilities and Exposures – CVE); việc ước lượng rủi ro định lượng theo Hệ thống chấm điểm lỗ hổng phổ biến (Common Vulnerability Scoring System - CVSS) và Dự án mở về bảo mật ứng dụng web (Open Web Application Security Project - OWASP). Ngoài ra, UET.SRA còn cung cấp chức năng phân tích, phát hiện các lỗ hổng, các đoạn mã độc trong mã nguồn ứng dụng Web sử dụng công nghệ học sâu (deep learning). Kết quả thử nghiệm giải pháp UET.SRA tại Bộ Tài nguyên và Môi trường (TN&MT) bước đầu đã minh chứng được ý nghĩa thực tiễn và cho phép quản lý được các rủi ro ATTT đối với một số hệ thống trọng yếu của Bộ TN&MT.

Lượt tải theo tháng

05511008/2209/2210/2211/2212/2201/2302/2303/2304/2305/2306/2307/2308/2309/2310/2311/2312/2301/2402/2403/2404/2405/2406/2407/2408/2409/2410/2411/2407/2509/2510/2511/2512/2501/2602/2603/2604/26

Di chuột vào cột để xem số lượt tải.

Cách trích dẫn

Phùng Văn Ổn, Lê Việt Hà, Nguyễn Ngọc Hóa (2023). Giải pháp đánh giá và quản lý rủi ro an toàn thông tin trong Chính phủ điện tử. Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin, 1(13), 35-48. https://doi.org/10.54654/isj.v1i13.144

Tài liệu tham khảo

  1. 1.R. M. Savola and P. Heinonen (2011), “A visualization and modeling tool for security metrics and measurements management,” doi:10.1109/ISA.2011.6027518. Information Security for South Africa (ISSA) Conference, pp. 1-8.
  2. 2.Himanshu Kumar (2014), “Learning Nessus for Penetration Testing”, Packt Publishing.
  3. 3.Sagar Rahalkar (2018), “Network Vulnerability Assessment: Identify security loopholes in your network's infrastructure”, Packt Publishing.
  4. 4.https://www.greenbone.net/en/live-demo/ (Truy cập ngày 10/3/2021).
  5. 5.https://www.tenable.com/plugins/newest (Truy cập ngày 10/3/2021).
  6. 6.Open Vulnerability Assessment Language (OVAL) scans- https://oval.cisecurity.org/ (Truy cập ngày 15/3/2021).
  7. 7.NIST (2013), “NIST SP 800-40r3 Guide to Enterprise Patch Management Technologies”. http://dx.doi.org/10.6028/NIST.SP.800-40r3.
  8. 8.Web Application Attack and Audit Framework – w3af- http://w3af.org/. Truy cập ngày 20/3/2021.
  9. 9.Ngoc-Hoa NGUYEN, Viet-Ha LE, Van-On PHUNG, Phuong-Hanh DU (2019): “Toward a Deep Learning Approach for Detecting PHP Webshell”. Proceedings of the Tenth International Symposium on Information and Communication Technology 2019 (SoICT 2019), ACM, New York, NY, USA. Pages 514–521. https://doi.org/10.1145/3368926.3369733.
  10. 10.Lv ZH., Yan HB., Mei R. (2019), “Automatic and Accurate Detection of Webshell Based on Convolutional Neural Network”. In Yun X. et al. (eds) Cyber Security. CNCERT 2018. Communications in Computer and Information Science, vol 970. Springer, Singapore. pp 73-85. https://doi.org/10.1007/978-981-13-6621-5_6.
  11. 11.Yifan Tian, Jiabao Wang, Zhenji Zhou, and Shengli Zhou (2017). “CNN-Webshell: Malicious Web Shell Detection with Convolutional Neural Network”. In Proceedings of the 2017 VI International Conference on Network, Communication and Computing (ICNCC 2017). ACM, New York, NY, USA, pp. 75-79.
  12. 12.Ha LE Viet, On PHUNG Van and Hoa NGUYEN Ngoc (2020): “Information Security Risk Management by a Holistic Approach: a Case Study for Vietnamese e-Government”. IJCSNS- International Journal of Computer Science and Network Security. VOL 20 No.6, June 2020. pp. 72-82.
  13. 13.Nguyễn Ngọc Hóa (2021), “Báo cáo tổng hợp kết quả đề tài KC01.19/16-20”.
  14. 14.ISO/IEC 27005:2018 Information technology - Security techniques - Information security risk management (third edition). https://www.iso.org/standard/75281.html (Truy cập ngày 22/3/2021).
  15. 15.NIST (2012), “NIST SP 800-30r, Guide for Conducting Risk Assessments”. https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final (Truy cập ngày 25/3/2021).
  16. 16.NIST (2011), “NIST SP 800-39, Managing Information Security Risk: Organization, Mission, and Information System View”. https://csrc.nist.gov/publications/detail/sp/800-39/final (Truy cập ngày 25/3/2021).
  17. 17.ISO/IEC 15408-1:2009 Information technology - Security techniques - Evaluation criteria for IT security. https://www.iso.org/standard/50341.html (Truy cập ngày 22/3/2021).
  18. 18.NIST (2018), “NIST Framework for Improving Critical Infrastructure Cybersecurity (Cybersecurity Framework)”. https://www.nist.gov/cyberframework (Truy cập ngày 25/3/2021).
  19. 19.NIST (2020), “NIST SP 800-53r4, Security and Privacy Controls for Federal Information Systemsand Organizations”. https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/final (Truy cập ngày 25/3/2021).
  20. 20.“Common Vulnerability Scoring System v3.1: Specification Document”, https://www.first.org/cvss/v3-1/cvss-v31-specification_r1.pdf (Truy cập ngày 28/3/2021).
  21. 21.“OWASP Risk Rating Methodology”, https://www.owasp.org/index.php/OWASP_Risk_Rating_Methodology (Truy cập ngày 28/3/2021).

Bài viết liên quan

Giải pháp đánh giá và quản lý rủi ro an toàn thông tin trong Chính phủ điện tử | Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin