• MACHINE LEARNING DATASETS FOR CYBER SECURITY APPLICATIONS

    pg(s) 109-112

    The main objective of this study is not to identify the best machine learning model, but instead to review the main datasets, publicly available, used to train and test security solutions that employ modern classification algorithms for anomaly detection. Hence, DARPA 1998 and KDD were studied as they were the first initiatives taken in this direction, while NSL-KDD, ISCXIDS2012 and CICIDS2017 are taken in consideration for future research because of their advantages. Personalized datasets will always bring a reasonable amount of uncertainty, especially since some feature vectors used for training remain unknown. Nevertheless, training on data specific to the protected infrastructure is more efficient, from the security point of view, than training on old attack signatures.

  • SOCIAL ENGINEERING AS A HIGH CYBERSECURITY THREAT

    pg(s) 106-108

    Cybersecurity became the most famous topic concerning security development. Having social engineering in mind, all technical devices can be beaten and a cyberattack can have success just having incompetent personnel employed. In this research paper, some real social engineering texts as e-mails are shown and malicious intends presented. Short analysis is made about SE letters subjects

  • STUDY OF THE IMBALANCE AND DISPROPORTIONS IN THE OPPOSITION OF CYBER DEFENSE AGAINST HACKERS

    pg(s) 102-105

    Study outlines the contours and the magnitude of the asymmetry in the opposition of cyber defense against hackers. Propose a
    model that reflects the dynamics of the opposition on both sides and the impact of the listed disproportions. It consist a functional analysis of the differences between organizational and technical approaches applied from both sides. Contains research into why even the most highly protected systems suffer from successful hacking attacks. The analysis sheds light on the magnitude of pressure exerted by malicious actors on cyber security for organizations and the disproportionate response from experts who protect information systems and networks.

  • ON THE CONTEMPORARY CYBERSECURITY THREATS

    pg(s) 111-113

    Cybersecurity is one of the most commented areas in IT nowadays. Plenty of network and application attacks are possessed worldwide. Security becomes serious issue for corporations and governmental computer networks as functionality of applications rises in technological aspect. Most affective and widely used network attacks and application vulnerabilities are commented in this reviewing paper. Primary solutions for network security are proposed.

  • BIOMETRIC MULTI-FACTOR AUTHENTICATION

    pg(s) 65-68

    This paper focuses on multi-factor authentication methods. It primarily addresses biometric methods, in particular authentication through written expression. It summarises the results of many years of research activities by the authors in the field of the dynamic biometric signature1 (DBS), including new experiments. It concludes by comparing this type of signature with a signature based on cryptographic methods with a view to the current eIDAS Regulation.

  • COMPARATIVE STUDY OF VULNERABILITY SCANNING TOOLS: NESSUS vs RETINA

    pg(s) 69-71

    Detecting vulnerabilities for a network is an important procedure which ensures that all the data, network-based applications and information communicated in this network, is secure. Detection of network vulnerabilities is used to determine weaknesses of the network, the risk evaluation of attacks, the diagnosis and suggestions to solve the problems. There are several types of scanning tools used to detect vulnerabilities, offering different features. In this paper, we will present a performance comparative study between two most used free, software based, network vulnerability scanning tools: Nessus and Retina. The comparison will be based on three main features: The ability to search, Scanning Time, The ability to detect vulnerabilities. In the conclusions of this paper, both scanners performed very well in vulnerability identification. In terms of speed without active Web Application feature, Nessus performed much faster than Retina; (on the other hand, with active Web Application module, Nessus performs much slower than Retina. In terms of scan depth, Nessus has a small advantage, since it includes a web mirroring tool that is very helpful in HTTP.

  • THE MOTIVATION OF HIGH SCHOOL TEACHERS IN THE FORMATION OF THEIR OWN COMPETENCIES IN THE FIELD OF INFORMATION SECURITY

    pg(s) 21-22

    The article describes the problem of involving high school teachers in establishing the national information security by applying their own competencies in the field of information security and protection in the educational process, the demonstration of their trainees and active implementation in their own professional activities. Tasks of the personal and proprietary information protection often not resolved, which is a potential threat to the learning process, research activities of the University, and can be used cyber criminals for cyber extremist or terrorist crimes. The teaching staff motivation is a cornerstone in forming the own competencies in the field of information security process. The traditional leadership approach to formation procedure of information security in this case is insufficient, as the teacher is a leader of a new person preparation, ready to operate successfully in an information society.