<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">mireabulletin</journal-id><journal-title-group><journal-title xml:lang="ru">Russian Technological Journal</journal-title><trans-title-group xml:lang="en"><trans-title>Russian Technological Journal</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">2782-3210</issn><issn pub-type="epub">2500-316X</issn><publisher><publisher-name>RTU MIREA</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.32362/2500-316X-2024-12-2-7-15</article-id><article-id custom-type="elpub" pub-id-type="custom">mireabulletin-876</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>ИНФОРМАЦИОННЫЕ СИСТЕМЫ. ИНФОРМАТИКА. ПРОБЛЕМЫ ИНФОРМАЦИОННОЙ БЕЗОПАСНОСТИ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>INFORMATION SYSTEMS. COMPUTER SCIENCES. ISSUES OF INFORMATION SECURITY</subject></subj-group></article-categories><title-group><article-title>Методы анализа влияния изменений программного обеспечения на целевые функции и функции безопасности</article-title><trans-title-group xml:lang="en"><trans-title>Methods for analyzing the impact of software changes on objective functions and safety functions</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-2562-4333</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Легкодумов</surname><given-names>А. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Legkodumov</surname><given-names>A. А.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Легкодумов Александр Алексеевич, специалист инженерно-криптографического анализа</p><p>127083, Москва, ул. Мишина, д. 56, стр. 2</p></bio><bio xml:lang="en"><p>Alexander A. Legkodumov, Cryptographic Analysis Specialist</p><p>56/2, Mishina ul., Moscow, 127083</p></bio><email xlink:type="simple">studkkso0416@mail.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0009-0993-8082</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Козеев</surname><given-names>Б. Н.</given-names></name><name name-style="western" xml:lang="en"><surname>Kozeyev</surname><given-names>B. N.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Козеев Борис Николаевич, главный специалист</p><p>107078, Москва, ул. Каланчевская, д. 27</p></bio><bio xml:lang="en"><p>Boris N. Kozeyev, Chief Specialist</p><p>27, Kalanchevskaya ul., Moscow, 107078</p></bio><email xlink:type="simple">kozeev.boris2018@yandex.ru</email><xref ref-type="aff" rid="aff-2"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0003-1423-1072</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Беликов</surname><given-names>В. В.</given-names></name><name name-style="western" xml:lang="en"><surname>Belikov</surname><given-names>V. V.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Беликов Владимир Вячеславович, к.воен.н., доцент, доцент кафедры информационной безопасности, Институт искусственного интеллекта</p><p>119454, Москва, пр-т Вернадского, д. 78</p><p>Scopus Author ID 57983605100</p></bio><bio xml:lang="en"><p>Vladimir V. Belikov, Cand. Sci. (Military), Docent, Assistant Professor, Department of Information Security, Institute of Artificial Intelligence</p><p>78, Vernadskogo pr., Moscow, 119454</p></bio><email xlink:type="simple">belikov_v@mirea.ru</email><xref ref-type="aff" rid="aff-3"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Корольков</surname><given-names>А. В.</given-names></name><name name-style="western" xml:lang="en"><surname>Korolkov</surname><given-names>A. V.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Корольков Андрей Вячеславович, к.т.н., старший научный сотрудник, заведующий кафедрой информационной безопасности, Институт искусственного интеллекта</p><p>119454, Москва, пр-т Вернадского, д. 78</p><p>SPIN-код РИНЦ 3849-6868.</p><p> </p></bio><bio xml:lang="en"><p>Andrey V. Korolkov, Cand. Sci. (Eng.), Senior Researcher, Head of the Department of Information Security, Institute of Artificial Intelligence</p><p>78, Vernadskogo pr., Moscow, 119454</p></bio><email xlink:type="simple">korolkov@mirea.ru</email><xref ref-type="aff" rid="aff-3"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>OOO «СФБ Лаборатория»</institution><country>Россия</country></aff><aff xml:lang="en"><institution>SFB Laboratory</institution><country>Russian Federation</country></aff></aff-alternatives><aff-alternatives id="aff-2"><aff xml:lang="ru"><institution>АО «АЛЬФА-БАНК»</institution><country>Россия</country></aff><aff xml:lang="en"><institution>ALFA-BANK</institution><country>Russian Federation</country></aff></aff-alternatives><aff-alternatives id="aff-3"><aff xml:lang="ru"><institution>ФГБОУ ВО «МИРЭА – Российский технологический университет»</institution><country>Россия</country></aff><aff xml:lang="en"><institution>MIREA – Russian Technological University</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2024</year></pub-date><pub-date pub-type="epub"><day>05</day><month>04</month><year>2024</year></pub-date><volume>12</volume><issue>2</issue><elocation-id>7–15</elocation-id><permissions><copyright-statement>Copyright &amp;#x00A9; Легкодумов А.А., Козеев Б.Н., Беликов В.В., Корольков А.В., 2024</copyright-statement><copyright-year>2024</copyright-year><copyright-holder xml:lang="ru">Легкодумов А.А., Козеев Б.Н., Беликов В.В., Корольков А.В.</copyright-holder><copyright-holder xml:lang="en">Legkodumov A.А., Kozeyev B.N., Belikov V.V., Korolkov A.V.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://www.rtj-mirea.ru/jour/article/view/876">https://www.rtj-mirea.ru/jour/article/view/876</self-uri><abstract><p>Цели. В статье рассматриваются различные подходы к выполнению процедуры анализа влияния изменений программного обеспечения (ПО) на его безопасность, а также предложен новый метод проведения процедуры анализа, использующий потоки управления функций. Анализ влияния изменений ПО – достаточно трудоемкая процедура, требующая значительных временных затрат и наличия необходимой компетенции у проводящего ее эксперта. Методика проведения анализа влияния изменений ПО не имеет детального описания и не закреплена на законодательном уровне. Цель предлагаемого метода – снижение уровня требований к эксперту, проводящему исследование ПО; локализация областей кода для исследования на наличие дефектов в функциях, обеспечивающих защиту информации; сокращение времени, затрачиваемого на проведение анализа влияния изменений.Методы. Проанализированы наиболее распространенные методы анализа изменений: построчное сравнение, система управления версиями, выполнение автоматизированных текстов. Приведено описание положительных и отрицательных сторон методов анализа. Рассмотрена возможность анализа изменений потока управления функциями ПО как альтернатива стандартному построчному сравнению полного объема исходных текстов. После построения потоки управления различных версий одного ПО, представленные в виде древовидных графов, проходят процедуру объединения. Конечный результат анализируется экспертом.Результаты. Приведены результаты исследования методов анализа изменений ПО с описанием недостатков. Представлено описание метода проведения анализа изменений, использующего поток управления функций, который дополняет существующие методы, устраняя их представленные недостатки. Проанализирована возможность применения данного метода за рамками задач, определенных во введении.Выводы. Использование методов, локализующих наиболее уязвимые участки кода, выделено как одно из наиболее перспективных направлений для проведения анализа влияния изменений. Помимо поиска уязвимых участков кода, важной является оценка эффективности метода сравнения потоков управления в анализе исходного кода при его переходе на другую кодовую базу. </p></abstract><trans-abstract xml:lang="en"><p>Objectives. This paper examines the various approaches to analyzing the impact of software changes, and suggests a new method using function control flows. Impact analysis of software change can require the investment of a lot of time and competence on the part of the expert conducting it. There is no detailed description of methodology for analyzing the impact of changes and it is not established at a legislative level. The proposed method has three aims: reducing the level of requirements for an expert when conducting software research; localizing code areas to establish defects in information protection functions; and reducing the time spent on analyzing the impact of changes.Methods. The study analyzes the common methods for analyzing software changes with a description of their positive and negative sides. The possibility of analyzing changes in the control flow of software functions is considered as an alternative to line-by-line comparison of the full volume of source codes. Represented as tree-shaped graphs, the control flows of different versions of the same software are subject to a merging procedure. The final result is analyzed by an expert from the research organization.Results. The research results of the software change analysis methods are presented with a description of their disadvantages. A description is given of the method for change analysis using function control. This complements existing methods, while eliminating their disadvantages. The study also analyzes the possibility of using this method beyond the tasks defined in the introduction.Conclusions. The use of methods to localize the most vulnerable code sections is considered one of the most promising areas for analyzing change impact. In addition to searching for vulnerable code sections, it is important to evaluate the effectiveness of the control flow comparison method in the analysis of source code when transferred to another code base.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>статический анализ</kwd><kwd>средство криптографической защиты</kwd><kwd>анализ влияния изменений</kwd><kwd>объединение графов</kwd><kwd>анализ программного кода</kwd></kwd-group><kwd-group xml:lang="en"><kwd>static analysis</kwd><kwd>cryptographic protection tool</kwd><kwd>change impact analysis</kwd><kwd>graph merging</kwd><kwd>program code analysis</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Карпов Ю.Г. Model checking. Верификация параллельных и распределенных программных систем. СПб.: БХВ-Петербург; 2010. 560 с. ISBN 978-5-9775-0404-1</mixed-citation><mixed-citation xml:lang="en">Karpov Yu.G. Model checking. Verifikatsiya parallel’nykh i raspredelennykh programmnykh system (Model checking. Verification of Parallel and Distributed Software Systems). St. Petersburg: BHV-Petersburg; 2010. 560 р. (in Russ.). ISBN 978-5-9775-0404-1</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Беликов Д.В. Использование статического анализа исходного кода в разработке и тестировании программного обеспечения. Студенческий форум. 2021;41:90–93.</mixed-citation><mixed-citation xml:lang="en">Belikov D.V. The use of static source code analysis in software development and testing. Studencheskii forum = Student Forum. 2021;41:90–93 (in Russ.).</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Беликов Д.В. Методы проведения статического анализа программного кода. Студенческий форум. 2022;13(192):15–18.</mixed-citation><mixed-citation xml:lang="en">Belikov D.V. Methods for conducting static analysis of program code. Studencheskii forum = Student Forum. 2022;13(192):15–18 (in Russ.).</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Казарин О.В., Скиба В.Ю. Об одном методе верификации расчетных программ. Безопасность информационных технологий. 1997;3:40–33.</mixed-citation><mixed-citation xml:lang="en">Kazarin O.V., Skiba V.Yu. About one method of verification of settlement programs. Bezopasnost’ informatsionnykh tekhnologii = IT Security (Russia). 1997;3:40–33 (in Russ.).</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Щедрин Д.А. Применение методов машинного обучения и анализа статического кода интеллектуальных систем. Научно-исследовательский центр «Technical Innovations». 2023;16:28–32.</mixed-citation><mixed-citation xml:lang="en">Shchedrin D.A. Application of machine learning methods and analysis of static code of intelligent systems. Nauchno-issledovatel’skii tsentr “Technical Innovations” = Scientific Journal “Research Center Technical Innovations.” 2023;16:28–32 (in Russ.).</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Иванников В.П., Белеванцев А.А., Бородин А.Е., Игнатьев В.Н., Журихин Д.М., Аветисян А.И., Леонов М.И. Статический анализатор Svace для поиска дефектов в исходном коде программ. Труды Института системного программирования РАН. 2014;26(1):231–250. https://doi.org/10.15514/ISPRAS-2014-26(1)-7</mixed-citation><mixed-citation xml:lang="en">Ivannikov V.P., Belevantsev A.A., Borodin A.E., Ignatiev V.N., Zhurikhin D.M., Avetisyan A.I., Leonov M.I. Static analyzer Svace for finding of defects in program source code. Тrudy Instituta sistemnogo programmirovaniya RAN = Proceedings of the Institute for System Programming of the RAS. 2014;26(1):231–250 (in Russ.). https://doi.org/10.15514/ISPRAS-2014-26(1)-7</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Викторов Д.С., Самоволина Е.В., Мокеева О.А. Эффективность статического анализа для поиска дефектов программного обеспечения. Вестник Военной академии воздушно-космической обороны. 2021;6:25–39.</mixed-citation><mixed-citation xml:lang="en">Viktorov D.S., Samovolina E.V., Mokeeva O.A. The effectiveness of static analysis for finding software defects. Vestnik Voennoi akademii vozdushno-kosmicheskoi oborony = Bulletin of the Military Academy of Aerospace Defense. 2021;6:25–39 (in Russ.).</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Бурякова Н.А., Чернов А.В. Классификация частично формализованных и формальных моделей и методов верификации программного обеспечения. Инженерный Вестник Дона. 2010;4:129–134.</mixed-citation><mixed-citation xml:lang="en">Buryakova N.A., Chernov A.V. Classification of partially formalized and formal models and methods of software verification. Inzhenernyi Vestnik Dona = Eng. J. Don. 2010;4:129–134 (in Russ.).</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Ефимов А.И. Проблема технологической безопасности программного обеспечения систем вооружения. Безопасность информационных технологий. 1994;3–4:22–33.</mixed-citation><mixed-citation xml:lang="en">Efimov A.I. The problem of technological security of software for weapons systems. Bezopasnost’ informatsionnykh tekhnologii = IT Security (Russia). 1994;3–4:22–33 (in Russ.).</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Ефимов А.И., Пальчун Б.П., Ухлинов Л.М. Методика построения тестов проверки технологической безопасности инструментальных средств автоматизации программирования на основе их функциональных диаграмм. Вопросы защиты информации. 1995;3(30):52–54.</mixed-citation><mixed-citation xml:lang="en">Efimov A.I., Palchun B.P., Ukhlinov L.M. Methodology for constructing tests for checking technological safety of programming automation tools based on their functional diagrams. Voprosy zashchity informatsii = Information Security Questions. 1995;3:30:52–54 (in Russ.).</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Глухих М.И., Ицыксон В.М., Цесько В.А. Использование зависимостей для повышения точности статического анализа программ. Моделирование и анализ информационных систем. 2011;18(4):68–79.</mixed-citation><mixed-citation xml:lang="en">Glukhikh M.I., Itsykson V.M., Tsesko V.A. Using dependencies to improve precision of code analysis. Aut. Control Comp. Sci. 2012;46(7):338–344. https://doi.org/10.3103/S0146411612070097 [Original Russian Text: Glukhikh M.I., Itsykson V.M., Tsesko V.A. Using dependencies to improve precision of code analysis. Modelirovanie i Analiz Informatsionnykh Sistem, 2011;18(4):68–79 (in Russ.).]</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Маликов О.Р. Автоматическое обнаружение уязвимостей в исходном коде программ. Известия Таганрогского радиотехнического университета (Известия ТРТУ). 2005;4:48–53.</mixed-citation><mixed-citation xml:lang="en">Malikov O.R. Automatic detection of vulnerabilities in the source code of programs. Izvestiya TRTU. 2005;4:48–53 (in Russ.).</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">Несов В.С., Маликов О.Р. Использование информации о линейных зависимостях для обнаружения уязвимостей в исходном коде программ. Труды Института системного программирования РАН. 2006;9:51–57.</mixed-citation><mixed-citation xml:lang="en">Nesov V.S., Malikov O.R. Using information about linear dependencies to detect vulnerabilities in the source code of programs. Тrudy Instituta sistemnogo programmirovaniya RAN = Proceedings of the Institute for System Programming of the RAS. 2006;9:51–57 (in Russ.).</mixed-citation></citation-alternatives></ref><ref id="cit14"><label>14</label><citation-alternatives><mixed-citation xml:lang="ru">Воротникова Т.Ю. Надежный код: статический анализ программного кода как средство повышения надежности программного обеспечения информационных систем. Информационные технологии в УИС. 2020;2:22–27.</mixed-citation><mixed-citation xml:lang="en">Vorotnikova T.Yu. Reliable code: static analysis of program code as a means of improving the reliability of software for information systems. Informatsionnye tekhnologii v UIS = Information Technologies in the UIS. 2020;2:22–27 (in Russ.).</mixed-citation></citation-alternatives></ref><ref id="cit15"><label>15</label><citation-alternatives><mixed-citation xml:lang="ru">Fritz C., Arzt S., Rashofer S., et al. Highly Precise Taint Analysis for Android Applications. Technical Report TUD-CS-2013-0113. EC SPRIDE. May 2013. 14 p. URL: http://www.bodden.de/pubs/TUD-CS-2013-0113.pdf</mixed-citation><mixed-citation xml:lang="en">Fritz C., Arzt S., Rashofer S., et al. Highly Precise Taint Analysis for Android Applications. Technical Report TUD-CS-2013-0113. EC SPRIDE. May 2013. 14 p. Available from URL: http://www.bodden.de/pubs/TUD-CS-2013-0113.pdf</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
