Управління інформацією і подіями безпеки комп’ютерних систем із використанням логіко-динамічних моделей
| dc.contributor.author | Павленко, Петро Миколайович | |
| dc.contributor.author | Самборський, Євген Іванович | |
| dc.date.accessioned | 2025-12-15T13:46:59Z | |
| dc.date.available | 2025-12-15T13:46:59Z | |
| dc.date.issued | 2025 | |
| dc.description.abstract | У статті розглядається один із можливих підходів до організації управління інформацією та подіями безпеки комп’ютерних систем. Проведений аналіз відомих результатів досліджень свідчить, що існуючим системам управління інформацією і подіями безпеки притаманна низка функціональних обмежень, які перешкоджають досягненню заданого рівня якості управління. Ці обмеження пов’язані з неможливістю оптимальної інтерпретації подій безпеки та забезпечення у повному обсязі адаптивного управління цими інцидентами з урахуванням реальних змін у поведінці загроз. Тому мета статті полягає в тому, щоб запропонувати ефективний підхід до синтезу алгоритмічного і програмного забезпечення систем управління інформацією і подіями безпеки, реалізація якого дозволить розширити їх можливості за рахунок формування в залежності від динаміки загроз автоматичних сценаріїв реагування на інциденти. Для досягнення цієї мети при моделюванні процесів організації управління інформацією і подіями безпеки комп’ютерних систем використані фундаментальні положення теорії логіко-динамічних систем. Ґрунтуючись на цій теорії, запропонована логіко-динамічна модель управління інформацією та подіями безпеки, яка має відмінності від існуючих моделей (наприклад, Petri Nets, Markov Chains, Bayesian Networks). Використання цієї моделі дозволяє формалізувати збір, обробку та аналіз інформації про інциденти, а також розробляти алгоритми їх компенсації. Відмічено, що застосування логіко-динамічних моделей дозволяє врахувати складність та динамічність процесів у комп'ютерних системах, а також неповноту інформації про події безпеки. Представлено алгоритм, який синергетизує відомості про різноманітні інциденти комп’ютерних систем та їх обробку в масивах подій безпеки з метою подальшого реагування на ці деструктивні події. Запропонованому алгоритму притаманна низка переваг, зокрема щодо адаптованості та гнучкості. Практична значущість роботи полягає у можливості впровадження отриманих результатів досліджень для вдосконалення існуючих та розробки перспективних систем захисту комп'ютерних систем, які входять в структуру об’єктів критичної інформаційної інфраструктури. Новизна запропонованого підходу полягає в поєднання традиційних сигнатурних та поведінкових методів ідентифікації загроз із їх логіко-динамічним аналізом. Це дозволяє підвищити точність і оперативність виявлення небезпекових аномалій в комп’ютерних системах. | |
| dc.description.abstractother | The article discusses one of the possible approaches to the organization of information management and security events of computer systems. The analysis of the known research results shows that the existing information and security event management systemsare characterized by a number of functional limitations that prevent the achievement of a given level of management quality. These limitations are associated with the impossibility of optimal interpretation of security events and ensuring the full adaptive management of these incidents, taking into account real changes in the behavior of threats. Therefore, the purpose of the article is to offer an effective approach to the synthesis of algorithmic and software for information and security event managementsystems, the implementation of which will expand their capabilities by forming, depending on the dynamics of threats, automatic scenarios for responding to incidents. To achieve this goal, the fundamental provisions of the theory of logical-dynamic systems are used in modeling the processes of organization of information management and security events of computer systems. Based on this theory, a logical-dynamic model of information and security event management has been proposed, which has differences fromexisting models (for example, Petri Nets, Markov Chains, Bayesian Networks). The use of this model makes it possible to formalize the collection, processing and analysis of information about incidents, as well as to develop algorithms for their compensation. It is noted that the use of logical-dynamic models allows taking into account the complexity and dynamism of processes in computer systems, as well as the incompleteness of information about security events. An algorithm is presented that synergizes information about various incidents of computer systems and their processing in arrays of security events in order to further respond to these destructive events. The proposed algorithm has a number of advantages, including adaptability and flexibility. The practical significance of the work lies in the possibility of implementing the obtained research results to improve the existing and develop promising systems for protecting computer systems, which are part of the structure of critical information infrastructure facilities. The novelty of the proposed approach lies in the combination of traditional signature and behavioral methods of threat identification with their logical-dynamic analysis. This allows you to increase the accuracy and efficiency of detecting dangerous anomalies in computer systems. | |
| dc.format.pagerange | Pp. 43-54 | |
| dc.identifier.citation | Павленко, П. Управління інформацією і подіями безпеки комп’ютерних систем із використанням логіко-динамічних моделей / Петро Павленко, Євген Самборський // Information Technology and Security. – 2025. – Vol. 13, Iss. 1 (24). – Pp. 43-54. – Bibliogr.: 17 ref. | |
| dc.identifier.doi | https://doi.org/10.20535/2411-1031.2025.13.1.328764 | |
| dc.identifier.orcid | 0000-0002-2581-230X | |
| dc.identifier.orcid | 0000- 0003-4441-1947 | |
| dc.identifier.uri | https://ela.kpi.ua/handle/123456789/77703 | |
| dc.language.iso | uk | |
| dc.publisher | Institute of Special Communication and Information Protection of National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute” | |
| dc.publisher.place | Kyiv | |
| dc.relation.ispartof | Information Technology and Security, Vol. 13, Iss. 1 (24) | |
| dc.rights.uri | https://creativecommons.org/licenses/by/4.0/ | |
| dc.subject | управління | |
| dc.subject | інформація | |
| dc.subject | подія | |
| dc.subject | безпека | |
| dc.subject | логіко-динамічна модель | |
| dc.subject | захист | |
| dc.subject | комп’ютерна система | |
| dc.subject | інформаційна інфраструктура | |
| dc.subject | management | |
| dc.subject | information | |
| dc.subject | event | |
| dc.subject | security | |
| dc.subject | logical-dynamic model | |
| dc.subject | protection | |
| dc.subject | computer system | |
| dc.subject | information infrastructure | |
| dc.subject.udc | 004.942 | |
| dc.title | Управління інформацією і подіями безпеки комп’ютерних систем із використанням логіко-динамічних моделей | |
| dc.title.alternative | Management of information and security events of computer systems using logical-dynamic models | |
| dc.type | Article |
Файли
Контейнер файлів
1 - 1 з 1
Ліцензійна угода
1 - 1 з 1
Ескіз недоступний
- Назва:
- license.txt
- Розмір:
- 8.98 KB
- Формат:
- Item-specific license agreed upon to submission
- Опис: