Управління інформацією і подіями безпеки комп’ютерних систем із використанням логіко-динамічних моделей

dc.contributor.authorПавленко, Петро Миколайович
dc.contributor.authorСамборський, Євген Іванович
dc.date.accessioned2025-12-15T13:46:59Z
dc.date.available2025-12-15T13:46:59Z
dc.date.issued2025
dc.description.abstractУ статті розглядається один із можливих підходів до організації управління інформацією та подіями безпеки комп’ютерних систем. Проведений аналіз відомих результатів досліджень свідчить, що існуючим системам управління інформацією і подіями безпеки притаманна низка функціональних обмежень, які перешкоджають досягненню заданого рівня якості управління. Ці обмеження пов’язані з неможливістю оптимальної інтерпретації подій безпеки та забезпечення у повному обсязі адаптивного управління цими інцидентами з урахуванням реальних змін у поведінці загроз. Тому мета статті полягає в тому, щоб запропонувати ефективний підхід до синтезу алгоритмічного і програмного забезпечення систем управління інформацією і подіями безпеки, реалізація якого дозволить розширити їх можливості за рахунок формування в залежності від динаміки загроз автоматичних сценаріїв реагування на інциденти. Для досягнення цієї мети при моделюванні процесів організації управління інформацією і подіями безпеки комп’ютерних систем використані фундаментальні положення теорії логіко-динамічних систем. Ґрунтуючись на цій теорії, запропонована логіко-динамічна модель управління інформацією та подіями безпеки, яка має відмінності від існуючих моделей (наприклад, Petri Nets, Markov Chains, Bayesian Networks). Використання цієї моделі дозволяє формалізувати збір, обробку та аналіз інформації про інциденти, а також розробляти алгоритми їх компенсації. Відмічено, що застосування логіко-динамічних моделей дозволяє врахувати складність та динамічність процесів у комп'ютерних системах, а також неповноту інформації про події безпеки. Представлено алгоритм, який синергетизує відомості про різноманітні інциденти комп’ютерних систем та їх обробку в масивах подій безпеки з метою подальшого реагування на ці деструктивні події. Запропонованому алгоритму притаманна низка переваг, зокрема щодо адаптованості та гнучкості. Практична значущість роботи полягає у можливості впровадження отриманих результатів досліджень для вдосконалення існуючих та розробки перспективних систем захисту комп'ютерних систем, які входять в структуру об’єктів критичної інформаційної інфраструктури. Новизна запропонованого підходу полягає в поєднання традиційних сигнатурних та поведінкових методів ідентифікації загроз із їх логіко-динамічним аналізом. Це дозволяє підвищити точність і оперативність виявлення небезпекових аномалій в комп’ютерних системах.
dc.description.abstractotherThe article discusses one of the possible approaches to the organization of information management and security events of computer systems. The analysis of the known research results shows that the existing information and security event management systemsare characterized by a number of functional limitations that prevent the achievement of a given level of management quality. These limitations are associated with the impossibility of optimal interpretation of security events and ensuring the full adaptive management of these incidents, taking into account real changes in the behavior of threats. Therefore, the purpose of the article is to offer an effective approach to the synthesis of algorithmic and software for information and security event managementsystems, the implementation of which will expand their capabilities by forming, depending on the dynamics of threats, automatic scenarios for responding to incidents. To achieve this goal, the fundamental provisions of the theory of logical-dynamic systems are used in modeling the processes of organization of information management and security events of computer systems. Based on this theory, a logical-dynamic model of information and security event management has been proposed, which has differences fromexisting models (for example, Petri Nets, Markov Chains, Bayesian Networks). The use of this model makes it possible to formalize the collection, processing and analysis of information about incidents, as well as to develop algorithms for their compensation. It is noted that the use of logical-dynamic models allows taking into account the complexity and dynamism of processes in computer systems, as well as the incompleteness of information about security events. An algorithm is presented that synergizes information about various incidents of computer systems and their processing in arrays of security events in order to further respond to these destructive events. The proposed algorithm has a number of advantages, including adaptability and flexibility. The practical significance of the work lies in the possibility of implementing the obtained research results to improve the existing and develop promising systems for protecting computer systems, which are part of the structure of critical information infrastructure facilities. The novelty of the proposed approach lies in the combination of traditional signature and behavioral methods of threat identification with their logical-dynamic analysis. This allows you to increase the accuracy and efficiency of detecting dangerous anomalies in computer systems.
dc.format.pagerangePp. 43-54
dc.identifier.citationПавленко, П. Управління інформацією і подіями безпеки комп’ютерних систем із використанням логіко-динамічних моделей / Петро Павленко, Євген Самборський // Information Technology and Security. – 2025. – Vol. 13, Iss. 1 (24). – Pp. 43-54. – Bibliogr.: 17 ref.
dc.identifier.doihttps://doi.org/10.20535/2411-1031.2025.13.1.328764
dc.identifier.orcid0000-0002-2581-230X
dc.identifier.orcid0000- 0003-4441-1947
dc.identifier.urihttps://ela.kpi.ua/handle/123456789/77703
dc.language.isouk
dc.publisherInstitute of Special Communication and Information Protection of National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute”
dc.publisher.placeKyiv
dc.relation.ispartofInformation Technology and Security, Vol. 13, Iss. 1 (24)
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/
dc.subjectуправління
dc.subjectінформація
dc.subjectподія
dc.subjectбезпека
dc.subjectлогіко-динамічна модель
dc.subjectзахист
dc.subjectкомп’ютерна система
dc.subjectінформаційна інфраструктура
dc.subjectmanagement
dc.subjectinformation
dc.subjectevent
dc.subjectsecurity
dc.subjectlogical-dynamic model
dc.subjectprotection
dc.subjectcomputer system
dc.subjectinformation infrastructure
dc.subject.udc004.942
dc.titleУправління інформацією і подіями безпеки комп’ютерних систем із використанням логіко-динамічних моделей
dc.title.alternativeManagement of information and security events of computer systems using logical-dynamic models
dc.typeArticle

Файли

Контейнер файлів
Зараз показуємо 1 - 1 з 1
Вантажиться...
Ескіз
Назва:
43-54.pdf
Розмір:
358.91 KB
Формат:
Adobe Portable Document Format
Ліцензійна угода
Зараз показуємо 1 - 1 з 1
Ескіз недоступний
Назва:
license.txt
Розмір:
8.98 KB
Формат:
Item-specific license agreed upon to submission
Опис: