Features of the Operation of Digital Ecosystems When Recording Security Events
摘要
The aspects of creating a vector of security events of information systems are studied. The methods used in the construction of the vector of security events are considered, their features are characterized, the specifics of using Markov chains to simulate the attacking actions of the intruder. The suitability of these methods for determining the parameters of the vector is determined, taking into account the use of elements of artificial intelligence in identifying signs of security events of various types. When creating a vector security events take into account the specifics of determining the probabilities of system transitions to various states of compromise. To solve the problems of searching for security events and the formation of their vectors, it is proposed to study the problems of modular architecture. The features of creating a simplified vector of security events are considered, taking into account the links between the tactics (states) proposed in the FSTEC methodological documents.