Business Infrastructure Resilience to IT Infrastructure Risks and Its Modeling
摘要
The purpose of the article is a systematic analysis of the security of critical components and parameters of the processes of the IT infrastructure of a business, a company in case of attacks on its infrastructure. The emphasis is on making decisions taking into account the hypothesis of the presence of uncertainty, white noise in the environment and taking into account expert heuristic procedures. In addition to system analysis and synthesis, methods of mathematical and situational modeling, computational mathematics are also used in the work. Analytics and models will help manage company's security strategy. Main research results: (1) offered analytics and classification of the effects of various attacks on the IT infrastructure of a distributed information system; (2) a mathematical model and algorithm for identifying integral damage during the implementation of potential risks in the IT ecosystem, as well as structural schemes of modeling, are proposed and investigated. The model is based on the Cobb-Douglas type function, the adequacy functional of the least squares method and classical (“hard”) and non-classical (“soft”) approaches and computational methods. Scientific and practical value of work: the results can be used to assess the security of the system and reduce the risks of targeted attacks, as well as damage from them. In addition, the proposed schemes will facilitate situational modeling to detect risk situations and assess the damage from their implementation.