Incident Management System Modeling Issues
摘要
The purpose of this paper is to consider approaches to modeling, and to develop a model for evaluating the effectiveness of the information security incident management system, allowing to evaluate the effectiveness of the system by changing the parameters of input data, without using third-party models and methods. The article raises the issue of the need to create a simulation model that will allow evaluating the effectiveness of the information security incident management system. To perform a system analysis of organizational activities of various objects, a context diagram in IDEF0 notation was created. It describes the entire life cycle of an incident, starting from the receipt of events into the system and ending with notification to the GosSOPKA (NCSCI). The article describes and justifies the need to create and implement such a system in the information network, as well as the need to create a model to evaluate the effectiveness of this system. To achieve the goal, the market of similar systems was analyzed, as well as the problems in their maintenance. Based on the analysis, a scheme of the logic of the system was developed with the subsequent implementation of the program code. Then a mathematical model was developed with the help of AnyLogic software, simulating the logic of the application. Approbation was carried out: changes were made to the model parameters, as well as their links with real incident management systems. As a result of this work, a simulation model was built that allows the information security incident management system to be evaluated before it is put into commercial operation in an information network, without requiring the construction of other simulation models.