RUS  ENG
Full version
JOURNALS // Vestnik of Astrakhan State Technical University. Series: Management, Computer Sciences and Informatics // Archive

Vestn. Astrakhan State Technical Univ. Ser. Management, Computer Sciences and Informatics, 2020 Number 2, Pages 84–94 (Mi vagtu629)

This article is cited in 3 papers

MATHEMATICAL MODELING

Model of security information and event management system

I. V. Kotenko, I. B. Parashchuk

St. Petersburg Institute for Informatics and Automation of the Russian Academy of Sciences, Saint-Petersburg, Russian Federation

Abstract: The article is focused on the development of a mathematical model of functioning the security information and event management system known as the SIEM system. This model is a formalized analytical description (in terms of a Markov chain in the form of stochastic differential equations) of the dynamics of the changing states of quality indicators characterizing the essential properties of functioning the security information and events management system in the state space. The model is a system of equations of state and observation, traditional for the Markov chain in the form of finite differences. The scientific task is to improve (modify) the algorithms for converting excitation noise used in the model. A mechanism is proposed for determining the values of the mathematical expectation increment of the simulated process, obtained on the basis of a priori data on the Markov chain, in relation to the mathematical expectation of white Gaussian noise exciting this process. Based on simple calculations the mechanism helps to decide what values can be taken by the elements of the vector of compensation additives in the equation of state of the auxiliary indicator vector of this modified model, taking into account the conversion of the excitation noise. This allows simplifying the model and reducing its computational complexity without significant losses in accuracy (adequacy). The practical application of an improved model is possible both in the framework of the research and in the systems of automated control of information security.

Keywords: mathematical expectation, system of security information and event management, quality indicator, functioning process, matrix, state.

UDC: 004.942

Received: 17.01.2020

DOI: 10.24143/2072-9502-2020-2-84-94



© Steklov Math. Inst. of RAS, 2026