<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">oo</journal-id><journal-title-group><journal-title xml:lang="ru">Открытое образование</journal-title><trans-title-group xml:lang="en"><trans-title>Open Education</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">1818-4243</issn><issn pub-type="epub">2079-5939</issn><publisher><publisher-name>Plekhanov Russian University of Economics</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.21686/1818-4243-2024-4-33-42</article-id><article-id custom-type="elpub" pub-id-type="custom">oo-1037</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>ПРОБЛЕМЫ ИНФОРМАТИЗАЦИИ ЭКОНОМИКИ И УПРАВЛЕНИЯ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>PROBLEMS OF INFORMATIZATION OF ECONOMICS AND MANAGEMENT</subject></subj-group></article-categories><title-group><article-title>Актуальные задачи выявления недопустимых событий на объектах критической информационной инфраструктуры</article-title><trans-title-group xml:lang="en"><trans-title>Current Tasks in Identifying Invalid Events in Critical Information Infrastructure</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0003-1387-3177</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Евдокимова</surname><given-names>Д. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Evdokimova</surname><given-names>D. A.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Москва</p></bio><bio xml:lang="en"><p>Moscow</p></bio><email xlink:type="simple">Evdokimova.DA@rea.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Микрюков</surname><given-names>А. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Mikryukov</surname><given-names>A. A.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Москва</p></bio><bio xml:lang="en"><p>Moscow</p></bio><email xlink:type="simple">mikrukov.aa@rea.ru</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Российский экономический университет им. Г.В. Плеханова</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Plekhanov Russian University of Economics</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2024</year></pub-date><pub-date pub-type="epub"><day>29</day><month>08</month><year>2024</year></pub-date><volume>28</volume><issue>4</issue><fpage>33</fpage><lpage>42</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Евдокимова Д.А., Микрюков А.А., 2024</copyright-statement><copyright-year>2024</copyright-year><copyright-holder xml:lang="ru">Евдокимова Д.А., Микрюков А.А.</copyright-holder><copyright-holder xml:lang="en">Evdokimova D.A., Mikryukov A.A.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://openedu.rea.ru/jour/article/view/1037">https://openedu.rea.ru/jour/article/view/1037</self-uri><abstract><p>Целью исследования является разработка подхода к выявлению и обработке недопустимых событий на объектах критической информационной инфраструктуры (КИИ) на основе концепции таксономии и категоризации. Подход направлен на решение задачи повышения эффективности идентификации, классификации и управления инцидентами информационной безопасности (ИБ). В статье рассматриваются актуальные задачи обеспечения требуемого уровня защищенности КИИ и минимизации негативных последствий от инцидентов информационной безопасности, являющихся следствием недопустимых событий, идентификация которых связана со сложностью их выявления, необходимостью обработки больших объемов данных, недостаточной оперативностью обнаружения событий ИБ, а также ограничениями технологического характера.</p><p>Актуальность выявления и классификации недопустимых событий в области информационной безопасности, особенно для объектов КИИ обусловлена необходимостью своевременного выявления и реагирования на инциденты, которые могут привести к негативным последствиям. Понимание природы и характеристик таких событий позволяет эффективно обеспечить защиту систем и предотвратить существенный ущерб.</p><p>С целью повышения эффективности обеспечения результативной безопасности требуется выявлять класс недопустимых событий среди множества событий информационной безопасности с учетом признаков, которыми характеризуются недопустимые события.</p><p>Новизна предлагаемого подхода заключается в решении задачи выявления класса недопустимых событий информационной безопасности на основе методов таксономии, предусматривающих использование инструментов категоризации событий с использованием атрибутов недопустимых событий.</p><p>Материалы и методы исследования. Для решения поставленной задачи использован подход к выявлению недопустимых событий на объектах КИИ, основанный на принципах таксономии событий информационной безопасности. Показано, что выявление недопустимых событий информационной безопасности напрямую связано с решением задачи поиска и анализа их атрибутов, которые представляют собой характеристики или параметры, используемые для описания и классификации инцидентов безопасности. На основе ключевых принципов таксономии разработана модель структуры множества недопустимых событий для определения признаков, которые могут положены в основу классификации недопустимых событий. Процесс выявления недопустимых событий информационной безопасности включает цепочку этапов: таксономию, категорирование и классификация, на каждом из которых реализуются соответствующие методы и инструменты.</p><sec><title>Результаты</title><p>Результаты: Проанализированы подходы к выявлению недопустимых событий на объектах КИИ. Рассмотрены проблемы, связанные с большим объемом данных, сложностью обработки событий, достаточно длительным временем их обнаружения и ограничениями технологических решений. Показано, что концепция таксономии и категоризации позволяет эффективно идентифицировать и классифицировать инциденты информационной безопасности, обеспечивая эффективные процессы обработки и реагирования на них. Обоснована целесообразность применения таксономии для описания и идентификации атрибутов недопустимых событий, что способствует разработке эффективных стратегий защиты и обеспечивает повышение уровня безопасности. Предложена обобщенная схема обработки недопустимых событий, включающая совокупность взаимосвязанных этапов идентификации, категоризации, оценки влияния, реагирования, документирования и анализа. Разработан алгоритм структурированного описания и классификации инцидентов, что позволяет более точно и оперативно реагировать на угрозы информационной безопасности.</p></sec><sec><title>Заключение</title><p>Заключение: Полученные результаты позволяют повысить эффективность решения задачи классификации инцидентов информационной безопасности за счет идентификации недопустимых событий, что позволяет снизить уровень негативных последствий инцидентов и повысить безопасность объектов КИИ.</p></sec><sec><title> </title><p> </p></sec></abstract><trans-abstract xml:lang="en"><p>The purpose of the study is to develop an approach for identifying and processing invalid events in critical information infrastructure (CII) based on the concepts of taxonomy and categorization. The approach aims to improve the efficiency of identifying, classifying, and managing information security (IS) incidents. The article addresses the current tasks of ensuring the required level of CII protection and minimizing the negative consequences of information security incidents resulting from invalid events. The identification of these events is associated with the complexity of detecting such events, the need to process large volumes of data, insufficient speed in detecting IS events, as well as technological limitations.The relevance of identifying and classifying invalid events in information security, especially for CII, is driven by the need for timely detection and response to incidents that could lead to negative consequences. Understanding the nature and characteristics of such events allows for effective system protection and prevention of significant damage. To enhance the effectiveness of ensuring security, it is necessary to identify the class of invalid events among the numerous information security events by considering the characteristics that define invalid events.The novelty of the proposed approach lies in solving the task of identifying the class of invalid information security events based on taxonomy methods, involving the use of event categorization tools with the attributes of invalid events.Materials and methods. The approach to identifying invalid events in CII, based on the principles of information security event taxonomy, was used to solve the task. It was shown that identifying invalid information security events is directly related to solving the problem of searching for and analyzing their attributes, which represent the characteristics or parameters used to describe and classify security incidents. Based on the key principles of taxonomy, a model of the structure of the set of invalid events was developed to determine the characteristics that can be the basis for classifying invalid events. The process of identifying invalid information security events includes a sequence of stages: taxonomy, categorization, and classification, with appropriate methods and tools implemented at each stage.Results. Approaches to identifying invalid events in CII have been analyzed. Problems related to large data volumes, the complexity of event processing, the considerable time required for their detection, and technological limitations were considered. It was shown that the concept of taxonomy and categorization allows for effective identification and classification of information security incidents, ensuring efficient processing and response. The feasibility of applying taxonomy for describing and identifying the attributes of invalid events was justified, contributing to the development of effective protection strategies and improving security levels. A generalized scheme for processing invalid events was proposed, including a set of interconnected stages of identification, categorization, impact assessment, response, documentation, and analysis. An algorithm for structured description and classification of incidents was developed, allowing for more accurate and timely responses to information security threats.Conclusion. The results obtained increase the effectiveness of solving the task of classifying information security incidents by identifying invalid events, which reduces the level of negative consequences of incidents and enhances the security of CII objects.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>Критическая информационная инфраструктура</kwd><kwd>недопустимые события</kwd><kwd>таксономия</kwd><kwd>классификация инцидентов</kwd><kwd>категоризация событий</kwd><kwd>реагирование на инциденты информационной безопасности</kwd></kwd-group><kwd-group xml:lang="en"><kwd>critical information infrastructure</kwd><kwd>invalid events</kwd><kwd>taxonomy</kwd><kwd>incident classification</kwd><kwd>event categorization</kwd><kwd>information security incident response</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Федеральный закон от 26 июля 2017 г. N 187-ФЗ (ред. от 10 июля 2023 г.) «О безопасности критической информационной инфраструктуры Российской Федерации».</mixed-citation><mixed-citation xml:lang="en">Federal Law of July 26, 2017 N 187-FZ (as amended on July 10, 2023) «On the Security of Critical Information Infrastructure of the Russian Federation». (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">ГОСТ ISO/IEC 27035-1:2016 Information technology — Security techniques — Information security incident management — Part 1: Principles of incident management. International Organization for Standardization, 2016.</mixed-citation><mixed-citation xml:lang="en">ISO/IEC 27035-1:2016 Information technology — Security techniques — Information security incident management – Part 1: Principles of incident management. International Organization for Standardization; 2016.</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">ГОСТ Р 59548—2022 «Защита информации. Регистрация событий безопасности. Требования к регистрируемой информации».</mixed-citation><mixed-citation xml:lang="en">GOST R 59548 - 2022 «Information protection. Registration of security events. Requirements for registered information». (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Методика определения недопустимых событий, сценариев и критериев их реализации компании «Positive Technology» [Электронный ресурс] – URL: https://www.ptsecurity.com/upload/corporate/ru-ru/webinars/ics/metodika-opredeleniya-ns.pdf (дата обращения 10.05.2024).</mixed-citation><mixed-citation xml:lang="en">Metodika opredeleniya nedopustimykh sobytiy, stsenariyev i kriteriyev ikh realizatsii kompanii «Positive Technology» = Methodology for determining unacceptable events, scenarios and criteria for their implementation by Positive Technology [Internet]. Available from: https://www.ptsecurity.com/upload/corporate/ru-ru/webinars/ics/metodika-opredeleniya-ns.pdf (cited 10.05.2024). (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Методика оценки угроз безопасности ФСТЭК России [Электронный ресурс] – URL: https://fstec.ru/dokumenty/vse-dokumenty/spetsialnye-normativnye-dokumenty/metodicheskij-dokument-ot-5-fevralya-2021-g (дата обращения 10.05.2024).</mixed-citation><mixed-citation xml:lang="en">Metodika otsenki ugroz bezopasnosti FSTEK Rossii = Methodology for assessing security threats of the FSTEC of Russia [Internet]. Available from: https://fstec.ru/dokumenty/vsedokumenty/spetsialnye-normativnye-dokumenty/metodicheskij-dokument-ot-5-fevralya-2021-g (cited 10.05.2024). (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Перечень негативных последствий из нового раздела банка данных угроз ФСТЭК России [Электронный ресурс] – URL: https://bdu.fstec.ru/threat-section/negatives (дата обращения 10.05.2024).</mixed-citation><mixed-citation xml:lang="en">Perechen’ negativnykh posledstviy iz novogo razdela banka dannykh ugroz FSTEK Rossii = List of negative consequences from the new section of the FSTEC of Russia threat database [Internet]. Available from: https://bdu.fstec.ru/threat-section/negatives (cited 10.05.2024). (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">«Security Information and Event Management (SIEM) Implementation». Author: David Miller, 2010. ISBN: 978-0-07-162677-4.</mixed-citation><mixed-citation xml:lang="en">«Security Information and Event Management (SIEM) Implementation». Author: David Miller; 2010.</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">NIST Special Publication 800-61 Revision 2, "Computer Security Incident Handling Guide". National Institute of Standards and Technology, 2012.</mixed-citation><mixed-citation xml:lang="en">NIST Special Publication 800-61 Revision 2, «Computer Security Incident Handling Guide». National Institute of Standards and Technology; 2012.</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">«Data-Driven Security: Analysis, Visualization and Dashboards». Authors: Jay Jacobs, Bob Rudis, 2014. ISBN: 978-1-118-78919-1.</mixed-citation><mixed-citation xml:lang="en">«Data-Driven Security: Analysis, Visualization and Dashboards». Authors: Jay Jacobs, Bob Rudis; 2014.</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">MITRE ATT&amp;CK Framework. [Электронный ресурс] – URL: https://attack.mitre.org/ (дата обращения 10.07.2024)</mixed-citation><mixed-citation xml:lang="en">MITRE ATT&amp;CK Framework. [Internet]. Available from: https://attack.mitre.org/ (cited 10.07.2024).</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Howard, J. D., Longstaff, T. A. (1998). A Common Language for Computer Security Incidents. Sandia National Laboratories. [Электронный ресурс] – URL: https://www.sandia.gov/app/uploads/sites/51/2021/05/SAND98-8667.pdf(дата обращения 10.07.2024).</mixed-citation><mixed-citation xml:lang="en">Howard J. D., Longstaff T. A. A Common Language for Computer Security Incidents. Sandia National Laboratories [Internet]. 1998. Available from: https://www.sandia.gov/app/uploads/sites/51/2021/05/SAND98-8667.pdf (cited 10.07.2024).</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru"></mixed-citation><mixed-citation xml:lang="en"></mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
