<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">oo</journal-id><journal-title-group><journal-title xml:lang="ru">Открытое образование</journal-title><trans-title-group xml:lang="en"><trans-title>Open Education</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">1818-4243</issn><issn pub-type="epub">2079-5939</issn><publisher><publisher-name>Plekhanov Russian University of Economics</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.21686/1818-4243-2021-4-47-54</article-id><article-id custom-type="elpub" pub-id-type="custom">oo-797</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>ПРОБЛЕМЫ ИНФОРМАТИЗАЦИИ ЭКОНОМИКИ И УПРАВЛЕНИЯ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>PROBLEMS OF INFORMATIZATION OF ECONOMICS AND MANAGEMENT</subject></subj-group></article-categories><title-group><article-title>Совершенствование процесса управления инцидентами на основе прецедентного подхода</article-title><trans-title-group xml:lang="en"><trans-title>Improving the Incident Management Process Based on a Use Case Approach</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Микрюков</surname><given-names>А. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Mikryukov</surname><given-names>A. A.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Андрей Александрович Микрюков, к.т.н., доцент кафедры Прикладной информатики и информационной безопасности</p><p>Москва</p></bio><bio xml:lang="en"><p>Andrei A. Mikryukov, Ph.D., Associate Professor of the Department of Applied Informatics and Information Security</p><p>Moscow</p></bio><email xlink:type="simple">mikrukov.aa@rea.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Куулар</surname><given-names>А. В.</given-names></name><name name-style="western" xml:lang="en"><surname>Kuular</surname><given-names>A. V.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Алексина Владимировна Куулар, старший специалист АО «ЦПЛ», аспирант кафедры Прикладной информатики и информационной безопасности</p><p>Москва</p></bio><bio xml:lang="en"><p>Aleksina Vl. Kuular, Senior Specialist Joint-Stock Company «Loyalty Program Center», graduate student of the Department of Applied Informatics and Information Security</p><p>Moscow</p></bio><email xlink:type="simple">kuularalexa@mail.ru</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Российский экономический университет им. Г. В. Плеханова</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Russian University of Economics named G. V. Plekhanova</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2021</year></pub-date><pub-date pub-type="epub"><day>30</day><month>07</month><year>2021</year></pub-date><volume>25</volume><issue>4</issue><fpage>47</fpage><lpage>54</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Микрюков А.А., Куулар А.В., 2021</copyright-statement><copyright-year>2021</copyright-year><copyright-holder xml:lang="ru">Микрюков А.А., Куулар А.В.</copyright-holder><copyright-holder xml:lang="en">Mikryukov A.A., Kuular A.V.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://openedu.rea.ru/jour/article/view/797">https://openedu.rea.ru/jour/article/view/797</self-uri><abstract><p>Целью исследования является совершенствование процесса управления инцидентами. В статье рассмотрен процессный подход к управлению инцидентами при технических сбоях и его основные стадии: обнаружение, реагирование, расследование, устранение, резолюция. На стадиях реагирования и расследования инцидента, а также его устранения имеет место актуальная проблема, заключающаяся в нарушении сроков принятых в Соглашении об уровне услуг (SLA).</p><p>Проведен сравнительный анализ показателей до и после применения предложенного прецедентного подхода. Предложенный алгоритм с использованием базы прецедентов, позволяет снизить количество инцидентов, которые возвращаются на доработку, а также снизить количество инцидентов, срок разрешения которых выходит за рамки принятых согласно SLA. Научная новизна заключается в применении аппарата прецедентного анализа для обработки инцидентов в службе технической поддержки.</p><sec><title>Материалы и методы</title><p>Материалы и методы. Для разрешения вышеописанной проблемы, связанной с нарушением сроков обработки инцидентов принятых в SLA, в статье рассмотрен подход к совершенствованию процесса управления инцидентами на основе прецедентного анализа инцидентов. Применение аппарата прецедентного анализа представляет собой цикл рассуждений на основе прецедентов. По значению степени подобия инциденту выбирается конкретный прецедент и связанный с ним сценарий принятия решения. Метод правдоподобных рассуждений позволяет в качестве интегрированного средства автоматизации решить проблему множественных эскалаций и как следствие снизить число нарушений сроков разрешения инцидентов. Данный подход позволяет повысить эффективность поиска схожих сценариев реагирования на инциденты. Для сравнения и извлечения прецедентов используется метод ближайшего соседа. Данный метод не требует больших вычислительных затрат и обеспечивает требуемую степень достоверности (ошибочности) принятого решения. Применение метода ближайшего соседа основано на расчете степени близости текущей ситуации к прецедентам, сохраненным в базе прецедентов.</p></sec><sec><title>Результаты</title><p>Результаты. Предложенный подход позволил разработать новый алгоритм классификации инцидентов в информационной системе на базе прецедентного и статистического анализа, обеспечивающий снижение сроков реагирования и устранения инцидентов. Проведен анализ статистических данных, сделана оценка эффективности в результате применения алгоритма, основанного на прецедентном анализе. Оценка показала значительное снижение ненужных эскалаций инцидентов на вторую линию поддержки, таким образом, использование базы прецедентов при разрешении инцидентов позволило совершенствовать процесс управления инцидентами.</p></sec><sec><title>Заключение</title><p>Заключение. В ходе проведенного исследования выявлена основная проблема в процессе управления инцидентами – нарушение сроков принятых в SLA. Проведен анализ базового алгоритма управления инцидентами. Обосновано применение метода правдоподобных рассуждений и метода ближайшего соседа. Рассмотрен цикл обновления базы прецедентов и концептуальная модель процесса управления инцидентами. В рамках разработанной концептуальной модели база прецедентов включает в себя решения, принятые экспертами, где используются знания предыдущего опыта для выхода из той или иной ситуации. Реализован алгоритм поиска решения в базе прецедентов. Отличительной особенностью разработанного алгоритма является использование алгоритма распознавания прецедента и поиск похожих образов, содержащихся в базе прецедентов, с использованием метода ближайшего соседа.</p></sec></abstract><trans-abstract xml:lang="en"><p>The purpose of the study is to improve the incident management process. The article considers the process approach to incident management in case of technical failures and its main stages: detection, response, investigation, elimination, resolution. At the stages of response and investigation of the incident, as well as its elimination, there is an urgent problem, which is the violation of the deadlines adopted in the Service Level Agreement (SLA).A comparative analysis of the indicators before and after the application of the proposed use case approach is carried out. The proposed algorithm, applying the base of use cases, allows reducing the number of incidents that are returned for revision, as well as reduce the number of incidents, the resolution period of which exceeds the limits accepted according to the SLA.</p><p>The scientific novelty lies in the use of the case analysis device for incident processing in the technical support service.</p><sec><title>Materials and methods</title><p>Materials and methods. To solve the above problem related to the violation of the deadlines for processing incidents accepted in the SLA, the article considers an approach to improving the incident management process based on the use case analysis of incidents. The use of the case analysis device is a cycle of reasoning based on use cases. By the value of the degree of similarity to the incident, a specific use case and the associated decision-making scenario are selected. The method of plausible reasoning allows us to solve the problem of multiple escalations as an integrated automation tool and, as a result, reduce the number of violations of the deadlines for resolving incidents. This approach allows you to increase the efficiency of finding similar scenarios for responding to incidents. The nearest neighbor method is used to compare and extract use cases. This method does not require large computational costs and provides the required degree of reliability (error) of the decision. The application of the nearest neighbor method is based on calculating the degree of proximity of the current situation to the use cases stored in the base of use cases.</p></sec><sec><title>Results</title><p>Results. The proposed approach allowed us to develop a new algorithm for classifying incidents in the information system based on the use case and statistical analysis, which reduces the response time and eliminates incidents. The analysis of statistical data is carried out; the efficiency is estimated as a result of the application of the algorithm based on the use case analysis. The assessment showed a significant reduction in unnecessary escalations of incidents to the second support line, so the application of the base of use cases in resolving incidents allowed for improving the incident management process.</p></sec></trans-abstract><kwd-group xml:lang="ru"><kwd>автоматизированная информационная система</kwd><kwd>прецедент</kwd><kwd>инцидент</kwd><kwd>служба технической поддержки</kwd><kwd>прецедентный анализ</kwd></kwd-group><kwd-group xml:lang="en"><kwd>automated information system</kwd><kwd>use case</kwd><kwd>incident</kwd><kwd>technical support service</kwd><kwd>use case analysis</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Ян В. Б. ИТ Сервис-менеджмент. Вводный курс на основе ITIL. Издатель: Van Haren Publishing, по заказу ITSMF Netherlands. 303 с.</mixed-citation><mixed-citation xml:lang="en">Yan V. B. IT Service Management. Introductory course based on ITIL. Publisher: Van Haren Publishing, commissioned by ITSMF Netherlands. 303 p.</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Жуков В.Г. Прецедентный анализ информационной безопасности // Вестник СибГАУ. 2013. № 2. С. 19–23.</mixed-citation><mixed-citation xml:lang="en">Zhukov V.G. A precedent analysis of information security. Vestnik SibGAU = Bulletin of SibGAU. 2013; 2: 19-23. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Шаляпин А.А. Модельно-алгоритмическое обеспечение системы прецедентного анализа инцидентов информационной безопасности // Решетневские чтения. 2015. С. 304–306.</mixed-citation><mixed-citation xml:lang="en">Shalyapin A.A. Model-algorithmic support of the system of precedent analysis of information security incidents. Reshetnevskiye chteniya= Reshetnevskie chteniya. 2015: 304-306. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Берман А. Ф. Концепция построения прецедентной экспертной системы // Mатериалы XII Международной научной конференции по вычислительной механике и современным прикладным программным системам. Владимир, 2003. Ч. 2. С. 110–111.</mixed-citation><mixed-citation xml:lang="en">Berman A. F. The concept of constructing a precedent expert system. Materialy XII Mezhdunarodnoy nauchnoy konferentsii po vychislitel’noy mekhanike i sovremennym prikladnym programmnym sistemam = Materials of the XII International Scientific Conference on Computational Mechanics and Modern Applied Programming Systems. Vladimir; 2003;2: 110–111. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Микрюков А.А., Усцелемов В.Н. Построение подсистемы информационной безопасности на основе прецедентного подхода // Научное обозрение. 2013. № 12. С.227–230.</mixed-citation><mixed-citation xml:lang="en">Mikryukov A.A., Ustselemov V.N. Building an information security subsystem based on a precedent approach. Nauchnoye obozreniye = Scientific Review. 2013; 12: 227-230. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Микрюков А.А., Усцелемов В.Н. Модель оценки степени риска информационных угроз в инфокоммуникационных системах на основе нейро-нечеткого вывода // Научное обозрение. 2013. № 12. С. 219–222.</mixed-citation><mixed-citation xml:lang="en">Mikryukov A.A., Ustselemov V.N. A model for assessing the degree of risk of information threats in infocommunication systems based on neuro-fuzzy inference. Nauchnoye obozreniye = Scientific Review. 2013; 12: 219-222. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Микрюков А.А., Усцелемов В.Н. Гибридная модель оценки рисков в информационных системах // Прикладная информатика. 2014. № 1(49). С. 50–55.</mixed-citation><mixed-citation xml:lang="en">Mikryukov A.A., Ustselemov V.N. Hybrid model of risk assessment in information systems. Prikladnaya informatika = Applied Informatics. 2014; 1(49): 50-55. (In Russ.)</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
