MODELING OF CRITICAL STATES IN SIEM SYSTEM BASED ON CATASTROPHE THEORY
DOI 10.31673/2412-4338.2025.028289
Abstract
Abstract: A study of the impact of cyber incidents on military information security management systems during the training of military units in training centers was conducted. An analysis of scientific research on the detection of cyber incidents using machine learning methods, which have their advantages and important disadvantages, has been carried out. It was found that the works do not consider the issues of system stability and the forecast of critical transitions of information system security states. The main advantages of using a SIEM system, which allows collecting, aggregating, storing and correlating events generated by a managed infrastructure, were determined. It was found that SIEM systems have significant disadvantages, including malfunction that prevent the detection of important threats, and no prediction of the development of events is carried out, which does not allow assessing future risks. An analysis of the main disadvantages of the SIEM system was conducted and solutions were proposed using a block with the catastrophe theory in the SIEM system. An analysis of modern systems for simulating the dynamics of combat operations in the format of command and staff training exercises in real time has been carried out. The structure of the integrated training system has been determined, as well as the main logical blocks that should be combined using SIEM into a single chain of events. The main components of the integrated training system, their purpose and the role of the SIEM system for responding to cyber incidents to establish data security have been established. An algorithm for detecting unstable system states during cyber incidents using SIEM and catastrophe theory in the integrated training system has been developed, which allows predicting and detecting unstable system states, as well as responding to information leaks in real time, which ensures an increase in the level of cyber resilience of the system.
Keywords: information security management system (ISMS), SIEM system, critical states, catastrophe theory, bifurcation points, cyber incident.