?
Марковская модель кибератак и ее применение к анализу защищенности информации в автоматизированных системах
The paper presents a description of the Markov model of cyber attacks as a method for analyzing information security in automated systems. Based on the presented model, the work provides a description of two safety metrics - the average time to safety failure (the average number of transitions between states in the corresponding Markov chain before it first enters one of the absorbing states) and the average risk in case of safety failure (the sum of the products of damages during the implementation of each from cyber attacks to the corresponding probabilities of these cyber attacks). An algorithm for estimating input parameters is given based on the relationship between the threat and vulnerability databases CVE, CWE and CAPEC. The relationships described in the work allow us to calculate the vector of probabilities of the occurrence of cyber attacks and the vector of damage from cyber attacks, which are formed as input data for the security assessment model. The paper also addresses the problem of numerical estimation of parameters through CVSS metrics. The study demonstrates that the vector of probabilities of repelling cyber attacks and the vector of probabilities of “delays” of cyber attacks can only be obtained using the method of expert assessments or statistics. The work also provides a description of the developed software product, which allows one to assess the security of an automated system over a given period of time.