?
Математическая модель анализа рисков деструктивных воздействий в информационных системах на основе нечеткой логики
The article proposes a formal apparatus for risk analysis in information systems based on the apparatus of fuzzy logic, graph theory and matrices. A system of definitions is introduced that includes a universe of entities, sets of violators and destructive influences, as well as membership functions describing the fuzzy relationships between them. A risk calculation model is proposed that considers not only the danger of individual threats and the capabilities of intruders, but also the synergy (mutual strengthening or weakening) of threats, which makes it possible to model complex attack scenarios. The nonadditivity of the total risk of the system is proved. For the practical implementation of the model, the concept of a graph of destructive influences is introduced, where vertices represent threats, and weighted arcs reflect their mutual influence. The total risk is defined as the maximum along all paths in the graph, which makes it possible to identify the most dangerous attack chains. The model considers the security of the system and allows us to formalize the process of choosing countermeasures aimed at breaking the most critical paths in the threat graph.