<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Formation of multilevel system to counteract computer attacks</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>Bauman Moscow state technical university</institution>
          ,
          <addr-line>Moscow</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Far Eastern Law Institute of the Ministry of Internal Affairs of Russia</institution>
          ,
          <addr-line>Khabarovsk</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Ryazan state radio engineering university named after V.F. Utkin</institution>
          ,
          <addr-line>Ryazan</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The main trend relating to state structures and large corporations is to build Information Security Monitoring Centers the key elements of which being SIEM-systems and SOC-Centers. Speaking about SOC-Centers the task of human resources optimal allocation among information security incident reporting lines taking into consideration staff competency and line capacity seems to be urgent. This task is solved in the article given. In general, the formulation of the task presented means the functioning of SOC-Center as a new mathematical model making use of “input - resources - output” terms. The target function of SOC-Center is built in an assumption of stationarity and independency of service reporting lines as a sum of their target functions. The main idea of human resources management in this case is the aspiration to achieve maximum significance of SOC-Center system aim, i.e. its general target function when organizing the fight with computer attacks. The problem was solved by Lagrange multiplier method. The expressions for optimal allocation of human resources on SOC-center service lines leading to maximum processing of message flow related to computer attacks have been received. The conclusion about this model being useful for transferring from stationary flows to their dynamic changes in SOC-Center resource provision including new different critical situations in computer system has been made.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Modern state structures being referred as critical ones
as well as geographically distributed intersectoral and
large industrial corporations form complex Information
Security Monitoring Centers (ISMC) [1-3]. The structural
elements of these Centers are represented as the devices to
collect incidents arising in external and internal sources
(user devices, network devices, different systems of
information defense, web-services, etc.) Primary
monitoring segment of ISMC is SIEM – systems. SIEM
(Security Information and Event Management) technology
presupposes automated real-time analysis of security
events in network devices and applications. The next
segment of monitoring, processing and reaction to
information security incidents in ISMC is SOC – center
(Security Operation Center) that receives notifications
about threats from SIEM – system where operators being
qualified employees in the sphere of information security
make decisions concerning the reports about threats.
Mathematical modeling of SIEM – system and SOC –
center functioning processes is of utmost importance to
improve the control of information security in
organizations [2, 3]. This fact is caused by the necessity to
create scientific apparatus allowing to efficiently solve the
problems connected with optimal ISMC resources control,
with evaluation, analysis and forecasting of computer
attacks, etc. The article given considers the model to
optimize SOC-center human resources allocation on
information security incident reporting lines taking into
consideration staff competence and line capacity.</p>
    </sec>
    <sec id="sec-2">
      <title>Materials and methods</title>
      <p>The formulation of management task is as follows.</p>
      <p>Let there be a certain multitude of problems to respond
on information security incidents, for them to be solved
SOC-center needs to have a certain amount of human
resources. Human resources need to be optimally allocated
among service levels (decision making levels) taking into
account a number of limitations.</p>
      <p>ISMC material and technical resources can be
considered in this case as the tools increasing the
realization opportunities of the staff that play the leading
role in the process of problem solution. Particularly,
different level of logistics in corresponding mathematical
models is seen in different parameters reflecting the
efficiency in staff activity of SOC-center that provides the
services on computer attacks incident reporting lines.</p>
      <p>Further let us designate the flow of input reports about
computer incidents as input vector  ⃗, the result of report
processing in SOC-center – as output vector  ⃗,  ⃗
designates the vector of human resources being competent
in decision making referring to computer incidents.
General form in the dependence of output variables vector
from input variables vector as well as human resources
vector is as follows:</p>
      <p>
        ⃗ =  ( ⃗, ⃗) , (
        <xref ref-type="bibr" rid="ref1">1</xref>
        )
meeting the condition: ∑ ==1   =  0, where I – is general
number of SOC-center reporting lines; Ri – the staff that
provides services for i-th line, i = 1,2,..I;  0 – general staff
providing services for all lines.
      </p>
      <p>
        By analogy with production processes described in the
applications of the theory of active systems [4-6] we shall
name the functional connection between acceptable level
of resource costs and input vector, on the one hand, and
output variable extreme values (minimum and maximum)
corresponding to them – on the other hand, as production
or target function:
(
        <xref ref-type="bibr" rid="ref2">2</xref>
        )
=  ( , ) ,
 
when ∑ =1   =  0.
      </p>
      <p>Two main approaches to build target functions –
statistic and optimization – can be mentioned [7, 8]. The
first one is based on statistics dependency recovery. The
second approach is based on generalizing the solutions of
tasks analogous to the ones in other areas as well as
theoretical speculations and assumptions.</p>
      <p>
        The article presented follows the second approach
where mathematical model “costs – results” is given by
introducing target function of the following type:
(
        <xref ref-type="bibr" rid="ref3">3</xref>
        )
  =   (  ,   , µ)
where Fi – the number of attack incidents in i-th line, Ri –
number of employees servicing i-th line, µ – target
function parameters vector in i-th line.
      </p>
      <p>
        We shall assume that function (
        <xref ref-type="bibr" rid="ref3">3</xref>
        ) monotonically
increases in the area 0 &lt; Ri &lt;∞, i.e., the higher SOC-Center
staffing is, the higher the value of target function:
  =     , ∞, µ
=   = 
,
with the function being limited in the upper part (Fig. 1).
These conditions are satisfied by the function of the type:
(
        <xref ref-type="bibr" rid="ref4">4</xref>
        )
(
        <xref ref-type="bibr" rid="ref5">5</xref>
        )
  =   · (1 − exp(−  ∗ ℎ )),
where   – is the coefficient reflecting competency and
professionalism of the staff in i-th SOC line that process
in i-th line.
computer attack incidents; ℎ =   /  – load on the staff
      </p>
      <p>
        The choice of the function being type (
        <xref ref-type="bibr" rid="ref5">5</xref>
        ) is offered in
works [9, 10] to describe the efficiency of fire service
activity depending on the load on firefighters. In our
opinion, when necessary statistical data to build target
function in relation to SOC-Center activity are absent, the
choice of well-adapted, logic and interpreted dependence
is appropriate and justified (
        <xref ref-type="bibr" rid="ref5">5</xref>
        ).
given (
        <xref ref-type="bibr" rid="ref3">3</xref>
        ) and known parameters µ is set as the following
Ф
= 

[∑ ==1   (  ,   , µ)],
(
        <xref ref-type="bibr" rid="ref7">7</xref>
        )
in case when human resources being at SOC – Center
disposal is limited: ∑ =
 =1
It is worth mentioning that the results received in the
work are easily generalized to other options of SOC –
Center organization bearing in mind the number of
reporting lines.
      </p>
      <p>The diagram shows that all reports about computer
attacks entering the first and the second SOC – Center
lines are subdivided into three categories regarding to
which the staff makes one of three decisions: first – the
ones representing no threat for computer system (  );  =
1,2,3; second – repulsed attacks (  );  = 1,2,3; third - the
ones transferred to a more competent and higher level of
decision making (  );  = 1, 2, 3. The third line, the one
where the most competent employees work is supposed to
transfer the reports with no decisions being made to a
special database in the form of  3 flow for further in-depth
examination.</p>
      <p>We shall assume that in a certain period of time a
stationary mode of processing computer attack reports is
seen. Then for three SOC – Center lines the following nine
equations are satisfied:
 1=  1 ·=[1 −1+e xp1(+−   11 ·   1)]
 1=  1 · [1 − exp(−  1 ·   1)]</p>
      <p>
        1 =  2 +  2 +  2
 2=  2 · [1 − exp(−  2 ·  12)] (
        <xref ref-type="bibr" rid="ref8">8</xref>
        )
 2=  2 · [1 − exp(−  2 ·  12)]
 2 =  3 +  3 +  3
      </p>
      <p>·  2 )]
 3=  3 · [1 − exp(−  3  3
 3=  3 · [1 − exp(−  3 ·  23)],
where AY1, AQ1; AY2, AQ2; AY3, AQ3 - constants,
characterizing flow asymptotes that reflect the number of
reports received by line operators having no threats to
computer systems and the number of repulsed attacks
correspondingly. In their turn,   1,   1;   2 ,   2 ;   3,   3
– are the coefficients that reflect competency and
professionalism of employees working on 1st, 2nd, and 3rd
SOC lines to process computer attack reports,
correspondingly. Here, the higher the service line, the
higher the competence.</p>
      <p>The following notations for loads in i-th line of SOC –
center are introduced:</p>
      <p>
        ℎ1 =   1 ; ℎ2 =  12; ℎ3 =  23 (
        <xref ref-type="bibr" rid="ref9">9</xref>
        )
To simplify further calculations we shall expand
exponential expressions from (
        <xref ref-type="bibr" rid="ref8">8</xref>
        ) in Maclaurin series
restricting ourselves to the first two terms for simplicity:
 =  1 +  1 +  1
 1=  1 · [1 − 1 +   1 · ℎ1]
 1=  1 · [1 − 1 +   1 · ℎ1]
      </p>
      <p>1 =  2 +  2 +  2
 2=  2 · [1 − 1 +   2 · ℎ2]
 2=  2 · [1 − 1 +   2 · ℎ2]</p>
      <p>
        2 =  3 +  3 +  3
 3=  3 · [1 − 1 +   3 · ℎ3]
 3=  3 · [1 − 1 +   3 · ℎ3]
Simplifying (
        <xref ref-type="bibr" rid="ref10">10</xref>
        ), we get:
 =  1 +  1 +  1
 1=  1 ·   1 · ℎ1
 1=  1 ·   1 · ℎ1
 1 =  2 +  2 +  2
 2=  2 ·   2 · ℎ2
 2=  2 ·   2 · ℎ2
 2 =  3 +  3 +  3
 3=  3 ·   3 · ℎ3
 3=  3 ·   3 · ℎ3
(
        <xref ref-type="bibr" rid="ref10">10</xref>
        )
(
        <xref ref-type="bibr" rid="ref11">11</xref>
        )
3. Solving the task of human resources optimal
distribution
      </p>
      <p>=3
∑ =1</p>
      <p>+  ·  12 +  ·  23 −  · (∑ ==31   −  0). (22)</p>
      <p>We shall believe that in case of stationary mode
expression (22) is found from ratios:
 ,  1
и  2 – are constant, then conditional extremum of
  
 ( , )</p>
      <p>( , )
=</p>
      <p>= 0; i = 1, 2, 3. (23)</p>
      <p>
        Having done differentiation we come to the system of
equations:
 1 +  1 =  · ℎ1
 2 +  2 =  · ℎ2,
 =   2 ·   2 +   2 ·   2 ,
 3 +  3 =  · ℎ3,
 =   3 ·   3 +   3 ·   3
(
        <xref ref-type="bibr" rid="ref12">12</xref>
        )
(
        <xref ref-type="bibr" rid="ref13">13</xref>
        )
(
        <xref ref-type="bibr" rid="ref14">14</xref>
        )
(
        <xref ref-type="bibr" rid="ref15">15</xref>
        )
(
        <xref ref-type="bibr" rid="ref16">16</xref>
        )
(17)
(20)
(24)
(25)
 ( ,  )
      </p>
      <p>1
 ( ,  )</p>
      <p>2
 ( ,  )
  3
 ( ,  )
= −  ·  12 −  = 0
 122 −  = 0
 2
 32 −  = 0
=</p>
      <p>−  = 0
= −  ·
= −  ·
 =3
 =1
 =3
 =1</p>
      <p>=</p>
      <sec id="sec-2-1">
        <title>From system (24) we obtain:</title>
        <p>12 =  ·  122 =  ·  232</p>
        <p>Equations (25) can easily give expressions for such
human resources allocation on SOC – Center reporting
lines that lead to the maximum processing of computer
attack incident report flow on computing system of the
organization. Namely:</p>
      </sec>
      <sec id="sec-2-2">
        <title>Next we introduce the notation:</title>
        <p>=   1 ·   1 +   1 ·   1
,
 2
· 1 −  .</p>
        <p>
          3
Besides, making use of ratios (
          <xref ref-type="bibr" rid="ref11">11</xref>
          ) we easily show that
        </p>
      </sec>
      <sec id="sec-2-3">
        <title>From (27) we see that</title>
        <p>Besides, (28) leads to inequality fairness:
0 &lt; 
&lt;  1; 0 &lt; 
&lt;  2
; 0 &lt;</p>
        <p>&lt;  3 .
 3 &lt;  2 &lt;  1 &lt; 
(29)</p>
        <p>Taking into consideration the dependences of flows  
from human resources allocation on reporting lines   ;  =
1,2,3, a recursive algorithm to find optimal solution has
been developed. To justify the values of model parameters,
initial conditions and</p>
        <p>asymptotic values the results
received in works [11-15] have been applied in the system
to counteract computer attacks.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>4. Results</title>
      <p>˗
˗
˗
˗</p>
      <p>The model of SCO – center operation being developed
in the article under consideration have allowed us to
describe the
system
of
multilevel computer
attack
reporting service taking into account competency of
employees and capacity of the channels that react to
information
security incidents. Formalization
of the
processes that react to reports about incidents in the model
justified and implemented by the authors allows studying:
efficiency of different allocations in human resources
being at SOC – Center disposal to fight with computer
attacks, viz., to find the allocation with maximum
result in the course of processing the reports about
threats to computing resources and cutting off real
threats from them;
influence</p>
      <p>of such factors as competency and
professionalism
of SOC –</p>
      <p>Center employees in
different service reporting lines on suppression of
computer attacks;
errors of first and second order in each reporting line;
possibilities to justify and transfer from stationary
flows in the model to their dynamic changes including
different critical situations of SOC – Center resource
provision.</p>
    </sec>
    <sec id="sec-4">
      <title>Acknowledgements</title>
      <p>The work has been implemented and published with
the RFBR support, grant 19-07-00445.
management processes of information security //</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Minaev</surname>
            <given-names>V.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bondar</surname>
            <given-names>K.M.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Vaits</given-names>
            <surname>Ye</surname>
          </string-name>
          .V.,
          <string-name>
            <surname>Belyakov</surname>
            <given-names>I.A</given-names>
          </string-name>
          .
          <article-title>Discrete and event modelling of monitoring</article-title>
          and Vestnik of Russian New University.
          <year>2019</year>
          . № 3. - Pp.
          <fpage>32</fpage>
          -
          <lpage>39</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Shaburov</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Borisov</surname>
            <given-names>V.I. Developing</given-names>
          </string-name>
          <article-title>the model of corporate network information protection based on the implementation of SIEM-System /</article-title>
          / Vestnik of PSTU.
          <year>2016</year>
          . № 19. - Pp.
          <fpage>111</fpage>
          -
          <lpage>124</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Zimmerman</surname>
            <given-names>C.</given-names>
          </string-name>
          <article-title>Ten Strategies of a World-Class Cybersecurity Operations Center</article-title>
          .
          <source>The MITRE Corporation, US</source>
          .
          <year>2014</year>
          .
          <article-title>- 334 с</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Novikov</surname>
            <given-names>D.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petrakov</surname>
            <given-names>S.N.</given-names>
          </string-name>
          <article-title>The course of active systems theory</article-title>
          .
          <source>М.: SINTEG</source>
          ,
          <year>1999</year>
          . - 104 p.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Burkov</surname>
            <given-names>V.N.</given-names>
          </string-name>
          <article-title>Foundations of mathematical theory of active systems</article-title>
          .
          <source>- М.: Nauka</source>
          ,
          <year>1977</year>
          . - 255 p.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Burkov</surname>
            <given-names>V.N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kondratiev</surname>
            <given-names>V.V.</given-names>
          </string-name>
          <article-title>Mechanisms of organization system functioning</article-title>
          .
          <source>- М.: Nauka</source>
          ,
          <year>1981</year>
          . - 333 p.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Minaev</surname>
            <given-names>V.A.</given-names>
          </string-name>
          <string-name>
            <surname>Human</surname>
          </string-name>
          <article-title>Resources of the Internal Affairs Bodies: Modern Management Approaches: Monograph</article-title>
          . М.:
          <article-title>Academy of the Ministry of Internal Affairs of the USSR</article-title>
          ,
          <year>1991</year>
          . - 163 p.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Burkov</surname>
            <given-names>V.N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Burkova</surname>
            <given-names>I.V.</given-names>
          </string-name>
          <article-title>Network programming method in target programs management // Automation and telemechanics</article-title>
          .
          <source>2014. № 3</source>
          . - Pp.
          <fpage>73</fpage>
          -
          <lpage>86</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Bessonov</surname>
            <given-names>V.A.</given-names>
          </string-name>
          <article-title>Problems of production functions formation in Russian transitional economy</article-title>
          . М.:
          <article-title>Institute for the economy in transition</article-title>
          ,
          <year>2002</year>
          . - 89 p.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>V.A.</given-names>
            <surname>Minaev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.G.</given-names>
            <surname>Topolskij</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.A.</given-names>
            <surname>Kjeu</surname>
          </string-name>
          .
          <article-title>Criteria management of territorial allocation of the fire service staff</article-title>
          resources in Vietnam // Vestnik of Russian New University. Series:
          <article-title>Complex systems: models, analysis and control</article-title>
          .
          <source>2019. № 2</source>
          . - Pp.
          <fpage>94</fpage>
          -
          <lpage>103</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>V.A.</given-names>
            <surname>Minaev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.G.</given-names>
            <surname>Topolskij</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.A.</given-names>
            <surname>Kjeu</surname>
          </string-name>
          .
          <article-title>Efficiency of territorial allocation of the fire service staff</article-title>
          resources in Vietnam // Technologies of technosphere security.
          <year>2019</year>
          . № 2. - Pp.
          <fpage>63</fpage>
          -
          <lpage>71</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Klimov</surname>
            <given-names>S.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sychyov</surname>
            <given-names>M.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Astrakhov</surname>
            <given-names>A.V.</given-names>
          </string-name>
          <article-title>Counteraction to computer attacks. Methodical bases: E-learning edition</article-title>
          . М.:
          <article-title>Publishing House of MSTU named after</article-title>
          N.E. Bauman,
          <year>2013</year>
          . - 108 p.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>ShaburovA</surname>
          </string-name>
          .S.,
          <string-name>
            <surname>Mironova</surname>
            <given-names>A.A.</given-names>
          </string-name>
          <article-title>The detection of computer attacks based on the functional approach</article-title>
          // Vestnik of Perm university.
          <source>Series: Mathematics. Mechanics. Informatics. 2015. Issue</source>
          <volume>4</volume>
          (
          <issue>31</issue>
          ). - Pp.
          <fpage>110</fpage>
          -
          <lpage>115</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Klimov</surname>
            <given-names>S.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Polovnikov</surname>
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Yu</surname>
          </string-name>
          .
          <article-title>Method to detect computer attacks on critically important information systems</article-title>
          // Issues of information security.
          <year>2016</year>
          . №
          <volume>1</volume>
          (
          <issue>112</issue>
          ). - Pp.
          <fpage>48</fpage>
          -
          <lpage>55</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Shlyapkin</surname>
            <given-names>A.V.</given-names>
          </string-name>
          <article-title>Methods and means to counteract attacks on computer networks // Information systems and technologies: control and security</article-title>
          .
          <source>2014. № 3</source>
          . - Pp.
          <fpage>325</fpage>
          -
          <lpage>338</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>Drobotun</given-names>
            <surname>Ye</surname>
          </string-name>
          .
          <source>B. Theoretical foundations of building security systems from computer attacks on automated control systems: Monograph</source>
          . - Saint
          <string-name>
            <surname>Petersburg</surname>
          </string-name>
          : High technologies,
          <year>2017</year>
          . - 120 p.
          <article-title>Minaev Vladimir A., Doctor in technical sciences</article-title>
          ,
          <source>PhD</source>
          , full professor, Bauman Moscow state technical university. E-mail:
          <article-title>m1va@yandex</article-title>
          .ru. Koryachko Aleksei V.,
          <source>PhD (in technical sciences)</source>
          ,
          <article-title>associate professor, deputy rector</article-title>
          , Ryazan state radio engineering university named after
          <string-name>
            <given-names>V.F.</given-names>
            <surname>Utkin</surname>
          </string-name>
          .
          <article-title>E-mail: akor89@yandex</article-title>
          .ru. Bondar Konstantin M.,
          <source>PhD (in technical sciences)</source>
          ,
          <article-title>associate professor, Far Eastern Law Institute of the Ministry of Internal Affairs of Russia. E-mail: bondar_km@mail</article-title>
          .ru.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>