<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Conceptual Approach to the Risk Analysis of Information Technology Security</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Roman S. Anosov</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Sergey S. Anosov</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Igor Yu. Shakhalov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Valentin L. Tsirlov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Bauman Moscow State Technical University</institution>
          ,
          <addr-line>5/1 2nd Baymanskay ul., Moscow, 105005</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>NPO Echelon</institution>
          ,
          <addr-line>24 2nd Electrozavodskaya ul., Moscow, 107023</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>STC Zarya</institution>
          ,
          <addr-line>9 2nd Brestskaya St., bld.1., Moscow, 123056</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>This paper describes the risk-oriented approach to the development of information security systems. The author suggests a concept-based formal model of security risk assessment and analysis for information technologies. It is suggested that the set of mean values of the subject activity integral effects, which determine the degree of its activity compliance with the purposes and regulatory requirements in conditions of information security threats, as the risk level indicator. It is concluded that the system element of information security risk analysis is a set of information, technical, organizational and socio-economic indicators for risk assessment at individual stages of analysis. It is demonstrated that the suggested concept-based approach can be specified in detail in the form of mathematical models.</p>
      </abstract>
      <kwd-group>
        <kwd>3 Risk assessment</kwd>
        <kwd>conceptual model</kwd>
        <kwd>risk management</kwd>
        <kwd>information technology</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        The notion of risk is a key notion in the field of security in general and information security in
particular [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. On the one hand, the information security risk combines the range of issues related to the
information security threats, including identification of the threat sources and vulnerabilities in protected
information technologies, determination of the methods, probability, and potential implications of the
threats. On the other hand, the risk is integrated into the processes of technical and economic analysis and
decision-making related to the information security assurance, creation of facilities and organization of
information technology security system, definition of its composition, architecture, and configuration.
      </p>
      <p>Characteristic features of the information security risk assessment include:
• High dimensions and the resultant labor-intensiveness of the assessment process stemming from
the large number of potential security threats and vulnerabilities in the protected information
technologies.
• Need to assess the risk at every stage of the information technology life cycle starting from the
product definition to its intended use and retirement;
• Need to assess the risk at various levels of the information technology management, including the
risk management and information security audit.</p>
      <p>The risk “deployment” process demonstrated in Figure 1 can be presented as the successive effect
produced by security threats on:
• The processes going on in the information system;
• The processes of the subject’s (data owner’s) activity management;
• The results of activity at the level of individual subjects and at the level of the activity field in
general.</p>
      <p>Relevant indicators are used at each of these risk “deployment” stages, for example:
• Probability of the incident occurrence, information security indicators: confidentiality, integrity,
availability;
• Performance of the information system, ability of the information system to perform its tasks;
• Potential damage of the subject that can be caused by any disruption in its control process;
probability of the damage occurrence.</p>
      <p>
        High dimensions and multiple levels of the risk analysis task explain the wide practical application of
qualitative (heuristic) methods used for its solution. However, the qualitative analysis methods do not
fully suit the existing situation in the IT field which is characterized by the high significance of
information infrastructure, intensive information confrontation, and high information security risks. An
important activity aimed to improve the risk analysis efficiency is the application of formal (qualitative)
methods of analysis based, in particular, on the results of formalization of various processes related to the
information security assurance [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. The formal access control model that provides a rigorous description
of the information flows in the system is the classical representative of such methods [
        <xref ref-type="bibr" rid="ref3 ref4 ref5 ref6 ref7 ref8">3-8</xref>
        ]. Data flow
diagrams (DFD), sequence charts of the Unified Modeling Language (UML), and tree formalism are
used, for example, to model threats when developing secure applications [
        <xref ref-type="bibr" rid="ref10 ref9">9, 10</xref>
        ].
      </p>
      <p>
        Papers [
        <xref ref-type="bibr" rid="ref11 ref12">11, 12</xref>
        ] use the tree and graph formalism to create the threat model. In papers [
        <xref ref-type="bibr" rid="ref13 ref6">6, 13</xref>
        ], the
model of controlled threat occurrence process is developed, including the stages of protection system
study and examination of protection facilities at the selected attack path and implementation of
destructive effects. The dynamics of information security threat occurrence can be modeled using the
Petri-Markov networks, which allows taking into account the parallelism and logical interrelation of
threat occurrence processes. Markov models are also used to study the threats and to select the optimal set
of information protection tools [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ].
      </p>
      <p>
        The formalism of individual processes associated with the information security assurance and specific
stages of the risk analysis serve as the basis for system research. Thus, papers [
        <xref ref-type="bibr" rid="ref15 ref16 ref17 ref18 ref19 ref20 ref21 ref22">15-22</xref>
        ] describes the
procedure for assessment of security risks in critical facilities that includes decomposition of the object
into multiple components, determination of a set of associated threats, calculation of the risk-contributing
potential of the object components considering the risk-reducing potential for protection measures. Paper
[
        <xref ref-type="bibr" rid="ref23">23</xref>
        ] suggests a structured risk analysis using expert assessment and statistical data on information
security incidents. In standard ISO/IEC/IEEE 247654, the hierarchy analysis method providing wide
opportunities for the analysis of multilevel nested structures is used to assess the risk. Papers [
        <xref ref-type="bibr" rid="ref24 ref25 ref26 ref27 ref28">24-28</xref>
        ]
deals with the issues of using fuzzy logic programming to evaluate the extent of damage arising from the
threats to information security. The mathematical tools of Bayes networks are used in papers [
        <xref ref-type="bibr" rid="ref29 ref30">29, 30</xref>
        ] to
build the intelligent (expert) automated system of threat analysis and risk evaluation. Paper [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ] suggests
using the immune systems and cognitive computing to reduce the risks.
      </p>
    </sec>
    <sec id="sec-2">
      <title>2. Rationale for the formal model</title>
      <p>The activity is regarded as a set of  elementary processes. Evey i-th elementary process is
characterized by a set of positive effects  + expressing the degree to which a functional purpose of the
process is achieved and a set of negative effects  − expressing the resource-intensiveness of the process
and side consequences (not relating to the functional purpose) associated with its implementation.</p>
      <p>Each level of activity is a system of serial/parallel elementary processes (operations) formalized by the
graph theory methods. The graph edge corresponds to elementary process   and the neighboring vertices
correspond to the set of input   ⊲ and the set of output effects   ⊳ of this process:</p>
      <p>⊲ =   +⊳,  +⊳, … ,  −⊳,  − ⊳, … , where indices  ,  , … ,  ,  … ∊ ℕ,  ,  , … ,  ,  … &lt;  are the indices
of the processes   ,   ,…,   ,   ,…, whose output effects determine the output effect of the i-th process;
  ⊳ = { +,  −} =   (  ⊲,   ,   ), where   is the set of control parameters of the  -th process,   is
the set of environmental parameters influencing the  -th process,   (∗) is the operation of transforming
the set {  ⊲,   ,   } into the set   ⊳.</p>
      <p>The principle of activity decomposition into elementary processes implies the determination of activity
nodes (time moments or process cycle events) where it is possible to identify uniquely the occurring
effects meeting at least one of the following conditions:
4 "ISO/IEC/IEEE International Standard - Systems and software engineering -- Vocabulary," in ISO/IEC/IEEE 24765:2010(E) , vol., no.,
pp.1418, 15 Dec. 2010, doi: 10.1109/IEEESTD.2010.5733835.</p>
      <sec id="sec-2-1">
        <title>Processes of the subject’s activity</title>
      </sec>
      <sec id="sec-2-2">
        <title>Subjects of activity</title>
      </sec>
      <sec id="sec-2-3">
        <title>Fields (industries) of activity</title>
      </sec>
      <sec id="sec-2-4">
        <title>Process operations</title>
      </sec>
      <sec id="sec-2-5">
        <title>Production processes</title>
      </sec>
      <sec id="sec-2-6">
        <title>Organizational and economical processes</title>
      </sec>
      <sec id="sec-2-7">
        <title>Organizations, enterprises, institutions</title>
      </sec>
      <sec id="sec-2-8">
        <title>Integrated structures</title>
      </sec>
      <sec id="sec-2-9">
        <title>Health care, science, transportation, communication, power generation, banks, fuel and power, nuclear sectors, defense industry, aerospace sector, metals and mining, chemical industry</title>
        <sec id="sec-2-9-1">
          <title>Standard characteristics</title>
        </sec>
      </sec>
      <sec id="sec-2-10">
        <title>Functional and technical characteristics of performed operations</title>
      </sec>
      <sec id="sec-2-11">
        <title>Indicators of the product life cycle, resource-intensiveness, performance, quality, effectiveness, reliability, security</title>
      </sec>
      <sec id="sec-2-12">
        <title>Financial, employment, marketing</title>
        <p>indicators of the processes</p>
      </sec>
      <sec id="sec-2-13">
        <title>Financial, employment, marketing</title>
        <p>indicators of the subjects</p>
      </sec>
      <sec id="sec-2-14">
        <title>Performance indicators in accordance with the target programs, projects, and plans</title>
      </sec>
      <sec id="sec-2-15">
        <title>Social, political, economic, environmental significance, importance for the national defense, national security and public order</title>
        <p>The effects are essential for further activity in accordance with its technology (also in order to form
control actions);</p>
        <p>The effects are essential in terms of compliance with regulatory requirements.</p>
        <p>The accepted approach to presentation of the practical activity as a system of elementary processes is
based on the following assumptions:</p>
        <p>1) At the level of process operations (Table 1), each i-th elementary process is considered to be an
indivisible entity;</p>
        <p>2) The course and result of i-th elementary process depend only on the set of input effects and set of
control parameters;</p>
        <p>3) At other levels of activities, starting from the level of production processes, a certain sequence of
processes of the preceding level to which assumptions 1)…2) apply is considered as the elementary
process.</p>
        <p>Presentation of practical activity as a system of elementary processes and effects is illustrated by
Figure 2.</p>
        <p>Thus, the activity is formalized by a sequence of states of the elementary process system in the effect
space { +,  −}. The states of one activity level can be nested into the states of another level by scalarizing
the effects of the preceding level or operating the state vector (without transforming the effect vector of
preceding level into the scalar effect of the next level. As the result, it becomes possible to perform
successive generalization of the effects of individual process operations as far as the activity effects of the
subject and industry on the whole. In the set of the subject’s (industry’s) activity effects, it is possible to
distinguish the subset of integral effects  Σ ⊂ { +,  −} whose size is used to assess the degree of the
activity compliance with the defined purposes and specified requirements.</p>
        <p>The information processes underpinning the practical activity control take place in the context of
information systems and, more broadly, in the context of the information infrastructure (Table 2).</p>
        <p>Information operations are the procedural analogue of the process operation of practical activities in
the information processes. They are performed by computation and communication information systems
in compliance with preset algorithms and protocols and are aimed to solve the following tasks (refer to
Figure 3):</p>
        <p>Implementation of the abstract model of practical activity in the state space  ;</p>
        <p>Formation of control parameters  ensuring the target path of the practical activity process in the state
space  considering the environmental conditions.</p>
        <p>In the Figure you can see that  is the state of practical activity processes,  are the environmental
parameters,  are control parameters.</p>
        <p>The values of control parameters  =   ( +,   +,  −,   −,  ,   ) are determined by such
information process characteristics as:
• Set of information operations  + provided by the information process algorithms (protocols);
• The probability that the i-th foreseen operation will be performed,   + ∊   +;
• Set of unforeseen (abnormal) operations  − which can be performed in the information system
under the influence of internal factors or environment;
• The probability that the i-th unforeseen operation will be performed,   − ∊   −;
• Quality parameter (degree of completion) of the i-th operation   ∊  ;
• Duration of the i-th operation implementation    ∊   = {  +,   −}.</p>
        <p>The set of values of information process characteristics  = { +,   +,  −,   −,  ,   } can be put into
correspondence with the set of characteristics (properties) peculiar to the processed information including
such classical properties as confidentiality, integrity, availability.</p>
        <p>The standard procedural approach to the information process analysis suggests its presentation on
several layers. Thus, the following layers are considered in computational information systems:
application programming language, operating system, instruction set architecture, microarchitecture,
digital logic layer. In communication information systems, such layers include the application layer,
presentation layer, session layer, transport layer, network layer, channel layer, and physical layer. In
databases, the conceptual, logical, and physical presentation layers are distinguished, each of which uses
specific data presentation models.</p>
        <p>The elementary information operation  of the information process is considered in this model as a set
including the input data  , instruction  for the input data processing, and the operation execution result
 :  = { ,  ,  } (Figure 4).</p>
        <p>Structurally, the information process is defined by the precedence relation (or consequence relation) 
specified on the set of information operations  : i-th operation   precedes the j-th operation   ,      ,
if the result of the i-th operation execution is used as the input data for the j-th operation. In general,
instruction  of the operation can depend on the results of one or several preceding operations, which is
formally specified by the influence relation  in the set  : i-th operation   influences the j-the operation
  ,      , if the result of the i-th operation execution determines the instruction of the j-th operation.</p>
        <p>The information processes are implemented using the information technology system described in
Table 3.</p>
        <p>This information technology system is a means of influencing the H characteristics of information
processes by the subjects A determining its content. Subject А is considered a source of threat if its
actions have the potential to cause an information security incident – occurrence of one or several
unintended information operations out of the set  − – or affect the effectiveness of foreseen operations
implementation assessed in compliance with the indicators of set { ,   +}. It is convenient to show the
correlation between the threats and the information technologies by which the threats can be implemented
(Table 4) using a binary matrix (  , ):   , = 1, if the j-th information technology can be used to
implement the i-th threat;   , = 0, if the j-th information technology cannot be used to implement the
ith threat.
information process parameters  and, consequently, control parameters  and effects of practical
activity  . The use of protective technologies is aimed to prevent the mean values of integral effects  Σ
from falling beyond the limits of permissible range  ∗Σ in the presence of information security threats.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Conclusion</title>
      <sec id="sec-3-1">
        <title>Tools for protection from unauthorized access;</title>
      </sec>
      <sec id="sec-3-2">
        <title>Antivirus protection tools;</title>
      </sec>
      <sec id="sec-3-3">
        <title>Cryptographic protection tools;</title>
      </sec>
      <sec id="sec-3-4">
        <title>Tools of information availability assurance</title>
      </sec>
      <sec id="sec-3-5">
        <title>Identification and authentication;</title>
      </sec>
      <sec id="sec-3-6">
        <title>Access control;</title>
      </sec>
      <sec id="sec-3-7">
        <title>Antivirus protection;</title>
      </sec>
      <sec id="sec-3-8">
        <title>Integrity assurance</title>
      </sec>
      <sec id="sec-3-9">
        <title>Availability assurance;</title>
      </sec>
      <sec id="sec-3-10">
        <title>Equipment protection;</title>
      </sec>
      <sec id="sec-3-11">
        <title>Personnel training</title>
      </sec>
      <sec id="sec-3-12">
        <title>Security monitoring (analysis) tools;</title>
      </sec>
      <sec id="sec-3-13">
        <title>Management tools for information security events;</title>
      </sec>
      <sec id="sec-3-14">
        <title>Intrusion detection systems;</title>
      </sec>
      <sec id="sec-3-15">
        <title>Data leak protection tools</title>
      </sec>
      <sec id="sec-3-16">
        <title>Security audit;</title>
      </sec>
      <sec id="sec-3-17">
        <title>Incident management;</title>
      </sec>
      <sec id="sec-3-18">
        <title>Asset management;</title>
      </sec>
      <sec id="sec-3-19">
        <title>Risk management</title>
        <sec id="sec-3-19-1">
          <title>Problem-solving methods</title>
        </sec>
      </sec>
      <sec id="sec-3-20">
        <title>Formal access control</title>
        <p>models; formal models of
integrity and availability;</p>
      </sec>
      <sec id="sec-3-21">
        <title>Discrete programming methods</title>
      </sec>
      <sec id="sec-3-22">
        <title>Operation analysis methods</title>
      </sec>
      <sec id="sec-3-23">
        <title>Optimization methods;</title>
      </sec>
      <sec id="sec-3-24">
        <title>Game theory methods</title>
      </sec>
      <sec id="sec-3-25">
        <title>System analysis methods</title>
        <p>The suggested model briefly outlines the stages of the information security risk “deployment”. The set
of mean values of the subject’s activity integral effects  Σ, which determine the degree of its activity
compliance with the purposes and regulatory requirements in conditions of information security threats is
used as the risk level indicator. Using  Σ as the risk level indicator allows taking into account both the
extent of potential consequences of the information security threat occurrence and the probability of
occurrence of such consequences. The risk is analyzed in accordance with the suggested model by solving
successively the following tasks:</p>
        <p>1) Analysis of threats to information security and development of a threat model. This task
investigates the sources of threats, causes and probability of their occurrence; possibility and ways of the
threat occurrence considering the applied information technologies are studied.</p>
        <p>2) Analysis of the threat consequences by information indicators. This task investigates the impact of
information security incidents on the efficiency of processes implemented by information technology, as
well as on the quality of the information system operation on the whole.</p>
        <p>3) Analysis of the threat occurrence consequences by organizational and technical indicators. This task
includes the study of the effect the quality of information system operation produces on the control of
automated processes in production and organizational activities.</p>
        <p>4) Analysis of the threat consequences by social and economic indicators. This task is solved by
investigating the influence of production and organizational activity effectiveness on integral indicators
 Σ characterizing the degree of the activity compliance with its purposes and regulatory requirements.</p>
        <p>5) Development of an information security system. This task is performed to investigate the
possibility, ways, and facilities for achieving admissible values  ∗Σ by countering the threats to
information security. Comparative assessment of the information security system development
alternatives is carried out based on the complex indicator { ∗Σ,  }, including the life cycle cost  of the
information security system.</p>
        <p>The essential element of the information security risk analysis is the complex of information,
technical, organizational, social, and economic indicators that ensure the risk evaluation at specific stages
of analysis.
4. References</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>Probabilistic</given-names>
            <surname>Modeling</surname>
          </string-name>
          in System Engineering/By ed. A.
          <string-name>
            <surname>Kostogryzov</surname>
          </string-name>
          . -London: IntechOpen,
          <year>2018</year>
          . 278 p. DOI:
          <volume>10</volume>
          .5772/intechopen.71396.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Markov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rautkin</surname>
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Luchin</surname>
            <given-names>D.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <article-title>"Evolution of a radio telecommunication hardware-software certification paradigm in accordance with information security requirements,"</article-title>
          <source>2015 International Siberian Conference on Control and Communications (SIBCON)</source>
          ,
          <year>2015</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          , doi: 10.1109/SIBCON.
          <year>2015</year>
          .
          <volume>7147139</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Anisimov</surname>
            <given-names>V.G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zegzhda P.D.</surname>
          </string-name>
          ,
          <string-name>
            <surname>Anisimov</surname>
            <given-names>E.G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bazhin</surname>
            <given-names>D.A.</given-names>
          </string-name>
          <article-title>A risk-oriented approach to the control arrangement of security protection subsystems of information systems</article-title>
          .
          <source>Automatic Control and Computer Sciences</source>
          .
          <year>2016</year>
          . V.
          <volume>50</volume>
          . No 8. P.
          <volume>717</volume>
          -
          <fpage>721</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Kostogryzov</surname>
            <given-names>A.I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stepanov</surname>
            <given-names>P.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nistratov</surname>
            <given-names>A.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nistratov</surname>
            <given-names>G.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zubarev</surname>
            <given-names>I.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Grigorev</surname>
            <given-names>L.I.</given-names>
          </string-name>
          <article-title>Analytical modelling operation processes of composed and integrated information systems on the principles of system engineering</article-title>
          .
          <source>Journal of Polish Safety and Reliability Association</source>
          .
          <year>2016</year>
          . V.
          <article-title>7</article-title>
          . No 1. P.
          <volume>157</volume>
          -
          <fpage>166</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Kostogryzov</surname>
            <given-names>A.I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stepanov</surname>
            <given-names>P.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nistratov</surname>
            <given-names>G.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nistratov</surname>
            <given-names>A.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Grigoriev</surname>
            <given-names>L.I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Atakishchev</surname>
            <given-names>O.I.</given-names>
          </string-name>
          <article-title>Innovative management based on risks prediction</article-title>
          .
          <source>In: Information Engineering and Education Science</source>
          .
          <year>2014</year>
          . P.
          <volume>159</volume>
          -
          <fpage>166</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Petrenko</surname>
            <given-names>A.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petrenko</surname>
            <given-names>S.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Makoveichuk</surname>
            <given-names>K.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Olifirov</surname>
            <given-names>A.A.</given-names>
          </string-name>
          <article-title>Methodological recommendations for the cyber risks management</article-title>
          .
          <source>In: CEUR Workshop Proceedings. (DLT 2020 - Selected Papers of the 5th International Scientific and Practical Conference Distance Learning Technologies)</source>
          .
          <year>2021</year>
          . P.
          <volume>234</volume>
          -
          <fpage>247</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Markov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Barabanov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V</given-names>
          </string-name>
          .
          <article-title>Models for Testing Modifiable Systems</article-title>
          . In Book:
          <article-title>Probabilistic Modeling in System Engineering</article-title>
          , by ed.
          <source>A.Kostogryzov. IntechOpen</source>
          ,
          <year>2018</year>
          , Chapter
          <issue>7</issue>
          , pp.
          <fpage>147</fpage>
          -
          <lpage>168</lpage>
          . DOI:
          <volume>10</volume>
          .5772/intechopen.75126.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Markov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Barabanov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V</given-names>
          </string-name>
          .
          <article-title>Periodic Monitoring and Recovery of Resources in Information Systems</article-title>
          . In Book:
          <article-title>Probabilistic Modeling in System Engineering</article-title>
          , by ed.
          <source>A.Kostogryzov. IntechOpen</source>
          ,
          <year>2018</year>
          , Chapter
          <issue>10</issue>
          , pp.
          <fpage>213</fpage>
          -
          <lpage>231</lpage>
          . DOI:
          <volume>10</volume>
          .5772/intechopen.75232.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>K.</given-names>
            <surname>Labunets</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Massacci</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Paci</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Marczak and F. M. de Oliveira</surname>
          </string-name>
          ,
          <article-title>"</article-title>
          [Journal First]
          <article-title>Model Comprehension for Security Risk Assessment: An Empirical Comparison of Tabular vs</article-title>
          .
          <source>Graphical Representations," 2018 IEEE/ACM 40th International Conference on Software Engineering (ICSE)</source>
          ,
          <year>2018</year>
          , pp.
          <fpage>395</fpage>
          -
          <lpage>395</lpage>
          , doi: 10.1145/3180155.3182511.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>M. J. M. Chowdhury</surname>
          </string-name>
          ,
          <article-title>"Security risk modelling using SecureUML," 16th Int'l Conf</article-title>
          .
          <source>Computer and Information Technology</source>
          ,
          <year>2014</year>
          , pp.
          <fpage>420</fpage>
          -
          <lpage>425</lpage>
          , doi: 10.1109/ICCITechn.
          <year>2014</year>
          .
          <volume>6997358</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>P.</given-names>
            <surname>Ongsakorn</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Turney</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Thornton</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Nair</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Szygenda</surname>
          </string-name>
          and
          <string-name>
            <given-names>T.</given-names>
            <surname>Manikas</surname>
          </string-name>
          ,
          <article-title>"Cyber threat trees for large system threat cataloging and analysis,"</article-title>
          <source>2010 IEEE International Systems Conference</source>
          ,
          <year>2010</year>
          , pp.
          <fpage>610</fpage>
          -
          <lpage>615</lpage>
          , doi: 10.1109/SYSTEMS.
          <year>2010</year>
          .
          <volume>5482351</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>J.</given-names>
            <surname>Straub</surname>
          </string-name>
          ,
          <article-title>"Modeling Attack, Defense and Threat Trees and the Cyber Kill Chain, ATT&amp;CK and STRIDE Frameworks as Blackboard Architecture Networks,"</article-title>
          <source>2020 IEEE International Conference on Smart Cloud (SmartCloud)</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>148</fpage>
          -
          <lpage>153</lpage>
          , doi: 10.1109/SmartCloud49737.
          <year>2020</year>
          .
          <volume>00035</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Kalinin</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Krundyshev</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zegzhda</surname>
            <given-names>P</given-names>
          </string-name>
          .
          <article-title>Cybersecurity risk assessment in smart city infrastructures</article-title>
          .
          <source>Machines</source>
          .
          <year>2021</year>
          . V.
          <article-title>9</article-title>
          . No 4. pp.
          <fpage>437</fpage>
          -
          <lpage>442</lpage>
          . DOI:
          <volume>10</volume>
          .3390/machines9040078.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>E. V.</given-names>
            <surname>Larkin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V. V.</given-names>
            <surname>Kotov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. N.</given-names>
            <surname>Ivutin</surname>
          </string-name>
          and
          <string-name>
            <given-names>A. G.</given-names>
            <surname>Troshina</surname>
          </string-name>
          ,
          <article-title>"Petri-Markov model of interruptions,"</article-title>
          <source>2017 6th Mediterranean Conference on Embedded Computing (MECO)</source>
          ,
          <year>2017</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          , doi: 10.1109/MECO.
          <year>2017</year>
          .
          <volume>7977249</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Massel</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gaskova</surname>
            <given-names>D</given-names>
          </string-name>
          .
          <article-title>Identification of critical objects in reliance on cyber threats in the energy sector</article-title>
          .
          <source>Acta Polytechnica Hungarica</source>
          .
          <year>2020</year>
          . V.
          <volume>17</volume>
          . No 8. P.
          <volume>61</volume>
          -
          <fpage>73</fpage>
          . DOI:
          <volume>10</volume>
          .12700/APH.17.8.
          <year>2020</year>
          .
          <volume>8</volume>
          .5.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Olifirov</surname>
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Makoveichuk</surname>
            <given-names>K.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petrenko</surname>
            <given-names>S.A.</given-names>
          </string-name>
          <article-title>Integration of cyber security into the smart grid operational risk management system</article-title>
          .
          <source>CEUR Workshop Proceedings</source>
          .
          <year>2019</year>
          . V.
          <volume>2522</volume>
          , pp.
          <fpage>132</fpage>
          -
          <lpage>144</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Petrenko</surname>
            <given-names>S.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Makoveichuk</surname>
            <given-names>K.A.</given-names>
          </string-name>
          <article-title>Ontology of Cyber Security of Self-Recovering Smart GRID</article-title>
          .
          <source>CEUR Workshop Proceedings</source>
          ,
          <year>2017</year>
          . V.
          <year>2081</year>
          , pp.
          <fpage>98</fpage>
          -
          <lpage>106</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>V.</given-names>
            <surname>Mokhor</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Honchar</surname>
          </string-name>
          and
          <string-name>
            <given-names>A.</given-names>
            <surname>Onyskova</surname>
          </string-name>
          ,
          <article-title>"Cybersecurity Risk Assessment of Information Systems of Critical Infrastructure Objects,"</article-title>
          2020 IEEE International Conference on Problems of Infocommunications. Science and
          <string-name>
            <surname>Technology (PIC S&amp;T)</surname>
          </string-name>
          ,
          <year>2020</year>
          , pp.
          <fpage>19</fpage>
          -
          <lpage>22</lpage>
          , doi: 10.1109/PICST51311.
          <year>2020</year>
          .
          <volume>9467957</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Butusov</surname>
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Romanov</surname>
            <given-names>A</given-names>
          </string-name>
          .
          <article-title>Methodology of security assessment automated systems as objects critical information infrastructure</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          .
          <source>2018. No</source>
          <volume>1</volume>
          (
          <issue>25</issue>
          ), pp.
          <fpage>2</fpage>
          -
          <lpage>10</lpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2018-1-2-10.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Livshitz</surname>
            <given-names>I.I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lontsikh</surname>
            <given-names>P.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lontsikh</surname>
            <given-names>N.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kunakov</surname>
            <given-names>E.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Drolova</surname>
            <given-names>E.Y.</given-names>
          </string-name>
          <article-title>Implementation and auditing of risk management for the oil and gas company</article-title>
          .
          <source>In: Proceedings of the 2017 International Conference "Quality Management, Transport and Information Security, Information Technologies"</source>
          ,
          <source>IT and QM and IS</source>
          <year>2017</year>
          .
          <year>2017</year>
          . P.
          <volume>539</volume>
          -
          <fpage>543</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Livshic</surname>
            <given-names>I.I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Podolyanets L</surname>
          </string-name>
          .
          <article-title>A. Models of complex industrial facilities assessment based on risk approach</article-title>
          .
          <source>International Review of Management and Marketing</source>
          .
          <year>2016</year>
          . V.
          <article-title>6</article-title>
          . No 5. P.
          <volume>125</volume>
          -
          <fpage>135</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <surname>Kalashnikov</surname>
            <given-names>A.O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Anikina</surname>
            <given-names>E.V.</given-names>
          </string-name>
          <article-title>Management of risks for complex computer network</article-title>
          .
          <source>Communications in Computer and Information Science</source>
          .
          <year>2020</year>
          . V. 1337. P.
          <volume>144</volume>
          -
          <fpage>157</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>A.</given-names>
            <surname>Kozlov</surname>
          </string-name>
          and
          <string-name>
            <given-names>N.</given-names>
            <surname>Noga</surname>
          </string-name>
          ,
          <article-title>"Some Method of Complex Structures Information Security Risk Assessment in Conditions of Uncertainty," 2020 13th International Conference "Management of large-scale system development"</article-title>
          <source>(MLSD)</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>5</lpage>
          , doi: 10.1109/MLSD49919.
          <year>2020</year>
          .
          <volume>9247662</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>I.V.</given-names>
            <surname>Anikin</surname>
          </string-name>
          ,
          <article-title>"Using fuzzy logic for vulnerability assessment in telecommunication network,"</article-title>
          <source>2017 International Conference on Industrial Engineering, Applications and Manufacturing (ICIEAM)</source>
          ,
          <year>2017</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          , doi: 10.1109/ICIEAM.
          <year>2017</year>
          .
          <volume>8076444</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>P. B.</given-names>
            <surname>Khorev</surname>
          </string-name>
          and
          <string-name>
            <surname>M. I. Zheltov</surname>
          </string-name>
          ,
          <article-title>"Assessing Information Risks When Using Web Applications Using Fuzzy Logic,"</article-title>
          2020
          <string-name>
            <given-names>V</given-names>
            <surname>International</surname>
          </string-name>
          <article-title>Conference on Information Technologies in Engineering Education ( Inforino</article-title>
          ),
          <year>2020</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          , doi: 10.1109/Inforino48376.
          <year>2020</year>
          .
          <volume>9111767</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>N.</given-names>
            <surname>Khokhlov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Kanavin</surname>
          </string-name>
          and
          <string-name>
            <given-names>A.</given-names>
            <surname>Rybokitov</surname>
          </string-name>
          ,
          <article-title>"Modeling Information Security Infringements in Mobile Self Organizing Network of Communication Using Fuzzy Logic and Theory of Graphs,"</article-title>
          <source>2019 1st International Conference on Control Systems, Mathematical Modelling, Automation and Energy Efficiency (SUMMA)</source>
          ,
          <year>2019</year>
          , pp.
          <fpage>60</fpage>
          -
          <lpage>63</lpage>
          , doi: 10.1109/SUMMA48161.
          <year>2019</year>
          .
          <volume>8947572</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <surname>Markov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V</given-names>
          </string-name>
          .
          <article-title>Simulation of Software Security Tests by Soft Computational Methods</article-title>
          .
          <source>In Proceedings of the VIth International Workshop 'Critical Infrastructures: Contingency Management, Intelligent, Agent-Based, Cloud Computing and Cyber Security' (IWCI</source>
          <year>2019</year>
          ).
          <source>(March 17-24</source>
          , 2019 in Irkutsk, Baikalsk, Russia).
          <source>Advances in Intelligent Systems Research</source>
          vol.
          <volume>169</volume>
          . Pp.
          <volume>257</volume>
          -
          <fpage>261</fpage>
          . DOI:
          <volume>10</volume>
          .2991/iwci-
          <fpage>19</fpage>
          .
          <year>2019</year>
          .
          <volume>45</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <surname>Glushenko</surname>
            <given-names>S.A.</given-names>
          </string-name>
          <article-title>An adaptive neuro-fuzzy inference system for assessment of risks to an organization's information security</article-title>
          .
          <source>Business Informatics</source>
          ,
          <year>2017</year>
          , no.
          <volume>1</volume>
          (
          <issue>39</issue>
          ), pp.
          <fpage>68</fpage>
          -
          <lpage>77</lpage>
          . DOI:
          <volume>10</volume>
          .17323/1998-
          <fpage>0663</fpage>
          .
          <year>2017</year>
          .
          <volume>1</volume>
          .68.77.
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>E. D.</given-names>
            <surname>Shishkina</surname>
          </string-name>
          ,
          <article-title>"Bayesian networks as probabilistic graphical model for economical risk assessment,"</article-title>
          <source>2015 XVIII International Conference on Soft Computing and Measurements (SCM)</source>
          ,
          <year>2015</year>
          , pp.
          <fpage>24</fpage>
          -
          <lpage>26</lpage>
          , doi: 10.1109/SCM.
          <year>2015</year>
          .
          <volume>7190400</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>N.</given-names>
            <surname>Poluektova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Klebanova</surname>
          </string-name>
          and
          <string-name>
            <given-names>L.</given-names>
            <surname>Guryanova</surname>
          </string-name>
          ,
          <article-title>"Risk Assessment of Corporate Infocommunication Systems Projects Using Bayesian Networks," 2018 International Scientific-Practical Conference Problems of Infocommunications</article-title>
          . Science and
          <string-name>
            <surname>Technology (PIC S&amp;T)</surname>
          </string-name>
          ,
          <year>2018</year>
          , pp.
          <fpage>31</fpage>
          -
          <lpage>34</lpage>
          , doi: 10.1109/INFOCOMMST.
          <year>2018</year>
          .
          <volume>8632150</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <surname>Sergei</surname>
            <given-names>Petrenko</given-names>
          </string-name>
          ,
          <article-title>"2 Mathematical Framework for Immune Protection of Industry 4.0," in Developing a Cybersecurity Immune System for Industry 4</article-title>
          .0 ,
          <string-name>
            <surname>River</surname>
            <given-names>Publishers</given-names>
          </string-name>
          ,
          <year>2020</year>
          , pp.
          <fpage>67</fpage>
          -
          <lpage>176</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <surname>Anosov</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Anosov</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shakhalov</surname>
            <given-names>I</given-names>
          </string-name>
          .
          <article-title>Formalized Risk-Oriented Model of the Information Technology System</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          ,
          <year>2020</year>
          , No
          <volume>5</volume>
          (
          <issue>39</issue>
          ), pp.
          <fpage>69</fpage>
          -
          <lpage>76</lpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2020-05-69-76
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [33]
          <string-name>
            <surname>Anosov</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Anosov</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shakhalov</surname>
            <given-names>I</given-names>
          </string-name>
          .
          <source>Conceptual Model Of Information Technology Security Risk Analysis. [Cybersecurity issues]</source>
          ,
          <year>2020</year>
          , No
          <volume>2</volume>
          (
          <issue>36</issue>
          ), pp.
          <fpage>2</fpage>
          -
          <lpage>10</lpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2020-2-
          <fpage>02</fpage>
          - 10.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>