<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>ORCID:</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>The Estimation of Probabilistic Risks for the Performance of System Human Resource Management Process</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Andrey I. Kostogryzov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Roman Yu. Avdonin</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andrey A. Nistratov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Federal Research Center “Computer Science and Control” of the Russian Academy of Sciences</institution>
          ,
          <addr-line>44/2 Vavilova Street., Moscow, 119333</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2021</year>
      </pub-date>
      <volume>000</volume>
      <fpage>0</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>The approach for estimation of probabilistic risks for the performance of system human resource management process considering information security requirements is proposed. The recommended models for risks prediction are described. The use of the proposed approach helps to identify "bottlenecks", reduce risks in system human resource management process, justify conditions and period, in which guarantees of risks retention within admissible limits are maintained, taking into account the requirements for system information security. The usability of the approach is illustrated by examples.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Analysis</kwd>
        <kwd>system information security</kwd>
        <kwd>model</kwd>
        <kwd>risk</kwd>
        <kwd>human resource management process</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
    </sec>
    <sec id="sec-2">
      <title>2. General propositions</title>
      <p>In general, the main output of the human resource management process are information and
nonmaterial results. The information results of management include plan for managing system human
resource and personnel selection plans, personnel database, employment contracts, plans and reports
on the implementation of projects. In turn, the non-material results include directly qualified and
motivated personnel assigned to the relevant positions, acquired skills, publicly available knowledge,
staff satisfaction with work, the level of staff turnover that meets the needs of the enterprise in
employees, an acceptable socio-psychological climate at the enterprise, the required level of safety,
quality and efficiency of the system and the innovative potential of the enterprise (connected with
human resource) etc.</p>
      <p>In the life cycle of systems, both the reliable performance of the human resource management
process itself and the system information security proper to this process should be ensured.</p>
      <p>To predict proper risks the approach for modeling human resource management process is
proposed below.</p>
    </sec>
    <sec id="sec-3">
      <title>3. The recommendations for modeling</title>
      <p>To predict the risks for a given prognostic time  it is proposed to use the following quantitative
probabilistic measures:</p>
      <p>human( ) − the probability of failure in reliable perform human resource management process
without consideration of system information security;
 sec( ) − the probability of violating system information security requirements;
 int ( ) − the integral probability of failure in reliable perform human resource management
process considering system information security.</p>
      <p>To calculate the risk measures, the entities under study can be considered as a system of simple or
complex structure. Models and methods for risks prediction use data obtained "upon the occurrence of
events", according to the identified prerequisites for the occurrence of events, and data collected and
accumulated statistics and possible conditions for their implementation of the process.</p>
      <p>A simple structure system for modeling is a system consisting of a single element or a set of
elements logically combined for analysis as a single element. The analysis of a simple structure
system is carried out according to the «Black box" principle, when the inputs and outputs are known,
but the internal details of the system operation are unknown. A system of a complex structure for
modeling is represented as a set of interacting elements, each of which is represented as a «Black
box" operating under conditions of uncertainty.</p>
      <p>
        The modeling is based on using concept of the probabilities of "success" and/or "unsuccess" (risk
of "failure" considering consequences) during the given prognostic time period. There are
recommended some «Black box” models for which probabilistic space (Ω, B, P) is created (see for
example [
        <xref ref-type="bibr" rid="ref1 ref14 ref16 ref3 ref6 ref8">1, 3, 6, 8, 14, 16</xref>
        ] etc.), where: Ω - is a limited space of elementary events; B – a class of all
subspace of Ω-space, satisfied to the properties of σ-algebra; P – is a probability measure on a space
of elementary events Ω. Because, Ω={ωk} is limited, there is enough to establish a reflection ωk→pk
=P(ωk) like that pk≥0 and ∑ pk = 1. Using these probabilistic models the measures  human( ) and
k
 sec( ) can be estimated considering uncertainty conditions, periodical diagnostics, monitoring
between diagnostics, recovery of the lost integrity for «Black box”.
      </p>
      <p>
        Applicable models for predicting such different risks, including the ways for generating models for
complex system with parallel or serial structure in the part of system human resource management
process, see in [
        <xref ref-type="bibr" rid="ref1 ref14 ref16 ref3 ref6 ref8">1, 3, 6, 8, 14, 16</xref>
        ]. These models can be used for an estimation of the probabilistic
risks proposed.
      </p>
    </sec>
    <sec id="sec-4">
      <title>4. Estimation of measures</title>
      <p>
        From engineering point of view the modelled system may be presented as “Black box” an as
complex system composed from «Black box” elements. There may be two cases for estimating the
probability of failure in “successful” operation of the j-th composing element (j ≥ 1) during given
prognostic time: the case of observed repeatability and the case of assumed repeatability of random
events [
        <xref ref-type="bibr" rid="ref1 ref14 ref16 ref6 ref8">1, 6, 8, 14, 16</xref>
        ].
4.1.
      </p>
    </sec>
    <sec id="sec-5">
      <title>The observed repeatability</title>
      <p>According to observed repeatability the inputs for the calculations of  human  ( ) and/or
 sec  ( ) (denoted below as  fai  (  )) use statistical data. Failure to perform the necessary actions
of the j-th composing system is a threat of possible damage. From the point of view of the
composition of actions and/or the severity of possible damage, all varieties of the actions can be
divided into K groups, K ≥ 1 (if necessary). Based on the statistical data, the probability of failure to
perform the actions of the j-th composing system element for the k-th group for a given time (it also
may be related to  human  ( ) or  sec  ( ) ) may be calculated by the formula
 act  (  ) =  failure  (  )/  (  ),
(1)
(2)
where  failure  (  ) ,   (  )- are accordingly, the number of cases of failures when performing
the necessary actions of the j-th composing system element and the total number of necessary actions
from the k-th group to be performed in a given time   .</p>
      <p>The probability  fai  (  ) of failure in “successful” operation of the j-th composing system
element during a given prognostic period   is proposed to be estimated for the option when only
those cases are taken into account for which the actions were not performed properly (they are the real
cause of the damage):</p>
      <p>fai  (  ) = 1 − ∑ =1   [1 −  
 (  )]  (α )⁄∑ =1   ,
where   is the maximum time for the j-th composing system element operation, including all
particular values   for the entire set of actions from different groups, taking into account their
overlaps;</p>
      <p>taken into account:</p>
      <p>− is the quantity of actions for the j-th composing system element from the k-th group taken
into account for multiple performances of the actions.</p>
      <p>For the k-th group the requirement to perform the actions using the indicator function  (α ) is
 (α) =
1, if condition α is peformed,
0, if condition α isn′t peformed.
performing the necessary actions from the k-th group.</p>
      <p>The condition α used in the indicator function is formed by the analysis of different specific
conditions, proper to the j-th composing system element operation (defined in terms of system quality,
safety, effectiveness etc.). It allows to take into account the consequences associated with the failure
to perform the necessary actions – see (1), (2). Condition α means a set of conditions for all process
actions, subject to quality, safety, effectiveness etc. and time constraints within the given time   for
4.2.</p>
    </sec>
    <sec id="sec-6">
      <title>The «Black box» formalization</title>
      <p>As modelled system (concerning a formalization of human resource management process) there
are considered as «Black box” with virtual random events affecting system operation – for estimating
 
( ) and/or</p>
      <p>( ) in modelled system, presented as one element.</p>
      <p>In general case “successful” modelled system operation is connected with counteraction against
various dangerous influences on system integrity - these may be counteractions against human
failures or “human factors” events in actions on time line.</p>
      <p>There are proposed the formalization for the general technology of counteraction against various
dangerous influences on system integrity. The technology is based on periodical diagnostics of system
integrity, that is carried out to detect danger sources penetration into a system or consequences of
negative influences (see Figure 1). The lost system integrity can be detected only as a result of
diagnostics, after which the system recovery is started. Dangerous influence on system is acted
stepby step: at first a danger source penetrates into the system and then after its activation begins to
influence. The system integrity can’t be lost before penetrated danger source is activated. A danger
for “successful” operation is considered to be realized only after a danger source has influenced on the
modelled system.</p>
      <p>
        It is supposed that used diagnostic tools allow to provide necessary integrity recovery after
revealing danger sources penetration into modelled system or the consequences of influences. Using
the probabilistic models (described in details in [
        <xref ref-type="bibr" rid="ref1 ref14 ref16 ref6 ref8">1, 6, 8, 14, 16</xref>
        ] the measures can be estimated in
terms “success” or “failure” considering uncertainty conditions, periodical diagnostics, monitoring
between diagnostics, recovery of the lost integrity for «Black box”. The next universal input data for
probabilistic modeling are:
      </p>
      <p>σ - frequency of the occurrences of potential threats (or mean time between the moments of the
occurrences of potential threats which equals to 1/frequency);
β - mean activation time of threats;
Tbetw - time between the end of diagnostics and the beginning of the next diagnostics;
Tdiag - diagnostics time;
Trecov - recovery time</p>
      <p>T - given prognostic period.
4.3.</p>
    </sec>
    <sec id="sec-7">
      <title>The formalization for complex structure</title>
      <p>For a complex system estimation with parallel or serial structure existing models can be developed
by usual methods of probability theory. For this purpose in analogy with reliability it is necessary to
know a mean time between losses of integrity for each element. Let's consider the elementary
structure from two independent series elements this means logic connection “AND” and for two
parallel elements this means logic connection “OR”. Let’s probability distribution function (PDF) of
time between losses of j-th element integrity is Вj(t) =Р (τj≤ t), and random values τ1, τ2 are
independent, then:</p>
      <p>
        1) time between losses of integrity for system combined from series connected independent
elements is equal to a minimum from two times τj: failure of 1st or 2nd elements (i.e. the system goes
into a state of lost integrity when either 1st, or 2nd element integrity will be lost). For this case the
PDF of time between losses of system integrity is defined as
В(t) = Р(min (τ1,τ2)≤t)=1-Р(min (τ1,τ2)&gt;t)= 1-Р(τ1&gt;t)Р(τ2 &gt; t)= 1 – [1-В1(t)] [1- В2(t)].
(3)
2) time between losses of integrity for system combined from parallel connected independent
elements (hot reservation) is equal to a maximum from two times τj: failure of 1st or 2nd elements
(i.e. the system goes into a state of lost integrity when both 1st and 2nd element integrity will be lost).
For this case the PDF of time between losses of system integrity is defined as
В(t)=Р(max (τ1,τ2)≤t)=Р(τ1 ≤ t)Р(τ2 ≤t)=В1(t)В2(t).
(4)
Note. The same approach is developed also by Prof. E.Ventcel in 80th and by others researchers, see [
        <xref ref-type="bibr" rid="ref1 ref16 ref3 ref6 ref7 ref8">1, 3, 6, 7, 8, 16</xref>
        ] .
      </p>
      <p>Thus, an adequacy of probabilistic models is reached by the consideration of real processes of
control, monitoring, element recovery for complex structure. Applying recurrently expressions (3) –
(4), it is possible to receive PDF of time between losses of integrity for any complex modelled system
with series and/or parallel structure.
4.4.</p>
    </sec>
    <sec id="sec-8">
      <title>The integral measure</title>
      <p>The integral probability of failure in reliable perform human resource management process
considering system information security  int ( ) for the period T is proposed to be calculated by the
formula:
 int ( ) = 1 − [1 −  human( )] · [1 −  sec( )].
(5)</p>
      <p>Here the probabilistic measure  human( ) is probability of failure in reliable perform human
resource management process without consideration of system information security and  sec( ) is
probability of violating system information security requirements. They are estimated according to
recommendations of section 3 and subsections 4.1-4.3 considering the possible damage.</p>
      <p>Note. The condition of independence between the random time before failure in performing the human resource management process
and the random time before violating system information security requirements is supposed.</p>
    </sec>
    <sec id="sec-9">
      <title>5. Examples</title>
    </sec>
    <sec id="sec-10">
      <title>5.1. General</title>
      <p>Without deviation from the general understanding of the proposed approach, the examples are
given with reference to the human resource management process in application to standard IEC 62508
“Guidance on human aspects of dependability”.</p>
      <p>Let some enterprise implement a set of actions for human resource management. According to the
recommendations of IEC 62508, devoted to the analysis of the influence of the human factor on the
system dependability, the main actions of the enterprise should be: the formation of human resources;
the use of human resources; the development of human resources; the evaluation of efficiency related
to human resource management.</p>
      <p>Without going into the details of the considered aspects, the structure of actions set for receiving
results of human resource management process is presented by Figure 2. For example 1 the actions set
of system human resource management process is considered as complex modelled system. The
approach of 4.3 is applied (because the approaches of 4.1, 4.2 are more simple, for them many aspects
of system human resource management process are not considered).
The elements of the modelled system are:
1st element (subsystem) - the actions of the formation of human resources;
2nd subsystem (elements 2.1 and 2.2) - the actions to use of human resources;
3rd element - the actions to the development of human resources;
4th element - the actions to the evaluation of efficiency related to human resource management.</p>
      <p>Subsystem 2 is designated in the modelled system as two duplicate elements of the system
elements 21 and 22. Duplication in practice means that actions are performed by more than one
performer, one of whom is a person, the functions of another performer can be performed either by
another person (for example, a boss) and/or supported by a robot and/or some artificial intelligence
system. From the point of view of elementary events, such interaction essentially means that actions
will be performed by subsystem 2 if " OR " element 2.1 "OR" element 2.2 will be in the elementary
state "The integrity of the element of the modeled system is retained".</p>
      <p>By definition, the reliable performance of human resource management process in the modelled
system is considered to be ensured during a given prognostic period, if during this period the "AND"
actions of the process for the formation of human resources (according to element 1), "AND" for the
use of human resources (according to element 2.1 "AND"/"OR" element 2.2), "AND" for the
development of human resources (according to element 4), "AND" for the evaluation of efficiency
(according to element 4) are reliably performed. The prognostic period itself for an individual element
can be interpreted as referring to the stage of creation (for threats inherent in this stage), and to the
stage of operation in the future (for potentially possible threats), modeling the acceptability of
solutions and confirming guarantees that acceptable risks are not exceeded.
5.2.</p>
    </sec>
    <sec id="sec-11">
      <title>Example 1</title>
      <p>The risk of violating the reliability of the process performance without taking into account the
requirements for system information security is estimated for modelled structure of Figure 1. Many
possible threats affecting the each of the structural elements of the modelled system have been
identified. At the same time, not only health threats and the possibility of human errors are taken into
account, but also hypothetical threats associated with the possible consequences of these errors at the
stage of enterprise operation. The generated input data for modeling, which cover each of the
composite elements, are presented in Table 1.
β - mean activation time of threats</p>
      <p>Elements
1 time in 5 years (because of lost qualifications or
knowledge for solving problems)
2 times in a year (because of insufficient
qualifications or knowledge to solve problems or
due to health problems of the staff)
The same as for element 2.1
1 time in 5 years (because of the violation of the
necessary terms of professional training and
advanced training)
1 time in a year (because of the violation of the
necessary deadlines or the quality of the periodic
evaluation of the effectiveness of the process
performance)
3 months up to possible damage
2 months up to possible damage
2 months up to possible damage
6 months up to possible damage
6 months up to possible damage
Tbetw - time between the end of
diagnostics and the beginning of
the next diagnostics
Tdiag - diagnostics time
Trecov - recovery time</p>
      <p>For all elements</p>
      <p>1 time in a week
The analysis of the calculation results showed that in probabilistic terms, the risk of failure in reliable
perform human resource management process without consideration of system information security
for 2 years will be about 0.02 for the entire set of actions (see Figure 2). With an increase in the
prognostic period from 1 year to 4 years (see Figure 3), the risk increases from 0.043 to 0.241. For an
acceptable risk at the level of 0.05, a period of up to 14 months is justified, in which guarantees are
maintained that the acceptable risk is not exceeded in the conditions of the example from Table 1.</p>
      <p>Figure 3. Dependence  human ( ) on the
prognostic period  lasting from 1 to 4 years</p>
      <p>The" bottleneck", the characteristics of which it makes sense to analyze for risk reduction, is only
subsystem 2 – this is a set of actions for the use of human resources related to functional support,
estimation and control. The identification of this "bottleneck" forces an additional analysis to identify
ways to reduce the risk. The simplest option is to combine efforts in the use of human resources.
These efforts imply mutual assistance, including mutual control of activities, and from the point of
view of modeling in the structure, instead of element 2.2 with characteristics identical to element 2.1,
the use of element 2.2, for which the frequency of occurrence of sources of threats associated with
ineffective functional support, evaluation and control of actions (σ) will not be 2 times a year (as in
Table 1 for medium-qualified personnel), but 1 time every 2 years, i.e. 4 times less often. This is quite
achievable due to the performance of functions by a more highly qualified human performer and/or a
robot and/or with the support of some kind of artificial intelligence system. All other input for
modeling are the same as shown in Table 1.</p>
      <p>As a result of additional modeling, it was found that due to the measures taken, the risk of failure
in reliable perform human resource management process without consideration of system information
security was reduced to the level of 0.076 (i.e. by 34.2%) and an increase from 14 to 16 months of the
period for which guarantees of non-excess of acceptable risks are retained (see Figure 4). In practice,
it is these measures (combining the efforts of several persons in the parallel solution of one task with
mutual control of the prepared solutions) that lead to success. The example shows only a quantitative
estimation of the results of applying such measures.</p>
      <p>Continuing Example 1, the prediction of the risk of violation of information security requirements
is illustrated for a set of actions according to the recommendations of ISO/IEC 27002 (Section 8) in
terms of ensuring the safety of personnel (see Figure 5). The actions set is considered as complex
modelled system. Still the approach of 4.3 is applied (because the approaches of 4.1, 4.2 are more
simple for modeling in the example).</p>
      <p>The input for each of the 3 constituent elements are presented in Table 2.</p>
      <p>for 3rd element
2 times in a year (these are
threats of damage caused
by previous mistakes or
due to dissatisfaction of</p>
      <p>dismissed personnel)
1 day (it is assumed that</p>
      <p>due to masking, the
sources of threats are not
activated immediately, but
with a certain delay of at
least 1 day)</p>
      <p>1 hour
(this time is determined by</p>
      <p>the regulations for
monitoring assets related
to staff)</p>
      <p>Analysis of the calculation results showed that in probabilistic terms, the risk of violating the
requirements for information security within two years will be about 0.130 for the entire set of
actions, amounting to 0.014 for the 1st element, 0.041 for the 2nd element, 0.080 for the 3rd element
("bottleneck"). With an increase in the prognostic period from a year to 4 years, the risk increases
from 0.067 to 0.243. For an acceptable risk at the level of 0.050, a period of up to 8 months is
justified, in which guarantees are maintained that the acceptable risk is not exceeded in the selected
set of actions characterized by the conditions of the example from Table 2.</p>
      <p>A "bottleneck" has been identified – it is the preservation of the ability of a person who has
stopped or changed his duties to use the information received (element 3). At the same time, the cause
of the "bottleneck" is a violator who is able (according to the accepted information security model) to
use this hypothetical vulnerability during a day - see Table 2, the value for β - mean activation time
of threats up to violation of information security.
5.4.</p>
    </sec>
    <sec id="sec-12">
      <title>Example 3</title>
      <p>In continuation of Examples 1 and 2, the integral probability    ( ) of failure in reliable perform
human resource management process considering system information security is calculated using the
recommendations of section 4. Considering that   ( =      ) = 0.076 and
  ( =     ) = 0.130, by formula (5)</p>
      <p>( =      ) = 1 ─ (1─0.076)·(1─0.130) ≈ 0.196.</p>
      <p>For commensurate damages in resulting value of integral risk 0.196 the risk of violating system
information security requirements (0.130) is 1.7 times higher than the risk of failure to reliable
perform human resource management process without consideration of system information security.
Comparing with the admissible level of 0.05, we can state that the calculated risks exceed the
acceptable risk (in probability value). It means the rationale that the system decisions are not balanced
and the improvement of human resource management process is needed. And the main goal is to
reduce the risk of violating information security requirements.</p>
      <p>Thus, the examples 1-3 demonstrated a usability of the approach.</p>
    </sec>
    <sec id="sec-13">
      <title>6. Conclusion</title>
    </sec>
    <sec id="sec-14">
      <title>7. References</title>
      <p>The proposed approach allows to estimate probabilistic risks for the performance of system human
resource management process considering information security requirements. It uses the measure for
uncertainty conditions – the integral probability of failure in reliable perform human resource
management process considering system information security. Considering system information
security the approach application helps to identify "bottlenecks" and the ways to reduce risks in
human resource management process, and justify conditions and period, in which guarantees of risks
retention within admissible limits are maintained, taking into account the requirements for system
information security.
power plants. Probability, combinatorics and control. IntechOpen, 2020, pp. 191-220. URL:
https://www.intechopen.com/books/probability-combinatorics-and-control
[21] I. Goncharov, N. Goncharov, P. Parinov, S. Kochedykov, A. Dushkin Modelling the
information-psychological impact in social networks. Probability, combinatorics and control.
IntechOpen, 2020, pp. 293-308. URL:
https://www.intechopen.com/books/probabilitycombinatorics-and-control</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>A.</given-names>
            <surname>Kostogryzov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Nistratov</surname>
          </string-name>
          and
          <string-name>
            <given-names>A.</given-names>
            <surname>Nistratov</surname>
          </string-name>
          .
          <article-title>Some Applicable Methods to Analyze and Optimize System Processes in Quality Management</article-title>
          .
          <source>Total Quality Management and Six Sigma, InTech</source>
          ,
          <year>2012</year>
          :
          <fpage>127</fpage>
          -
          <lpage>196</lpage>
          . DOI:
          <volume>10</volume>
          .5772/46106
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>A.</given-names>
            <surname>Barabanov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Markov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Tsirlov</surname>
          </string-name>
          .
          <article-title>Methodological Framework for Analysis and Synthesis of a Set of Secure Software Development Controls</article-title>
          ,
          <source>Journal of Theoretical and Applied Information Technology</source>
          ,
          <year>2016</year>
          , vol.
          <volume>88</volume>
          , No 1, pp.
          <fpage>77</fpage>
          -
          <lpage>88</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>M.</given-names>
            <surname>Eid</surname>
          </string-name>
          , and
          <string-name>
            <given-names>V.</given-names>
            <surname>Rosato</surname>
          </string-name>
          .
          <source>Critical Infrastructure Disruption Scenarios Analyses via Simulation. Managing the Complexity of Critical Infrastructures. A Modelling and Simulation Approach</source>
          , SpringerOpen,
          <year>2016</year>
          :
          <fpage>43</fpage>
          -
          <lpage>62</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>A.</given-names>
            <surname>Markov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Fadin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Tsirlov</surname>
          </string-name>
          .
          <article-title>Multilevel Metamodel for Heuristic Search of Vulnerabilities in the Software Source Code</article-title>
          ,
          <source>International Journal of Control Theory and Applications</source>
          ,
          <year>2016</year>
          , vol.
          <volume>9</volume>
          , No 30, pp.
          <fpage>313</fpage>
          -
          <lpage>320</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Zegzhda</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zegzhda</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pavlenko</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dremov</surname>
            ,
            <given-names>A. Detecting</given-names>
          </string-name>
          <article-title>Android application malicious behaviors based on the analysis of control flows and data flows</article-title>
          .
          <source>ACM International Conference Proceeding Series</source>
          ,
          <year>2017</year>
          , pp.
          <fpage>280</fpage>
          -
          <lpage>286</lpage>
          . DOI:
          <volume>10</volume>
          .1145/3136825.3140583.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Kostogryzov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stepanov</surname>
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nistratov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nistratov</surname>
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Klimov</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Grigoriev</surname>
            <given-names>L.</given-names>
          </string-name>
          (
          <year>2017</year>
          ).
          <article-title>The method of rational dispatching a sequence of heterogeneous repair works</article-title>
          .
          <source>Energetica</source>
          . Vol.
          <volume>63</volume>
          ,
          <issue>4</issue>
          ,
          <fpage>154</fpage>
          -
          <lpage>162</lpage>
          . www.lmaleidyka.lt/ojs/index.php/energetika/index
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>V.</given-names>
            <surname>Artemyev</surname>
          </string-name>
          , Ju. Rudenko,
          <string-name>
            <given-names>G.</given-names>
            <surname>Nistratov</surname>
          </string-name>
          .
          <article-title>Probabilistic modeling in system engineering. Probabilistic methods and technologies of risks prediction and rationale of preventive measures by using “smart systems”. Applications to coal branch for increasing Industrial safety of enterprises</article-title>
          .
          <source>IntechOpen</source>
          ,
          <year>2018</year>
          :
          <fpage>23</fpage>
          -
          <lpage>51</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>V.</given-names>
            <surname>Kershenbaum</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Grigoriev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Kanygin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Nistratov</surname>
          </string-name>
          .
          <article-title>Probabilistic modeling in system engineering. Probabilistic modeling processes for oil and gas systems</article-title>
          .
          <source>IntechOpen</source>
          ,
          <year>2018</year>
          :
          <fpage>55</fpage>
          -
          <lpage>79</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>A.</given-names>
            <surname>Markov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Barabanov</surname>
          </string-name>
          and
          <string-name>
            <given-names>V.</given-names>
            <surname>Tsirlov</surname>
          </string-name>
          .
          <article-title>Probabilistic modeling in system engineering</article-title>
          .
          <source>Periodic Monitoring and Recovery of Resources in Information Systems. IntechOpen</source>
          ,
          <year>2018</year>
          :
          <article-title>Chapter 10</article-title>
          . URL: http://www.intechopen.com/books/probabilistic
          <article-title>-modeling-in-system-engineering</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>I.</given-names>
            <surname>Goncharov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Goncharov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Kochedykov</surname>
          </string-name>
          and
          <string-name>
            <given-names>P.</given-names>
            <surname>Parinov</surname>
          </string-name>
          .
          <article-title>Probabilistic modeling in system engineering</article-title>
          .
          <article-title>Probabilistic analysis of the influence of staff qualification and informationpsychological conditions on the level of systems information security</article-title>
          .
          <source>IntechOpen</source>
          ,
          <year>2018</year>
          :
          <article-title>Chapter 11</article-title>
          . URL: http://www.intechopen.com/books/probabilistic
          <article-title>-modeling-in-system-engineering</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>A.</given-names>
            <surname>Barabanov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Markov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Tsirlov</surname>
          </string-name>
          .
          <source>Information Security Controls Against Cross-Site Request Forgery Attacks on Software Application of Automated Systems. Journal of Physics: Conference Series</source>
          .
          <year>2018</year>
          . V. 1015. P. 042034. DOI :
          <volume>10</volume>
          .1088/
          <fpage>1742</fpage>
          - 6596/1015/4/04203.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>A.</given-names>
            <surname>Berdyugin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Revenkov</surname>
          </string-name>
          .
          <article-title>Approaches to measuring the risk of cyberattacks in remote banking services of Russia</article-title>
          .
          <year>2019</year>
          . Vol-
          <volume>2603</volume>
          . P.
          <volume>23</volume>
          -
          <fpage>38</fpage>
          . URL: http://ceur-ws.
          <source>org/</source>
          Vol-
          <volume>2603</volume>
          /short2.pdf
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>N.</given-names>
            <surname>Korneev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Merkulov</surname>
          </string-name>
          .
          <article-title>Intellectual analysis and basic modeling of complex threats</article-title>
          .
          <year>2019</year>
          . Vol2603. P.
          <volume>23</volume>
          -
          <fpage>38</fpage>
          . URL: http://ceur-ws.
          <source>org/</source>
          Vol-
          <volume>2603</volume>
          /paper6.pdf
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>A.</given-names>
            <surname>Kostogryzov</surname>
          </string-name>
          .
          <source>Risks Prediction for Artificial Intelligence Systems Using Monitoring Data</source>
          .
          <year>2019</year>
          . Vol-
          <volume>2603</volume>
          . P.
          <volume>29</volume>
          -
          <fpage>33</fpage>
          . URL: http://ceur-ws.
          <source>org/</source>
          Vol-
          <volume>2603</volume>
          /short7.pdf
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>V.</given-names>
            <surname>Varenitca</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Markov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Savchenko</surname>
          </string-name>
          .
          <article-title>Recommended Practices for the Analysis of Web Application Vulnerabilities</article-title>
          .
          <year>2019</year>
          . Vol-
          <volume>2603</volume>
          . P.
          <volume>75</volume>
          -
          <fpage>78</fpage>
          . URL: http://ceur-ws.org/Vol2603/short16.pdf
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>A.</given-names>
            <surname>Kostogryzov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Korolev</surname>
          </string-name>
          .
          <article-title>Probabilistic methods for cognitive solving some problems of artificial intelligence systems. Probability, combinatorics and control</article-title>
          .
          <source>IntechOpen</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>3</fpage>
          -
          <lpage>34</lpage>
          . URL: https://www.intechopen.com/books/probability
          <article-title>-combinatorics-and-control</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>V.A.</given-names>
            <surname>Nadein</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.A.</given-names>
            <surname>Makhutov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.I.</given-names>
            <surname>Osipov</surname>
          </string-name>
          ,
          <string-name>
            <surname>G.I. Shmal'</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.A.</given-names>
            <surname>Truskov</surname>
          </string-name>
          <article-title>Hybrid modelling of offshore platforms' stress-deformed and limit states with taking into account probabilistic parameters. Probability, combinatorics and control</article-title>
          .
          <source>IntechOpen</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>73</fpage>
          -
          <lpage>116</lpage>
          . URL: https://www.intechopen.com/books/probability
          <article-title>-combinatorics-and-control</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>I.</given-names>
            <surname>Sinitsyn</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Shalamov</surname>
          </string-name>
          <article-title>Probabilistic analysis, modeling and estimation in CALS technologies. Probability, combinatorics and control</article-title>
          .
          <source>IntechOpen</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>117</fpage>
          -
          <lpage>142</lpage>
          . URL: https://www.intechopen.com/books/probability
          <article-title>-combinatorics-and-control</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>D.</given-names>
            <surname>Neganov</surname>
          </string-name>
          .,
          <string-name>
            <given-names>N.</given-names>
            <surname>Makhutov</surname>
          </string-name>
          .
          <article-title>Combined calculated, experimental and determinated and probable justification for strength of trunk oil pipelines. Probability, combinatorics and control</article-title>
          .
          <source>IntechOpen</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>143</fpage>
          -
          <lpage>164</lpage>
          . URL: https://www.intechopen.com/books/probabilitycombinatorics-and-control
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>N.</given-names>
            <surname>Makhutov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Gadenin</surname>
          </string-name>
          , Yu. Dragunov,
          <string-name>
            <given-names>S.</given-names>
            <surname>Evropin</surname>
          </string-name>
          ,
          <string-name>
            <surname>V.</surname>
          </string-name>
          <article-title>Pimenov Probability modeling taking into account nonlinear processes of a deformation and fracture for the equipment of nuclear</article-title>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>