<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Models of Fuzzy Identification of Cyber Incidents in Information  and Communication Systems by Intelligent SIEM Systems </article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Ihor Subach</string-name>
          <email>igor_subach@ukr.net</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Dmytro Mogylevych</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Artem Mykytiuk</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Volodymyr Kubrak</string-name>
          <email>volodymir.kubrak@ukr.net</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Vitalii Fesokha</string-name>
          <email>vitaliifesokha@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Heroes of Kruty Military Institute of Telecommunications and Information Technologies</institution>
          ,
          <addr-line>Kyivska str., 45/1, Kyiv, 01011</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>National Technical University of Ukraine "Igor Sikorsky Kyiv Polytechnic Institute"</institution>
          ,
          <addr-line>Verkhnoklyuchova str., 4, Kyiv, 03056</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>151</fpage>
      <lpage>160</lpage>
      <abstract>
        <p>   The issue of detecting cyber incidents that occur during the functioning of information and communication systems, based on the use of a SIEM system in the cyber protection circuit, as the basis for its design, is considered. This study concludes that the use of the latest information technologies, such as artificial intelligence, intelligent data analysis, big data processing, and machine learning, is necessary to improve cyber incident detection. These technologies make it possible to increase the effectiveness of the SIEM system by minimizing human involvement in solving cyber incident response tasks. The analysis of methods used to detect cyber incidents has revealed their major limitations, particularly their inability to consistently provide the desired outcome in scenarios where information about such incidents is incomplete or inaccurate. To address this issue, a new approach to detect cyber incidents is proposed. This approach is based on using knowledge delivery models within the knowledge base that provide information about the signs of cyber incidents occurring in information and communication systems, as well as the various types of cyber incidents. This knowledge will be used to identify cyber incidents by collecting and processing expert information, utilizing the theory of fuzzy sets. Additionally, the proposed approach includes the formalization of the causal relationships between the variables "signs of cyber incidents" and "types of cyber incidents." This is achieved by describing these relationships in natural language using the theory of fuzzy sets and linguistic variables. The models proposed in this study can improve the effectiveness of cyber incident detection by addressing the limitations of current methods.</p>
      </abstract>
      <kwd-group>
        <kwd> 1  Cybersecurity</kwd>
        <kwd>cyber incident</kwd>
        <kwd>SIEM system</kwd>
        <kwd>fuzzy sets</kwd>
        <kwd>fuzzy production rules</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction </title>
      <p>
        management, data analysis, decision-making, and implementation. In [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], a method for the rational
selection of a SIEM system for constructing a cyber security situational center has been discussed.
      </p>
      <p>
        The effectiveness of the system developed based on the proposed model is heavily reliant on the
utilization of the latest information technologies, including Artificial Intelligence (AI), Data Mining
(DM), Big Data, Machine Learning (ML), and others. These technologies enable the system to
minimize human involvement in responding to cyber incidents occurring within the ICS, thereby
increasing the efficiency and accuracy of its decisions [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
      </p>
      <p>Analysis of recent research and publications confirms the feasibility of using these technologies for
detecting and promptly responding to cyber incidents.</p>
      <p>
        The works [
        <xref ref-type="bibr" rid="ref5 ref6">5, 6</xref>
        ] address the use of data mining (DM) technology for detecting cyber incidents in
SIEM systems. Specifically, this study analyzes the efficiency of using DM methods, such as
association rules, classification, clustering, prediction, and sequential patterns, for implementing the
primary functions of a SIEM system.
      </p>
      <p>
        The authors of [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] examine the application of association rules in intrusion detection systems (IDS),
with a focus on how these rules are formed from big data.
      </p>
      <p>
        The study [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] presents a classification model for cyber incidents based on rules with weighted
attributes.
      </p>
      <p>
        The work [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] focuses on detecting DoS attack patterns by analyzing HTTP, HTTPS, and FTP traffic.
      </p>
      <p>
        The issues of detecting unknown cyber attacks by IDS-systems, which are built on the basis of
statistical methods, are considered in [
        <xref ref-type="bibr" rid="ref10 ref11">10, 11</xref>
        ].
      </p>
      <p>
        The work [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ] is devoted to the application of hybrid methods of detecting cyberattacks based on
associative rules and ant algorithms. The authors prove the effectiveness of this approach in comparison
with known ones by conducting experimental studies with the NSL-KDD data set.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] a simulation model was proposed for evaluating the effectiveness of cyber attack detection
systems.
      </p>
      <p>
        The study [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] focuses on increasing the effectiveness of detecting network attacks in IDS Snort by
applying DM techniques. The effectiveness of the results is experimentally evaluated using the
MITDARPA 1999 data set.
      </p>
      <p>
        The authors of [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] propose using a self-learning SIEM system to analyze network events and detect
abnormal patterns using associative rules.
      </p>
      <p>Despite numerous scientific publications on the application of DM and other modern information
technologies in SIEM systems to detect cyber incidents, knowledge organization in the knowledge
bases of intelligent SIEM systems remains largely unexplored.</p>
      <p>This study aims to develop a model for incorporating knowledge about cyber incidents into the
knowledge base of an intelligent SIEM system.
2. Statement of the problem of cyber incidents identification </p>
      <p>
        It is widely acknowledged that the effectiveness of any intelligent system depends largely on the
quality of its knowledge base. In [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ], the matter of organizing knowledge in the knowledge bases of
intelligent systems is discussed. However, research suggests that the most commonly used methods
for detecting cyber incidents in SIEM systems are rule-oriented [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] approaches that rely on classical
production rules. Therefore, a production model of knowledge delivery is used to represent
knowledge in the SIEM system's knowledge base.
      </p>
      <p>
        However, when information about cyber incidents during ICS operation is incomplete or
inaccurate, these methods may not produce the desired results, making them inefficient. To address
this issue, it is recommended to utilize models and techniques based on fuzzy set theory for fuzzy
inference [
        <xref ref-type="bibr" rid="ref16 ref17 ref18 ref19 ref20 ref21">16-21</xref>
        ].
      </p>
      <p>
        According to this, the model for detecting (recognizing) cyber incidents by a SIEM system can be
represented as [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]:
where KF – fuzzy classifier;
,  ,  
⟩,
(1)
      </p>
      <p>− a set of fuzzy rules for recognizing cyber incidents:
: , 
,  
: , 
,  … ,  
: ,</p>
      <p>  →   .
their identification, and its solution is to find a mapping:</p>
      <p>
        Based on the works [
        <xref ref-type="bibr" rid="ref22 ref23 ref24 ref25">22-25</xref>
        ], the task of recognizing cyber incidents can be considered as the task of
 * 
*,   * , … ,  * → 
∈ 
 ,  , … , 
,
(2)

where  * a set of signs of a cyber incident;
      </p>
      <p>a set of possible cyber incidents.</p>
      <p>The area of change of signs of a cyber incident  ∈  ,  ,  1, 
, and the initial value of the
identification result с ∈  , 
are considered to be known. Accordingly,  
– the lower (upper)
value of the parameters of the cyber incident,  ,   1, 
; с ,  ,  1, 
– the lower (upper) value of
the identification result.</p>
      <p>In practice, the most commonly used methods for solving the problem (2) are parametric
identification</p>
      <p>
        methods, such as the least squares method, maximum likelihood method, mean
discrepancy method, stochastic approximation method, and more [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ].
      </p>
      <p>
        The main drawbacks of these methods that complicate their use include [
        <xref ref-type="bibr" rid="ref22 ref23">22, 23</xref>
        ]:
- the lack of clear interpretation in "input-output" type models;
- the inability to work with qualitative input and output variables;
- the inability to incorporate expert experience regarding object structure in the form of
"IFTHEN" logical statements.
      </p>
      <p>To address these shortcomings, a different approach based on models and methods of knowledge
engineering is needed, particularly models for delivering knowledge base (KB) about the signs of cyber
incidents (SCI) and classes of cyber incidents (CCI) that occur during ICS operation. This approach
involves collecting and processing expert information using fuzzy set theory.</p>
      <p>The primary concept of this approach is to formalize causal relationships between "SCI-CCI"
variables by describing them in natural language using the theory of fuzzy sets and linguistic variables.
This enables the mathematical formalization of natural language statements to solve the problem of
identifying cyber incidents in the statement of the problem (2).</p>
      <p>To translate expert knowledge presented in "IF-THEN" linguistic statements into a mathematical
model, the mathematical apparatus of membership functions (MF) is used to express the expert's degree
of confidence that a certain value belongs to a fuzzy concept (term). In turn, methods of fuzzy logical
inference make it possible to connect the FN of the signs of cyber incidents with the results of their
identification, provided that there is a model of cyber incidents in the form of a set of fuzzy rules of the
"IF–THEN" type – a fuzzy knowledge base (FKB).</p>
      <p>
        The primary principles used in developing a mathematical model for identifying cyber incidents
include [
        <xref ref-type="bibr" rid="ref17 ref18 ref20 ref22 ref23">17, 18, 20, 22, 23</xref>
        ]:
      </p>
      <p>- the principle of linguistic state of the ICS, which considers the type of cyber incident and its signs
as linguistic variables (LV) evaluated by qualitative terms;</p>
      <p>- the principle of forming the structure of the dependence of the type of cyber incident on its signs
by means of the FKB;
of nested logical statements.</p>
      <p>- the principle of the hierarchy of the FKB, according to which the reduction in the dimension of the
FKB can be carried out by classifying input variables and building an "output tree" that defines a system</p>
      <p>The third principle of the model allows for consideration of a wide range of indicators used in
identifying cyber incidents. Its implementation is particularly significant when dealing with a complex
model since adding new indicators and accumulating knowledge about them requires such an approach.</p>
      <p>Therefore, the model for identifying (detecting) cyber incidents can be specified in the form of FKB,
represented by a set of "IF-THEN" fuzzy rules that connect linguistic evaluations of the signs of cyber
incidents with their identification results.</p>
      <p>Based on the above, the problem (2) can be formulated as follows.</p>
      <p>It is important to note that the formal solution to this problem requires the presence of dependence
(3):
of dependence (3):
 ,</p>
      <p>Let  ∗
,  1,</p>
      <p>∗,    ∗,   … ,    ∗ is a vector of fixed values of signs of a cyber incident, where  ∗ ∈
. Then the task of identification is to determine the type of cyber incident 
∈  based
on the vector  *. Note that a necessary condition for the formal solution of this problem is the presence
с 
 ,  , … , 
,
where  ,  , … ,</p>
      <p>– a set of values of signs of cyber incidents,  – the result of identification.</p>
      <p>
        Models of fuzzy identification of cyber incidents 
To evaluate a LV, it is quite appropriate to apply qualitative terms that make up term sets [
        <xref ref-type="bibr" rid="ref22 ref23 ref24 ref25">22-25</xref>
        ]:
 ,  , … , 
– term set of the variable  ,  1, 
, where 
– k-linguistic term of the
variable  ,  1, 
,  1,
      </p>
      <p>;
variable  , m – number of possible classes of cyber incidents.</p>
      <p>In general, cardinalities of term sets Α ,  1,</p>
      <p>can be different:
 ,  , … , 
– term set of the variable  , where  ,  1, 
– linguistic term of the
Note that in expressions (6) and (7) the sign  denotes the union of pairs  
/ .</p>
      <p>Let L be the amount of data that links the input data – the characteristics of cyber incidents and the
output value – the class of the cyber incident, and:
 

⋯ 
,
where  – the number of data received from experts that correspond to the output variable – the class
, m – the number of classes of cyber incidents, and in the general
of the cyber incident 
case: 

⋯ 
∈ Δ,  1, 
.
various combinations  of input signs of cyber incidents.</p>
      <p>Note that the number of data received from experts is much smaller than a complete enumeration of
Α
Δ
where</p>
      <p> ik  i , k  1, ki , i  1, n</p>
      <p>;

j
 , j  1, m
of the term – the class of cyber incident
Besides, term names  ,  , … , 
Therefore, the linguistic terms 
may differ for different linguistic variables  ,  1, 
.
∈ Α ,  1, 
,  1, 
and 
∈ Δ,  1, 
can be considered
as fuzzy sets defined on the universal sets  ,</p>
      <p>(5).</p>
      <p>
        In turn, the fuzzy sets 
and 
can be defined as follows [
        <xref ref-type="bibr" rid="ref22 ref23">22, 23</xref>
        ]:


⋯
      </p>
      <p>.
oi
oi
c
c
j
 ik   ik oi / oi ,
</p>
      <p>j
j    j c j / c j ,</p>
      <p>
        To solve the formulated problem, it is necessary to consider the input and output variables from (3)
as linguistic variables defined on universal sets [
        <xref ref-type="bibr" rid="ref22 ref23">22, 23</xref>
        ]:

 , 
, 
 ,  .
      </p>
      <p>(3)
(4)
(5) 
(6) 
(7)
(8) 
o1  o2  oi  …  on 
11  111    211    i11   …   n11  
1…2   …112   …212    …i12    ……   …n12     1  
1k1  11k1   11k2    i1k1   …   n1k1  
…  …  …  …  …  …  … 
j1  1j1    2j1    ij1   …   nj1  
j…2   …1j 2   …2j 2   …ij 2   ……   …nj 2    j  
jkj  1jk j    2jk j    ijk j   …   njk j  
…  …  …  …  …  …  … 
m1  1m1    2m1    im1   …   nm1  
m…2   …1m 2   …2m 2    im 2   ……    nm 2    m  
mkm  1mkm    2mkm    imkm   …   nmkm  </p>
      <p>
        Similarly to [
        <xref ref-type="bibr" rid="ref22 ref23">22, 23</xref>
        ], let us call this table a matrix of knowledge about cyber incidents. It has the
following properties:
      </p>
      <p>- dimension of the matrix: n  1 N , where n  1 – the number of columns of the matrix,
and L  l1  l2  lm – the number of its rows;</p>
      <p>- each row of the matrix is a combination of the input values of the signs of cyber incidents
oi ,i  1, n , which is assigned by the expert to one of its classes  j , with the first 1l rows corresponding
to the class 1 , and the last 1m rows – to the class  m ;</p>
      <p>- first n columns of the matrix correspond to the input values of the signs of cyber incidents
oi ,i  1, n , and n  1 column corresponds to the output value – the class of the cyber incident c.</p>
      <p>- at the intersection of the i-column and the jkj -row there is an element  ijk j , that corresponds
to the linguistic assessment of the cyber incident sign oi the row of the matrix jk j , which belongs to
the term set of the corresponding sign oi:  ik  i , k  1, ki , i  1, n .</p>
      <p>
        The matrix of knowledge about cyber incidents described above can be represented in the form of a
system of fuzzy rules of "IF–THEN" type [
        <xref ref-type="bibr" rid="ref22 ref23">22, 23</xref>
        ], that connect the values of the input signs of cyber
incidents oi ,i  1, n with one of the possible classes of cyber incidents  j  , j  1, m :
      </p>
      <p>IF( oi   111 )AND( o2   211 )AND…AND( on   n11 )OR
…, IF( oi   1j1 )AND( o2   2j1 )AND…AND( on   nj1 )OR
( oi   112 )AND( o2   212 )AND…AND( on   n12 )OR
( oi   11k1 )AND( o2   21k1 )AND…AND( on   n1k1 )THEN(с=1 ),…
( oi   1j2 )AND( o2   2j2 )AND…AND( on   nj2 )OR
( oi  1k j )AND( o2   2jk j )AND…AND( on   njk j )THEN(с= j ),… (9)
…, IF( oi   1m1 )AND( o2   2m1 )AND…AND( on   nm1 )OR</p>
      <p>( oi   1m2 )AND( o2   2m2 )AND…AND( on   nm2 )OR
( oi  1mkm )AND( o2   2mkm )AND…AND( on   nmkm )THEN(с= m ),
(10)
(11)
determined on the term set i   i1, i2 ,, iki ;
where  ijk – linguistic evaluation of the sign of cyber incident oi ,i  1, n in the k row of j-disjunction
 j  , j  1, m – linguistic evaluation of the class of cyber incident, determined on the term
set   1, 2 ,, m.</p>
      <p>Therefore, the expression (9) given in the form of a set of fuzzy rules of "IF–THEN" type, which
are based on the matrix of knowledge about cyber incidents (Table 1), represents a model for the
identification of cyber incidents by the SIEM system.</p>
      <p>If the linguistic evaluations  ijk of the variables o1, o2 ,,on and  j , j  1, m from (9) are
   
considered as fuzzy sets defined on universal sets oi   oi , oi , c   c j , c j , i  1, n, j  1, m , then
   
 jk  
 i – MF (belongingness) of the sign of cyber incident oi   oi , oi  to the fuzzy term
 
 ijk , i  1, n, j  1, m, k  1, k j , and   j o1, o2 ,, on  – to the vector of sign of a cyber incident,
O  o1, o2 ,, on,i  1, n , to the value of the initial assessment с   j , j  1, m .</p>
      <p>The relationship between them is determined through a fuzzy matrix of knowledge about cyber
incidents (Table 1) and by replacing linguistic terms with their MF, as well as replacing logical
operations AND or OR with operations  and  can be represented as follows:
  j o1, o2 ,, on    1j1 o1    2j1 o2    nj1 on 
  1j2 o1    2j2 o    nj2 o  </p>
      <p>2 n
  1jk j o1    2 o2    n on , j  1, m</p>
      <p> jk j  jk j
Then expression (10) can be represented as follows:</p>
      <p>kj  n 
 j o1.о2 ,,оn   k1i1ijk oi , j 1, m.</p>
      <p>
        Taking into account that in the theory of fuzzy sets, operations  and  correspond to operations
min and max [
        <xref ref-type="bibr" rid="ref22 ref23">22, 23</xref>
        ], then by transforming (11) we will obtain a model of identification of cyber
incidents by SIEM systems (12):
  j oi , o2 ,, on   max  min ijk oi , j  1, m. (12)
      </p>
      <p>
k  1, k j i  1, n </p>
      <p>This model can be the basis for the development of a rule-oriented method of detecting cyber
incidents by a SIEM system.
4. Model of fuzzy identification of cyber incidents with weighted rules </p>
      <p>
        The main drawback of the model (12) is that the expert’s confidence in each "IF–THEN" rule, which
is included in the fuzzy KB (9), may differ. This shortcoming can be eliminated by introducing the
weight of the rule, which will characterize the significance of a particular rule during the identification
of cyber incidents. Based on the works [
        <xref ref-type="bibr" rid="ref24 ref27 ref28">24, 27, 28</xref>
        ], the weight of a rule should be understood as a
number in the interval [
        <xref ref-type="bibr" rid="ref1">0, 1</xref>
        ], which characterizes the subjective measure of the expert’s confidence in
a particular rule.
      </p>
      <p>In this case, the multidimensional table of signs of cyber incidents and their corresponding classes
(Table 1), taking into account the expert’s confidence in a particular rule, which is specified using the
weight of the rule, will take the following form (Table 2):
Table 2 
Multidimensional table of signs of cyber incidents and their corresponding classes in accordance with 
the weight of the rules </p>
      <sec id="sec-1-1">
        <title>Signs of cyber incident </title>
      </sec>
      <sec id="sec-1-2">
        <title>Class of </title>
        <p>cyber incident 
The number of </p>
        <p>the input 
combination of 
cyber incident 
sign values 
11 
12 
… 
1k1 
… 
j1 
j2 
… 
jkj 
… 
m1 
m2 
… 
mkm 
o1 </p>
        <p>Thereby, taking into account the weight of the rules, the FKB, which is represented by a set of fuzzy
"IF–THEN" rules that link linguistic evaluations of signs of cyber incidents with the results of their
identification, will take the following form:</p>
        <p>IF( oi   111 )AND( o2   211 )AND…AND( on   n11 ) with weight w11
OR
( oi   112 )AND( o2   212 )AND…AND( on   n12 ) with weight w12 OR
( oi   11k1 )AND( o2   21k1 )AND…AND( on   n1k1 ) with weight w1k1</p>
        <p>THEN(с=1 ), …
…, IF( oi   1j1 )AND( o2   2j1 )AND…AND( on   nj1 ) with weight w j1 OR
( oi   1j 2 )AND( o2   2j2 )AND…AND( on   nj 2 ) з вагою
( oi   1jk j )AND( o2   2jk j )AND…AND( on   njk j ) з вагою w jk j</p>
        <p>THEN(с= j ), …
…, IF( oi   1m1 )AND( o2   2m1 )AND…AND( on   nm1 ) with weight wm1</p>
        <p>OR
THEN(с= m ),
( oi   1m2 )AND( o2  2m2 )AND…AND( on  nm2 ) with weight wm2
( oi   1mkm )AND( o2   2mkm )AND…AND( on   nmk m ) with weight wmk m
disjunction determined on the term set i   i1, i2 ,, iki ;
where  ijk – linguistic evaluation of the sign of cyber incident oi ,i  1, n in the k row of
j j  , j  1, m – linguistic evaluation of the class of cyber incident determined on the term set
  1, 2 ,, m;
w jk – weight of the rule.</p>
        <p>Taking into account the weight of the rules, the fuzzy knowledge base (13) can be represented by a
modified system of fuzzy equations (11) as follows:</p>
        <p>k j   n 
  j o1.о2 ,, оn     jk i1</p>
        <p>   ijk oi , j  1, m
k 1 </p>
        <p>By replacing the operations  and  with min та max operations, which correspond to them, we
will obtain a modified model of fuzzy identification of cyber incidents by SIEM systems (15) with
weighted rules:
  j oi , o2 ,, on  
max  min  </p>
        <p>  ijk oi , j  1, m.</p>
        <p>k  1, k j  jk i  1, n  </p>
        <p>The given model makes it possible to eliminate the shortcomings present in model (12) by taking
into account the expert's confidence in a particular rule.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>5. Conclusion </title>
      <p>The models proposed for cyber incident identification by a SIEM system differ from existing models
in that they utilize fuzzy rules to identify incidents that occur during the operation of an information
and communication system. As a result, it becomes possible to mitigate the shortcomings that arise
from incomplete and inaccurate information in the identification process.</p>
      <p>OR
(13) 
OR
(14)
(15) </p>
      <p>Potential areas for future research include developing rule-oriented methods for detecting cyber
incidents using the proposed models in the SIEM system, along with techniques for generating fuzzy
production rules to apply within these methods.
6. References </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Fesokha</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Fesokha</surname>
          </string-name>
          ,
          <article-title>Analysis of existing intrusion prevention solutions in information and telecommunication networks, opened on the basis of publicly available licenses</article-title>
          ,
          <source>Information Technology and Security</source>
          Vol.
          <volume>5</volume>
          Iss. 1 (
          <year>2017</year>
          )
          <fpage>29</fpage>
          -
          <lpage>41</lpage>
          . doi:
          <volume>10</volume>
          .20535/
          <fpage>2411</fpage>
          -
          <lpage>1031</lpage>
          .
          <year>2017</year>
          .
          <volume>5</volume>
          .1.120554.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kubrak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Mykytiuk</surname>
          </string-name>
          ,
          <article-title>Architecture and functional model of a promising proactive intelligent system SIEM-system for cyber protection of critical infrastructure</article-title>
          ,
          <source>Information Technology and Security</source>
          Vol.
          <volume>7</volume>
          Iss. 2 (
          <year>2019</year>
          )
          <fpage>208</fpage>
          -
          <lpage>215</lpage>
          . doi:
          <volume>10</volume>
          .20535/
          <fpage>2411</fpage>
          -
          <lpage>1031</lpage>
          .
          <year>2019</year>
          .
          <volume>7</volume>
          .2.190570.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kubrak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Mykytiuk</surname>
          </string-name>
          ,
          <article-title>Methodology of rational choice of security incident management system for building operational security center</article-title>
          ,
          <source>CEUR Workshop Proceedings (CEUR-WS.org)</source>
          Vol.
          <volume>2577</volume>
          (
          <year>2019</year>
          )
          <fpage>11</fpage>
          -
          <lpage>20</lpage>
          . doi:
          <volume>10</volume>
          .5281/zenodo.7027782.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Gerasimov</surname>
          </string-name>
          ,
          <article-title>Quality indicators of information support and their impact on the effectiveness of decision support systems</article-title>
          , Bulletin of Taras Shevchenko National University of Kiev Vol.
          <volume>20</volume>
          (
          <year>2008</year>
          )
          <fpage>18</fpage>
          -
          <lpage>25</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>A. R.</given-names>
            <surname>Zope</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Vidhate</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Harale</surname>
          </string-name>
          ,
          <article-title>Data Mining Approach in Security Information</article-title>
          and EventManagement,
          <source>International Journal of Future Computer and Communication</source>
          Vol.
          <volume>2</volume>
          Iss. 2 (
          <year>2013</year>
          )
          <fpage>80</fpage>
          -
          <lpage>84</lpage>
          . doi:
          <volume>10</volume>
          .7763/IJFCC.
          <year>2013</year>
          .V2.126
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>F.</given-names>
            <surname>Salo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Injadat</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Nassif</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Shami</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Essex</surname>
          </string-name>
          ,
          <article-title>Data Mining Techniques in Intrusion Detection Systems: A Systematic Literature Review</article-title>
          ,
          <source>in Proc. IEEEAccess</source>
          Vol.
          <volume>6</volume>
          (
          <year>2018</year>
          )
          <fpage>56046</fpage>
          -
          <lpage>56058</lpage>
          . doi:
          <volume>10</volume>
          .1109/ACCESS.
          <year>2018</year>
          .
          <volume>2872784</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>D.</given-names>
            <surname>Selvamani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Selvi</surname>
          </string-name>
          ,
          <article-title>Association Rule Mining for Intrusion Detection System: A Survey</article-title>
          ,
          <source>Asian Journal of Engineering and Applied</source>
          Technology Vol.
          <volume>8</volume>
          Iss. 1 (
          <year>2019</year>
          )
          <fpage>20</fpage>
          -
          <lpage>24</lpage>
          . doi:
          <volume>10</volume>
          .51983/ajeat-2019.8.1.1065.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>L.</given-names>
            <surname>Mehrotra</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. S.</given-names>
            <surname>Saxena</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N. V.</given-names>
            <surname>Doohan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A Data</given-names>
            <surname>Classification</surname>
          </string-name>
          <article-title>Model: For Effective Classification of Intrusion in an Intrusion Detection System Based on Decision Tree Learning Algorithm</article-title>
          ,
          <source>Information and Communication Technology for Sustainable Development</source>
          vol
          <volume>9</volume>
          (
          <year>2018</year>
          )
          <fpage>61</fpage>
          -
          <lpage>66</lpage>
          . doi:
          <volume>10</volume>
          .1007/
          <fpage>978</fpage>
          -981-10-3932-
          <issue>4</issue>
          _
          <fpage>7</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>HC.</given-names>
            <surname>Chen</surname>
          </string-name>
          , SS. Kuo,
          <source>DoS Attack Pattern Mining Based on Association Rule Approach for Web Server, International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing. Innovative Mobile and Internet Services in Ubiquitous Computing</source>
          Vol.
          <volume>773</volume>
          (
          <year>2018</year>
          )
          <fpage>527</fpage>
          -
          <lpage>536</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -93554-6_
          <fpage>50</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>L.</given-names>
            <surname>Mehrotra</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. S.</given-names>
            <surname>Saxena</surname>
          </string-name>
          ,
          <source>An Assessment Report on: Statistics-Based and Signature-Based Intrusion Detection Techniques, Information and Communication Technology Springer. Advances in Intelligent Systems and Computing</source>
          Vol.
          <volume>625</volume>
          (
          <year>2018</year>
          )
          <fpage>321</fpage>
          -
          <lpage>327</lpage>
          . doi:
          <volume>10</volume>
          .1007/
          <fpage>978</fpage>
          - 981-10-5508-9_
          <fpage>31</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>R.</given-names>
            <surname>Shanmugavadivu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Nagarajan</surname>
          </string-name>
          ,
          <article-title>Network Intrusion Detection System using Fuzzy Logic</article-title>
          ,
          <source>Indian Journal of Computer Science and Engineering (IJCSE)</source>
          Vol.
          <volume>2</volume>
          Iss. 1.(
          <year>2011</year>
          )
          <fpage>101</fpage>
          -
          <lpage>111</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>C.</given-names>
            <surname>Gupta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Sinhal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Kamble</surname>
          </string-name>
          ,
          <article-title>An Enhanced Associative Ant Colony Optimization Technique-based Intrusion Detection</article-title>
          ,
          <source>Artificial Intelligence and Evolutionary Algorithms in Engineering Systems. Advances in Intelligent Systems and Computing</source>
          Vol.
          <volume>325</volume>
          (
          <year>2015</year>
          )
          <fpage>541</fpage>
          -
          <lpage>553</lpage>
          . doi:
          <volume>10</volume>
          .1007/
          <fpage>978</fpage>
          -81-322-2135-7_
          <fpage>58</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Mogylevych</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Mykytiuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kubrak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Fesokha</surname>
          </string-name>
          ,
          <article-title>Simulation Model of a Fuzzy Cyber Attack Detection System</article-title>
          ,
          <source>CEUR Workshop Proceedings (CEUR-WS.org)</source>
          Vol.
          <volume>3421</volume>
          (
          <year>2021</year>
          )
          <fpage>92</fpage>
          -
          <lpage>101</lpage>
          . doi:
          <volume>10</volume>
          .5281/zenodo.7247964.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>N.</given-names>
            <surname>Khamphakdee</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Benjamas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Saiyod</surname>
          </string-name>
          ,
          <article-title>Improving Intrusion Detection System Based on Snort Rules for Network Probe Attacks Detection with Association Rules Technique of Data Mining</article-title>
          ,
          <source>Journal of ICT Research and Applications</source>
          , Vol.
          <volume>8</volume>
          ,
          <issue>Iss</issue>
          .
          <volume>3</volume>
          , (
          <year>2015</year>
          )
          <fpage>234</fpage>
          -
          <lpage>250</lpage>
          . doi:
          <volume>10</volume>
          .5614/itbj.ict.
          <source>res.appl</source>
          .
          <year>2015</year>
          .
          <volume>8</volume>
          .
          <issue>3</issue>
          .4.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>R. R.</given-names>
            <surname>Tiwari</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. K.</given-names>
            <surname>Singh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Singh</surname>
          </string-name>
          ,
          <article-title>Self-Learning SIEM System Using Association Rule Mining</article-title>
          ,
          <source>Journal of Advanced Database Management &amp; Systems</source>
          Vol.
          <volume>2</volume>
          Iss. 2, (
          <year>2015</year>
          )
          <fpage>10</fpage>
          -
          <lpage>23</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Gerasimov</surname>
          </string-name>
          , E. Nikiforov,
          <article-title>Models of knowledge delivery for use in decision support systems</article-title>
          ,
          <source>Scientific and technical information</source>
          Vol.
          <volume>1</volume>
          (
          <issue>2005</issue>
          )
          <fpage>7</fpage>
          -
          <lpage>11</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kubrak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Mykytiuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Korotaev</surname>
          </string-name>
          ,
          <article-title>Rule-oriented method of cyber incidents detection by SIEM based on fuzzy logical inference</article-title>
          ,
          <source>CEUR Workshop Proceedings (CEURWS.org)</source>
          Vol.
          <volume>2859</volume>
          (
          <year>2020</year>
          )
          <fpage>210</fpage>
          -
          <lpage>219</lpage>
          . doi:
          <volume>10</volume>
          .5281/zenodo.7123656.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>L.</given-names>
            <surname>Zadeh</surname>
          </string-name>
          ,
          <article-title>The concept of a linguistic variable and its application to approximate reasoning</article-title>
          , Moscow, Mir,
          <year>1976</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>A.N.</given-names>
            <surname>Borisov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.A.</given-names>
            <surname>Krumberg</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I.P.</given-names>
            <surname>Fedorov</surname>
          </string-name>
          ,
          <article-title>Decision-making based on fuzzy models: examples of use</article-title>
          , Riga, Zinatne,
          <year>1990</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Zaichenko</surname>
          </string-name>
          , Operations Research: Fuzzy Optimization, Kiev, High school,
          <year>1991</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>A.</given-names>
            <surname>Piegat</surname>
          </string-name>
          , Fuzzy Modeling and Control, Physica-Verlag, Heidelberg,
          <year>2001</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>M.</given-names>
            <surname>Dodonov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Dodonova</surname>
          </string-name>
          ,
          <article-title>Automated detection system of insider attacks using fuzzy logic</article-title>
          ,
          <source>CEUR Workshop Proceedings (CEUR-WS.org)</source>
          Vol.
          <volume>1490</volume>
          (
          <year>2015</year>
          )
          <fpage>376</fpage>
          -
          <lpage>380</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>A.</given-names>
            <surname>Rothstein</surname>
          </string-name>
          ,
          <article-title>Medical diagnostics on fuzzy logic</article-title>
          , Vinnytsia, Continent-PRIM,
          <year>1996</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>A.</given-names>
            <surname>Rothstein</surname>
          </string-name>
          ,
          <article-title>Intelligent identification technologies: fuzzy sets, genetic algorithms, neural networks</article-title>
          , Vinnytsia,
          <string-name>
            <surname>UNIVERSUM</surname>
          </string-name>
          ,
          <year>1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>O.</given-names>
            <surname>Rothstein</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Chernovolyk</surname>
          </string-name>
          , E. Laryushkin,
          <article-title>Method of constructing membership functions of fuzzy sets</article-title>
          .
          <source>Bulletin of VPI</source>
          , Vol.
          <volume>3</volume>
          (
          <year>1996</year>
          )
          <fpage>72</fpage>
          -
          <lpage>75</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Mityushkin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Mokin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Rothstein</surname>
          </string-name>
          , Soft Computing:
          <article-title>identification of patterns of fuzzy knowledge bases: a monograph. Vinnytsia, UNIVERSUM-</article-title>
          <string-name>
            <surname>Vinnytsia</surname>
          </string-name>
          ,
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <surname>Rotshtein</surname>
            <given-names>A.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Katelnikov</surname>
            <given-names>D.I.</given-names>
          </string-name>
          <article-title>Identification of Nonlinear Objects by Fuzzy Knowledge Bases. Cybernetics and System Analysis Iss</article-title>
          .
          <volume>5</volume>
          (
          <year>1998</year>
          )
          <fpage>53</fpage>
          -
          <lpage>61</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <surname>Rotshtein</surname>
            <given-names>А</given-names>
          </string-name>
          .
          <article-title>Design and Tuning of Fuzzy Rule-Based Systems for Medical Diagnosis</article-title>
          . In N.- H. Teodorescu (ed):
          <source>Fuzzy and Neuro - Fuzzy Systems in Medicine</source>
          (
          <year>1998</year>
          )
          <fpage>243</fpage>
          -
          <lpage>289</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>