<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>Y. Kostiuk);</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Effectiveness of Information Security Control using Audit Logs</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Yevhen Ivanichenko</string-name>
          <email>y.ivanichenko@kubg.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Borys Grinchenko Kyiv Metropolitan University</institution>
          ,
          <addr-line>18/2 Bulvarno-Kudriavska str., 04053 Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Yuliia Kostiuk</institution>
        </aff>
      </contrib-group>
      <volume>000</volume>
      <fpage>0</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>With the ever-increasing interconnectedness of computers through corporate networks and the Internet, ensuring information security and implementing appropriate security policies and procedures is becoming increasingly important. An essential aspect of security is information registration in security audit logs. At present, information security is ensured through corporate application packages that use security agents specific to each platform. These agents are installed on workstations to provide security, but they have limited capabilities and are only part of the application suite. There is a need to find optimized solutions. When detecting an attack, the proactive audit system makes a decision on neutralization, taking into account the type of object and attack conditions, and performs various measures, such as notifying the administrator, blocking user access, and rebooting the workstation. The general model of proactive audit logs eliminates agents and places security audit logs on a remote server. The server can perform a thorough and intelligent analysis of audit logs to effectively verify and enforce security policies in a more comprehensive format. This paper aims to analyze and study the use of audit logs for security purposes in enterprise products.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;security audit</kwd>
        <kwd>information security</kwd>
        <kwd>audit log</kwd>
        <kwd>security policy</kwd>
        <kwd>monitoring</kwd>
        <kwd>security agents</kwd>
        <kwd>process model</kwd>
        <kwd>fuzzy Petri net</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        an assessment should be carried out regularly and is called an IS audit, which has been studied by
many scientists, including Ziro Aasso, Shara Toybayeva, Azamat Imanbayev, Zhaybergenova
Zhanshuak, Y. Xu, Y. Yang, T. Li, J. Ju and Q. Wang, Cheryl Vroom, Solms Rossouw,
EdegbemeBelaz Annamarie, Kerti Andras, Stephen Ganz, Gerat Tejasvini, Gerat Hemanta, Satoh Naoki,
Samejima Masaki, Wang Zhanjiang, Wang Shuoning, Wang Ling and others [
        <xref ref-type="bibr" rid="ref1 ref10 ref11 ref12 ref13 ref14 ref15 ref16 ref17 ref2 ref3 ref4 ref5 ref6 ref7 ref8 ref9">1–17</xref>
        ].
      </p>
      <p>
        There are various risk assessment and management approaches, including the statistical
method, the approach based on expert judgment and subjective probability, the
probabilisticstatistical approach, the theoretical-probabilistic method, and the risk calculation method.
However, these methods do not always adequately reflect real affairs, since the security system
must withstand specific IS threats and destructive actions against information assets. Therefore,
there is a need to develop IS audit methods that provide quantitative assessments and meet modern
information security requirements [
        <xref ref-type="bibr" rid="ref16 ref18">16, 18</xref>
        ].
      </p>
      <p>
        An essential element of ensuring information security is effective information security control,
particularly through audit logs that record all actions in computer systems and can be the basis for
analyzing security breaches [
        <xref ref-type="bibr" rid="ref19 ref20">19, 20</xref>
        ]. Each user action must be accurately recorded, contributing to
implementing a high-level information technology security policy. Integrating audit logs into
corporate product packages is vital in ensuring security and maintaining a proactive approach to
information technology security.
      </p>
      <p>In today’s information environment, sophisticated enterprise software packages that meet the
needs of large enterprises for integrated solutions include application management, business
process management, Internet control, network management, workstation and server management,
and security. In this context, security management includes security auditing based on checking
logs to identify entries that may indicate a security breach. However, this process only partially
solves the problem within large software packages, as most such products use similar principles
and methods to process logs and identify potential threats.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Model of the information security audit process</title>
      <p>The functional model of information security audit of an information system is a structured
approach that defines the stages, methodology, and criteria for assessing the security system’s
effectiveness [14, 16, 18, 21]. The process includes planning, information collection, risk
assessment, audit, analysis of results, report development, and follow-up. At the planning stage, the
audit’s goals, objectives, and scope are determined, and an audit consent is formed to conduct the
audit. Information gathering involves analyzing documentation, such as security policies and
procedures, and interviews with specialists and users to obtain details about the system’s
operation. Risk assessment involves identifying threats and vulnerabilities that could lead to
noncompliance with security requirements. Audit includes technical analysis and verification of
technical aspects of security and evaluation of compliance with policies and standards. The report
consists of documentation of the results, identified problems, and recommendations for
elimination. Upon completion of the audit, the implementation of recommendations is monitored,
and preparations are made for further audits to improve the security system [15–17, 22, 23]. The
model provides a comprehensive and systematic approach to ensuring the effectiveness of
information security of information systems (Fig. 1).
The model reflects the complexity of audit tasks and allows auditors to systematically and
effectively assess the degree of compliance of an information system with security requirements.
The built functional model is essential for ensuring high security and compliance with information
security standards.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Methodology for auditing the information security of an information system</title>
      <p>
        The development of an IS audit methodology for modernizing a security system that meets current
threats is essential and depends on assessing the effectiveness of such systems. To eliminate the
shortcomings of existing methods to evaluate the likelihood of realization of IS threats, which do
not take into account the sources of threats and destructive actions against information assets, a
new method for assessing the likelihood of realization of threats has been developed that allows
taking into account the parameters of threat sources, vulnerable links in the system and their
impact on critical assets [
        <xref ref-type="bibr" rid="ref15 ref16 ref17 ref20 ref23 ref24 ref25">15–17, 20, 23–25</xref>
        ]. This method improves the accuracy and objectivity of
IS threat assessment, considering a wide range of factors affecting security.
      </p>
      <p>An analysis of approaches to detecting internal attacks has revealed significant shortcomings in
prototype attack detection systems, complicating their implementation in corporate networks. The
problems are the complexity of implementation, the choice of methods for data collection, attack
detection, data processing, and load distribution on system components. Traditional methods, such
as signature and anomaly detection, do not provide effective attack detection. Neural
networkbased methods have certain advantages, but suffer from the complexity of setup, high resource
requirements, and difficulty in retraining. Therefore, existing approaches do not meet the
requirements of effective control over the conduct of an IS audit. Further research should help
improve attack detection systems and ensure high security in corporate networks. A promising
alternative is the development of active audit systems based on artificial intelligence, which
provide high speed, ease of training, and low resource consumption. “Active auditing” is a
continuous process of checking the system for compliance with the security policy and
automatically responding to deviations [13, 15, 17]. It combines elements of traditional audit and
intrusion detection systems, making it an effective tool for IS control. The security state of an
information system depends on a set of events occurring in the network. It is described by a fuzzy
network called a Petri net, which is used to model and analyze processes related to the control and
security of information systems. In particular, a fuzzy Petri net can model the information security
K ={ K 1∪ K 2∪ K 3∪ K 4∪ K 5∪ K 6 }.</p>
      <p>C f =( N , f , λ , m0) ,</p>
      <p>
        A fuzzy Petri net that describes the behavior of an information system has the following form:
where N is the structure of the fuzzy Petri net (Fig. 2), N =( P , T , I , O ); f ={f 1 , … , f u} is the
vector of values of the membership function of fuzzy transition triggering, f j∈ [
        <xref ref-type="bibr" rid="ref1">0,1</xref>
        ], j=1 , … , u;
λ= λ1 , … , λu is the vector of values of transition triggering thresholds, λ j∈ [
        <xref ref-type="bibr" rid="ref1">0,1</xref>
        ], j=1 , … , u; m0
0
is the vector of initial labeling, ml ∈ [
        <xref ref-type="bibr" rid="ref1">0,1</xref>
        ] , l=1 , … , n.
(1)
(2)
(3)
(4)
S={S1 , S2 , S3 , S4 , S5 },
      </p>
      <p>K ={ K 1 , … , K 6 },
where S1 is the state of normal functioning of an information system; S2 is the state of an attack on
an information system in which an attacker affects the information system to disrupt its normal
functioning; S3 is the state of violation of the confidentiality of information system resources; S4 is
the state of violation of the integrity of information system resources; S5 is the state of violation of
the availability of information system resources. The set of events in the information system is
determined:
where K 1 is the event of an intruder; K 2 is a set of events leading to a breach of confidentiality; K 3
is a set of events leading to a breach of integrity; K 4 is a set of events leading to a breach of
availability; K 5 is a set of events that trigger information system security measures; K 6 is a set of
events that result in the recovery of an information system after an attack.</p>
      <p>
        A set of events in an information system is a union of sets of events in an information system,
i.e.:
audit process by defining system states, audit-related actions, and their interactions. Audit logs can
be represented as one of the system elements. Modeling using fuzzy Petri nets is a powerful tool for
analyzing and optimizing audit processes, including the stages of information collection, analysis of
audit logs, detection of anomalies, and development of countermeasures. Each is a separate
subnetwork with defined transitions marked by audit activities. This approach allows you to
identify potential risks, analyze audit effectiveness, and develop optimal control strategies using
mathematical methods, which helps to improve security systems and detect threats. For this
purpose, a set of information systems states is defined:
The structure of the fuzzy Petri net N =( P , T , I , O ) is similar to the structure of a traditional
Petri net and can be represented by the following elements [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ]: P={ pl , … , pn} is a set of
positions of a fuzzy Petri net, T ={t1 , t 2 , … , tu} is a set of transitions of a fuzzy Petri net, u∈ N ; I
is the input function of transitions, I P × T →{0,1}; O is the output transition function,
O T × P→{0,1}.
      </p>
      <p>A base of rules for fuzzy inference is formulated, which defines the conditions for triggering the
transitions of the fuzzy Petri net. Each predicate from the compiled rules is matched with a
particular position of the fuzzy Petri net. Each position of P={ pl , … , pn} is matched with
elements of the sets S and K :</p>
      <p>P={S1 , K 1 , S2 , K 2 , K 3 , K 4 , K 5 , S3 , S4 , S5 , K 6 }.</p>
      <p>Next, the initial labeling vector is determined:</p>
      <p>m0=(m10 , m20 , m30 , m04 , m50 , m60 , m70 , m80 , m09 , m100 , m101) ,
where m10( l=1 , 3 , 8 , 9 , 10 ) are the values of the membership functions for the presence of
markers in positions S1 … S5 that is, the values of the membership functions that determine the
different states of the information system, m0 determines the value of the membership function for
2
the presence of a marker in a position K 1, which determines the probability of an intruder in the
information system, m0j ( j=4 , 5 , 6 ) are values of the membership functions for the presence of
markers in positions K 2, K 3, K 4, which leads to a violation of the confidentiality, integrity, and
availability of information in the information system, m0 determines the value of the membership
7
function for the presence of a marker in a position K 5, which determines the actual probability of a
correct response to an attack by active audit tools, m101 is the value of the membership function for
the presence of a marker in position K 6, which determines the probability of a correct response of
recovery tools after an attack, the values of the membership functions
0 0 0
m1=1 , m3,8,9,10=0 , m4,5,6=1 , f 18=1 are also accepted.</p>
      <p>
        The dynamics of changing the labels of a fuzzy Petri net are determined by the following rules
[
        <xref ref-type="bibr" rid="ref21">21</xref>
        ]:
1. The rule for determining the current marking any state of the fuzzy Petri net is determined by
the vector m , whose components are interpreted as the value of the membership function of
the presence of one marker in the corresponding positions of the fuzzy Petri net.
2. The rule of active transition t k ∈ T of a fuzzy Petri net is active if the condition is met:
0
m2 ≥ λ1 ,
(5)
(6)
(7)
(8)
(9)
min {ml }≥ λk ; (t ∈ {1,2 , … , n }) ∧( I ( pl , t k )&gt;0 ) .
3. Rule for fuzzy triggering of transition, if transition t k ∈ T of the fuzzy Petri net is active, then
fuzzy triggering leads to a new labeling mν , whose vector components are determined as
follows:
      </p>
      <p>ν
ml =0 , ( ∀ pl∈ P ) ∧ ( I ( pl , t k )&gt;0) ,
ν
m j =max {m j , min {ml , f k },(∀ pl ∈ P)∧( I ( pl , t k )&gt;0) },</p>
      <p>i ∈ {1,2 , … , n }∧ ( I ( pl , t k )&gt;0) .</p>
      <p>During the initial markup, the t1 link is active when:
i.e., if the probability of an attacker is greater than the threshold of the transition t1. Next, we
analyze the following transitions in the information system. If condition (9) is satisfied, then the
1 1
fuzzy triggering of the transition t1 will lead to a new labeling m1. At the same time m1=m2=0,
since the positions S1 and K 1 are input values for the transition. For the position
S2 ∙ m3=max {0 , min {m20 ,1 }}, i.e., m3=m ≥ λ1. All other positions remain unchanged, since
1 1 0</p>
      <p>2
m14,5,6=1, then the transitions t 2, t 3, and t 4 will be active when the conditions
m3&gt; λ2 , m13&gt; λ3 , m13&gt; λ4. Transition t5 will be active when the condition is met:
1
min {m13 , m71 }&gt; λ5 or min {m20 , m70 }&gt; λ5.
(10)
The analysis of expressions (9) and (10) indicates that achieving secure operation of the
information system is possible by: (a) increasing the value of the coefficient λ1, which can be
achieved by properly setting up the IS security policy; (b) reducing the value of the coefficient λ5,
which is the threshold of sensitivity of the active audit system. In addition, it is necessary to work
1
on increasing the value of the coefficient m .</p>
      <p>7</p>
      <p>
        The structure of the active audit system (Fig. 3) includes sensors for analyzing and processing
information about the functioning of the information system and user actions, a database for
storing the received information, a data analysis and processing unit for streaming input data and
generating control actions, a response unit that affects the information system, an administrator
console, and a log of the active audit system.
System sensors analyze system parameters and user actions, generating alerts for further
processing, detecting attempts to brute force passwords, mount media, and log in/out, and
statistical sensors generate profiles to record typical behavior. The data filter eliminates duplicate
alerts, increasing system efficiency. To improve signal processing, it is necessary to ensure reliable
storage of incoming information, fast signal processing for prompt detection of attacks and timely
decision-making, as well as secure storage of information for updating user profiles, using
encryption and data protection, which will increase the efficiency of the active audit system [
        <xref ref-type="bibr" rid="ref13 ref15 ref17 ref20 ref22 ref23 ref24 ref25">13, 15,
17, 20, 22–25</xref>
        ].
      </p>
      <p>The signature method, which is effective for known threats, and the neural network method,
which is capable of detecting new attacks but requires customization and significant computing
resources, are used to detect abnormalities. If an attack is detected, the active audit system makes a
decision based on fuzzy logic, considering the type of object and attack conditions, with the option
of notifying the administrator, blocking access, rebooting the workstation, or unloading programs.</p>
      <p>Critical information resources are initially identified, each of which is assigned importance
labels regarding confidentiality, integrity, and availability of information. The threat analysis
algorithm includes identifying potential threats, classifying them, creating an attacker model,
identifying protection methods, and assessing the level of security. After which, the possible
damage and probability of the threat being realized are evaluated, allowing for the creation of a
threat model for a particular organization. This approach ensures systematic threat management
and prevention of negative consequences.</p>
      <p>The threat realization rate Y indicates whether a specific threat will be realized in a given
system, taking into account the probability of the danger being discovered and the level of initial
protection of the valuable asset targeted by the threat. The formula calculates it:</p>
      <p>Y =
( X + K )
2</p>
      <p>,</p>
      <p>Y ∙ U
R=Z ∙ , 0 ≤ R ≤ 100 ,</p>
      <p>10
where Y is a threat realization, 0 ≤ Y ≤ 10; X is the probability of information security threats
realization, 0 ≤ X ≤ 10; K is the level of initial security of a valuable asset, 0 ≤ K ≤ 10.</p>
      <p>The information security risk level R means the probability of a particular adverse event
associated with the realization of a specific threat, which has a certain probability of occurrence
and can lead to potential damage. When calculating this indicator, it is vital to take into account
three parameters and use a special formula:
where U is the magnitude of the vulnerability; Y is the realization of threats; Z is the damage from
the realized threat. Once a risk is identified, it is essential to consider ways to mitigate it. There are
five primary methods: risk avoidance, risk transfer, risk reduction, radical risk reduction, and risk
acceptance.</p>
      <p>It is possible to assess an organization’s information security level only if you calculate the
value of several risks or risks for a particular block. For example: by security areas, by information
security measures, by valuable assets (employees of the organization). To determine the level of
information security of an organization by a block of parameters, it is necessary to:
(11)
(12)
(13)
(14)
(15)
l
Drj=1−∏ (1− Dgrj) ,
j=1
where Oij is the probability of occurrence of the ith threat source in the interests of realizing the
jth threat, n is the number of threat sources that can realize the jth security threat.</p>
      <p>Vulnerable links between the information system and its relationship with the considered IS
threats have been identified. The list of potential vulnerable links is determined based on the
developed questionnaires. The probability of exploitation of the vulnerable link characterizes each
vulnerable link. The relationship between vulnerable links and IS threats, based on the information
in the information security threat database, makes it possible to determine the likelihood of
exploiting vulnerable links in the interests of implementing the j threat:
where V kj is the probability of exploiting the k th vulnerable link in the interests of implementing
the jth threat, m is the number of vulnerable links through which the jth security threat can be
implemented.</p>
      <p>
        The destructive actions against critical information resources of the information system and the
probability of performing a specific destructive action based on the degree of importance of the
information system resources are determined [
        <xref ref-type="bibr" rid="ref17 ref19 ref23 ref24">17, 19, 23, 24</xref>
        ]. Each identified possible IS threat is
matched with destructive actions that may result from its implementation. The relationship is
based on analyzing information in the database of information security threats. The probability of
performing destructive actions against ther information asset as a result of the implementation of
the j threat as a result of the implementation of the j threat is calculated by the formula:
where Dgrj is the probability of performing the gth destructive action during the implementation of
the jth agrozone with the rth information resource, l is the number of harmful actions that will
result in the jth security threat.
      </p>
      <p>The same threat can be implemented against different information assets of an information
system. At the same time, it is considered realized if at least one destructive action has been
performed. Therefore, knowing the probability of each threat being discovered to each information
asset is necessary. Since the events that lead to the realization of IS threats are independent, the
probability of a security threat to ther information asset is calculated using the probability of the
product of events formula:
The probabilities of security threats tor information assets form a complete group, so the total
probability of a particular threat is calculated using the formula of total or average probability:
Prj=O j ∙ V j ∙ Dgrj .</p>
      <p>t</p>
      <p>1
P j=∑ Prj ∙ t ,
r=1
(17)
(18)
where t is the number of information assets to be protected in respect of which the jth IS threat
may be realized in respect of which the jth IS threat may be realized.</p>
      <p>To evaluate the security system’s effectiveness, it is necessary to assess its efficacy against each
current threat based on the measures taken to minimize the likelihood of this IS threat being
realized [15–17, 20, 22, 23]. The assessment will be based on the adequacy of measures that
compensate for the IS threats. The result of the study of ways to assess the effectiveness of the
protection system was the development of a method for determining the effectiveness of the ISMS
based on the Mamdani fuzzy inference system.</p>
      <p>For this purpose, each input and output variable is described as a linguistic variable in a
formalized form. The following variables are used:</p>
      <p>For this purpose, each input and output variable is described as a linguistic variable in a
formalized form. The following variables are used (Fig. 4):</p>
      <p>1. β x is “Threat probability” (probability of realization of an actual security threat) with the
scope of definition X =[ 0 , 100 ] and a set of base values</p>
      <p>T x={very low , low , medium , high , very high }={ax 1 , ax 2 , ax 3 , ax 4 , ax 5}.</p>
      <p>2. β y is “Compliance of measures” (compliance of measures to compensate for the IS threat)
with the scope of the definition Y =[ 0 , 100 ] and a set of baseline values</p>
      <p>T x={practically absent , small , moderate , high , very high }={a y 1 , a y 2 , a y 3 , a y 4 , a y 5}.
3. β z is “Protection system effectiveness” (Assessment of the effectiveness of the protection
system) with the scope of the definition Z =[ 0 , 100 ]and a set of baseline values
T x={not effective at all , insufficiently effective , moderately effective , effective , very effective }=
={az 1 , az 2 , az 3 , az 4 , az 5}.</p>
      <p>
        Membership functions are built for each of the variables. Trapezoidal functions built based on
expert opinions are used as membership functions (Fig. 4).
variables (a) “Probability of threat,” (b)
Fuzzy rules reflecting the relationship between input and output parameters are formed. Such
statements are presented as a matrix of positioning the effectiveness of the protection system
(Table 1).
The input values of the linguistic variables are located vertically and horizontally, and the output
variable values are located at the intersection. The graphs of membership functions and fuzzy rules
form a knowledge base that allows using the Mamdani fuzzy inference method to obtain a
quantitative output variable value. It is advisable to implement it in the MATLAB environment
using the FUZZY LOGIC package, which makes it possible to evaluate the effectiveness of the
protection system according to two specified input parameters [
        <xref ref-type="bibr" rid="ref10 ref11 ref15 ref16 ref17 ref19 ref23 ref25 ref3 ref8 ref9">3, 8–11, 15–17, 19, 23, 25</xref>
        ].
      </p>
      <p>An information security audit of an information system is conducted in the following sequence:
collecting initial data and describing the object of protection, identifying critical resources, sources
of threats and their probabilities, identifying vulnerabilities and their connection with current
threats, assessing destructive actions against information assets and the likelihood of threats,
evaluating protection measures and the effectiveness of the protection system for each threat, and
formulating recommendations for improving the protection system by regulatory requirements.
Figure 5: Algorithm for conducting an information security audit
This methodology, based on the input parameters and the results obtained, makes it possible to
make an informed decision on the modernization of the security system and the implementation of
a set of organizational and technical security measures. The proposed methodology can be used not
only for information systems but can also be easily adapted to other objects, such as grid systems,
virtual infrastructures, and cloud computing.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Determining the effectiveness of a security audit</title>
      <p>To assess the effectiveness, it is necessary to compare the most important factors of the developed
method with the benchmark factors. These factors should be significant enough to impact the
quality and effectiveness of the IS audit significantly. Such factors will be: objectivity of the results
of the IS audit, experience and qualifications of specialists conducting the IS audit, cost of the IS
audit, adaptation of the method to the specifics of the organization, and simplicity of the technique
in understanding and application. A benchmark is an “ideal” method of ensuring and conducting
an information security audit. The comparison is made by mathematical calculations using the
additive process.</p>
      <p>The additive method of calculating the IS audit method weight consists of a weighted sum of
private criteria. The weighting factor of the IS audit method is calculated within the framework of
the accepted additive model of the calculation method. The efficiency coefficient of the IS audit
method is as follows:
where S1 is a reference IS audit method; S2 developed IS audit method; W ( S ) is the effectiveness
coefficient (weight) of the IS audit method. The f index plays the role of the factor number; N is
the number of factors; af is a coefficient characterizing the contribution of each of the factors
N
sf ( S ) to the weight of the audit method’s effectiveness: ∑ af =1 ; 0 ≤ af ≤ 1; sf ( S ) are partial
f =1
indicators (coefficients) of a specific factor characterizing the quality and effectiveness of the IS
audit method 0 ≤ sf ( S ) ≤ 1. Coefficients af and partial indicators sf ( S ) are determined by experts
(Table 2).
The formula for the final values of the effectiveness of the reference method of IS audit S1 is as
follows:</p>
      <p>The formula for the final values of the effectiveness of the developed IS audit method S2 is as
follows:</p>
      <p>W ( S2)=0.35⋅s1( S2)+ 0.25⋅s2( S2)+ 0.15⋅s3 ( S2)+ 0.15⋅s4 ( S2)+ 0.10⋅s5 ( S2) ,</p>
      <p>W ( S1)=0.35⋅0.80+ 0.25⋅0.70+ 0.15⋅0.90+ 0.15⋅0.90+ 0.10⋅0.90=1.</p>
      <p>Based on the calculations, we can conclude that the effectiveness of the developed IS audit method
is W ( S2)=0 . 82. This is a relatively high indicator of the effectiveness and reliability of the
method.</p>
      <p>
        The advantages of the developed method are a high efficiency ratio, a combination of
quantitative and qualitative assessments, consideration of the organization’s characteristics, ease of
understanding and use, the ability to assess the level of IS without involving external specialists
and high costs, application at all stages of the organization’s existence and consideration of the
(19)
0.8
0.7
0.9
0.9
0.9
ratio of losses, threats, level of IS, attitude to risks and costs of ensuring IS [
        <xref ref-type="bibr" rid="ref10 ref11 ref15 ref16 ref17 ref19 ref23 ref25 ref3 ref8 ref9">3, 8–11, 15–17, 19, 23,
25</xref>
        ]. The disadvantages of the method are the lack of an estimate of losses and audit costs in
monetary terms and the need for highly qualified audit staff.
      </p>
    </sec>
    <sec id="sec-5">
      <title>5. Characterization of the security model based on secondary agents</title>
      <p>
        The enterprise application model is a structured approach to developing software to address
enterprise management and IT tasks, including functions such as software distribution, security,
logging, and network maintenance. It integrates various functions into a single product, providing
centralized management across devices and operating systems. An important aspect is improving
security with agents that monitor and respond to events, adapting to different platforms. However,
security is often secondary, creating opportunities to strengthen audit logs in a security context.
Enterprise software packages integrate system administration, which allows you to solve various
tasks of managing the company’s information environment. However, these programs have a
disadvantage in the security field, as security audit is only a secondary component, which opens up
opportunities to improve the effectiveness of audit logs [
        <xref ref-type="bibr" rid="ref15 ref16 ref17 ref20 ref22 ref24 ref25">15–17, 20, 22, 24, 25</xref>
        ].
      </p>
      <p>The agent-based security model uses software modules to monitor, analyze, and respond to
events in an information system. This allows automating monitoring and security processes,
particularly through control over security policies and threat detection. Security agents monitor
audit logs, recording violations of technical guidelines, adapting to different platforms and
operating systems. Still, their work requires specialists to create new rules for each security policy,
complicating management [10–13, 18, 19]. The limitations of the agent-based security model
include high resource consumption, agent compatibility with system elements, deployment
complexity, and the need for regular updates to respond to new threats. They can increase the load
on the system, reducing performance, especially if there are many policies, which complicates
management and requires significant effort to configure and maintain.</p>
      <p>
        Agents only select individual lines in audit logs, which limits the ability to detect threats
proactively. The isolation of agents on different platforms can reduce the effectiveness of detecting
threats associated with activities at various system levels. In addition, expensive enterprise
packages primarily available to large corporations put SMBs at a disadvantage, as existing tools
cannot perform detailed log analysis to detect serious security breaches. Agent-based security
models have limitations regarding the efficiency of searching and analyzing logs, which require
significant resources. It is optimal to use specialized servers to process logs, which will reduce
overhead costs, increase the effectiveness of security policies, and ensure the transition to a
proactive approach to security management [
        <xref ref-type="bibr" rid="ref15 ref16 ref17 ref23 ref24 ref25">15–17, 23–25</xref>
        ].
      </p>
    </sec>
    <sec id="sec-6">
      <title>6. Security model based on the primary agent</title>
      <p>
        The primary agent-based security model involves using agents to actively monitor user activity
and detect security breaches through analyzing audit logs, which allows for proactive threat
detection instead of a reactive response. This approach helps to prevent security breaches by
focusing on user activity, access to resources, and use of privileges, which increases the efficiency
of detecting and responding to threats to ensure information security. A prototype security model
based on a primary agent using proactive auditing was developed to effectively monitor user
activities, particularly to detect security breaches through audit logs, as opposed to the traditional
reactive approach [
        <xref ref-type="bibr" rid="ref19 ref20 ref5">5, 19, 20</xref>
        ].
      </p>
      <p>
        The overall concept of a proactive audit log differs from the agent approach used in a secondary
agent-based security model designed to reduce the processing overhead of application servers or
workstations. Compared to the traditional approach, where the agent is used on application servers
or workstations and adds processing to the normal activities of the computer, the new approach
proposes to use a dedicated log server that performs audit log analysis [
        <xref ref-type="bibr" rid="ref16 ref17 ref25">16, 17, 25</xref>
        ]. This server will
combine and duplicate all platform-independent audit logs created by computers in the company
(Fig. 6).
Proactive analysis of the audit log on the log server is carried out using modules that include
exception analysis, trending, and security status reporting, which allows you to effectively detect
security breaches and inform information security professionals about anomalies [
        <xref ref-type="bibr" rid="ref15 ref24 ref25">15, 24, 25</xref>
        ]. The
modules are part of the overall proactive audit model, which consists of four components: a
platform for data logging and duplication, a central server for storage and monitoring, task
modules for real-time analysis, and a security workstation with a graphical interface for interacting
with audit logs. The data logging platform provides segregated storage for analysis, preventing
impact on system performance. The log server acts as a central data repository and online
monitoring tool, generating reports whenever a breach is detected. Task modules perform real-time
analysis, including status, exception, and trend reports that identify security anomalies over long
periods, but are resource-intensive. The security workstation uses an interface to interact with logs
and automatically displays breach notifications. The model also includes an analysis tool using a
powerful query language for regular and one-time analysis of security logs. The goal is to create an
“intelligent system” that not only interprets events but also alerts personnel to potential security
breaches, responding to events that may occur in the future.
      </p>
    </sec>
    <sec id="sec-7">
      <title>7. Strengthening security in the overall proactive audit log model</title>
      <p>Strengthening the security of the general proactive audit log model involves measures to improve
the protection of the information environment, including maintaining access control, enhancing
security policies, monitoring threats, raising staff awareness, and regular auditing to identify
weaknesses. The model consolidates logs from different platforms (UNIX, Linux, etc.) on a central
log server, providing online monitoring and reporting functions for exceptions and system status.</p>
      <p>Integrating audit logs from different operating systems is challenging due to the lack of
common standards, which requires data cleansing to remove unnecessary information before
saving it. In addition, detecting security breaches involves the integration of intelligent alerts that
adapt to the severity of the incident, as well as specialized tools to implement high-level security
policies in the corporate environment.</p>
      <p>
        Recognition of hacker attacks is possible by identifying typical signs that appear in logs, which
allows for the development of scripts to detect security breaches by comparing data with
theoretical attack patterns [
        <xref ref-type="bibr" rid="ref15 ref16 ref17 ref23 ref24 ref25 ref4">4, 15–17, 23–25</xref>
        ]. The system should be able to determine the most
effective notification methods, considering the availability of security personnel. At the same time,
centralized log processing on a log server creates an additional load on the network due to
increased traffic associated with data duplication. The overall model includes highly developed
analysis tools and integration with other systems to identify security breach trends across different
platforms. This allows for the timely detection of potential threats and notification of the relevant
security authorities.
      </p>
    </sec>
    <sec id="sec-8">
      <title>Conclusion</title>
      <p>The effectiveness of information security audit control of information systems using audit logs
largely depends on the system’s ability to detect and respond to potential threats in real time. To
achieve high efficiency, collecting and processing audit data correctly and applying modern risk
assessment methods that allow you to monitor the system’s state and adapt protection by changing
threats is crucial. Using fuzzy Petri net models to model audit and security control enables you to
determine the effectiveness of measures and the interaction between different stages of the audit,
which increases the ability to predict new threats and respond quickly to them.</p>
      <p>The audit methodology, which includes a quantitative assessment of the security system’s
effectiveness, provides an opportunity to make informed decisions on improving security measures
and adapting them to new conditions. This universal approach can be adapted to different
information systems, including grid systems, virtual infrastructures, and cloud computing,
expanding these methods’ scope.</p>
      <p>An active audit system that uses fuzzy logic to make real-time decisions allows you to quickly
neutralize threats and identify new attack patterns through reverse tracking analysis. This
increases the reliability of protection and enables the generation of new security policies
automatically implemented in the system without user intervention. Prospects for further research
in this area will contribute to creating software that can effectively respond to unknown threats by
automatically creating new attack patterns and corresponding security policies.</p>
    </sec>
    <sec id="sec-9">
      <title>Declaration on Generative AI</title>
      <p>While preparing this work, the authors used the AI programs Grammarly Pro to correct text
grammar and Strike Plagiarism to search for possible plagiarism. After using this tool, the authors
reviewed and edited the content as needed and took full responsibility for the publication’s content.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>A.</given-names>
             
            <surname>Ziro</surname>
          </string-name>
          , et al.,
          <article-title>Research of the information security audit system in organizations</article-title>
          ,
          <source>in: IEEE Int. Conf. on Smart Information Systems and Technologies (SIST)</source>
          ,
          <year>2023</year>
          ,
          <fpage>440</fpage>
          -
          <lpage>444</lpage>
          . doi:
          <volume>10</volume>
          .1109/sist58284.
          <year>2023</year>
          .10223557
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>Y.</given-names>
             
            <surname>Xu</surname>
          </string-name>
          , et al.,
          <article-title>Review on cyber vulnerabilities of communication protocols in industrial control systems</article-title>
          ,
          <source>in: IEEE Conf. on Energy Internet and Energy System Integration (EI2)</source>
          ,
          <year>2017</year>
          ,
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . doi:
          <volume>10</volume>
          .1109/ei2.
          <year>2017</year>
          .8245509
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>A.</given-names>
             
            <surname>Mahfuth</surname>
          </string-name>
          , et al.,
          <article-title>A systematic literature review: Information security culture</article-title>
          ,
          <source>in: Int. Conf. on Research and Innovation in Information Systems (ICRIIS)</source>
          ,
          <year>2017</year>
          ,
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . doi:
          <volume>10</volume>
          .1109/icriis.
          <year>2017</year>
          .8002442
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>A.</given-names>
             
            <surname>Edegbeme-Beláz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
             
            <surname>Kerti</surname>
          </string-name>
          ,
          <article-title>A new approach to information security auditing in public administration</article-title>
          ,
          <source>Hadmérnök</source>
          ,
          <volume>17</volume>
          (
          <issue>3</issue>
          ) (
          <year>2022</year>
          )
          <fpage>109</fpage>
          -
          <lpage>131</lpage>
          . doi:
          <volume>10</volume>
          .32567/hm.
          <year>2022</year>
          .
          <volume>3</volume>
          .
          <fpage>8</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>D.</given-names>
             A. 
            <surname>Appelbaum</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
             
            <surname>Kogan</surname>
          </string-name>
          ,
          <string-name>
            <surname>M.</surname>
          </string-name>
           A. Vasarhelyi.
          <article-title>Analytical procedures in external auditing: A comprehensive literature survey and framework for external audit analytics</article-title>
          ,
          <source>J. Account. Lit</source>
          .
          <volume>40</volume>
          (
          <issue>1</issue>
          ) (
          <year>2018</year>
          )
          <fpage>83</fpage>
          -
          <lpage>101</lpage>
          . doi:
          <volume>10</volume>
          .1016/j.acclit.
          <year>2018</year>
          .
          <volume>01</volume>
          .001
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>S.</surname>
          </string-name>
           D. Gantz, IT audit fundamentals.
          <source>The basics of IT audit</source>
          ,
          <year>2014</year>
          ,
          <fpage>1</fpage>
          -
          <lpage>19</lpage>
          . doi:
          <volume>10</volume>
          .1016/b978-0
          <source>-12- 417159-6</source>
          .
          <fpage>00001</fpage>
          -
          <lpage>8</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>C.</given-names>
             
            <surname>Vroom</surname>
          </string-name>
          ,
          <string-name>
            <surname>R.</surname>
          </string-name>
           Solms,
          <article-title>Information security: Auditing the behaviour of the employee</article-title>
          ,
          <source>in: Security and Privacy in the Age of Uncertainty</source>
          ,
          <year>2003</year>
          ,
          <fpage>401</fpage>
          -
          <lpage>404</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-0-
          <fpage>387</fpage>
          -35691-4_
          <fpage>35</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>T.</given-names>
             
            <surname>Herath</surname>
          </string-name>
          ,
          <string-name>
            <surname>H.</surname>
          </string-name>
           
          <article-title>Herath, Information security auditing-A decision model for performance evaluation, SSRN Electr</article-title>
          . J.,
          <year>2010</year>
          . doi:
          <volume>10</volume>
          .2139/ssrn.1534192
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>O.</given-names>
             
            <surname>Kryvoruchko</surname>
          </string-name>
          , et al.,
          <article-title>Analysis of technical indicators of efficiency and quality of intelligent systems</article-title>
          ,
          <source>J. Theor. Appl. Inf. Technol</source>
          .
          <volume>101</volume>
          (
          <issue>24</issue>
          ) (
          <year>2023</year>
          )
          <fpage>127</fpage>
          -
          <lpage>139</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>Z.</given-names>
             
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
             
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <surname>L.</surname>
          </string-name>
           
          <article-title>Wang, Research on information security audit base on semantic web ontology and improve vector space model</article-title>
          ,
          <source>Int. J. Secur. Its App</source>
          .
          <volume>10</volume>
          (
          <issue>12</issue>
          ) (
          <year>2016</year>
          )
          <fpage>141</fpage>
          -
          <lpage>152</lpage>
          . doi:
          <volume>10</volume>
          .14257/ijsia.
          <year>2016</year>
          .
          <volume>10</volume>
          .12.12
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>A.</surname>
          </string-name>
           
          <article-title>Anon, Information system security audit, Manag</article-title>
          . Account. J.
          <volume>56</volume>
          (
          <issue>9</issue>
          ) (
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>M.</given-names>
             
            <surname>Gulzira</surname>
          </string-name>
          , et al.,
          <article-title>The audit method of enterprise's Information security</article-title>
          ,
          <source>in: 6th Int. Conf. on Engineering &amp; MIS (ICEMIS)</source>
          ,
          <year>2020</year>
          ,
          <fpage>1</fpage>
          -
          <lpage>5</lpage>
          . ACM. doi:
          <volume>10</volume>
          .1145/3410352.3410761
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>L.</given-names>
             
            <surname>Jin</surname>
          </string-name>
          , et al.,
          <article-title>Research on information security testing technology of relay protection equipment</article-title>
          ,
          <source>in: 2nd Int. Conf. on Testing Technology and Automation Engineering (TTAE)</source>
          ,
          <year>2022</year>
          , 11. SPIE. doi:
          <volume>10</volume>
          .1117/12.2660304
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>Y.</given-names>
             
            <surname>Kostiuk</surname>
          </string-name>
          , et al.,
          <article-title>Integrated protection strategies and adaptive resource distribution for secure video streaming over a Bluetooth network, in: Cybersecurity Providing in Information and Telecommunication Systems II</article-title>
          , vol.
          <volume>3826</volume>
          ,
          <year>2024</year>
          ,
          <fpage>129</fpage>
          -
          <lpage>138</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15] H. 
          <article-title>Janssen, Decentralized data processing: Personal data stores and the GDPR</article-title>
          ,
          <source>Int. Data Priv. Law</source>
          ,
          <volume>10</volume>
          (
          <issue>4</issue>
          ) (
          <year>2020</year>
          )
          <fpage>356</fpage>
          -
          <lpage>384</lpage>
          . doi:
          <volume>10</volume>
          .1093/idpl/ipaa016
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>Z.</given-names>
             
            <surname>Zeng</surname>
          </string-name>
          , et al.,
          <article-title>Watson: Abstracting behaviors from audit logs via aggregation of contextual semantics, in: 28th Annual Network and Distributed System Security Symposium</article-title>
          , NDSS,
          <year>2021</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>S.</given-names>
             
            <surname>Majumdar</surname>
          </string-name>
          , et al.,
          <article-title>Learning probabilistic dependencies among events for proactive security auditing in clouds</article-title>
          ,
          <source>J. Comput. Secur</source>
          .
          <volume>27</volume>
          (
          <issue>2</issue>
          ) (
          <year>2018</year>
          )
          <fpage>165</fpage>
          -
          <lpage>202</lpage>
          . doi:
          <volume>10</volume>
          .3233/jcs-181137
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18] N. U. 
          <string-name>
            <surname>Ibne Hossain</surname>
          </string-name>
          , et al.,
          <article-title>Modeling and assessing cyber resilience of smart grid using Bayesian network-based approach: a system of systems problem</article-title>
          ,
          <source>J. Comput. Des. Eng</source>
          .
          <volume>7</volume>
          (
          <issue>3</issue>
          ) (
          <year>2020</year>
          )
          <fpage>352</fpage>
          -
          <lpage>366</lpage>
          . doi:
          <volume>10</volume>
          .1093/jcde/qwaa029
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>O.</given-names>
             
            <surname>Kryvoruchko</surname>
          </string-name>
          , et al.,
          <article-title>Implementation of procedure for the identification of dynamic systems based on neural networks: Software engineering and cybersecurity</article-title>
          ,
          <source>in: Int. Conf. SECS-2022</source>
          ,
          <year>2023</year>
          , pp.
          <fpage>46</fpage>
          -
          <lpage>58</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20] T. H. Morris,
          <string-name>
            <given-names>P.</given-names>
             
            <surname>Shengyi</surname>
          </string-name>
          ,
          <string-name>
            <surname>U.</surname>
          </string-name>
           Adhikari,
          <article-title>Cyber security recommendations for wide area monitoring, protection, and control systems</article-title>
          ,
          <source>in: 2012 IEEE Power and Energy Society General Meeting</source>
          ,
          <year>2012</year>
          ,
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . doi:
          <volume>10</volume>
          .1109/pesgm.
          <year>2012</year>
          .6345127
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>C.</given-names>
             
            <surname>Lakos</surname>
          </string-name>
          ,
          <article-title>Object oriented modelling with object Petri nets</article-title>
          ,
          <source>in: Lecture Notes in Computer Science</source>
          ,
          <year>2001</year>
          ,
          <fpage>1</fpage>
          -
          <lpage>37</lpage>
          . doi:
          <volume>10</volume>
          .1007/3-540-45397-
          <issue>0</issue>
          _
          <fpage>1</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>Y.</given-names>
             
            <surname>Kostiuk</surname>
          </string-name>
          , et al.,
          <article-title>Research of methods of control and management of the quality of butter on the basis of the neural network</article-title>
          ,
          <source>in: Int. Conf. on Smart Information Systems and Technologies (SIST)</source>
          ,
          <year>2022</year>
          ,
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . doi:
          <volume>10</volume>
          .1109/sist54437.
          <year>2022</year>
          .9945764
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>Y.</given-names>
             
            <surname>Kostiuk</surname>
          </string-name>
          , et al.,
          <article-title>Information protection and data exchange security in wireless mobile networks with authentication and key exchange protocols</article-title>
          .
          <source>Cybersecur.: Edu. Sci. Technol</source>
          .
          <volume>1</volume>
          (
          <issue>25</issue>
          ) (
          <year>2024</year>
          )
          <fpage>229</fpage>
          -
          <lpage>252</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>C.</given-names>
             
            <surname>Regueiro</surname>
          </string-name>
          , et al.,
          <article-title>A blockchain-based audit trail mechanism: Design and implementation</article-title>
          .
          <source>Algorithms</source>
          <volume>14</volume>
          (
          <issue>12</issue>
          ) (
          <year>2021</year>
          )
          <article-title>341</article-title>
          . doi:
          <volume>10</volume>
          .3390/a14120341
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>F.</given-names>
             
            <surname>Yang</surname>
          </string-name>
          , et al.,
          <article-title>A flexible approach for cyber threat hunting based on kernel audit records</article-title>
          ,
          <source>Cybersecur</source>
          .
          <volume>5</volume>
          (
          <issue>1</issue>
          ) (
          <year>2022</year>
          ).
          <source>doi:10.1186/s42400-022-00111-2</source>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>