<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">vdgtu</journal-id><journal-title-group><journal-title xml:lang="ru">Вестник Дагестанского государственного технического университета. Технические науки</journal-title><trans-title-group xml:lang="en"><trans-title>Herald of Dagestan State Technical University. Technical Sciences</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">2073-6185</issn><issn pub-type="epub">2542-095X</issn><publisher><publisher-name>Daghestan State Technical University</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.21822/2073-6185-2025-52-2-74-80</article-id><article-id custom-type="elpub" pub-id-type="custom">vdgtu-1772</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>ИНФОРМАЦИОННЫЕ ТЕХНОЛОГИИ И ТЕЛЕКОММУНИКАЦИИ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>INFORMATION TECHNOLOGY AND TELECOMMUNICATIONS</subject></subj-group></article-categories><title-group><article-title>Сервис управления и анализа инцидентов информационной безопасности</article-title><trans-title-group xml:lang="en"><trans-title>Information security incident management and analysis service</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Башарина</surname><given-names>О. Ю.</given-names></name><name name-style="western" xml:lang="en"><surname>Basharina</surname><given-names>O. Yu.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Ольга Юрьевна Башарина, кандидат технических наук, доцент кафедры бизнес-информатики</p><p>620144, г. Екатеринбург, ул.8 Марта, 62</p></bio><bio xml:lang="en"><p>Olga Yu. Basharina, Dr. Sci. (Eng.), Assoc. Prof.</p><p>62 8 Marta St., Yekaterinburg 620144</p></bio><email xlink:type="simple">basharinaolga@mail.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Буценко</surname><given-names>Е. В.</given-names></name><name name-style="western" xml:lang="en"><surname>Butsenko</surname><given-names>E. V.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Елена Владимировна Буценко, кандидат экономических наук, доцент кафедры бизнес-информатики</p><p>620144, г. Екатеринбург, ул.8 Марта, 62</p></bio><bio xml:lang="en"><p>Elena V. Butsenko, Dr. Sci. (Econ.), Assoc. Prof.</p><p>62 8 Marta St., Yekaterinburg 620144</p></bio><email xlink:type="simple">evl@usue.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Еремеев</surname><given-names>А. С.</given-names></name><name name-style="western" xml:lang="en"><surname>Eremeev</surname><given-names>A. S.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Артем Сергеевич Еремеев, студент</p><p>620144, г. Екатеринбург, ул.8 Марта, 62</p></bio><bio xml:lang="en"><p>Artem S. Eremeev, Student</p><p>62 8 Marta St., Yekaterinburg 620144</p></bio><email xlink:type="simple">artemdog77@gmail.com</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Уральский государственный экономический университет</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Ural State University of Economics</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2025</year></pub-date><pub-date pub-type="epub"><day>10</day><month>08</month><year>2025</year></pub-date><volume>52</volume><issue>2</issue><fpage>74</fpage><lpage>80</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Башарина О.Ю., Буценко Е.В., Еремеев А.С., 2025</copyright-statement><copyright-year>2025</copyright-year><copyright-holder xml:lang="ru">Башарина О.Ю., Буценко Е.В., Еремеев А.С.</copyright-holder><copyright-holder xml:lang="en">Basharina O.Y., Butsenko E.V., Eremeev A.S.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://vestnik.dgtu.ru/jour/article/view/1772">https://vestnik.dgtu.ru/jour/article/view/1772</self-uri><abstract><p>Цель. В работе рассмотрены вопросы проектирования и разработки сервиса для автоматизации процессов управления и анализа инцидентами информационной безопасности для металлургического предприятия; обследованы и описаны основные этапы и действия управления инцидентами на данном предприятии. Метод. Программный сервис, позволяющий автоматизировать процессы мониторинга, оценки и анализа нежелательных и неожиданных событий информационной безопасности, разработан в среде Visual Studio Code на высокоуровневом языке программирования Python. Для расширения функционала созданного программного приложения использовались дополнительные фреймворки и необходимые библиотеки. Хранение информации об инцидентах компании организовано в созданной базе данных. Результат. Описан алгоритм разработки программного сервиса, представлены примеры экранных форм данного приложения. Функционал сервиса позволяет получать различную аналитику: общий и детальный анализ произошедших инцидентов по типам, способам обнаружения, временны́м затратам на решение инцидента, уровню критичности, статусу, способу обнаружения, быстроте реагирования, причиненным последствиям. Вывод. Апробация программного сервиса в отделе информационной безопасности показала эффективное обнаружение новых атак и оперативную защиту информационных систем и автоматизированного оборудования предприятия. Анализ инцидентов направлен также на выявление проблемных участков в работе служб информационной безопасности компании, устранение которых позволит гораздо быстрее обнаруживать нежелательные события и минимизировать повторное появление инцидентов и их последствия.</p></abstract><trans-abstract xml:lang="en"><p>Objective. The paper considers the issues of designing and developing a service for automating the management and analysis of information security incidents for a metallurgical enterprise. The main stages and actions of incident management at the enterprise are examined and described. Methods. A software service that allows you to automate the processes of monitoring, evaluating and analyzing undesirable and unexpected information security events has been developed in the Visual Studio Code environment in the high-level Python programming language. To expand the functionality of the created software application, additional frameworks and the necessary libraries were used. The storage of information about the company's incidents is organized in the created database. Result. The article describes the algorithm for developing a software service, and provides examples of screen forms of this application. The functionality of the service allows you to receive various analytics: a general and detailed analysis of incidents by type, detection methods, time spent on solving the incident, the level of criticality, status, method of detection, speed of response, and the consequences caused. Conclusion. Testing of the software service demonstrated effective detection of new attacks and prompt protection of information systems and automated equipment of the enterprise. Incident analysis is aimed at identifying problem areas in the work of information security services, the elimination of which will allow for faster detection of unwanted events and minimization of the recurrence of incidents and their consequences.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>программная система</kwd><kwd>информационная безопасность</kwd><kwd>инцидент</kwd><kwd>угроза</kwd><kwd>распознавание</kwd><kwd>анализ</kwd><kwd>управление</kwd><kwd>реагирование</kwd></kwd-group><kwd-group xml:lang="en"><kwd>software system</kwd><kwd>information security</kwd><kwd>incident</kwd><kwd>threat</kwd><kwd>recognition</kwd><kwd>analysis</kwd><kwd>management</kwd><kwd>response</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Bandari V. Enterprise data security measures: a comparative review of effectiveness and risks across different industries and organization types. International Journal of Business Intelligence and Big Data Analytics. 2023; 6(1):1-11.</mixed-citation><mixed-citation xml:lang="en">Bandari V. Enterprise data security measures: a comparative review of effectiveness and risks across different industries and organization types. International Journal of Business Intelligence and Big Data Analytics. 2023; 6(1):1-11.</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Patterson C.M., Nurse J.R.C., Franqueira V.N.L. Learning from cyber security incidents: A systematic review and future research agenda // Computers &amp; Security. – 2023. – Т. 132. – С. 103309.</mixed-citation><mixed-citation xml:lang="en">Patterson C.M., Nurse J.R.C., Franqueira V.N.L. Learning from cyber security incidents: A systematic review and future research agenda. Computers &amp; Security. 2023;132:103309.</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Alarcon J.C.M. Information security: A comprehensive approach to risk management in the digital world //SCT Proceedings in Interdisciplinary Insights and Innovations. – 2023. – Т. 1. – С. 84-84.</mixed-citation><mixed-citation xml:lang="en">Alarcon J.C.M. Information security: A comprehensive approach to risk management in the digital world. SCT Proceedings in Interdisciplinary Insights and Innovations. 2023;1:84-84.</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Информационная технология. Методы и средства обеспечения безопасности. Менеджмент инцидентов информационной безопасности. ГОСТ Р ИСО/МЭК ТО 18044-2007. Москва: Стандартинформ, 2009. URL:https://rosgosts.ru/file/gost/01/040/gost_r_iso!mek_to_18044-2007.pdf (20.05.2024).</mixed-citation><mixed-citation xml:lang="en">Information technology. Methods and means of ensuring security. Information security incident management. GOST R ISO/IEC TO 18044-2007. Moscow: Standartinform, 2009. URL: https://rosgosts.ru/file/gost/01/040/gost_r_iso!mek_to_18044-2007.pdf (accessed: 05/20/2024). (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Олейникова А.А., Золотарев В.В. Концепция управления информационной безопасностью на основе цикла непрерывного детектирования и реагирования на инциденты безопасности информации // Известия ЮФУ. Технические науки. 2023. № 5(235). С. 66-81. DOI: 10.18522/2311-3103-2023-5-66-81.</mixed-citation><mixed-citation xml:lang="en">Oleinikova A.A., Zolotarev V.V. The concept of information security management based on a cycle of continuous detection and response to information security incidents. Izvestiya SFU. Technical sciences. 2023; 5(235):66-81. DOI: 10.18522/2311-3103-2023-5-66-81. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Трофимов Д.О., Шепелев М.С., Резниченко С.А. Организация реагирования на инциденты информационной безопасности // Вестник Дагестанского государственного технического университета. Технические науки. 2023. №4(50). С. 148-157. DOI: 10.21822/2073-6185-2023-50-4-148-157.</mixed-citation><mixed-citation xml:lang="en">Trofimov D.O., Shepelev M.S., Reznichenko S.A. Organization of response to information security incidents. Herald of the Daghestan State Technical University. Technical Sciences. 2023;4(50):148-157. DOI: 10.21822/2073-6185-2023-50-4-148-157. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Башарина О.Ю., Буценко Е.В., Похомчикова Е.О., Шильникова И.С. Технология корпоративной защиты персональных данных и конфиденциальной информации // Современные наукоемкие технологии. 2024. № 2. С. 8-14. DOI: 10.17513/snt.39924.</mixed-citation><mixed-citation xml:lang="en">Basharina O.Yu., Butsenko E.V., Pokhomchikova E.O., Shilnikova I.S. Technology of corporate protection of personal data and confidential information. Modern high-tech technologies. 2024; 2:8-14. DOI: 10.17513/snt.39924. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Солдатов Е.Ю., Селифанов В.В., Кувшинов М.А. Разработка системы контроля инцидентов информационной безопасности // Безопасность цифровых технологий. 2023. № 3(110). С. 54-66. DOI: 10.17212/2782-2230-2023-3-54-66.</mixed-citation><mixed-citation xml:lang="en">Soldatov E.Yu., Selifanov V.V., Kuvshinov M.A. Development of an information security incident control system. Security of digital technologies. 2023;3(110):54-66. DOI:10.17212/2782-2230-2023-3-54-66.</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Ehis A. T. Optimization of security information and event management (SIEM) infrastructures, and events correlation/regression analysis for optimal cyber security posture. Archives of Advanced Engineering Science. – 2023. – С. 1-10.</mixed-citation><mixed-citation xml:lang="en">Ehis A. T. Optimization of security information and event management (SIEM) infrastructures, and events correlation/regression analysis for optimal cyber security posture.Archives of Advanced Engineering Science. 2023;1-10.</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Рытов М.Ю., Голембиовская О.М., Кондрашова Е.В. Порядок оценки уровня эффективности системы непрерывного противодействия инцидентам информационной безопасности на объекте // Информация и безопасность. 2024. Т. 27. № 1. С. 135-142. DOI: 10.36622/1682-7813.2024.27.1.011.</mixed-citation><mixed-citation xml:lang="en">Rytov M. Yu., Golembiovskaya O.M., Kondrashova E.V. The procedure for assessing the level of effectiveness of the system of continuous counteraction to information security incidents at the facility. Information and Security. 2024;27(1):135-142. DOI: 10.36622/1682-7813.2024.27.1.011. (In Russ)</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Mouratidis H., Islam S., Santos-Olmo A., Sanchez L.E, Ismail M.U. Modelling language for cyber security incident handling for critical infrastructures.Computers &amp; Security. 2023;128:103139. DOI: 10.1016/j.cose.2023.103139</mixed-citation><mixed-citation xml:lang="en">Mouratidis H., Islam S., Santos-Olmo A., Sanchez L.E, Ismail M.U. Modelling language for cyber security incident handling for critical infrastructures.Computers &amp; Security. 2023;128:103139. DOI: 10.1016/j.cose.2023.103139.</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Naseer H., Desouza K.C., Maynard S.B., Ahmad A. Enabling cybersecurity incident response agility through dynamic capabilities: the role of real-time analytics // European Journal of Information Systems. 2024. V. 33. No. 2. P. 200-220. DOI:10.1080/0960085X.2023.2257168.</mixed-citation><mixed-citation xml:lang="en">Naseer H., Desouza K.C., Maynard S.B., Ahmad A. Enabling cybersecurity incident response agility through dynamic capabilities: the role of real-time analytics. European Journal of Information Systems. 2024;33(2): 200-220. DOI:10.1080/0960085X.2023.2257168.</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">Walter M., Heinrich R., Reussner R. Architecture-based attack path analysis for identifying potential security incidents. European Conference on Software Architecture. Cham: Springer Nature Switzerland. 2023; 37-53.</mixed-citation><mixed-citation xml:lang="en">Walter M., Heinrich R., Reussner R. Architecture-based attack path analysis for identifying potential security incidents. European Conference on Software Architecture. Cham: Springer Nature Switzerland. 2023; 37-53.</mixed-citation></citation-alternatives></ref><ref id="cit14"><label>14</label><citation-alternatives><mixed-citation xml:lang="ru">Kyriazoglou J. Improving Security Incident and Data Breach Responses // Information Security Incident and Data Breach Management: A Step-by-Step Approach. – Berkeley, CA : Apress, 2024. – С. 67-73.</mixed-citation><mixed-citation xml:lang="en">Kyriazoglou J. Improving Security Incident and Data Breach Responses. Information Security Incident and Data Breach Management: A Step-by-Step Approach. – Berkeley, CA : Apress, 2024; 67-73.</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
