Abstract

The article presents a method of forming fuzzy associative rules with weighted attributes from the database (DB) of the SIEM to supplement its knowledge base (KB) in order to more effectively detect cyber incidents that occur during the operation of special information and communication systems (SICS). The problems that reduce the effectiveness of the application of existing methods for solving the problem of forming associative rules based on the analysis of information located in the database of cyber protection systems are considered. An analysis of publications devoted to methods in which attempts were made to eliminate these problems was made. The basic idea of eliminating the shortcomings inherent in known methods is formulated, which consists in finding a compromise between reducing the time of the computing algorithm that implements the method in practice and reducing information losses as a result of its operation. An improved method of finding associative rules from SIEM databases is proposed, which is based on the theory of fuzzy sets and linguistic terms. The problem of finding fuzzy associative rules with weighted attributes is formulated. The mathematical apparatus that forms the basis of the implementation of the method is given. An algorithm for finding frequent sets of elements, including the values of the signs of cyber incidents and the classes to which they belong, is proposed, which implements the first stage of the proposed method. The peculiarities of the structure of the test data sets used for training and testing of cyber protection systems were analyzed, and based on its results, a conclusion was drawn about the possibility of improving the considered algorithm. A graphic illustration of the idea of improving the algorithm for finding frequent sets of elements is given and the essence of its improvement is described. An improved algorithm for finding frequent sets of elements of the considered method is proposed and its main advantages are given.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call