<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">6</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/rmzt-68hn-ung8</article-id>
      <title-group>
        <article-title>Optimization of computer incident investigation algorithm in SIEM systems</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Оптимизация алгоритма расследования компьютерных инцидентов в SIEM-системах</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0007-7981-1146</contrib-id>
          <name>
            <surname>Chizhevsky</surname>
            <given-names>Maxim</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>ch.inc@yandex.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-5583-4972</contrib-id>
          <name>
            <surname>Serpeninov</surname>
            <given-names>Oleg</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>serpeninov53@mail.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-2273-725X</contrib-id>
          <name>
            <surname>Lapsar</surname>
            <given-names>Aleksey</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>lapsar1958@mail.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Rostov State University of Economics</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2025-09-30">
        <day>30</day>
        <month>09</month>
        <year>2025</year>
      </pub-date>
      <issue>3</issue>
      <fpage>69</fpage>
      <lpage>80</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/pib_3_5-6.pdf"/>
      <abstract xml:lang="en">
        <p>In the context of increasing frequency and complexity of cyberattacks, effective incident investigation has become a priority task in ensuring organizational information security. One of the key challenges in using SIEM systems for investigating computer incidents is the lack of formalized algorithmic approaches to the processing and analysis of security events. To address this issue, an algorithm has been developed to optimize the actions of specialists when analyzing suspicious activity in information systems. The algorithm covers the key stages of investigation – from event verification to the analysis of potential intruder actions. The results of the study demonstrate that formalizing investigation processes contributes to more effective incident response and reduces the time required for their resolution.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Incident investigation algorithm</kwd>
        <kwd>information security</kwd>
        <kwd>SIEM systems</kwd>
        <kwd>event analysis</kwd>
        <kwd>incident response</kwd>
        <kwd>cybersecurity</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
