<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="en">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">2</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/vzkp-rbuh-xd9m</article-id>
      <title-group>
        <article-title>Mathematical model of information security event management using Markov chain in industrial systems</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Математическая модель управления событиями информационной безопасности с использованием цепи Маркова в промышленных системах</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name>
            <surname>Markov</surname>
            <given-names>Georgy</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-2264-7513</contrib-id>
          <name>
            <surname>Krundyshev</surname>
            <given-names>Vasiliy</given-names>
          </name>
          <xref ref-type="aff" rid="aff2"/>
          <email>krundyshev_vm@spbstu.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-0232-7248</contrib-id>
          <contrib-id contrib-id-type="scopus">13103571000</contrib-id>
          <name>
            <surname>Zegzhda</surname>
            <given-names>Dmitry</given-names>
          </name>
          <xref ref-type="aff" rid="aff2"/>
          <email>zegzhda_dp@spbstu.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Jet Infosystems</aff>
      <aff id="aff2">Peter the Great St. Petersburg Polytechnic University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2024-06-20">
        <day>20</day>
        <month>06</month>
        <year>2024</year>
      </pub-date>
      <issue>2</issue>
      <fpage>20</fpage>
      <lpage>30</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2024_2_eng.pdf"/>
      <abstract xml:lang="en">
        <p>This paper examines the problem of ensuring information security in industrial Internet of Things systems. The study found that in order to comprehensively protect the information perimeter of an industrial enterprise from external and internal threats, in most cases information security event and incident management systems (SIEM systems) with customized rules for correlating events in the information infrastructure are used. At the same time, there is a need to create a mathematical apparatus that allows one to accurately and objectively assess the effectiveness of the SIEM system. As a result of the study, the problem of preventing information security incidents in industrial Internet of Things systems was formalized based on the developed mathematical model for managing information security events using a continuous-time Markov chain.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>mathematical model</kwd>
        <kwd>industrial Internet of things</kwd>
        <kwd>information security event management</kwd>
        <kwd>Markov chains</kwd>
        <kwd>SIEM system</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
