Detecting targeted attacks in order to counteract them in a timely manner requires an operational analysis of the information space using specialized monitoring systems. Such systems should provide not only hardware analysis of information attacks, but also quantitative analysis of the dynamics of these attacks, taking into account their specifics. In the event of an attack, the intensity of incidents of the attack flow, which is a time series by the number of information incidents over a certain period of time (usually per day), may contain information both about the fact of a targeted attack and about the phase of the scenario in which it is carried out. It is noted that the current detection of information security threats is mainly a manual process in which teams of analysts monitor suspicious events using auxiliary tools. The ability of analysts to recognize suspicious activity and the authority to make decisions about threats put people at the centre of the threat detection process. It is noted that excessive reliance on human abilities can lead to a large number of undetected threats. The author substantiates the need for a new detection paradigm that would be largely automa
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً