Assessment methodology for security of an automated control system of critical information infrastructure against DDoS attacks based on Monte Carlo simulation

V. Voevodin, V. S. Chernyaev, D. S. Burenok, I. V. Vinogradov
{"title":"Assessment methodology for security of an automated control system of critical information infrastructure against DDoS attacks based on Monte Carlo simulation","authors":"V. Voevodin, V. S. Chernyaev, D. S. Burenok, I. V. Vinogradov","doi":"10.21822/2073-6185-2023-50-1-62-74","DOIUrl":null,"url":null,"abstract":"Objective. The purpose of the study is to develop a methodology for assessing the security of an automated control system of critical information infrastructure from DDoS attacks. The purpose of the methodology development is to provide the decision–maker with a scientifically sound tool for assessing the risk of implementing a DDoS attack.Method. To achieve the stated goal of the study, simulation modeling based on the Monte Carlo method was used.Result. The expediency of using Monte Carlo simulation to assess the probability of server failure under DDoS attacks is confirmed. It was concluded that the server can be considered as a queuing system, however, the flow of incoming applications under DDoS attacks is not Poisson, so the use of analytical expressions to assess the probability of failure is considered incorrect. The simulation results allow the decision-maker to assess the probability of server failure and make organizational and technical decisions to increase the level of security. Analysis of the simulation results showed the effectiveness of improving server performance by increasing service channels.Conclusion. Thus, the developed methodology will be useful in conducting an information security audit of an organization to justify the amount of its insurance premium in the framework of cyber risk insurance. A possible direction for further research is to study the issue of computer network security, taking into account the features of a specific topology.","PeriodicalId":202454,"journal":{"name":"Herald of Dagestan State Technical University. Technical Sciences","volume":"138 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-05-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Herald of Dagestan State Technical University. Technical Sciences","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.21822/2073-6185-2023-50-1-62-74","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Objective. The purpose of the study is to develop a methodology for assessing the security of an automated control system of critical information infrastructure from DDoS attacks. The purpose of the methodology development is to provide the decision–maker with a scientifically sound tool for assessing the risk of implementing a DDoS attack.Method. To achieve the stated goal of the study, simulation modeling based on the Monte Carlo method was used.Result. The expediency of using Monte Carlo simulation to assess the probability of server failure under DDoS attacks is confirmed. It was concluded that the server can be considered as a queuing system, however, the flow of incoming applications under DDoS attacks is not Poisson, so the use of analytical expressions to assess the probability of failure is considered incorrect. The simulation results allow the decision-maker to assess the probability of server failure and make organizational and technical decisions to increase the level of security. Analysis of the simulation results showed the effectiveness of improving server performance by increasing service channels.Conclusion. Thus, the developed methodology will be useful in conducting an information security audit of an organization to justify the amount of its insurance premium in the framework of cyber risk insurance. A possible direction for further research is to study the issue of computer network security, taking into account the features of a specific topology.
基于蒙特卡罗模拟的关键信息基础设施自动化控制系统抗DDoS攻击安全性评估方法
目标。本研究的目的是开发一种评估关键信息基础设施自动化控制系统免受DDoS攻击的安全性的方法。开发该方法的目的是为决策者提供一种科学可靠的工具,用于评估实施DDoS攻击的风险。为了达到既定的研究目标,采用了基于蒙特卡罗方法的仿真建模。验证了利用蒙特卡罗仿真来评估DDoS攻击下服务器故障概率的方便性。结果表明,服务器可以看作是一个排队系统,然而,在DDoS攻击下,传入应用程序的流不是泊松的,因此使用解析表达式来评估失败概率被认为是不正确的。模拟结果允许决策者评估服务器故障的概率,并做出组织和技术决策,以提高安全级别。仿真结果表明,通过增加服务通道来提高服务器性能是有效的。因此,所开发的方法将有助于对组织进行信息安全审计,以证明其在网络风险保险框架内的保险费数额是合理的。一个可能的进一步研究方向是研究计算机网络安全问题,考虑到特定拓扑结构的特征。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信