Notation and modification of a methodology for detecting computer incidents in accordance with the GOST 59709-59712

DOI: 10.21293/1818-0442-2025-28-3-45-52

Download article in PDF format

JATS xml

Abstract: The paper describes the regulatory framework governing the operation of the state system aimed at identifying, preventing and eliminating the consequences of cyberattacks on the infor-mation resources of the Russian Federation. The authors pre-sent a notation of the process ащк detecting such attacks in accordance with the GOST 59709-59712 standards. A modifi-cation of the methodology for identifying computer attacks is proposed, which – unlike existing approaches based on signa-ture analysis – incorporates the use of machine learning algo-rithms. As a result of the study, a hybrid methodology for de-tecting computer incidents has been formulated, containing a formalized process notation that ensures compliance with the national standards, as well as mechanisms for predictive analy-sis based on machine learning.

Keywords: GosSOPKA, GOST 59709-59712, computer incident, methodology, IDF0 notation, machine learning

For citation:
Pavlychev A. V. Notation and modification of a methodology for detecting computer incidents in accordance with the GOST 59709-59712. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2025, vol. 28, no. 3, pp. 45–52. DOI: 10.21293/1818-0442-2025-28-3-45-52

Authors and copyright holders:

  • 1. Tsymbal V.N. [Analysis of the activities of government agencies of the Russian Federation in countering cybercrime]. Vestnik of Moscow University of the Ministry of Internal Affairs of Russia, 2024, no. 4, pp. 183–191 (in Russ.).
  • 2. Martins B. F. et al. Conceptual characterization of cybersecurity ontologies. IFIP Working Conference on The Practice of Enterprise Modeling, Springer International Publishing, 2020, pp. 323–338.
  • 3. Konev A. Functional Modeling as a Basis for Classifying Security Threats, International Siberian Conference on Control and Communications (SIBCON), IEEE, 2022, pp. 1–6.
  • 4. Soldatov E. et al. Incident Management System Modeling Issues. AISMA-2024: International Workshop on Advanced Information Security Management and Applications. ISMA 2024. Lecture Notes in Networks and Systems. Cham: Springer Nature Switzerland, 2024, vol. 863, pp. 293–299.
  • 5. Polishchuk O., Bobrova Y., Bobrov Y. The formation of a safety ecosystem in the context of ensuring the national homeland security. International Journal of Safety and Security Engineering, 2021, vol. 11, no. 6. pp. 683–689.
  • 6. Fuentes-García M., Camacho J., Maciá-Fernández G. Present and future of network security monitoring, IEEE Access, 2021, no. 9. pp. 112744–112760.
  • 7. Ullah F., Babar M. A. On the scalability of big data cyber security analytics systems. Journal of Network and Computer Applications, 2022, no. 198, p. 103294.
  • 8. Naseer A. et al. Real-time analytics, incident response process agility and enterprise cybersecurity performance: A contingent resource-based analysis. International Journal of Information Management, 2021, no. 59. p. 102334.
  • 9. Van der Kleij R. et al. Developing decision support for cybersecurity threat and incident managers. Computers & Security, 2022, no. 113, p. 102535.
  • 10. Salem A. H. et al. Advancing cybersecurity: a comprehensive review of AI-driven detection techniques. Journal of Big Data, 2024, vol. 11, no. 1, p. 105.
  • 11. Ghurab M. et al. A detailed analysis of benchmark datasets for network intrusion detection system. Asian Journal of Research in Computer Science, 2021, vol. 7, no. 4, pp. 14–33.
  • 12. Carvalho D. V., Pereira E. M., Cardoso J. S. Machine learning interpretability: A survey on methods and metrics. Electronics, 2019, vol. 8, no. 8, p. 832.
  • 13. Husselman L. Anomaly Detection with Windows Event Logs: A comparative study between traditional and ML based approaches. University of Zurich, 2024, 183 p.
  • 14. Pavlychev A.V., Starodubov M. I., Galimov A.D. [Using the Random Forest machine learning algorithm to identify complex computer incidents]. Voprosy kiberbezopasnosti, 2022, no. 5 (51), pp. 74–81 (in Russ.).
  • 15. Sattar S. et al. Anomaly detection in encrypted network traffic using self-supervised learning. Scientific Reports, 2025, vol. 15, no. 1, p. 26585.
  • 16. Salman H. A., Kalakech A., Steiti A. [Random forest algorithm overview]. Babylonian Journal of Machine Learning, 2024, vol. 2024, pp. 69–79.
  • 17. Ayua S. I. [Random forest ensemble machine learning model for early detection and prediction of weight category]. Journal of Data Science and Intelligent Systems, 2024, vol. 2, no. 4, pp. 233–240.
Editorial office address

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 701-582

  journal@tusur.ru

 

Viktor N. Maslennikov

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02

Subscription for updates