FIELD: information technology.
SUBSTANCE: invention relates to automated information systems, specifically to information security in information systems, and can be used to detect information and technical actions (ITA) on information systems. Detection ITA consists in collection of data containing data of information technology (IT), application of multiple rules to preprocessed information, classification of known types ITA, collecting information not containing IT data associated with ITA, subsets of the analysis base are formed such that at least one of the obtained information contains at least one feature ITA, wherein comparing the predetermined criterion with the IT related data to determine the lower value of the subjective probability in the form of a confidence function, comparing the predetermined criterion with the non-IT information to determine the upper value of the subjective probability in the form of a likelihood function, determining the values of the confidence function and the likelihood function; degree of similarity of current event with known ITA.
EFFECT: technical result consists in providing evaluation of impact classification veracity.
1 cl, 1 dwg
Authors
Dates
2019-09-18—Published
2019-03-22—Filed