Вестник Дагестанского государственного технического университета: Технические науки (May 2023)

Assessment methodology for security of an automated control system of critical information infrastructure against DDoS attacks based on Monte Carlo simulation

  • V. A. Voevodin,
  • V. S. Chernyaev,
  • D. S. Burenok,
  • I. V. Vinogradov

DOI
https://doi.org/10.21822/2073-6185-2023-50-1-62-74
Journal volume & issue
Vol. 50, no. 1
pp. 62 – 74

Abstract

Read online

Objective. The purpose of the study is to develop a methodology for assessing the security of an automated control system of critical information infrastructure from DDoS attacks. The purpose of the methodology development is to provide the decision–maker with a scientifically sound tool for assessing the risk of implementing a DDoS attack.Method. To achieve the stated goal of the study, simulation modeling based on the Monte Carlo method was used.Result. The expediency of using Monte Carlo simulation to assess the probability of server failure under DDoS attacks is confirmed. It was concluded that the server can be considered as a queuing system, however, the flow of incoming applications under DDoS attacks is not Poisson, so the use of analytical expressions to assess the probability of failure is considered incorrect. The simulation results allow the decision-maker to assess the probability of server failure and make organizational and technical decisions to increase the level of security. Analysis of the simulation results showed the effectiveness of improving server performance by increasing service channels.Conclusion. Thus, the developed methodology will be useful in conducting an information security audit of an organization to justify the amount of its insurance premium in the framework of cyber risk insurance. A possible direction for further research is to study the issue of computer network security, taking into account the features of a specific topology.

Keywords