DOI

The article presents a clustering method for identifying file impacts used in information security incidents investigation. The proposed method is based on application of k-means clusterization algorithm with adapted automatic optimal cluster number determination algorithm. Precisely defined clusters amount allows to group data to describe file impacts. The article discusses preparation process of input data obtained from $UsnJrnl volume changes log records, as well as the algorithm for identifying complex file impacts based on the search for relationships between clusters. The proposed clustering method has a pronounced automated character, which allows a specialist that carries out an information security incident investigation to speed up the process of identifying and eliminating the consequences of an incident.
Translated title of the contributionA CLUSTERING METHOD FOR IDENTIFYING FILE IMPACTS BASED ON THE K-MEANS ALGORITHM USED IN INFORMATION SECURITY INCIDENTS INVESTIGATION
Original languageRussian
Pages (from-to)35-47
Number of pages13
JournalВестник УрФО. Безопасность в информационной сфере
Issue number1 (35)
DOIs
Publication statusPublished - 2020

    GRNTI

  • 81.93.00

    Level of Research Output

  • VAK List

ID: 13189617