Scholay

学术搜索 · AI 审稿 · LaTeX 协作

METHODS FOR AUTOMATING CYBERSECURITY INCIDENT INVESTIGATION BASED ON WINDOWS OPERATING SYSTEM LOGS USING PYTHON TO SUPPORT INFORMATION SECURITY MANAGEMENT

作者:O. Polotai, N. Kukharska, A. Tkachenko, Ievgeny Siedin, M. Nykolaichuk · 发表于:Cybersecurity: Education, Science, Technique · 年份:2026 · DOI:10.28925/2663-4023.2026.33.1219

The article presents an approach to the analysis and visualization of information security risks based on the processing of system and network logs using automation software. An algorithm in Python has been developed that provides collection, structuring and analysis of events occurring in the operating system and network devices in order to detect potentially suspicious activity. Pandas and datetime libraries were used for data processing, which allow for efficient work with large amounts of information and time stamps, and matplotlib was used to visualize the results, which provides a visual representation of patterns and anomalies. The algorithm classifies events according to certain criteria of suspicious activity, taking into account their type, frequency and time characteristics. The resulting graphical models allow assessing the level of risk in different segments of the system and making informed management decisions regarding information security. An experimental verification of the algorithm was carried out using real logs, which confirmed its effectiveness in early detection of anomalous behavior and optimization of monitoring processes. The results of the study emphasize the importance of integrating log analysis and data visualization methods into modern information security management systems. The use of automation software helps minimize the human factor, increase the accuracy of risk assessment and the efficiency of responding to threats. The article has pract...