MODELING INFORMATION SECURITY SYSTEMS BASED ON MARKOV PROCESSES WITH DISCRETE STATES AND CONTINUOUS TIME: AN ANALYTICAL APPROACH TO MANDATORY SECURITY POLICIES

M. B. Zhelenkova · 2025

The article examines the use of continuous-time Markov processes with discrete states for modeling information security systems. An analytical approach is proposed to assess the effectiveness of mandatory security policies, which enforce strict regulations on access between subjects and objects of varying confidentiality levels. It is substantiated that the use of Markov models allows not only to reflect the probabilistic nature of threats but also to evaluate the resilience of a system to different types of attacks, considering their intensity and transition probabilities. The article outlines principles for constructing Markov chains that formalize the behavior of IS components under changing conditions and suggests quantitative methods for analyzing security metrics such as threat blocking probability, leakage probability, and average time the system remains vulnerable. The integration of mandatory policy rules into the model structure and their influence on transition pathways is analyzed. The potential for what-if analysis and model adaptation to dynamic environments is also demonstrated. The practical relevance of this approach is highlighted, offering a flexible, predictive, and regulated framework for maintaining information security in today’s digital landscape.

Read the paper · More papers on PaperTik