Security incident detection technique for multilevel intelligent control systems on railway transport in Russia

Security monitoring and incident management systems has become the main research focus in the area of intelligent railway control systems. In the work we discuss a system architecture of multilevel intelligent control system on Russian Railway transport. We make a detail explanation of problems and tasks of security information and event management system as an important part of multilevel intelligent control system. We use a rough sets theory in order to detect abnormal activity in considered system. Our main result consists in development of simple and fast security incident detection techniques based on rough sets theory.