Abstract
Statement of the problem. The advancement of modern technologies has enabled adversaries to employ intelligent and sophisticated tools during the execution of multi-stage attacks to conceal their activities within the network infrastructure. Countering such attacks constitutes one of the primary objectives of information security monitoring for data transmission networks. Given this persistent challenge, there is a continuous demand for the development of novel countermeasures or the optimization of existing anomaly detection systems. These systems must not only facilitate more efficient acquisition of relevant information but also leverage this information to enhance the prediction of potential cyberattacks. Purpose: to determine the relationship between the probabilistic and temporal characteristics of the network security monitoring process. Results. А network security monitoring tool structure is proposed that utilizes streaming two-layer recurrent neural networks with controlled synapses to classify and predict multi-stage attacks. The network security monitoring process for a data transmission network was modeled to determine the impact of various factors. Software was developed to calculate the probabilistic and temporal characteristics of the network security monitoring process for a data transmission network under attacker attack. Theoretical significance. The model and software used allow for the formulation of requirements for various subprocesses of network security monitoring for a data transmission network. Practical Significance: The proposed model can serve as a foundational framework for the development of systems designed to prevent multi-stage attacks.