In the article, the questions of modelling of complex security system networks are considered. The simulation model of operation of similar complexes and approbation of the offered approach to identification of the incidents are presented. The approach is based on detection of uncharacteristic alterations of the network operation mode. The results of the experiment allow one to draw a conclusion on possibility of the offered model application to analyse the current status of heterogeneous security systems. Also, it is confirmed that the application of short-term forecasting methods for the analysis of monitoring system data allows one to automate the process of formation the criteria to reveal the incidents.