№ 1 (71)

Contents of the 1st issue of the Cybersecurity Issues journal for 2026:

Title Pages
Dvoryankin, S. V. POTENTIAL INTELLIGIBILITY, A NEW INDICATOR OF SPEECH SECURITY / S. V. Dvoryankin // Cybersecurity issues. – 2026. – № 1(71). – С. 2-12. – DOI: 10.21681/2311-3456-2026-1-2-12.
Abstract
Research objective: to develop approaches for assessing speech intelligibility in confidential negotiation rooms, considering the intruder's capabilities in noise reduction and reconstruction of speech signals distorted by acoustic protection measures.
Research methods: digital signal and image processing, digital time-frequency analysis, image-based speech analysissynthesis, comprehensive theoretical and applied analysis of experimental results on improving intelligibility of speech distorted by noise and interference.
Results: limitations of existing methods for assessing the security of negotiation rooms against speech information leakage have been analyzed, which do not account for the capabilities of modern intelligibility restoration technologies.
It is shown that the potential intelligibility index adequately reflects the real abilities of a skilled intruder to extract semantics from noisy speech messages and can serve as a new indicator of speech information security in negotiation rooms.
Scientific novelty: new approaches to assessing the security of negotiation rooms are proposed, based on a comparative analysis of spectrogram images of the original and reconstructed signals. This aligns with the fact that the focus of research interest, both domestically and abroad, is actively shifting from classical intelligibility assessment metrics to models for its evaluation based on spectrogram images using deep learning methods and tools.
Practical significance: the obtained results will allow for the expansion of capabilities of existing speech information protection systems in negotiation rooms and the development of more effective means based on the presented approaches.
Keywords: speech information, speech information protection, speech intelligibility, potential intelligibility, spectrogram, noise reduction.
References
1. Khorev A. A., Porsev I. S. Veroyatnostny'j metod obosnovaniya pokazatelej i kriteriev e'ffektivnosti zashhity' rechevoj informacii ot ee utechki po texnicheskim kanalam // Vestnik UrFO. Bezopasnost' v informacionnoj sfere. 2024. № 2(52). S. 24–36.
2. Dvoryankin S. V. Sovremenny'e metody' i sredstva vosstanovleniya razborchivosti iskazhennoj rechevoj informacii // Informacionnaya bezopasnost' finansovo-kreditny'x organizacij v usloviyax cifrovoj transformacii e'konomiki / Pod red. S. I. Koz'miny'x. – Moskva: Obshhestvo s ogranichennoj otvetstvennost'yu «Izdatel'stvo Prometej», 2020. – S. 448–544.
3. Alyushin M. V., Alyushin A. M., Dvoryankin S. V., Dvoryankin N.S. Fiziologicheskie aspekty' postroeniya sonogramm i rekonstrukcii spektra iskazhenny'x rechevy'x vokalizmov // Bezopasnost' informacionny'x texnologij. 2025. T. 32. № 2. S. 32–47.
4. Khorev A. A., Dvoryankin S. V., Kozlachkov S. B., Vasilevskaya N. V. Analiz predel'ny'x vozmozhnostej metodov shumoponizheniya i rekonstrukcii rechevy'x signalov, maskiruemy'x razlichny'mi tipami pomex // Voprosy' kiberbezopasnosti. 2024. № 1(59). S. 89–100. DOI:10.21681/2311-3456-2024-1-89-100.
5. Dvoryankin S. V., Zenov A. E., Ustinov R. A., Dvoryankin N. S. Kodirovanie izobrazhenij spektrogramm dlya obespecheniya peremennoj skorosti peredachi audiodanny'x s soxraneniem kachestva ix zvuchaniya // Bezopasnost' informacionny'x texnologij. – 2021. – T. 28, № 4. – S. 22–38.
6. Dvoryankin S. V., Dvoryankin N. S., Alyushin A. M. By'stry'j sintez audiosignalov po izobrazheniyam spektrogramm v zadachax zashhity' rechevoj informacii // Voprosy' kiberbezopasnosti. 2024. № 5(63). S. 34–46. DOI:10.21681/2311-3456-2024-5-34-46.
7. Dvoryankin S. V., Dvoryankin N. S., Ustinov R. A. Rechepodobnaya pomexa, stojkaya k shumoochistke, kak rezul'tat skremblirovaniya zashhishhaemoj rechi // Voprosy' kiberbezopasnosti. 2022. № 5(51). S. 14–27. DOI:10.21681/2311-3456-2022-5-14-27.
8. Durakovskij A. P., Dvoryankin S. V., Dvoryankin N. S. E'volyuciya i napravleniya razvitiya texnologij maskirovaniya konfidencial'ny'x rechevy'x soobshhenij // Voprosy' kiberbezopasnosti. 2024. № 5(63). S. 58–66. DOI:10.21681/2311-3456-2024-5-58-66.
9. Dvoryankin S. V., Antipenko A. O. Primenenie fazovy'x xarakteristik golosovy'x vokalizmov v reshenii zadach zashhity' rechevoj informacii // Bezopasnost' informacionny'x texnologij = IT Security, Tom 28, № 2(2021), s. 2–33.
10. Dvoryankin S. V., Ustinov R. A. Formirovanie novogo podxoda k ocenke zashhishhennosti akusticheskoj (rechevoj) informacii // V knige: Kibernetika i informacionnaya bezopasnost' KIB-2023. Sbornik nauchny'x trudov Vserossijskoj nauchno-texnicheskoj konferencii. Moskva. 2023. S. 48–49.
11. Dvoryankin S. V., Dvoryankin N. S., Durakovskij A. P. Sovremenny'e podxody' k postroeniyu i modelirovaniyu intellektual'ny'x sistem zashhity' rechevoj informacii / V sbornike: Aktual'ny'e problemy' zashhity' informacii: sovremennost' i perspektivy'. Materialy' II Nauchnoprakticheskoj konferencii. Moskva, 2025. S. 71–77.
12. Stolbov M. B., Ivanov V. L., Analiz i modeli rechevy'x signalov – SPb.: NIU ITMO, 2024. – 97 s.
13. Dzhumaev A. B. O programmny'x sredstvax sinteza russkoj rechi // Nauchny'j rezul'tat. Informacionny'e texnologii. 2023. T. 8, № 2. – S. 3–10. DOI: 10.18413/2518-1092-2022-8-2-0-1.
14. Dzhumaev A. B. Metody' ocenivaniya kachestva sintezirovannoj rechi // Nauchny'j rezul'tat. Informacionny'e texnologii. 2021. T. 6, № 4. - S. 3–12. DOI: 10.18413/2518-1092-2021 -6-4-0-1.
15. Gauy M. M., Brookes M., Naylor P. A. The ICASSP 2021 Speech Intelligibility Prediction Challenge: Analysis and Outcomes // Proceedings of the IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). 2021. Pp. 431–435.
2–12
Mischenko, E. Yu.ASSESSMENT OF THE PROBABILITY OF IMPLEMENTATION OF INFORMATION SECURITY THREATS / E. Yu. Mischenko, A. A. Povyshev // Cybersecurity issues. – 2026. – № 1(71). – С. 13-19. – DOI: 10.21681/2311-3456-2026-1-13-19.
Abstract
Purpose of the study: to develop a methodology for quantitative (criterion) assessment of the probability of threats, taking into account the fact of vulnerability, competence of the intruder and relevance of the target.
Research method(s): applied analytical approach to assessing the probability of realization of threats to information security using a simple mathematical apparatus.
Result(s): the methodology of criterion evaluation of the probability of realization of threats to information security is proposed, taking into account the presence of vulnerabilities in the protected information system, the level of competence of the potential intruder, the relevance of achieving the goal of the intruder, including the size of possible damage and the probability of its timely detection and suppression.
Scientific novelty: the proposed methodology of criterion evaluation allows predicting the behavior of the intruder based on the assessment of the probability of successful completion of the attack, which contributes to improving the accuracy of the risk assessment process. The results of the study can be used to develop threat models and analyze information security risks.
Keywords: information security threat, information security incident, probability of threat realization, risk assessment.
References
1. Korolev I.D., Popov V.I., & Konovalenko S.A. (2020). Analytical treatment technique distributed during information security incidents in time, 12(5), 53-61.
2. Xarlamova (Shumajlova), V. A., Tanygin, M. O., & Dobrica, V. P. (2021). Quantitative Evaluationof Security Threatsto Different Information Systems. Information technologies in modeling and management: approaches, methods, solutions. III All-Russian scientific conference with international participation: collection of reports, 184–189.
3. Mal'cev, G. N., & Matveev, S. A. (2020). Mathematical models of the process of overcoming by an intruder of a multilevel information protection system. Proceeding sof the A. F. Mozhaisky Military Space Academy, (673), 126–135.
4. Mosolov, S. A., Krasnov, E. A., & Urban, A. N. (2022). On the Application of the Vulnerability Analysis Method of the Technological Process of the Production Facility to Ensure the Information Security of the Automated Process Control System, Taking into Account the Interrelation of Components. Information Technology Security, 38–52. https://doi.org/http://dx.doi.org/10.26583/bit.2022.3.03.
5. Baranov V. V. (2022). Models and methods for assessing the security of an informatization object. Vestnik SibGUTI, 3 (59), 14–28. 
6. Makarova, O. S, & Porshnev, S. V. (2021). Determination of parameters affecting the possibility of computer attack implemented by an intruder. Information Technology Security, 2(28), 6–20. https://doi.org/10.26583/bit.2021.2.01.
7. Makarova, O. S, & Porshnev, S. V. (2020). Assessment of Probabilities of Computer Attacks Based on the Method of Analysis of Hierarchies with Dynamic Priorities and Preference. Information Technology Security, 1(27), 6–18. https://doi.org/10.26583/bit.2019.4.01.
8. Butrina, E. P., & Oleinikov, V. P. (2021). Security - Objects and Events. Informatics, Computer Science and Control, 2(60), 86–90.
9. Butrina, E. P., & Oleinikov, V. P. (2021). Object Security: Event Structures and Scenario Approach. Informatics, Computer Science and Control, 3(61), 55–60.
10. Butrina, E. P., & Oleinikov, V. P. (2022). Object Security: Eventbased Threat Model. Informatics, Computer Science and Control, 4(66), 78–82.
11. Povyshev, A. A., Sokolov, A. N., & Mischenko, E. Y. (2023). Universal classification of threats to information security and its application to the development of a threat model and risk assessment. Vestnik UrFO. Security in the Information Sphere, 3(49), 68–80. https://doi.org/10.14529/secur230307.
13–19
Lapina, M. A.INVESTIGATION OF METHODS FOR DETECTING ATTACKS ON THE DNP3 PROTOCOL USING MACHINE LEARNING TECHNOLOGIES / M. A. Lapina, D. I. Shchepina, V. G. Lapin, E. A. Kenkov // Cybersecurity issues. – 2026. – № 1(71). – С. 20-30. – DOI: 10.21681/2311-3456-2026-1-20-30.
Abstract
The aim of the study is to analyze machine learning methods for detecting attacks on the distributed network protocol (DNP3) in critical infrastructure systems in order to improve the accuracy of classification of malicious traffic and reduce false positives.
Research methods: ensemble algorithms, neural networks, as well as methods of logistic regression and fuzzy logic were used. To assess the effectiveness of the models, cross-validation, principal component analysis, and the F-measure metric were used.
Results: The study showed that ensemble methods such as random forest and ensemble trees demonstrate the highest accuracy of F-measure = 0.999 in classifying attacks on the DNP3 protocol. The neural network model also achieved high results of F-measure = 0.999 with an optimal configuration of two hidden layers of 10 neurons each. anomaly detection tasks. Logistic regression and the naïve Bayesian classifier turned out to be less accurate due to the limitations associated with linear dependencies and the assumption of feature independence. The PCA analysis revealed that for most models,
the optimal number of components ranges from 8 to 47, while further increasing the number of components does not lead to a significant improvement in accuracy. The results highlight the superiority of ensemble approaches in cybersecurity tasks, especially when working with structured network traffic data.
Scientific novelty: the paper proposes an integrated approach to detecting attacks on the DNP3 protocol, combining machine learning methods with hyperparameter optimization and data preprocessing. The novelty of the research lies in the comparative analysis of the effectiveness of ensemble methods and neural networks for this task, as well as in the identification of optimal model configurations that provide high accuracy with minimal risk of overfitting.
Contribution of the authors: Lapina M. A. – general management of the project, development of the general concept of work and research methodology, coordination of the team's work, as well as analysis and interpretation of the results obtained; Shchepina D. I. – conducting an experiment, implementation of machine learning algorithms in the KNIME environment, setting up and optimizing models and preparing data for analysis; Lapin V. G. – development of a methodology for data preliminary processing, selection of significant features, analysis of the main component (PCA) and preparation of the technical documentation of the study; E.A. Kenkov – comparative analysis of the effectiveness of various machine learning methods, development of recommendations for optimizing model parameters, as well as preparation of the text part of the publication, including the presentation of results and drawing conclusions.
Keywords: distributed network protocol 3, cybersecurity, machine learning, attack detection, retraining, KNIME, critical infrastructure, traffic analysis, neural networks.
References
1. Altaha, M., & Hong, S. (2022). Anomaly Detection for SCADA System Security Based on Unsupervised Learning and Function Codes Analysis in the DNP3 Protocol. Electronics, 2022, 11(14), 2184. DOI: 10.3390/electronics11142184.
2. Rudnik S. N. Protokoly' mezhmashinnogo vzaimodejstviya promy'shlennogo interneta veshhej / S. N. Rudnik, A. I. Smirnov, K. V. Matroxina // Vy'sokie texnologii i innovacii v nauke: sbornik izbranny'x statej Mezhdunarodnoj nauchnoj konferencii, Sankt-Peterburg, 27 noyabrya 2020 goda. – Sankt-Peterburg: Chastnoe nauchno-obrazovatel'noe uchrezhdenie dopolnitel'nogo professional'nogo obrazovaniya Gumanitarny'j nacional'ny'j issledovatel'skij institut «NACzRAZVITIE», 2020. – S. 194–199. – DOI: 10.37539/VT188.2020.37.97.021.
3. Osobennosti ispol'zovaniya ob''ektov kriticheskoj informacionnoj infrastruktury' s sovremennoj sistemoj obnaruzheniya vtorzhenij / M.A. Bugorskij, M. A. Kaplin, S. V. Ostroczkij [i dr.] // Sciences of Europe. – 2021. – № 66-1(66). – S. 42–46. – DOI 10.24412/3162-2364-2021-66-1-42-46.
4. Marian, M., Cusman, A., Stîngă, F., Ionică, D., & Popescu, D. (2020). Experimenting with digital signatures over a DNP3 protocol in a multitenant cloud-based SCADA architecture. IEEE Access, 2020, 8, 156484–156503. DOI: 10.1109/ACCESS.2020.3019112.
5. Yadav, G., & Paul, K. (2021). Architecture and security of SCADA systems: A review. International Journal of Critical Infrastructure Protection, 34, 100433. DOI: 10.1016/j.ijcip.2021.100433.
6. Lapina, M. A., Kapshuk, N. R., Rusanov, M. A., Timofeeva, E. F. (2025). Detection of sql injection attacks through the network logs using machine learning methods. Proceedings of the Institute for System Programming of the RAS., 37(5), 81–92. DOI: 10.15514/ISPRAS-2025-37(5)-6.
7. Issledovanie metodov mashinnogo obucheniya dlya obnaruzheniya spufing-atak v decentralizovanny'x setyax / M. A. Lapina, R. A. Dy'muxa, N. N. Kucherov, E. S. Basan // Izvestiya YuFU. Texnicheskie nauki. 2025. № 3(245). S. 16-31. DOI: 10.18522/2311-3103-2025-3-16-31.
8. Lapina, M. A., Podruchny, N. V., Rusanov, M. A., Babenko, M. G. (2025) Research of machine learning methods for detecting network attacks. Proceedings of the Institute for System Programming of the RAS., 37(4), 147–174. DOI: 10.15514/ISPRAS-2025-37(4)-24.
9. Primenenie texnologij mashinnogo obucheniya dlya obnaruzheniya veb-atak / M. A. Lapina, V. V. Movzalevskaya, M. E. Tokmakova, M. G. Babenko, Moxammad Sadzhid // Voprosy' kiberbezopasnosti. 2024. № 4(62). DOI: 10.21681/2311-3456-2024-4-92-103.
10. Daniel, S. A., & Victor, S. S. (2024). Emerging trends in cybersecurity for critical infrastructure protection: A comprehensive review. Computer Science & IT Research Journal, *5*(3), 576–593. DOI: 10.51594/csitrj.v5i3.872.
11. Bolikulov, F., Nasimov, R., Rashidov, A., Akhmedov, F., & Cho, Y. I. (2024). Effective methods of categorical data encoding for artificial intelligence algorithms // Mathematics, 12(16), 2553. DOI: 10.3390/math12162553.
12. Sun, Y., Li, J., Xu, Y., Zhang, T., & Wang, X. (2023). Deep learning versus conventional methods for missing data imputation: A review and comparative study. Expert Systems with Applications, 227, 120201. DOI: 10.1016/j.eswa.2023.120201.
13. Breskuvienė, D., Dzemyda, G. (2023). Categorical feature encoding techniques for improved classifier performance when dealing with imbalanced data of fraudulent transactions. International Journal of Computers Communications & Control, 18(3), 5433. DOI: 10.15837/ijccc.2023.3.5433.
14. Ghrib, Z., Jaziri, R., & Romdhane, R. (2020, July). Hybrid approach for anomaly detection in time series data. In 2020 international joint
conference on neural networks (ijcnn) (pp. 1–7). IEEE. DOI: 10.1109/IJCNN48605.2020.9207013.
15. Borrohou, S., Fissoune, R., & Badir, H. (2023). Data cleaning survey and challenges–improving outlier detection algorithm in machine
learning. Journal of Smart Cities and Society, 2(3), 125–140. DOI: 10.3233/SCS-230008.
16. Charbuty, B., & Abdulazeez, A. (2021). Classification based on decision tree algorithm for machine learning. Journal of applied science
and technology trends, 2(01), 20–28. DOI: 10.38094/jastt20165.
17. Salman, H. A., Kalakech, A., & Steiti, A. (2024). Random forest algorithm overview. Babylonian Journal of Machine Learning, 2024, 69–79. DOI: 10.58496/BJML/2024/007.
18. Orrù, P. F., Zoccheddu, A., Sassu, L., Mattia, C., Cozza, R., & Arena, S. (2020). Machine learning approach using MLP and SVM algorithms for the fault prediction of a centrifugal pump in the oil and gas industry. Sustainability, 12(11), 4776. DOI: 10.3390/su12114776
19. Konstantinov, A. V., & Utkin, L. V. (2021). Interpretable machine learning with an ensemble of gradient boosting machines. Knowledge-Based Systems, 222, 106993. DOI: 10.1016/j.knosys.2021.106993.
20. Rincy, T. N., & Gupta, R. (2020, February). Ensemble learning techniques and its efficiency in machine learning: A survey. In 2nd international conference on data, engineering and applications (IDEA) (pp. 1–6). IEEE. DOI: 10.1109/IDEA49133.2020.9170675.
21. Gray, N., & Ferson, S. (2021). Logistic regression through the veil of imprecise data. arXiv preprint arXiv:2106.00492. DOI: 10.48550/arXiv.2106.00492.
22. Singh, H. P., Singh, N., Mishra, A., Sen, S. K., Swarnkar, M., & Pandey, D. (2024, February). Logistic regression-based sentiment analysis system: Rectify. In 2024 IEEE International Conference on Big Data & Machine Learning (ICBDML) (pp. 186–191). IEEE. DOI: 10.1109/ICBDML60909.2024.10577296.
23. Peretz, O., Koren, M., & Koren, O. (2024). Naive Bayes classifier–An ensemble procedure for recall and precision enrichment. Engineering Applications of Artificial Intelligence, 136, 108972. DOI: 10.1016/j.engappai.2024.108972.
24. Mirzakhanov, V. E. (2020). Value of fuzzy logic for data mining and machine learning: A case study. Expert Systems with Applications, 162, 113781. DOI: 10.1016/j.eswa.2020.113781.
25. Lu, J., Ma, G., & Zhang, G. (2024). Fuzzy machine learning: A comprehensive framework and systematic review. IEEE Transactions on Fuzzy Systems, 32(7), 3861-3878. DOI: 10.1109/TFUZZ.2024.3387429.
26. Bansal, M., Goyal, A., & Choudhary, A. (2022). A comparative analysis of K-nearest neighbor, genetic, support vector machine, decision tree, and long short-term memory algorithms in machine learning. Decision analytics journal, 3, 100071. DOI: 10.1016/j.dajour.2022.100071.
20–30
Poletykin, A. G.THE MATHEMATICAL APPARATUS OF THE METHOD OF AS-SESSING THE RISK FROM CYBER ATTACKS CALCYBER / A. G. Poletykin, K. V. Semenkov, V. G. Promyslov // Cybersecurity issues. – 2026. – № 1(71). – С. 31-41. – DOI: 10.21681/2311-3456-2026-1-31-41.
Abstract
The purpose of the study is to create a scientifically based and affordable technology for automating the management
of risks from cyber threats for ICS.
Research method(s): mathematical modeling.
Result(s) of the study: the paper describes and provides a method for calculating the risk from cyber threats for ICS of a new formalized method for assessing the risk from cyber-attacks CALCYBER, which is being developed at ICS RAS in order to create a scientifically based and affordable technology for automating activities to manage risks from cyber threats for automated process control systems (APCS). The method defines the concept of «production function» to denote protected
assets of the object of control and the «hidden function» for designating malicious inclusions in the ICS. The concepts of damage in the form of a function with values in an ordinal scale, requirements for the availability and integrity of software elements as Boolean functions are introduced. Based on the availability property, the criterion for the regular operation of the automated process control system is determined, and the formulas for calculating risks are given. The conditions
for searching for critical vulnerabilities and the stability of ICS cyber defense barriers are formulated. The reflection of the requirements of GOST R ISO/IEC 27005 in the developed CALCYBER method is analyzed. The article provides an example of the application of the developed method for vulnerability analysis, containing information about the CALCYBER project and existing software prototypes available for download and research.
Scientific novelty: for the first time, the concept of production and hidden functions is formalized, for which the method of risk assessment for ICS is formulated.

Keywords: ICS, attackers, vulnerabilities, integrity, availability, cyberattacks, risk management.
References
1. Promyslov V. G. i dr. Otsenka riska i obespechenie kiberbezopasnosti atomnykh elektrostantsii. Moskva: IPU RAN. 193 p. DOI: 10.18411/doicode-2023.100
2. Cherdantseva Y. et al. A review of cyber security risk assessment methods for SCADA systems // Computers & Security. Elsevier BV, 2016. Vol. 56. P. 1–27. DOI:10.1016/j.cose.2015.09.009.
3. Zharko E. F., Promyslov V. G. Approaches to risk assessment in cybersecurity of A-plant process control systems // Avtomatizatsiia v promyshlennosti. 2022. T. 11. DOI: 10.25728/avtprom.2022.11.06.
4. Aydinyan A. R., Tsvetkova O. L. Assessment of information security risks of automated system using neuro-fuzzy logic. Herald of Dagestan State Technical University. Technical Sciences. 2023; 50(2): 15–24. (In Russ.) DOI:10.21822/2073-6185-2023-50-2-15-24.
5. Joshi N. K., Lussier C. F., Kaldenbach K. The Role of Organizational Culture in Nuclear Security // The Challenges of Nuclear Security / Ed. Kapur S. P., Rajagopalan R. P., Wueger D. Cham: Springer International Publishing, 2024. P. 71–113. DOI:10.1007/978-3-031-56814-5_3.
6. Devi R. K. et al. Information Security Risk Assessment (ISRA): A Systematic Literature Review // J. Inf. Syst. Eng. Bus. Intell. 2022. Vol. 8, № 2. P. 207–217. DOI:10.20473/jisebi.8.2.207-217.
7. Kalashnikov A. O., Anikina E. V. Information risk management models of complex systems // Informatsiia i bezopasnost'. 2020. T. 23, № 2(4). P. 191–202.
8. Kalashnikov A. O. i dr. Application of the logical-probabilistic method in infor-mation security // Voprosy kiberbezopasnosti. 2025. Vol. 1. P. 65. DOI: 10.21681/2311-3456-2025-1-96-107.
9. Draeger J., Hahndel S. Formalized Risk Assessment for Safety and Security. arXiv, 2017. DOI:10.48550/arXiv.1709.00567.
31–41
Mashkina, I. V.ANALYSIS OF HYPER-CONVERGED INFRASTRUCTURE AS A PROTECTION OBJECT / I. V. Mashkina, K. S. Dunyushkina // Cybersecurity issues. – 2026. – № 1(71). – С. 42-50. – DOI: 10.21681/2311-3456-2026-1-42-50.
Abstract
Purpose of the study: conduct a systematic analysis of the research object, the Hyper-Converged Infrastructure (HCI), by building models of the object of protection and information security threats.
Methods of research: system analysis, decomposition, structural modeling, and the graphical standard for process modeling (Event-Driven Process Chain – EPC modeling).
Result: the paper analyzes the advantages of hyperconverged platforms and the specifics of their use in various fields, as well as the development of HCI and Kubernetes orchestrators by a Russian manufacturer, and the features of information risks in such systems. A conceptual model of hyperconverged infrastructure as an object of protection has been developed.
Specific objects of HCI security threats have been identified and systematized. A practical example using EPC modeling demonstrates a scenario of a threat in HCI.
Scientific novelty: for the first time, a hyperconverged infrastructure is considered as a holistic, emergent object of protection, and a structural verbal model of HCI is developed. A methodology for applying EPC modeling to formally describe and analyze complex, multi-component attack scenarios on HCI is proposed and tested, which allows for the visual identification of critical points of threat application and the logical conditions for their implementation.

Keywords: hyperconverged infrastructure, security object, threat model, attack scenario, EPC modeling, virtualization, containerization, Kubernetes.
References
1. Saleh A., Karslioglu M. Kubernetes in Production Best Practices: Build and manage highly available production-ready Kubernetes clusters // Publisher: Packt Publishing, – 2021. 292 s.
2. Levan M. 50 Kubernetes Concepts Every DevOps Engineer Should Know: Your go-to guide for making production-level decisions on how and why to implement Kubernetes // Publisher: Packt Publishing., 2023. 278 s.
3. Adhipta D., Widyawan S. Docker Swarm Orchestration for High Performance Computing Cluster as Container // 2023 6th International Seminar on Research of Information Technology and Intelligent Systems (ISRITI). – 21 March 2024.
4. Sergeev A., Rezedinova E., Khakhina A. Docker Container Performance Comparison on Windows and Linux Operating Systems // 2022 International Conference on Communications, Information, Electronic and Energy Systems (CIEES). – 30 December 2022.
5. Egorov V. B. E'volyuciya i perspektivy' koncepcii programmnogo opredeleniya // Sistemy' i sredstva informatiki. 2024. T.34. № 2. S. 83–94.
6. Egorov V. B. Programmnoe opredelenie seti v konvergentnoj i giperkonvergentnoj infrastrukturax // Sistemy' i sredstva informatiki. 2023. T. 33. № 1. S. 105–113.
7. Sagalaev. Yu. R., Romashkova O. N. Analiz giperkonvergentnoj vy'chislitel'noj infrastruktury' dlya xraneniya o obrabotki danny'x vy'sokonagruzhenny'x informacionny'x sistem // Sovremennaya nauka: Aktual'ny'e problemy' teorii i praktiki. Seriya: Estestvenny'e i texnicheskie nauki. 2021. № 6. S. 118–124.
8. Kavya Sri. B., Mahalakshmi K. Exploring Large Scale Docker Image Vulnerability and Storage Performance Analysis Using High Performance Container-Based Docker Environment // 2024 International Conference on System, Computation, Automation and Networking (ICSCAN). – 26 February 2025.
9. Mahajan V. B., Mane S. B. Detection, Analysis and Countermeasures for Container based Misconfiguration using Docker and Kubernetes // 2022 International Conference on Computing, Communication, Security and Intelligent Systems (IC3SIS). 15 September 2022.
10. Abbasova T. S., Semenov A. B., Abbasov T. E'. Ocenka e'ffektivnosti giperkonvergentny'x reshenij pri obrabotke bol'shix danny'x // Informacionno-texnologicheskij vestnik. 2023. № 2 (36). S. 63–75.
11. Zaid Alkilani M. O., Mashkina I. V. Razrabotka scenariev atak dlya ocenki ugroz narusheniya informacionnoj bezopasnosti v promy'shlennoj seti // Problemy' informacionnoj bezopasnosti. Komp'yuterny'e sistemy'. 2024. № 1(58). C. 96–109.
12. Mashkina I. V., Urazaeva A. M. Metod razrabotki bazy' znanij scenariev ugroz dlya sistemy' reagirovaniya na incidenty' (IRP) // Izvestiya YuFU. Texnicheskie nauki. 2024. № 5(241). S. 79–88.
42-50
Zharova, A. K.METHODS FOR DETECTING ILLEGAL CONTENT IN END-TO-END ENCRYPTED CONTENT / A. K. Zharova // Cybersecurity issues. – 2026. – № 1(71). – С. 51-58. – DOI: 10.21681/2311-3456-2026-1-51-58.
Abstract
The purpose of the study: to confirm or refute the hypothesis that the use of an integrated approach to the analysis of metadata, network structures and behavioral patterns in "closed" chats, supplemented by big data analysis technologies, makes it possible to achieve a significant increase in the efficiency of detecting illegal content without violating the human rights to privacy, communication, and confidentiality of information.
Research method(s): a set of theoretical-legal research methods, methods of mathematical-statistical and probabilistic modeling were used.
Result(s) of the study: the proposed method for detecting illegal content based on metadata analysis protects the confidentiality of personal data, since the analyzed metadata does not fall under any of the categories of personal data defined in the Federal Law "On Personal Data". but it all depends on the specific circumstances of data collection and analysis. In addition, the application of the proposed method will also not entail a violation of the legal requirements for respect for the right to privacy, since metadata cannot be attributed to any type of secret. In order to avoid a breach of confidentiality, a list of persons authorized to use metadata analysis technologies for national security purposes should be established, and mandatory requirements for the data processing process should be determined. Compliance with these conditions will minimize possible risks and threats.
The results of the study are important for the development of information security policy and legal regulation in the field of protection against illegal content.
Scientific novelty: in the proposal of a formalized probabilistic model for detecting illegal content in E2EE traffic based only on metadata, without decrypting the content of messages, while considering the legal restrictions on handling such data.

Keywords: messengers, end-to-end encryption, metadata analysis, big data, machine learning, information security, algorithmic moderation, Client-Side Scanning.
References
1. Putyato M. M. Klassifikaciya messendzherov na osnove analiza urovnya bezopasnosti xranimy'x danny'x / M. M. Putyato, A. S. Makaryan // Prikaspijskij zhurnal: upravlenie i vy'sokie texnologii. – 2019. – № 4(48). – S. 135-143. – DOI: 10.21672/2074-1707.2019. 48.4.135-143.
2. Patrin A. N. Razrabotka intellektual'noj sistemy' opoveshheniya nesankcionirovannogo dostupa / A. N. Patrin, A. I. Petrov, D. N. Titov // Intere'kspo Geo-Sibir'. – 2024. – T. 7, № 3. – S. 169–173. – EDN RGEKNR.
3. Nevolin A. O. Metody' ocenki e'ffektivnosti vualiruyushhix preobrazovanij internet-protokolov / A. O. Nevolin // Trudy' MAI. – 2020. – № 115. – S. 12. – DOI: 10.34759/trd-2020-115-12.
4. Anikin A. D. Analiz protokolov bezopasnosti na baze sistemy' rasprostraneniya licenziruemogo kontenta / A. D. Anikin, K. A. Biryukov, A. B. Arxipova // Bezopasnost' cifrovy'x texnologij. – 2023. № 1(108). S. 26–35. – DOI: 10.17212/2782-2230-2023-1-26-35.
5. Zharova A. K. Preduprezhdenie komp'yuterny'x atak tipa man in the middle, sovershaemy'x s ispol'zovaniem generativnogo iskusstvennogo intellekta / A. K. Zharova, V. M. Elin, B. R. Avetisyan // Voprosy' kiberbezopasnosti. – 2024. – № 6(64). – S. 28–41. – DOI: 10.21681/2311-3456-2024-6-28-41
6. Morozov V. E. Kompleksny'e resheniya dlya minimizacii vnutrennix ugroz informacionnoj bezopasnosti / V. E. Morozov, N. G. Miloslavskaya // Voprosy' kiberbezopasnosti. – 2024. – № 5(63). – S. 67–78. – DOI: 10.21681/2311-3456-2024-5-67-78.
7. Moskvitin G. I. Mexanizmy' analiza i sinteza sistem zashhity' ot nesankcionirovannogo dostupa k danny'm v informacionny'x sistemax / G. I. Moskvitin // Voprosy' zashhity' informacii. – 2019. – № 2(125). – S. 3–5. – EDN ZINJUL.
8. Zharova A. K. Internet-provajdery' kak sub''ekty' preduprezhdeniya seksual'noj prestupnosti v Internete / A. K. Zharova // Pravoprimenenie. – 2023. – T. 7, № 1. – S. 72–82. – DOI: 10.52468/2542-1514.2023.7(1).72-82.
9. Zharova A. K. Ispol'zovanie prediktivnoj analitiki v prognozirovanii prestupnosti: opy't SShA i otechestvenny'e praktiki / A. K. Zharova // Informacionnoe obshhestvo. – 2025. – № 5. – S. 40–52. – DOI: 10.52605/16059921_2025_05_40.
10. Dadashova A. S. Informacionnaya bezopasnost' i sistemny'j analiz: strategii zashhity' i analiz riskov / A. S. Dadashova, S. G. Nikolaeva, S. S. Dzhabagova // Nauchno-texnicheskij vestnik Povolzh'ya. – 2023. – № 12. – S. 239–241. – EDN ZNGXJG.
11. Somu, R. Analysis of Learner’s Emotional Engagement in Online Learning Using Machine Learning Adam Robust Optimization Algorithm / R. Somu, P. Ashok Kumar // Scientific Programming. – 2024. – Vol. 2024, No. 1. – P. 10.1155/2024/8886197. – DOI: 10.1155/2024/8886197
12. Shibzukhov, Z. M. Machine Learning Based on Minimizing Robust Mean Estimates / Z. M. Shibzukhov, T. A. Semenov // Lecture Notes in Computer Science. – 2021. – Vol. 12665 LNCS. – P. 112–119. – DOI: 10.1007/978-3-030-68821-9_11.
13. Smirnov Yu. V. Informacionny'j poisk dlya oblachny'x bibliotechny'x sistem: osobennosti lingvisticheskogo obespecheniya: avtoreferat dis. kan.tex.nauk: 05.25.05 — Moskva, 2020. — 23 s.
14. Zharova A. K. Analiz razmeshhaemy'x v seti otkry'ty'x danny'x v celyax polucheniya informacii o kriminogennoj obstanovke / A. K. Zharova, V. M. Elin, I. V. Atlasov // Voprosy' kiberbezopasnosti. – 2025. – № 4(68). – S. 152–159. – DOI: 10.21681/2311-3456-2025-4-152-159.
15. Wang Z., Fok K.-W., Thing V. L. L. Machine learning for encrypted malicious traffic detection: Approaches, datasets and comparative study // Computers & Security. 2022. Vol. 113. Art. 102542. DOI: 10.1016/j.cose.2021.102542.
51-58
Kalashnikov, A. O.METHODS FOR DETECTING ILLEGAL CONTENT IN END-TO-END ENCRYPTED CONTENT / A. O. Kalashnikov, E. V. Anikina, K. A. Bugaysky // Cybersecurity issues. – 2026. – № 1(71). – С. 59-68. – DOI: 10.21681/2311-3456-2026-1-59-68.
Abstract
The purpose of the research is to adapt the logical-probabilistic method of evaluating complex systems to the tasks of building information security systems in a multi-agent system.
Research method: the study uses the main provisions of the methodology of structural analysis, system analysis, decision-making theory, methods for assessing events under the condition of incomplete information, logical and probabilistic methods.
Result: This article continues to consider the issues of information security on the basis of the analysis of the relationship between the subjects and the object of protection, published earlier in the journal Cybersecurity Issues. Within the framework of the developed model, a definition is given and a method for the formation of the function of the algebra of logic, describing the ways to achieve the ultimate goal of the subject's activity in the information system, is proposed. Structural parameters of the function of the algebra of logic are developed, which allow to give quantitative and qualitative assessments of the possibility of the subject achieving the ultimate goal of his activity. It is shown that these parameters can be determined on the basis of the corresponding structure of links and estimates of the states of the relationships of agents on these links. The possibility of forming practical recommendations for the formation of the structure of agent connections in the information system is shown. The results obtained provide a reasonable calculation and use of assessments of the capabilities of the subject in terms of information security based on the use of the logical-probabilistic method.
Scientific novelty: consideration of the issues of information protection using the apparatus of mathematical and logical relations. Methods of quantitative assessment of the subject's capabilities to achieve the ultimate goal of his activity on the basis of the information resources of agents available to him have been developed. The possibility of obtaining quantitative estimates of the influence of the structure of relations between agents on the activity of the subject without involving probabilistic assessments of the state of relations between them has been shown. Within the framework of the application of the logical-probabilistic method, a formula for calculating the shortest paths for the initial scheme of connections, presented in the form of a perfect disjunctive normal form, was obtained. It is shown that the developed structural parameters of the algebra function of the logic of achieving the final goal of the subject can be used as initial data for predicting the actions of the subject, including from the point of view of estimating the required resources or choosing the optimal way to achieve the goal based on the availability and accessibility of these resources. Methods have been developed that allow obtaining integral assessments of the possibilities of achieving the ultimate goal of the subject for managing the structure of information flows and information resources both at the level of individual agents and various subsystems of modern information systems and systems as a whole.

Keywords: information security model, assessment of a complex system, logical-probabilistic method, theory of relations, system analysis.
References
1. Ryabinin, I. A. Reshenie odnoj zadachi ocenki nadezhnosti strukturno-slozhnoj sistemy raznymi logiko-veroyatnostnymi metodami / I. A. Ryabinin, A. V. Strukov // Modelirovanie i analiz bezopasnosti i riska v slozhnyh sistemah, Sankt-Peterburg, 19–21 iyunya 2019 goda. – Sankt-Peterburg: Sankt-Peterburgskij gosudarstvennyj universitet aerokosmicheskogo priborostroeniya, 2019. – Pp. 159–172.
2. Demin, A. V. Glubokoe obuchenie adaptivnyh sistem upravleniya na osnove logiko-veroyatnostnogo podhoda / A. V. Demin // Izvestiya Irkutskogo gosudarstvennogo universiteta. Seriya: Matematika. – 2021. – T. 38. – Pp. 65–83.
3. Viktorova, V. S. Vychislenie pokazatelej nadezhnosti v nemonotonnyh logiko-veroyatnostnyh modelyah mnogourovnevyh sistem / V. S. Viktorova, A. S. Stepanyanc // Avtomatika i telemekhanika. – 2021. – № 5. – Pp. 106–123.
4. Leont'ev, A. S. Matematicheskie modeli ocenki pokazatelej nadezhnosti dlya issledovaniya veroyatnostno-vremennyh harakteristik mnogomashinnyh kompleksov s uchetom otkazov / A. S. Leont'ev, M. S. Timoshkin // Mezhdunarodnyj nauchno-issledovatel'skij zhurnal. – 2023. – № 1(127). – Pp. 1–13.
5. Puchkova, F. Yu. Logiko-veroyatnostnyj metod i ego prakticheskoe ispol'zovanie / F. Yu. Puchkova // Informacionnye tekhnologii v processe podgotovki sovremennogo specialista: Mezhvuzovskij sbornik nauchnyh trudov / Ministerstvo prosveshcheniya Rossijskoj Federacii; Federal'noe gosudarstvennoe byudzhetnoe obrazovatel'noe uchrezhdenie vysshego obrazovaniya «Lipeckij gosudarstvennyj pedagogicheskij universitet imeni P.P. SEMENOVA-TYAN-SHANSKOGO». Tom Vypusk 25. – Lipeck: Lipeckij gosudarstvennyj pedagogicheskij universitet imeni P. P. Semenova-Tyan-Shanskogo, 2021. – Pp. 187–193.
6. Rossihina, L. V. O primenenii logiko-veroyatnostnogo metoda I.A. Ryabinina dlya analiza riskov informacionnoj bezopasnosti / L. V. Rossihina, O. O. Gubenko, M. A. CHernositova // Aktual'nye problemy deyatel'nosti podrazdelenij UIS: Sbornik materialov Vserossijskoj nauchno-prakticheskoj konferencii, Voronezh, 20 oktyabrya 2022 goda. – Voronezh: Izdatel'sko-poligraficheskij centr «Nauchnaya kniga», 2022. – Pp. 108–109.
7. Karpov, A. V. Model' kanala utechki informacii na ob"ekte informatizacii / A. V. Karpov // Aktual'nye problemy infotelekommunikacij v nauke i obrazovanii (APINO 2018): VII Mezhdunarodnaya nauchno-tekhnicheskaya i nauchno-metodicheskaya konferenciya. Sbornik nauchnyh statej. V 4-h tomah, Sankt-Peterburg, 28 fevralya – 01 marta 2018 goda / Pod redakciej S.V. Bachevskogo. Tom 2. – Sankt-Peterburg: Sankt-Peterburgskij gosudarstvennyj universitet telekommunikacij im. prof. M. A. Bonch-Bruevicha, 2018. – Pp. 378–382.
8. Metodika kiberneticheskoj ustojchivosti v usloviyah vozdejstviya targetirovannyh kiberneticheskih atak / D. A. Ivanov, M. A. Kocynyak, O. S. Lauta, I. R. Murtazin // Aktual'nye problemy infotelekommunikacij v nauke i obrazovanii (APINO 2018): VII Mezhdunarodnaya nauchno-tekhnicheskaya i nauchno-metodicheskaya konferenciya. Sbornik nauchnyh statej. V 4-h tomah, Sankt-Peterburg, 28 fevralya – 01 marta 2018 goda / Pod redakciej S. V. Bachevskogo. Tom 2. – Sankt-Peterburg: Sankt-Peterburgskij gosudarstvennyj universitet telekommunikacij im. prof. M. A. Bonch-Bruevicha, 2018. – Pp. 343–346.
9. Eliseev, N. I. Ocenka urovnya zashchishchennosti avtomatizirovannyh informacionnyh sistem yuridicheski znachimogo elektronnogo dokumentooborota na osnove logiko-veroyatnostnogo metoda / N. I. Eliseev, D. I. Tali, A. A. Oblanenko // Voprosy kiberbezopasnosti. – 2019. – № 6(34). – Pp. 7–16.
10. Kocynyak, M. A. Matematicheskaya model' targetirovannoj komp'yuternoj ataki / M. A. Kocynyak, O. S. Lauta, D. A. Ivanov // Naukoemkie tekhnologii v kosmicheskih issledovaniyah Zemli. – 2019. – T. 11, № 2. – Pp. 73–81.
11. Belyakova, T. V. Funkcional'naya model' processa vozdejstviya celevoj komp'yuternoj ataki / T. V. Belyakova, N. V. Sidorov, M. A. Gudkov // Radiolokaciya, navigaciya, svyaz': Sbornik trudov XXV Mezhdunarodnoj nauchno-tekhnicheskoj konferencii, posvyashchennoj 160-letiyu so dnya rozhdeniya A. S. Popova. V 6-ti tomah, Voronezh, 16–18 aprelya 2019 goda. Tom 2. – Voronezh: Voronezhskij gosudarstvennyj universitet, 2019. – Pp. 108–111.
12. Kalashnikov A. O. Primenenie logiko-veroiatnostnogo metoda v informatsionnoi bezopasnosti (Chast 1) / A. O. Kalashnikov, K. A. Bugaiskii, D. S. Birin, B. O. Deriabin, S. O. Tsependa, K. V. Tabakov // Voprosy kiberbezopasnosti. – 2023. – № 4(56). – Pp. 23–32. DOI:10.21681/2311-3456-2023-4-23-32.
13. Kalashnikov A. O. Primenenie logiko-veroiatnostnogo metoda v informatsionnoi bezopasnosti (Chast 2) / Kalashnikov A. O., Bugaiskii K. A., Anikina E. I., Pereskokov I. S., Petrov An. O., Petrov Al. O., Khramchenkova E. S., Molotov A.A. // Voprosy kiberbezopasnosti. – 2023. – № 5(57). – pp. 113–127. DOI:10.21681/2311-3456-2023-5-113-127.
14. Kalashnikov A.O. Primenenie logiko-veroiatnostnogo metoda v informatsionnoi bezopasnosti (Chast 3) / A.O. Kalashnikov A.O., K.A. Bugaiskii, E. I. Anikina, I. S. Pereskokov, An. O. Petrov, Al. O. Petrov, E. S. Khramchenkova, A. A. Molotov // Voprosy kiberbezopasnosti. – 2023. – № 6(58). – Pp. 20–34. DOI:10.21681/2311-3456-2023-6-20-34.
15. Kalashnikov A. O. Primenenie logiko-veroiatnostnogo metoda v informatsionnoi bezopasnosti (Chast 4) / A. O. Kalashnikov, K. A. Bugaiskii, E. I. Anikina, I. S. Pereskokov, An. O. Petrov, Al. O. Petrov, E. S. Khramchenkova, A. A. Molotov // Voprosy kiberbezopasnosti. – 2024. – № 3(61). – Pp. 23–32. DOI:10.21681/2311-3456-2024-3-23-32.
16. Kalashnikov, A. O. Model otsenki bezopasnosti slozhnoi seti (Chast 1) / A. O. Kalashnikov, K. A. Bugaiskii, A. A. Molotov // Voprosy kiberbezopasnosti. – 2022. – № 4(50). – Pp. 26–38. DOI:10.21681/2311-3456-2022-4-26-38.
17. Kalashnikov A. O. Primenenie logiko-veroiatnostnogo metoda v informatsionnoi bezopasnosti (Chast 5) / A. O. Kalashnikov, K. A. Bugaiskii, E. I. Anikina, I. S. Pereskokov, An. O. Petrov, Al. O. Petrov, E. S. Khramchenkova, A. A. Molotov // Voprosy kiberbezopasnosti. – 2024. – № 4(62). – Pp. 26–37. DOI:10.21681/2311-3456-2023-4-26-37.
18. Kalashnikov A. O. Primenenie logiko-veroiatnostnogo metoda v informatsionnoi bezopasnosti (Chast 6) / A.O. Kalashnikov, K.A. Bugaiskii, E. I. Anikina, A. A. Molotov // Voprosy kiberbezopasnosti. – 2024. – № 1(65). – Pp. 96–107. DOI:10.21681/2311-3456-2024-1-96-107.
59-68
Gorbachev, A. A.METHOD OF INTELLIGENT SIMULATION OF TOPOLOGICAL CHARACTERISTICS OF COMPUTER NETWORKS IN NETWORK RECONNAISSANCE / Gorbachev A. A. // Cybersecurity issues. – 2026. – № 1(71). – С. 69-80. – DOI: 10.21681/2311-3456-2026-1-69-80.
Abstract
The purpose of the study: development of a method that includes classes of random graph models, metaheuristic algorithms for numerical optimization, and generative machine learning models, designed to solve the problem of intelligent imitation of the topological characteristics of computing networks in order to counteract cyber reconnaissance by intruders, taking into account the algorithmic complexity and resource limitations of security measures.
Methods used: weighted ideal point method, random graph model, modified genetic algorithm of numerical optimization, Bayesian optimization algorithm, convolutional variational autoencoder model, backpropagation method.
The result of the study: the presented method allows us to ensure counteraction of computer intelligence by demonstrating to the attacker false topological characteristics of the computing network by optimizing the number and connectivity indicators of false and real nodes, taking into account the requirements for resource constraints on the creation and maintenance of false information directions and nodes.
Scientific novelty: consists in the development of a method for intelligent simulation of the topological characteristics of computational networks, which differs from the known method by using a modified genetic algorithm and a random graph model based on binary random vectors of variable length to form a training array, and by applying a Bayesian algorithm to select the optimal point for synthesizing a false topology of a computational network from the hidden space of a trained
variational autoencoder, which corresponds to the minimum Cartesian distance from the ideal point to the current point in the weighted criterion space.

Keywords: generative models, deep learning, time complexity, computational attacks, directed graphs, augmentation, sliding window.
References
1. Markov A. S. Bezopasny'e informacionny'e texnologii – 2025 // Bezopasnost' informacionny'x texnologij. 2025. T. 32. №. 4. S. 217–221.
2. Gorbachev A. A. Maskirovanie topologicheskix svojstv vy'chislitel'ny'x setej. Chast' 1 // Voprosy' kiberbezopasnosti. 2024. № 6(64). S. 130–139. DOI: 10.21681/2311-3456-2024-6-130-139.
3. Gorbachev A. A. Maskirovanie topologicheskix svojstv vy'chislitel'ny'x setej. Chast' 2 // Voprosy' kiberbezopasnosti. 2025. № 1(65). S. 63–72. DOI: 10.21681/2311-3456-2025-1-63-72
4. Maksimov R. V., Telen'ga A. P. Koncepciya protivodejstviya identifikacii metastruktur korporativny'x informacionny'x sistem na urovne perkolyacionny'x klasterov kiberprostranstva // Sistemy' upravleniya, svyazi i bezopasnosti. 2024. № 4. S. 179-222. DOI: 10.24412/2410-9916-2024-4-179-222.
5. Telen'ga A. P. Maskirovanie metastruktur informacionny'x sistem v kiberprostranstve // Voprosy' kiberbezopasnosti. 2023. № 5(57). S. 50-59. DOI: 10.21681/2311-3456-2023-5-50-59.
6. Sherstobitov R. S. Model' maskirovaniya informacionny'x napravlenij setej peredachi danny'x vedomstvennogo naznacheniya v usloviyax komp'yuternoj razvedki // Sistemy' upravleniya, svyazi i bezopasnosti. 2025. № 1. S. 79-104. DOI: 10.24412/2410-9916-2025-1-079-104.
7. Moskvin A. A., Maksimov R. V., Gorbachev A. A. Model', optimizaciya i ocenka e'ffektivnosti primeneniya mnogoadresny'x setevy'x soedinenij v usloviyax setevoj razvedki // Voprosy' kiberbezopasnosti. 2023. № 3(55). S. 13–22. DOI 10.21681/2311-3456-2023-3-13-22.
8. Kaverin S. S., Maksimov R. V., Moskvin A. A. Model' processa funkcionirovaniya i algoritm opredeleniya optimal'ny'x znachenij konfiguriruemy'x parametrov veb-sluzhby' korporativny'x informacionny'x sistem // Voprosy' kiberbezopasnosti. 2025. № 1(65). S. 50–62. DOI 10.21681/2311-3456-2025-1-50-62
9. Gorbachev A. A., Maksimov R. V. Problema maskirovaniya i primeneniya texnologij mashinnogo obucheniya v kiberprostranstve // Voprosy' kiberbezopasnosti. 2023. № 5(57). S. 37–49. DOI 10.21681/4311-3456-2023-5-37-49.
10. Maximov R. V., Sokolovsky S. P., Telenga A. P. Methodology for sustaniating the characteristics of false network traffic to simulate information systems // Selected Papers of the XI International Scientific and Technical Conference on Secure Information Technologies (BIT–2021). 2021. p. 115–124.
11. Maximov R. V., Sokolovsky S. P., Telenga A. P. Honeypots network traffic parameters modelling // Selected Papers of the XI International Scientific and Technical Conference on Secure Information Technologies (BIT–2021). 2021. P. 229–239.
12. Landsborough J., Rowe N., Nguyen T., Fugate S. WiP: Deception-in-Depth Using Multiple Layers of Deception // 2024. p. 1–14. arXiv: 2412.16430v1.
13. Beltan-Lopez P., Perez M. G., Nespoli P. Cyber Deception: Taxonomy, State of the Art, Frameworks, Trends, and Open Challenges // IEEE Communications Surveys & Tutorials. 2025. P. 1–40.
14. Zhu Z., Zhu G., Zhang Yu, Shi J., Huang X., Fang Y. EigenObfu: A Novel Network Topology Obfuscation Defense Method // IEEE Transactions on Network Science and Engineering. 2024. N 12(1). P. 451–462.
15. Wang Y., Liu S., Zhang C., Wang W., Jin J., Zhu C., Zhou C. Graph Pre-training for Reconnaissance Perception in Automated Penetration Testing // ICIC (3). P. 302–318.
16. Kouremetis M., Dotter M., Byrne A., Martin D., Michalak E., Russo G., Threet M., Zarrella G. OCCULT: Evaluating Large Language Models for Offensive Cyber Operation Capabilities // arXiv e-prints. 2025. arXiv: 2502.15797.
69-80
Kulikov, A. L.METHOD OF RESTORING THE FUNCTIONING OF ELECTRIC POWER SYSTEMS UNDER CYBER ATTACKS / A. L. Kulikov, L. A. Gurina // Cybersecurity issues. – 2026. – № 1(71). – С. 81-88. – DOI: 10.21681/2311-3456-2026-1-81-88.
Abstract
The research aims to develop method for restoring the functioning of an intelligent electric power system (EPS) in the event of failures. The research relies on the graphoanalytic methods, theory of semi–Markov processes, numerical methods.
Research result: the mutual influence and interrelations of the information system and the technological part of the intelligent EPS in the event of failures under cyber attacks are analyzed. The features of the process of restoring the intelligent EPS in the event of emergency situations as a result of cyber attacks are revealed. A model of the intelligent EPS and an algorithm for determining the EPS restoration indicator in the event of cyber attacks are proposed. A method for restoring the intelligent EPS has been developed that prevents the development of emergency situations by detecting, localizing cyber attacks and isolating the operation of the technological part of the EPS into "islands".
The scientific novelty lies in the fact that a method for restoring an intelligent power system has been proposed that takes into account the mutual influence of information and physical systems, and the peculiarities of the propagation of failures during cyber-attacks.

Keywords: intelligent EPS, emergency modes, cyber attack, recovery rate, Markov model, sliding window.
References
1. Voropai N. Electric Power System Transformations: A Review of Main Prospects and Challenges. Energies. 2020. 13. 5639. DOI: 10.3390/en13215639.
2. Ilyushin P. V. Sistemny'j podxod k razvitiyu i vnedreniyu raspredelennoj e'nergetiki i vozobnovlyaemy'x istochnikov e'nergii v Rossii // E'nergetik. 2022. № 4. C. 20–27.
3. Kulikov A. L., Zinin V. M. Trebovaniya k informacionnoj bezopasnosti v e'lektroe'nergetike i ix realizaciya v intellektual'ny'x ustrojstvax cifrovy'x podstancij // Intellektual'naya e'lektrotexnika. 2022. № 3(19). C. 49–78. DOI: 10.46960/2658-6754_2022_3_4.
4. Gurina L. A. Povy'shenie kiberustojchivosti SCADA i WAMS pri kiberatakax na informacionno-kommunikacionnuyu podsistemu E'E'S // Voprosy' kiberbezopasnosti. 2022. № 2(48). C. 18–26. DOI: 10.21681/2311-3456-2022-2-18-26.
5. M. Ali, X. Gao, A. Rahman, M. M. Hossain and W. Sun. Emerging Coordinated Cyber-Physical-Systems Attacks and Adaptive Restoration Strategies // 2023 IEEE PES Grid Edge Technologies Conference & Exposition (Grid Edge), San Diego, CA, USA. 2023. Pp. 1–5. DOI: 10.1109/GridEdge54130.2023.10102741.
6. Listopad, S. Hybrid Intelligent Multi-Agent System for Power Restoration // In: Golenkov, V., Krasnoproshin, V., Golovko, V., Azarov, E. (eds). Open Semantic Technologies for Intelligent System. OSTIS 2020. Communications in Computer and Information Science. Vol 1282. Springer, Cham. DOI: 10.1007/978-3-030-60447-9_16.
7. Lyubarskij Yu. Ya., Aleksandrov N. M. Primenenie iskusstvennogo intellekta v upravlenii e'lektricheskimi setyami // E'nergiya edinoj seti. 2020, № 1(50), s. 16–22.
8. Golovinskij I. A. Vozmozhnosti avtomaticheskogo vosstanovleniya e'lektrosnabzheniya v raspredelitel'noj seti pri gruppe odnovremenny'x povrezhdenij // Vestnik Severo-Kavkazskogo federal'nogo universiteta. 2021. № 4(85). C. 7–16. DOI: 10.37493/2307-907X.2021.4.2.
9. Vidy' upravlyayushhix vozdejstvij PA. – [E'lektronny'j resurs]. – Rezhim dostupa: https://www.so-ups.ru/functioning/tech-base/rza/rzameans/rza-actions/ (data poseshheniya 17.06.25).
10. Fishov A. G., Gulomzoda A. X. Sposob udalennoj sinxronizacii i vosstanovleniya normal'nogo rezhima avarijno razdelennoj e'lektricheskoj seti s generatorami // Operativnoe upravlenie v e'lektroe'nergetike: podgotovka personala i podderzhanie ego kvalifikacii. 2021. № 5, s. 61–64.
11. Voropaj N. I. Napravleniya i problemy' transformacii e'lektroe'nergeticheskix sistem // E'lektrichestvo. 2020. № 7. S. 12-21. DOI: 10.24160/0013-5380-2020-7-12-21
12. Gurina L. A. Ocenka riskov kiberbezopasnosti e'nergeticheskogo soobshhestva mikrosetej // Voprosy' kiberbezopasnosti. 2024. № 1(59). C. 101–107. DOI: 10.21681/2311-3456-2024-1-101-107.
13. G. Cao et al. Operational Risk Evaluation of Active Distribution Networks Considering Cyber Contingencies // in IEEE Transactions on Industrial Informatics. 2020. Vol. 16, no. 6. Pp. 3849–3861. DOI: 10.1109/TII.2019.2939346.
14. A. Sturaro, S. Silvestri, M. Conti and S. K. Das. A Realistic Model for Failure Propagation in Interdependent Cyber-Physical Systems // in IEEE Transactions on Network Science and Engineering. 2020. Vol. 7, no. 2. Pp. 817–831. DOI: 10.1109/TNSE.2018.2872034.
15. Md Zahidul Islam, Yuzhang Lin, Vinod M. Vokkarane, Venkatesh Venkataramanan. Cyber-physical cascading failure and resilience of power grid: A comprehensive review // Energy Research. 2023. Vol. 11. DOI: 10.3389/fenrg.2023.1095303.
16. Y. Zhang, O. Yagan. Robustness of Interdependent Cyber-Physical Systems Against Cascading Failures // IEEE Transactions on Automatic Control. 2020. Vol. 65, no. 2. Pp. 711–726. DOI: 10.1109/TAC.2019.2918120.
17. Gurina L. A., Tomin N. V. Intellektual'ny'e metody' obespecheniya kiberbezopasnosti mul'tiagentny'x sistem upravleniya mikrosetyami // Voprosy' kiberbezopasnosti. 2024. № 6(64). C. 53–64. DOI: 10.21681/2311-3456-2024-6-53-64.
18. C. Roberts et al. Learning Behavior of Distribution System Discrete Control Devices for Cyber-Physical Security // in IEEE Transactions on Smart Grid. 2020. Vol. 11, no. 1. Pp. 749–761. DOI: 10.1109/TSG.2019.2936016.
19. V. Venkataramanan, A. Hahn and A. Srivastava. CP-SAM: Cyber-Physical Security Assessment Metric for Monitoring Microgrid Resiliency // in IEEE Transactions on Smart Grid. 2020. Vol. 11, no. 2. Pp. 1055–1065. DOI: 10.1109/TSG.2019.2930241.
20. Y. Zhang et al. Cyber Physical Security Analytics for Transactive Energy Systems // in IEEE Transactions on Smart Grid. 2020. Vol. 11, no. 2. Pp. 931–941. DOI: 10.1109/TSG.2019.2928168.
21. Raxmatullin R. R., Ferenecz A. V., Isakov R. G., Musaev T. A., Fedorov O. V. Razrabotka sovremenny'x podxodov k vy'boru optimal'nogo mestoraspolozheniya kommutacionny'x apparatov v radial'noj raspredelitel'noj seti 6(10) kV // Intellektual'naya e'lektrotexnika. 2024.
№ 1(25). C. 101–122.
22. Sistema avtomaticheskogo vosstanovleniya e'lektrosnabzheniya setej 6–10 kV na baze PTK «Cifrovoj RE'S». – [E'lektronny'j resurs]. – Rezhim dostupa: https://enip2.ru/Publication/public_art_SAVS_2020.pdf (data poseshheniya 21.05.25).
23. Fishov A. G., Gulomzoda A. X., Kasobov L. S. Decentralizovannaya rekonfiguraciya e'lektricheskoj seti s Microgrid s ispol'zovaniem reklouzerov // Vestnik Irkutskogo gosudarstvennogo texnicheskogo universiteta. 2020. № 24(2). C. 382–395. DOI: 10.21285/1814-3520-2020-2-382-395
24. Vosstanovlenie e'lektroe'nergeticheskix sistem posle krupny'x avarij. Principy' i metod. sredstva / [Voropaj N.I. i dr.]. – M.: Informe'nergo, 1991. – 51 s.
25. Kulikov A. L., Kolesnikov A. A. Metody' sovershenstvovaniya differencial'noj relejnoj zashhity' // Bibliotechka e'lektrotexnika. 2021. № 2(266). S. 1–96.
81-88
Kotenko, I. V.THE CRITICAL INFORMATION INFRASTRUCTURE OF RAILWAY TRANSPORT ADAPTIVE CYBER THREAT ASSESSMENT USING A DIGITAL TWIN IN / I. V. Kotenko, I. B. Sayenko, E. S. Mityakov // Cybersecurity issues. – 2026. – № 1(71). – С. 89-98. – DOI: 10.21681/2311-3456-2026-1-81-88.
Abstract
The purpose of the study: development and experimental validation of a methodology for adaptive cyber threat assessment in the telemetry infrastructure of railway transport using a digital twin for safe machine learning model retraining.
Research methods: cyberattack scenario modeling, statistical analysis of time series, machine learning techniques, synthetic data generation within a digital twin environment.
Results obtained: an architecture for an adaptive cyber threat detection system is proposed, implementing a closed-loop cycle of monitoring, evaluation, and safe model retraining within an isolated digital twin environment. A synthetic dataset was generated to simulate six types of stealthy and evolving cyberattacks targeting the telemetry of traction power systems
and SCADA systems in railway infrastructure. Experimental results demonstrate that a static machine learning model suffers severe performance degradation under concept drift, exhibiting extremely low recall. In contrast, the proposed adaptation mechanism—based on the analysis of false negatives and the targeted addition of representative examples to the training set—significantly improves recall while maintaining high precision. Even the inclusion of a small number of new samples (less
than 3 % of the original dataset) yields a substantial increase in F1-score, confirming the approach’s effectiveness under strict regulatory constraints that limit direct intervention in real critical infrastructure operations.
Scientific novelty: The proposed approach is distinguished by the integration of a digital twin as a secure environment for generating synthetic attack scenarios and retraining the detection model based on false-negative analysis. This enables effective compensation for concept drift without disrupting the operation of the actual railway infrastructure.
Contributions: Kotenko I. V. – development of the problem statement and general approach to adaptive assessment of cyber threats in the telemetry infrastructure of railway transport; Kotenko I. V., Saenko I. B. and Mityakov E. S. – analysis of modern research on cyber threat assessment and development of the architecture of the adaptive cyber threat assessment system; Mityakov E. S. – experimental study of the proposed approach; Kotenko I. V., Saenko I. B. and Mityakov E. S. –
analysis of the research results.

Keywords: railway infrastructure cybersecurity, attack and anomaly detection, adaptive systems, concept drift, machine learning.
References
1. Adadurov S. E., Glukhov A. P., Kotenko I. V., Saenko I. B. An Intelligent System for Information Security Management // Automation, Communications, Informatics. 2021. No. 12. P. 14–18. DOI:10.34649/AT.2021.12.12.004.
2. Adadurov S. E., Glukhov A. P., Kotenko I. V., Saenko I. B. Intelligent Information Security Services // Automation, Communications, Informatics. 2022. No. 3. P. 27–30. DOI:10.34649/AT.2022.3.3.004.
3. Adadurov S. E., Kotenko I. V., Saenko I. B. An Approach to Ensuring Resilience and Operational Efficiency of a Distributed Big Data Storage System // Automation, Communications, Informatics. 2022. No. 12. P. 19–21. DOI:10.34649/AT.2022.12.12.004.
4. Adadurov S. E., Kotenko I. V., Saenko I. B., Glukhov A. P. Using Supercomputers for Information Security Data Analysis // Automation, Communications, Informatics. 2024. No. 11. P. 14–17. DOI:10.62994/AT.2024.11.11.002.
5. Ibadah N., Benavente-Peces C., Pahl M. Securing the Future of Railway Systems: A Comprehensive Cybersecurity Strategy for Critical On-Board and Track-Side Infrastructure // Sensors (Basel, Switzerland). 2024. Vol. 24. DOI:10.3390/s24248218.
6. Nunes J., Cruz T., Simões P. Railway Infrastructure Cybersecurity: An Overview // European Conference on Cyber Warfare and Security. 2024. DOI:10.34190/eccws.23.1.2296.
7. Kour R., Patwardhan A., Thaduri A., Karim R. A review on cybersecurity in railways // Proceedings of the Institution of Mechanical Engineers, Part F: Journal of Rail and Rapid Transit. 2022. Vol. 237. P. 3–20. DOI:10.1177/09544097221089389.
8. Abudu R., Bridgelall R., Quayson B., Tolliver D., Dadson K. Railroad Cybersecurity: A Systematic Bibliometric Review // Designs. 2025. DOI:10.3390/designs9010023.
9. Soderi S., Masti D., Lun Y. Railway Cyber-Security in the Era of Interconnected Systems: A Survey // IEEE Transactions on Intelligent Transportation Systems. 2022. Vol. 24. P. 6764–6779. DOI:10.1109/TITS.2023.3254442.
10. Unwin D., Sanzogni L. Railway cyber safety: An intelligent threat perspective // Proceedings of the Institution of Mechanical Engineers, Part F: Journal of Rail and Rapid Transit. 2021. Vol. 236. P. 26–34. DOI:10.1177/09544097211000518.
11. Soderi S., Masti D., Hämäläinen M., Iinatti J. Cybersecurity Considerations for Communication Based Train Control // IEEE Access. 2023. Vol. 11. P. 92312–92321. DOI:10.1109/ACCESS.2023.3309005.
12. Kour R., Karim R., Thaduri A. Cybersecurity for railways – A maturity model // Proceedings of the Institution of Mechanical Engineers,
Part F: Journal of Rail and Rapid Transit. 2019. Vol. 234. P. 1129–1148. DOI:10.1177/0954409719881849.
13. Gruba Ł. Cybersecurity risk assessment in railway applications // WUT Journal of Transportation Engineering. 2023. DOI:10.5604/01.3001.0054.9040.
14. Parkinson H., Basher D., Bamford G. Railway cyber security and TS50701 // Civil-Comp Conferences. 2023. DOI:10.4203/ccc.1.17.1. 
15. Wang Z., Liu X. Cyber security of railway cyber-physical system (CPS) – A risk management methodology // Communications in Transportation Research. 2022. DOI:10.1016/j.commtr.2022.100078.
16. Okstad E., Bains R., Mewcha A., Flå L., Bernsmed K. Cybersecurity in Railway – Alternatives of Independent Assessors' Involvement in Cybersecurity Assurance // Proceeding of the 33rd European Safety and Reliability Conference. 2023. DOI:10.3850/978-981-18-8071-1_p210-cd.
17. Qi J., Wang J. Bridging Artificial Intelligence and Railway Cybersecurity: A Comprehensive Anomaly Detection Review // Transportation Research Record. 2024. Vol. 2679. P. 232–255. DOI:10.1177/03611981241302335.
18. Kushwaha D., Kumar A., Harsha S. Advancements and applications of digital twin in the railway industry: a literature review // International Journal of Rail Transportation. 2024. DOI:10.1080/23248378.2024.2434834.
19. Salierno G., Leonardi L., Cabri G. A Big Data Architecture for Digital Twin Creation of Railway Signals Based on Synthetic Data // IEEE Open Journal of Intelligent Transportation Systems. 2024. Vol. 5. P. 1–18. DOI:10.1109/OJITS.2024.3412820.
20. De Donato L., Dirnfeld R., Somma A., De Benedictis A., Flammini F., Marrone S., Azari M., Vittorini V. Towards AI-assisted digital twins for smart railways: preliminary guideline and reference architecture // Journal of Reliable Intelligent Environments. 2023. Vol. 9.
P. 303–317. DOI:10.1007/s40860-023-00208-6.
21. Bernal E., Wu Q., Spiryagin M., Cole C. Augmented digital twin for railway systems // Vehicle System Dynamics. 2023. Vol. 62. P. 67–83. DOI: 10.1080/00423114.2023.2194543.
22. Sarp S., Kuzlu M., Jovanovic V., Polat Z., Guler O. Digitalization of railway transportation through AI-powered services: digital twin trains // European Transport Research Review. 2024. DOI:10.1186/s12544-024-00679-5.
23. Krmac E., Djordjević B. Digital Twins for Railway Sector: Current State and Future Directions // IEEE Access. 2024. Vol. 12. P. 108597–108615. DOI:10.1109/ACCESS.2024.3439471.
24. Ghaboura S., Ferdousi R., Laamarti F., Yang C., Saddik A. Digital Twin for Railway: A Comprehensive Survey // IEEE Access. 2023. Vol. 11. P. 120237–120257. DOI:10.1109/ACCESS.2023.3327042.
25. Dirnfeld R., De Donato L., Flammini F., Azari M., Vittorini V. Railway Digital Twins and Artificial Intelligence: Challenges and Design Guidelines // 2022. P. 102–113. DOI:10.1007/978-3-031-16245-9_8.
26. Zhu L., Li Y., Yu F., Ning B., Tang T., Wang X. Cross-Layer Defense Methods for Jamming-Resistant CBTC Systems // IEEE Transactions on Intelligent Transportation Systems. 2021. Vol. 22. P. 7266–7278. DOI:10.1109/tits.2020.3005931.
27. Soderi S., Masti D., Lun Y. Railway Cyber-Security in the Era of Interconnected Systems: A Survey // IEEE Transactions on Intelligent Transportation Systems. 2022. Vol. 24. P. 6764–6779. DOI:10.1109/TITS.2023.3254442.
28. Mohammed A., Anthi E., Rana O., Saxena N., Burnap P. Detection and mitigation of field flooding attacks on oil and gas critical infrastructure communication // Computers & Security. 2022. Vol. 124. Article 103007. DOI:10.1016/j.cose.2022.103007.
29. Arafat Z., Yudina O. V., Abdulazeez Z. A. Generative adversarial networks in cyber security: Literature review // Russian Technological Journal. 2025. Vol. 13(5). P. 7–24. DOI:10.32362/2500-316X-2025-13-5-7-24.
89-98
Korneev, N. V.PATTERN FOR ENSURING THE SECURITY OF THE WEB SERVICE OF AN ONLINE TELECOMMUNICATIONS SYSTEM WHEN THE THREAT OF SPAM IN ITS OWN ECOSYSTEM / N. V. Korneev // Cybersecurity issues. – 2026. – № 1(71). – С. 99-110. – DOI: 10.21681/2311-3456-2026-1-99-110.
Abstract
The purpose of the article is to develop a pattern for ensuring the security of web services of online telecommunication systems that make calls and send SMS messages in case of a spam threat in their own ecosystem integrated with critical information infrastructure.
Research method: the study was carried out by full-scale modeling of the web service of an online telecommunications system in the Kubernetes cluster.
Result: the security features of web services of telecommunication online systems that make calls and send SMS messages under the threat of spam are formulated. A microservice architecture of the security pattern of the web service of the online telecommunications system has been constructed. The security pattern of the web service of the telecommunications online system under the threat of spam attacks in order to disable the service and distribute malicious content has been developed. The pattern includes the service security-service, the Voice-service service for making calls and
the service for sending SMS messages sms-service. All services are developed in Ruby and implemented in Docker containers using Docker Desktop, PostgreSQL, Redis, WSL2 tools. A new protection mechanism is proposed to ensure the security of the online telecommunications system from spam attacks, taking into account the synthesis of both scenarios and the formation of a universal mechanism for protecting against such threats, through comprehensive user verification, including the stages of checking the IP address for permanent blocking; temporary blocking, with an incorrect key; authorization based on the provided key; checking the number of requests per unit of time; checking access rights to make a call separately and to send SMS separately. An algorithm for configuring a security service in a Kubernetes cluster has been developed, which allows you to implement a new protection mechanism. For the security service, 6 classes of models have been created for each entity and 3 classes of controllers to implement business logic and protection mechanism. The security pattern functionality was tested in two ways: automated unit testing and manual acceptance testing. All tests were successful.
Practical value: the significance of the proposed solution includes a pattern for ensuring the security of the web service of an online telecommunications system, which can be deployed as part of the company's own ecosystems.

Keywords: template, spam attack, instant messaging service, call service, security service.
References
1. Anies Faziehan Zakaria, Soon Chong Johnson Lim, Muhammad Aamir, A pricing optimization modelling for assisted decision making in telecommunication product-service bundling, International Journal of Information Management Data Insights, Volume 4, Issue 1, 2024, 100212. DOI: 10.1016/j.jjimei.2024.100212.
2. Chao Zong, Weidong Chen, Nan Yuan, Haiyang Feng, Mobile telecommunication companies’ investment and pricing strategies for content service, Journal of Management Science and Engineering, Volume 9, Issue 3, 2024, 440–459. DOI: 10.1016/j.jmse.2024.06.001.
3. Hyunjin Shin, Sanghyun Park, Leehee Kim, Jinseob Kim, Taeeun Kim, Youngkeun Song, Sungjoo Lee, The future service scenarios of 6G telecommunications technology, Telecommunications Policy, Volume 48, Issue 2, 2024, 102678. DOI: 10.1016/j.telpol.2023.102678.
4. Hsien-Cheng Lin, Understanding the determinants of falls for deception in telecommunications fraud, International Journal of Information Management, Volume 84, 2025, 102936. DOI: 10.1016/j.ijinfomgt.2025.102936.
5. Jakub Trýb, Jakub Hospodka, GNSS Interference and Security: Impacts on Critical Infrastructure and Mitigation Strategies, Procedia Computer Science, Volume 253, 2025, 2635–2644. DOI: 10.1016/j.procs.2025.01.323.
6. Miloslavskaya N. G., Tolstoj A. I. Upravlenie aktivami informacionno-telekommunikacionny'x setej kak obyazatel'ny'j e'tap upravleniya ix uyazvimostyami // Voprosy' kiberbezopasnosti. 2025. № 1(65). S. 73–85. DOI: 10.21681/2311-3456-2025-1-73-85.
7. J. Carrillo-Mondéjar, J. L. Martinez, G. Suarez-Tangil, On how VoIP attacks foster the malicious call ecosystem, Computers & Security, Volume 119, 2022, 102758. DOI: 10.1016/j.cose.2022.102758.
8. Or Haim Anidjar, Revital Marbel, Ran Dubin, Amit Dvir, Chen Hajaj, Extending limited datasets with GAN-like self-supervision for SMS spam detection, Computers & Security, Volume 145, 2024, 103998. DOI: 10.1016/j.cose.2024.103998.
9. Lu Zhang, Mingming Xu, Zhan Bu, Gaofeng He, Haiting Zhu, Changjian Fang, Collusive spam detection from Chinese community question answering sites: A collective classification framework, Information Sciences, Volume 667, 2024, 120379. DOI: 10.1016/j.ins.2024.120379.
10. Shushanta Pudasaini, Aman Shakya, Sanjeeb Prasad Pandey, Prakriti Paudel, Sunil Ghimire, Prabhat Ale, SMS Spam Detection using
Relevance Vector Machine, Procedia Computer Science, Volume 230, 2023, 337–346. DOI: 10.1016/j.procs.2023.12.089.
11. Xinxin Hu, Hongchang Chen, Shuxin Liu, Haocong Jiang, Guanghan Chu, Ran Li, BTG: A Bridge to Graph machine learning in telecommunications fraud detection, Future Generation Computer Systems, Volume 137, 2022, 274–287. DOI: 10.1016/j.future.2022.07.020.
12. Hongsheng Xu, Akeel Qadir, Saima Sadiq, Malicious SMS detection using ensemble learning and SMOTE to improve mobile cybersecurity, Computers & Security, Volume 154, 2025, 104443. DOI: 10.1016/j.cose.2025.104443.
13. Anisha Asirvatham, C. Meenakshi, The Impact of SMS Phishing using Machine Learning Classifiers with Innovative Techniques, Procedia Computer Science, Volume 260, 2025, 608–615. DOI: 10.1016/j.procs.2025.03.239.
14. Korneev N. V., Trubacheva-Gudovich A. E. Pattern dlya obespecheniya bezopasnosti veb-prilozhenij pri ugroze nekontroliruemogo rosta chisla zarezervirovanny'x resursov // Voprosy' kiberbezopasnosti. 2025. № 4(68). S. 35–45. DOI: 10.21681/2311-3456-2025-4-35-45.
15. Korneev N. V., Kotrini E. S. Pattern dlya obespecheniya bezopasnosti prilozheniya pri ugroze modifikacii modeli mashinnogo obucheniya // Voprosy' kiberbezopasnosti. 2025. № 1(65). S. 117–127. DOI: 10.21681/2311-3456-2025-1-117-127.
16. Korneev N. V., Dikij A. B. Pattern dlya obespecheniya bezopasnosti informacionnoj infrastruktury' pri migracii obrazov virtual'ny'x mashin // Voprosy' kiberbezopasnosti. 2025. № 2(66). S. 29–40. DOI: 10.21681/2311-3456-2025-2-29-40.
17. Korneev N. V., Lazorin D. S. Pattern dlya obespecheniya bezopasnosti veb-prilozheniya pri ugroze XSS atak v oblachnoj infrastrukture // Voprosy' kiberbezopasnosti. 2024. № 6(64). S. 76–84. DOI: 10.21681/2311-3456-2024-6-76-84.
18. Danyang Zheng, Chao Wang, Honghui Xu, Wenyi Tang, Yihan Zhong, Xiaojun Cao, A Provably Efficient In-Network Computing Services Deployment Approach for Security Burst, Computer Networks, 2025, 111737. DOI: 10.1016/j.comnet.2025.111737.
19. Qiqing Deng, Zhen Xu, Qihui Zhou, Yan Zhang, Cordon: Enhancing security through kernel-level control in containerized computing environments, Computers & Security, Volume 158, 2025, 104644. DOI: 10.1016/j.cose.2025.104644.
20. Min Hyeok Kang, Seongcheol Kim, Resilience in telecommunications networks: A Korean case study, Telecommunications Policy, Volume 49, Issue 6, 2025, 102987. DOI: 10.1016/j.telpol.2025.102987.
21. Alok Mishra, Yehia Ibrahim Alzoubi, Memoona Javeria Anwar, Asif Qumer Gill, Attributes impacting cybersecurity policy development: An Evidence from seven nations, Computers & Security, Volume 120, 2022, 102820. DOI: 10.1016/j.cose.2022.102820.
22. Engin Yakar, H. Hakan Kilinc, Exploring the Impact of Big Data Analytics on Emergency Calls within Telecommunication Systems, Procedia Computer Science, Volume 238, 2024, 240-247. DOI: 10.1016/j.procs.2024.06.021.
99-110
Konev, A. A.METAGRAPH MODELS OF THE VIRTUAL AND HARDWARE LEVELS OF THE INFORMATION SYSTEM / A. A. Konev, N. A. Korovkin, D. A. Korovkin // Cybersecurity issues. – 2026. – № 1(71). – С. 111-118. – DOI: 10.21681/2311-3456-2026-1-111-118.
Abstract
The purpose of the research is to adapt the method of metagraph modeling to the task of assessing the security of information systems.
The research methods are based on the provisions of the theory of graphs and hypergraphs, the concepts of graph structures, the hierarchical metagraph model with metavertices and meta-edges.
Results: this article examines the adaptation of the method of metagraph modeling for assessing the security of information systems. A mathematical description of the metagraph model of an abstract information system has been developed, including the formalization of its structure with a division into hardware and virtual levels. It is shown that metagraphs allow describing complex interactions of system components at three levels: a local network within a global network, a computer within a global network local network and OS processes/PC components. Metagraphs for the hardware and software levels are modeled, taking into account the specifics of their functioning, which is confirmed by the graphical representation and detailing of attributes and relationships. It is established that the division of metagraph elements into abstraction levels increases the accuracy of vulnerability analysis by taking into account the semantics and dynamics of connections.
The results obtained expand the possibilities of applying graph theory in the field of information security, providing systematization of threats and the development of protective measures for modern computer systems. The proposed approach demonstrates the potential for predicting cyber threats and forming a bank of protection measures adapted to the multi-level structure of information systems.
Scientific novelty: the possibility of dividing the elements of the metagraph model of the information system into hardware and virtual levels has been demonstrated. A mathematical description of the information system of three levels in relation to the hardware and virtual components of the computer system has been developed.

Keywords: assessment of the security of information systems, graph theory, information security, mathematical description, metavertex, metaedge.
References
1. Chapis, M. A. Informacionnaya bezopasnost' gosudarstva kak pravovoj poryadok obespecheniya nacional'noj bezopasnosti v informacionnoj sfere / M. A. Chapis // Naukosfera. – 2024. – № 6–1. – S. 551–557. – DOI: 10.5281/zenodo.11638587.
2. Nikolaeva, M. O. Informacionnaya bezopasnost': sovremennaya kartina problemy' informacionnoj bezopasnosti i zashhity' informacii / M. O. Nikolaeva // Monitoring. Obrazovanie. Bezopasnost'. – 2023. – T. 1, № 1. – S. 51–57. – EDN IOIQDI.
3. Problemny'e voprosy' informacionnoj bezopasnosti kiberfizicheskix sistem / D. S. Levshun, D. A. Gajfulina, A. A. Chechulin, I. V. Kotenko // Informatika i avtomatizaciya. – 2020. – T. 19, № 5. – S. 1050–1088. – DOI 10.15622/ia.2020.19.5.6.
4. Gnevanov, M. V. Aspekty' bezopasnosti kiberfizicheskix sistem / M. V. Gnevanov // Texnologii i texnika: puti innovacionnogo razvitiya: sbornik nauchny'x statej Mezhdunarodnoj nauchno-texnicheskoj konferencii, Voronezh, 09 iyunya 2023 goda. – Voronezh: Voronezhskij gosudarstvenny'j texnicheskij universitet, 2023. – S. 193–196. – EDN KMCMIE.
5. Korovkin, N. A. Modelirovanie ugroz bezopasnosti sistemy' peresy'lki i polucheniya e'lektronny'x soobshhenij / N. A. Korovkin, D. A. Korovkin
// E'lektronny'e sredstva i sistemy' upravleniya. Materialy' dokladov Mezhdunarodnoj nauchno-prakticheskoj konferencii. – 2023. – № 1–2. – S. 133–135. – EDN DSYESX.
6. Terekhov, V. Semantic Search System with Metagraph Knowledge Base and Natural Language Processing / V. Terekhov, A. Kanev // Conference of Open Innovations Association, FRUCT. – 2021. – No. 28. – P. 652–658. – EDN VQYKFJ.
7. Integracionny'j podxod k dokumentirovaniyu na osnove metagrafov / A. V. Seliverstova, M. V. Vinogradova, S. S. Loseva, Yu. E. Gapanyuk // Computational Nanotechnology. – 2024. – T. 11, № S5. – S. 116–123. – DOI: 10.33693/2313-223X-2024-11-5-116–123.
8. Mnushka, O. V. Model' bezopasnosti informacionnoj sistemy' na baze texnologij IoT / O. V. Mnushka, V. N. Savchenko // Vestnik Nacional'nogo texnicheskogo universiteta Xar'kovskij politexnicheskij institut. Seriya: Informatika i modelirovanie. – 2019. – № 28(1353). – S. 108–116. – DOI: 10.20998/2411–0558.2019.28.09.
9. Predstavlenie metagrafovoj modeli v vide kategorii / S. S. Vinnikov, A. N. Nardid, G. I. Revunkov, Yu. E. Gapanyuk // Dinamika slozhny'x sistem - XXI vek. – 2023. – T. 17, № 3. – S. 72–77. – DOI: 10.18127/j19997493-202303–10.
10. Chernenkiy, V. M. The Software Implementation of a Metagraph Processing System Based on the Big Data Approach / V. M. Chernenkiy, I. V. Dunin, Yu. E. Gapanyuk // Proceedings of the Institute for System Programming of the RAS. – 2022. – Vol. 34, No. 1. – P. 87–100. – DOI: 10.15514/ISPRAS-2022-34(1)-7.
11. Rasshirenie metagrafovogo podxoda dlya opisaniya sinergeticheskix intellektual'ny'x sistem / Yu. T. Kaganov, G. I. Revunkov, A. M. Andreev, Yu. E. Gapanyuk // Gibridny'e i sinergeticheskie intellektual'ny'e sistemy': Materialy' V Vserossijskoj Pospelovskoj konferencii s mezhdunarodny'm uchastiem, Zelenogradsk, Kaliningradskaya oblast', 18–20 maya 2020 goda / Pod redakciej A. V. Kolesnikova. – Zelenogradsk, Kaliningradskaya oblast': Baltijskij federal'ny'j universitet imeni Immanuila Kanta, 2020. – S. 412–419. – EDN KBOOBK.
12. Gapanyuk, Yu. E. Metagrafovoe opisanie sinergeticheskix xolarxij / Yu. E. Gapanyuk, Yu. T. Kaganov, M. G. Kuz'mina // Gibridny'e i sinergeticheskie intellektual'ny'e sistemy' : sbornik statej po materialam nauchnoj VII Vserossijskoj Pospelovskoj konferencii, Kaliningrad, 03–07 iyunya 2024 goda. – Kaliningrad, Sankt-Peterburg: Russkaya xristianskaya gumanitarnaya akademiya im. F. M. Dostoevskogo, 2024. – S. 351–360. – EDN ALCYTQ.
13. Zhbanova, N. Yu. Programmnaya realizaciya algoritma Dejkstry' pri grafostrukturnom modelirovanii organizacionny'x sistem s ispol'zovaniem metagrafov / N. Yu. Zhbanova, A. I. Miroshnikov // Modelirovanie, optimizaciya i informacionny'e texnologii. – 2020. – T. 8, № 2(29). – DOI 10.26102/=.29.2.008.
14. Shtogrina E. S., Krivenko A. S. Metod vizualizacii metagrafa // Nauchno-texnicheskij vestnik informacionny'x texnologij, mexaniki i optiki. - 2014. – № 3.–- S. 124–130.
15. Astanin S. V., Zhukovskaya N. K. Ispol'zovanie konstrukcii vlozhennogo metagrafa dlya modelirovaniya slozhny'x sistem // Inzhenerny'j vestnik Dona. – 2022. – № 6.
16. Lubenets, Y. V. Software Implementation of Finding Minimal Spanning Trees in Structure Modeling of Socio-economic Systems Using Metagraphs / Y. V. Lubenets, A. Miroshnikov // Proceedings - 2021 3rd International Conference on Control Systems, Mathematical Modeling, Automation and Energy Efficiency, SUMMA 2021: 3, Lipetsk, 10–12 noyabrya 2021 goda. Vol. 3rd International Conference. – Lipetsk, 2021. – P. 445–447. – DOI: 10.1109/SUMMA53307.2021.9632067.
17. Gam, A. V. Modeli sluchajny'x grafov i ix primenenie dlya modelirovaniya programmny'x sistem / A. V. Gam // Perspektivy' nauki. – 2023. – № 9(168). – S. 10–15. – EDN PVSDXM.
18. Kuz'min, V. N. Sravnitel'ny'j analiz modelej sluchajny'x grafov / V. N. Kuz'min, F. L. Shuvaev, M. V. Rozganov // Vestnik Tomskogo gosudarstvennogo
universiteta. Upravlenie, vy'chislitel'naya texnika i informatika. – 2022. – № 58. – S. 23–34. – DOI 10.17223/19988605/58/3.
111-118
Ladikov, A. V.ENHANCING A PERSONAL DATA ANONYMIZATION METHOD BY ATTRIBUTE VALUE PERMUTATION / A. V. Ladikov, M. Ya. Kleptsov // Cybersecurity issues. – 2026. – № 1(71). – С. 119-127. – DOI: 10.21681/2311-3456-2026-1-119-127.
Abstract
Purpose of the study: analyze an adversary’s capabilities to maliciously exploit data anonymized by the shuffling (permutation) method, and to develop countermeasures to mitigate the potential misuse of such anonymized data.
Methods of research: comparison and juxtaposition, scenario analysis, systems analysis, probability theory, algorithm theory, and experimental demonstration.
Result(s): the article examines a method of personal data anonymization based on shuffling the values of attributes containing subject identifiers. It is demonstrated that the shuffling method preserves the analytical value of data while simultaneously reducing the risk of direct subject re-identification. However, vulnerabilities of the shuffling method were identified, associated with the possibility of adversarial exploitation of anonymized datasets. To improve security, a modification of the method is proposed, based on expanding the set of identifiers with artificially generated, syntactically relevant values. This approach reduces the likelihood of a successful attack and diminishes the market value of leaked datasets on data black markets. In addition, the study considers the use of a trusted intermediary (an anonymization center) that accumulates large identifier dictionaries and ensures the isolation of personal data processing, thereby enabling the application of the proposed modification of the shuffling method without requiring artificial generation of personal identifiers on the part of the data operator.
Scientific novelty: the novelty of the study lies in identifying security threats to personal data subjects that arise when data are anonymized using the shuffling method, as well as in proposing a way to mitigate these threats by enhancing the shuffling method through the expansion of the set of shuffled values.

Keywords: personal data, data anonymization, shuffling method, information security, data protection, data leakage.
References
1. Takahashi C. N., Ward D. Pp., Cazzaniga C., et al. Evaluating the risk of data loss due to particle radiation damage in a DNA data storage system // Nature Communications. – 2024. – Vol. 15. – Art. 8067. – DOI: 10.1038/s41467-024-51768-x.
2. Holt T. J., Smirnova O., Chua Y. T. Exploring and Estimating the Revenues and Profits of Participants in Stolen Data Markets / T. J. Holt, O. Smirnova, Y. T. Chua // Deviant Behavior. – 2016. – Vol. 37, № 4. – S. 353–367. – DOI: 10.1080/01639625.2015.1026766.
3. Cross C., Holt T. J. Beyond fraud and identity theft: assessing the impact of data breaches on individual victims // Journal of Crime and Justice. – 2025. – Pp. 1–24. – DOI: 10.1080/0735648X.2025.2535007.
4. Maher C. A., Hayes B. E. Nonfinancial Consequences of Identity Theft Revisited: Examining the Association of out-Of-Pocket Losses with Physical or Emotional Distress and Behavioral Health // Criminal Justice and Behavior. – 2024. – Vol. 51, № 3. – Pp. 459–481. – DOI: 10.1177/00938548231223166.
5. Data security strategies to avoid data breaches in modern information systems / Chukwudi Tabitha Aghaunor, Patience Eshua, Tawo Obah, Oluwatoyin Aromokeye // World Journal of Advanced Research and Reviews. – 2023 (Vol. 20, No. 03). – Pp. 2122–2144. – DOI: 10.30574/wjarr.2023.20.3.2515.
6. Morozov V. E., Miloslavskaya N. G. Kompleksny'e resheniya dlya minimizacii vnutrennix ugroz informacionnoj bezopasnosti // Voprosy' kiberbezopasnosti. – 2024. – № 5(63). – S. 67–78. – DOI: 10.21681/2311-3456-2024-5-67-78.
7. Kang H., Lee S., Park J. Theory and Application of Zero Trust Security: A Brief Survey // Entropy. – 2023. – Vol. 25, № 12. – Art. 1595. – DOI: 10.3390/e25121595.
8. Sathiya Devi S., Indhumathi R. Enhancing privacy for automatically detected quasi-identifier using data anonymization // Web Intelligence. – 2023. – Vol. 21, № 1. – Pp. 71–91. – DOI: 10.3233/WEB-221823.
9. Demelius A., Kern R., Trügler A. Recent Advances of Differential Privacy in Centralized Deep Learning: A Systematic Survey // ACM Computing Surveys. – 2023. – Vol. 56, № 10. – Pp. 1–28. – DOI: 10.1145/3712000.
10. Deußer T., Sparrenberg L., Berger M., et al. A Survey on Current Trends and Recent Advances in Text Anonymization // arXiv preprint. –
2025. – arXiv:2508.21587. – URL: https://arxiv.org/abs/2508.21587.
11. Mishhenko E. Yu., Sokolov A. N. Algoritmy' realizacii metodov obezlichivaniya personal'ny'x danny'x v raspredelenny'x informacionny'x
sistemax // Doklady' Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioe'lektroniki. 2019. T. 22. № 1. S. 66–70.
12. Ladikov A. V. Obezlichivanie pol'zovatel'skix danny'x v sistemax biznes-analitiki // Sovremennaya nauka: aktual'ny'e problemy' teorii i praktiki. Seriya: Estestvenny'e i Texnicheskie Nauki. – 2024. – № 01. – S. 76–81. DOI 10.37882/2223-2966.2024.01.24.
13. Gadotti A., Bilogrevic I., Gürses S., Troncoso C., Danezis G. Anonymization: The imperfect science of using data while preserving privacy // Science Advances. – 2024. – Vol. 10, № 29. – Art. eadn7053. – DOI: 10.1126/sciadv.adn7053.
14. Rupp V., von Grafenstein M. Clarifying «personal data» and the role of anonymisation in data protection law: Including and excluding data from the scope of the GDPR (more clearly) through refining the concept of data protection // Computer Law & Security Review. – 2024. – Vol. 52. – Art. 105932. – DOI: 10.1016/j.clsr.2023.105932.
15. Poluyanova E. V. Personal'ny'e danny'e: aktual'ny'e voprosy' pravovogo regulirovaniya // Agrarnoe i zemel'noe pravo. – 2024. – № 7(235). – S. 104–106. – DOI: 10.47643/1815-1329_2024_7_104.
16. Canim M., Kantarcioglu M., Bertino E. Secure Management of Private Data on the Cloud Using a Policy-Driven Middleware // IEEE Transactions on Dependable and Secure Computing. – 2012. – Vol. 9, № 4. – Pp. 483–497. – DOI: 10.1109/TDSC.2011.46.
17. Ladikov A. V. Obezlichivanie pol'zovatel'skix danny'x s ispol'zovaniem doverennogo centra depersonalizacii // Sistemy' i sredstva informatiki. – 2025. – Tom 35, № 3. – S. 117–129. – DOI: 10.14357/08696527250308.
18. Shang Y., Xue M., Zhang L. Y., Zhang Y., Liu W. Tracking the Leaker: An Encodable Watermarking Method for Dataset Intellectual Property Protection // Proceedings of ACM Turing Award Celebration Conference – CHINA 2024 (TURC 2024). – 2024. – Pp. 114–119. – DOI 10.1145/3674399.3674446.
119-127
Stepanov, P. P.IMPLEMENTATION OF A CLIENT APPLICATION FOR IDENTIFYING THE «MAN-IN-THE-MIDDLE» ATTACKS AS A WINDOWS SYSTEM SERVICE / P. P. Stepanov, G. V. Nikonova // Cybersecurity issues. – 2026. – № 1(71). – С. 128-138. – DOI: 10.21681/2311-3456-2026-1-128-138.
Abstract
The purpose of this study is to develop a client-server application for identifying and prompt reacting to the attacks of the «man-in-the-middle» type. This application is intended for fine tuning the security policies for different network nodes.
The method for this study is the development of a network utility program by means of object-oriented programming in C#, with the implementation of the software functionality at the level of classes and methods. A method for developing the functionality is proposed at the most abstract level – contracts or interfaces – with a description of the methods signature, which the class should implement.
As a result of this study, a utility program has been developed, which acts as a Windows system service and analyzes the continuous data of a network node. This study describes the client application of this utility program. The utility program collects such parameters as DHCP server address; DNS server addresses; gateway address; IP address of the active computer; the name of the active computer; ARP table and the routing table. These network parameters are transmitted for further analysis and response to information security incidents.
The practical value of this study is the development of the client application of this utility program. The implementation of a Windows system service in C#, which transmits data that helps revealing the attacks, which in turn helps identifying and analyzing the status of all network nodes (for example, computers of the same organization) as to detect a «man-in-the middle» attack, such as: MAC spoofing; ARP Spoofing; Evil Twin; DHCP Spoofing; ICMP Redirect; DNS Spoofing; configuration
of hacked router. The result of running the application could be observed in the Windows logs through Event Viewer application.

Keywords: Windows service, C#, Utility, ARP Protocol, DHCP server, DNS server, ARP spoofing, traffic interception, MITM Defense, Evil Twin, ICMP redirect, DHCP spoofing, DNS spoofing, MAC spoofing.
References
1. Tanenbaum, Andrew S., Austin, Todd. (2023). Structured computer organization. 6th ed. Pearson Education, Inc., published as Prentice Hall. 776 p.
2. Olifer, V. G., Olifer, N. A. (2023). Computernye seti. Principy, Technologie, Protocoly. SPb. Piter. 1008 p. (in Russ.)
3. Snaider, J. (2020). Effective TCP/IP Programming. 44 Tips to Improve Your Network Programs. Pearson Education. 320 p.
4. Bidzhieva, S. H., Shebzuhova, K. V. (2022). Network data transfer protocols: advantages and disadvantages. Trends in the development of science and education, 1(86), 43–45. DOI: 10.18411/trnio-06-2022-14 (in Russ.)
5. Shah, M., Ahmed, S., Saeed, K., Junaid, M., Hamayun, Khan, Ata-ur Rehman. (2019). Penetration Testing Active Reconnaissance Phase – Optimized Port Scanning With Nmap Tool. 2nd International Conference on Computing, Mathematics and Engineering Technologies (iCoMET), IEEE, DOI: 10.1109/ICOMET.2019.8673520.
6. Muthalagu, R., Sanjay, S. (2021). Evil Twin Attack Mitigation Techniques in 802.11 Networks. International Journal of Advanced Computer Science and Applications, 6 (12), P. 38–41.
7. Mehrotra, T. (2021). A review on attack in wireless and computer networking. Asian Journal of Multidimensional Research, 10(10), 1457–1463.
8. Stepanov, P. P., Nikonova, G. V. (2024). Bezopasnaya peredacha soobshcheniy s razdeleniem dannykh cherez pochtovye server. Voprosy kiberbezopasnosti, 2(60), 120–129. DOI: 10.21681/2311-3456-2024-2-120-129. (in Russ.)
9. Man, K., Zhou, X., Qian, Z. (2021). DNS cache poisoning attack: Resurrections with side channels. CCS '21. Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, 3400–3414.
10. Mvah, F., Kengne, V., Tchendji, C. Tayou. (2024). Djamegni et al. GaTeBaSep: game theory-based security protocol against ARP spoofing attacks in software-defined networks. International Journal of Information Security, 1(23), 373–387.
11. Stepanov, P. P., Nikonova, G. V., Pavlychenko, T. S., Gil, A. S. (2020). Attack on the Address Resolution Protocol. 2020 International Conference Engineering and Telecommunication (En&T), IEEE, DOI: 10.1109/EnT50437.2020.9431297.
12. Zhang, Z., Liu, Z., Bai, J. (2022). Network Attack Detection Model Based on Linux Memory Forensics. 2022 14th International Conference on Measuring Technology and Mechatronics Automation, ICMTMA, IEEE, 2022, 931–935. DOI: 10.1109/ICMTMA54903.2022.00189.
13. Galal, A. A., Ghalwash, A. Z., Nasr, M. (2022). A new approach for detecting and mitigating address resolution protocol (ARP) poisoning. International Journal of Advanced Computer Science and Applications, 6(13), P. 377–382. DOI: 10.14569/IJACSA.2022.0130647.
14. Stepanov, P. P., Nikonova, G. V., Pavlychenko, T. S., Gil, A. S. (2021). The problem of security address resolution protocol // Journal of Physics: Conference Series, 1791, P. 012061. DOI: 10.1088/1742-6596/1791/1/012061.
15. Shah, Z., Cosgrove, S. (2019). Mitigating ARP Cache Poisoning Attack in Software-Defined Networking (SDN): A Survey. Electronics, 8(10), 1095. DOI: 10.3390/electronics8101095.
16. Stepanov, P. P., Nikonova, G. V., Pavlychenko, T. S., Solovev, V. V. (2022). Osobennosti raboty protokola razrescheniya addresov v computernech setyack. Programmnaya Ingeneria. 5(13), 211–218. DOI 10.17587/prin. 13. 211–218 (in Russ.)
17. Dolgachev, M. V., Kostynin, V. A. (2025). Kompleksnuy analiz povedeniya sistemy WINDOWS dlya obnaruzheniya kiberugroz. Voprosy kiberbezopasnosti, 2(66), 71–77. DOI: 10.21681/2311-3456-2025-2-71-77.
18. Hijazi, S., Obaidat, M. (2019). Address resolution protocol spoofing attacks and security approaches: A survey. Security and Privacy, 1(2), e49.
19. Shaw, S., Choudhury, P. (2015). A new local area network attack through IP and MAC address spoofing. 2015 international conference on advances in computer engineering and applications. IEEE, 347–350. DOI: 10.1109/ICACEA.2015.7164728.
20. Novokhrestov, A., Konev, A., Shelupanov, A. (2019). Model of Threats to Computer Network Software. Symmetry, 2019, 12(11), 1506.
21. Maximov, R. V., Sokolovsky, S. P., Telenga, A. P. Model of client-server information system functioning in the conditions of network reconnaissance. CEUR Workshop Proceedings : Selected Papers of the X Anniversary International Scientific and Technical Conference on Secure Information Technologies (BIT 2019). Moscow : CEUR Workshop Proceedings, 2603, 44–51.
22. Aldaoud, M. Al-Abri, D., Maashri, A. Al, Kausa F. (2021). DHCP attacking tools: an analysis. Journal of Computer Virology and Hacking Techniques, 2(17), 119–129.
23. Wan, K., Coffman, J. (2021). Game-theoretic modeling of DDoS attacks in cloud computing. Proceedings of the 14th IEEE/ACM International Conference on Utility and Cloud Computing. P. 1-10. https://doi.org/10.1145/3468737.3494093.
128-138
Babenko L. K.ESTIMATING THE EXECUTION TIME OF A KNOWN PLAINTEXT ATTACK ON THE DOMINGO-FERRER CRYPTOSYSTEM / L. K. Babenko, V. S. Starodubcev // Cybersecurity issues. – 2026. – № 1(71). – С. 139-147. – DOI: 10.21681/2311-3456-2026-1-139-147.
Abstract
Purpose of the work: to quantify the execution time of an attack with a known plaintext on a fully homomorphic Domingo‑Ferrer cryptographic system.
Research methods: analysis of algorithms for implementing the stages of an attack with a known plaintext on the Domingo-Ferrer cryptosystem, comparison of the computational complexity of these algorithms, measurement of the execution time of the attack in question, taking into account the computational complexity of the implemented stages.
Object of research: fully homomorphic Domingo-Ferrer cryptosystem based on the number factorization problem.
Research results: an analysis of the literature on the topic of fully homomorphic encryption has been carried out. The properties and operations of the Domingo-Ferrer cryptosystem based on the number factorization problem are described. A description of the attack with a known plaintext is presented, as well as the characteristics of its individual stages. A comparative analysis of the methods of implementing the attack stages has been carried out, and those that are less time-consuming have been identified. The computational complexity of two stages of an attack with a known plaintext on the Domingo-Ferrer cryptographic system is estimated, depending on the selected parameters of the cryptosystem. Computational complexity is expressed in the number of basic mathematical operations and is confirmed by the results of a number of experimental studies. The time characteristics of the practical implementation of both the individual stages of the attack and the entire attack are also given.
Practical significance: using the results of quantitative estimates of the computational complexity and execution time of a known-plaintext attack on the Domingo-Ferrer cryptosystem presented in this paper, combined with existing estimates of the probability of successful implementation of this attack, will allow a comprehensive assessment of its impact on the security of the cryptosystem. This, in turn, will become the basis for the development of appropriate measures to increase the strength of the Domingo-Ferrer cryptographic system against attacks with known plaintext.

Keywords: information security; homomorphic encryption; homomorphic encryption scheme; fully homomorphic encryption; Domingo-Ferrer cryptosystem; cryptanalysis.
References
1. Sadeeq M. M. et al. IoT and Cloud computing issues, challenges and opportunities: A review // Qubahan Academic Journal. – 2021. – Т. 1. – № 2. – С. 1–7. – DOI:10.48161/qaj.v1n2a36.
2. Sidharth S. Homomorphic Encryption: Enabling Secure Cloud Data Processing. – 2023.
3. Mohammed S. J., Taha D. B. From cloud computing security towards homomorphic encryption: A comprehensive review // TELKOMNIKA (Telecommunication Computing Electronics and Control). – 2021. – Т. 19. – № 4. – С. 1152–1161. – DOI:10.12928/TELKOMNIKA. v19i4.16875.
4. Kiesel R. et al. Potential of homomorphic encryption for cloud computing use cases in manufacturing // Journal of Cybersecurity and Privacy. – 2023. – Т. 3. – № 1. – С. 44–60. – DOI:10.3390/jcp3010004.
5. Domingo-Ferrer J., Blanco-Justicia A. Privacy-preserving technologies // The Ethics of Cybersecurity. – 2020. – С. 279–297. – DOI:10.1007/978-3-030-29053-5_14.
6. Mittal S., Ramkumar K. R. A retrospective analysis on fully homomorphic encryption scheme // International Journal of Electronic Security and Digital Forensics. – 2024. – Т. 16. – № 2. – С. 223–254. – DOI:10.1504/IJESDF.2024.137031.
7. Wibawa F. et al. BFV-based homomorphic encryption for privacy-preserving CNN models // Cryptography. – 2022. – Т. 6. – № 3. – С. 34. – DOI:10.3390/cryptography6030034.
8. Bai L. et al. Research on Noise Management Technology for Fully Homomorphic Encryption // IEEE Access. – 2024. – DOI:10.1109/ACCESS.2024.3461729.
9. Babenko, L. K., Starodubcev V. S. Ocenka vremeni vypolneniya operacij shifrovaniya, rasshifrovaniya, gomomorfnyh vychislenij s ispol'zovaniem kriptosistemy Domingo-Ferrera // Izvestiya SFedU. Engineering Sciences. – 2024. – No. 5(241). – pp. 6–15. – DOI 10.18522/2311-3103-2024-5-6-15.
10. Trepacheva A. V. O stojkosti gomomorfnoj kriptosistemy Domingo-Ferrera protiv ataki tol'ko po shifrtekstam //Prikladnaâ diskretnaâ matematika. Prilozhenie. – 2023. – No. 16. – pp. 98–102. DOI: 10.17223/2226308X/16/25.
11. Alhassan E. A. et al. On some algebraic properties of the Chinese remainder theorem with applications to real life //Journal of Applied Mathematics and Computation. – 2021. – Т. 5. – № 3.
12. Iwakoshi T. Security evaluation of y00 protocol based on time-translational symmetry under quantum collective known-plaintext attacks // IEEE Access. – 2021. – Т. 9. – С. 31608–31617. – DOI:10.1109/ACCESS.2021.3056494.
13. Gaudry P., Golovnev A. Breaking the encryption scheme of the Moscow internet voting system // Financial Cryptography and Data Security: 24th International Conference, FC 2020, Kota Kinabalu, Malaysia, February 10–14, 2020 Revised Selected Papers 24. – Springer International Publishing, 2020. – С. 32–49. – DOI:10.1007/978-3-030-51280-4_3.
14. Bouillaguet C., Zimmermann P. Parallel structured gaussian elimination for the number field sieve // Mathematical Cryptology. – 2021. – № 1. – С. 22–39.
15. Du Z., da Fonseca C. M. Sylvester–Kac matrices with quadratic spectra: A comprehensive note // The Ramanujan Journal. – 2024. – Т. 65. – № 3. – С. 1313–1322. – DOI:10.1007/s11139-024-00940-4.
16. Sechenov P. A. Comparison of the speed of numerical methods of Gaussian and LUP decomposition in the problem of finding the equilibrium chemical composition // Vestnik Voronezhskogo gosudarstvennogo tekhnicheskogo universiteta [The Bulletin of Voronezh State Technical University]. – 2023. – Vol. 19. – No. 2. – Pp. 79–85. – DOI 10.36622/VSTU.2023.19.2.012.
17. Zeng Z. The numerical greatest common divisor of univariate polynomials // Contemp. Math. Amer. Math. Soc. – 2021. – DOI:10.48550/arXiv.2103.04196.
18. Häner T. et al. Improved quantum circuits for elliptic curve discrete logarithms // Post-Quantum Cryptography: 11th International Conference, PQCrypto 2020, Paris, France, April 15–17, 2020, Proceedings 11. – Springer International Publishing, 2020. – С. 425–444. – DOI:10.1007/978-3-030-44223-1_23.
19. Babenko L. K., Starodubcev V. S. Estimation of the search time for key components in a known plaintext attack on the Domingo-Ferrer cryptosystem // Izvestiya YUFU. Tekhnicheskie nauki [Izvestiya SFedU. Engineering sciences]. – 2025. – No. 3(245). – Pp. 110–118. – DOI: 10.18522/2311-3103-2025-3-110-118.
20. Babenko L. K., Starodubcev V. S. Features of the implementation of the cryptanalysis system of homomorphic ciphers based on the problem of factorization of numbers // Izvestiya YUFU. Tekhnicheskie nauki [Izvestiya SFedU. Engineering sciences]. – 2024. – No. 3(239). – Pp. 55–64. – DOI 10.18522/2311-3103-2024-3-55-64.
21. Babenko L. K., Starodubcev V. S. Features of the implementation of the cryptanalysis systems of homomorphic ciphers based on the problem of factorization of numbers, using the example of the cryptosystem MORE // Voprosy kiberbezopasnosti [Cybersecurity issues]. – 2024. – No. 3(61). – pp. 141–145. – DOI: 10.21681/2311-3456-2024-3-141-145.
139-147
Izrailov, K. E.MODEL FOR ASSESSING THE NEUTRALIZING VULNERABILITIES IN A PROGRAM EFFECTIVENESS FROM THE POSITION OF THE APPROACHES USED TO THE ITS REPRESENTATIONS DE-EVOLUTION / K. E. Izrailov, M. V. Buinevich // Cybersecurity issues. – 2026. – № 1(71). – С. 148-159. – DOI: 10.21681/2311-3456-2026-1-148-159.
Abstract
The goal of the research: increasing the efficiency of vulnerability neutralization in a program by improvements approaches to the de-evolution of its representations.
Research methods: system analysis, analytical modeling, expert assessment, experiment.
Results: an efficiency model was synthesized to assess the process of vulnerability neutralization based on the indicators of the approach used to the de-evolution of its representations; the model consists of four levels: the goal, 4 main and 16 auxiliary criteria, as well as 12 parameters of alternatives; the numerical values needed to calculate the elements of the model were obtained expertly.
The scientific novelty lies in obtaining an evaluation tool that for the first time analytically links the indicators of the key element of the neutralization process – the de-evolution of representations, with the target criteria of the entire process – effectiveness, efficiency and resource efficiency.

Keywords: software, vulnerability neutralization, system analysis, efficiency model, de-evolution of representations, decompilation, experiment.
References
1. Abdullin T. I., Baev V. D., Bujnevich M. V., Burzunov D. D., Vasil'eva I. N., Galiullina Je. F. i dr. Cifrovye tehnologii i problemy informacionnoj bezopasnosti: monografija. SPb: SPGJeU 2021. 163 s.
2. Leonov N. V. Protivodejstvie ujazvimostjam programmnogo obespechenija. Chast' 1. Ontologicheskaja model' // Voprosy kiberbezopasnosti. 2024. № 2 (60). S. 87–92. DOI: 10.21681/2311-3456-2024-2-87-92.
3. Leonov N. V. Protivodejstvie ujazvimostjam programmnogo obespechenija. Chast' 2. Analiticheskaja model' i konceptual'nye reshenija // Voprosy kiberbezopasnosti. 2024. № 3 (61). S. 90–95. DOI: 10.21681/2311-3456-2024-3-90-95.
4. Zamorjonov M. V., Malickaja A. A. Issledovanie processa protivostojanija specialistov po komp'juternoj bezopasnosti i hakerov s uchetom vremeni na ustranenie ujazvimosti // Izvestija Tul'skogo gosudarstvennogo universiteta. Tehnicheskie nauki. 2023. № 4. S. 335–339.
DOI: 10.24412/2071-6168-2023-4-335-339.
5. Nedjak M. S. Povyshenie jeffektivnosti poiska ujazvimostej s ispol'zovaniem tehnologii fazzinga v virtual'nyh mashinah JavaScript // Prikladnaja diskretnaja matematika. Prilozhenie. 2021. № 14. S. 140–146. DOI: 10.17223/2226308X/14/31.
6. Chastikova V. A., Merkulov P. A. Issledovanie jeffektivnosti primenenija metodov mashinnogo obuchenija v zadache upravlenija
ujazvimostjami // Jelektronnyj setevoj politematicheskij zhurnal «Nauchnye trudy KubGTU». 2024. № 6. S. 160–169. DOI: 10.26297/2312-9409.2024.6.14.
7. Jarovoj R. V., Rjabov G. A., Izotov D. Ju. Sravnenie i analiz podhodov k obnaruzheniju vredonosnogo programmnogo obespechenija: ocenka jeffektivnosti i primenimosti // Tendencii razvitija nauki i obrazovanija. 2023. № 102-5. S. 48–51. DOI: 10.18411/trnio-10-2023-253.
8. Yu Z., Theisen C., Williams L., Menzies T. Improving Vulnerability Inspection Efficiency Using Active Learning // The proceedings of IEEE Transactions on Software Engineering. Vol. 47. No. 11. PP. 2401–2420. DOI: 10.1109/TSE.2019.2949275.
9. Prorokov V. A., Shhegoleva M. S., Astrahancev R. G. Novyj podhod k bezopasnosti po: iskusstvennyj intellekt v analize i ustranenii ujazvimostej // Sbornik nauchnyh trudov vuzov Rossii «Problemy jekonomiki, finansov i upravlenija proizvodstvom». 2024. № 54. S. 163–165.
10. Shimchik N. V., Ignat'ev V. N., Belevancev A. A. IRBIS: Staticheskij analizator pomechennyh dannyh dlja poiska ujazvimostej v programmah na C/C++ // Trudy Instituta sistemnogo programmirovanija RAN. 2022. T. 34. № 6. S. 51–66. DOI: 10.15514/ISPRAS-2022-34(6)-4.
11. Brovko E. V., Zajcev V. V. Metod poiska ujazvimostej v programmnom kode s ispol'zovaniem svjortochnoj nejronnoj seti // Metody i tehnicheskie sredstva obespechenija bezopasnosti informacii. 2024. № 33. S. 3–5.
12. Jones A., Omar M. Harnessing the Efficiency of Reformers to Detect Software Vulnerabilities // The proceedings of Congress in Computer Science, Computer Engineering, & Applied Computing (Las Vegas, NV, USA, 24–27 July 2023). 2023. PP. 2259–2264. DOI: 10.1109/CSCE60160.2023.00368
13. Kulagin I. I., Padarjan V. A., Koshkin V. A. O metodah izvlechenija algoritmov iz binarnogo koda // Trudy Instituta sistemnogo programmirovanija RAN. 2024. T. 36. № 3. S. 139–160. DOI: 10.15514/ISPRAS-2024-36(3)-10.
14. Gavshin D. A. Ispol'zovanie instrumentov Ghidra dlja analiza fajlov UEFI // Vestnik molodyh uchenyh Sankt-Peterburgskogo gosudarstvennogo universiteta tehnologii i dizajna. 2021. № 4. S. 39–43.
15. Xia B., Ge Y., Yang R., Yin J., Pang J., Tang C. BContext2Name: Naming Functions in Stripped Binaries with Multi-Label Learning and Neural Networks // The proceedings of IEEE 10th International Conference on Cyber Security and Cloud Computing / 2023 IEEE 9th International Conference on Edge Computing and Scalable Cloud (Xiangtan, Hunan, China, 01–03 July 2023). 2023. PP. 167–172.
DOI: 10.1109/CSCloud-EdgeCom58631.2023.00037.
16. Izrailov K. E. Koncepcija geneticheskoj dejevoljucii predstavlenij programmy. Chast' 1 // Voprosy kiberbezopasnosti. 2024. № 1 (59). S. 61–66. DOI: 10.21681/2311-3456-2024-1-61-66.
17. Izrailov K. E. Koncepcija geneticheskoj dejevoljucii predstavlenij programmy. Chast' 2 // Voprosy kiberbezopasnosti. 2024. № 2 (60). S. 81–86. DOI: 10.21681/2311-3456-2024-2-81-86.
18. He Y., Zhou H., Zhang S., Lu S., Yan Y., Li R., Gao Y. Research on Evaluation Model and Algorithm of Information System Health State Based on Realtime Operation Data and Analytic Hierarchy Process // The proceedings of International Conference on Networking, Communications and Information Technology (Manchester, United Kingdom, 26-27 December 2021). 2020. PP. 353–356. DOI: 10.1109/NetCIT54147.2021.00077.
19. Izrailov K., Kotenko I. The Concept of Genetic Reverse-Engineering to Restore the Program's Source Code from a Binary Code: Theory and Applying Practice // The proceedings of 17th International Conference on COMmunication Systems & NETworkS (Bengaluru, India, 06–10 January 2025). 2025. Pp. 1023–1026, DOI: 10.1109/COMSNETS63942.2025.10885658.
20. Izrailov K. E. Problemnye voprosy geneticheskoj dejevoljucii predstavlenij programmy dlja poiska v nih ujazvimostej i rekomendacii po ih razresheniju // Trudy uchebnyh zavedenij svjazi. 2025. T. 11. № 1. C. 84–98. DOI: 10.31854/1813-324X-2025-11-1-84-98.
148-159

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.