DEVELOPING A THREAT MODEL FOR THE INFORMATION ENVIRONMENT OF HYPERCONVERGED INFRASTRUCTURE BASED ON CONSTRUCTING MULTI-COMPONENT ATTACK SCENARIOS
Abstract
This study aims to develop a formalized information security threat model for hyperconverged infrastructure by constructing multi-component attack scenarios using the EPC (Event-driven Process Chain) methodology, taking into account the architectural features of HCI, the cascading nature of threat propagation, specific security objects, and the multitenant access model. The method of system analysis, the principle of the ARIS (Architecture of Integrated Information Systems) methodology, as well as the method of formalization of multicomponent attack scenarios are applied in the work. The technical basis was the FSTEC of Russia's methodology for assessing information security threats, the register of information security threats, and vulnerability information from the FSTEC Threat databank and the International Database (NVD). The study revealed the key architectural features of hyperconverged infrastructure as an object of protection close integration of components (computing, storage, and network), software definability of components, multitenancy, cascading nature of threat propagation. A classification of violators by privilege level is proposed. Two formalized scenarios of multicomponent attacks on specific threat targets in HCI have been developed. The scenarios are presented in the form of EPC diagrams, which allows not only to visualize the actions of the violator, visually present the tactics and techniques used by him, but also to numerically assess the probabilities of the scenarios. Based on the study of the structural and functional characteristics of HCI and taking into account the FSTEC threat assessment model, a generalized threat model of hyperconverged infrastructure with examples of filling for some affected objects has been developed. The scientific novelty of the study lies in the adaptation of the EPC threat modeling method for hyperconverged infrastructure, taking into account its architectural features and multitenancy, as well as in the development of formalized attack scenarios reflecting real vulnerability exploitation chains published in 2025-2026
##article.references##
1. Azeem S.А., Sharma S.К. Study of Converged Infrastructure & Hyper Converge Infrastructre As Future of Data Centre, International Journal of Advanced Research in Computer Science. Computer Science, En-gineering, May-June 2017, Vol. 8, No. 5.
2. Egorov V.B. Programmnoe opredelenie seti v konvergentnoy i giperkonvergentnoy infrastrukturakh [Software definition of a network in converged and hyperconverged infrastructures], Sistemy i sredstva in-formatiki [Systems and Computer Science Tools], 2023, Vol. 33, No. 1, pp. 105-113.
3. Ob"em, prognoz i osnovnye tendentsii mirovogo rynka giperkonvergentnoy infrastruktury na 2025-2037 gg. [Volume, forecast and main trends of the global hyperconverged infrastructure market for 2025-2037]. researchnester.com. Available at: https://www.researchnester.com/ru/reports/hyper-converged-infrastructure-market/4792 (accessed 09 February 2026).
4. Metodicheskiy dokument ot 05.02.2021g.: federal'naya sluzhba po tekhnicheskomu i eksportnomu kontrolyu metodicheskiy dokument metodika otsenki ugroz bezopasnosti informatsii [Methodological document dated 02/05/2021: Federal Service for Technical and Export Control methodological document methodology for assessing information security threats]. Available at: https://fstec.ru/dokumenty/ vse-dokumenty/spetsialnye-normativnyedokumenty/metodicheskij-dokument-ot-5-fevralya-2021-g (accessed 09 March 2025).
5. Sagalaev Yu.R., Romashkova O.N. Analiz giperkonvergentnoy vychislitel'noy infrastruktury dlya khraneniya o obrabotki dannykh vysokonagruzhennykh informatsionnykh sistem [Analysis of hypercon-verged computing infrastructure for data storage and processing of highly loaded information systems], Sovremennaya nauka: Aktual'nye problemy teorii i praktiki. Seriya: Estestvennye i tekhnicheskie nauki [Modern science: Actual problems of theory and practice. Series: Natural and Technical Sciences], 2021, No. 6, pp. 118-124.
6. Shuvatova, E.A., Martynenko T.V. Analiz metodov opredeleniya effektivnoy arkhitektury programmnykh sistem [Analysis of methods for determining the effective architecture of software systems], Informatika, upravlyayushchie sistemy, matematicheskoe i komp'yuternoe modelirovanie (IUSMKM-2024): XV Mezhdunarodnaya nauchno-tekhnicheskaya konferentsiya v ramkakh X Mezhdunarodnogo Nauchnogo foruma Donetskoy Narodnoy Respubliki, Donetsk, 29-30 maya 2024 goda [Informatics, control systems, mathematical and Computer modeling (IUSMKM-2024): XV International Scientific and Technical Con-ference within the framework of the X International Scientific Forum of the Donetsk People's Republic, Donetsk, May 29-30, 2024]. Donetsk: Donetskiy natsional'nyy tekhnicheskiy universitet, 2024, pp. 125-130.
7. Nesterenko A.A., Vlatskaya I.V. Bezopasnost' konteynerizatsii: uyazvimosti Docker i Kubernetes. razbor CVE, Escape-atak i nepravil'nykh konfiguratsiy [Containerization security: vulnerabilities of Docker and Kubernetes. analysis of CVE, Escape attacks and incorrect configurations], Aktual'nye voprosy obespech-eniya kompleksnoy bezopasnosti: Mater. natsional'noy nauchno-prakticheskoy konferentsii s mezhdu-narodnym uchastiem, posvyashchennoy 35-letiyu MCHS Rossii i 95-letiyu Orenburgskogo GAU [Topical issues of ensuring integrated security: Materials of the national scientific and practical conference with in-ternational participation dedicated to the 35th anniversary of the Russian Ministry of Emergency Situations and the 95th anniversary of the Orenburg State Agrarian University]. Orenburg, 2025, pp. 360-363.
8. Gorelov P.D., Lysov D.A., Morozova K.V., Denisenya D.I. Razrabotka effektivnykh metodov zashchity konteynerov programmnogo obespecheniya kubernetes [Development of effective methods for protecting kubernetes software containers], Bezopasnost' informatsionnogo prostranstva – 2024: Sb. materialov XXIII vserossiyskoy nauchno-prakticheskoy konferentsii studentov, aspirantov i molodykh uchenykh [In-formation space security – 2024: Proceedings of the XXIII All-Russian scientific and practical conference of students, postgraduates and young scientists]. Kurgan, 2025, pp. 190-195.
9. Mashkina I.V., Garipov I.R. Razrabotka ERS-modeley ugroz narusheniya informatsionnoy bezopasnosti avtomatizirovannoy sistemy upravleniya tekhnologicheskimi protsessami [Development of EPC models of threats to information security violations of an automated process control system], Bezopasnost' infor-matsionnykh tekhnologiy [Information Technology Security], [S.I.], 2019, Vol. 26, No. 4, pp. 6-20. ISSN 2074-7136. DOI: http://dx.doi.org/10.26583/bit.2019.4.01.
10. Zaid Alkilani M.O., Mashkina I.V. Razrabotka stsenariev atak dlya otsenki ugroz narusheniya infor-matsionnoy bezopasnosti v promyshlennoy seti [Development of attack scenarios for assessing threats to information security in an industrial network], Problemy informatsionnoy bezopasnosti. Komp'yuternye sistemy [Problems of information security. Computer systems], 2024, No. 1 (58), pp. 96-109. DOI 10.48612/jisp/xvkx-k619-3f2z 25.04.2024. EDN: PDNEWN.
11. Sheer A.V. ARIS-modelirovanie biznes-protsessov [ARIS-modeling of business processes]. Moscow: Vil'yams, 2000, 175 p.
12. Mashkina I.V., Urazaev A.M. Metod razrabotki bazy znaniy stsenariev ugroz dlya sistemy reagirovaniya na intsidenty (IRP) [A method for developing a knowledge base of threat scenarios for an incident re-sponse system (IRP)], Izvestiya YuFU. Tekhnicheskie nauki [Izvestiya SFedU. Engineering Sciences], 2024, No. 5 (241), pp. 79-88. DOI 10.18522/2311-3103-2024-5-79-88.
13. NIST - National vulnerability database NVD CVE-2025-22224. Available at: https://nvd.nist.gov/ vuln/ detail/CVE-2025-22224 (accessed 09 March 2026).
14. Popov A.D. Konteynernaya virtualizatsiya kak osnova oblachnykh avtomatizirovannykh sistem [Container virtualization as the basis of cloud automated systems], Promyshlennye ASU i kontrollery [Industrial Au-tomated Control Systems and Controllers], 2024, No. 9, pp. 23-33.
15. Zima V.M., Kryukov R.O. Podkhod k bezopasnomu ispol'zovaniyu konteynernoy virtualizatsii v kritich-eski vazhnykh avtomatizirovannykh sistemakh [An approach to the safe use of container virtualization in critically important automated systems], Voprosy oboronnoy tekhniki. Seriya 16: Tekhnicheskie sredstva protivodeystviya terrorizmu [Issues of defense technology. Series 16: Technical means of countering ter-rorism], 2022, No. 11–12 (173–174), pp. 89-99.
16. Korolev A.S., Byrkov V.A., Rachishkin A.A. Tekhnologiya docker: konteynerizatsiya i razvertyvanie proekta [Docker technology: containerization and project deployment], Obrazovanie v XXI veke: problemy i perspektivy: Sb. statey XV Mezhdunarodnoy nauchno-prakticheskoy konferentsii [Education in the XXI century: problems and prospects. Collection of articles of the XV International Scientific and Practical Conference]. Penza, 2023, pp. 69-73.
17. NIST - National vulnerability database NVD CVE-2025-23990. Available at: https://nvd.nist.gov/ vuln/detail/CVE-2026-23990 (accessed 09 March 2025).
18. NIST - National vulnerability database NVD CVE-2024-05045. Available at: https://nvd.nist.gov/ vuln/detail/CVE-2024-21626 (accessed 09 March 2025).
19. NIST - National vulnerability database NVD CVE-2024-41110. Available at: https://nvd.nist.gov/ vuln/detail/CVE-2024-41110 (accessed 09 March 2025).
20. Mashkina I.V., Dunyushkina K.S. Analiz giperkonvergentnoy infrastruktury kak ob"ekta za-shchity [Analysis of hyperconverged infrastructure as an object of protection], Voprosy kiberbezopasnosti [Cy-bersecurity Issues], 2026, No. 1 (71), pp. 42-50. DOI: 10.21681/2311-3456-2026-1-42-50.








