Skip to main content Skip to main navigation menu Skip to site footer
##common.pageHeaderLogo.altText##
Izvestiya SFedU
Engineering sciences
  • Current
  • Previous issues
    • Archive
    • Issues 1995 – 2019
  • Editorial Board
  • About journal
    • Officially
    • The main tasks
    • Main sections
    • Specialties of the Higher Attestation Commission of the Russian Federation
    • Editor-in-Chief
ISSN 1999-9429 print
ISSN 2311-3103 online
  • Login
  1. Home /
  2. Search

Search

Advanced filters
Published After
Published Before

Search Results

##search.searchResults.foundPlural##
  • DEVELOPING A THREAT MODEL FOR THE INFORMATION ENVIRONMENT OF HYPERCONVERGED INFRASTRUCTURE BASED ON CONSTRUCTING MULTI-COMPONENT ATTACK SCENARIOS

    К.S. Dunyushkina , I. V. Mashkina
    18-31
    2026-07-07
    Abstract ▼

    This study aims to develop a formalized information security threat model for hyperconverged infrastructure by constructing multi-component attack scenarios using the EPC (Event-driven Process Chain) methodology, taking into account the architectural features of HCI, the cascading nature of threat propagation, specific security objects, and the multitenant access model. The method of system analysis, the principle of the ARIS (Architecture of Integrated Information Systems) methodology, as well as the method of formalization of multicomponent attack scenarios are applied in the work. The technical basis was the FSTEC of Russia's methodology for assessing information security threats, the register of information security threats, and vulnerability information from the FSTEC Threat databank and the International Database (NVD). The study revealed the key architectural features of hyperconverged infrastructure as an object of protection close integration of components (computing, storage, and network), software definability of components, multitenancy, cascading nature of threat propagation. A classification of violators by privilege level is proposed. Two formalized scenarios of multicomponent attacks on specific threat targets in HCI have been developed. The scenarios are presented in the form of EPC diagrams, which allows not only to visualize the actions of the violator, visually present the tactics and techniques used by him, but also to numerically assess the probabilities of the scenarios. Based on the study of the structural and functional characteristics of HCI and taking into account the FSTEC threat assessment model, a generalized threat model of hyperconverged infrastructure with examples of filling for some affected objects has been developed. The scientific novelty of the study lies in the adaptation of the EPC threat modeling method for hyperconverged infrastructure, taking into account its architectural features and multitenancy, as well as in the development of formalized attack scenarios reflecting real vulnerability exploitation chains published in 2025-2026

  • METHOD OF DEVELOPMENT OF THREAT SCENARIOS KNOWLEDGE BASE FOR INCIDENT RESPONSE PLATFORM (IRP)

    I.V. Mashkina, А.М. Urazaeva
    2024-11-10
    Abstract ▼

    The objective of the work is to study the possibility of increasing the efficiency of response to information
    security (IS) incidents. This can be achieved by developing a system capable of quickly localizing
    an incident, providing automation of response to an IS threat, taking predetermined actions depending on
    the details of the threat scenario being implemented. An architecture for constructing an IRP system is
    proposed, the main modules of which are a response scenario knowledge base, a threat scenario
    knowledge base, modules for determining the incident status and making decisions on the formation of
    command information. The problem of developing threat scenarios for creating a scenario knowledge
    base has been solved, on the basis of which adequate response scenarios can be developed that are unique
    for each chain of the cybercriminal's actions, events and involved objects. The paper formalizes the method
    for developing a knowledge base of threat scenarios based on constructing EPC diagrams of scenarios
    that display multi-component attacks taking into account tactics, techniques, vulnerabilities used, and
    information security threats (IST) specified in regulatory documents and databases. The paper formulates
    the rules for constructing EPC diagrams of threat scenarios and the methodology for EPC modeling for
    objects of influence in ICS. An example of an attack scenario on an industrial network from a global network
    is considered in the case when a cybercriminal, having attacked a remote user's computer, first gains
    unauthorized access to the corporate segment and gains a foothold in it for further penetration beyond the
    perimeter of the process network. The paper presents the developed EPC diagram of a threat scenario
    indicating the tactics, techniques, intermediate IST, and some vulnerabilities used. The assessment of the
    probability of scenario implementation is formalized

1 - 2 of 2 items

links

For authors
  • Submit article
  • Author Guidelines
  • Editorial Policy
  • Reviewing
  • Ethics of scientific publications
  • Open access policy
  • Supporting documents
Language
  • English
  • русский

journal

* not an advertisement

index

Индексация журнала
* not an advertisement
Information
  • For Readers
  • For Authors
  • For Librarians
Address: 347900, Taganrog, Chekhov St., 22, A-211 Phone: +7 (8634) 37-19-80 E-mail: iborodyanskiy@sfedu.ru
Publication is free
More information about the publishing system, Platform and Workflow by OJS/PKP.
logo Developed by RDCenter