Search
Search Results
Found one item.
1 - 1 of 1 items
This study aims to develop a formalized information security threat model for hyperconverged infrastructure by constructing multi-component attack scenarios using the EPC (Event-driven Process Chain) methodology, taking into account the architectural features of HCI, the cascading nature of threat propagation, specific security objects, and the multitenant access model. The method of system analysis, the principle of the ARIS (Architecture of Integrated Information Systems) methodology, as well as the method of formalization of multicomponent attack scenarios are applied in the work. The technical basis was the FSTEC of Russia's methodology for assessing information security threats, the register of information security threats, and vulnerability information from the FSTEC Threat databank and the International Database (NVD). The study revealed the key architectural features of hyperconverged infrastructure as an object of protection close integration of components (computing, storage, and network), software definability of components, multitenancy, cascading nature of threat propagation. A classification of violators by privilege level is proposed. Two formalized scenarios of multicomponent attacks on specific threat targets in HCI have been developed. The scenarios are presented in the form of EPC diagrams, which allows not only to visualize the actions of the violator, visually present the tactics and techniques used by him, but also to numerically assess the probabilities of the scenarios. Based on the study of the structural and functional characteristics of HCI and taking into account the FSTEC threat assessment model, a generalized threat model of hyperconverged infrastructure with examples of filling for some affected objects has been developed. The scientific novelty of the study lies in the adaptation of the EPC threat modeling method for hyperconverged infrastructure, taking into account its architectural features and multitenancy, as well as in the development of formalized attack scenarios reflecting real vulnerability exploitation chains published in 2025-2026