Skip to main content Skip to main navigation menu Skip to site footer
##common.pageHeaderLogo.altText##
Izvestiya SFedU
Engineering sciences
  • Current
  • Previous issues
    • Archive
    • Issues 1995 – 2019
  • Editorial Board
  • About journal
    • Officially
    • The main tasks
    • Main sections
    • Specialties of the Higher Attestation Commission of the Russian Federation
    • Editor-in-Chief
ISSN 1999-9429 print
ISSN 2311-3103 online
  • Login
  1. Home /
  2. Search

Search

Advanced filters
Published After
Published Before

Search Results

##search.searchResults.foundPlural##
  • ALGORITHM FOR CONTEXTUAL VALIDATION OF INDICATORS OF BEHAVIOR (IOB) FOR DETECTING STEALTHY ATTACKS IN ICS

    Е. S. Abramov , N.Е. Belov , G. Е. Veselov
    6-20
    2026-09-10
    Abstract ▼

    This article addresses the pressing issue of ensuring the information security of critical information infrastructure (CII) amidst the qualitative evolution of cyber threats and the massive shift of threat actors toward stealthy "Living-off-the-Land" (LotL) attacks. Because such attacks are executed using legitimate administration tools, classical indicators of compromise (IOCs) lose their effectiveness, and traditional monitoring systems generate an excessive number of false alarms, thereby provoking "alert fatigue". To solve this problem, the paper proposes a methodology for the contextual validation of indicators of behavior (IOB) in Industrial Control Systems (ICS) networks. The primary scientific result is the developed "reverse enrichment" algorithm, which utilizes the deterministic nature of the technological process as a strict a priori filter. The algorithm verifies every control action by predicting the next state of the system using a state-space mathematical model and checking its membership in a formalized set of safe values, $\Omega_{safe}$. Additionally, the organizational context, $S_{org}$, including shift schedules and maintenance windows, is taken into account. Unlike probabilistic machine learning approaches, this method provides a strict binary criterion for command admissibility. The effectiveness of the proposed approach is confirmed by simulation results based on the verified dataset of the SWaT (Secure Water Treatment) academic testbed. The implementation of physical and organizational filters achieved a 97.7% False Positive Reduction Rate (FPRR) and successfully detected 1,021 out of 1,035 injected stealthy destructive impacts. The average computational latency of the algorithm was 1.4 ms, which fully satisfies the stringent requirements of real-time systems. The proposed method does not require the instrumentation of legacy field equipment and ensures the precise attribution of cyber incidents based on the physical laws of the production cycle.

  • RISK‑ORIENTED GEOPORTAL DECISION SUPPORT SYSTEM FOR TERRITORIALLY DISTRIBUTED ORGANIZATIONAL SYSTEMS

    А.М. Bershadsky , S.А. Yamashkin
    278-297
    2026-07-07
    Abstract ▼

    The article discusses the development of a risk-oriented geoportal decision support system for territorially distributed organizational systems (TDOS). The aim of the work is to develop an architecture and a formalized model that integrates spatial data, risk structures, key performance indicators (KPIs), and management action options within a unified analytical framework. The relevance is due to the fact that classical DSS and geoportals fragmentarily cover the tasks of TDOS management due to the lack of integration of spatial analysis with risk cascading models, which leads to inconsistency of decisions and increased territorial vulnerability. The methodological foundation includes the formalization of "object-risk-indicator-impact" relationships, the construction of directed influence graphs, and mechanisms for the propagation of risk effects across the territory and management levels. A multi-layered architecture of the geoportal platform is proposed, including subsystems for spatial data collection, risk analytics, KPI dashboards, and scenario modeling. The technical implementation is based on open geoportals of the Russian Geographical Society and a unified spatial data repository. As a pilot area, the regional management system for development and natural resource use of the Republic of Mordovia was studied, where a prototype of the risk-oriented module was implemented. The article demonstrates the ability to visualize the distribution of natural and man-made risks, assess integral territorial vulnerability indices, and select priority management scenarios. The results of implementation at EM-KAT LLC showed a reduction in energy consumption. The application of the system in the Main Directorate of the Ministry of Emergency Situations for the Republic of Mordovia made it possible to optimize territorial management and increase risk predictability. The proposed approach ensures holistic and reproducible management of territorially distributed systems, increasing their resilience to local and transitive impacts, decision-making transparency, and the efficiency of interdepartmental coordination

1 - 2 of 2 items

links

For authors
  • Submit article
  • Author Guidelines
  • Editorial Policy
  • Reviewing
  • Ethics of scientific publications
  • Open access policy
  • Supporting documents
Language
  • English
  • русский

journal

* not an advertisement

index

Индексация журнала
* not an advertisement
Information
  • For Readers
  • For Authors
  • For Librarians
Address: 347900, Taganrog, Chekhov St., 22, A-211 Phone: +7 (8634) 37-19-80 E-mail: iborodyanskiy@sfedu.ru
Publication is free
More information about the publishing system, Platform and Workflow by OJS/PKP.
logo Developed by RDCenter