The present paper addresses the problem of modeling the resilient operation of a cryptocurrency exchange (CEX) under delayed quantum attacks of the harvest-now-decrypt-later type. The proposed model diverges from extant approaches in its conceptualization of the quantum threat. Whereas extant approaches treat the quantum threat as an external shock, the proposed model conceptualizes the accumulation of cryptographically vulnerable data as an internal state variable of the system. The framework under consideration is formulated as a system of nonlinear differential equations linking the exchange’s liquidity, the intensity of post-quantum cryptography (PQC) adoption, and the volume of accumulated threat. The analytical conditions for asymptotic stability are derived. The resolution of the system enables the identification of a region of admissible defense strategies, which is interpreted in the paper as a “survival dome.” Numerical simulations demonstrate that both delayed and excessively aggressive migration strategies toward post-quantum cryptography may lead to the degradation of the exchange. The findings indicate that a balanced and adaptive transition strategy, aimed at mitigating quantum risks, can preserve liquidity while minimizing long-term losses. The findings establish a theoretical framework for the development of migration strategies for financial platforms undergoing a transition to post-quantum security standards.
LMS platforms are attractive targets for cybercriminals because of the large amount of sensitive data (particularly personal data of students, faculty, test scores, and financial information). The threat model consists of the main current cyber threats to LMS platforms, in particular: phishing attacks, credential stuffing, data privacy attacks, SQL injection and other web-based attacks, DDoS attacks, exploitation of vulnerabilities in third-party plugins and extensions, ransomware, unauthorized access and API attacks, exploitation of vulnerabilities in non-updated software, and insider threats. Creating a model is an important part of security system development, which will allow more accurate selection of defence mechanisms and procedures. In addition, the paper presents recommendations for ensuring LMS cybersecurity in the context of the realization of different types of threats.
A modular architecture of an Intelligent Information System (IIS) is proposed for optimizing the network of air quality monitoring stations in smart cities. The architecture employs IoT and Data Science technologies to implement environmental monitoring functions, illustrating key elements and their interconnections. The concept highlights the importance of strategic planning and technology selection to build a scalable and efficient system. The system enables the collection, analysis, and interpretation of air quality data, facilitating informed decisions to improve environmental conditions and enhance citizens' quality of life. Furthermore, the architecture integrates analytical modules aimed at data analysis and forecasting. Scalability and flexibility ensure the system adapts to new requirements and technological trends. These solutions provide a foundation for long-term strategic planning to improve air quality.
When designing a virtual desktop infrastructure (VDI) for a university or inter-university cloud, developers must overcome many complex technical challenges. One of these tasks is estimating the required number of virtualization cluster nodes. Such nodes host virtual machines for users. These virtual machines can be used by students and teachers to complete academic assignments or research work. Another task that arises in the VDI design process is the problem of algorithmizing the placement of virtual machines in a computer network. In this case, optimal placement of virtual machines will reduce the number of computer nodes without affecting functionality. And this, ultimately, helps to reduce the cost of such a solution, which is important for educational institutions. The article proposes a model for estimating the required number of virtualization cluster nodes. The proposed model is based on a combined approach, which involves jointly solving the problem of optimal packaging and finding the configuration of server platforms of a private university cloud using a genetic algorithm. The model introduced in this research is universal. It can be used in the design of university cloud systems for different purposes-for example, educational systems or inter-university scientific laboratory management systems.
For an electronic textbook on information and communication technologies (ICT), methodological foundations for the design of electronic courses in the field of ICT based on an ontological model for the implementation of information technologies for automated processing of ontologies are proposed. It is shown that the ontological model is designed to implement information technologies for automated computerized processing of ontologies of subject areas (VSS) using the example of ICT, which allows updating this content as the VSS develops on the basis of relevant content in the field of information and communication technologies corresponding to the current state of this subject area, using electronic courses (EC) and/or electronic textbooks (ETS) simplify the procedures associated with the implementation. On the basis of computer ontologies, a functional and information model of processes is implemented that form a combination of information technologies for automated processing of ontologies of subject areas characteristic of the field of information and communication technologies. Modeling technologies were also analyzed, in particular, technologies such as IDEF, DFD, UML were considered, which can be used in the design of complex systems such as EC and/or EO in the field of information and communication technologies for high school students. The results obtained in the course of the study are primarily aimed at improving the effectiveness of the preparation of electronic courses and/or electronic textbooks in the field of ICT for secondary school students. However, the results presented in the article can be used both to create EC and/or EO, as well as for other subject areas characterized by a high level of formalization of knowledge description and the presence of computer ontologies of these subject-disciplinary areas.
Ішкі шабуылдар компаниялар мен ұйымдар үшін, соның ішінде маңызды компьютерлік жүйелерді (МКЖ) пайдаланатындар үшін үнемі өсіп келе жатқан қауіп екені дәлелденді. Себебі, МКЖ-ге заңды қол жетімділігі бар алаяқтар және/немесе инсайдерлер, соның ішінде олардың бизнес-процестерінде қолданылатын бұлттық қызметтер (БҚ) және киберқауіпсіздік саясаты туралы ақпараты бар қызметкерлер анықтаудан аулақ бола алады (яғни, қашып құтылады). Қазіргі уақыттағы IDS/IPS, DLP, SIEM, ACS және тағы басқалары сияқты ішкі киберқауіпсіздікті бұзушыларды анықтауға арналған техникалық құралдардың кең арсеналына қарамастан, компаниялар мен ұйымдар әлі де күрделі ішкі шабуылдарды, соның ішінде инсайдерлік шабуылдарды анықтауға, ұстауға және азайтуға дайын емес, өйткені олардың киберқауіпсіздік (КҚ) әдістері негізінен сыртқы қауіптерге бейімделген. Осы жұмыста ішкі құқық бұзушыларды анықтау үшін МКЖ-дің қауіпсіздік қызметіне пайдалы болуы мүмкін Байес желісінің (БЖ) моделі ұсынылып отыр. Бұл модель ұқсас шешімдерден ерекшелігі БҚ-ді пайдаланатын компаниялардағы басшылық лауазымдардағы тұлғалардың алаяқтық қаупін ескереді, сонымен қатар МКЖ-мен жұмыс істеу кезінде қызметкер қалдырған цифрлық іздерді қамтиды. Ұсынылған БЖ моделінің бағдарламалық шешімі жасалды, ол синтетикалық деректер жиынтығында сыналып өзінің жұмыс қабілеттілігін көрсетті, бұл оны компаниялардың және/немесе ұйымдардың КҚ құрылымына енгізуге жарамды деп санауға мүмкіндік береді.
Настоящее исследование демонстрирует ключевую роль экологической составляющей в развитии умных городов (далее Smart City). Smart City стремятся к устойчивому развитию, снижению уровня загрязнения воздуха и повышению качества жизни горожан, а внедрение технологий Интернета вещей (IoT) и Data Science позволят уже сегодня создавать эффективные системы мониторинга и управления экологическими параметрами Smart City. Эти технологии обеспечивают своевременное обнаружение и реагирование на экологические проблемы, что способствует оперативному принятию мер по их устранению и минимизации негативного воздействия на окружающую среду (далее ОкСр) в Smart City. Показано, что объединенные станции, совмещающие функции метеостанций и пунктов контроля загрязнения воздуха (далее ПКЗВ), предлагают комплексный подход к мониторингу состояния ОкСр, обеспечивая получение более полных и точных данных. Внедрение IoT-технологий в мониторинговые станции, как стационарные, так и мобильные, а также ПКЗВ, позволит передавать данные в реальном времени в централизованную систему управления Smart City, что поспособствует более эффективному управлению и принятию решений по защите ОкСр. Научная новизна данного исследования заключается в развитии аналитической составляющей проблематики решения задачи оптимизации сети метеостанций и ПКЗВ для Smart City на основе IoT и Data Science. Практическая ценность исследования заключается в изложении аргументации в пользу релевантных подходов и методов, которые могут быть использованы для разработки и оптимизации интегрированных систем мониторинга, способствующих улучшению экологической обстановки и повышению качества жизни населения Smart City.
A dynamic model of countering phishing attacks is considered. Cryptocurrency exchanges (CCE) and/or their clients are considered as an example of a phishing victim. The model, unlike similar ones, is based on the assumption that the dynamics of the states of the player-victim of phishing attacks and the player-intruder (fisher) is set by means of a system of differential equations. The peculiarity of this model is that it represents a bilinear differential game of quality, for which methods for solving linear differential games are not applicable and, in addition, the absence of functional restrictions on the strategies of players (even immeasurable functions are allowed) does not allow the use of traditional approach. And their solution makes it possible to form payoff matrices, which are part of the training set for artificial neural networks (ANNs). Such a collaboration of models will make it possible to accurately build an anti-phishing strategy, minimizing the costs of both a potential victim of phishing attacks and the defense side when building a secure system of communication with CCE clients. The neuro-game approach makes it possible to predict the process of countering phishing in the context of costs for both parties using different strategies.
Қазіргі заманғы ақпараттық қауіпсіздік жүйелерін (АҚЖ) жобалау және олардың ақпараттық қауіпсіздік (АҚ) саясатын құру үшін сыртқы және ішкі қауіптерді бағалау және түсіну үшін бастапқы деректердің дәлдігін қамтамасыз ету қажеттілігі көрсетілген. Байес желілері (БЖ) әртүрлі оқиғалар арасындағы ықтималдық тәуелділіктерді модельдеу қабілетіне байланысты ақпараттық қауіпсіздік объектілерінің (АҚО) компьютерлік жүйелеріне (КЖ) қауіптер мен ену кезеңдерін болжау мәселесін шешуге көмектесе алады. Бұл әсіресе көптеген факторлар қауіптердің туындау ықтималдығына әсер ететін ақпараттық қауіпсіздік тапсырмасы контексінде пайдалы. Мақала ұйымдар мен компаниялардағы қызметкерлердің инсайдерлік мінез-құлқын анықтау және алдын алу мәселесіне арналған. Ақпараттық қауіпсіздік және ішкі қауіптерді тану саласындағы пәндік білімдерді тиімді біріктіруге болатын шешімдерді қабылдауды қолдау жүйесін (ШҚҚЖ) құру ұсынылады. Ең алдымен қызметкерлердің инсайдерлік мінез-құлқына байланысты қауіптер, сондай-ақ Python кітапханалары - Pandas, NumPy және т.б. арқылы жүзеге асырылатын аналитикалық және операциялық басқару құралдары қарастырылады. Персоналдың инсайдерлік сипаттамаларын анықтау және талдау үшін ШҚҚЖ-нің есептеуіш ядросы қолданылады.
The article considers the prerequisites for the formation of a secure information and educational environment of a modern university. Publications of domestic and leading foreign studies were analyzed. An overview and analysis of previous research in the field of cybersecurity of the information space of educational institutions was carried out. The analysis of publications published on this topic was carried out. The analysis confirmed the relevance of the problem of further development of models for VHS in the tasks of continuous mutual investment of the system of higher education institutions. Analysis of publications based on the results of research on the use of Petri nets to describe the model of cyber threats of informatization objects was carried out. Although these works make a significant theoretical contribution to this task, in our opinion, the programmatic implementation of the models proposed by the authors, in particular, The an in the ICIS and ICS on ICS, is somewhat difficult. This, in turn, requires additional research.
Optimizing the placement of a network of air quality monitoring stations (MSCS) in a smart city is a complex multi–criteria task. When solving it, it is necessary to take into account many contradictory goals, such as minimizing cost, maximizing coverage of the territory and ensuring high measurement accuracy. Genetic algorithms (GA) with a common objective function are an effective tool for solving such problems. However, determining the optimal weights for the various criteria in this function is a significant problem. Our vision of the development of a methodology for solving the problem under consideration based on game theory and a genetic algorithm (GA) is presented. The general paradigm of our reasoning lies in the fact that when talking about the "Price" parameter of the established MSCS, the variability of strategies for investing resources in one or another variant of the MSCS is not taken into account. And this aspect is important, because in the end we can say that the optimal MSCS network will be more efficient in terms of spending money on its creation and maintenance.
При обработке и передаче больших массивов информации в информационно-измерительных системах часто используются различные методы сжатия данных. На сегодняшний день хорошо разработанными можно считать методы квазиобратимого сжатия. Такие методы широко применяются в радиотелеметрических системах, например, космических летательных аппаратов. Основным недостатком квазиобратимых методов является их неэффективность для обработки быстроменяющихся (широкополосных) сигналов. При обработке широкополосных сигналов квазиобратимое сжатие не позволяют получить приемлемый коэффициент сжатия. Это приводит к необходимости для обработки широкополосных (быстроменяющихся) сигналов разрабатывать более эффективные методы обработки, позволяющие существенно сократить избыточность передаваемых по каналам связи данных. В статье рассматриваются методы обработки данных на основе информационного пространства инверсий. Сжатие данных на основе информационного пространства инверсий позволяет производить обработку и передачу широкополосных сигналов и достигать при этом достаточных коэффициентов сжатия. Особую актуальность это приобретает при обработке нестационарных широкополосных случайных процессов в реальном темпе времени в условиях априорной неопределенности о виде функции распределения измеряемых процессов. В статье дается понятие элементарных инверсий и информационного пространства инверсий. В статье приводятся результаты исследований методов сжатия данных на основе информационного пространства инверсий.
The potential breach of access to confidential content hosted in a university's Private Academic Cloud (PAC) underscores the need for developing new protection methods. This paper introduces a Threat Analyzer Software (TAS) and a predictive algorithm rooted in both an operational model and discrete threat recognition procedures (DTRPs). These tools aid in identifying the functional layers that attackers could exploit to embed malware in guest operating systems (OS) and the PAC hypervisor. The solutions proposed herein play a crucial role in ensuring countermeasures against malware introduction into the PAC. Various hypervisor components are viewed as potential threat sources to the PAC's information security (IS). Such threats may manifest through the distribution of malware or the initiation of processes that compromise the PAC's security. The demonstrated counter-threat method, which is founded on the operational model and discrete threat recognition procedures, facilitates the use of mechanisms within the HIPV to quickly identify cyber attacks on the PAC, especially those employing "rootkit" technologies. This prompt identification empowers defenders to take swift and appropriate actions to safeguard the PAC.
Мақалада темір жолдағы апаттық жағдайлары (ТЖ АЖ) туындаған кезде жедел штабтың басшысы мұндай жағдайдың компоненттері арасындағы себеп-салдарлық байланыстар туралы толық және жеткілікті ақпараттың болмауының күрделі жағдайларында бағынысты басқару пункттері мен жою бөлімшелерін келісуге, үйлестіруге және басқаруға бағытталған жеке, алқалық, ақпараттық, ұйымдастырушылық, жедел шешімдердің белгілі бір санын қабылдауы қажет екені анықталатындығы, олар мұндай шешімдер қабылдау және/немесе олардың негізділігіне әсер ету мүмкіндігі арттыруы мүмкіндігі айтылады. Қауіпті жүктермен (ҚЖ) ТЖ АЖ-ны оқшаулау және олардың салдарын жою бойынша негізделген басқару шешімдерін қабылдау шешім қабылдауды қолдау жүйелері (ШҚҚЖ) көмегімен жүзеге асырылуы тиіс, оларды құру үшін осындай жағдайлардың дамуын болжаудың ұсынылған математикалық модельдерін және жедел штаб басшылары іс-қимылдарының құрылымдық-логикалық сызбаларын қолдану қажет.
Заманауи ақылды қалалар барлық индустриялық дамыған елдердің экономикасы мен адами капиталын дамытудың негізі екені анықталды. Қала өмірін ақпараттандыру саласында, бүгінгі таңда қалалар арасындағы бәсекелестік айтарлықтай артып, күшейіп жатқаны анықталды, ал ірі инвесторлар экономикалық тиімді даму жобаларына уақтылы инвестициялау мүмкіндігін алу үшін ең тартымды және қарқынды дамып келе жатқан қалаларды дамытудың ағымдағы жағдайын мұқият зерделеуде. Ақпараттық технологиялардың (АТ) дамуымен барлық ірі қалалар муниципалды инфрақұрылымды басқару жүйелерін жеңілдету үшін, сондай-ақ қала өмірінің басқа салаларында қолдану үшін АТ әлеуетін пайдалану мүмкіндіктерін қарастыра бастағаны анықталды. Демек, Smart City үшін АТ-ға инвестициялау саласы инвестициялық жобаларды жүзеге асыру үшін ең тартымды салалардың бірі болып табылады. Smart City үшін инновациялық АТ-жобаларды инвестициялау тәртібі көбінесе белгісіздік пен тәуекелдің жоғары дәрежесімен сипатталатыны анықталды. Қалалық инфрақұрылымды дамытуға арналған ірі инвестициялық жобалардың менеджерлері өз уақытының көп бөлігін қала тұрғындарының өмірін жақсарту үшін сол немесе басқа инвестиция туралы шешім қабылдауға және осы немесе басқа бағытқа жұмсауға мәжбүр екендігі көрсетілген.
A new approach for the information security (IS) improvement of the educational institution's network has been proposed. The proposed approach is structured and systematic. It allows one to assess the security of the network of an educational institution (for example, a university) as a whole, as well as its subsystems and components that provide IS of an educational institution. Statistical, expert, heuristic and other indicators have been used to assess the degree of security. The proposed model allows one to describe the procedure for securing the IS network of the university. A balanced system of IS indicators has been proposed, which will allow the effectiveness evaluation of the university's network protection. Also as part of the research, a model of a secure network of an educational institution has been built, where network devices were emulated in a virtual machine (VM) with the EVE-NG application installed. Other network resources have been reproduced with the server virtualization system Proxmox VE. The IPS Suricata threat detection system, the Splunk platform, and the Pi-Hole DNS filter have been deployed on PVE-managed hosts.