To improve the information security of transportation systems, it is necessary that co research is aimed at the further development of models for the recognition of cyber threats in information and communication environment of transport (ICET) and decision making with vaguely specified inputted information. It was offered a new approach of decision making for cyber security of critically important information systems and automated control systems of ground transportation. It was reviewed the ICET case of cyber defense based on fuzzy regression of logical inference mechanisms for decision support with fuzzy input data.
The last decade showed the rapid development of major-critical information systems (MCIS), where cyber tech-nology detection and identification of cyber-attacks are used for cyber defense. Necessity of further research in the development of methodological and theoretical foundations of information synthesis of self-learning cyber defense systems are caused by growing number destabilizing factors of cyber security of MCIS. This paper contains tasks of improving the stability of MCIS in terms of introduction of new systems and moderniza-tion of existing information and automated control sys-tems with increasing number of destabilizing effects on the availability, confidentiality and integrity of infor-mation.The process of cyber defense of MCIS is monitored and analyzed by values of several parameters of abnormalities signs or cyber-attacks. This is make it possible to carry out a preliminary assessment of information security via the clustering feature set of abnormalities or attempted cyber-attacks. Offered a categorical model of develop-ment adaptive systems of an intellectual detection of cyber threats (ASIDCT). Algorism of self-learning of ASIDCT is developed with the help of procedure of fuzzy clustering. This allows to create an adaptive self-learning mechanisms of ASIDCT. To assess the quality partitioning area of abnormalities signs, vulnerabilities and cyber-attacks is made a rational set of number of clusters and fuzziness index clusters in features area. It is proved that the offered approach gives the possibility to solve complex problems in control of cyber-attack pro-cess of MCIS and can be used in the development of software solutions for cyber defense systems.