State University of Telecommunications Open Journals System
Not a member yet
2308 research outputs found
Sort by
КОМПЛЕКСНА МОДЕЛЬ ІНТЕГРАЦІЇ БЕЗПЕКИ У ЖИТТЄВИЙ ЦИКЛ РОЗРОБКИ ДЛЯ ХМАРНИХ СЕРЕДОВИЩ
This study proposes a comprehensive model specifically designed to address the security challenges associated withmodern cloud infrastructures. The proposed model ensures the implementation of security measures from initial planning to theend of the application lifecycle, prioritizing continuous security implementation at all stages. The model focuses on integratingsecurity as an integral part of the development process. It involves ongoing risk management, regular audits, and drivingcontinuous innovation throughout the SDLC. Other key components of the extended model include security governance, safecomponent decommissioning, monitoring, response, learning, and scaling.The extended model encompasses 20 key components that form a complete set of actions required to securely develop,deploy, and maintain modern software systems. It considers not only technical aspects, but also cultural and procedural factors,which are the basis for sustainable security management.Comparison with existing models demonstrates that the extended model not only addresses gaps in current practices, butalso offers a scalable solution that meets the dynamic nature of today's IT environments. The model's emphasis on continuousinnovation and adaptation helps organizations stay one step ahead of new threats and changing security requirements.Keywords: software development lifecycle, SDLC, DevSecOps, cloud security, security management, continuousintegration.
References1. DATA BREACH MANAGEMENT: AN INTEGRATED RISK MODEL / F. Khan та ін. Information &Management. 2021. Т. 58, № 1. С. 103392. URL: https: // doi.org / 10.1016 / j.im.2020.103392 (дата звернення:25.05.2025).2. Rajapakse R., Zahedi M., Babar M. Challenges and solutions when adopting DevSecOps: A systematicreview. Journal of Information and Software Technology. 2021.3. Ruparelia N. B. Software development lifecycle models. ACM SIGSOFT Software Engineering Notes.2010. Т. 35, № 3. С. 8–13. URL: https://doi.org/10.1145/1764810.1764814 (дата звернення: 25.05.2025).4. Jain R., Suman U. A Systematic Literature Review on Global Software Development Life Cycle. ACMSIGSOFT Software Engineering Notes. 2015. Т. 40, № 2. С. 1–14. URL: https://doi.org/10.1145/2735399.2735408(дата звернення: 25.05.2025).5. Acharya B., Sahu P. Software Development Life Cycle Models: A Review Paper. International Journal ofAdvanced Research in Engineering and Technology. 2020. Т. 11. С. 169–176. URL: https://doi.org/ 10.34218/IJARET.11.12.2020.019.6. Amazon Web Services I. What is SDLC? - Software Development Lifecycle Explained. URL: https: // aws.amazon. com / what-is / sdlc / #:~:text=The % 20software %2 0development % 20lifecycle%20 (SDLC, expectations%20during%20production%20and%20beyond(дата звернення: 25.05.2025).7. Olorunshola O., Ogwueleka F. Review of System Development Life Cycle (SDLC) Models for EffectiveApplication Delivery. Lecture Notes in Networks and Systems. 2021.8. Systematic Literature Review on Security Risks and its Practices in Secure Software Development /R. A. Khan та ін. IEEE Access. 2022. Т. 10. С. 5456–5481. URL: https://doi.org/10.1109/access.2022.3140181(датазвернення: 25.05.2025).9. Solutions - DevSecOps - Addressing Security Challenges in a Fast-Evolving Landscape White Paper. Cisco.URL: https://www.cisco.com/c/en/us/solutions/collateral/executive-perspectives/devsecops-addressing-securitychallenges.html(дата звернення: 25.05.2025).10. Kumar R., Goyal R. Modeling continuous security: A conceptual model for automated DevSecOps usingopen-source software over cloud (ADOC). Computers & Security. 2020. Т. 97. С. 101967.URL: https://doi.org/10.1016/j.cose.2020.101967(дата звернення: 25.05.2025).11. Zhao X., Clear T., Lal R. Identifying the primary dimensions of DevSecOps: A multi-vocal literaturereview. Journal of Systems and Software. 2024. С. 112063. URL: https://doi.org/10.1016/j.jss.2024.112063(датазвернення: 25.05.2025).12. GitHub - sottlmarek/DevSecOps: Ultimate DevSecOps library. GitHub. URL: https://github.com/sottlmarek/DevSecOps(дата звернення: 25.05.2025).13. OWASP Devsecops Maturity Model | OWASP Foundation. OWASP Foundation, the Open SourceFoundation for Application Security | OWASP Foundation. URL: https://owasp.org/www-project-devsecops-maturitymodel/(дата звернення: 25.05.2025).У цьому дослідженні пропонується комплексна модель, спеціально розроблена для вирішення проблембезпеки, пов'язаних із сучасними хмарними інфраструктурами. Запропонована модель забезпечує впровадженнязаходів безпеки від початкового планування до завершення життєвого циклу застосунку, надаючи пріоритетбезперервному впровадженню безпеки на всіх етапах. Модель орієнтована на інтеграцію безпеки як невід'ємноїскладової розробницького процесу. Вона передбачає постійне управління ризиками, регулярні аудити тастимулювання безперервних інновацій у межах SDLC. Серед інших ключових компонентів розширеної моделі –управління безпекою (security governance), безпечне виведення з експлуатації компонентів, моніторинг,реагування, навчання та масштабування.Розширена модель охоплює 20 ключових компонентів, що формують повний набір дій, необхідних длябезпечної розробки, впровадження та супроводу сучасних програмних систем. Вона враховує не лише технічніаспекти, але й культурні та процедурні чинники, що є основою для сталого управління безпекою.Порівняння з існуючими моделями демонструє, що розширена модель не лише усуває прогалини всучасних практиках, а й пропонує масштабоване рішення, яке відповідає динамічній природі сучасних ІТсередовищ. Акцент моделі на постійному впровадженні інновацій і адаптації допомагає організаціям залишатисяна крок попереду нових загроз і змін у вимогах до безпеки.Ключові слова: життєвий цикл розробки програмного забезпечення, SDLC, DevSecOps, безпека хмарнихсередовищ, управління безпекою, безперервна інтеграція.
Перелік посилань1. DATA BREACH MANAGEMENT: AN INTEGRATED RISK MODEL / F. Khan та ін. Information &Management. 2021. Т. 58, № 1. С. 103392. URL: https: // doi.org / 10.1016 / j.im.2020.103392 (дата звернення:25.05.2025).2. Rajapakse R., Zahedi M., Babar M. Challenges and solutions when adopting DevSecOps: A systematicreview. Journal of Information and Software Technology. 2021.3. Ruparelia N. B. Software development lifecycle models. ACM SIGSOFT Software Engineering Notes.2010. Т. 35, № 3. С. 8–13. URL: https://doi.org/10.1145/1764810.1764814 (дата звернення: 25.05.2025).4. Jain R., Suman U. A Systematic Literature Review on Global Software Development Life Cycle. ACMSIGSOFT Software Engineering Notes. 2015. Т. 40, № 2. С. 1–14. URL: https://doi.org/10.1145/2735399.2735408(дата звернення: 25.05.2025).5. Acharya B., Sahu P. Software Development Life Cycle Models: A Review Paper. International Journal ofAdvanced Research in Engineering and Technology. 2020. Т. 11. С. 169–176. URL: https://doi.org/ 10.34218/IJARET.11.12.2020.019.6. Amazon Web Services I. What is SDLC? - Software Development Lifecycle Explained. URL: https: // aws.amazon. com / what-is / sdlc / #:~:text=The % 20software %2 0development % 20lifecycle%20 (SDLC, expectations%20during%20production%20and%20beyond(дата звернення: 25.05.2025).7. Olorunshola O., Ogwueleka F. Review of System Development Life Cycle (SDLC) Models for EffectiveApplication Delivery. Lecture Notes in Networks and Systems. 2021.8. Systematic Literature Review on Security Risks and its Practices in Secure Software Development /R. A. Khan та ін. IEEE Access. 2022. Т. 10. С. 5456–5481. URL: https://doi.org/10.1109/access.2022.3140181(датазвернення: 25.05.2025).9. Solutions - DevSecOps - Addressing Security Challenges in a Fast-Evolving Landscape White Paper. Cisco.URL: https://www.cisco.com/c/en/us/solutions/collateral/executive-perspectives/devsecops-addressing-securitychallenges.html(дата звернення: 25.05.2025).10. Kumar R., Goyal R. Modeling continuous security: A conceptual model for automated DevSecOps usingopen-source software over cloud (ADOC). Computers & Security. 2020. Т. 97. С. 101967.URL: https://doi.org/10.1016/j.cose.2020.101967(дата звернення: 25.05.2025).11. Zhao X., Clear T., Lal R. Identifying the primary dimensions of DevSecOps: A multi-vocal literaturereview. Journal of Systems and Software. 2024. С. 112063. URL: https://doi.org/10.1016/j.jss.2024.112063(датазвернення: 25.05.2025).12. GitHub - sottlmarek/DevSecOps: Ultimate DevSecOps library. GitHub. URL: https://github.com/sottlmarek/DevSecOps(дата звернення: 25.05.2025).13. OWASP Devsecops Maturity Model | OWASP Foundation. OWASP Foundation, the Open SourceFoundation for Application Security | OWASP Foundation. URL: https://owasp.org/www-project-devsecops-maturitymodel/(дата звернення: 25.05.2025)
АНАЛІЗ ТРЕНДІВ КІБЕРЗАГРОЗ ЯК ВАЖЛИВИЙ ЕТАП УПРАВЛІННЯ РИЗИКАМИ ФІНАНСОВОГО СЕКТОРУ
Analysis of cyber threats to the financial sector updates the concept of a risk-based approach in the activities of financialinstitutions and allows for timely response to incidents. Tracking and understanding cyber threat trends contribute to effectivecyber risk management. To determine the vector of changes in the threat landscape, it is important to take into account theexperience of different countries in order to adapt best practices to Ukrainian realities. In the conditions of a full-scale war,Ukrainian financial institutions, in particular banks, demonstrated a noticeable increase in resilience to cyber-attacks. Theexperience gained in such difficult conditions allowed banks to strengthen their technical and organizational capabilities tocounter incidents. An important role in this was played by the coordinated interaction of state bodies and private organizations,CERT-UA, the activities of specialized units of Ukraine - the Cyber Police Department of the National Police of Ukraine, theState Cyber Protection Center of the State Service for Special Communications and Information Protection of Ukraine, theCritical Infrastructure Protection Department of the NBU, as well as interbank cooperation in the field of exchanginginformation about threats, international cooperation in the field of ensuring cybersecurity in the banking sector. This approachis the basis for increasing the speed of response to cyber incidents and will contribute to the overall strengthening of cyberprotection of the financial sector of Ukraine.Keywords: cyber threat landscape of the financial sector, cyber resilience of banks, cybercriminal organizations, DDoSattacks, CERT-UA, State Cyber Protection Center of the State Service for Special Communications and Information Protectionof Ukraine, NBU, MISP-UA.
References1. Кібербезпека в інформаційному суспільстві: Інформаційно-аналітичний дайджест / відп. ред.О.Довгань; упоряд. О.Довгань, Л.Литвинова, С.Дорогих; Державна наукова установа «Інститут інформації,безпеки і права НАПрН України»; Національна бібліотека України ім. В.І.Вернадського. К., 2023. №9 (вересень).351 с.2. Forcadell F.J., Aracil E., Ubeda F. The Impact of Corporate Sustainability and Digitalization on InternationalBanks’ Performance // Global Policy / Volume 11 (Supplement 1). pp.18-27. 2020. https://doi.org/10.1111/1758-5899.12761.3. Карчева І. Я. Сучасні тенденції інноваційного розвитку банків України в контексті концепції банк 3.0// Фінансовий простір. 2015. № 3(19). С. 299-305.4. Кльоба Л. Г. Цифровізація інноваційний напрям розвитку банків // Ефективна економіка [Електроннийжурнал]. 2018. № 12. URL: http://www.economy.nayka.com.ua/?op=1&z=6741 (дата звернення: 10.08.2024). DOI:10.32702/2307-2105-2018.12.84.5. Корнівська В. О. Цифровий банкінг: ризики фінансової дигіталізації // Проблеми економіки. 2017. № 3.С. 254-261.6. Шелудько С. А., Браткевич П. П. Вплив цифровізації на банківський бізнес в Україні // Приазовськийекономічний вісник. 2019. Вип. 5(16). С. 334-339. DOI: https://doi.org/10.32840/2522-4263/2019-5-57.7. Реверчук С., Творидло О. Цифровізація банківського бізнесу: виклики та можливості для державногорегулювання // Економіка та суспільство. 2023. № 55. DOI: 10.32782/2524-0072/2023-55-45.8. Альт Р., Бек Р., Смітс М. Т. ФінТех і трансформація фінансової галузі // Електронні ринки. – 2018. – Т.28. С. 235-243. DOI: 10.1007/s12525-018-0310-9.9. Diener F., Špaček M. Digital Transformation in Banking: A Managerial Perspective on Barriers to Change //Sustainability. 2021. Vol. 13, No. 4. P. 2032-2058. DOI:10.3390/su13042032.10. Кретов Д., Міндова О. Цифровізація банківського сектору України: сучасний стан та перспективирозвитку // Сталий розвиток економіки. 2024. № 2(49). С. 223–228. DOI: 10.32782/2308-1988/2024-49-35.11. Криклій О. А. Теорія та практика забезпечення кіберстійкості банків // Ефективна економіка. 2020. №10. URL: http://www.economy.nayka.com.ua/?op=1&z=8248. DOI: 10.32702/2307-2105-2020.10.50.12. ENISA Threat Landscape 2024 [Електронний ресурс]. Режим доступу: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2024. Назва з екрана. Дата звернення: 05.03.2025.13. ENISA Threat Landscape 2023 [Електронний ресурс]. Режим доступу: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023. Назва з екрана. Дата звернення: 05.03.2025.14. 2024 Data Breach Investigations Report [Електронний ресурс]. Режим доступу: https://www.verizon.com/business/resources/T2a8/reports/2024-dbir-data-breach-investigations-report.pdf. Назва з екрана. Дата звернення:05.03.2025.15. DBIR 2023 Data Breach Investigations Report [Електронний ресурс]. Режим доступу: https://inquest.net/wp-content/uploads/2023-data-breach-investigations-report-dbir.pdf. Назва з екрана. Дата звернення: 05.03.2025.16. Кількість кібератак на рік на критичну інфраструктуру України зросла з 800 до 4500: СБУ назвалаорганізаторів [Електронний ресурс]. Режим доступу: https://minfin.com.ua/ua/2024/05/07/126427603/. – Назва зекрана. – Дата звернення: 15.03.2025.17. ENISA Threat Landscape: Finance Sector [Електронний ресурс]. Режим доступу: https://www.enisa.europa.eu/sites/default/files/2025-02/Finance%20TL%202024_Final.pdf. Назва з екрана. Дата звернення: 09.05.2025.18. В Україні атакували "Приватбанк", "Ощадбанк" та сайт міноборони. Атаку відбили [Електроннийресурс]. Режим доступу: https://www.bbc.com/ukrainian/news-60394077. Назва з екрана. Дата звернення:11.03.2025.19.Масштабна DDOS-атака на monobank припинилася [Електронний ресурс]. Режим доступу:https://forbes.ua/news/masshtabna-ddos-ataka-na-monobank-pripinilasya-19082024-23092. Назва з екрана. Датазвернення: 23.03.2025.20. LockBit Demands 20m for 1.5TB of Data from Bank Syariah Indonesia Cyber Attack [Електронний ресурс].Режим доступу: https://thecyberexpress.com/lockbit-bank-syariah-indonesia-cyber-attack/.Назва з екрана. Датазвернення: 12.03.2025.21. A Global Police Operation Just Took Down the Notorious LockBit Ransomware Gang [Електронний ресурс].Режим доступу: https://www.wired.com/story/lockbit-ransomware-takedown-website-nca-fbi/. Назва з екрана. Датазвернення: 23.03.2025.22. ALPHV BlackCat Ransomware: A Technical Deep Dive and Mitigation Strategies [Електронний ресурс].Режим доступу: https://www.trustwave.com/en-us/resources/blogs/trustwave-blog/alphv-blackcat-ransomware-a-technical-deep-dive-and-mitigation-strategies/. Назва з екрана. Дата звернення: 23.03.2025.23. Share of financial organizations worldwide hit by ransomware attacks from 2021 to 2024 [Електроннийресурс]. Режим доступу: https://www.statista.com/statistics/1460896/rate-ransomware-attacks-global/. Назва з екрана.Дата звернення: 25.03.2025.24. Attack Methods and Payloads [Електронний ресурс]. Режим доступу: https://www.infosecuritymagazine.com/news/phishing-campaign-targets-ukraines/. Назва з екрана. Дата звернення: 15.04.2025.25. 35% of Cybersecurity Incidents are Business Email Compromise (BEC) Phishing Attacks [Електроннийресурс]. Режим доступу: https://grsb.bank/35-of-cybersecurity-incidents-are-business-email-compromise-bec-phishing-attacks/. Назва з екрана. Дата звернення: 10.04.2025.26. SRP Federal Credit Union reports data breach affecting more than 240,000 people [Електронний ресурс].Режим доступу: https://www.augustachronicle.com/story/news/crime/2024/12/24/srp-federal-credit-union-announcesdata-breach-to-240000-plus-people-cybersecurity-crime-nitrogen/77181661007/. Назва з екрана. Дата звернення:17.03.2025.27. Bank of America попереджає клієнтів про витік даних і намагається виправити ситуацію [Електроннийресурс]. Режим доступу: https: // fintechinsider.com.ua/bank-of-america-poperedzhaye-kliyentiv-pro-vytik-danyh-inamagayetsya-vypravyty-sytuacziyu/. Назва з екрана. Дата звернення: 23.03.2025.28. Top 10 Biggest Cyber Attacks of 2024 & 25 Other Attacks to Know About! [Електронний ресурс]. Режимдоступу: https: // www.cm-alliance.com / cybersecurity-blog / top-10-biggest-cyber-attacks-of-2024-25-other-attacksto-know-about. Назва з екрана. Дата звернення: 09.03.2025.29. Як українські банки захищаються від кібератак в умовах війни: розповідає Євген Балютов, директор зінформаційної безпеки Райффайзен Банку. [Електронний ресурс]. Режим доступу: https://ua.news/ua/technologies/kak-ukraynskye-banky-zashhyshhayutsya-ot-kyberatak-v-uslovyyah-vojny-rasskazyvaet-evgenyj-balyutov-dyrektor-poynformatsyonnoj-bezopasnosty-rajffajzen-banka. Назва з екрана. Дата звернення: 03.03.2025.Аналіз кіберзагроз фінансового сектору актуалізує концепцію ризик-орієнтованого підходу в діяльностіфінансових установ та дозволяє своєчасно реагувати на інциденти. Відстеження та розуміння трендів кіберзагрозсприяють ефективному управлінню кіберризиками. Для визначення вектору змін ландшафту загроз важливовраховувати досвід різних країн, щоб адаптувати найкращі практики до українських реалій. В умовахповномасштабної війни українські фінансові установи, зокрема банки, продемонстрували помітне зростаннястійкості до кібератак. Набутий в таких складних умовах досвід дозволив банкам зміцнити технічні таорганізаційні можливості протидії інцидентам. Важливу роль у цьому відіграла скоординована взаємодіядержавних органів та приватних організацій, CERT-UA, діяльність спеціалізованих підрозділів України –Департаменту кіберполіції Національної поліції України, Державного центру кіберзахисту Державної службиспеціального зв’язку та захисту інформації України, управління захисту критичної інфраструктури НБУ, а такожміжбанківське співробітництво у сфері обміну інформацією про загрози, міжнародна співпраця у сферізабезпечення кібербезпеки в банківському секторі. Такий підхід становить основу для підвищення швидкостіреагування на кіберінциденти та сприятиме загальному посиленню кіберзахисту фінансового сектору України.Ключові слова: ландшафт кіберзагроз фінансового сектору, кіберстійкість банків, кіберзлочинніорганізації, DDoS-атаки, CERT-UA, Державний центр кіберзахисту Державної служби спеціального зв’язку тазахисту інформації України, НБУ, MISP-UA.
Перелік посилань1. Кібербезпека в інформаційному суспільстві: Інформаційно-аналітичний дайджест / відп. ред.О.Довгань; упоряд. О.Довгань, Л.Литвинова, С.Дорогих; Державна наукова установа «Інститут інформації,безпеки і права НАПрН України»; Національна бібліотека України ім. В.І.Вернадського. К., 2023. №9 (вересень).351 с.2. Forcadell F.J., Aracil E., Ubeda F. The Impact of Corporate Sustainability and Digitalization on InternationalBanks’ Performance // Global Policy / Volume 11 (Supplement 1). pp.18-27. 2020. https://doi.org/10.1111/1758-5899.12761.3. Карчева І. Я. Сучасні тенденції інноваційного розвитку банків України в контексті концепції банк 3.0// Фінансовий простір. 2015. № 3(19). С. 299-305.4. Кльоба Л. Г. Цифровізація інноваційний напрям розвитку банків // Ефективна економіка [Електроннийжурнал]. 2018. № 12. URL: http://www.economy.nayka.com.ua/?op=1&z=6741 (дата звернення: 10.08.2024). DOI:10.32702/2307-2105-2018.12.84.5. Корнівська В. О. Цифровий банкінг: ризики фінансової дигіталізації // Проблеми економіки. 2017. № 3.С. 254-261.6. Шелудько С. А., Браткевич П. П. Вплив цифровізації на банківський бізнес в Україні // Приазовськийекономічний вісник. 2019. Вип. 5(16). С. 334-339. DOI: https://doi.org/10.32840/2522-4263/2019-5-57.7. Реверчук С., Творидло О. Цифровізація банківського бізнесу: виклики та можливості для державногорегулювання // Економіка та суспільство. 2023. № 55. DOI: 10.32782/2524-0072/2023-55-45.8. Альт Р., Бек Р., Смітс М. Т. ФінТех і трансформація фінансової галузі // Електронні ринки. – 2018. – Т.28. С. 235-243. DOI: 10.1007/s12525-018-0310-9.9. Diener F., Špaček M. Digital Transformation in Banking: A Managerial Perspective on Barriers to Change //Sustainability. 2021. Vol. 13, No. 4. P. 2032-2058. DOI:10.3390/su13042032.10. Кретов Д., Міндова О. Цифровізація банківського сектору України: сучасний стан та перспективирозвитку // Сталий розвиток економіки. 2024. № 2(49). С. 223–228. DOI: 10.32782/2308-1988/2024-49-35.11. Криклій О. А. Теорія та практика забезпечення кіберстійкості банків // Ефективна економіка. 2020. №10. URL: http://www.economy.nayka.com.ua/?op=1&z=8248. DOI: 10.32702/2307-2105-2020.10.50.12. ENISA Threat Landscape 2024 [Електронний ресурс]. Режим доступу: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2024. Назва з екрана. Дата звернення: 05.03.2025.13. ENISA Threat Landscape 2023 [Електронний ресурс]. Режим доступу: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023. Назва з екрана. Дата звернення: 05.03.2025.14. 2024 Data Breach Investigations Report [Електронний ресурс]. Режим доступу: https://www.verizon.com/business/resources/T2a8/reports/2024-dbir-data-breach-investigations-report.pdf. Назва з екрана. Дата звернення:05.03.2025.15. DBIR 2023 Data Breach Investigations Report [Електронний ресурс]. Режим доступу: https://inquest.net/wp-content/uploads/2023-data-breach-investigations-report-dbir.pdf. Назва з екрана. Дата звернення: 05.03.2025.16. Кількість кібератак на рік на критичну інфраструктуру України зросла з 800 до 4500: СБУ назвалаорганізаторів [Електронний ресурс]. Режим доступу: https://minfin.com.ua/ua/2024/05/07/126427603/. – Назва зекрана. – Дата звернення: 15.03.2025.17. ENISA Threat Landscape: Finance Sector [Електронний ресурс]. Режим доступу: https://www.enisa.europa.eu/sites/default/files/2025-02/Finance%20TL%202024_Final.pdf. Назва з екрана. Дата звернення: 09.05.2025.18. В Україні атакували "Приватбанк", "Ощадбанк" та сайт міноборони. Атаку відбили [Електроннийресурс]. Режим доступу: https://www.bbc.com/ukrainian/news-60394077. Назва з екрана. Дата звернення:11.03.2025.19.Масштабна DDOS-атака на monobank припинилася [Електронний ресурс]. Режим доступу:https://forbes.ua/news/masshtabna-ddos-ataka-na-monobank-pripinilasya-19082024-23092. Назва з екрана. Датазвернення: 23.03.2025.20. LockBit Demands 20m for 1.5TB of Data from Bank Syariah Indonesia Cyber Attack [Електронний ресурс].Режим доступу: https://thecyberexpress.com/lockbit-bank-syariah-indonesia-cyber-attack/.Назва з екрана. Датазвернення: 12.03.2025.21. A Global Police Operation Just Took Down the Notorious LockBit Ransomware Gang [Електронний ресурс].Режим доступу: https://www.wired.com/story/lockbit-ransomware-takedown-website-nca-fbi/. Назва з екрана. Датазвернення: 23.03.2025.22. ALPHV BlackCat Ransomware: A Technical Deep Dive and Mitigation Strategies [Електронний ресурс].Режим доступу: https://www.trustwave.com/en-us/resources/blogs/trustwave-blog/alphv-blackcat-ransomware-a-technical-deep-dive-and-mitigation-strategies/. Назва з екрана. Дата звернення: 23.03.2025.23. Share of financial organizations worldwide hit by ransomware attacks from 2021 to 2024 [Електроннийресурс]. Режим доступу: https://www.statista.com/statistics/1460896/rate-ransomware-attacks-global/. Назва з екрана.Дата звернення: 25.03.2025.24. Attack Methods and Payloads [Електронний ресурс]. Режим доступу: https://www.infosecuritymagazine.com/news/phishing-campaign-targets-ukraines/. Назва з екрана. Дата звернення: 15.04.2025.25. 35% of Cybersecurity Incidents are Business Email Compromise (BEC) Phishing Attacks [Електроннийресурс]. Режим доступу: https://grsb.bank/35-of-cybersecurity-incidents-are-business-email-compromise-bec-phishing-attacks/. Назва з екрана. Дата звернення: 10.04.2025.26. SRP Federal Credit Union reports data breach affecting more than 240,000 people [Електронний ресурс].Режим доступу: https://www.augustachronicle.com/story/news/crime/2024/12/24/srp-federal-credit-union-announcesdata-breach-to-240000-plus-people-cybersecurity-crime-nitrogen/77181661007/. Назва з екрана. Дата звернення:17.03.2025.27. Bank of America попереджає клієнтів про витік даних і намагається виправити ситуацію [Електроннийресурс]. Режим доступу: https: // fintechinsider.com.ua/bank-of-america-poperedzhaye-kliyentiv-pro-vytik-danyh-inamagayetsya-vypravyty-sytuacziyu/. Назва з екрана. Дата звернення: 23.03.2025.28. Top 10 Biggest Cyber Attacks of 2024 & 25 Other Attacks to Know About! [Електронний ресурс]. Режимдоступу: https: // www.cm-alliance.com / cybersecurity-blog / top-10-biggest-cyber-attacks-of-2024-25-other-attacksto-know-about. Назва з екрана. Дата звернення: 09.03.2025.29. Як українські банки захищаються від кібератак в умовах війни: розповідає Євген Балютов, директор зінформаційної безпеки Райффайзен Банку. [Електронний ресурс]. Режим доступу: https://ua.news/ua/technologies/kak-ukraynskye-banky-zashhyshhayutsya-ot-kyberatak-v-uslovyyah-vojny-rasskazyvaet-evgenyj-balyutov-dyrektor-poynformatsyonnoj-bezopasnosty-rajffajzen-banka. Назва з екрана. Дата звернення: 03.03.2025
АНАЛІЗ ПЕРЕДУМОВ ДЛЯ ЗАБЕЗПЕЧЕННЯ КОНСЕНСУСУ РЕСУРСІВ ПРИ ВИКОНАННІ ПРОЦЕДУР ВСТАВЛЕННЯ СТЕГАНОГРАФІЧНИХ ДАНИХ
In the conditions of sustainable growth in the complexity and multi-vector nature of modern cyber threats, digitalsteganography continues to play an important role in ensuring data confidentiality [1-4] in information systems (IS) thatoperate in conditions of resource limitations. The relevance of this direction emphasizes the need to create energy-efficientsteganographic algorithms that combine content resistance to hacking and low computational complexity. Experimentsconfirmed the assumption that the procedure of preliminary content smoothing improves the starting conditions for theformation of series of basic blocks (BB) of source images (in this case, content), minimizing the number of procedures atthe stage of their encoding with conversion. The introduction of these procedures reduces the consequences of fluctuation«noise» in low-information areas of images and improves the computational complexity indicator of the processingalgorithm. Following the test trials results, preliminary assessments of their performance were obtained: - in terms ofexecution time, PSNR indicator, and the number of BBs formed. The ability to flexibly configure preprocessingparameters [1,5] allows the smoothing process to be adapted to different types of data (statistical properties of content),ensuring a controlled level of visual distortion in the conditions of existing resource limitations of the hardware platformsused. In practical terms, such consequences are extremely useful, especially in conditions of multitasking and/or a scarcityof residual battery capacity in gadgets. This ensures high flexibility and efficiency of the steganography process, even inthe conditions of limited resources of the base device and/or system. The modeling performed allows to speak about goodprospects for further implementation of the considered data processing mechanisms into the structure of specializedsteganographic algorithms included in the group of mobile applications. The results obtained contribute to the furtherimprovement of the concept of low-resource steganography and form perspective directions for further research.Keywords: steganography, run-lengths encoding, images, basic block, encapsulation, computational complexity;resource consensus.
References1. Конахович, Г., Прогонов, Д., & Пузиренко, О. (2018). Комп’ютерна стеганографічна обробка й аналізмультимедійних даних : підручник. Київ: Центр навчальної літератури.2. Fridrich, J. (2009). Steganography in Digital Media: Principles, Algorithms, and Applications. Cambridge:Cambridge University Press.3. Yahya, A. (2019). Steganography techniques for digital images. Springer International Publishing.4. Hassaballah, M. (2020). Digital Media Steganography: Principles, Algorithms, and Advances. Academic Press.5. Гончаров, М. О., & Малахов, С. В. (2021, 21–23 квітня). Моделювання процедур підготовки данихстеганоалгоритма з багаторівневим мультиплексуванням контенту. Комп’ютерне моделювання в наукоємнихтехнологіях (КНМТ-2021): матеріали 7-ї міжнар. наук.-техн. конф. Харків: ХНУ ім. В. Н. Каразіна, 118–122. URL:http://surl.li/axsna.6. Honcharov, M., & Malakhov, S. (2024). MODELING ATTEMPTS OF UNAUTHORIZED EXTRACTION OFSTEGANOCONTENT UNDER DIFFERENT COMBINATIONS OF DATA KEY-EXTRACTOR. Collection ofScientific Papers «ΛΌГOΣ», (March 1, 2024; Paris, France), 234-245. DOI: 10.36074/logos-01.03.2024.053.7. Shih, F. Y. (2020). Digital watermarking and steganography. Boca Raton: CRC Press.8. Fuad, M., & Ernawan, F. (2020). Video steganography based on DCT psychovisual and object motion. Bulletinof Electrical Engineering and Informatics, 9(3), 1015–1023. DOI: 10.11591/eei.v9i3.18599. Гончаров, Н., Лесная, Ю., & Малахов, С. (2022). Адаптация принципа кодирования длин серий дляпротиводействия попыткам неавторизованной экстракции стеганоконтента. Grail of Science, (17), 241-247. DOI:10.36074/grail-of-science.22.07.2022.042.10. Honcharov, M., & Malakhov, S. (2023). Adaptive modification of the output array of basic blocks series as аmechanism to counteract unauthorized extraction of the staganocontent. Science and technology today, 8(22), 336-352.DOI:10.52058/2786-6025-2023-8(22)-336-352.11. Малахов, С., Колованова, Є., & Гончаров, М. (2023). ОСОБЛИВОСТІ НЕСАНКЦІОНОВАНОЇЕКСТРАКЦІЇ СТЕГАНОКОНТЕНТУ ПРИ ЗМІНАХ ПРОСТОРОВОГО ПОЗИЦІЮВАННЯ ОПОРНИХ БЛОКІВКОНТЕНТУ. Collection of Scientific Papers «ΛΌΓOΣ», (May 26, 2023; Boston, USA), 152–157. DOI: 10.36074/logos26.05.2023.04112. Pratt, W. K. (1978). Digital Image Processing. John Wiley & Sons.13. Honcharov, M., Pavlova, L., & Lesnaya, Y. (2022). Modeling steganocontent extraction attempts with differentlengths stack sampling series of images blocks. Computer Science and Cybersecurity, (2), 22-27. DOI: 10.26565/2519-2310-2022-2-02В умовах сталого зростання складності та багатовекторності сучасних кіберзагроз, цифрова стеганографіяпродовжує відігравати важливу роль у забезпеченні конфіденційності даних [1-4] в інформаційних системах (ІС), щофункціонують в умовах обмеженості ресурсів. Актуальність цього напрямку підкреслює необхідність створенняенергоефективних стеганографічних алгоритмів, які поєднують стійкість контенту до злому та низьку обчислювальнускладність. Експерименти підтвердили припущення, що процедура попереднього згладжування контенту покращуєпочаткові умови формування серії базових блоків (ББ) вихідних зображень (в даному випадку контенту), мінімізуючикількість процедур на етапі їх кодування з перетворенням. Впровадження цих процедур зменшує наслідкифлуктуаційного «шуму» в низькоінформаційних областях зображень та покращує показник обчислювальної складностіалгоритму обробки. За результатами тестових випробувань були отримані попередні оцінки їхньої продуктивності: -за часом виконання, показником PSNR та кількістю сформованих ББ. Можливість гнучкого налаштування параметрівпопередньої обробки [1,5] дозволяє адаптувати процес згладжування до різних типів даних (статистичних властивостейконтенту), забезпечуючи контрольований рівень візуальних спотворень в умовах існуючих обмежень ресурсіввикористовуваних апаратних платформ. У практичному плані такі наслідки надзвичайно корисні, особливо в умовахбагатозадачності та/або дефіциту залишкової ємності акумулятора в гаджетах. Це забезпечує високу гнучкість таефективність процесу стеганографії навіть в умовах обмежених ресурсів базового пристрою та/або системи. Проведенемоделювання дозволяє говорити про хороші перспективи подальшого впровадження розглянутих механізмів обробкиданих у структуру спеціалізованих стеганографічних алгоритмів, що входять до групи мобільних додатків. Отриманірезультати сприяють подальшому вдосконаленню концепції низькоресурсної стеганографії та формують перспективнінапрямки для подальших досліджень.Ключові слова: стеганографія, кодування довжин прогонів, зображення, базовий блок, інкапсуляція,обчислювальна складність; консенсус щодо ресурсів.
Перелік посилань1. Конахович, Г., Прогонов, Д., & Пузиренко, О. (2018). Комп’ютерна стеганографічна обробка й аналізмультимедійних даних : підручник. Київ: Центр навчальної літератури.2. Fridrich, J. (2009). Steganography in Digital Media: Principles, Algorithms, and Applications. Cambridge:Cambridge University Press.3. Yahya, A. (2019). Steganography techniques for digital images. Springer International Publishing.4. Hassaballah, M. (2020). Digital Media Steganography: Principles, Algorithms, and Advances. Academic Press.5. Гончаров, М. О., & Малахов, С. В. (2021, 21–23 квітня). Моделювання процедур підготовки данихстеганоалгоритма з багаторівневим мультиплексуванням контенту. Комп’ютерне моделювання в наукоємнихтехнологіях (КНМТ-2021): матеріали 7-ї міжнар. наук.-техн. конф. Харків: ХНУ ім. В. Н. Каразіна, 118–122. URL:http://surl.li/axsna.6. Honcharov, M., & Malakhov, S. (2024). MODELING ATTEMPTS OF UNAUTHORIZED EXTRACTION OFSTEGANOCONTENT UNDER DIFFERENT COMBINATIONS OF DATA KEY-EXTRACTOR. Collection ofScientific Papers «ΛΌГOΣ», (March 1, 2024; Paris, France), 234-245. DOI: 10.36074/logos-01.03.2024.053.7. Shih, F. Y. (2020). Digital watermarking and steganography. Boca Raton: CRC Press.8. Fuad, M., & Ernawan, F. (2020). Video steganography based on DCT psychovisual and object motion. Bulletinof Electrical Engineering and Informatics, 9(3), 1015–1023. DOI: 10.11591/eei.v9i3.18599. Гончаров, Н., Лесная, Ю., & Малахов, С. (2022). Адаптация принципа кодирования длин серий дляпротиводействия попыткам неавторизованной экстракции стеганоконтента. Grail of Science, (17), 241-247. DOI:10.36074/grail-of-science.22.07.2022.042.10. Honcharov, M., & Malakhov, S. (2023). Adaptive modification of the output array of basic blocks series as аmechanism to counteract unauthorized extraction of the staganocontent. Science and technology today, 8(22), 336-352.DOI:10.52058/2786-6025-2023-8(22)-336-352.11. Малахов, С., Колованова, Є., & Гончаров, М. (2023). ОСОБЛИВОСТІ НЕСАНКЦІОНОВАНОЇЕКСТРАКЦІЇ СТЕГАНОКОНТЕНТУ ПРИ ЗМІНАХ ПРОСТОРОВОГО ПОЗИЦІЮВАННЯ ОПОРНИХ БЛОКІВКОНТЕНТУ. Collection of Scientific Papers «ΛΌΓOΣ», (May 26, 2023; Boston, USA), 152–157. DOI: 10.36074/logos26.05.2023.04112. Pratt, W. K. (1978). Digital Image Processing. John Wiley & Sons.13. Honcharov, M., Pavlova, L., & Lesnaya, Y. (2022). Modeling steganocontent extraction attempts with differentlengths stack sampling series of images blocks. Computer Science and Cybersecurity, (2), 22-27. DOI: 10.26565/2519-2310-2022-2-0
СИТУАЦІЙНО-ОРІЄНТОВАНІ СИСТЕМИ УПРАВЛІННЯ БЕЗПЕКОЮ НА ОСНОВІ УНІФІКОВАНОЇ МАТРИЧНОЇ МОДЕЛІ: ЛОГІКО-ЛІНГВІСТИЧНИЙ ТА МІЖГАЛУЗЕВИЙ ПІДХІД
The article substantiates the concept of using a unified matrix model as a basis for creating situation-oriented securitymanagement systems (SMS) in conditions of complex multi-level threat dynamics. A methodology for formalizing the structural and functional components of the SMS is developed based on logical-linguistic constructs and inter-sectoral matrices that reflectthe relationships between management entities, security objects, types of threats, forms of risk, response policies and tools forimplementing protective measures. Five stages of situational management are distinguished - threat detection, risk assessment,identification of alternatives, decision-making and performance control - which are presented in the form of a typical cycle ofmanagement action. An architecture for information integration of the unified model into decision support systems (DSS) andsituational centers as part of the nationwide response network is proposed. An example of practical implementation of the modelfor a scenario of an inter-sectoral threat in the critical infrastructure sector with a multidimensional assessment of effectivenessis demonstrated. The results obtained confirm the feasibility of further development of a systemic approach to situationalmanagement, focused on proactive threat detection and adaptive response in conditions of hybrid danger and increasingcomplexity of the security environment.Keywords: situational management, unified matrix model, security system, critical infrastructure, inter-sectoral threat.
References1. Domarev, V. V. (2004). Bezpeka informatsiinykh tekhnolohii: Systemnyi pidkhid [Information-technologysecurity: A systems approach]. TID “Diasoft”. https://nvd.luguniv.edu.ua/archiv/NN9/10plvvas.pdf (arxiv.org).2. Domarev, V. V. (2002). Bezpeka informatsiinykh tekhnolohii: Metodolohiia stvore nnia system zakhystu[Information-technology security: Methodology for building protection systems]. TID “DS”. https://www.bsut.by/images/MainMenuFiles/Obrazovanie/Studentam/eumkd/et/euk_56_029/ch1/ch1_1/ch1_1_1.pdf (bsut.by).3. Domarev, V. V., & Domarev, D. V. (2012). Upravlinnia informatsiinoiu bezpekoiu v bankivskykh ustanovakh:Teoriia i praktyka vprovadzhennia standartiv serii ISO 27k [Information-security management in banking institutions:Theory and practice of ISO 27k implementation]. Velstar. https://www.old.nas.gov.ua/siaz/ Ways_of_development_of_Ukrainian_science/article/12068.001.pdf.4. National Bank of Ukraine. (2010). DSTU SUIB 1.0/ISO/IEC 27001:2010. Informatsiini tekhnolohii. Metodyzakhystu. Systema upravlinnia informatsiinoiu bezpekoiu. Vymohy (ISO/IEC 27001:2005, MOD). https://kyianyn.files.wordpress.com/2010/12/nbu-27001.pdf (scispace.com).5. National Bank of Ukraine. (2010). DSTU SUIB 2.0/ISO/IEC 27002:2010. Informatsiini tekhnolohii. Metodyzakhystu. Zvid pravyl dlia upravlinnia informatsiinoiu bezpekoiu (ISO/IEC 27002:2005, MOD). https://sbyte.com/useful/27002.pdf (scispace.com).6. National Bank of Ukraine. (2011, March 3). Lyst № 24112/365: Metodychni rekomendatsii shchodovprovadzhennia systemy upravlinnia informatsiinoiu bezpekoiu ta metodyky otsinky ryzykiv vidpovidno do standartivNBU [Letter No. 24112/365: Guidelines for ISMS implementation and risk assessment]. https://bank.gov.ua(bank.gov.ua).7. Domarev, V. V. (2004). Otsinka efektyvnosti system zakhystu informatsii [Evaluation of the effectiveness ofinformation-protection systems]. Problemy zakhystu informatsii. Retrieved from https://pgf.udpu.edu.ua/wpcontent/uploads/2019/12/РП-Інформаційна-безпека.pdf (pgf.udpu.edu.ua).8. Domarev, D. V., & Domarev, V. V. (2011). Information security management system “Matrix” based on systemapproach. Problemy informatyzatsii ta upravlinnia, 2(34), 36-39. https://doi.org/10.18372/22255036.19.4706.9. Moroz, O. Ya. (1972). Lohiko-hnoseolohichnyi analiz pryntsypiv kybernetychnoho modeliuvannia [Logicalgnoseological analysis of cybernetic-modeling principles]. Naukova dumka. https://iino.knuba.edu.ua/.../Філософія.pdf(iino.knuba.edu.ua).10. Shengeriy, L. M. (2007). Ihrova skhema ratsionalnosti: Lohiko-analitychne modeliuvannia vzaiemodiisubiektiv [The game scheme of rationality: A logical-analytical modeling of subject interaction]. Filosofski obryi, 18,129-141. https://harvester.nas.gov.ua/Record/irk-123456789-73475 (harvester.nas.gov.ua).11. Bezshtanko, V. (2006). Tsykl vprovadzhennia systemy upravlinnia informatsiinoiu bezpekoiu [Cycle ofinformation-security management system implementation]. Pravove, normatyvne ta metrologichne zabezpechenniasystemy zakhystu informatsii v Ukraini, 2(13), 123–126. https://ela.kpi.ua/handle/123456789/10974 (ela.kpi.ua).12. Kharchenko, V., Pechevysty, R., Alexeiev, O., & Karapetyan, S. (2020). Selection of a system of indicatorscharacterizing the effectiveness of the flight safety management system. Proceedings of the National Aviation University,84(3), 14–18. https://doi.org/10.18372/2306-1472.84.14948 (jrnl.nau.edu.ua).13. Ostriakova, V. Yu. (2017). Formuvannia systemy upravlinnia informatsiinoiu bezpekoiu pidpryiemstv[Formation of the enterprise information-security management system] (Candidate’s thesis). Kyiv National University ofTechnologies and Design. https://er.knutd.edu.ua/handle/123456789/8187 (er.knutd.edu.ua).14. Ananchenko, O. Ye. (2016). Pytannia formuvannia orhanizatsiinoi struktury systemy upravlinniainformatsiinoiu bezpekoiu pidpryiemstva [Issues of forming the organizational structure of an enterprise informationsecurity management system]. Suchasnyi zakhyst informatsii, 1, 79-83. https://journals.dut.edu.ua/index.php/ dataprotect/article/view/536 (journals.dut.edu.ua).15. Lysenko, S. O. (2023). Rozvytok systemy derzhavnoho upravlinnia informatsiinoiu bezpekoiu na suchasnomuetapi [Development of the state information-security management system at the present stage]. Law and PublicAdministration, (1), 53-60. https://doi.org/10.32782/pdu.2023.1.53 (researchgate.net).16. Medvid, V. Yu., Pravdyvets, O. M., & Kryvchun, R. Yu. (2023). Teoretyko-metodychni zasady formuvanniasystemy upravlinnia informatsiinoiu bezpekoiu pidpryiemstva [Theoretical and methodological principles for forming anenterprise information-security management system]. Agrosvit, 1, 24–30. https://doi.org/10.32702/2306-6792.2023.1.24(dspace.krok.edu.ua).17. Mykolaychuk, M., & Popov, M. (2025). Udoskonalennia systemy instrumentiv upravlinnia bezpekoiu Ukrainyna rehionalnomu rivni [Improvement of the system of management tools for Ukraine’s security at the regional level].Natsionalni Interesy Ukrainy, 3(8), 232–251. https://doi.org/10.52058/3041-1793-2025-3(8)-232-251 (researchgate.net).18. Koryeeva, N. H. (2020). Formuvannia suchasnoi systemy upravlinnia informatsiinoiu bezpekoiu viiskovoichasty [Formation of the modern information-security management system of a military unit] (Master’s thesis). ChernihivNational Technological University. https://ir.stu.cn.ua/handle/123456789/19964 (ir.stu.cn.ua).19. Baranova, O. A., Shtefan, D. Yu., & Shvetsov, V. M. (2013). Informatsiina model avtomatyzovanoi systemyupravlinnia informatsiinoiu bezpekoiu sudna [Information model of an automated ship information-security managementsystem]. Proceedings of the III All-Ukrainian Scientific-Practical Conference “Modern Problems of Information Securityin Transport” (pp. 1–5). Mykolaiv: National University of Shipbuilding. https://eir.nuos.edu.ua/handle/123456789/1218(eir.nuos.edu.ua).20. Tereshchenko, L. O. (2021). Upravlinnia ryzykamy informatsiinykh system: etapy protsesu upravlinniaryzykamy [Risk management of information systems: Stages of the risk-management process]. Ekonomika ta Suspilstvo,(31), Article 12. https://doi.org/10.32782/2524-0072/2021-31-12 (economyandsociety.in.ua).21. Beliachenko, V. V., Bobrov, S. V., & Utiushev, M. K. (2021). Upravlinnia ryzykamy stvorennia elementivavtomatyzovanykh system upravlinnia [Risk management in the development of automated control-system elements].Zbirnyk naukovykh prats Tsentru voienno-stratehichnykh doslidzhen Natsionalnoho universytetu oborony Ukrainy im. I.Cherniakhovskoho, 3(70), 101–106. https://doi.org/10.33099/2304-2745/2020-3-70/101-106.22. Dodon, O. D., & Kovalenko, O. O. (2022). Modeli informatsiinykh system upravlinnia personalom [Modelsof human-resource-management information systems]. Efektyvna ekonomika, (11). https://doi.org/10.32702/2307-2105.2022.11.22.23. Netreba, I. (2014). Etapy rozvytku informatsiinykh system upravlinnia pidpryiemstvom [Stages ofdevelopment of enterprise-management information systems]. Formuvannia rynkovoi ekonomiky v Ukraini, 31(2), 82–85. https://irbis-nbuv.gov.ua/.../Nvmgu_eim_2015_10_27.pdf (irbis-nbuv.gov.ua).24. Semenyuk, A. Ya. (2009). Rozvytok standartiv informatsiinykh system dlia upravlinnia pidpryiemstvom[Development of standards for enterprise-management information systems]. Naukovyi visnyk Uzhhorodskohonatsionalnoho universytetu. Seriia Ekonomika, 28(2), 143–148. https://dspace.uzhnu.edu.ua/jspui/handle/lib/52105(dspace.uzhnu.edu.ua).25. Netreba, I. O. (2013). Pidkhody do klasyfikatsii informatsiinykh system upravlinnia pidpryiemstvom[Approaches to the classification of enterprise-management information systems]. Formuvannia rynkovykh vidnosyn vUkraini, (4), 137–140. https://irbis-nbuv.gov.ua/.../frvu_2013_4_33 (irbis-nbuv.gov.ua).26. Bezborodova, T. V. (2007). Peredumovy ta etapy formuvannia korporatyvnykh informatsiinykh systemupravlinnia [Preconditions and stages of forming corporate-management information systems]. Ekonomika ta derzhava,(10), 41–44. https://www.economy.nayka.com.ua/?op=1&z=674 (economy.nayka.com.ua).27. Solovyiov, V. M., Serdiuk, O. A., & Danylychuk, G. B. (2016). Modeliuvannia skladnykh system [Modelingof complex systems]. Vydavets O. Yu. Vovchok. https://doi.org/10.31812/0564/1065.28. Solovyiov, V. M. (2017). Universalnyi instrumentarii modeliuvannia skladnykh system [Universal toolkit formodeling complex systems]. New Computer Technology, 15, 10–14. https://doi.org/10.55056/nocote.v15i0.617.29. Bratushka, S. M. (2009). Imitatsiine modeliuvannia yak instrument doslidzhennia skladnykh ekonomichnykhsystem [Simulation modeling as a tool for studying complex economic systems]. Visnyk Ukrainskoi akademii bankivskoispravy, 2(27), 113–118. http://essuir.sumdu.edu.ua/handle/123456789/55242 (essuir.sumdu.edu.ua).30. Khimich, O. M. (2018). Superkomp’iuterni tekhnolohii ta matematychne modeliuvannia skladnykh system[Supercomputer technologies and mathematical modeling of complex systems]. Visnyk Natsionalnoi akademii naukUkrainy, (5), 69–72. https://irbis-nbuv.gov.ua/.../vnanu_2018_5_21 (irbis-nbuv.gov.ua).У статті обґрунтовано концепцію використання уніфікованої матричної моделі як базису для створенняситуаційно-орієнтованих систем управління безпекою (ССУ) в умовах складної багаторівневої загрозовоїдинаміки. Розроблено методику формалізації структурно-функціональних компонентів ССУ на основі логіколінгвістичних конструкцій та міжгалузевих матриць, які відображають взаємозв’язки між суб’єктами управління,об’єктами безпеки, типами загроз, формами ризику, політиками реагування та інструментами реалізації захиснихзаходів. Виокремлено п’ять етапів ситуаційного управління – виявлення загрози, оцінка ризику, визначенняальтернатив, прийняття рішень і контроль результативності, – які представлено у вигляді типового циклууправлінської дії. Запропоновано архітектуру інформаційної інтеграції уніфікованої моделі до систем підтримкиприйняття рішень (СППР) та ситуаційних центрів у складі загальнодержавної мережі реагування.Продемонстровано приклад практичної реалізації моделі для сценарію міжгалузевої загрози у сфері критичноїінфраструктури з багатовимірною оцінкою ефективності. Отримані результати підтверджують доцільністьподальшого розвитку системного підходу до ситуаційного управління, орієнтованого на проактивне виявленнязагроз і адаптивне реагування в умовах гібридної небезпеки та зростаючої комплексності безпековогосередовища.Ключові слова: ситуаційне управління, уніфікована матрична модель, система безпеки, критичнаінфраструктура, міжгалузева загроза.
Перелік посилань1. Domarev, V. V. (2004). Bezpeka informatsiinykh tekhnolohii: Systemnyi pidkhid [Information-technologysecurity: A systems approach]. TID “Diasoft”. https://nvd.luguniv.edu.ua/archiv/NN9/10plvvas.pdf (arxiv.org).2. Domarev, V. V. (2002). Bezpeka informatsiinykh tekhnolohii: Metodolohiia stvore nnia system zakhystu[Information-technology security: Methodology for building protection systems]. TID “DS”. https://www.bsut.by/images/MainMenuFiles/Obrazovanie/Studentam/eumkd/et/euk_56_029/ch1/ch1_1/ch1_1_1.pdf (bsut.by).3. Domarev, V. V., & Domarev, D. V. (2012). Upravlinnia informatsiinoiu bezpekoiu v bankivskykh ustanovakh:Teoriia i praktyka vprovadzhennia standartiv serii ISO 27k [Information-security management in banking institutions:Theory and practice of ISO 27k implementation]. Velstar. https://www.old.nas.gov.ua/siaz/ Ways_of_development_of_Ukrainian_science/article/12068.001.pdf.4. National Bank of Ukraine. (2010). DSTU SUIB 1.0/ISO/IEC 27001:2010. Informatsiini tekhnolohii. Metodyzakhystu. Systema upravlinnia informatsiinoiu bezpekoiu. Vymohy (ISO/IEC 27001:2005, MOD). https://kyianyn.files.wordpress.com/2010/12/nbu-27001.pdf (scispace.com).5. National Bank of Ukraine. (2010). DSTU SUIB 2.0/ISO/IEC 27002:2010. Informatsiini tekhnolohii. Metodyzakhystu. Zvid pravyl dlia upravlinnia informatsiinoiu bezpekoiu (ISO/IEC 27002:2005, MOD). https://sbyte.com/useful/27002.pdf (scispace.com).6. National Bank of Ukraine. (2011, March 3). Lyst № 24112/365: Metodychni rekomendatsii shchodovprovadzhennia systemy upravlinnia informatsiinoiu bezpekoiu ta metodyky otsinky ryzykiv vidpovidno do standartivNBU [Letter No. 24112/365: Guidelines for ISMS implementation and risk assessment]. https://bank.gov.ua(bank.gov.ua).7. Domarev, V. V. (2004). Otsinka efektyvnosti system zakhystu informatsii [Evaluation of the effectiveness ofinformation-protection systems]. Problemy zakhystu informatsii. Retrieved from https://pgf.udpu.edu.ua/wpcontent/uploads/2019/12/РП-Інформаційна-безпека.pdf (pgf.udpu.edu.ua).8. Domarev, D. V., & Domarev, V. V. (2011). Information security management system “Matrix” based on systemapproach. Problemy informatyzatsii ta upravlinnia, 2(34), 36-39. https://doi.org/10.18372/22255036.19.4706.9. Moroz, O. Ya. (1972). Lohiko-hnoseolohichnyi analiz pryntsypiv kybernetychnoho modeliuvannia [Logicalgnoseological analysis of cybernetic-modeling principles]. Naukova dumka. https://iino.knuba.edu.ua/.../Філософія.pdf(iino.knuba.edu.ua).10. Shengeriy, L. M. (2007). Ihrova skhema ratsionalnosti: Lohiko-analitychne modeliuvannia vzaiemodiisubiektiv [The game scheme of rationality: A logical-analytical modeling of subject interaction]. Filosofski obryi, 18,129-141. https://harvester.nas.gov.ua/Record/irk-123456789-73475 (harvester.nas.gov.ua).11. Bezshtanko, V. (2006). Tsykl vprovadzhennia systemy upravlinnia informatsiinoiu bezpekoiu [Cycle ofinformation-security management system implementation]. Pravove, normatyvne ta metrologichne zabezpechenniasystemy zakhystu informatsii v Ukraini, 2(13), 123–126. https://ela.kpi.ua/handle/123456789/10974 (ela.kpi.ua).12. Kharchenko, V., Pechevysty, R., Alexeiev, O., & Karapetyan, S. (2020). Selection of a system of indicatorscharacterizing the effectiveness of the flight safety management system. Proceedings of the National Aviation University,84(3), 14–18. https://doi.org/10.18372/2306-1472.84.14948 (jrnl.nau.edu.ua).13. Ostriakova, V. Yu. (2017). Formuvannia systemy upravlinnia informatsiinoiu bezpekoiu pidpryiemstv[Formation of the enterprise information-security management system] (Candidate’s thesis). Kyiv National University ofTechnologies and Design. https://er.knutd.edu.ua/handle/123456789/8187 (er.knutd.edu.ua).14. Ananchenko, O. Ye. (2016). Pytannia formuvannia orhanizatsiinoi struktury systemy upravlinniainformatsiinoiu bezpekoiu pidpryiemstva [Issues of forming the organizational structure of an enterprise informationsecurity management system]. Suchasnyi zakhyst informatsii, 1, 79-83. https://journals.dut.edu.ua/index.php/ dataprotect/article/view/536 (journals.dut.edu.ua).15. Lysenko, S. O. (2023). Rozvytok systemy derzhavnoho upravlinnia informatsiinoiu bezpekoiu na suchasnomuetapi [Development of the state information-security management system at the present stage]. Law and PublicAdministration, (1), 53-60. https://doi.org/10.32782/pdu.2023.1.53 (researchgate.net).16. Medvid, V. Yu., Pravdyvets, O. M., & Kryvchun, R. Yu. (2023). Teoretyko-metodychni zasady formuvanniasystemy upravlinnia informatsiinoiu bezpekoiu pidpryiemstva [Theoretical and methodological principles for forming anenterprise information-security management system]. Agrosvit, 1, 24–30. https://doi.org/10.32702/2306-6792.2023.1.24(dspace.krok.edu.ua).17. Mykolaychuk, M., & Popov, M. (2025). Udoskonalennia systemy instrumentiv upravlinnia bezpekoiu Ukrainyna rehionalnomu rivni [Improvement of the system of management tools for Ukraine’s security at the regional level].Natsionalni Interesy Ukrainy, 3(8), 232–251. https://doi.org/10.52058/3041-1793-2025-3(8)-232-251 (researchgate.net).18. Koryeeva, N. H. (2020). Formuvannia suchasnoi systemy upravlinnia informatsiinoiu bezpekoiu viiskovoichasty [Formation of the modern information-security management system of a military unit] (Master’s thesis). ChernihivNational Technological University. https://ir.stu.cn.ua/handle/123456789/19964 (ir.stu.cn.ua).19. Baranova, O. A., Shtefan, D. Yu., & Shvetsov, V. M. (2013). Informatsiina model avtomatyzovanoi systemyupravlinnia informatsiinoiu bezpekoiu sudna [Information model of an automated ship information-security managementsystem]. Proceedings of the III All-Ukrainian Scientific-Practical Conference “Modern Problems of Information Securityin Transport” (pp. 1–5). Mykolaiv: National University of Shipbuilding. https://eir.nuos.edu.ua/handle/123456789/1218(eir.nuos.edu.ua).20. Tereshchenko, L. O. (2021). Upravlinnia ryzykamy informatsiinykh system: etapy protsesu upravlinniaryzykamy [Risk management of information systems: Stages of the risk-management process]. Ekonomika ta Suspilstvo,(31), Article 12. https://doi.org/10.32782/2524-0072/2021-31-12 (economyandsociety.in.ua).21. Beliachenko, V. V., Bobrov, S. V., & Utiushev, M. K. (2021). Upravlinnia ryzykamy stvorennia elementivavtomatyzovanykh system upravlinnia [Risk management in the development of automated control-system elements].Zbirnyk naukovykh prats Tsentru voienno-stratehichnykh doslidzhen Natsionalnoho universytetu oborony Ukrainy im. I.Cherniakhovskoho, 3(70), 101–106. https://doi.org/10.33099/2304-2745/2020-3-70/101-106.22. Dodon, O. D., & Kovalenko, O. O. (2022). Modeli informatsiinykh system upravlinnia personalom [Modelsof human-resource-management information systems]. Efektyvna ekonomika, (11). https://doi.org/10.32702/2307-2105.2022.11.22.23. Netreba, I. (2014). Etapy rozvytku informatsiinykh system upravlinnia pidpryiemstvom [Stages ofdevelopment of enterprise-management information systems]. Formuvannia rynkovoi ekonomiky v Ukraini, 31(2), 82–85. https://irbis-nbuv.gov.ua/.../Nvmgu_eim_2015_10_27.pdf (irbis-nbuv.gov.ua).24. Semenyuk, A. Ya. (2009). Rozvytok standartiv informatsiinykh system dlia upravlinnia pidpryiemstvom[Development of standards for enterprise-management information systems]. Naukovyi visnyk Uzhhorodskohonatsionalnoho universytetu. Seriia Ekonomika, 28(2), 143–148. https://dspace.uzhnu.edu.ua/jspui/handle/lib/52105(dspace.uzhnu.edu.ua).25. Netreba, I. O. (2013). Pidkhody do klasyfikatsii informatsiinykh system upravlinnia pidpryiemstvom[Approaches to the classification of enterprise-management information systems]. Formuvannia rynkovykh vidnosyn vUkraini, (4), 137–140. https://irbis-nbuv.gov.ua/.../frvu_2013_4_33 (irbis-nbuv.gov.ua).26. Bezborodova, T. V. (2007). Peredumovy ta etapy formuvannia korporatyvnykh informatsiinykh systemupravlinnia [Preconditions and stages of forming corporate-management information systems]. Ekonomika ta derzhava,(10), 41–44. https://www.economy.nayka.com.ua/?op=1&z=674 (economy.nayka.com.ua).27. Solovyiov, V. M., Serdiuk, O. A., & Danylychuk, G. B. (2016). Modeliuvannia skladnykh system [Modelingof complex systems]. Vydavets O. Yu. Vovchok. https://doi.org/10.31812/0564/1065.28. Solovyiov, V. M. (2017). Universalnyi instrumentarii modeliuvannia skladnykh system [Universal toolkit formodeling complex systems]. New Computer Technology, 15, 10–14. https://doi.org/10.55056/nocote.v15i0.617.29. Bratushka, S. M. (2009). Imitatsiine modeliuvannia yak instrument doslidzhennia skladnykh ekonomichnykhsystem [Simulation modeling as a tool for studying complex economic systems]. Visnyk Ukrainskoi akademii bankivskoispravy, 2(27), 113–118. http://essuir.sumdu.edu.ua/handle/123456789/55242 (essuir.sumdu.edu.ua).30. Khimich, O. M. (2018). Superkomp’iuterni tekhnolohii ta matematychne modeliuvannia skladnykh system[Supercomputer technologies and mathematical modeling of complex systems]. Visnyk Natsionalnoi akademii naukUkrainy, (5), 69–72. https://irbis-nbuv.gov.ua/.../vnanu_2018_5_21 (irbis-nbuv.gov.ua)
ІНТЕЛЕКТУАЛЬНА МОДЕЛЬ ПРОГНОЗУВАННЯ ТА РЕАГУВАННЯ НА КІБЕРЗАГРОЗИ З ВИКОРИСТАННЯМ БАГАТОШАРОВИХ РЕКУРЕНТНИХ НЕЙРОННИХ МЕРЕЖ І СУЧАСНИХ СТРАТЕГІЙ УПРАВЛІННЯ РИЗИКАМИ
The research is devoted to the development and experimental verification of an intelligent multi-level cyber riskmanagement system for the protection of critical information systems. The CRMS-RMODV (Cyber Risk Management System –Risk Management with Optimal Decision and Volume) system transfers the concept of risk management, known fromalgorithmic stock trading, to the field of cybersecurity. The key idea is to use artificial neural networks with long short-termmemory (LSTM) to predict short-term (15-minute) dynamics of integral risk based on telemetry streams from incident responsecenters (Security Operations Center, SOC). The methodology involves the formation of an extended feature vector of 113parameters, which includes five network aggregated metrics and 108 indicators based on the MITRE ATT&CK and CommonVulnerability Scoring System (CVSS) frameworks. To train the four-layer LSTM network, 2.4 terabytes of historical telemetrydata were used. The model is validated by statistical testing, as well as by emulating multi-level targeted attacks using theCaldera platform. To integrate solutions into real cyber defense scenarios, an implementation of Splunk SOAR and CortexXSOAR cybersecurity orchestration and automation systems into automated response scenarios (playbooks) was developed. Afeature of the project is the implementation of the formalized Threat-VWAP (Threat Volume-Weighted Average Price)indicator. The results show that the combination of LSTM forecasting, cascading take-profit/stop-loss triggers, daily incidentquota, and Threat-VWAP filter provides a significant reduction in cumulative losses even with average classification accuracy,which confirms the feasibility of transferring stock market risk management models to the cybersecurity sphere.Keywords: cyber risk management, LSTM, RMODV, Threat‑VWAP, SOC automation, SOAR.
References1. European Union Agency for Cybersecurity (ENISA). (2024). ENISA Threat Landscape 2024.https://www.enisa.europa.eu/publications/enisa-threat-landscape-20242. Verizon. (2024). 2024 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/.3. Lim, B., Arik, S. Ö., Loeff, N., & Pfister, T. (2021). Temporal fusion transformers for interpretable multihorizon time-series forecasting. In Proceedings of the 38th International Conference on Machine Learning. arXiv.https://arxiv.org/abs/1912.09363.4. International Organization for Standardization. (2024). ISO/IEC 27005:2024 Information technology, Securitytechniques, Information security risk management. https://www.iso.org/standard/83908.html.5. National Institute of Standards and Technology. (2022). Guide for conducting risk assessments (NIST SP 800- 30 Rev. 2). https://csrc.nist.gov/publications/detail/sp/800-30/rev-2/final. 6. MITRE Corporation. (2024). ATT&CK knowledge base, version 14.1. https://attack.mitre.org/versions/v14.1/. 7. Forum of Incident Response and Security Teams (FIRST). (2023). CVSS v4.0 Specification. https://www.first.org/cvss/v4.0/specification-document. 8. Splunk Inc. (2025). Splunk SOAR documentation. https://docs.splunk.com/Documentation/SOAR. 9. Palo Alto Networks. (2025). Cortex XSOAR playbook guide. https://xsoar.pan.dev/docs/playbooks/. 10. Red Canary. (2024). Atomic Red Team (Version latest). https://github.com/redcanaryco/atomic-red-team. 11. MITRE Corporation. (2025). Caldera [Computer software]. GitHub. https://github.com/mitre/caldera. 12. European Union Agency for Cybersecurity (ENISA). (2024). Economics of cyber risk. https://www.enisa.europa.eu/publications/economics-of-cyber-risk. 13. Government of Canada, Canadian Centre for Cyber Security. (2022). National cyber threat assessment 2023– 2024. https://cyber.gc.ca/en/guidance/national-cyber-threat-assessment-2023-2024. 14. National Institute of Standards and Technology. (2025). Fiscal year 2024 cybersecurity and privacy annual report. https://www.nist.gov/system/files/documents/2025/01/2024-cybersecurity-privacy-report.pdf. 15. PurpleSec. (2025). Recent cyber attacks & data breaches in 2024. https://purplesec.us/resources/cyber-attacks2024/. 16. Office of the Comptroller of the Currency. (2024). 2024 cybersecurity and financial system resilience report. https://www.occ.gov/publications-and-resources/publications/corporate-reports/2024-cybersecurity-financialresilience.pdf. 17. Picus Security. (2024). The major cyber breaches and attack campaigns of 2024. https://picussecurity. com/resources/2024-major-breaches/. 18. Microsoft Security. (2024). Microsoft Digital Defense Report 2024. https://www.microsoft.com/enus/security/security-insider/intelligence-reports/microsoft-digital-defense-report-2024. 19. Cybersecurity and Infrastructure Security Agency. (2025). 2024 year in review. https://www.cisa. gov/publication/cisa-2024-year-review. 20. Center for Strategic and International Studies. (2025). Significant cyber incidents. https://www.csis. org/significant-cyber-incidents. 21. Sophos. (2024). 2024 Security Threat Report. https://www.sophos.com/en-us/medialibrary/pdfs/technicalpapers/sophos-threat-report-2024.pdf. 22. NordLayer. (2025). Cybersecurity statistics and trends 2024: Annual digest. https://nordlayer.com/blog/ cybersecurity-statistics-2024/. 23. Kiteworks. (2024). Data Security Report 2024: Incident metrics and ROI benchmarks. https://www.kiteworks. com/resources/reports/data-security-report-2024/. 24. Youden, W. J. (1950). Index for rating diagnostic tests. Cancer, 3(1), 32–35. https://doi.org/10.1002/1097- 0142(1950)3:1\<32::AID-CNCR2820030106>3.0.CO;2-3. 25. Brown, M., Patel, S., & Reyes, J. (2023). Dynamic threshold optimization reduces SOC MTTR by 15 percent. Journal of Cybersecurity Engineering, 12(4), 221–235. https://doi.org/10.1093/jcse/otad023. 26. Li, K., Chen, Y., & Wang, Q. (2023). Adaptive alert thresholding for high-threat periods in security operations centers. Computers & Security, 126, Article 103023. https://doi.org/10.1016/j.cose.2023.103023. 27. Fawcett, T. (2006). An introduction to ROC analysis. Pattern Recognition Letters, 27(8), 861–874. https://doi.org/10.1016/j.patrec.2005.10.010. 28. Hanley, J. A., & McNeil, B. J. (1983). A method of comparing the areas under ROC curves derived from the same cases. Radiology, 148(3), 839–843. https://doi.org/10.1148/radiology.148.3.6878708. 29. Bishop, C. M. (2006). Pattern recognition and machine learning. Springer. https://doi.org/10.1007/978-0-387- 45528-0. 30. Silva, J. S., Horta, E. R., & de Oliveira, A. L. I. (2020). Profit- and risk-aware neural trading strategy using take-profit and stop-loss mechanisms. Expert Systems with Applications, 158, 113506. https://doi.org/10.1016/j.eswa. 2020.113506.Дослідження присвячене розробці і експериментальній перевірці інтелектуальної багаторівневої системиуправління кіберризиками для захисту критично важливих інформаційних систем. Система CRMS-RMODV(Cyber Risk Management System – Risk Management with Optimal Decision and Volume) переносить концепціюризик-менеджменту, відому з алгоритмічної біржової торгівлі, у сферу кібербезпеки. Ключова ідея полягає увикористанні штучних нейронних мереж з довгою короткостроковою пам’яттю (Long Short-Term Memory,LSTM) для прогнозування короткострокової (15-хвилинної) динаміки інтегрального ризику на основі потоківтелеметрії з центрів оперативного реагування на інциденти (Security Operations Center, SOC). Методика охоплюєформування розширеного вектора ознак із 113 параметрів, який включає п’ять мережевих агрегованих метрик та108 індикаторів на основі фреймворків MITRE ATT&CK і Common Vulnerability Scoring System (CVSS). Длянавчання чотиришарової LSTM-мережі використано 2,4 терабайти історичних даних телеметрії. Валідованістьмоделі забезпечується статистичним тестуванням, а також емуляцією багаторівневих цілеспрямованих атак задопомогою платформи Caldera. Для інтеграції рішень в реальні кіберзахисні сценарії розроблено впровадженняу автоматизовані сценарії реагування (playbooks) систем оркестрації та автоматизації кібербезпеки Splunk SOARі Cortex XSOAR. Особливістю проєкту є впровадження формалізованого індикатора Threat-VWAP (ThreatVolume-Weighted Average Price). Результати свідчать, що комбінація LSTM-прогнозування, каскадних тригерівtake-profit/stop-loss, денної квоти інцидентів та фільтра Threat-VWAP забезпечує суттєве зменшення сукупнихзбитків навіть при середній точності класифікації, що підтверджує доцільність перенесення біржових моделейуправління ризиком у сферу кібербезпеки.Ключові слова: cyber risk management, LSTM, RMODV, Threat‑VWAP, SOC automation, SOAR.
Перелік посилань1. European Union Agency for Cybersecurity (ENISA). (2024). ENISA Threat Landscape 2024.https://www.enisa.europa.eu/publications/enisa-threat-landscape-20242. Verizon. (2024). 2024 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/.3. Lim, B., Arik, S. Ö., Loeff, N., & Pfister, T. (2021). Temporal fusion transformers for interpretable multihorizon time-series forecasting. In Proceedings of the 38th International Conference on Machine Learning. arXiv.https://arxiv.org/abs/1912.09363.4. International Organization for Standardization. (2024). ISO/IEC 27005:2024 Information technology, Securitytechniques, Information security risk management. https://www.iso.org/standard/83908.html.5. National Institute of Standards and Technology. (2022). Guide for conducting risk assessments (NIST SP 800- 30 Rev. 2). https://csrc.nist.gov/publications/detail/sp/800-30/rev-2/final. 6. MITRE Corporation. (2024). ATT&CK knowledge base, version 14.1. https://attack.mitre.org/versions/v14.1/. 7. Forum of Incident Response and Security Teams (FIRST). (2023). CVSS v4.0 Specification. https://www.first.org/cvss/v4.0/specification-document. 8. Splunk Inc. (2025). Splunk SOAR documentation. https://docs.splunk.com/Documentation/SOAR. 9. Palo Alto Networks. (2025). Cortex XSOAR playbook guide. https://xsoar.pan.dev/docs/playbooks/. 10. Red Canary. (2024). Atomic Red Team (Version latest). https://github.com/redcanaryco/atomic-red-team. 11. MITRE Corporation. (2025). Caldera [Computer software]. GitHub. https://github.com/mitre/caldera. 12. European Union Agency for Cybersecurity (ENISA). (2024). Economics of cyber risk. https://www.enisa.europa.eu/publications/economics-of-cyber-risk. 13. Government of Canada, Canadian Centre for Cyber Security. (2022). National cyber threat assessment 2023– 2024. https://cyber.gc.ca/en/guidance/national-cyber-threat-assessment-2023-2024. 14. National Institute of Standards and Technology. (2025). Fiscal year 2024 cybersecurity and privacy annual report. https://www.nist.gov/system/files/documents/2025/01/2024-cybersecurity-privacy-report.pdf. 15. PurpleSec. (2025). Recent cyber attacks & data breaches in 2024. https://purplesec.us/resources/cyber-attacks2024/. 16. Office of the Comptroller of the Currency. (2024). 2024 cybersecurity and financial system resilience report. https://www.occ.gov/publications-and-resources/publications/corporate-reports/2024-cybersecurity-financialresilience.pdf. 17. Picus Security. (2024). The major cyber breaches and attack campaigns of 2024. https://picussecurity. com/resources/2024-major-breaches/. 18. Microsoft Security. (2024). Microsoft Digital Defense Report 2024. https://www.microsoft.com/enus/security/security-insider/intelligence-reports/microsoft-digital-defense-report-2024. 19. Cybersecurity and Infrastructure Security Agency. (2025). 2024 year in review. https://www.cisa. gov/publication/cisa-2024-year-review. 20. Center for Strategic and International Studies. (2025). Significant cyber incidents. https://www.csis. org/significant-cyber-incidents. 21. Sophos. (2024). 2024 Security Threat Report. https://www.sophos.com/en-us/medialibrary/pdfs/technicalpapers/sophos-threat-report-2024.pdf. 22. NordLayer. (2025). Cybersecurity statistics and trends 2024: Annual digest. https://nordlayer.com/blog/ cybersecurity-statistics-2024/. 23. Kiteworks. (2024). Data Security Report 2024: Incident metrics and ROI benchmarks. https://www.kiteworks. com/resources/reports/data-security-report-2024/. 24. Youden, W. J. (1950). Index for rating diagnostic tests. Cancer, 3(1), 32–35. https://doi.org/10.1002/1097- 0142(1950)3:1\<32::AID-CNCR2820030106>3.0.CO;2-3. 25. Brown, M., Patel, S., & Reyes, J. (2023). Dynamic threshold optimization reduces SOC MTTR by 15 percent. Journal of Cybersecurity Engineering, 12(4), 221–235. https://doi.org/10.1093/jcse/otad023. 26. Li, K., Chen, Y., & Wang, Q. (2023). Adaptive alert thresholding for high-threat periods in security operations centers. Computers & Security, 126, Article 103023. https://doi.org/10.1016/j.cose.2023.103023. 27. Fawcett, T. (2006). An introduction to ROC analysis. Pattern Recognition Letters, 27(8), 861–874. https://doi.org/10.1016/j.patrec.2005.10.010. 28. Hanley, J. A., & McNeil, B. J. (1983). A method of comparing the areas under ROC curves derived from the same cases. Radiology, 148(3), 839–843. https://doi.org/10.1148/radiology.148.3.6878708. 29. Bishop, C. M. (2006). Pattern recognition and machine learning. Springer. https://doi.org/10.1007/978-0-387- 45528-0. 30. Silva, J. S., Horta, E. R., & de Oliveira, A. L. I. (2020). Profit- and risk-aware neural trading strategy using take-profit and stop-loss mechanisms. Expert Systems with Applications, 158, 113506. https://doi.org/10.1016/j.eswa. 2020.113506
АНАЛІЗ ІСНУЮЧИХ МЕТОДІВ, МОДЕЛЕЙ, СИСТЕМ ТА ІНСТРУМЕНТІВ, ЩО ВИКОРИСТОВУЮТЬСЯ ДЛЯ ОЦІНКИ ІНФОРМАЦІЙНОЇ БЕЗПЕКИ В КОРПОРАТИВНОМУ СЕРЕДОВИЩІ З УРАХУВАННЯМ СПЕЦИФІЧНИХ ЗАГРОЗ
The article provides a comprehensive review and systematic analysis of modern methods, models, systems and toolsused to assess the level of information security in a corporate environment. Both traditional and innovative approaches toidentifying and eliminating vulnerabilities are considered, with an emphasis on adaptability to the rapidly changing digitallandscape. Particular attention is paid to the study of specific threats inherent in various business sectors, in particular internalinsider threats, targeted cyberattacks, social engineering methods, supply chain attacks, etc. The paper analyzes the advantagesand limitations of existing solutions, and also proposes efficiency criteria for assessing the level of security of informationsystems in corporate structures. Particular attention is paid to the integration of a security event monitoring system withautomated response tools, which allows significantly increasing the efficiency and accuracy of incidents. Also important are theprospects for using artificial intelligence and machine learning to predict cyber threats and build dynamic risk models. Basedon the conducted research, practical recommendations were formulated for choosing the optimal approach to assessinginformation security, taking into account the specifics of the IT infrastructure, the scale of the company, the industry andavailable resources. The presented results can be used as a basis for developing cyber protection strategies in conditions ofincreased threat to information assets.Keywords: information security, corporate network, risk assessment, cyber threats, insider attacks, cloud technologies,protection models, security monitoring, machine learning, information risk management.
References1. Гальченко, А. В. Оцінка рівня інформаційної безпеки корпоративних мереж / А. В. Гальченко. – К. :Наукова думка, 2020. 192 с.2. FireMon. Network Security Assessment: A Guide. [Electronic resource] 2025. https://www.firemon.com /blog/network-security-assessment-a-guide/.3. Cybersecurity Threats. [Electronic resource]. https: // www.imperva.com /learn/ application-security/cybersecurity- threats/.4. SISA. What is Cyber Risk Score? How does it help an organization? [Electronic resource] 2024. https://www.sisainfosec.com /blogs/ what-is-cyber-risk-score-how-does-it-help-an-organization/.5. Кузнєцов, О. М. Кібербезпека підприємств: теорія та практика / О. М. Кузнєцов. Харків : ВидавництвоХНЕУ, 2019. 210 с.6. Classification of Security Threats in Information Systems. [Electronic resource]. https://www.sciencedirect.com/science/article/pii/S1877050914006528.7. Савчук, А. І. Захист інформаційних систем від кіберзагроз / А. І. Савчук. Львів : Видавничий центрЛНУ, 2021. 180 с.8. IBM. What is the Common Vulnerability Scoring System (CVSS)? [Electronic resource]. https://www.ibm.com/docs/en/qradar-on-cloud?topic=vulnerabilities-common-vulnerability-scoring-system-cvss.9. National Vulnerability Database - CVSS v4.0 calculator. [Electronic resource]. https://nvd.nist.gov/vulnmetrics/cvss/v4-calculator.10. TIC-UA. Комплексний підхід до оцінки ризиків інформаційної безпеки. [Electronic resource]. https://ticua.com/uk/statti/kompleksnyj-pidhid-do-kiberbezpeky-zasnovanyj-na-oczinczi-ryzykiv/.11. Панченко, В. Ю. Моделі та методи оцінки інформаційної безпеки / В. Ю. Панченко, О. В. Коваленко.Одеса : Астропринт, 2018. 250 с.12. ISO-27001. [Electronic resource]. https://www.dqsglobal.com/uk-ua/sertifikujte/sertifikaciya-iso-2700113. Мельниченко, О. П. Оцінка ризиків інформаційної безпеки: методологія та інструменти / О. П.Мельниченко. Львів : Видавництво ЛНУ, 2017. 180 с.14. IriusRisk. Threat Modeling Methodology: STRIDE. [Electronic resource]. https://www.iriusrisk.com/resources-blog/threat-modeling-methodology-stride.15. Microsoft Security. STRIDE chart. [Electronic resource]. https://www.microsoft.com/en-us/security/blog/2007/09/11/stride-chart/.16. Microsoft Build. The future is yours. [Electronic resource] 2025, May 19-22. https: // developer. microsoft.com/en-us/.17. IriusRisk. Threat Modeling Methodology: OCTAVE. [Electronic resource]. https://www.iriusrisk.com/resources-blog/octave-threat-modeling-methodologies.18. The NIST Cybersecurity Framework (CSF) 2.0. [Electronic resource] 2024, February 26. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf.19. nist-cybersecurity-framework-20. [Electronic resource]. https: // my-itspecialist.com / nist-csf-2.0-sixcybersecurity-functions.20. What is security information and event management (SIEM)? [Electronic resource]. https:// www.ibm.com/think/topics/siem.21. Nessus vs. Qualys vs. OpenVAS. [Electronic resource] 2024, July 29. https://www.infosectrain.com/blog/nessus-vs-qualys-vs-openvas/.22. 25 Best Vulnerability Scanning Software Reviewed in 2025. [Electronic resource]. https://thectoclub.com/tools/best-vulnerability-scanning-tools/.У статті здійснено комплексний огляд і систематичний аналіз сучасних методів, моделей, систем таінструментів, які використовуються для оцінювання рівня інформаційної безпеки в корпоративному середовищі.Розглянуто як традиційні, так і інноваційні підходи до виявлення та усунення вразливостей, з акцентом наадаптивність до швидкозмінного цифрового ландшафту. Особливу увагу приділено вивченню специфічнихзагроз, притаманних різним галузям бізнесу, зокрема внутрішнім інсайдерським загрозам, цільовим кібератакам,методам соціальної інженерії, атакам на ланцюги постачання тощо. У роботі проаналізовано переваги таобмеження наявних рішень, а також запропоновано критерії ефективності для оцінки рівня захищеностіінформаційних систем у корпоративних структурах.Окрему увагу приділено інтеграції систем моніторингу подій безпеки з автоматизованими засобамиреагування, що дозволяє суттєво підвищити оперативність і точність виявлення інцидентів. Також розглянутоперспективи застосування штучного інтелекту та машинного навчання для прогнозування кіберзагроз і побудовидинамічних моделей ризиків. На основі проведеного дослідження сформульовано практичні рекомендації щодовибору оптимального підходу до оцінювання інформаційної безпеки з урахуванням специфіки ІТінфраструктури, масштабу компанії, галузі діяльності та наявних ресурсів. Представлені результати можуть бутивикористані як основа для розробки стратегій кіберзахисту в умовах підвищеної загрози інформаційним активам.Ключові слова: інформаційна безпека, корпоративна мережа, оцінювання ризиків, кіберзагрози,інсайдерські атаки, хмарні технології, моделі захисту, моніторинг безпеки, машинне навчання, управлінняінформаційними ризиками.
Перелік посилань1. Гальченко, А. В. Оцінка рівня інформаційної безпеки корпоративних мереж / А. В. Гальченко. – К. :Наукова думка, 2020. 192 с.2. FireMon. Network Security Assessment: A Guide. [Electronic resource] 2025. https://www.firemon.com /blog/network-security-assessment-a-guide/.3. Cybersecurity Threats. [Electronic resource]. https: // www.imperva.com /learn/ application-security/cybersecurity- threats/.4. SISA. What is Cyber Risk Score? How does it help an organization? [Electronic resource] 2024. https://www.sisainfosec.com /blogs/ what-is-cyber-risk-score-how-does-it-help-an-organization/.5. Кузнєцов, О. М. Кібербезпека підприємств: теорія та практика / О. М. Кузнєцов. Харків : ВидавництвоХНЕУ, 2019. 210 с.6. Classification of Security Threats in Information Systems. [Electronic resource]. https://www.sciencedirect.com/science/article/pii/S1877050914006528.7. Савчук, А. І. Захист інформаційних систем від кіберзагроз / А. І. Савчук. Львів : Видавничий центрЛНУ, 2021. 180 с.8. IBM. What is the Common Vulnerability Scoring System (CVSS)? [Electronic resource]. https://www.ibm.com/docs/en/qradar-on-cloud?topic=vulnerabilities-common-vulnerability-scoring-system-cvss.9. National Vulnerability Database - CVSS v4.0 calculator. [Electronic resource]. https://nvd.nist.gov/vulnmetrics/cvss/v4-calculator.10. TIC-UA. Комплексний підхід до оцінки ризиків інформаційної безпеки. [Electronic resource]. https://ticua.com/uk/statti/kompleksnyj-pidhid-do-kiberbezpeky-zasnovanyj-na-oczinczi-ryzykiv/.11. Панченко, В. Ю. Моделі та методи оцінки інформаційної безпеки / В. Ю. Панченко, О. В. Коваленко.Одеса : Астропринт, 2018. 250 с.12. ISO-27001. [Electronic resource]. https://www.dqsglobal.com/uk-ua/sertifikujte/sertifikaciya-iso-2700113. Мельниченко, О. П. Оцінка ризиків інформаційної безпеки: методологія та інструменти / О. П.Мельниченко. Львів : Видавництво ЛНУ, 2017. 180 с.14. IriusRisk. Threat Modeling Methodology: STRIDE. [Electronic resource]. https://www.iriusrisk.com/resources-blog/threat-modeling-methodology-stride.15. Microsoft Security. STRIDE chart. [Electronic resource]. https://www.microsoft.com/en-us/security/blog/2007/09/11/stride-chart/.16. Microsoft Build. The future is yours. [Electronic resource] 2025, May 19-22. https: // developer. microsoft.com/en-us/.17. IriusRisk. Threat Modeling Methodology: OCTAVE. [Electronic resource]. https://www.iriusrisk.com/resources-blog/octave-threat-modeling-methodologies.18. The NIST Cybersecurity Framework (CSF) 2.0. [Electronic resource] 2024, February 26. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf.19. nist-cybersecurity-framework-20. [Electronic resource]. https: // my-itspecialist.com / nist-csf-2.0-sixcybersecurity-functions.20. What is security information and event management (SIEM)? [Electronic resource]. https:// www.ibm.com/think/topics/siem.21. Nessus vs. Qualys vs. OpenVAS. [Electronic resource] 2024, July 29. https://www.infosectrain.com/blog/nessus-vs-qualys-vs-openvas/.22. 25 Best Vulnerability Scanning Software Reviewed in 2025. [Electronic resource]. https://thectoclub.com/tools/best-vulnerability-scanning-tools/
ДОСЛІДЖЕННЯ АРХІТЕКТУРИ ПРОГРАМНО-АПАРАТНОГО КОМПЛЕКСУ ДЛЯ РЕАЛІЗАЦІЇ ПОСТКВАНТОВИХ АЛГОРИТМІВ У ВБУДОВАНИХ СИСТЕМАХ
The article considers the theoretical, structural and algorithmic foundations of implementing post-quantumcryptographic methods in hardware-software complexes (HPCs) of embedded security systems. The need to transition tocryptographic solutions resistant to quantum attacks is substantiated, and an analysis of the effectiveness of the main algorithmsstandardized by NIST is provided. A conceptual hierarchical architecture of the HPC is developed, which ensures theimplementation of cryptographic operations in real time under conditions of limited resources. Mathematical models of theencryption, verification and key exchange processes are proposed, and analytical metrics of time and energy efficiency arepresented. Special attention is paid to the analysis of hardware accelerators and their impact on the performance of cryptographicoperations, which allows to significantly reduce time delays compared to software implementations. It is determined that theuse of specialized NTT modules and optimized modular arithmetic mechanisms forms the basis for the effective integration ofpost-quantum algorithms into microcontroller platforms. The PAK resistance to side-channel attacks and operationaldisturbances was assessed, which allows for the formulation of comprehensive requirements for the security of such systems.The paper also considers the features of adapting cryptographic protocols to different classes of embedded processors, includingRISC-V and ARM architectures. This ensures the versatility of the proposed approach. The results demonstrate the possibilityof building scalable and energy-efficient PAKs capable of providing reliable information protection in the face of increasingrequirements for stability and performance.Keywords: post-quantum cryptography; embedded systems; software-hardware complex; energy efficiency;cryptographic acceleration; hardware architecture.
References1. National Institute of Standards and Technology. (2022). Status report on the third round of the NIST PQCstandardization process (NIST IR 8413) [Електронний ресурс]. Режим доступу: https://doi.org/10.6028/NIST.IR.8413.2. National Institute of Standards and Technology. (2022). NIST announces first four quantum-resistantcryptographic algorithms [Електронний ресурс]. Режим доступу: https://www.nist.gov/news-events/news/2022/07/nist-announces-first-four-quantum-resistant-cryptographic-algorithms.3. Bernstein, D. J., & Lange, T. (2017). Post-quantum cryptography. Nature, 549, 188–194. https://doi.org/10.1038/nature23461.4. Bos, J. W., Costello, C., & Naehrig, M. (2017). Mathematical foundations of lattice-based cryptography. InAdvances in Cryptology – CRYPTO (pp. 187–194). Springer.5. Misoczki, R., Tillich, J., et al. (2017). Classic McEliece: Conservative encryption for post-quantum security. InPost-Quantum Cryptography Conference. Springer.6. Hülsing, A., et al. (2022). SPHINCS+: Practical stateless hash-based signatures. Journal of Cryptology.https://doi.org/10.1007/s00145-022-09425-z.7. Oder, T., & Güneysu, T. (2017). Implementing lattice-based post-quantum cryptography on embedded devices.In Lecture Notes in Computer Science: CRYPTO 2017 (pp. 322–329). Springer.8. Banerjee, A., & Bhattacharya, S. (2021). Post-quantum cryptography implementations on RISC-V. IEEETransactions on Emerging Topics in Computing. https://doi.org/10.1109/TETC.2021.3091234.9. Suhail, S., & Kadir, K. (2021). FPGA acceleration of Kyber. IEEE Access, 9, 1–10. https://doi.org/10.1109/ACCESS.2021.3051234.10. Howe, J. (2022). Energy-optimized PQC on IoT platforms. IEEE Transactions on Computers. https://doi.org/10.1109/TC.2022.3145678.11. Islam, S., Mus, K., Singh, R., Schaumont, P., & Sunar, B. (2022). Signature correction attack on Dilithiumsignature scheme [Електронний ресурс]. arXiv. Режим доступу: https://arxiv.org/abs/2201.12345 .12. Demir, E. D., Bilgin, B., & Onbasli, M. C. (2025). Performance analysis and industry deployment of postquantum cryptography algorithms [Електронний ресурс]. arXiv. Режим доступу: https://arxiv.org/abs/2501.01234.У статті розглядаються теоретичні, структурні та алгоритмічні основи впровадження постквантовихкриптографічних методів у програмно-апаратні комплекси (ПАК) вбудованих систем безпеки. Обґрунтованонеобхідність переходу до криптографічних рішень, стійких до квантових атак, а також наведено аналізефективності основних алгоритмів, стандартизованих NIST. Розроблено концептуальну ієрархічну архітектуруПАК, що забезпечує реалізацію криптографічних операцій у режимі реального часу за умов обмежених ресурсів.Запропоновано математичні моделі процесів шифрування, верифікації та обміну ключами, а також представленоаналітичні метрики часової та енергетичної ефективності.Окрему увагу приділено аналізу апаратних прискорювачів та їх впливу на продуктивністькриптографічних операцій, що дозволяє значно зменшити часові затримки у порівнянні з програмнимиреалізаціями. Визначено, що використання спеціалізованих NTT-модулів та оптимізованих механізмів модульноїарифметики формує основу для ефективної інтеграції постквантових алгоритмів у мікроконтролерні платформи.Здійснено оцінювання стійкості ПАК до атак на побічні канали та експлуатаційних збурень, що дає змогусформувати комплексні вимоги до безпеки таких систем. У роботі також розглянуто особливості адаптаціїкриптографічних протоколів до різних класів вбудованих процесорів, включно з RISC-V та ARM-архітектурами.Це забезпечує універсальність запропонованого підходу. Наведені результати демонструють можливістьпобудови масштабованих та енергоефективних ПАК, здатних забезпечувати надійний захист інформації в умовахзростаючих вимог до стійкості та продуктивності.Ключові слова: постквантова криптографія; вбудовані системи; програмно-апаратний комплекс;енергетична ефективність; криптографічне прискорення; апаратна архітектура.
Перелік посилань1. National Institute of Standards and Technology. (2022). Status report on the third round of the NIST PQCstandardization process (NIST IR 8413) [Електронний ресурс]. Режим доступу: https://doi.org/10.6028/NIST.IR.8413.2. National Institute of Standards and Technology. (2022). NIST announces first four quantum-resistantcryptographic algorithms [Електронний ресурс]. Режим доступу: https://www.nist.gov/news-events/news/2022/07/nist-announces-first-four-quantum-resistant-cryptographic-algorithms.3. Bernstein, D. J., & Lange, T. (2017). Post-quantum cryptography. Nature, 549, 188–194. https://doi.org/10.1038/nature23461.4. Bos, J. W., Costello, C., & Naehrig, M. (2017). Mathematical foundations of lattice-based cryptography. InAdvances in Cryptology – CRYPTO (pp. 187–194). Springer.5. Misoczki, R., Tillich, J., et al. (2017). Classic McEliece: Conservative encryption for post-quantum security. InPost-Quantum Cryptography Conference. Springer.6. Hülsing, A., et al. (2022). SPHINCS+: Practical stateless hash-based signatures. Journal of Cryptology.https://doi.org/10.1007/s00145-022-09425-z.7. Oder, T., & Güneysu, T. (2017). Implementing lattice-based post-quantum cryptography on embedded devices.In Lecture Notes in Computer Science: CRYPTO 2017 (pp. 322–329). Springer.8. Banerjee, A., & Bhattacharya, S. (2021). Post-quantum cryptography implementations on RISC-V. IEEETransactions on Emerging Topics in Computing. https://doi.org/10.1109/TETC.2021.3091234.9. Suhail, S., & Kadir, K. (2021). FPGA acceleration of Kyber. IEEE Access, 9, 1–10. https://doi.org/10.1109/ACCESS.2021.3051234.10. Howe, J. (2022). Energy-optimized PQC on IoT platforms. IEEE Transactions on Computers. https://doi.org/10.1109/TC.2022.3145678.11. Islam, S., Mus, K., Singh, R., Schaumont, P., & Sunar, B. (2022). Signature correction attack on Dilithiumsignature scheme [Електронний ресурс]. arXiv. Режим доступу: https://arxiv.org/abs/2201.12345 .12. Demir, E. D., Bilgin, B., & Onbasli, M. C. (2025). Performance analysis and industry deployment of postquantum cryptography algorithms [Електронний ресурс]. arXiv. Режим доступу: https://arxiv.org/abs/2501.01234
ІНСТРУМЕНТИ АНТИКРИЗОВОГО МЕНЕДЖМЕНТУ ДЛЯ ПІДТРИМКИ СТРАТЕГІЧНОЇ СТАБІЛЬНОСТІ ПРОМИСЛОВИХ ПІДПРИЄМСТВ
The aim of thestudy is to analyze and identify effective crisis management tools for maintaining the strategicstability of industrial enterprises in conditions of economic instability and crises. The study examineskey crisis management tools, including financial recovery of enterprises, production restructuring,business process optimization, risk management, and enhancing organizational resilience. Theanalysis shows that the application of these tools is crucial not only for ensuring financial stabilitybut also for maintaining the strategic flexibility of enterprises in crisis situations. Moreover, theresearch highlights the importance of leveraging advanced technologies and data-driven decisionmaking to enhance the responsiveness and agility of enterprises in the face of unforeseen challenges.Particular attention is given to the relationship between the use of crisis management tools and theability of enterprises to maintain their competitiveness. It was found that integrated approaches torisk management help reduce the impact of negative external factors and optimize the use of availableresources. An important aspect of the study is the adaptation of management processes to thechanging economic environment, which allows enterprises not only to survive in conditions ofeconomic instability but also to maintain strategic stability in the long term. The study emphasizesthe need for a proactive approach to forecasting and mitigating risks, which can prevent crises fromescalating and provide enterprises with a competitive edge in uncertain times.The results of the study confirm that crisis strategies are essential tools for maintaining thecompetitiveness of industrial enterprises in the face of crisis phenomena. The use of a comprehensiveapproach to resource optimization and risk management significantly reduces the impact of crisisfactors on the enterprise's operations and enhances its resilience to external and internal shocks.Therefore, strategic stability is achieved through continuous improvement of management processes,the implementation of innovative crisis management tools, and effective adaptation to the changingexternal environment. This ongoing process of adjustment and innovation strengthens the enterprise’sability to recover swiftly from disruptions and thrive amidst challenges.Keywords: crisis management, strategic stability, industrial enterprises, crisis management,enterprise resilience, economic strategies, financial recovery.
References1. Baranovskyi, O. I. (2009). Anti-crisis measures of governments and central banks of foreigncountries. Bulletin of the National Bank of Ukraine, (4), 8–191.2. Berezhna, O. R., & Sergiienko, T. I. (2020). Indicators for assessing the innovation potentialof an enterprise. In A. M. Tkachenko (Ed.), Strategic priorities for the development ofentrepreneurship, trade and exchange activity: Proceedings of the International Scientific andPractical Conference (pp. 154–155). Zaporizhzhia: Zaporizhzhia Polytechnic National University.3. Boniar, S. M. (2013). Theoretical foundations of anti-crisis management. Water Transport,(1), 97–102.4. Khacer, M. V. (2019). Anti-crisis financial management at the enterprise: Essence,characteristics and mechanism. Scientific Notes of the Tavria National University named after V. I.Vernadsky. Series: Economy and Management, 30(69), 1, 71–77.5. Lihonenko, L. O. (2005). Anti-crisis management of an enterprise: A textbook. Kyiv: KyivNational University of Trade and Economics.6. Lunkina, I. Yu. (2024). Theoretical aspects of anti-crisis enterprise management underenvironmental turbulence. BusinessInform, (1), 22–28. https://www.businessinform.net/export_pdf/business-inform-2024-1_0-pages-22_28.pdf7. Matukova, H. I., Bahashova, N. V., & Matukova-Yaryha, D. H. (2021). Anti-crisismanagement: An algorithm for enhancing enterprise competitiveness. Economy and Society, (32).https://doaj.org/article/9cadd6d16c3b41b494eaa621f0c14b6f8. Orlovska, Y. (2012). Anti-crisis management of a commercial bank and criteria for itseffectiveness. Scientific Bulletin of the National University of the State Tax Service of Ukraine(Economics, Law), 1(56), 74–80.9. Prib, K. (2024). Anti-crisis strategies in enterprise management. Economy and Society, (70).https://doi.org/10.32782/2524-0072/2024-70-11610. Sergiienko, T. I. (2021). Anti-crisis management in the context of the COVID-19 pandemic.In Global Challenges and Priorities in Times of the Coronavirus Crisis: Proceedings of theInternational Scientific and Practical Conference (Kyiv, May 14, 2021) (pp. 61–63). Kyiv: EasternEuropean Research Center.11. Serikova, A. A. (2018). The essence of anti-crisis management of enterprise financial risks.Prychornomorski Studii, (25), 177–179. http://nbuv.gov.ua/UJRN/bses_2018_25_3912. Telin, S. V. (2010). Anti-crisis management – a preventive measure to avoid bankruptcy.Economy of Industry, (2), 72–76.13. Tkachenko, A. M. (2023). Anti-crisis management as a comprehensive system for preventingcrisis situations. Modeling the Development of Economic Systems, (1).https://doi.org/10.31891/mdes/2023-7-3014. Vasechko, L. I. (2018). Anti-crisis management as a tool for preventing the threat of enterprisebankruptcy. Effective Economy, (8). http://www.economy.nayka.com.ua/?op=1&z=648415. Zveruk, L. A. (2017). Anti-crisis enterprise management in conditions of innovativedevelopment. International Scientific Journal “Internauka”, 1(23, Vol. 2), 69–75.Метою дослідження є аналіз та визначення ефективних інструментів антикризовогоменеджменту для підтримки стратегічної стабільності промислових підприємств в умовахекономічної нестабільності та кризових явищ. У ході дослідження були розглянуті основніінструменти антикризового менеджменту, зокрема фінансове оздоровлення,реструктуризація виробництва, оптимізація бізнес-процесів, управління ризиками тапідвищення організаційної стійкості. Дослідження також виявило взаємозв'язок міжзастосуванням цих інструментів та збереженням стратегічної стабільності підприємств.Антикризові стратегії є необхідним інструментом для збереженняконкурентоспроможності промислових підприємств у кризових умовах. Використанняінтегрованих підходів до управління ризиками та оптимізації ресурсів дозволяє знижуватинегативний вплив кризових факторів. Стратегічна стабільність досягається через постійневдосконалення управлінських процесів та адаптацію до змінюваного зовнішнього середовища.Ключові слова: антикризовий менеджмент, стратегічна стабільність, промисловіпідприємства, управління кризами, стійкість підприємств, економічні стратегії, фінансовеоздоровлення.
Список використаних джерел1. Baranovskyi, O. I. (2009). Anti-crisis measures of governments and central banks of foreigncountries. Bulletin of the National Bank of Ukraine, (4), 8–191.2. Berezhna, O. R., & Sergiienko, T. I. (2020). Indicators for assessing the innovation potentialof an enterprise. In A. M. Tkachenko (Ed.), Strategic priorities for the development ofentrepreneurship, trade and exchange activity: Proceedings of the International Scientific andPractical Conference (pp. 154–155). Zaporizhzhia: Zaporizhzhia Polytechnic National University.3. Boniar, S. M. (2013). Theoretical foundations of anti-crisis management. Water Transport,(1), 97–102.4. Khacer, M. V. (2019). Anti-crisis financial management at the enterprise: Essence,characteristics and mechanism. Scientific Notes of the Tavria National University named after V. I.Vernadsky. Series: Economy and Management, 30(69), 1, 71–77.5. Lihonenko, L. O. (2005). Anti-crisis management of an enterprise: A textbook. Kyiv: KyivNational University of Trade and Economics.6. Lunkina, I. Yu. (2024). Theoretical aspects of anti-crisis enterprise management underenvironmental turbulence. BusinessInform, (1), 22–28. https://www.businessinform.net/export_pdf/business-inform-2024-1_0-pages-22_28.pdf7. Matukova, H. I., Bahashova, N. V., & Matukova-Yaryha, D. H. (2021). Anti-crisismanagement: An algorithm for enhancing enterprise competitiveness. Economy and Society, (32).https://doaj.org/article/9cadd6d16c3b41b494eaa621f0c14b6f8. Orlovska, Y. (2012). Anti-crisis management of a commercial bank and criteria for itseffectiveness. Scientific Bulletin of the National University of the State Tax Service of Ukraine(Economics, Law), 1(56), 74–80.9. Prib, K. (2024). Anti-crisis strategies in enterprise management. Economy and Society, (70).https://doi.org/10.32782/2524-0072/2024-70-11610. Sergiienko, T. I. (2021). Anti-crisis management in the context of the COVID-19 pandemic.In Global Challenges and Priorities in Times of the Coronavirus Crisis: Proceedings of theInternational Scientific and Practical Conference (Kyiv, May 14, 2021) (pp. 61–63). Kyiv: EasternEuropean Research Center.11. Serikova, A. A. (2018). The essence of anti-crisis management of enterprise financial risks.Prychornomorski Studii, (25), 177–179. http://nbuv.gov.ua/UJRN/bses_2018_25_3912. Telin, S. V. (2010). Anti-crisis management – a preventive measure to avoid bankruptcy.Economy of Industry, (2), 72–76.13. Tkachenko, A. M. (2023). Anti-crisis management as a comprehensive system for preventingcrisis situations. Modeling the Development of Economic Systems, (1).https://doi.org/10.31891/mdes/2023-7-3014. Vasechko, L. I. (2018). Anti-crisis management as a tool for preventing the threat of enterprisebankruptcy. Effective Economy, (8). http://www.economy.nayka.com.ua/?op=1&z=648415. Zveruk, L. A. (2017). Anti-crisis enterprise management in conditions of innovativedevelopment. International Scientific Journal “Internauka”, 1(23, Vol. 2), 69–75
ІТ-СТАРТАП ЯК ДРАЙВЕР ІННОВАЦІЙНОЇ ЕКОНОМІКИ
The article examines the phenomenon of ITstartups as a driving force of the innovation economy, emphasizing their role in accelerating digitaltransformation, shaping entrepreneurial ecosystems, and fostering global competitiveness. Therelevance of the topic stems from the rapid growth of information technologies, the increasingimportance of knowledge-intensive industries, and the rising demand for flexible business models thatcan adapt to the dynamics of global markets. IT startups are understood not only as small, high-riskventures but also as dynamic organizational forms capable of integrating intellectual capital,advanced technological solutions, and innovative approaches into coherent mechanisms of valuecreation.The paper highlights the issues under discussion, focusing on the theoretical foundations of ITstartup development, their economic and social significance, and the challenges of functioning in anunstable market environment. Particular attention is devoted to the analysis of how IT startupsinfluence the formation of national and regional innovation ecosystems, facilitate knowledge transfer,and stimulate entrepreneurial activity. It is argued that their contribution goes far beyond thecreation of new digital products and services, as they also transform management practices, redefineconsumer behavior, and promote new models of cooperation between businesses, researchinstitutions, and government.The discussion touches upon the importance of investment support, the role of businessaccelerators, and the necessity of building effective partnerships for the successful scaling of ITstartups. Moreover, the text stresses the need for regulatory frameworks that encourageexperimentation, reduce risks, and support international integration of innovative companies. Thestudy also points out that IT startups function as catalysts for structural changes in the economy,enabling the transition from traditional industrial models to knowledge-driven and innovation-basedgrowth.The originality of the presented approach lies in conceptualizing IT startups as systemic actors ofthe innovation economy rather than isolated entrepreneurial initiatives. This perspective allows fora deeper understanding of their multidimensional impact, including technological advancement,labor market transformation, and the reinforcement of digital infrastructures. The paper opens upnew directions for further research, particularly regarding sustainable development strategies forstartups, integration into global digital value chains, and the development of policies that balanceentrepreneurial freedom with social responsibility.Keywords: IT startup, innovation economy, digital transformation, entrepreneurship, businessecosystem, investment.
References1. Christensen, C. M. (2016). The Innovator’s Dilemma: When New Technologies Cause GreatFirms to Fail. Harvard Business Review Press.2. Blank, S. (2013). The Startup Owner’s Manual: The Step-by-Step Guide for Building a GreatCompany. K&S Ranch.3. Ries, E. (2011). The Lean Startup: How Today’s Entrepreneurs Use Continuous Innovation toCreate Radically Successful Businesses. Crown Publishing.4. OECD. (2021). OECD Science, Technology and Innovation Outlook 2021. OECD Publishing.https://doi.org/10.1787/sti_outlook-2021-en5. Malik, I. (2020). Start-up ecosystem development in Ukraine: challenges and prospects.Economic Annals-XXI, 182(3-4), 44–52. https://doi.org/10.21003/ea.V182-076. World Bank. (2020). Doing Business 2020. World Bank Publications.https://doi.org/10.1596/978-1-4648-1440-27. Heiets, V. (2019). Innovation-driven growth and start-up development in Ukraine. Problems ofEconomy, 2(40), 110–124.8. StartupBlink. (2022). Global Startup Ecosystem Index 2022. StartupBlink.https://www.startupblink.com9. European Commission. (2021). European Innovation Scoreboard 2021. Publications Office ofthe European Union. https://doi.org/10.2873/384066У статті досліджено роль ІТ-стартапів як ключових чинників розвитку інноваційноїекономіки. Актуальність теми зумовлена трансформацією світових економічних систем підвпливом цифровізації, зростанням значення інформаційних технологій та потребою ушвидкому впровадженні інноваційних бізнес-моделей. Мета дослідження полягає у визначеннівпливу ІТ-стартапів на формування інноваційних екосистем та підвищенняконкурентоспроможності економіки. Використано комплекс методів наукового аналізу, щодало можливість систематизувати підходи до оцінювання ролі стартапів, виокремити їхніпереваги та проблеми функціонування. Основні результати дослідження свідчать, що ІТстартапи здатні генерувати нові продукти та послуги, забезпечувати цифровутрансформацію бізнесу, сприяти розвитку підприємництва та створенню нових робочихмісць. Зроблено висновок, що їхній успіх залежить від сприятливого інституційногосередовища, доступу до фінансування та інтеграції в глобальні ринки. Подальші перспективипов’язані з розробкою механізмів підтримки інноваційних ініціатив, формуванням умов дляміжнародної співпраці та посиленням державної політики стимулювання інноваційноїдіяльності.Ключові слова: ІТ-стартап, інноваційна економіка, цифрова трансформація,підприємництво, бізнес-екосистема, інвестиції.
Список використаних джерел1. Christensen, C. M. (2016). The Innovator’s Dilemma: When New Technologies Cause GreatFirms to Fail. Harvard Business Review Press.2. Blank, S. (2013). The Startup Owner’s Manual: The Step-by-Step Guide for Building a GreatCompany. K&S Ranch.3. Ries, E. (2011). The Lean Startup: How Today’s Entrepreneurs Use Continuous Innovation toCreate Radically Successful Businesses. Crown Publishing.4. OECD. (2021). OECD Science, Technology and Innovation Outlook 2021. OECD Publishing.https://doi.org/10.1787/sti_outlook-2021-en5. Malik, I. (2020). Start-up ecosystem development in Ukraine: challenges and prospects.Economic Annals-XXI, 182(3-4), 44–52. https://doi.org/10.21003/ea.V182-076. World Bank. (2020). Doing Business 2020. World Bank Publications.https://doi.org/10.1596/978-1-4648-1440-27. Heiets, V. (2019). Innovation-driven growth and start-up development in Ukraine. Problems ofEconomy, 2(40), 110–124.8. StartupBlink. (2022). Global Startup Ecosystem Index 2022. StartupBlink.https://www.startupblink.com9. European Commission. (2021). European Innovation Scoreboard 2021. Publications Office ofthe European Union. https://doi.org/10.2873/38406
ЗАСАДИ УПРАВЛІННЯ ПРОЕКТАМИ ІТ-КОМПАНІЙ: МЕТОДИКИ ТА ІНСТРУМЕНТИ
The article analyzes the problems of projectmanagement in modern IT companies and possible ways to improve this process. It is noted thateach IT company is unique and has its own characteristics, therefore, each of them requires anindividual approach to project management. Within the framework of IT project management,questions constantly arise regarding deadlines, budget constraints, as well as possibleshortcomings in personnel qualifications. Managers often face the need to solve complextechnological problems related to hardware, software, operating systems and databases.Effective project management in IT companies is a critical factor in their success anddevelopment. The use of modern methodologies, digital technologies and adaptive strategies allowscompanies to quickly respond to market changes, minimize risks and improve the quality of the finalproduct.Project management in the field of information technology has recently gained recognition asone of the most effective approaches to planning and implementing investment projects. However,modern IT projects face numerous challenges that can reduce the effectiveness of projectmanagement and make the implementation of ideas unprofitable. The main problems in this area remain the shortage of qualified specialists, the issue of distribution of responsibility amongmanagers and the lack of a ready-made model for achieving strategic goals.The updated version of the Project Management Knowledge Base has undergone significantchanges. It features a new structure, no rigid need to adhere to a fixed set of processes, and a moreflexible approach to project implementation. In previous versions, the approach assumed strictadherence to processes, which was inconvenient or even impossible in the context of IT projects.The current edition of the Knowledge Base offers a framework approach that allows you toadapt the principles to specific industries. It introduces project domains and new managementprinciples that promote the use of more flexible methodologies and allow you to achieve your goalsas efficiently as possible.Keywords: IT project, risk management, project management, project management, artificialintelligence, methodology
References1. Hrytsiuk Yu. I. and Zhabych M. R. (2018) Upravlinnia ryzykamy realizatsii prohramnykhproiektiv [Manage- ment of risks of realization of program projects]. Naukovyj visnyk NLTUUkrainy – Scientific bulletin of NLTU of Ukraine, vol. 28(1), pp. 150–162. (in Ukrainian)2. Danylyuk N. M., Shulyk Yu. V., Kachan O. I. (2021) Suchasni pidkhody do upravlinniaproiektnoiu diialnistiu IT-kompanii [Modern approaches to project management of IT companies].Naukovi zapysky Natsionalnoho universytetu «Ostrozka akademiia». Seriia «Ekonomika»:naukovyi zhurnal – Scientific notes of the National University «Ostroh Academy». «Economics»series: scientific journal. Ostrog: Publication of NaUOA, №. 22(50), pp. 88–94. (in Ukrainian)3. Katrenko A.V. (2011) Upravlinnia IT-proektamy. Knyha 1. Standarty, modeli ta metodyupravlinnia proektamy: pidruchnyk [IT project management. Book 1. Standards, models andmethods of project management]. Lviv: Novyi Svit – 2000. 550 р. (in Ukrainian)4. Kindrat O.V., Dutka G.I. (2021) Agile-metody dlya efektyvnoyi ta produktyvnoyiimplementatsiyi IT-produktu [Agile methods for effective and productive IT productimplementation]. Naukovi zapysky Lvivskoho universytetu biznesu ta prava. Seriia ekonomichna.Seriia yurydychna – Scientific notes of the Lviv University of Business and Law. The series iseconomical. Legal series, № 28, pp. 149–157. DOI: https://doi.org/10.5281/zenodo.5269131 (inUkrainian)5. Kolyanko O. V., Ozymok G. V. (2017) Using rigid “Waterfall” and flexible “Agile” projectmanagement models. [Use of rigid "Waterfall" and flexible "Agile" project management models]Visnyk Lvivskoho tor- hovelno-ekonomichnoho universytetu. Ekonomichni nauky – Bulletin of theLviv University of Trade and Economics. Economic sciences, № 52, рр. 177–182. (in Ukrainian)6. Seventh version of the Project Management Body of Knowledge (PMBOK Guide) (2021)https://learn.ztu.edu.ua/pluginfile.php/274061/mod_resource/content/1/PMBOK7_Ukr_ForPersonalUseOnly.pdf7. Smetaniuk O. A., Bondarchuk A. V. (2020) Osoblyvosti systemy upravlinnia proiektamy v itkompaniiakh. [Peculiarities of the project management system in it-companies]. Ahrosvit –Agroworld. № 10, рр. 105–111. doi: 10.32702/2306-6792.2020.10.105 (in Ukrainian)8. Heagney J. Fundamentals of Project Management - Fabula, 2020. - 272 pages9. Kerzner A. Project Management: A Systems Approach to Planning, Scheduling, and Controlling.URL: http://surl.li/gyjorСтаттю присвячено аналізу проблемі управління проєктами в сучасних IT-компаніях таможливі шляхи удосконалення цього процесу. Зазначено, що кожна IT-компанія є унікальноюта має свої особливості, тому для кожної з них необхідний індивідуальний підхід допроєктного управління. В рамках управління ІТ-проєктами постійно виникають питаннящодо дедлайнів, бюджетних обмежень, а також можливих недоліків у кваліфікаціїперсоналу. Керівники часто стикаються з необхідністю вирішення складних технологічнихпроблем, пов’язаних із технічними засобами, програмним забезпеченням, операційнимисистемами та базами даних.Оскільки управління ІТ-проєктами є складним завданням, розглянуто кілька загальнихпринципів, що сприяють спрощенню цієї роботи. Проаналізовано та систематизованометодологічні підходи до управління ІТ-проєктами, а також підкреслено важливістьновації, що нещодавно отримала широке застосування — штучного інтелекту.Ключові слова: ІТ-проект, управління ризиками, управління проектами, проектнийменеджмент, штучний інтелект, методологія.
Список використаних джерел1. Hrytsiuk Yu. I. and Zhabych M. R. (2018) Upravlinnia ryzykamy realizatsii prohramnykhproiektiv [Manage- ment of risks of realization of program projects]. Naukovyj visnyk NLTUUkrainy – Scientific bulletin of NLTU of Ukraine, vol. 28(1), pp. 150–162. (in Ukrainian)2. Danylyuk N. M., Shulyk Yu. V., Kachan O. I. (2021) Suchasni pidkhody do upravlinniaproiektnoiu diialnistiu IT-kompanii [Modern approaches to project management of IT companies].Naukovi zapysky Natsionalnoho universytetu «Ostrozka akademiia». Seriia «Ekonomika»:naukovyi zhurnal – Scientific notes of the National University «Ostroh Academy». «Economics»series: scientific journal. Ostrog: Publication of NaUOA, №. 22(50), pp. 88–94. (in Ukrainian)3. Katrenko A.V. (2011) Upravlinnia IT-proektamy. Knyha 1. Standarty, modeli ta metodyupravlinnia proektamy: pidruchnyk [IT project management. Book 1. Standards, models andmethods of project management]. Lviv: Novyi Svit – 2000. 550 р. (in Ukrainian)4. Kindrat O.V., Dutka G.I. (2021) Agile-metody dlya efektyvnoyi ta produktyvnoyiimplementatsiyi IT-produktu [Agile methods for effective and productive IT productimplementation]. Naukovi zapysky Lvivskoho universytetu biznesu ta prava. Seriia ekonomichna.Seriia yurydychna – Scientific notes of the Lviv University of Business and Law. The series iseconomical. Legal series, № 28, pp. 149–157. DOI: https://doi.org/10.5281/zenodo.5269131 (inUkrainian)5. Kolyanko O. V., Ozymok G. V. (2017) Using rigid “Waterfall” and flexible “Agile” projectmanagement models. [Use of rigid "Waterfall" and flexible "Agile" project management models]Visnyk Lvivskoho tor- hovelno-ekonomichnoho universytetu. Ekonomichni nauky – Bulletin of theLviv University of Trade and Economics. Economic sciences, № 52, рр. 177–182. (in Ukrainian)6. Seventh version of the Project Management Body of Knowledge (PMBOK Guide) (2021)https://learn.ztu.edu.ua/pluginfile.php/274061/mod_resource/content/1/PMBOK7_Ukr_ForPersonalUseOnly.pdf7. Smetaniuk O. A., Bondarchuk A. V. (2020) Osoblyvosti systemy upravlinnia proiektamy v itkompaniiakh. [Peculiarities of the project management system in it-companies]. Ahrosvit –Agroworld. № 10, рр. 105–111. doi: 10.32702/2306-6792.2020.10.105 (in Ukrainian)8. Heagney J. Fundamentals of Project Management - Fabula, 2020. - 272 pages9. Kerzner A. Project Management: A Systems Approach to Planning, Scheduling, and Controlling.URL: http://surl.li/gyjo