State University of Telecommunications Open Journals System
Not a member yet
2308 research outputs found
Sort by
ВАЖЛИВІСТЬ КОМУНІКАЦІЙ ПРИ ІНТЕГРАЦІЙНОМУ РОЗВИТКУ ІНТЕРНЕТ-ТЕХНОЛОГІЙ НА ПІДПРИЄМСТВІ
The articleexamines the importance of communications in the integrated development of Internet technologiesin an enterprise. In the modern information world, Internet technologies strongly influence anenterprise and have a deep and comprehensive impact on its activities, transforming almost allaspects of its functioning in society. The role and features of communications in a certain interactionwith Internet technologies are described, which open a new era for establishing ties in an enterprise.The impact of modern information technologies on enterprise communications has become a relevanttopic in the modern business environment. Technologies provide enterprises with new opportunitiesfor personalizing communications with their contact audiences. The development of suchtechnologies, especially the Internet, social media, mobile applications and electroniccommunication, affects the ways in which an enterprise interacts with its customers. The need to usecommunication in enterprise management arises from the high level of information andcommunication complexity of the tasks facing modern business entities. It was analyzed whichenterprises in the field of information and communication technologies have access to the Internet,which has such a significant impact on their activities and communication links with contactaudiences. It was emphasized that the rapid development of the Internet and the spread oftechnologies have reached such a scale that they have changed the way businesses interact withconsumers and have affected the working moments of employees at the enterprise. The passage ofinformation through communication channels with the implementation of Internet technologies at theenterprise, which ensure the interaction of subjects at different levels of management in the processof special contacts, is considered. It was established that an in-depth study of the importance ofcommunications in the integration development of Internet technologies at the enterprise isunderstood as technical and managerial aspects of their implementation, which are aimed at ensuringsuccessful, effective and sustainable integration of new technologies, while minimizing possible risksand barriers to communication.Keywords: communication, Internet technologies, integrated development, enterprise, business,interaction, information technologies, Internet.
References1. Bodnarchuk, YU. (2023). Istorychni osoblyvosti mulʹtymediynoyi kulʹtury ta elektronnoyikomunikatsiyi [Historical features of multimedia culture and electronic communication].Informatsiya ta sotsium, 11-13.2. Derzhavnyy komitet statystyky Ukrayiny [State Statistics Committee of Ukraine].https://www.ukrstat.gov.ua/operativ/operativ2018/zv/ikt/arh_ikt_u.html3. Hermanyuk, N.V. (2021). Rolʹ komunikatsiy v upravlinni orhanizatsiynym protsesom [Therole of communications in organizational process management]. Efektyvna ekonomika, 10.http://www.economy.nayka.com.ua/pdf/10_2021/75.pdf4. Hlyebova, A.O. & Kravchenko, V.V. (2021). Rozvytok tsyfrovykh komunikatsiy v umovakhdidzhytalizatsiyi ekonomiky Ukrayiny: problemy ta mozhlyvosti [Development of digitalcommunications in the context of digitalization of the Ukrainian economy: problems andopportunities]. Efektyvna ekonomika, 9. http://www.economy.nayka.com.ua/? op=1&z=92775. Ilʹchuk, O.O., Udud, I.R. & Ivanochko, A.T. (2023). Rolʹ komunikatsiyi v pobudovi stratehiyiantykryzovoho rozvytku pidpryyemstva [The role of communication in building an anti-crisisdevelopment strategy for an enterprise]. Visnyk Sumsʹkoho natsionalʹnoho ahrarnoho universytetu.Seriya «Ekonomika i menedzhment», 4 (96), 307.6. Makovetsʹka, I. M. (2025). Znachennya upravlinsʹkykh Internet-tekhnolohiy v biznesi [Theimportance of managerial Internet technologies in business]. Development Service IndustryManagement, 2, 158-163.7. Olifirenko, L. & Pysʹmenyuk, M. (2019). Kryteriyi efektyvnosti internet-tekhnolohiy vaspekti planuvannya marketynhovykh komunikatsiy [Criteria for the effectiveness of Internettechnologies in the aspect of planning marketing communications]. Problemy i perspektyvyekonomiky ta upravlinnya, 2, 33-44.8. Osokin, M.H. & Osokina, A.V. (2024). Tsyfrovi komunikatsiyi v systemi upravlinnyabiznesom [Digital communications in the business management system]. Ekonomika ta suspilʹstvo,64. https://economyandsociety.in.ua/index.php/journal/article/view/4233/41599. Voyt, B. R. (2023). Sutnistʹ komunikatsiy pidpryyemstva ta yikh rolʹ u protsesi upravlinnyanym [The essence of enterprise communications and their role in the process of managing them].Biznes Inform, 3, 166-171.У статті досліджено важливість комунікацій при інтеграційному розвитку Інтернеттехнологій на підприємстві. В сучасному інформаційному світі Інтернет-технології сильновпливають на підприємство та мають глибокий і всеосяжний вплив на їх діяльність,трансформуючи майже всі аспекти їхнього функціонування в суспільстві. Описано роль таособливості комунікацій при певній взаємодії з Інтернет-технологіями, які відкривають новуеру для налагодження зав’язків на підприємстві. Проаналізовано, яка кількість підприємствза напрямом діяльності інформаційно-комунікаційних технологій, має доступ до мережіІнтернет, що так відчутно впливає на їх діяльність та комунікаційні зв’язки з контактнимиаудиторіями. Наголошено на тому, що швидкий розвиток Інтернету та поширеннятехнологій набули таких масштабів, які змінили спосіб взаємодії бізнесу зі споживачами тавплинули на робочі моменти працівників на підприємстві. Розглянуто проходження інформаціїпо каналах комунікацій з впровадженням Інтернет-технологій на підприємстві, щозабезпечують взаємодію суб’єктів різних рівнів управління в процесі особливих контактів.Встановлено, що поглиблене дослідження важливості комунікацій при інтеграційномурозвитку Інтернет-технологій на підприємстві розуміється як технічні та управлінськіаспекти їх впровадження, що мають на меті забезпечити успішну, ефективну та стійкуінтеграцію нових технологій, мінімізуючи при цьому можливі ризики та бар’єри в комунікації.Ключові слова: комунікація, Інтернет-технології, інтеграційний розвиток, підприємство,бізнес, взаємодія, інформаційні технології, Інтернет.
Список використаних джерел1. Bodnarchuk, YU. (2023). Istorychni osoblyvosti mulʹtymediynoyi kulʹtury ta elektronnoyikomunikatsiyi [Historical features of multimedia culture and electronic communication].Informatsiya ta sotsium, 11-13.2. Derzhavnyy komitet statystyky Ukrayiny [State Statistics Committee of Ukraine].https://www.ukrstat.gov.ua/operativ/operativ2018/zv/ikt/arh_ikt_u.html3. Hermanyuk, N.V. (2021). Rolʹ komunikatsiy v upravlinni orhanizatsiynym protsesom [Therole of communications in organizational process management]. Efektyvna ekonomika, 10.http://www.economy.nayka.com.ua/pdf/10_2021/75.pdf4. Hlyebova, A.O. & Kravchenko, V.V. (2021). Rozvytok tsyfrovykh komunikatsiy v umovakhdidzhytalizatsiyi ekonomiky Ukrayiny: problemy ta mozhlyvosti [Development of digitalcommunications in the context of digitalization of the Ukrainian economy: problems andopportunities]. Efektyvna ekonomika, 9. http://www.economy.nayka.com.ua/? op=1&z=92775. Ilʹchuk, O.O., Udud, I.R. & Ivanochko, A.T. (2023). Rolʹ komunikatsiyi v pobudovi stratehiyiantykryzovoho rozvytku pidpryyemstva [The role of communication in building an anti-crisisdevelopment strategy for an enterprise]. Visnyk Sumsʹkoho natsionalʹnoho ahrarnoho universytetu.Seriya «Ekonomika i menedzhment», 4 (96), 307.6. Makovetsʹka, I. M. (2025). Znachennya upravlinsʹkykh Internet-tekhnolohiy v biznesi [Theimportance of managerial Internet technologies in business]. Development Service IndustryManagement, 2, 158-163.7. Olifirenko, L. & Pysʹmenyuk, M. (2019). Kryteriyi efektyvnosti internet-tekhnolohiy vaspekti planuvannya marketynhovykh komunikatsiy [Criteria for the effectiveness of Internettechnologies in the aspect of planning marketing communications]. Problemy i perspektyvyekonomiky ta upravlinnya, 2, 33-44.8. Osokin, M.H. & Osokina, A.V. (2024). Tsyfrovi komunikatsiyi v systemi upravlinnyabiznesom [Digital communications in the business management system]. Ekonomika ta suspilʹstvo,64. https://economyandsociety.in.ua/index.php/journal/article/view/4233/41599. Voyt, B. R. (2023). Sutnistʹ komunikatsiy pidpryyemstva ta yikh rolʹ u protsesi upravlinnyanym [The essence of enterprise communications and their role in the process of managing them].Biznes Inform, 3, 166-171
РОЗВИТОК ЛОГІСТИЧНИХ МЕРЕЖ В УМОВАХ ЦИФРОВІЗАЦІЇ ТА НЕСТАБІЛЬНОСТІ РИНКУ
This article explores the development of logistics networks in thecontext of ongoing digital transformation and increasing market volatility. The relevance of the studystems from the urgent need to adapt logistics systems to rapidly changing global conditions, whichare shaped by technological innovations, unpredictable crises (such as the COVID-19 pandemic, thewar in Ukraine, and supply chain disruptions), and shifts in consumer demand. The main objectiveis to identify current trends, risks, and tools that influence the evolution of logistics networks underthese conditions.The research is grounded in a comprehensive analysis of scientific literature on digital logisticsand risk management and employs a methodological framework based on systems analysis,comparative analysis, content analysis, expert assessments, and scenario modeling. Key focus areasinclude the impact of digital platforms (such as TMS, WMS, ERP, SCM), big data analytics fordemand forecasting, automation of warehouse and transport processes, blockchain for supply chaintransparency, the Internet of Things (IoT) for real-time monitoring, and sustainable ("green")logistics strategies.The findings emphasize the necessity of transitioning from traditional, linear logistics models todecentralized, flexible, and digitally integrated networks capable of responding proactively toexternal shocks and internal operational shifts. The article presents practical recommendations forenhancing supply chain resilience, operational efficiency, and environmental sustainability throughthe strategic implementation of digital technologies. It also outlines avenues for further research,including automation, risk forecasting, and adaptation of global practices to local economic contexts,particularly in Ukraine.Keywords: digitalization, logistics networks, market instability, supply chain, Internet of Things,risk management, automation, resilience, sustainable logistics.
References1. Kyzym M. O., Shemeta L. O. (2021) Tsyfrova lohistyka v umovakh hlobalizatsiyi [Digitallogistics in the context of globalization]. Business Inform (9), рр. 112–118. (in Ukrainian)2. Mnykh O. B. (2022) Tsyfrovi platformy v lohistytsi: ryzyky ta perspektyvy. [Digital platformsin logistics: risks and prospects] Economy and State. (5) pp. 45–50. (in Ukrainian)3. Hrabynsʹka I. S., Voloshyn N. V. (2023). Innovatsiyni tekhnolohiyi v lohistytsi: trendytsyfrovizatsiyi [Innovative technologies in logistics: digitalization trends]. Bulletin of social andeconomic research. (80). pp. 84–91. (in Ukrainian)4. Christopher M., Peck H. (2004) Building the Resilient Supply Chain. International Journal ofLogistics Management. 15 (2). pp. 1–14. DOI: https://doi.org/10.1108/095740904107002755. Ivanov D. (2021) Digital Supply Chain Twins: Managing the Ripple Effect, Resilience, andDisruption Risks. Transportation Research Part E: Logistics and Transportation Review. 136. DOI:https://doi.org/10.1016/j.tre.2019.1019226. Martynenko, M. O., & Nikolenko, I. Yu. (2024). Optimization of logistics processes ininternational trade. Ekonomika. Menedzhment. Biznes, (1), 82–86. https://doi.org/10.31673/2415-8089.2024.010012У статті розглядаються ключові аспекти розвитку логістичних мереж у контекстісучасних викликів, спричинених цифровізацією та ринковою нестабільністю. Актуальністьдослідження обумовлена необхідністю адаптації логістичних систем до умов, які швидкозмінюються, в тому числі через глобальні кризи, цифрові трансформації та зміну поведінкиспоживачів. Метою статті є виявлення сучасних тенденцій, ризиків та інструментіврозвитку логістичних мереж. Проаналізовано наукові публікації з тематики цифровоїтрансформації логістики та ризик-менеджменту. Використано системний, порівняльний іконтент-аналіз як методологічну основу. Результатом дослідження стало формулюванняпідходів до формування гнучких і цифрово адаптованих логістичних мереж, здатних швидкореагувати на зовнішні виклики. У статті запропоновано шляхи підвищення ефективностілогістичних систем на основі цифрових технологій, зокрема інтернету речей (IoT), хмарних рішень і штучного інтелекту. Розкрито перспективи подальших досліджень у напряміавтоматизації та стійкості логістичних ланцюгів постачання.Ключові слова: цифровізація, логістичні мережі, нестабільність ринку, ланцюгпостачання, інтернет речей, ризик-менеджмент.
Список використаних джерел1. Kyzym M. O., Shemeta L. O. (2021) Tsyfrova lohistyka v umovakh hlobalizatsiyi [Digitallogistics in the context of globalization]. Business Inform (9), рр. 112–118. (in Ukrainian)2. Mnykh O. B. (2022) Tsyfrovi platformy v lohistytsi: ryzyky ta perspektyvy. [Digital platformsin logistics: risks and prospects] Economy and State. (5) pp. 45–50. (in Ukrainian)3. Hrabynsʹka I. S., Voloshyn N. V. (2023). Innovatsiyni tekhnolohiyi v lohistytsi: trendytsyfrovizatsiyi [Innovative technologies in logistics: digitalization trends]. Bulletin of social andeconomic research. (80). pp. 84–91. (in Ukrainian)4. Christopher M., Peck H. (2004) Building the Resilient Supply Chain. International Journal ofLogistics Management. 15 (2). pp. 1–14. DOI: https://doi.org/10.1108/095740904107002755. Ivanov D. (2021) Digital Supply Chain Twins: Managing the Ripple Effect, Resilience, andDisruption Risks. Transportation Research Part E: Logistics and Transportation Review. 136. DOI:https://doi.org/10.1016/j.tre.2019.1019226. Martynenko, M. O., & Nikolenko, I. Yu. (2024). Optimization of logistics processes ininternational trade. Ekonomika. Menedzhment. Biznes, (1), 82–86. https://doi.org/10.31673/2415-8089.2024.01001
ІННОВАЦІЙНІ ПІДХОДИ ДО УПРАВЛІННЯ ФІНАНСОВИМИ РИЗИКАМИ У СУЧАСНИХ ПІДПРИЄМСТВАХ
This paper addresses thegrowing necessity for holistic mechanisms aimed at identifying, analyzing, and mitigating financialrisks that contemporary enterprises confront in a volatile market environment. The study focuses onhow the intricacies of global economic shifts, the proliferation of digital tools, and the heightenedrole of strategic decision-making have underscored the need for more adaptive risk managementframeworks. Particular attention is given to the theoretical underpinnings of financial riskclassification, emphasizing those factors that most critically influence liquidity, solvency, andlong-term stability of organizations. By examining the interplay between conventional instrumentsand modern solutions based on advanced financial technologies, the paper seeks to revealprospective pathways for enhancing risk assessment and strategic resilience. These modernsolutions include blockchain-based platforms and artificial intelligence which collectively promiseto transform the speed, transparency, and cost efficiency of operations. The relevance of thisinvestigation lies in the fact that enterprises increasingly rely on integrated and data-driveninsights to safeguard cash flows and maintain competitive advantages in environments marked byfrequent economic swings and regulatory changes. The paper gives particular emphasis to thepotential for integrating big data analytics into corporate processes, thereby enabling real-timemonitoring of credit, liquidity, and market uncertainties. By establishing a conceptual foundationfor how cutting-edge tools may be incorporated into existing management structures, this researchpaves the way for professionals seeking more precise approaches to risk mitigation. The paperpresents a developed algorithm for financial risk management that leverages innovativetechnologies such as blockchain-based platforms and artificial intelligence. These modern solutionspromise to transform the speed, transparency, and cost efficiency of operations, enablingenterprises to integrate big data analytics into their corporate processes for real-time monitoring ofcredit, liquidity, and market uncertainties. The relevance of this investigation lies in the fact thatenterprises increasingly rely on integrated, data-driven insights to safeguard cash flows andmaintain competitive advantages in environments marked by frequent economic swings andregulatory changes Furthermore, the study identifies potential threats associated with the use ofinnovative technologies, including technological vulnerabilities and regulatory challenges, whichmust be carefully managed to ensure stability and security. By establishing a conceptual foundationfor incorporating cutting-edge tools into management structures, this research paves the way forprofessionals seeking more precise approaches to risk mitigation. The issues under discussionrange from identifying gaps in current practices to outlining possible directions for futureexploration of innovative financial solutions that can strengthen an enterprise’s capacity tonavigate global uncertainty and market disruptions.Keywords: risk, financial risk management, artificial intelligence, financial instruments, riskmanagement, financial technologies.
References1. Laktionova O. A. (2020) Upravlinnia finansovymy ryzykamy: navchalnyi posibnyk[Financial Risk Management: A Textbook]. Vinnytsia: DonNU imeni Vasylia Stusa. (in Ukrainian)2. Financial Risks in IFRS Reporting: Rules for Identification and Management. URL:https://mof.gov.ua/storage/files/IFRS%2007_ukr.pdf.3. Iankovska, L. A., Semchuk, Zh. V., Shevchuk, Ya. V., Antoniuk, N. A., & Nahirna, O. V.(2023). Upravlinnia finansovymy ryzykamy pidpryiemstv v umovakh viiny [Management ofFinancial Risks of Enterprises in Wartime Conditions.]. Scientific notes of Lviv University ofBusiness and Law, (37), pp. 307-314. URL:https://nzlubp.org.ua/index.php/journal/article/view/8164. Kustrich L. O. (2022) Upravlinnia finansovymy ryzykamy pidpryiemnytskoi diialnosti vumovakh kryzy [Entrepreneurial Financial Risk Management in Crisis Conditions]. InternationalScientific Journal "Internauka". Series: "Economic Sciences", (5). https://doi.org/10.25313/2520-2294-2022-5-80225. Kondratenko, N., Pysarevskyi, I., & Borovyk, M. (2022). TEORETYKOMETODYCHNI ASPEKTY UPRAVLINNIA FINANSOVYMY RYZYKAMYPROMYSLOVYKH PIDPRYIEMSTV [Theoretical and Methodological Aspects of IndustrialEnterprises' Financial Risk Management]. Economy and Society, (40).https://doi.org/10.32782/2524-0072/2022-40-576. Zhytar, M. O., & Ananieva, Yu. V. (2025). Metodolohichna systema formuvanniastratehii upravlinnia finansovymy ryzykamy v umovakh hlobalizatsii ekonomiky[MethodologicalSystem for Forming Strategies of Financial Risk Management in the Context of EconomicGlobalization]. Business Inform, (1), pp. 229-240. DOI: https://doi.org/10.32983/2222-4459-2025-1-229-2407. Kanyhin, S. M. (2024). Velyki dani v upravlinni finansamy pidpryiemstva [Big Data inEnterprise Financial Management]. Ekonomika, upravlinnia ta administruvannia, 3(109), pp. 97–104. https://doi.org/10.26642/ema-2024-3(109)-97-1048. Kyshakevych, B. Yu., Luchakivskyi, A. O., Zvarych, B. Ya., & Sledz, S. Yu. (2024).Innovatsiini pidkhody do upravlinnia ryzykamy v ZED: vykorystannia tekhnolohii blokchein tashtuchnoho intelektu [Innovative Approaches to Risk Management in Foreign Economic Activity:The Use of Blockchain and Artificial Intelligence Technologies]. Zdobutky ekonomiky:perspektyvy ta innovatsii, (8). https://doi.org/10.5281/zenodo.127500419. Kondrat, O. B. (2024). Innovatsiini finansovi instrumenty v systemi rozvytkupidpryiemstv [Innovative Financial Instruments in the Enterprise Development System]. UkrainianJournal of Applied Economics and Technology, 9(1), pp. 339-344. DOI:https://doi.org/10.36887/2415-8453-2024-1-57У статті досліджено актуальність впровадження сучасних підходів до управлінняфінансовими ризиками в умовах постійних економічних коливань, зростання конкуренції тастрімкого розвитку технологічних інновацій. Метою дослідження є розробка комплексноїмоделі, що інтегрує традиційні методи та інноваційні інструменти управління фінансовимиризиками задля підвищення оперативності прийняття управлінських рішень тазабезпечення стійкості підприємства. Проведено аналіз основних джерел ризиків, зокремакредитного, ліквідного та ринкового, а також визначено недоліки стандартних методів їхмінімізації, що обумовлюють необхідність використання сучасних технологічних рішень.Основні результати дослідження свідчать про те, що інтеграція інноваційних підходівдозволяє значно покращити якість аналізу, скоротити час реагування на зовнішні тавнутрішні загрози, а також оптимізувати використання фінансових ресурсів. Отриманівисновки підтверджують необхідність комплексного підходу до управління фінансовимиризиками, який поєднує традиційні методи з новітніми технологіями для досягненнямаксимальної адаптивності підприємства до змін ринкових умов та забезпечення йогоконкурентоспроможності в умовах високої невизначеності.Ключові слова: ризик, управління фінансовими ризиками, штучний інтелект, фінансовіінструменти, ризик-менеджмент, фінансові технології.
Список використаних джерел1. Laktionova O. A. (2020) Upravlinnia finansovymy ryzykamy: navchalnyi posibnyk[Financial Risk Management: A Textbook]. Vinnytsia: DonNU imeni Vasylia Stusa. (in Ukrainian)2. Financial Risks in IFRS Reporting: Rules for Identification and Management. URL:https://mof.gov.ua/storage/files/IFRS%2007_ukr.pdf.3. Iankovska, L. A., Semchuk, Zh. V., Shevchuk, Ya. V., Antoniuk, N. A., & Nahirna, O. V.(2023). Upravlinnia finansovymy ryzykamy pidpryiemstv v umovakh viiny [Management ofFinancial Risks of Enterprises in Wartime Conditions.]. Scientific notes of Lviv University ofBusiness and Law, (37), pp. 307-314. URL:https://nzlubp.org.ua/index.php/journal/article/view/8164. Kustrich L. O. (2022) Upravlinnia finansovymy ryzykamy pidpryiemnytskoi diialnosti vumovakh kryzy [Entrepreneurial Financial Risk Management in Crisis Conditions]. InternationalScientific Journal "Internauka". Series: "Economic Sciences", (5). https://doi.org/10.25313/2520-2294-2022-5-80225. Kondratenko, N., Pysarevskyi, I., & Borovyk, M. (2022). TEORETYKOMETODYCHNI ASPEKTY UPRAVLINNIA FINANSOVYMY RYZYKAMYPROMYSLOVYKH PIDPRYIEMSTV [Theoretical and Methodological Aspects of IndustrialEnterprises' Financial Risk Management]. Economy and Society, (40).https://doi.org/10.32782/2524-0072/2022-40-576. Zhytar, M. O., & Ananieva, Yu. V. (2025). Metodolohichna systema formuvanniastratehii upravlinnia finansovymy ryzykamy v umovakh hlobalizatsii ekonomiky[MethodologicalSystem for Forming Strategies of Financial Risk Management in the Context of EconomicGlobalization]. Business Inform, (1), pp. 229-240. DOI: https://doi.org/10.32983/2222-4459-2025-1-229-2407. Kanyhin, S. M. (2024). Velyki dani v upravlinni finansamy pidpryiemstva [Big Data inEnterprise Financial Management]. Ekonomika, upravlinnia ta administruvannia, 3(109), pp. 97–104. https://doi.org/10.26642/ema-2024-3(109)-97-1048. Kyshakevych, B. Yu., Luchakivskyi, A. O., Zvarych, B. Ya., & Sledz, S. Yu. (2024).Innovatsiini pidkhody do upravlinnia ryzykamy v ZED: vykorystannia tekhnolohii blokchein tashtuchnoho intelektu [Innovative Approaches to Risk Management in Foreign Economic Activity:The Use of Blockchain and Artificial Intelligence Technologies]. Zdobutky ekonomiky:perspektyvy ta innovatsii, (8). https://doi.org/10.5281/zenodo.127500419. Kondrat, O. B. (2024). Innovatsiini finansovi instrumenty v systemi rozvytkupidpryiemstv [Innovative Financial Instruments in the Enterprise Development System]. UkrainianJournal of Applied Economics and Technology, 9(1), pp. 339-344. DOI:https://doi.org/10.36887/2415-8453-2024-1-5
ВПРОВАДЖЕННЯ СИСТЕМ ОДНОРАЗОВОГО ВХОДУ (SSO) ДЛЯ ПІДВИЩЕННЯ КІБЕРБЕЗПЕКИ
In today's digital environment, where the security of users and their data is a priority, Single Sign-On (SSO) systemsplay a key role in simplifying the authentication process and increasing the level of cybersecurity. This article is devoted to theresearch, development and implementation of a centralized authorization system based on the OAuth2.0 (Open Authorization)and OpenID Connect (OIDC) standards. The authors analyze modern approaches to user identity management, and also considerthe advantages of implementing an authorization server with support for JSON Web Token (JWT) and the PKCE (Proof Keyfor Code Exchange) mechanism to increase the security of client applications. The main attention in the article is paid to theimplementation of an authentication server that provides centralized user verification and transfer of access tokens betweenservices. Security Assertion Markup Language (SAML), OAuth2.0 and OIDC are considered as the main standards foridentification and access management. The authors examined the advantages and disadvantages of each approach, emphasizingthe importance of using Authorization Code Flow with PKCE to increase resistance to attacks such as "client spoofing" and"token theft". The paper also examines in detail the mechanisms for protecting against cross-site scripting (XSS), attacks onbrowser applications, and secure storage of access tokens. Particular attention is paid to the issues of local token validation toreduce the load on the authorization server and increase system performance. The result of the research is a functional SSOmodel that supports OAuth 2.0, OIDC, JWT and provides authentication for public and confidential clients. The proposedsolution can be used in corporate and commercial environments to protect resources and simplify access management. Theresults obtained have both theoretical and practical significance, as they contribute to the development of secure digitalidentification systems and improve user protection in the Internet environment.Keywords: Single Sign-On (SSO), authentication, authorization, cybersecurity, OAuth2.0, OpenID Connect (OIDC),JSON Web Token (JWT), Security Assertion Markup Language (SAML), PKCE (Proof Key for Code Exchange), local tokenvalidation, cross-site scripting (XSS), secure token storage, access control, authentication server, digital identity.
References1. Чирський Ю.В. Запровадження системи електронного документообігу в Україні. Режим доступу:http://old.minjust.gov.ua/7546.2. Morkonda S. G., Chiasson S., van Oorschot P. C. Influences of displaying permission-related information onweb single sign-on login decisions / Srivathsan G. Morkonda, Sonia Chiasson, Paul C. van Oorschot // Computers &Security. - April 2024. - Vol. 139. - P. 103666. - Available online 20 December 2023. - DOI:https://doi.org/10.1016/j.cose.2023.1036663. Wilson Y., Hingnikar A. Single Sign-On. In: Solving Identity Management in Modern Applications / Y.Wilson, A. Hingnikar. – Berkeley, CA: Apress, 2023. – DOI: https://doi.org/10.1007/978-1-4842-8261-8_114. Suoranta S., Manzoor K., Tontti A., Ruuskanen J., Aura T. Logout in single sign-on systems: Problems andsolutions / Sanna Suoranta, Kamran Manzoor, Asko Tontti, Joonas Ruuskanen, Tuomas Aura // Journal of InformationSecurity and Applications. – February 2014. – Vol. 19, Issue 1. – P. 61-77. – DOI:https://doi.org/10.1016/j.jisa.2014.03.0055. Surya M., Anithadevi N. Single Sign-on Mechanism Using Attribute-Based Encryption in DistributedComputer Networks / M. Surya, N. Anithadevi // Procedia Computer Science. – 2015. – Vol. 47. – P. 441-451. – DOI:https://doi.org/10.1016/j.procs.2015.03.2286. Heckle R. R., Lutters W. G. Tensions of network security and collaborative work practice: Understanding asingle sign-on deployment in a regional hospital / Rosa R. Heckle, Wayne G. Lutters // International Journal of MedicalInformatics. – August 2011. – Vol. 80, Issue 8. – P. e49-e61. – DOI: https://doi.org/10.1016/j.ijmedinf.2011.02.0017. Cusack B., Ghazizadeh E. Evaluating single sign-on security failure in cloud services / Brian Cusack, EghbalGhazizadeh // Business Horizons. – November–December 2016. – Vol. 59, Issue 6. – P. 605-614. – DOI:https://doi.org/10.1016/j.bushor.2016.08.0028. Pérez Méndez A., Marín López R., López Millán G. Providing efficient SSO to cloud service access in AAAbased identity federations / Alejandro Pérez Méndez, Rafael Marín López, Gabriel López Millán // Future GenerationComputer Systems. – May 2016. – Vol. 58. – P. 13-28. – DOI: https://doi.org/10.1016/j.future.2015.12.0029. Фединишин Т., Михайлова О., Опірський І. Метод визначення потенційно небезпечних осіб по данихBluetooth // Ukrainian Scientific Journal of Information Security. – 2023. – Том 29, Випуск 3. – С. 5.10. Yevseiev, S., Hryshchuk, R., Molodetska, K., et al. (2022). Modeling of Security Systems for CriticalInfrastructure Facilities. PC Technology Center. Available at: [Link or URL if available, e.g., polissiauniver.edu.ua]11. Bhargavan, K., Delignat-Lavaud, A., Fournet, C., Pironti, A., & Strub, P.-Y. (2014). Triple handshakes andcookie cutters: Breaking and fixing authentication over TLS. IEEE Symposium on Security and Privacy (SP), 98–113.https://doi.org/10.1109/SP.2014.1512. Cantor, S., Kemp, J., Philpott, R., & Maler, E. (2005). Assertions and Protocols for the OASIS SecurityAssertion Markup Language (SAML) v2.0. OASIS Standard. Retrieved from https://www.oasis-open.org13. Choudhary, A., & Kesswani, N. (2022). A comparative analysis of OAuth 2.0 and OpenID Connect securityprotocols. Future Generation Computer Systems, 130, 254–266. https://doi.org/10.1016/j.future.2022.01.01814. Cusack, B., & Ghazizadeh, E. (2016). Evaluating single sign-on security failure in cloud services. BusinessHorizons, 59(6), 605–614. https://doi.org/10.1016/j.bushor.2016.08.00215. Hardt, D. (2012). The OAuth 2.0 Authorization Framework. Internet Engineering Task Force (IETF).https://tools.ietf.org/html/rfc6749.У сучасному цифровому середовищі, де безпека користувачів та їхніх даних є пріоритетом, системиодноразового входу (Single Sign-On, SSO) відіграють ключову роль у спрощенні процесу автентифікації тапідвищенні рівня кібербезпеки. Дана стаття присвячена дослідженню, розробці та впровадженню централізованоїсистеми авторизації на основі стандартів OAuth2.0 (Open Authorization) та OpenID Connect (OIDC). Авторианалізують сучасні підходи до управління ідентифікацією користувачів, а також розглядають перевагивпровадження авторизаційного сервера з підтримкою JSON Web Token (JWT) та механізму PKCE (Proof Key forCode Exchange) для підвищення безпеки клієнтських додатків. Основна увага у статті приділена реалізаціїсервера автентифікації, який забезпечує централізовану перевірку користувачів та передачу токенів доступу міжсервісами. Розглянуто Security Assertion Markup Language (SAML), OAuth2.0 та OIDC як основні стандартиідентифікації та управління доступом. Автори дослідили переваги та недоліки кожного з підходів, підкреслюючиважливість використання Authorization Code Flow з PKCE для підвищення стійкості до атак типу "підмінаклієнта" та "викрадення токенів". Також у роботі детально розглянуто механізми захисту від міжсайтовогоскриптингу (XSS), атаки на браузерні додатки та безпечне зберігання токенів доступу. Особливу увагу приділенопитанням локальної валідації токенів для зменшення навантаження на авторизаційний сервер та підвищенняпродуктивності системи. Результатом дослідження є функціональна модель SSO, що підтримує OAuth 2.0, OIDC,JWT та забезпечує автентифікацію для публічних і конфіденційних клієнтів. Запропоноване рішення може бутизастосоване в корпоративних та комерційних середовищах для захисту ресурсів та спрощення управліннядоступом. Отримані результати мають як теоретичне, так і практичне значення, оскільки сприяють розвиткубезпечних цифрових ідентифікаційних систем та покращенню захисту користувачів в інтернет-середовищі.Ключові слова: Single Sign-On (SSO), автентифікація, авторизація, кібербезпека, OAuth2.0, OpenIDConnect (OIDC), JSON Web Token (JWT), Security Assertion Markup Language (SAML), PKCE (Proof Key for CodeExchange), локальна валідація токенів, міжсайтовий скриптинг (XSS), безпечне зберігання токенів, управліннядоступом, сервер автентифікації, цифрова ідентифікація.
Перелік посилань1. Чирський Ю.В. Запровадження системи електронного документообігу в Україні. Режим доступу:http://old.minjust.gov.ua/7546.2. Morkonda S. G., Chiasson S., van Oorschot P. C. Influences of displaying permission-related information onweb single sign-on login decisions / Srivathsan G. Morkonda, Sonia Chiasson, Paul C. van Oorschot // Computers &Security. - April 2024. - Vol. 139. - P. 103666. - Available online 20 December 2023. - DOI:https://doi.org/10.1016/j.cose.2023.1036663. Wilson Y., Hingnikar A. Single Sign-On. In: Solving Identity Management in Modern Applications / Y.Wilson, A. Hingnikar. – Berkeley, CA: Apress, 2023. – DOI: https://doi.org/10.1007/978-1-4842-8261-8_114. Suoranta S., Manzoor K., Tontti A., Ruuskanen J., Aura T. Logout in single sign-on systems: Problems andsolutions / Sanna Suoranta, Kamran Manzoor, Asko Tontti, Joonas Ruuskanen, Tuomas Aura // Journal of InformationSecurity and Applications. – February 2014. – Vol. 19, Issue 1. – P. 61-77. – DOI:https://doi.org/10.1016/j.jisa.2014.03.0055. Surya M., Anithadevi N. Single Sign-on Mechanism Using Attribute-Based Encryption in DistributedComputer Networks / M. Surya, N. Anithadevi // Procedia Computer Science. – 2015. – Vol. 47. – P. 441-451. – DOI:https://doi.org/10.1016/j.procs.2015.03.2286. Heckle R. R., Lutters W. G. Tensions of network security and collaborative work practice: Understanding asingle sign-on deployment in a regional hospital / Rosa R. Heckle, Wayne G. Lutters // International Journal of MedicalInformatics. – August 2011. – Vol. 80, Issue 8. – P. e49-e61. – DOI: https://doi.org/10.1016/j.ijmedinf.2011.02.0017. Cusack B., Ghazizadeh E. Evaluating single sign-on security failure in cloud services / Brian Cusack, EghbalGhazizadeh // Business Horizons. – November–December 2016. – Vol. 59, Issue 6. – P. 605-614. – DOI:https://doi.org/10.1016/j.bushor.2016.08.0028. Pérez Méndez A., Marín López R., López Millán G. Providing efficient SSO to cloud service access in AAAbased identity federations / Alejandro Pérez Méndez, Rafael Marín López, Gabriel López Millán // Future GenerationComputer Systems. – May 2016. – Vol. 58. – P. 13-28. – DOI: https://doi.org/10.1016/j.future.2015.12.0029. Фединишин Т., Михайлова О., Опірський І. Метод визначення потенційно небезпечних осіб по данихBluetooth // Ukrainian Scientific Journal of Information Security. – 2023. – Том 29, Випуск 3. – С. 5.10. Yevseiev, S., Hryshchuk, R., Molodetska, K., et al. (2022). Modeling of Security Systems for CriticalInfrastructure Facilities. PC Technology Center. Available at: [Link or URL if available, e.g., polissiauniver.edu.ua]11. Bhargavan, K., Delignat-Lavaud, A., Fournet, C., Pironti, A., & Strub, P.-Y. (2014). Triple handshakes andcookie cutters: Breaking and fixing authentication over TLS. IEEE Symposium on Security and Privacy (SP), 98–113.https://doi.org/10.1109/SP.2014.1512. Cantor, S., Kemp, J., Philpott, R., & Maler, E. (2005). Assertions and Protocols for the OASIS SecurityAssertion Markup Language (SAML) v2.0. OASIS Standard. Retrieved from https://www.oasis-open.org13. Choudhary, A., & Kesswani, N. (2022). A comparative analysis of OAuth 2.0 and OpenID Connect securityprotocols. Future Generation Computer Systems, 130, 254–266. https://doi.org/10.1016/j.future.2022.01.01814. Cusack, B., & Ghazizadeh, E. (2016). Evaluating single sign-on security failure in cloud services. BusinessHorizons, 59(6), 605–614. https://doi.org/10.1016/j.bushor.2016.08.00215. Hardt, D. (2012). The OAuth 2.0 Authorization Framework. Internet Engineering Task Force (IETF).https://tools.ietf.org/html/rfc6749
МЕТОДИ ПІДВИЩЕННЯ НЕПОМІТНОСТІ ТА СТІЙКОСТІ СТЕГАНОПОВІДОМЛЕНЬ ІЗ ЗАСТОСУВАННЯ ФРАКТАЛЬНИХ РОЗМІРНОСТЕЙ
The article considers modern approaches to increasing the stealth and stability of steganographic methods through theanalysis of fractal properties of digital images. An approach is proposed that is based on identifying areas with high fractaldimension for embedding hidden information. This approach allows you to select areas of the image where hidden data is lessnoticeable for steganography, in particular, for attacks such as compression, noise addition and blurring, which are typical threatsto steganographic systems in real operating conditions. The technique involves the use of a cellular method of calculating fractal dimensions (box-counting), which allows you to quantitatively assess the complexity of local image textures. This makes itpossible to identify areas with a high level of structural heterogeneity, which are optimal for hiding information, since suchareas are less susceptible to visual detection or mathematical analysis. In addition, the use of high-frequency filters (in particular,Sobel and Laplace) allows you to additionally identify areas with high detail that are more resistant to attacks based oncompression (for example, JPEG) or smoothing. A comparative analysis of the effectiveness of steganographic algorithms hasshown that using fractal dimension as a criterion for selecting areas for hiding information allows to increase stealth by 10–15%according to PSNR and SSIM metrics while maintaining acceptable stability to lossy transformations. Studies have shown thata combined approach that combines fractal analysis and frequency processing minimizes the risk of revealing hiddeninformation even after standard image processing. This makes the proposed approach promising for use in highly secureinformation systems, where both concealment of the fact of information transmission and its integrity after possible attacks areimportant.Keywords: steganography, fractal dimension, stealth, stability, stegomessage, digital images, box-counting, highfrequency filters.
References1. Хорошко В. О., Яремчук Ю. Є., Карпінець В. В. Комп'ютерна стеганографія: методи приховуванняінформації у цифрових зображеннях // Науковий вісник ВНТУ. 2021. № 3. С. 45–52. URL: http://ir.lib.vntu.edu.ua(дата звернення: 28.02.2025).2. Мар’єнко О. В., Степаненко О. О. Фрактальний аналіз зображень у медицині та морфології: базовіметоди та перспективи застосування // Morphologia. 2021. Т. 15, № 3. С. 200–207. URL: http://repo.knmu.edu.ua(дата звернення: 28.02.2025).3. Журавель І. М. Вибір налаштувань під час обчислення поля фрактальних розмірностей зображення //Науковий вісник НЛТУ України. 2018. Т. 28, № 2. С. 159–163.4. Дубовик О. В., Коваленко О. В. Методика оцінки стеганографічних методів приховування інформаціїв зображеннях // Системи обробки інформації. 2015. № 2(127). С. 45–48.5. Kaur S., Kaur A. Palette-Based Image Steganography: A Survey // International Journal of ComputerApplications. 2015. Vol. 111, No. 12. P. 1–5.6. Chan C. K., Cheng L. M. Image Steganography Using Pixel Value Differencing and LSB Substitution //Microelectronics Journal. 2016. Vol. 37, No. 7. P. 393–402.7. Pustyulga S. I., Samchuk V. P. Quantitative analysis of null-dimensional (points) multiplicity by methods offractal geometry // Applied Geometry and Engineering Graphics. 2019. № 96. С. 64–72. DOI: 10.32347/0131-579x.2019.96.64-72.8. Журавель Ю. І., Мичуда Л. З. Метод кількісного оцінювання візуальної якості цифрових кольоровихзображень // Сучасний захист інформації. 2024. № 4 (60). С. 39–45. DOI: 10.31673/2409-7292.2024.040004.9. Журавель Ю. І., Мичуда Л. З. Стеганографічний метод приховування інформації з використаннямфрактальних розмірностей зображення // Інформаційні технології і автоматизація – 2024: матеріали XVIIміжнародної науково-практичної конференції, Одеса, 31 жовтня – 1 листопада 2024 р. Одеса: ВидавництвоОНТУ, 2024. С. 191–194.10. Вовк О. О., Астраханцев А. А. Синтез стеганографічного методу передачі даних, ефективного закритеріями надійності та захищеності // Проблеми телекомунікацій. 2015. № 1. С. 45–52. URL: https://visnicct.uu.edu.ua/index.php/icct/article/download/61/18 (дата звернення: 28.02.2025).У статті розглянуто сучасні підходи до підвищення непомітності та стійкості стеганографічних методівчерез аналіз фрактальних властивостей цифрових зображень. Запропоновано підхід, який базується на визначенніобластей із високою фрактальною розмірністю для вбудовування прихованої інформації. Такий підхід дозволяєвибирати ділянки зображення, де приховані дані менш помітні для стеганоаналізу, зокрема, для атак типу стиск,додавання шуму та розмиття, що є типовими загрозами для стеганографічних систем у реальних умовахексплуатації. Методика передбачає застосування клітинного методу обчислення фрактальних розмірностей (boxcounting), який дозволяє кількісно оцінити складність локальних текстур зображення. Це дає змогу виділитиобласті з високим рівнем структурної неоднорідності, що є оптимальними для приховування інформації, оскількитакі зони менш схильні до візуального виявлення або математичного аналізу. Крім того, використаннявисокочастотних фільтрів (зокрема, Собела та Лапласа) дозволяє додатково визначати ділянки з високоюдеталізацією, які стійкіші до атак на основі стискання (наприклад, JPEG) або згладжування. Порівняльний аналізефективності стеганографічних алгоритмів засвідчив, що використання фрактальної розмірності як критеріювибору областей для приховування інформації дозволяє підвищити непомітність на 10–15% за метриками PSNRі SSIM при збереженні прийнятної стійкості до втратних перетворень. Дослідження продемонстрували, щокомбінований підхід, який поєднує фрактальний аналіз і частотну обробку, мінімізує ризик викриття прихованоїінформації навіть після стандартної обробки зображення. Це робить запропонований підхід перспективним длявикористання у високозахищених інформаційних системах, де важливі як приховання факту передаванняінформації, так і її цілісність після можливих атак.Ключові слова: стеганографія, фрактальна розмірність, непомітність, стійкість, стегоповідомлення,цифрові зображення, box-counting, високочастотні фільтри.
Перелік посилань1. Хорошко В. О., Яремчук Ю. Є., Карпінець В. В. Комп'ютерна стеганографія: методи приховуванняінформації у цифрових зображеннях // Науковий вісник ВНТУ. 2021. № 3. С. 45–52. URL: http://ir.lib.vntu.edu.ua(дата звернення: 28.02.2025).2. Мар’єнко О. В., Степаненко О. О. Фрактальний аналіз зображень у медицині та морфології: базовіметоди та перспективи застосування // Morphologia. 2021. Т. 15, № 3. С. 200–207. URL: http://repo.knmu.edu.ua(дата звернення: 28.02.2025).3. Журавель І. М. Вибір налаштувань під час обчислення поля фрактальних розмірностей зображення //Науковий вісник НЛТУ України. 2018. Т. 28, № 2. С. 159–163.4. Дубовик О. В., Коваленко О. В. Методика оцінки стеганографічних методів приховування інформаціїв зображеннях // Системи обробки інформації. 2015. № 2(127). С. 45–48.5. Kaur S., Kaur A. Palette-Based Image Steganography: A Survey // International Journal of ComputerApplications. 2015. Vol. 111, No. 12. P. 1–5.6. Chan C. K., Cheng L. M. Image Steganography Using Pixel Value Differencing and LSB Substitution //Microelectronics Journal. 2016. Vol. 37, No. 7. P. 393–402.7. Pustyulga S. I., Samchuk V. P. Quantitative analysis of null-dimensional (points) multiplicity by methods offractal geometry // Applied Geometry and Engineering Graphics. 2019. № 96. С. 64–72. DOI: 10.32347/0131-579x.2019.96.64-72.8. Журавель Ю. І., Мичуда Л. З. Метод кількісного оцінювання візуальної якості цифрових кольоровихзображень // Сучасний захист інформації. 2024. № 4 (60). С. 39–45. DOI: 10.31673/2409-7292.2024.040004.9. Журавель Ю. І., Мичуда Л. З. Стеганографічний метод приховування інформації з використаннямфрактальних розмірностей зображення // Інформаційні технології і автоматизація – 2024: матеріали XVIIміжнародної науково-практичної конференції, Одеса, 31 жовтня – 1 листопада 2024 р. Одеса: ВидавництвоОНТУ, 2024. С. 191–194.10. Вовк О. О., Астраханцев А. А. Синтез стеганографічного методу передачі даних, ефективного закритеріями надійності та захищеності // Проблеми телекомунікацій. 2015. № 1. С. 45–52. URL: https://visnicct.uu.edu.ua/index.php/icct/article/download/61/18 (дата звернення: 28.02.2025)
ОСНОВНІ ЗАГРОЗИ ІНФОРМАЦІЇ ПРИ ПЕРЕДАЧІ РАДІОКАНАЛОМ ТА МЕТОДИ ЇЇ ЗАХИСТУ
Due to the rapid development and spread of remote-control systems that use a radio channel to transmit commands, theissue of ensuring reliable protection of transmitted data is becoming more urgent. Such systems are actively used in manyindustries, in particular, in automated access control systems, home automation, industry, medicine and in the concept of theInternet of Things. The popularity of radio channel systems is explained by the low cost of implementation, ease ofconfiguration, and the absence of the need to lay cable lines, which significantly simplifies their operation and reduces the initialcosts of installing equipment. However, the use of an open radio channel creates serious risks to information security due to theavailability of the air for interception and interference by third parties. The most relevant are threats to informationconfidentiality (listening and interception of transmitted commands), threats to authenticity (replay attacks that allow you toimitate commands from legitimate transmitters) and threats to data integrity (intentional or accidental distortion of messages inthe transmission channel). The implementation of protection is complicated by the limited technical characteristics of remotecontrol devices with small computing resources and energy constraints. The paper analyzes the above threats and proposes a setof effective methods for protecting information. It is recommended to use hybrid cryptographic schemes that combine symmetricand asymmetric crypto algorithms with the formation of unique session keys to ensure the confidentiality of data transmission.To protect authenticity, it is proposed to use time stamps and one-time pseudo-random identifiers, which significantly reducesthe likelihood of successful implementation of replay attacks. To ensure the integrity of information, it is recommended to usenoise-resistant coding, in particular, the Reed-Solomon code, which allows not only to detect, but also to effectively correcterrors that arise as a result of external influences or intentional interference in the operation of the radio channel.Keywords: remote control, radio channel, encryption, authentication, replay, noise-resistant coding.
References1. Investigating Radio Frequency Vulnerabilities in the Internet of Things (IoT) / E. Anthi et al. IoT. 2024. Vol.5, no. 2. P. 356—380. URL: https://doi.org/10.3390/iot5020018 (date of access: 08.11.2024).2. Resistance to Replay Attacks of Remote Control Protocols using the 433 MHz Radio Channel / A. Stefankivet al. Cybersecurity Providing in Information and Telecommunication Systems 2024. 2024. Vol. 3654, no. 1. P. 98–110.3. Pichamuthu R., Sathishkumar A., Khadirkumar N. An Enhanced Deep Learning Approach for PreventingReplay Attacks in Wireless Sensor Network. Solid State Technology. 2020. Vol. 63, no. 4. P. 8010—80234. RFC 8017. PKCS #1: RSA Cryptography Specifications Version 2.2. Replaces RFC 3447 ; effective from2016-11-01. Official edition. Fremont, CA : IETF, 2016. 78 p. URL: https://datatracker.ietf.org/doc/html/rfc8017.5. Pointcheval D. How to encrypt properly with RSA. RSA Laboratories CryptoBytes. 2002. Vol. 5, no. 1. P. 9—19.6. Elgamal T. A public key cryptosystem and a signature scheme based on discrete logarithms. IEEE Transactionson Information Theory. 1985. Vol. 31, no. 4. P. 469—472. URL: https://doi.org/10.1109/tit.1985.1057074 (date of access:08.11.2024).7. Rivest R. L., Shamir A., Adleman L. A method for obtaining digital signatures and public-key cryptosystems.Communications of the ACM. 1978. Vol. 21, no. 2. P. 120—126. URL: https://doi.org/10.1145/359340.359342 (date ofaccess: 08.11.2024).8. FIPS 197. Advanced Encryption Standard (AES). Replaces FIPS 197 (11/26/2001) ; effective from 2023-05-09. Official edition. Gaithersburg, MA : NIST, 2023. 46 p. URL: https://doi.org/10.6028/NIST.FIPS.197-upd1.9. FIPS 46-3. Data Encryption Standard (DES). Replaces FIPS 46-2 ; effective from 1999-10-25. Official edition.Gathiersburg, MA : NIST, 1999. 27 p.10. Schneier B. The Blowfish Encryption Algorithm. Dr. Dobb’s Journal. 1994. Vol. 19, no. 4. P. 38—40.11. Twofish: A 128-Bit Block Cipher / B. Schneier et al. Schneier on Security. URL:https://www.schneier.com/wp-content/uploads/2016/02/paper-twofish-paper.pdf (date of access: 08.11.2024).12. Massey J. L., Lai X. A Proposal for a New Block Encryption Standard. Advances in Cryptology —EUROCRYPT '90. Lecture Notes in Computer Science. 1991. Vol. 473, no. 1. P. 389—404.13. GnuPG. GnuPG. Version 2.5.1. 2024. URL: https://gnupg.org/index.html (date of access: 08.11.2024).14. dm-crypt — The Linux Kernel documentation. The Linux Kernel documentation — The Linux Kerneldocumentation. URL: https://docs.kernel.org/admin-guide/device-mapper/dm-crypt.html (date of access: 08.11.2024).15. BitLocker overview. Microsoft Learn: Build skills that open doors in your career. URL:https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/ (date of access:08.11.2024).16. IDRIX. VeraCrypt. Version 1.26.15. Paris: IDRIX, 2024. URL: https://veracrypt.fr (date of access:08.11.2024).17. Гарасимчук О. І., Максимович В. М. Генератори псевдовипадкових чисел, їх застосування,класифікація, основні методи побудови і оцінка якості. Ukrainian Information Security Research Journal. 2003. Т. 5,№ 3(16). URL: https://doi.org/10.18372/2410-7840.5.4270 (дата звернення: 08.11.2024).18. Хомік М., Гарасимчук О. АНАЛІЗ ЗАГРОЗ ДЛЯ ГЕНЕРАТОРІВ ПСЕВДОВИПАДКОВИХ ЧИСЕЛ ІПСЕВДОВИПАДКОВИХ ПОСЛІДОВНОСТЕЙ ТА ЗАХОДИ ЗАХИСТУ. Ukrainian Information Security ResearchJournal. 2023. Т. 25, № 4. С. 172—184. URL: https://doi.org/10.18372/2410-7840.25.18222 (дата звернення:08.11.2024).19. Івашко А. В. Теорія інформації та кодування в прикладах і задачах : навч. посібник / А. В. Івашко, В.А. Крилова ; Нац. техн. ун-т "Харків. політехн. ін-т". – Харків : НТУ "ХПІ", 2022. – 317 с.20. Kuila B. Design and Implementation of RS (255, 223) Detecting Code in FPGA. International Journal ofComputer Applications. 2015. Vol. 123, no. 9. P. 33-39. URL: https://discovery.researcher.life/download/article/ecde86c509123e8ba804da34f30903f0/full-text (date of access: 08.11.2024).21. Czynszak S. Decoding algorithms of Reed-Solomon code: магістерська робота. Karlskrona, 2011. 125 p.URL: https://www.diva-portal.org/smash/get/diva2:833161/FULLTEXT01.pdf (date of access: 08.11.2024).22. Chien R. Cyclic decoding procedures for Bose- Chaudhuri-Hocquenghem codes. IEEE Transactions onInformation Theory. 1964. Vol. 10, no. 4. P. 357–363. URL: https://doi.org/10.1109/tit.1964.1053699 (date of access:08.11.2024).23. Forney G. On decoding BCH codes. IEEE Transactions on Information Theory. 1965. Vol. 11, no. 4. P. 549–557. URL: https://doi.org/10.1109/tit.1965.1053825 (date of access: 08.11.2024).У зв’язку зі стрімким розвитком і поширенням систем дистанційного керування, які використовуютьрадіоканал для передачі команд, актуалізується питання забезпечення надійного захисту переданих даних. Такісистеми активно застосовуються у багатьох галузях, зокрема, в автоматизованих системах управління доступом,домашній автоматизації, промисловості, медицині та у концепції інтернету речей. Популярність радіоканальнихсистем пояснюється низькою вартістю впровадження, простотою налаштування, відсутністю потреби упрокладанні кабельних ліній, що істотно спрощує їх експлуатацію та знижує початкові витрати на встановленняобладнання. Однак використання відкритого радіоканалу створює серйозні ризики інформаційній безпеці черездоступність ефіру для перехоплення та втручання сторонніх осіб. Найбільш актуальними є загрозиконфіденційності інформації (прослуховування і перехоплення переданих команд), загрози автентичності (атакиповторного відтворення, що дозволяють імітувати команди легітимних передавачів) та загрози цілісності даних(умисне або випадкове спотворення повідомлень у каналі передачі). Реалізація захисту ускладнюєтьсяобмеженими технічними характеристиками пристроїв дистанційного керування, що мають малі обчислювальніресурси та енергетичні обмеження. У роботі проведено аналіз зазначених загроз та запропоновано комплексефективних методів захисту інформації. Рекомендується використання гібридних криптографічних схем, якіпоєднують симетричні та асиметричні криптоалгоритми з формуванням унікальних сесійних ключів длязабезпечення конфіденційності передачі даних. Для захисту автентичності пропонується застосування часовихміток і одноразових псевдовипадкових ідентифікаторів, що суттєво знижує ймовірність успішної реалізації атакповторного відтворення. Для забезпечення цілісності інформації рекомендовано застосовувати завадостійкекодування, зокрема, код Ріда-Соломона, який дозволяє не тільки виявляти, але й ефективно коригувати помилки,що виникають внаслідок зовнішніх впливів або навмисних втручань у роботу радіоканалу.Ключові слова: дистанційне керування, радіоканал, шифрування, автентифікація, повторне відтворення,завадостійке кодування.
Список використаних джерел1. Investigating Radio Frequency Vulnerabilities in the Internet of Things (IoT) / E. Anthi et al. IoT. 2024. Vol.5, no. 2. P. 356—380. URL: https://doi.org/10.3390/iot5020018 (date of access: 08.11.2024).2. Resistance to Replay Attacks of Remote Control Protocols using the 433 MHz Radio Channel / A. Stefankivet al. Cybersecurity Providing in Information and Telecommunication Systems 2024. 2024. Vol. 3654, no. 1. P. 98–110.3. Pichamuthu R., Sathishkumar A., Khadirkumar N. An Enhanced Deep Learning Approach for PreventingReplay Attacks in Wireless Sensor Network. Solid State Technology. 2020. Vol. 63, no. 4. P. 8010—80234. RFC 8017. PKCS #1: RSA Cryptography Specifications Version 2.2. Replaces RFC 3447 ; effective from2016-11-01. Official edition. Fremont, CA : IETF, 2016. 78 p. URL: https://datatracker.ietf.org/doc/html/rfc8017.5. Pointcheval D. How to encrypt properly with RSA. RSA Laboratories CryptoBytes. 2002. Vol. 5, no. 1. P. 9—19.6. Elgamal T. A public key cryptosystem and a signature scheme based on discrete logarithms. IEEE Transactionson Information Theory. 1985. Vol. 31, no. 4. P. 469—472. URL: https://doi.org/10.1109/tit.1985.1057074 (date of access:08.11.2024).7. Rivest R. L., Shamir A., Adleman L. A method for obtaining digital signatures and public-key cryptosystems.Communications of the ACM. 1978. Vol. 21, no. 2. P. 120—126. URL: https://doi.org/10.1145/359340.359342 (date ofaccess: 08.11.2024).8. FIPS 197. Advanced Encryption Standard (AES). Replaces FIPS 197 (11/26/2001) ; effective from 2023-05-09. Official edition. Gaithersburg, MA : NIST, 2023. 46 p. URL: https://doi.org/10.6028/NIST.FIPS.197-upd1.9. FIPS 46-3. Data Encryption Standard (DES). Replaces FIPS 46-2 ; effective from 1999-10-25. Official edition.Gathiersburg, MA : NIST, 1999. 27 p.10. Schneier B. The Blowfish Encryption Algorithm. Dr. Dobb’s Journal. 1994. Vol. 19, no. 4. P. 38—40.11. Twofish: A 128-Bit Block Cipher / B. Schneier et al. Schneier on Security. URL:https://www.schneier.com/wp-content/uploads/2016/02/paper-twofish-paper.pdf (date of access: 08.11.2024).12. Massey J. L., Lai X. A Proposal for a New Block Encryption Standard. Advances in Cryptology —EUROCRYPT '90. Lecture Notes in Computer Science. 1991. Vol. 473, no. 1. P. 389—404.13. GnuPG. GnuPG. Version 2.5.1. 2024. URL: https://gnupg.org/index.html (date of access: 08.11.2024).14. dm-crypt — The Linux Kernel documentation. The Linux Kernel documentation — The Linux Kerneldocumentation. URL: https://docs.kernel.org/admin-guide/device-mapper/dm-crypt.html (date of access: 08.11.2024).15. BitLocker overview. Microsoft Learn: Build skills that open doors in your career. URL:https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/ (date of access:08.11.2024).16. IDRIX. VeraCrypt. Version 1.26.15. Paris: IDRIX, 2024. URL: https://veracrypt.fr (date of access:08.11.2024).17. Гарасимчук О. І., Максимович В. М. Генератори псевдовипадкових чисел, їх застосування,класифікація, основні методи побудови і оцінка якості. Ukrainian Information Security Research Journal. 2003. Т. 5,№ 3(16). URL: https://doi.org/10.18372/2410-7840.5.4270 (дата звернення: 08.11.2024).18. Хомік М., Гарасимчук О. АНАЛІЗ ЗАГРОЗ ДЛЯ ГЕНЕРАТОРІВ ПСЕВДОВИПАДКОВИХ ЧИСЕЛ ІПСЕВДОВИПАДКОВИХ ПОСЛІДОВНОСТЕЙ ТА ЗАХОДИ ЗАХИСТУ. Ukrainian Information Security ResearchJournal. 2023. Т. 25, № 4. С. 172—184. URL: https://doi.org/10.18372/2410-7840.25.18222 (дата звернення:08.11.2024).19. Івашко А. В. Теорія інформації та кодування в прикладах і задачах : навч. посібник / А. В. Івашко, В.А. Крилова ; Нац. техн. ун-т "Харків. політехн. ін-т". – Харків : НТУ "ХПІ", 2022. – 317 с.20. Kuila B. Design and Implementation of RS (255, 223) Detecting Code in FPGA. International Journal ofComputer Applications. 2015. Vol. 123, no. 9. P. 33-39. URL: https://discovery.researcher.life/download/article/ecde86c509123e8ba804da34f30903f0/full-text (date of access: 08.11.2024).21. Czynszak S. Decoding algorithms of Reed-Solomon code: магістерська робота. Karlskrona, 2011. 125 p.URL: https://www.diva-portal.org/smash/get/diva2:833161/FULLTEXT01.pdf (date of access: 08.11.2024).22. Chien R. Cyclic decoding procedures for Bose- Chaudhuri-Hocquenghem codes. IEEE Transactions onInformation Theory. 1964. Vol. 10, no. 4. P. 357–363. URL: https://doi.org/10.1109/tit.1964.1053699 (date of access:08.11.2024).23. Forney G. On decoding BCH codes. IEEE Transactions on Information Theory. 1965. Vol. 11, no. 4. P. 549–557. URL: https://doi.org/10.1109/tit.1965.1053825 (date of access: 08.11.2024)
ЕКСПЕРИМЕНТАЛЬНЕ ДОСЛІДЖЕННЯ, ПРОГРАМНА РЕАЛІЗАЦІЯ ТА ОЦІНКА ЕФЕКТИВНОСТІ ЗАСТОСУВАННЯ МЕТОДУ ЗАХИСТУ ПРОГРАМНОГО ЗАБЕЗПЕЧЕННЯ НА ОСНОВІ ГІБРИДНОГО АНАЛІЗУ
The growth of cyber threats, especially in the context of the active spread of malicious software, leads to seriousconsequences, including unauthorized access to confidential systems, mass theft or loss of critical data, as well as theirencryption for the purpose of extortion. These events not only cause significant economic damage, but are also classified ascriminal offenses in many jurisdictions, which emphasizes their legal and social significance. In this context, software protectionhas acquired strategic importance, especially at the stages of its development, when it is possible to proactively prevent potentialvulnerabilities. Modern methods of code analysis, in particular static and dynamic, demonstrate significant limitations in thefight against polymorphic and metamorphic malware. Static analysis, based on signatures, is unable to effectively detect newforms of threats due to the lag of virus databases and a high rate of false positives. Dynamic analysis, although it allows tocapture behavioral signs of malicious code, is resource-intensive, slows down the testing process and is sensitive to antiemulation techniques that hide the true nature of the threat. To overcome these problems, a hybrid code analysis method isproposed, which synergistically combines the advantages of static, dynamic and semantic approaches. This approach providescomprehensive threat detection based on simultaneous analysis of the code structure and its behavior during execution, whichsignificantly increases the accuracy of detection, reduces the number of false positives and provides a wider coverage of potentialrisks. Of particular importance is its application for early detection of threats in widely used open-source libraries, where supplychain risks are the highest. The implementation of hybrid analysis provides a significant increase in the overall level of softwaresecurity, optimization of testing costs, reduction of verification time and increased confidence in the results obtained. Thisdirection is especially relevant for large-scale projects with microservice architecture and intensive use of open-source components, where the need for reliable protection against evolving cyber threats is critically important. Thus, the developmentand practical implementation of hybrid code analysis is of scientific and applied value in ensuring cyber resilience of modernand promising information systems.Keywords: malware, software protection, static code analysis, dynamic code analysis, hybrid code analysis, securityvulnerabilities, malicious patterns, polymorphic viruses, code security.
References1. Захисний комплекс Microsoft / Що таке шкідливе програмне забезпечення? https://www.microsoft.com/uk-ua/security/business/security-101/what-is-malware.2. Python Type Checking. URL: https://testdriven.io/blog/python-typechecking/ (дата звернення 16.04.2024).3. Delmas, D. (2022). Static analysis of program portability by abstract interpretation (Doctoral dissertation).Sorbonne Université.4. Generating and using a Callgraph, in Python. URL: https://cerfacs.fr/coop/pycallgraph (дата звернення16.04.2024).5. Data Flow Analysis. URL: https://www.codingninjas.com/studio/library/data-flow-analysis (дата звернення16.04.2024).6. Python Control Flow Statements and Loops. URL: https://pynative.com/python-control-flow-statements/ (датазвернення 16.04.2024).7. Akhtar, M. S., & Feng, T. (2022). Malware analysis and detection using machine learning algorithms.Symmetry, 14(11), 2304. URL: https://doi.org/10.3390/sym14112304 (дата звернення 16.04.2024).8. Monat, R., Ouadjaout, A., Miné, A. (2021). A Multilanguage Static Analysis of Python Programs with NativeC Extensions. In: Drăgoi, C., Mukherjee, S., Namjoshi, K. Static Analysis. SAS 2021. Lecture Notes in ComputerScience(), vol 12913. Springer, Cham. URL: https://doi.org/10.1007/978-3-030-88806-0_16.9. Infographic Open source linters, tools for code analysis 2021. URL: https://www.promyze.com/open-sourcelinters-2021/ (дата звернення 16.04.2024).10. Vassallo, C., Panichella, S., Palomba, F., et al. (2020). How developers engage with static analysis tools indifferent contexts. Empirical Software Engineering, 25, 1419-1457.11. B. Chess and G. McGraw, “Static analysis for security,” in IEEE Security & Privacy, vol. 2, no. 6, pp. 76-79,Nov.-Dec. 2004, doi: 10.1109/MSP.2004.111.12. Лаптєв, О. А., Колесник, В. В., Ровда, В. В., & Половінкін, М. І. Метод підвищення захисту особистихданих за рахунок синтезу резильєнтних віртуальних спільнот. 2024. Сучасний захист інформації. 4(60). С. 141-146. https://doi.org/10.31673/2409-7292.2024.040015.13. Лаптєв О.А., Марченко В.В. Застосування завад для захисту інформації від витоку радіоканалом.Сучасний захист інформації. 2025. №1. С.89-97. https://doi.org/10.31673/2409-7292.2025.013057.14. Дробик О. В., Лаптєв О. А., Пархоменко І. І., Богуславська О. В., Пепа Ю. В., Пономаренко В. В.Розпізнавання радіосигналів на основі апроксимації спектральної функції у базисі передатних функційрезонансних ланок другого порядку. Сучасний захист інформації. 2024. №2. С.13-23. https://doi.org/10.31673/2409-7292.2024.020002.15. Аль-Дальваш А., Петченко М.В., Лаптєв О.А. Метод детектування цифрових радіосигналів задопомогою диференціального перетворення. Сучасний захист інформації. 2025. №1. С.285-291. https://doi.org/10.31673/2409-7292.2025.014329.Зростання кіберзагроз, особливо в умовах активного поширення шкідливого програмного забезпечення,призводить до серйозних наслідків, серед яких несанкціонований доступ до конфіденційних систем, масовевикрадення або втрата критичних даних, а також їх шифрування з метою вимагання. Ці події не лише завдаютьзначної економічної шкоди, але й кваліфікуються як кримінальні правопорушення в багатьох юрисдикціях, щопідкреслює їхню правову та соціальну значущість. У цьому контексті захист програмного забезпечення набувстратегічного значення, особливо на етапах його розробки, коли є можливість проактивного запобіганняпотенційним вразливостям. Сучасні методи аналізу коду, зокрема статичний і динамічний, демонструють суттєвіобмеження у боротьбі з поліморфним та метаморфним шкідливим ПЗ. Статичний аналіз, спираючись насигнатури, не в змозі ефективно виявляти нові форми загроз через відставання баз даних вірусів та високий рівеньхибнопозитивних результатів. Динамічний аналіз, хоча й дозволяє фіксувати поведінкові ознаки шкідливогокоду, є ресурсомістким, уповільнює процес тестування та чутливий до антиемуляційних технік, що приховуютьсправжню природу загрози. Для подолання цих проблем пропонується гібридний метод аналізу коду, якийсинергетично поєднує переваги статичного, динамічного та семантичного підходів. Такий підхід забезпечуєкомплексне виявлення загроз на основі одночасного аналізу структури коду та його поведінки під час виконання,що суттєво підвищує точність детектування, зменшує кількість помилкових результатів і забезпечує ширшеохоплення потенційних ризиків. Особливе значення має його застосування для раннього виявлення небезпек ушироко використовуваних бібліотеках з відкритим кодом, де ризики ланцюга поставок є найвищими.Впровадження гібридного аналізу забезпечує суттєве підвищення загального рівня безпеки програмногозабезпечення, оптимізацію витрат на тестування, скорочення часу на верифікацію та підвищення довіри доотриманих результатів. Цей напрямок є особливо актуальним для великомасштабних проектів із мікросервісноюархітектурою та інтенсивним використанням open-source компонентів, де потреба в надійному захисті відеволюціонуючих кіберзагроз є критично важливою. Таким чином, розвиток і практичне впровадженнягібридного аналізу коду становить наукову та прикладну цінність у забезпеченні кіберстійкості сучасних іперспективних інформаційних систем.Ключові слова: шкідливе програмне забезпечення, захист програмного забезпечення, статичний аналізкоду, динамічний аналіз коду, гібридний аналіз коду, вразливості безпеки, шкідливі паттерни, поліморфні віруси,безпека коду.
Перелік посилань1. Захисний комплекс Microsoft / Що таке шкідливе програмне забезпечення? https://www.microsoft.com/uk-ua/security/business/security-101/what-is-malware.2. Python Type Checking. URL: https://testdriven.io/blog/python-typechecking/ (дата звернення 16.04.2024).3. Delmas, D. (2022). Static analysis of program portability by abstract interpretation (Doctoral dissertation).Sorbonne Université.4. Generating and using a Callgraph, in Python. URL: https://cerfacs.fr/coop/pycallgraph (дата звернення16.04.2024).5. Data Flow Analysis. URL: https://www.codingninjas.com/studio/library/data-flow-analysis (дата звернення16.04.2024).6. Python Control Flow Statements and Loops. URL: https://pynative.com/python-control-flow-statements/ (датазвернення 16.04.2024).7. Akhtar, M. S., & Feng, T. (2022). Malware analysis and detection using machine learning algorithms.Symmetry, 14(11), 2304. URL: https://doi.org/10.3390/sym14112304 (дата звернення 16.04.2024).8. Monat, R., Ouadjaout, A., Miné, A. (2021). A Multilanguage Static Analysis of Python Programs with NativeC Extensions. In: Drăgoi, C., Mukherjee, S., Namjoshi, K. Static Analysis. SAS 2021. Lecture Notes in ComputerScience(), vol 12913. Springer, Cham. URL: https://doi.org/10.1007/978-3-030-88806-0_16.9. Infographic Open source linters, tools for code analysis 2021. URL: https://www.promyze.com/open-sourcelinters-2021/ (дата звернення 16.04.2024).10. Vassallo, C., Panichella, S., Palomba, F., et al. (2020). How developers engage with static analysis tools indifferent contexts. Empirical Software Engineering, 25, 1419-1457.11. B. Chess and G. McGraw, “Static analysis for security,” in IEEE Security & Privacy, vol. 2, no. 6, pp. 76-79,Nov.-Dec. 2004, doi: 10.1109/MSP.2004.111.12. Лаптєв, О. А., Колесник, В. В., Ровда, В. В., & Половінкін, М. І. Метод підвищення захисту особистихданих за рахунок синтезу резильєнтних віртуальних спільнот. 2024. Сучасний захист інформації. 4(60). С. 141-146. https://doi.org/10.31673/2409-7292.2024.040015.13. Лаптєв О.А., Марченко В.В. Застосування завад для захисту інформації від витоку радіоканалом.Сучасний захист інформації. 2025. №1. С.89-97. https://doi.org/10.31673/2409-7292.2025.013057.14. Дробик О. В., Лаптєв О. А., Пархоменко І. І., Богуславська О. В., Пепа Ю. В., Пономаренко В. В.Розпізнавання радіосигналів на основі апроксимації спектральної функції у базисі передатних функційрезонансних ланок другого порядку. Сучасний захист інформації. 2024. №2. С.13-23. https://doi.org/10.31673/2409-7292.2024.020002.15. Аль-Дальваш А., Петченко М.В., Лаптєв О.А. Метод детектування цифрових радіосигналів задопомогою диференціального перетворення. Сучасний захист інформації. 2025. №1. С.285-291. https://doi.org/10.31673/2409-7292.2025.014329
ШТУЧНИЙ ІНТЕЛЕКТ У КІБЕРБЕЗПЕЦІ КРИТИЧНОЇ ІНФРАСТРУКТУРИ: ПІДХОДИ, ОЦІНКА СТАНУ ТА ПЕРСПЕКТИВИ РОЗВИТКУ
The article presents a detailed analysis of modern approaches, an assessment of the current state and prospects for thedevelopment of artificial intelligence (AI technologies, AI systems and AI tools) in ensuring the cybersecurity of criticalinfrastructure both at the industry/sectoral levels and at the level of individual facilities. It is emphasized that in the conditionsof rapid growth of digital dependence and the spread of hybrid threats, the issue of protecting critical infrastructure (energy,telecommunications, transport, medical sectors, water supply, etc.) is gaining strategic importance for ensuring national security,state stability and the stability of social processes. The application of AI (AI technologies, AI systems and AI tools) in the fieldof cybersecurity of critical infrastructure demonstrates a transformative impact on the processes of detecting, identifying andneutralizing cyber threats. It was noted that AI (AI technologies, AI systems and AI tools) provides a significant increase in thespeed of processing large amounts of data, allows you to accurately identify anomalous actions in networks, predict behavioralpatterns of attackers and provide automated response to incidents. At the same time, it was emphasized that the complexity ofprotecting critical infrastructure is due to the integration of IT systems with industrial control systems and operationaltechnologies, which require specific methods of monitoring, control and management. The close intertwining oftelecommunication networks with networks of production processes and management processes complicates protection and creates the need for specialized AI tools. It was noted that key approaches to the application of AI in cybersecurity - in particular,machine learning for early detection of anomalies, automated SOAR technologies for incident response, as well as SCADA/ICSvulnerability assessment methods - are already successfully used in practice and prove their effectiveness in conditions of realthreats. Special attention is paid to assessing the state of security using AI, which allows not only to promptly respond to activeattacks, but also to predict possible paths of their evolution, ensuring proactive protection. Promising directions for thedevelopment of the AI market in the field of cyber defense of critical infrastructure are considered. Among them, the expansionof the use of autonomous cyber-immune systems focused on creating self-learning and self-managed security environments ishighlighted; further market segmentation and development of specialized AI for individual sectors of critical infrastructure;integration of AI into complex corporate security ecosystems. A number of recommendations are proposed aimed at increasingthe efficiency and resilience of the critical infrastructure cybersecurity system. Key recommendations include: activeimplementation of hybrid systems "AI + human control" to ensure the optimal combination of automation and expert assessment;regular updating and adaptation of AI models to new types of threats; investing in the development of human capital throughtraining and advanced training of specialists in the field of AI and cybersecurity; harmonizing national approaches withinternational standards (in particular, NIST CSF and ISO/IEC 27001); forming state programs for integrating AI into the criticalinfrastructure protection system; actively expanding international cooperation focused on exchanging information about cyberthreats and best practices in the use of AI. It is emphasized that effective inter-sectoral, inter-sectoral and interstate interactionof expert communities is a key condition for building a modern, adaptive and sustainable system of cyber protection of criticalinfrastructure, capable of withstanding the growing challenges of the digital age.Keywords: cybersecurity, critical infrastructure, cyber-physical systems, artificial intelligence, machine learning, threatdetection, response automation.
References1. Держспецзв’язку презентували інструмент оцінки кібербезпеки для українських організацій. 2024.https://ain.ua/2024/09/30/instrument-ocinki-kiberbezpeki/.2. Держспецзв’язку провела презентацію інструменту оцінки кібербезпеки CSET (Cybersecurity EvaluationTool) та провела практичне заняття з його використання. 2024. https://delo.ua/telecom/derzspeczvyazkuprezentuvala-novii-instrument-ocinki-kiberbezpeki-436947/.3. Зоря І.С., Марущак А. В. застосування штучного інтелекту для виявлення та реагування накіберзагрози. 2024. http://ir.lib.vntu.edu.ua/bitstream/handle/123456789/42057/20610.pdf?sequence=3&isAllowed=y .4. Інструмент оцінки кібербезпеки (CSET). https://www.cisa.gov/resources-tools/services/cyber-securityevaluation-tool-cset.5. Інструмент оцінки кібербезпеки CSET. https://csirt.csi.cip.gov.ua/uk/pages/cset .6. Мануілов Я.С. Забезпечення кібербезпеки об’єктів критичної інфраструктури в умовах кібервійни.Інформація і право. № 1(44)/2023. С.154-163.7. Нормативно-правова база у сфері захисту об'єктів критичної інфраструктури України.https://csirt.csi.cip.gov.ua/uk/pages/cio.8. Подвійні переваги штучного інтелекту в кібербезпеці: висновки зі звіту Benchmark Survey за 2024 рік.2024. https://hyperproof.io/resource/ai-in-cybersecurity-2024-benchmark-report/.9. Про затвердження Положення про організаційно-технічну модель кіберзахисту : постанова КабінетуМіністрів України від 29.12.2021 № 1426. https://zakon.rada.gov.ua/laws/show/1426-2021-%D0%BF#Text.10. Про критичну інфраструктуру : закон України від 16.11.2021 № 1882-ІХ. Відомості Верховної Ради(ВВР), 2023, № 5, ст.13. https://zakon.rada.gov.ua/laws/show/1882-20#Text.11. Пуаро К. Огляд тенденцій кібер-штучного інтелекту: підготовка до 2025 року. 2024.https://www.infosecurity-magazine.com/news-features/cyber-ai-trends-review-preparing/.12. Федорченко О.С. Роль штучного інтелекту у забезпеченні кібербезпеки України: сучасний стан таперспективи розвитку. Інформація і право. № 3(54)/2025. С.139-146. DOI: https://doi.org/10.37750/2616-6798.2025.3(54).340521. http://il.ippi.org.ua/article/view/340521 .13. Як AI захищає критичну інфраструктуру України: все про кібербезпеку OT/ICS. 2025. https://neoversity.com.ua/blog/yak-ai-zahishchaie-kritichnu-infrastrukturu-ukrayini-vse-pro-kiberbezpeku-ot-ics.14. AIxCC: AI Cyber Challenge / Defense Advanced Research Projects Agency. Arlington, VA : DARPA, 2024.https://www.darpa.mil/research/programs/ai-cyber .15. Artificial Intelligence and Cybersecurity / European Union Agency for Cybersecurity. Athens : ENISA, 2024.62p. https://www.enisa.europa.eu/publications/artificial-intelligence-and-cybersecurity .16. Artificial Intelligence: DHS Needs to Improve Risk Assessment Guidance for Critical Infrastructure Sectors /U.S. Government Accountability Office. Washington, DC : GAO, 2024. 42p. (GAO-25-107435). https://www.gao.gov/assets/gao-25-107435.pdf .17. Assess the current state of the cybersecurity program and identify capability gaps. (Оцінити поточний станпрограми кібербезпеки та виявити прогалини в можливостях) 2024. https://www.gartner.com/en/ cybersecurity/topics/cybersecurity-roadmap.18. CISA's 2024 Year in Review / Cybersecurity and Infrastructure Security Agency. Washington, DC : CISA,2024. 80p. https://www.cisa.gov/sites/default/files/2024-12/CSAC%20Annual%20Report_20241210.pdf .19. Crichton, K. Securing Critical Infrastructure in the Age of AI / K. Crichton, J. Baker, A. Luedtke // Center forSecurity and Emerging Technology. Washington, DC : CSET, 2024. 58p. https://cset.georgetown.edu/wpcontent/uploads/CSET-Securing-Critical-Infrastructure-in-the-Age-of-AI.pdf.20. Cyber AI Trends Review: Preparing for 2025 / Infosecurity Magazine. London : Infosecurity Magazine, 2025.https://www.infosecurity-magazine.com/news-features/cyber-ai-trends-review-preparing/.21. DHS Artificial Intelligence Roadmap / Department of Homeland Security. Washington, DC : DHS, 2024. 36p.https://www.dhs.gov/sites/default/files/2024-03/24_0315_ocio_roadmap_artificialintelligence-ciov3-signed-508.pdf .22. DHS Highlights AI as a Threat and Asset to Critical Infrastructure in New Priority Guidance / Nextgov/FCW.Washington, DC : Nextgov/FCW, 2024. https://www.nextgov.com/cybersecurity/2024/06/dhs-highlights-ai-threat-andasset-critical-infrastructure-new-priority-guidance/397524/ .23. Emerging Threats to Critical Infrastructure: AI Driven Cybersecurity Trends for 2025 / Capitol TechnologyUniversity. Laurel, MD : Capitol Technology University, 2024. https://www.captechu.edu/blog/ai-driven-cybersecuritytrends-2025 .24. Gartner states that in the GenAI era, the future of cybersecurity lies in prevention rather than detection andresponse. 2025. https: // www.gartner.com/en/newsroom / press-releases / 2025-09-18-gartner-says-that-in-the-age-ofgenai-preemptive-capabilities-not-detection-and-response-are-the-future-of-cybersecurity.25. Idaho National Laboratory. Cyber Security Evaluation Tool (CSET) User Guide. https://inl.gov/wpcontent/uploads/2020/06/CSET-User-Guide.pdf.26. Safety and Security Guidelines for Critical Infrastructure Sector Owners and Operators / Department ofHomeland Security. Washington, DC : DHS, 2024. 24p. https://www.dhs.gov/sites/default/files/2024-04/24_0426_dhs_ai-ci-safety-security-guidelines-508c.pdf .27. The Cybersecurity Provider's Next Opportunity: Making AI Safer / McKinsey & Company. New York :McKinsey & Company, 2024. https: // www.mckinsey.com / capabilities / risk-and-resilience/our-insights/thecybersecurity-providers-next-opportunity-making-ai-safer .28. The Dual Edges of AI in Cybersecurity: Insights from the 2024 Benchmark Survey Report / Hyperproof.Seattle, WA : Hyperproof, 2024. https://hyperproof.io/resource/ai-in-cybersecurity-2024-benchmark-report/ .29. What is Operational Technology (OT) Cyber Security?. https://www.axians.co.uk/glossary/what-isoperational-technology-security/#:~:text=Operational%20Technology%20(OT)%20security%2C,vulnerabilities%20from%202017%20to%20У статті представлено розгорнутий аналіз сучасних підходів, оцінки поточного стану та перспективрозвитку штучного інтелекту (ШІ-технологій, ШІ-систем та інструментів ШІ) у забезпеченні кібербезпекикритичної інфраструктури як на галузевому/секторальному рівнях, так і на рівні окремих об’єктів. Підкреслено,що в умовах стрімкого зростання цифрової залежності та поширення гібридних загроз питання захисту критичноїінфраструктури (енергетична, телекомунікаційна, транспортна, медична сфери, водопостачання тощо) набуваєстратегічного значення для забезпечення національної безпеки, стійкості держави та стабільності суспільнихпроцесів. Застосування ШІ (ШІ-технологій, ШІ-систем та інструментів ШІ) у сфері кібербезпеки критичноїінфраструктури демонструє трансформаційний вплив на процеси виявлення, ідентифікації та нейтралізаціїкіберзагроз. Відзначено, що ШІ (ШІ-технології, ШІ-системи та інструменти ШІ) забезпечує суттєве підвищенняшвидкості обробки великих обсягів даних, дозволяє точно визначати аномальні дії у мережах, прогнозуватиповедінкові патерни зловмисників і забезпечувати автоматизовану реакцію на інциденти. Водночас підкреслено,що складність захисту критичної інфраструктури зумовлена інтеграцією ІТ-систем із промисловими системамикерування та операційними технологіями, які вимагають специфічних методів моніторингу, контролю тауправління. Тісне переплетіння телекомунікаційних мереж із мережами виробничих процесів та процесівуправління, ускладнює захист і формує потребу у спеціалізованих інструментах ШІ. Відзначено, що ключовіпідходи до застосування ШІ в кібербезпеці – зокрема, машинне навчання для раннього виявлення аномалій,автоматизовані технології SOAR для реагування на інциденти, а також методики оцінки вразливостейSCADA/ICS – вже успішно використовуються на практиці та доводять свою результативність в умовах реальнихзагроз. Окрему увагу приділено оцінюванню стану безпеки з використанням ШІ, що дозволяє не лише оперативнореагувати на активні атаки, а й прогнозувати можливі шляхи їх еволюції, забезпечуючи випереджувальнийхарактер захисту. Розглянуто перспективні напрями розвитку ринку ШІ у сфері кіберзахисту критичноїінфраструктури. Серед них виокремлено розширення застосування автономних кіберімунних систем,орієнтованих на створення самонавчальних і самокерованих середовищ безпеки; подальшу сегментацію ринкута розроблення спеціалізованих ШІ для окремих секторів критичної інфраструктури; інтеграцію ШІ у комплекснікорпоративні екосистеми безпеки. Запропоновано низку рекомендацій, спрямованих на підвищенняефективності та стійкості системи кібербезпеки критичної інфраструктури. Серед ключових рекомендацій:активне впровадження гібридних систем «ШІ + людський контроль» для забезпечення оптимального поєднанняавтоматизації та експертної оцінки; регулярне оновлення та адаптація моделей ШІ до нових типів загроз;інвестування у розвиток людського капіталу шляхом навчання та підвищення кваліфікації спеціалістів у галузіШІ та кібербезпеки; гармонізація національних підходів із міжнародними стандартами (зокрема NIST CSF таISO/IEC 27001); формування державних програм інтеграції ШІ у систему захисту критичної інфраструктури;активне розширення міжнародної співпраці, орієнтованої на обмін інформацією про кіберзагрози та кращимипрактиками застосування ШІ. Підкреслено, що ефективна міжгалузева, міжсекторальна та міждержавнавзаємодія експертних спільнот є ключовою умовою розбудови сучасної, адаптивної та стійкої системикіберзахисту критичної інфраструктури, здатної протистояти зростаючим викликам цифрової епохи.Ключові слова: кібербезпека, критична інфраструктура, кіберфізичні системи, штучний інтелект,машинне навчання, виявлення загроз, автоматизація реагування.
Перелік посилань1. Держспецзв’язку презентували інструмент оцінки кібербезпеки для українських організацій. 2024.https://ain.ua/2024/09/30/instrument-ocinki-kiberbezpeki/.2. Держспецзв’язку провела презентацію інструменту оцінки кібербезпеки CSET (Cybersecurity EvaluationTool) та провела практичне заняття з його використання. 2024. https://delo.ua/telecom/derzspeczvyazkuprezentuvala-novii-instrument-ocinki-kiberbezpeki-436947/.3. Зоря І.С., Марущак А. В. застосування штучного інтелекту для виявлення та реагування накіберзагрози. 2024. http://ir.lib.vntu.edu.ua/bitstream/handle/123456789/42057/20610.pdf?sequence=3&isAllowed=y .4. Інструмент оцінки кібербезпеки (CSET). https://www.cisa.gov/resources-tools/services/cyber-securityevaluation-tool-cset.5. Інструмент оцінки кібербезпеки CSET. https://csirt.csi.cip.gov.ua/uk/pages/cset .6. Мануілов Я.С. Забезпечення кібербезпеки об’єктів критичної інфраструктури в умовах кібервійни.Інформація і право. № 1(44)/2023. С.154-163.7. Нормативно-правова база у сфері захисту об'єктів критичної інфраструктури України.https://csirt.csi.cip.gov.ua/uk/pages/cio.8. Подвійні переваги штучного інтелекту в кібербезпеці: висновки зі звіту Benchmark Survey за 2024 рік.2024. https://hyperproof.io/resource/ai-in-cybersecurity-2024-benchmark-report/.9. Про затвердження Положення про організаційно-технічну модель кіберзахисту : постанова КабінетуМіністрів України від 29.12.2021 № 1426. https://zakon.rada.gov.ua/laws/show/1426-2021-%D0%BF#Text.10. Про критичну інфраструктуру : закон України від 16.11.2021 № 1882-ІХ. Відомості Верховної Ради(ВВР), 2023, № 5, ст.13. https://zakon.rada.gov.ua/laws/show/1882-20#Text.11. Пуаро К. Огляд тенденцій кібер-штучного інтелекту: підготовка до 2025 року. 2024.https://www.infosecurity-magazine.com/news-features/cyber-ai-trends-review-preparing/.12. Федорченко О.С. Роль штучного інтелекту у забезпеченні кібербезпеки України: сучасний стан таперспективи розвитку. Інформація і право. № 3(54)/2025. С.139-146. DOI: https://doi.org/10.37750/2616-6798.2025.3(54).340521. http://il.ippi.org.ua/article/view/340521 .13. Як AI захищає критичну інфраструктуру України: все про кібербезпеку OT/ICS. 2025. https://neoversity.com.ua/blog/yak-ai-zahishchaie-kritichnu-infrastrukturu-ukrayini-vse-pro-kiberbezpeku-ot-ics.14. AIxCC: AI Cyber Challenge / Defense Advanced Research Projects Agency. Arlington, VA : DARPA, 2024.https://www.darpa.mil/research/programs/ai-cyber .15. Artificial Intelligence and Cybersecurity / European Union Agency for Cybersecurity. Athens : ENISA, 2024.62p. https://www.enisa.europa.eu/publications/artificial-intelligence-and-cybersecurity .16. Artificial Intelligence: DHS Needs to Improve Risk Assessment Guidance for Critical Infrastructure Sectors /U.S. Government Accountability Office. Washington, DC : GAO, 2024. 42p. (GAO-25-107435). https://www.gao.gov/assets/gao-25-107435.pdf .17. Assess the current state of the cybersecurity program and identify capability gaps. (Оцінити поточний станпрограми кібербезпеки та виявити прогалини в можливостях) 2024. https://www.gartner.com/en/ cybersecurity/topics/cybersecurity-roadmap.18. CISA's 2024 Year in Review / Cybersecurity and Infrastructure Security Agency. Washington, DC : CISA,2024. 80p. https://www.cisa.gov/sites/default/files/2024-12/CSAC%20Annual%20Report_20241210.pdf .19. Crichton, K. Securing Critical Infrastructure in the Age of AI / K. Crichton, J. Baker, A. Luedtke // Center forSecurity and Emerging Technology. Washington, DC : CSET, 2024. 58p. https://cset.georgetown.edu/wpcontent/uploads/CSET-Securing-Critical-Infrastructure-in-the-Age-of-AI.pdf.20. Cyber AI Trends Review: Preparing for 2025 / Infosecurity Magazine. London : Infosecurity Magazine, 2025.https://www.infosecurity-magazine.com/news-features/cyber-ai-trends-review-preparing/.21. DHS Artificial Intelligence Roadmap / Department of Homeland Security. Washington, DC : DHS, 2024. 36p.https://www.dhs.gov/sites/default/files/2024-03/24_0315_ocio_roadmap_artificialintelligence-ciov3-signed-508.pdf .22. DHS Highlights AI as a Threat and Asset to Critical Infrastructure in New Priority Guidance / Nextgov/FCW.Washington, DC : Nextgov/FCW, 2024. https://www.nextgov.com/cybersecurity/2024/06/dhs-highlights-ai-threat-andasset-critical-infrastructure-new-priority-guidance/397524/ .23. Emerging Threats to Critical Infrastructure: AI Driven Cybersecurity Trends for 2025 / Capitol TechnologyUniversity. Laurel, MD : Capitol Technology University, 2024. https://www.captechu.edu/blog/ai-driven-cybersecuritytrends-2025 .24. Gartner states that in the GenAI era, the future of cybersecurity lies in prevention rather than detection andresponse. 2025. https: // www.gartner.com/en/newsroom / press-releases / 2025-09-18-gartner-says-that-in-the-age-ofgenai-preemptive-capabilities-not-detection-and-response-are-the-future-of-cybersecurity.25. Idaho National Laboratory. Cyber Security Evaluation Tool (CSET) User Guide. https://inl.gov/wpcontent/uploads/2020/06/CSET-User-Guide.pdf.26. Safety and Security Guidelines for Critical Infrastructure Sector Owners and Operators / Department ofHomeland Security. Washington, DC : DHS, 2024. 24p. https://www.dhs.gov/sites/default/files/2024-04/24_0426_dhs_ai-ci-safety-security-guidelines-508c.pdf .27. The Cybersecurity Provider's Next Opportunity: Making AI Safer / McKinsey & Company. New York :McKinsey & Company, 2024. https: // www.mckinsey.com / capabilities / risk-and-resilience/our-insights/thecybersecurity-providers-next-opportunity-making-ai-safer .28. The Dual Edges of AI in Cybersecurity: Insights from the 2024 Benchmark Survey Report / Hyperproof.Seattle, WA : Hyperproof, 2024. https://hyperproof.io/resource/ai-in-cybersecurity-2024-benchmark-report/ .29. What is Operational Technology (OT) Cyber Security?. https://www.axians.co.uk/glossary/what-isoperational-technology-security/#:~:text=Operational%20Technology%20(OT)%20security%2C,vulnerabilities%20from%202017%20to%2
ВИКОРИСТАННЯ СМАРТ-КОНТРАКТІВ ЯК ЗАСІБ ЗБЕРЕЖЕННЯ ДАНИХ В АВТОМАТИЗОВАНИХ СИСТЕМАХ
This article isdevoted to the study of the possibilities of implementing smart contracts as a means of ensuring data securityin modern automated systems. In today's world, where digitalization covers all areas of activity, the problemof reliable data storage, protection and exchange is becoming increasingly relevant. Smart contracts, whichare one of the key elements of blockchain technology, offer an innovative approach to solving theseproblems due to their transparency, process automation, and decentralization. This article analyzes thefunctionality of smart contracts, which allow for the automatic execution of agreements between the partiesbased on predefined conditions. These mechanisms significantly reduce the risks of data misuse and ensuretheir integrity and availability within the specified parameters. The main emphasis is placed on theintegration of smart contracts with modern databases and cloud storage, which contributes to the efficiencyof information management in automated systems
Keywords: smart contracts, blockchain, data storage, automated systems, information security
List of used literature:1.Taherdoost H. Smart Contracts in Blockchain Technology: A Critical Review. Information.2023. Vol. 14, no. 2. P. 117. URL: https://doi.org/10.3390/info14020117.2. High-G Shock Reliability of 3-D Integrated Structure Microsystem Based on Finite ElementSimulation / Y. Long et al. IEEE Transactions on Components, Packaging and ManufacturingTechnology. 2021. Vol. 11, no. 8. P. 1243–1249. URL: https://doi.org/10.1109/tcpmt.2021.30945943. Tan E., Mahula S., Crompvoets J. Blockchain governance in the public sector: a conceptualframework for public management. Government information quarterly. 2021. P. 101625. URL:https://doi.org/10.1016/j.giq.2021.101625.4. Guo H., Yu X. A survey on blockchain technology and its security. Blockchain: research andapplications. 2022. P. 100067. URL: https://doi.org/10.1016/j.bcra.2022.1000675.Antonopoulos, A., & Wood, G. (2021). Mastering Ethereum: Building Smart Contracts andDapps. O'Reilly Media.6.Blockchain for healthcare systems: architecture, security challenges, trends and futuredirections / A. J et al. Journal of network and computer applications. 2023. Vol. 215. P. 103633.URL: https://doi.org/10.1016/j.jnca.2023.103633.7. Uni-OPU: An FPGA-Based Uniform Accelerator for Convolutional and TransposedConvolutional Networks / Y. Yu et al. IEEE Transactions on Very Large Scale Integration (VLSI)Systems. 2020. Vol. 28, no. 7. P. 1545–1556. URL: https://doi.org/10.1109/tvlsi.2020.2995741.Смарт-контракти є новітньою технологією, яка дозволяєзабезпечувати прозорість, безпеку та автоматизацію процесів у різних сферах діяльності.Використання смарт-контрактів у автоматизованих системах для збереження даних дає можливістьмінімізувати ризики зловживання інформацією, а також гарантувати її цілісність і доступність. Устатті розглядаються основні принципи роботи смарт-контрактів, їх переваги у сфері обробкиданих, а також можливі сценарії застосування в автоматизованих системах. Запропоновані підходидо інтеграції смарт-контрактів з сучасними базами даних, які забезпечують високу ефективність істійкість до зовнішніх впливів. Наведено аналіз перспектив застосування технології блокчейн длявирішення завдань у промислових, фінансових і медичних автоматизованих системах.
Ключові слова: смарт-контракти, блокчейн, збереження даних, автоматизовані системи,безпека інформації
Список використаної літератури:1.Taherdoost H. Smart Contracts in Blockchain Technology: A Critical Review. Information.2023. Vol. 14, no. 2. P. 117. URL: https://doi.org/10.3390/info14020117.2. High-G Shock Reliability of 3-D Integrated Structure Microsystem Based on Finite ElementSimulation / Y. Long et al. IEEE Transactions on Components, Packaging and ManufacturingTechnology. 2021. Vol. 11, no. 8. P. 1243–1249. URL: https://doi.org/10.1109/tcpmt.2021.30945943. Tan E., Mahula S., Crompvoets J. Blockchain governance in the public sector: a conceptualframework for public management. Government information quarterly. 2021. P. 101625. URL:https://doi.org/10.1016/j.giq.2021.101625.4. Guo H., Yu X. A survey on blockchain technology and its security. Blockchain: research andapplications. 2022. P. 100067. URL: https://doi.org/10.1016/j.bcra.2022.1000675.Antonopoulos, A., & Wood, G. (2021). Mastering Ethereum: Building Smart Contracts andDapps. O'Reilly Media.6.Blockchain for healthcare systems: architecture, security challenges, trends and futuredirections / A. J et al. Journal of network and computer applications. 2023. Vol. 215. P. 103633.URL: https://doi.org/10.1016/j.jnca.2023.103633.7. Uni-OPU: An FPGA-Based Uniform Accelerator for Convolutional and TransposedConvolutional Networks / Y. Yu et al. IEEE Transactions on Very Large Scale Integration (VLSI)Systems. 2020. Vol. 28, no. 7. P. 1545–1556. URL: https://doi.org/10.1109/tvlsi.2020.2995741