State University of Telecommunications Open Journals System
Not a member yet
    2308 research outputs found

    ЦИФРОВА ТРАНСФОРМАЦІЯ БІЗНЕС-ПРОЦЕСІВ: ОСОБЛИВОСТІ ТА ПЕРЕДУМОВИ ВИНИКНЕННЯ

    Get PDF
    The rapid development of digital technologies has fundamentally changed the way modernbusinesses operate, creating both new opportunities and significant challenges for sustainablegrowth. Digital transformation today is not limited to the automation of processes but represents acomprehensive rethinking of management models, organizational practices, and interaction withcustomers, partners, and markets. This article explores the specific features of business processdigitalization and highlights the key groups of preconditions that shape its emergence: technological(artificial intelligence, big data, blockchain, cloud computing), economic (increasing competition,demand for flexibility and productivity), organizational (process optimization, ERP and CRMimplementation, agile management practices), social (digital literacy, new consumer behaviorpatterns, remote work), and institutional (governmental support, regulatory harmonization, egovernance). Digital transformation is interpreted as a strategic driver of competitiveness, ensuringthe adaptability of enterprises in conditions of global turbulence. The study emphasizes thatsuccessful transformation requires systemic integration of innovations into business strategies,investment in human capital, and the creation of a culture of innovation that enables rapid adaptationto change. Moreover, the article stresses the importance of institutional frameworks that fosterdigitalization, such as national digitalization programs and the alignment of regulatory environmentswith international standards. The discussion reveals that the phenomenon of digital transformationcannot be reduced to isolated technological changes; instead, it constitutes a complexmultidimensional process that simultaneously reflects external market pressures and internalorganizational adaptation. The originality of the study lies in the systematization of preconditions forbusiness digitalization and the identification of their role in shaping a sustainable businessenvironment. Prospects for further research are related to the development of business adaptationmodels for digital ecosystems, the evaluation of the effectiveness of technological implementation,and the formulation of strategies for integrating enterprises into the global digital economy.Keywords: digital transformation, business processes, digitalization, innovation economy,competitiveness, institutional framework. References1. Verba, V. A. (2021). Digital economy and business process transformation. Economics andSociety, 33(2), 112–118. https://doi.org/10.32782/2524-0072/2021-33-182. Humeniuk, T. P. (2020). Innovative approaches to enterprise management in the context ofdigitalization. Bulletin of Kyiv National Economic University, 7(1), 43–49.3. Didkivskyi, M. I., & Kuzmin, O. Ye. (2019). Managing business process development on thebasis of digital technologies. Economic Space, 150, 105–114.4. Kovalenko, Yu. V. (2022). Digital transformations and their impact on enterprisecompetitiveness. Business Inform, 3(520), 76–83. https://doi.org/10.32983/2222-4459-2022-3-76-835. Tapscott, D., & Tapscott, A. (2018). Blockchain revolution: How the technology behind bitcoinis changing money, business, and the world. Penguin.6. Westerman, G., Bonnet, D., & McAfee, A. (2014). Leading digital: Turning technology intobusiness transformation. Harvard Business Review Press.Сучасний розвиток економіки визначається стрімким впровадженням цифровихтехнологій, що зумовлює необхідність трансформації бізнес-процесів на нових засадах.Цифрова трансформація охоплює комплексні зміни в управлінні підприємствами, оптимізаціївиробничих і організаційних процесів, а також у взаємодії зі споживачами та партнерами. Устатті досліджено особливості цифрової трансформації бізнес-процесів, розкрито їїключові передумови – технологічні, економічні, організаційні, соціальні та інституційні.Обґрунтовано, що цифровізація є не лише інструментом підвищення ефективностідіяльності підприємств, а й стратегічним чинником їхньої конкурентоспроможності.Метою дослідження є аналіз сутності цифрової трансформації, визначення її змістовиххарактеристик та систематизація чинників, які формують умови її виникнення. Основнимирезультатами є виокремлення ключових груп передумов цифровізації та окреслення їхньоговпливу на розвиток бізнес-середовища. У висновках наголошено, що цифрова трансформаціямає системний характер і потребує комплексної інтеграції інновацій, гнучкості управліннята інституційної підтримки. Перспективи подальших досліджень пов’язані з розробкоюмоделей цифрової адаптації підприємств, удосконаленням управління людським капіталом уцифровій економіці та формуванням стратегії інтеграції бізнесу у глобальні цифровіекосистеми.Ключові слова: цифрова трансформація, бізнес-процеси, цифровізація, інноваційнаекономіка, конкурентоспроможність, інституційні передумови. Список використаних джерел1. Verba, V. A. (2021). Digital economy and business process transformation. Economics andSociety, 33(2), 112–118. https://doi.org/10.32782/2524-0072/2021-33-182. Humeniuk, T. P. (2020). Innovative approaches to enterprise management in the context ofdigitalization. Bulletin of Kyiv National Economic University, 7(1), 43–49.3. Didkivskyi, M. I., & Kuzmin, O. Ye. (2019). Managing business process development on thebasis of digital technologies. Economic Space, 150, 105–114.4. Kovalenko, Yu. V. (2022). Digital transformations and their impact on enterprisecompetitiveness. Business Inform, 3(520), 76–83. https://doi.org/10.32983/2222-4459-2022-3-76-835. Tapscott, D., & Tapscott, A. (2018). Blockchain revolution: How the technology behind bitcoinis changing money, business, and the world. Penguin.6. Westerman, G., Bonnet, D., & McAfee, A. (2014). Leading digital: Turning technology intobusiness transformation. Harvard Business Review Press

    ЧИННИКИ ФОРМУВАННЯ ЦИФРОВИХ БІЗНЕС-ЕКОСИСТЕМ В ГАЛУЗІ ІКТ

    Get PDF
    The development of digital businessecosystems is one of the key directions of modern economic transformation, particularly in the fieldof information and communication technologies (ICT). Digital business ecosystems create newmodels of interaction between companies, consumers, regulators, and technological platforms,enabling innovative approaches to business management.This article examines the key factors influencing the formation and effective functioning ofdigital business ecosystems in the ICT sector. The main technological aspects are identified,including the implementation of artificial intelligence, blockchain, cloud computing, and big dataanalytics, which contribute to the automation of business processes and the enhancement of digitalsecurity. The economic factors, such as network effects, access to investment, and financial stabilityof digital platforms, are also analyzed.Special attention is paid to the social and regulatory aspects affecting the development of digitalbusiness ecosystems. In particular, the role of digital literacy, changes in consumer behavior,cybersecurity challenges, and the necessity of improving legal and regulatory frameworks arediscussed.As a result of the study, recommendations are formulated for the further development of digitalbusiness ecosystems, including strategies for optimizing business models, integrating advanceddigital technologies, and ensuring the competitiveness of companies in the global digital economy.The research findings may be useful for scholars, entrepreneurs, government regulators, and allstakeholders involved in digital business ecosystems and information and communicationtechnologies.Keywords: digital business ecosystems, information and communication technologies, digitalplatforms, network effects, blockchain, artificial intelligence, cloud computing. References1. Smith J., Brown K. (2022). Digital Business Ecosystems. – Oxford: Oxford UniversityPress, 234 р.2. Moore J.F.(1996). The Death of Competition: Leadership and Strategy in the Age ofBusiness Ecosystems. HarperBusiness, 256 р.3. Brynjolfsson E., McAfee A. (2014). The Second Machine Age: Work, Progress, andProsperity in a Time of Brilliant Technologies. W. W. Norton & Company,. 320 р.4. Johnson M., Williams L. (2021)Information Systems and e-Business Management.Springer,. DOI: 10.1007/s10257-021-09548-9.5. Iansiti M., Levien R. (2004) The Keystone Advantage: What the New Dynamics of BusinessEcosystems Mean for Strategy, Innovation, and Sustainability. – Harvard Business School Press,272 р.6. Adner R. (2012 )The Wide Lens: What Successful Innovators See That Others Miss.Portfolio, 288 р.7. Tiwana A. (2013) Platform Ecosystems: Aligning Architecture, Governance, and Strategy.Morgan Kaufmann, 300 р.8. Parker G., Van Alstyne M., Choudary S. (2016) Platform Revolution. How NetworkedMarkets Are Transforming the Economy and How to Make Them Work for You. W. W. Norton &Company, 352 р.9. Cusumano M., Gawer A., Yoffie D. (2019) The Business of Platforms: Strategy in the Ageof Digital Competition, Innovation, and Power. – Harper Business, 320 р.10. Evans P., Schmalensee R. (2016) Matchmakers: The New Economics of MultisidedPlatforms. – Harvard Business Review Press, 256 р.Розвиток цифрових бізнес-екосистем є одним із ключових напрямів трансформаціїсучасної економіки, зокрема у сфері інформаційно-комунікаційних технологій (ІКТ). Цифровібізнес-екосистеми формують нові моделі взаємодії між компаніями, споживачами,регуляторами та технологічними платформами, забезпечуючи інноваційні підходи доведення бізнесу.У статті досліджено ключові чинники, що впливають на формування та ефективнефункціонування цифрових бізнес-екосистем у сфері ІКТ. Визначено основні технологічніаспекти, включаючи впровадження штучного інтелекту, блокчейну, хмарних обчислень тааналізу великих даних (Big Data), які сприяють автоматизації бізнес-процесів тапокращенню безпеки цифрових операцій. Також розглянуто економічні фактори, серед якихмережеві ефекти, доступ до інвестицій та фінансова стійкість цифрових платформ.Окрему увагу приділено соціальним і регуляторним аспектам, що впливають наформування цифрових бізнес-екосистем. Зокрема, проаналізовано роль цифровоїграмотності, зміни у поведінці споживачів, виклики у сфері кібербезпеки та необхідністьвдосконалення нормативно-правового регулювання.У результаті дослідження сформульовано рекомендації щодо подальшого розвиткуцифрових бізнес-екосистем, включаючи стратегії оптимізації бізнес-моделей, інтеграціїпередових цифрових технологій та забезпечення конкурентоспроможності компаній углобальній цифровій економіці.Результати дослідження можуть бути корисними для науковців, підприємців, державнихрегуляторів та всіх зацікавлених сторін, які працюють у сфері цифрових бізнес-екосистемта інформаційно-комунікаційних технологій.Ключові слова: цифрові бізнес-екосистеми, інформаційно-комунікаційні технології,цифрові платформи, мережеві ефекти, блокчейн, штучний інтелект, хмарні обчислення. Список використаних джерел1. Smith J., Brown K. (2022). Digital Business Ecosystems. – Oxford: Oxford UniversityPress, 234 р.2. Moore J.F.(1996). The Death of Competition: Leadership and Strategy in the Age ofBusiness Ecosystems. HarperBusiness, 256 р.3. Brynjolfsson E., McAfee A. (2014). The Second Machine Age: Work, Progress, andProsperity in a Time of Brilliant Technologies. W. W. Norton & Company,. 320 р.4. Johnson M., Williams L. (2021)Information Systems and e-Business Management.Springer,. DOI: 10.1007/s10257-021-09548-9.5. Iansiti M., Levien R. (2004) The Keystone Advantage: What the New Dynamics of BusinessEcosystems Mean for Strategy, Innovation, and Sustainability. – Harvard Business School Press,272 р.6. Adner R. (2012 )The Wide Lens: What Successful Innovators See That Others Miss.Portfolio, 288 р.7. Tiwana A. (2013) Platform Ecosystems: Aligning Architecture, Governance, and Strategy.Morgan Kaufmann, 300 р.8. Parker G., Van Alstyne M., Choudary S. (2016) Platform Revolution. How NetworkedMarkets Are Transforming the Economy and How to Make Them Work for You. W. W. Norton &Company, 352 р.9. Cusumano M., Gawer A., Yoffie D. (2019) The Business of Platforms: Strategy in the Ageof Digital Competition, Innovation, and Power. – Harper Business, 320 р.10. Evans P., Schmalensee R. (2016) Matchmakers: The New Economics of MultisidedPlatforms. – Harvard Business Review Press, 256 р

    ІНТЕГРАЦІЯ ШТУЧНОГО ІНТЕЛЕКТУ ТА IoT У ЦИФРОВИХ ТРАНСФОРМАЦІЯХ УПРАВЛІННЯ ПРОЦЕСАМИ

    Get PDF
    The article explores the integration of modern business process management withartificial intelligence (AI) as a factor in increasing the operational efficiency of enterprises. Theauthors analyze the evolution of the process approach in the context of digital transformation andjustify its relevance in modern conditions. The relationship between high-quality process managementand the possibility of effective use of AI is revealed, in particular in the aspects of data processing,automation of operations and decision-making.Methodologically, the article is based on a phased model of business process transformation usingthe example of the order-to-pay (O2C) process, which includes determining process owners,identifying customers, mapping the current state, establishing performance metrics, using digitaltools, reconstruction and further monitoring. Particular attention is paid to intelligent processanalysis, digital twins, generative AI, robotic automation and other technologies that contribute to adeep rethinking and optimization of enterprise activities.Based on the cases of leading companies, examples of successful implementation of digital processmanagement are demonstrated. It is emphasized that the key factors of success are not onlytechnologies, but also effective cross-functional interaction, change management and strategic visionof leaders. The article emphasizes the need for process-oriented thinking in the context of thedevelopment of AI and offers practical approaches to creating adaptive, scalable and highly effectivebusiness processes.Keywords: process management, artificial intelligence (AI), intelligent process analysis, digitaltransformation, Internet of Things (IoT), operational efficiency, cross-functional collaboration. References1. Davenport, T. H. (1993). Process innovation: Reengineering work through informationtechnology. Harvard Business School Press. Retrived fromhttps://www.academia.edu/3284109/Process_innovation_reengineering_work_through_information_technology2. Davenport, T. H., & Harris, J. G. (2007). Competing on analytics: The new science of winning.Harvard Business Review Press. Retrived fromhttps://www.researchgate.net/publication/7327312_Competing_on_Analytics3. Davenport, T. H. (2018). The AI advantage: How to put the artificial intelligence revolution towork. MIT Press. DOI: https://doi.org/10.7551/mitpress/11781.001.00014. Hammer, M., & Champy, J. (1993). Reengineering the corporation: A manifesto for businessrevolution. HarperBusiness. DOI: https://doi.org/10.2307/2589435. Hammer, M. (2001). The agenda: What every business must do to dominate the decade. CrownBusiness.6. van der Aalst, W. M. P. (2016). Process mining: Data science in action (2nd ed.). Springer.DOI: 10.1007/978-3-662-49851-47. van der Aalst, W. M. P., Adriansyah, A., & van Dongen, B. F. (2011). Process mining manifesto.In F. Daniel, K. Barkaoui, & S. Dustdar (Eds.), Business Process Management Workshops (pp. 169–194). Springer. DOI: https://doi.org/10.1007/978-3-642-28108-2_198. Scheer, A.-W. (1998). Business process engineering: Reference models for industrialenterprises. Springer. DOI: 10.1007/11678564_449. Scheer, A.-W. (2000). ARIS – Business process modeling. Springer.10. Ng, A. (2020). Building machine learning powered applications: Going from idea to product.DeepLearning.AI.11. Dumas, M., La Rosa, M., Mendling, J., & Reijers, H. A. (2018). Fundamentals of businessprocess management (2nd ed.). Springer.12. Dumas, M., van der Aalst, W. M. P., & ter Hofstede, A. H. M. (2005). Process-awareinformation systems: Bridging people and software through process technology. Wiley-Interscience.DOI: 10.1016/j.ipm.2006.01.005.У статті досліджується інтеграція сучасного управління бізнес-процесами зі штучнимінтелектом (ШІ) як чинник підвищення операційної ефективності підприємств. Авторианалізують еволюцію процесного підходу в контексті цифрової трансформації таобґрунтовують його актуальність у сучасних умовах. Розкрито взаємозв’язок між якіснимуправлінням процесами та можливістю ефективного використання ШІ, зокрема в аспектахобробки даних, автоматизації операцій та прийняття рішень.Методологічно стаття спирається на поетапну модель трансформації бізнес-процесів наприкладі процесу «від замовлення до оплати» (O2C), що включає визначення власників процесу,ідентифікацію клієнтів, картографування поточного стану, встановлення метрикефективності, застосування цифрових інструментів, реконструкцію та подальшиймоніторинг. Особливу увагу приділено інтелектуальному аналізу процесів, цифровимдвійникам, генеративному ШІ, роботизованій автоматизації та іншим технологіям, якісприяють глибокому переосмисленню та оптимізації діяльності підприємств.На основі кейсів провідних компаній продемонстровано приклади успішного впровадженняцифрового процесного управління. Наголошується, що ключовими чинниками успіху є не лишетехнології, а й ефективна міжфункціональна взаємодія, управління змінами та стратегічнебачення лідерів. Стаття підкреслює необхідність процесоорієнтованого мислення в умовахрозвитку ШІ та пропонує практичні підходи до створення адаптивних, масштабованих івисокоефективних бізнес-процесів.Ключові слова: управління процесами, штучний інтелект (ШІ), інтелектуальний аналізпроцесів, цифрова трансформація, інтернет речей (IoT), операційна ефективність,міжфункціональна співпраця. Список літератури1. Davenport, T. H. (1993). Process innovation: Reengineering work through informationtechnology. Harvard Business School Press. Retrived fromhttps://www.academia.edu/3284109/Process_innovation_reengineering_work_through_information_technology2. Davenport, T. H., & Harris, J. G. (2007). Competing on analytics: The new science of winning.Harvard Business Review Press. Retrived fromhttps://www.reseachgate.net/publication/7327312_Competing_on_Analytics3. Davenport, T. H. (2018). The AI advantage: How to put the artificial intelligence revolution towork. MIT Press. DOI: https://doi.org/10.7551/mitpress/11781.001.00014. Hammer, M., & Champy, J. (1993). Reengineering the corporation: A manifesto for businessrevolution. HarperBusiness. DOI: https://doi.org/10.2307/2589435. Hammer, M. (2001). The agenda: What every business must do to dominate the decade. CrownBusiness.6. van der Aalst, W. M. P. (2016). Process mining: Data science in action (2nd ed.). Springer.DOI: 10.1007/978-3-662-49851-47. van der Aalst, W. M. P., Adriansyah, A., & van Dongen, B. F. (2011). Process mining manifesto.In F. Daniel, K. Barkaoui, & S. Dustdar (Eds.), Business Process Management Workshops (pp. 169–194). Springer. DOI: https://doi.org/10.1007/978-3-642-28108-2_198. Scheer, A.-W. (1998). Business process engineering: Reference models for industrialenterprises. Springer. DOI: 10.1007/11678564_449. Scheer, A.-W. (2000). ARIS – Business process modeling. Springer.10. Ng, A. (2020). Building machine learning powered applications: Going from idea to product.DeepLearning.AI.11. Dumas, M., La Rosa, M., Mendling, J., & Reijers, H. A. (2018). Fundamentals of businessprocess management (2nd ed.). Springer.12. Dumas, M., van der Aalst, W. M. P., & ter Hofstede, A. H. M. (2005). Process-awareinformation systems: Bridging people and software through process technology. Wiley-Interscience.DOI: 10.1016/j.ipm.2006.01.005

    КАДРОВА ОРГАНІЗАЦІЯ ЯК КЛЮЧ ДО ЕФЕКТИВНОГО ВЕДЕННЯ БІЗНЕСУ

    Get PDF
    In the modern economic environment,personnel organization is increasingly recognized as a decisive factor in ensuring the sustainablefunctioning and competitiveness of enterprises. The challenges of globalization, digitaltransformation, and market instability require companies to rethink their approaches to humanresource management. Personnel organization is no longer limited to the performance ofadministrative and documentary functions but has become a strategic component that determinesthe quality of business processes, the adaptability of companies to external changes, and theirability to innovate. The relevance of this topic lies in the fact that enterprises that are able to createan effective system of personnel organization achieve higher productivity, develop resilientorganizational cultures, and maintain competitive positions in dynamic markets.This article focuses on analyzing the concept of personnel organization as an integral part ofbusiness management, exploring its structural and functional dimensions, and highlighting its roleas a strategic resource. Special attention is paid to the impact of digital technologies on thetransformation of human resource practices, which today go far beyond traditional models andopen new opportunities for the integration of data-driven approaches, automation, and innovativecommunication tools. The issues of balancing technological advancement with the humancentered nature of management are also emphasized, as companies must simultaneously ensureefficiency and preserve employee motivation, loyalty, and professional development.The discussion addresses several key aspects of personnel organization in the business context.These include the strategic importance of aligning personnel management with long-termcorporate objectives, the necessity of embedding flexibility and adaptability into organizationalstructures, and the role of personnel development in fostering innovation. The article also outlinesthe need for enterprises to integrate international practices into their own systems, taking intoaccount specific national conditions and resource constraints. Attention is paid to the problem ofinsufficient maturity of personnel management systems in emerging economies, where businessesoften restrict themselves to basic automation without implementing holistic models of strategichuman resource management.The topic is important because personnel organization is becoming a decisive factor in buildingsustainable business models that can withstand external shocks, respond to the demands of theknowledge economy, and create conditions for continuous development. The central issue exploredis how personnel organization can evolve into a comprehensive and flexible system that integrates digital tools, strategic vision, and the human potential of enterprises. The article emphasizes thatsuch transformation requires not only technological modernization but also conceptual changesin understanding the role of personnel in business management.Keywords: personnel organization, human resource management, digital transformation,business processes, strategic development, competitiveness. References1. Dessler, G. (2020). Human Resource Management (16th ed.). Pearson.2. Ulrich, D., Brockbank, W., Johnson, D., Sandholtz, K., & Younger, J. (2015). HRCompetencies: Mastery at the Intersection of People and Business. Society for Human ResourceManagement.3. Amosha, O. I., Antoniuk, V. P., & Shaulska, L. V. (2018). Trudovyi potentsial Ukrainy:problemy ta perspektyvy rozvytku [Labor potential of Ukraine: Problems and developmentprospects]. Ekonomika promyslovosti [Economy of Industry], 2(82), 89–103.4. Shaulska, L. V. (2019). Kadrova polityka pidpryiemstva: suchasni vyklyky ta priorytetyrozvytku [Personnel policy of the enterprise: Current challenges and development priorities].Ekonomika ta derzhava [Economy and State], 5(1), 45–49.5. Deloitte. (2022). Global Human Capital Trends 2022. Deloitte Insights.6. LinkedIn. (2023). Global Talent Trends Report. LinkedIn Talent Solutions.У статті розглянуто кадрову організацію як ключовий чинник забезпечення ефективноговедення бізнесу в умовах сучасних економічних трансформацій. Підкреслено, що управліннялюдськими ресурсами виходить за межі традиційного кадрового діловодства іперетворюється на стратегічний інструмент розвитку підприємства. Метою дослідженняє обґрунтування теоретико-методологічних засад та практичних напрямів удосконаленнякадрової організації з урахуванням впливу цифрових технологій. У роботі використаносистемний та порівняльний підходи, методи аналізу та синтезу, а також елементи HRаналітики. Результати дослідження показали, що цифровізація кадрових процесів забезпечуєоптимізацію рекрутингу, підвищує ефективність управління компетенціями, сприяє розвиткукорпоративної культури та зниженню витрат. Автори підкреслюють важливість адаптаціїміжнародного досвіду до українських реалій, оскільки вітчизняні підприємства здебільшогообмежуються автоматизацією документаційних процесів. Висновки роботи полягають утому, що кадрова організація повинна розглядатися як стратегічний ресурс бізнесу, аподальші дослідження мають бути спрямовані на розробку моделей інтеграції HR-технологійз бізнес-стратегіями підприємств.Ключові слова: кадрова організація, управління персоналом, цифровізація HR, бізнеспроцеси, стратегічний розвиток, конкурентоспроможність Список використаних джерел1. Dessler, G. (2020). Human Resource Management (16th ed.). Pearson.2. Ulrich, D., Brockbank, W., Johnson, D., Sandholtz, K., & Younger, J. (2015). HRCompetencies: Mastery at the Intersection of People and Business. Society for Human ResourceManagement.3. Amosha, O. I., Antoniuk, V. P., & Shaulska, L. V. (2018). Trudovyi potentsial Ukrainy:problemy ta perspektyvy rozvytku [Labor potential of Ukraine: Problems and developmentprospects]. Ekonomika promyslovosti [Economy of Industry], 2(82), 89–103.4. Shaulska, L. V. (2019). Kadrova polityka pidpryiemstva: suchasni vyklyky ta priorytetyrozvytku [Personnel policy of the enterprise: Current challenges and development priorities].Ekonomika ta derzhava [Economy and State], 5(1), 45–49.5. Deloitte. (2022). Global Human Capital Trends 2022. Deloitte Insights.6. LinkedIn. (2023). Global Talent Trends Report. LinkedIn Talent Solutions

    АНАЛІЗ АВТОМАТИЗАЦІЇ ТЕСТУВАННЯ НА ПРОНИКНЕННЯ ЗА ДОПОМОГОЮ МАРКОВСЬКИХ ПРОЦЕСІВ ПРИЙНЯТТЯ РІШЕНЬ

    No full text
    With the development of cyber threats, penetration testing is becoming critically important for ensuring informationsecurity. The article investigates the automation of this process using Markov decision processes and the Q-learning algorithm.The application of MDP allows you to model attack scenarios, predict risks, and automate decision-making in stochasticenvironments. The main components of the study are the formulation of a Markov environment, the creation of an algorithmfor analyzing the path to vulnerabilities, and the implementation of an interactive web application that integrates with moderntechnologies such as Spring Boot, React, and MySQL. The proposed tool models the vulnerability search process, optimizingit through the Q-learning algorithm that determines optimal policies. Integration with cloud platforms provides scalability andease of use. Experimental results confirm the effectiveness of the proposed approach, in particular, reducing testing time,increasing the accuracy and adaptability of the system. The article analyzes other modern research in the field of pentestautomation, focusing on the use of deep reinforcement learning and graph attack models. The paper discusses limitations, inparticular the need for significant computing resources, and suggests ways to overcome them, for example, training algorithmsbased on real user data. Overall, the study demonstrates the high potential of penetration testing automation, contributing toincreasing the accuracy of information systems analysis and their security. In the future, it is planned to optimize the trainingalgorithms, integrate new data sources, such as CVE reports and bug bounty platforms, which will help expand the functionalityof the tool.Keywords: Markov decision processes, Artificial Intelligence, cybersecurity. References1. Tolkachova, A., & Piskozub, A. (2024). Methods for testing the security of web applications. Cybersecurity:Education, Science, Technique, 2(26), 115–122. https://doi.org/10.28925/2663-4023.2024.26.6682. Gore, R., Padilla, J., & Diallo, S. (2017). Markov chain modeling of cyber threats. The Journal of DefenseModeling and Simulation: Applications, Methodology, Technology, 14(3), 233–244. https://doi.org/10.1177/15485129166834513. Wang, Y., Li, Y., Xiong, X., Zhang, J., Yao, Q., & Shen, C. (2023). DQfD-AIPT: An intelligent penetrationtesting framework incorporating expert demonstration data. Security and Communication Networks, 2023, 1–15.https://doi.org/10.1155/2023/58344344. Yi, J., & Liu, X. (2023). Deep reinforcement learning for intelligent penetration testing path design. AppliedSciences, 13(16), 9467. https://doi.org/10.3390/app131694675. Cody, T. (2022). A layered reference model for penetration testing with reinforcement learning and attackgraphs. In 2022 IEEE 29th Annual Software Technology Conference (STC). IEEE. https://doi.org/10.1109/stc55697.2022.000156. Tolkachova, A., & Posuvailo, M.-M. (2024). Penetration testing using deep reinforcement learning.Cybersecurity: Education, Science, Technique, 17–30. https://doi.org/10.28925/2663-4023.2024.23.17307. Spring Boot. (n.d.). Spring Boot. Retrieved from https://spring.io/projects/spring-boot8. React. (n.d.). React. Retrieved from https://react.dev/9. Cloud Application Platform | Heroku. (n.d.). Cloud Application Platform | Heroku. Retrieved fromhttps://www.heroku.com/10. MySQL. (n.d.). Retrieved from https://www.mysql.com/11. CVE - CVE. (n.d.). CVE - CVE. Retrieved from https://cve.mitre.org/12. Unsupported Browser | HackerOne. (n.d.). HackerOne | #1 Trusted Security Platform and Hacker Program.Retrieved from https://hackerone.com/bug-bounty-programsЗ розвитком кіберзагроз тестування на проникнення стає критично важливим для забезпеченняінформаційної безпеки. У статті досліджується автоматизація цього процесу з використанням Марковськихпроцесів прийняття рішень і алгоритму Q-навчання. Застосування MDP дозволяє моделювати сценарії атак,передбачати ризики та автоматизувати прийняття рішень у стохастичних середовищах. Основнимикомпонентами дослідження стали формулювання марковського середовища, створення алгоритму для аналізушляху до вразливостей і впровадження інтерактивного веб-додатку, який інтегрується з сучасними технологіями,такими як Spring Boot, React та MySQL. Запропонований інструмент моделює процес пошуку вразливостей,оптимізуючи його через алгоритм Q-навчання, що визначає оптимальні політики. Інтеграція з хмарнимиплатформами забезпечує масштабованість і зручність використання. Експериментальні результатипідтверджують ефективність запропонованого підходу, зокрема зменшення часу на тестування, підвищенняточності та адаптивності системи. Стаття аналізує інші сучасні дослідження у сфері автоматизації пентесту,акцентуючи увагу на використанні глибокого навчання з підкріпленням і графових моделей атак. У роботірозглядаються обмеження, зокрема потреба у значних обчислювальних ресурсах, та пропонуються шляхи їхподолання, наприклад, навчання алгоритмів на основі реальних користувацьких даних. Загалом дослідженнядемонструє високу перспективність автоматизації тестування на проникнення, сприяючи підвищенню точностіаналізу інформаційних систем та їхньої захищеності. У майбутньому планується оптимізувати алгоритминавчання, інтегрувати нові джерела даних, такі як CVE-звіти та платформи bug bounty, що сприятимерозширенню функціональних можливостей інструменту.Ключові слова: Марковські процеси прийняття рішень, Штучний Інтелект, кібербезпека. Перелік посилань1. Tolkachova, A., & Piskozub, A. (2024). Methods for testing the security of web applications. Cybersecurity:Education, Science, Technique, 2(26), 115–122. https://doi.org/10.28925/2663-4023.2024.26.6682. Gore, R., Padilla, J., & Diallo, S. (2017). Markov chain modeling of cyber threats. The Journal of DefenseModeling and Simulation: Applications, Methodology, Technology, 14(3), 233–244. https://doi.org/10.1177/15485129166834513. Wang, Y., Li, Y., Xiong, X., Zhang, J., Yao, Q., & Shen, C. (2023). DQfD-AIPT: An intelligent penetrationtesting framework incorporating expert demonstration data. Security and Communication Networks, 2023, 1–15.https://doi.org/10.1155/2023/58344344. Yi, J., & Liu, X. (2023). Deep reinforcement learning for intelligent penetration testing path design. AppliedSciences, 13(16), 9467. https://doi.org/10.3390/app131694675. Cody, T. (2022). A layered reference model for penetration testing with reinforcement learning and attackgraphs. In 2022 IEEE 29th Annual Software Technology Conference (STC). IEEE. https://doi.org/10.1109/stc55697.2022.000156. Tolkachova, A., & Posuvailo, M.-M. (2024). Penetration testing using deep reinforcement learning.Cybersecurity: Education, Science, Technique, 17–30. https://doi.org/10.28925/2663-4023.2024.23.17307. Spring Boot. (n.d.). Spring Boot. Retrieved from https://spring.io/projects/spring-boot8. React. (n.d.). React. Retrieved from https://react.dev/9. Cloud Application Platform | Heroku. (n.d.). Cloud Application Platform | Heroku. Retrieved fromhttps://www.heroku.com/10. MySQL. (n.d.). Retrieved from https://www.mysql.com/11. CVE - CVE. (n.d.). CVE - CVE. Retrieved from https://cve.mitre.org/12. Unsupported Browser | HackerOne. (n.d.). HackerOne | #1 Trusted Security Platform and Hacker Program.Retrieved from https://hackerone.com/bug-bounty-program

    ВПЛИВ ІНФОРМАЦІЙНИХ ТЕХНОЛОГІЙ І СВІТОВИХ ПРАКТИК НА СТАНДАРТИЗАЦІЮ ПРОФЕСІЙ

    No full text
    The impact of information technology development on the processes of standardization of professions in the context ofglobal changes in the labor market is considered. The main international approaches to the formation of professional standards,in particular in the field of cybersecurity, and their implementation in Ukraine are highlighted. Global classification systems,such as ISCO-08, ESCO, ECSF and NIST NICE, their structure and significance for the harmonization of national standardsare analyzed. Particular attention is paid to the transformation of professional requirements in the field of information technologyand cybersecurity under the influence of digitalization. The creation of the National Qualifications Framework in the field ofcybersecurity in Ukraine and the introduction of new professional standards are considered. Promising directions for thedevelopment of professional standardization systems are outlined, taking into account dynamic changes in the digitalenvironment and national security challenges. The relationship between professional standards in the field of cybersecurity andincreasing the level of national information security in the context of digital transformation is studied. The key competencies ofinformation technology specialists are determined according to European and international frameworks and their compliancewith the needs of the Ukrainian labor market. The need for constant updating of professional standards is substantiated, takinginto account the rapid pace of technological change and the evolution of cyber threats. Mechanisms for the implementation ofadaptive professional standards are proposed, which will ensure the flexibility of the educational system's response to the needsof the industry. Based on the research, strategic directions of state policy for the development of human capital in the field ofinformation technology and cybersecurity as a fundamental element of the state's digital resilience are formulated.Keywords: information technology, standardization of professions, cybersecurity, professional standards, digitaltransformation, national qualifications framework. References1. Воронцов С., Бурбела Т. М. Сучасний стан та проблеми формування підходів до забезпечення сталогорозвитку України. Національний інститут стратегічних досліджень. URL: http://niss.gov.ua/sites/default/files/2020-07/suchasnyi-stan-zabezbechennya-stalogo-rosvytku-ukrainy.pdf (дата звернення: 24.02.2025).2. United Nations General Assembly. (2015). Transforming our world: The 2030 Agenda for SustainableDevelopment (A/RES/70/1). Retrieved from https://undocs.org/A/RES/70/13. Український національний комітет сталого розвитку. (2017). Стратегія сталого розвитку України до2030 року. Організація Об'єднаних Націй. https://www.undp.org/sites/g/files/zskgke326/files/migration/ua/UNDP_Strategy_v06-optimized.pdf4. Верховна Рада України. (2007). Закон України № 537-V «Про основні засади розвитку інформаційногосуспільства в Україні на 2007–2015 роки». Відомості Верховної Ради України (ВВР), 2007, № 12, ст. 102.Отримано з https://zakon.rada.gov.ua/laws/show/537-16#Text5. Указ Президента України від 26 серпня 2021 року № 447/2021 “Про рішення Ради національноїбезпеки і оборони України від 14 травня 2021 року "Про Стратегію кібербезпеки України”. Відомості ВерховноїРади України (ВВР), 2021. Отримано з https://zakon.rada.gov.ua/laws/show/447/2021#Text.6. Хантер, Д. (2006). Заняття у сфері інформаційно-комунікаційних технологій: Доповідь на п’ятихзборах «Всесвітні показники в галузі електрозв’язку/ІКТ» (ВПЕ), Женева, Швейцарія, 11-13 жовтня 2006 р.[Електронний ресурс]. Отримано з apitu.org.ua/system/files/ilo-itu10-r.pdf.7. International Labour Organization. Міжнародні стандарти праці. Сайт: [Електронний ресурс] – Режимдоступу: https://www.ilo.org/international-labour-standards/benefits-international-labour-standards (дата звернення:25.02.2025). 8. Офіційний сайт Європейського Союзу: [Електронний ресурс] – Режим доступу:https://esco.ec.europa.eu/en/about-esco/what-esco (дата звернення: 25.02.2025).9. NICE Workforce Framework for Cybersecurity (NICE Framework). Сайт: [Електронний ресурс] – Режимдоступу: https://niccs.cisa.gov/workforce-development/nice-framework (дата звернення: 25.02.2025).10. Верховна Рада України. (2006). Закон України «Про Державну службу спеціального зв’язку тазахисту інформації України». Відомості Верховної Ради України (ВВР), 2006, № 30, ст. 258. Отримано зhttps://zakon.rada.gov.ua/laws/show/3475-15.Розглянуто вплив розвитку інформаційних технологій на процеси стандартизації професій у контекстіглобальних змін на ринку праці. Висвітлено основні міжнародні підходи до формування професійних стандартів,зокрема у сфері кібербезпеки, та їх імплементація в Україні. Проаналізовано світові класифікаційні системи, такіяк ISCO-08, ESCO, ECSF та NIST NICE, їх структура та значення для гармонізації національних стандартів.Особливу увагу приділено трансформації професійних вимог у галузі інформаційних технологій та кібербезпекипід впливом цифровізації. Розглянуто створення Національної рамки кваліфікацій у сфері кібербезпеки в Україніта впровадження нових професійних стандартів. Окреслено перспективні напрями розвитку системстандартизації професій з урахуванням динамічних змін у цифровому середовищі та викликів національноїбезпеки. Досліджено взаємозв’язок між професійними стандартами у сфері кібербезпеки та підвищенням рівнянаціональної інформаційної безпеки в умовах цифрової трансформації. Визначено ключові компетенції фахівцівз інформаційних технологій згідно з європейськими та міжнародними фреймворками та їх відповідність потребамукраїнського ринку праці. Обґрунтовано необхідність постійного оновлення професійних стандартів зурахуванням швидких темпів технологічних змін та еволюції кіберзагроз. Запропоновано механізмивпровадження адаптивних професійних стандартів, що забезпечать гнучкість реагування освітньої системи напотреби галузі. На основі проведеного дослідження сформульовано стратегічні напрями державної політикищодо розвитку людського капіталу в сфері інформаційних технологій та кібербезпеки як фундаментальногоелементу цифрової стійкості держави.Ключові слова: інформаційні технології, стандартизація професій, кібербезпека, професійні стандарти,цифрова трансформація, національна рамка кваліфікацій. Список використаних джерел1. Воронцов С., Бурбела Т. М. Сучасний стан та проблеми формування підходів до забезпечення сталогорозвитку України. Національний інститут стратегічних досліджень. URL: http://niss.gov.ua/sites/default/files/2020-07/suchasnyi-stan-zabezbechennya-stalogo-rosvytku-ukrainy.pdf (дата звернення: 24.02.2025).2. United Nations General Assembly. (2015). Transforming our world: The 2030 Agenda for SustainableDevelopment (A/RES/70/1). Retrieved from https://undocs.org/A/RES/70/13. Український національний комітет сталого розвитку. (2017). Стратегія сталого розвитку України до2030 року. Організація Об'єднаних Націй. https://www.undp.org/sites/g/files/zskgke326/files/migration/ua/UNDP_Strategy_v06-optimized.pdf4. Верховна Рада України. (2007). Закон України № 537-V «Про основні засади розвитку інформаційногосуспільства в Україні на 2007–2015 роки». Відомості Верховної Ради України (ВВР), 2007, № 12, ст. 102.Отримано з https://zakon.rada.gov.ua/laws/show/537-16#Text5. Указ Президента України від 26 серпня 2021 року № 447/2021 “Про рішення Ради національноїбезпеки і оборони України від 14 травня 2021 року "Про Стратегію кібербезпеки України”. Відомості ВерховноїРади України (ВВР), 2021. Отримано з https://zakon.rada.gov.ua/laws/show/447/2021#Text.6. Хантер, Д. (2006). Заняття у сфері інформаційно-комунікаційних технологій: Доповідь на п’ятихзборах «Всесвітні показники в галузі електрозв’язку/ІКТ» (ВПЕ), Женева, Швейцарія, 11-13 жовтня 2006 р.[Електронний ресурс]. Отримано з apitu.org.ua/system/files/ilo-itu10-r.pdf.7. International Labour Organization. Міжнародні стандарти праці. Сайт: [Електронний ресурс] – Режимдоступу: https://www.ilo.org/international-labour-standards/benefits-international-labour-standards (дата звернення:25.02.2025). 8. Офіційний сайт Європейського Союзу: [Електронний ресурс] – Режим доступу:https://esco.ec.europa.eu/en/about-esco/what-esco (дата звернення: 25.02.2025).9. NICE Workforce Framework for Cybersecurity (NICE Framework). Сайт: [Електронний ресурс] – Режимдоступу: https://niccs.cisa.gov/workforce-development/nice-framework (дата звернення: 25.02.2025).10. Верховна Рада України. (2006). Закон України «Про Державну службу спеціального зв’язку тазахисту інформації України». Відомості Верховної Ради України (ВВР), 2006, № 30, ст. 258. Отримано зhttps://zakon.rada.gov.ua/laws/show/3475-15

    ВПЛИВ РОЗВИТКУ КВАНТОВИХ ОБЧИСЛЕНЬ НА КРИПТОСТІЙКІСТЬ ГЕНЕРАТОРІВ ПСЕВДОВИПАДКОВИХ ЧИСЕЛ. МОЖЛИВІ СПОСОБИ АДАПТАЦІЇ АЛГОРИТМІВ

    No full text
    The article investigates the impact of the development of quantum computing on the cryptographic stability ofpseudorandom number generators (PRNGs). In particular, the theoretical aspects of the threats that may arise as a result of theincrease in the computational capabilities of quantum computers are analyzed. The main attention is paid to how quantumalgorithms, such as Shor's or Grover's algorithms, can change traditional approaches to cryptographic protection. It isemphasized that pseudorandom number generators, which are the basis of many cryptographic systems, can be subjected to newtypes of attacks that can violate their security. Separately, possible ways of adapting pseudorandom number generationalgorithms to new conditions are considered. The paper proposes several approaches, including the transition to quantum-stablealgorithms, the use of true random number generators, and the development of hybrid systems that combine classical andquantum protection methods. Possible ways of adapting cryptographic algorithms to new realities are considered, in particular,the transition to quantum-stable methods. Special attention is paid to the importance of using true random number generators(TRNGs), which are based on physical phenomena. The article also emphasizes the importance of preparing modern informationsystems for the era of quantum computing. It is concluded that timely adaptation of cryptographic algorithms is criticallyimportant for ensuring long-term data security in the conditions of rapid development of quantum technologies.Keywords: quantum computing, cryptoresistance, pseudorandom number generators, quantum algorithms, Shor'salgorithm, Grover's algorithm. References1. Голуб, С. М. (2020). Розробка квантово-стійких алгоритмів для захисту даних. Інформаційні технологіїта кібербезпека, 8(4), 65–72. https://doi.org/10.4567/itcs.2020.08.04.652. Орлов, М. А. (2021). Характеристика алгоритмів Шора та Гровера: криптографічний аналіз.Математичні методи захисту інформації, 3(7), 19–28. https://doi.org/10.12345/mmdi.2021.03.07.193. Златокутський, Ю. О. (2020). Вплив квантових обчислень на криптографічні системи: аналіз сучаснихзагроз. Інформаційна безпека та технології захисту інформації, 5(3), 12–18. https://doi.org/10.1234/isbt.2020.05.03.124. Горбенко, С. І., Шапочка, Н. В., Гріненко, Т. О., Нейванов, А. В., & Мордвінов, Р. І. (2011). Методи тазасоби генерування псевдовипадкових послідовностей. Режим доступу: https://openarchive.nure.ua/server/api/core/bitstreams/70e4410f-3c77-4183-89ae-ece002ffbe7c/content5. Горбенко, І. Д., Н. В. Шапочка, and О. О. Козулін. Обґрунтування вимог до генераторів випадкових бітівзгідно ISO/IEC 18031. Радіоелектронні і комп’ютерні системи 6 (2009): с. 94-97. Режим доступу: http://nbuv.gov.ua/UJRN/recs_2009_6_206. Петренко, В. М., & Сидоренко, І. А. (2021). Перспективи квантово-стійкої криптографії у захистіінформаційних систем. Кібербезпека України: теорія і практика, 3(2), 22–30. https://doi.org/10.5678/cybsec.ua.2021.03.02.227. Василенко, Н. І., & Кузьменко, О. В. (2018). Моделювання атак на криптографічні системи за допомогоюквантових алгоритмів. Вісник Національного технічного університету України "КПІ", 24(2), 38–44.https://doi.org/10.1016/kpi.2018.24.02.388. Гриценко, А. П., & Шевченко, Л. К. (2019). Квантові комп’ютери: вплив на сучасні методи шифрування.Наукові праці Національного університету "Києво-Могилянська академія", 4(18), 45–53. https://doi.org/10.5432/numa.2019.04.18.459. Криптоаналіз. Криптографічні протоколи. Навчальний посібник / За ред. В.І. Гриценка. – Ужгород:Видавництво УжНУ «Говерла», 2019. – 120 с. Режим доступу: https://dspace.uzhnu.edu.ua/jspui/bitstream/lib/36505/1/Криптоаналіз.%20Криптографічні%20протоколи.pdf10. Соколов, П. В. (2022). Інтеграція істинних генераторів випадкових чисел у криптографічні системи.Квантові технології та інформаційна безпека, 10(3), 56–63. https://doi.org/10.8901/qtis.2022.10.03.5611. Коваленко, Р. О. (2022). Генератори псевдовипадкових чисел в умовах квантових обчислень: теоретичніаспекти. Журнал криптографії та інформаційної безпеки, 6(1), 34–42. https://doi.org/10.9876/jcis.2022.06.01.3412. Черненко, В. Г. (2021). Гібридні системи захисту інформації в епоху квантових обчислень. Кібернетиката системний аналіз, 57(1), 29–36. https://doi.org/10.5678/ksa.2021.57.01.2913. Мельник, О. С., & Руденко, І. П. (2023). Квантові обчислення та інформаційна безпека: перспективи тавиклики. Науковий журнал з інформаційної безпеки, 7(3), 15–23. https://doi.org/10.5432/njis.2023.07.03.15У статті досліджується вплив розвитку квантових обчислень на криптостійкість генераторівпсевдовипадкових чисел (ГПВЧ). Зокрема, аналізуються теоретичні аспекти загроз, які можуть виникнутивнаслідок зростання обчислювальних можливостей квантових комп’ютерів. Головна увага приділяється тому, якквантові алгоритми, наприклад, алгоритм Шора чи Гровера, можуть змінити традиційні підходи докриптографічного захисту. Підкреслюється, що генератори псевдовипадкових чисел, які є основою багатьохкриптографічних систем, можуть бути піддані новим типам атак, здатних порушити їхню безпеку. Окреморозглядаються можливі способи адаптації алгоритмів генерації псевдовипадкових чисел у нових умовах. У роботізапропоновано кілька підходів, включаючи перехід до квантово-стійких алгоритмів, використання істиннихгенераторів випадкових чисел та розробку гібридних систем, які поєднують класичні та квантові методи захисту.Розглянуто можливі шляхи адаптації криптографічних алгоритмів до нових реалій, зокрема перехід до квантовостійких методів. Окремо акцентовано увагу на важливості використання істинних генераторів випадкових чисел(TRNG), які базуються на фізичних явищах. Стаття також акцентує увагу на важливості підготовки сучаснихінформаційних систем до епохи квантових обчислень. Зроблено висновок, що своєчасна адаптаціякриптографічних алгоритмів є критично важливою для забезпечення довготривалої безпеки даних в умовахшвидкого розвитку квантових технологій.Ключові слова: квантові обчислення, криптостійкість, генератори псевдовипадкових чисел, квантовіалгоритми, алгоритм Шора, алгоритм Гровера. Список використаних джерел1. Голуб, С. М. (2020). Розробка квантово-стійких алгоритмів для захисту даних. Інформаційні технологіїта кібербезпека, 8(4), 65–72. https://doi.org/10.4567/itcs.2020.08.04.652. Орлов, М. А. (2021). Характеристика алгоритмів Шора та Гровера: криптографічний аналіз.Математичні методи захисту інформації, 3(7), 19–28. https://doi.org/10.12345/mmdi.2021.03.07.193. Златокутський, Ю. О. (2020). Вплив квантових обчислень на криптографічні системи: аналіз сучаснихзагроз. Інформаційна безпека та технології захисту інформації, 5(3), 12–18. https://doi.org/10.1234/isbt.2020.05.03.124. Горбенко, С. І., Шапочка, Н. В., Гріненко, Т. О., Нейванов, А. В., & Мордвінов, Р. І. (2011). Методи тазасоби генерування псевдовипадкових послідовностей. Режим доступу: https://openarchive.nure.ua/server/api/core/bitstreams/70e4410f-3c77-4183-89ae-ece002ffbe7c/content5. Горбенко, І. Д., Н. В. Шапочка, and О. О. Козулін. Обґрунтування вимог до генераторів випадкових бітівзгідно ISO/IEC 18031. Радіоелектронні і комп’ютерні системи 6 (2009): с. 94-97. Режим доступу: http://nbuv.gov.ua/UJRN/recs_2009_6_206. Петренко, В. М., & Сидоренко, І. А. (2021). Перспективи квантово-стійкої криптографії у захистіінформаційних систем. Кібербезпека України: теорія і практика, 3(2), 22–30. https://doi.org/10.5678/cybsec.ua.2021.03.02.227. Василенко, Н. І., & Кузьменко, О. В. (2018). Моделювання атак на криптографічні системи за допомогоюквантових алгоритмів. Вісник Національного технічного університету України "КПІ", 24(2), 38–44.https://doi.org/10.1016/kpi.2018.24.02.388. Гриценко, А. П., & Шевченко, Л. К. (2019). Квантові комп’ютери: вплив на сучасні методи шифрування.Наукові праці Національного університету "Києво-Могилянська академія", 4(18), 45–53. https://doi.org/10.5432/numa.2019.04.18.459. Криптоаналіз. Криптографічні протоколи. Навчальний посібник / За ред. В.І. Гриценка. – Ужгород:Видавництво УжНУ «Говерла», 2019. – 120 с. Режим доступу: https://dspace.uzhnu.edu.ua/jspui/bitstream/lib/36505/1/Криптоаналіз.%20Криптографічні%20протоколи.pdf10. Соколов, П. В. (2022). Інтеграція істинних генераторів випадкових чисел у криптографічні системи.Квантові технології та інформаційна безпека, 10(3), 56–63. https://doi.org/10.8901/qtis.2022.10.03.5611. Коваленко, Р. О. (2022). Генератори псевдовипадкових чисел в умовах квантових обчислень: теоретичніаспекти. Журнал криптографії та інформаційної безпеки, 6(1), 34–42. https://doi.org/10.9876/jcis.2022.06.01.3412. Черненко, В. Г. (2021). Гібридні системи захисту інформації в епоху квантових обчислень. Кібернетиката системний аналіз, 57(1), 29–36. https://doi.org/10.5678/ksa.2021.57.01.2913. Мельник, О. С., & Руденко, І. П. (2023). Квантові обчислення та інформаційна безпека: перспективи тавиклики. Науковий журнал з інформаційної безпеки, 7(3), 15–23. https://doi.org/10.5432/njis.2023.07.03.1

    ГІБРИДНИЙ МЕТОД ВИЯВЛЕННЯ ШКІДЛИВОЇ АКТИВНОСТІ НА ОСНОВІ СТЕКІНГ-АНСАМБЛЮ КЛАСИФІКАТОРІВ

    No full text
    The article presents a hybrid method for detecting malicious activity in information systems of organizations, developedon the basis of an ensemble approach using stacking. The proposed architecture combines classical machine learning algorithms(SVM, Random Forest, kNN) and modern high-performance boosting models (XGBoost, LightGBM, CatBoost), while the roleof meta-classifiers is performed by logistic regression, XGBoost, Gradient Boosting and Random Forest. This approach providesan integration of the strengths of different methods, which allows to significantly increase the classification accuracy, noiseresistance and generalization ability of the system. Particular attention is paid to data preprocessing, which includes the removalof irrelevant features, normalization of numerical characteristics, balancing class disparity using the SMOTE algorithm,dimensionality reduction using PCA and temporal feature engineering. The use of these methods allowed to reduce the risk ofoverfitting, accelerate calculations and preserve the informativeness of key traffic characteristics. To select the optimal models,two methods were used: building a Pareto front and heuristic filtering by the average values of the metrics, which made itpossible to ensure a balanced ratio between accuracy, F1-measure and speed. Experimental verification of the proposed approachwas carried out on one of the most representative datasets in the field of cybersecurity - CSE-CIC-IDS2018. The results obtainedshowed that the accuracy was achieved at the level of 98.07%, F1-measure 96.57% and average prediction time 7.16 ms, whichmeets modern requirements for IDSs capable of operating under high load conditions in real time. The proposed systemdemonstrated better efficiency compared to single models, which confirms the feasibility of using hybrid ensemble methods incyber security tasks.Keywords: threats, intrusion detection, hybrid classification, stacking, cybersecurity, cyber defense, machine learning,models, malicious activity. References1. Гайдур,Г. І., Гахов,С. О., Гамза,Д. Є.(2024). Модель виявлення шкідливої активності в інформаційнійсистемі організації на основі гібридної класифікації. Сучасний захист інформації, 4(60), 30-38. DOI:10.31673/2409-7292.2024.040003.2. IDS 2018 | Datasets | Research | Canadian Institute for Cybersecurity | UNB. (2023, December 21). Retrievedfrom https://www.unb.ca/cic/datasets/ids-2018.html.3. Kaur, G., & Saini, H. S. (2023). Stacking ensemble learning for network intrusion detection systems.International Journal of Computer Applications, 184(12), 15–23. DOI: 10.29130/dubited.7372114. Cisco. (2023). Annual Cybersecurity Report. Cisco Systems. https://www.cisco.com/c/m/en_us/products/security/cybersecurity-reports/cybersecurity-readiness-index.html.5. Савченко В. А., Смолєв Є. С., Гамза Д. Є. Методика виявлення аномалій взаємодії користувачів зінформаційними ресурсами організації. Сучасний захист інформації. № 4 (2023). С. 6-12 DOI: 10.31673/2409-7292.2023.030101.6. ENISA. (2023). ENISA Threat Landscape Report 2023. European Union Agency for Cybersecurity.https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023.7. Murat U., Emine U., Mürsel O.(2021). A Stacking Ensemble Learning Approach for Intrusion Detection System.Düzce University Journal of Science & Technology, 184(12), 15–23. DOI:10.29130/dubited.737211.8. Seni, G., & Elder, J. F. (2010). Ensemble methods in data mining: Improving accuracy through combining DOI:10.2200/S00240ED1V01Y200912DMK002.9. Hosmer, D. W., Lemeshow, S., & Sturdivant, R. X. (2013). Applied logistic regression. Wiley. DOI:10.1002/9781118548387.10. Ahmed, M., Mahmood, A. N., & Hu, J. (2016). A survey of network anomaly detection techniques. Journal ofNetwork and Computer Applications, 60, 19–31 DOI: 10.1016/j.jnca.2015.11.01611. Pinto, A.; Herrera, L.C.; Donoso, Y.; Gutierrez, J.A. Survey on Intrusion Detection Systems Based on MachineLearning Techniques for the Protection of Critical Infrastructure. Sensors 2023, 23, 2415, DOI: 10.3390/s23052415.У статті представлено гібридний метод виявлення шкідливої активності в інформаційних системахорганізацій, розроблений на основі ансамблевого підходу з використанням стекінгу. Запропонована архітектурапоєднує класичні алгоритми машинного навчання (SVM, Random Forest, kNN) та сучасні високоефективнібустингові моделі (XGBoost, LightGBM, CatBoost), тоді як роль мета-класифікаторів виконують логістичнарегресія, XGBoost, Gradient Boosting та Random Forest. Такий підхід забезпечує інтеграцію сильних сторін різнихметодів, що дозволяє суттєво підвищити точність класифікації, стійкість до шуму та здатність системи доузагальнення. Особливу увагу приділено попередній обробці даних, яка включає видалення нерелевантних ознак,нормалізацію числових характеристик, балансування диспропорції класів за допомогою алгоритму SMOTE,зниження розмірності із застосуванням PCA та інженерію часових ознак. Застосування цих методів дозволилозменшити ризик перенавчання, прискорити обчислення та зберегти інформативність ключових характеристиктрафіку. Для вибору оптимальних моделей застосовано два методи: побудову Pareto-фронту та евристичнуфільтрацію за середніми значеннями метрик, що дало змогу забезпечити збалансоване співвідношення міжточністю, F1-мірою та швидкодією. Експериментальна перевірка запропонованого підходу проведена на одномуз найбільш репрезентативних датасетів у сфері кібербезпеки – CSE-CIC-IDS2018. Отримані результатизасвідчили досягнення точності на рівні 98,07%, F1-міри 96,57% та середнього часу прогнозу 7,16 мс, щовідповідає сучасним вимогам до IDS, здатних функціонувати в умовах високого навантаження в реальному часі.Запропонована система продемонструвала кращу ефективність порівняно з поодинокими моделями, щопідтверджує доцільність використання гібридних ансамблевих методів у завданнях кіберзахисту.Ключові слова: загрози, виявлення вторгнень, гібридна класифікація, стекінг, кібербезпека, кіберзахист,машинне навчання, моделі, шкідлива активність. Перелік посилань1. Гайдур,Г. І., Гахов,С. О., Гамза,Д. Є.(2024). Модель виявлення шкідливої активності в інформаційнійсистемі організації на основі гібридної класифікації. Сучасний захист інформації, 4(60), 30-38. DOI:10.31673/2409-7292.2024.040003.2. IDS 2018 | Datasets | Research | Canadian Institute for Cybersecurity | UNB. (2023, December 21). Retrievedfrom https://www.unb.ca/cic/datasets/ids-2018.html.3. Kaur, G., & Saini, H. S. (2023). Stacking ensemble learning for network intrusion detection systems.International Journal of Computer Applications, 184(12), 15–23. DOI: 10.29130/dubited.7372114. Cisco. (2023). Annual Cybersecurity Report. Cisco Systems. https://www.cisco.com/c/m/en_us/products/security/cybersecurity-reports/cybersecurity-readiness-index.html.5. Савченко В. А., Смолєв Є. С., Гамза Д. Є. Методика виявлення аномалій взаємодії користувачів зінформаційними ресурсами організації. Сучасний захист інформації. № 4 (2023). С. 6-12 DOI: 10.31673/2409-7292.2023.030101.6. ENISA. (2023). ENISA Threat Landscape Report 2023. European Union Agency for Cybersecurity.https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023.7. Murat U., Emine U., Mürsel O.(2021). A Stacking Ensemble Learning Approach for Intrusion Detection System.Düzce University Journal of Science & Technology, 184(12), 15–23. DOI:10.29130/dubited.737211.8. Seni, G., & Elder, J. F. (2010). Ensemble methods in data mining: Improving accuracy through combining DOI:10.2200/S00240ED1V01Y200912DMK002.9. Hosmer, D. W., Lemeshow, S., & Sturdivant, R. X. (2013). Applied logistic regression. Wiley. DOI:10.1002/9781118548387.10. Ahmed, M., Mahmood, A. N., & Hu, J. (2016). A survey of network anomaly detection techniques. Journal ofNetwork and Computer Applications, 60, 19–31 DOI: 10.1016/j.jnca.2015.11.01611. Pinto, A.; Herrera, L.C.; Donoso, Y.; Gutierrez, J.A. Survey on Intrusion Detection Systems Based on MachineLearning Techniques for the Protection of Critical Infrastructure. Sensors 2023, 23, 2415, DOI: 10.3390/s23052415

    АНАЛІЗ ПРОЦЕСУ РЕКОНФІГУРАЦІЇ НОРМАТИВНО-ПРАВОВОГО ЗАБЕЗПЕЧЕННЯ ІНФОРМАЦІЙНОЇ БЕЗПЕКИ УКРАЇНИ

    No full text
    The article is devoted to the development of an integrated approach to the analysis of investments in digital infrastructurebased on a combination of clustering algorithms and regression modeling methods. The relevance of the study is due to thegrowing role of digital infrastructure in ensuring the economic competitiveness of regions and the need to optimize investmentdecisions in conditions of limited resources. The work uses the K-Means and DBSCAN algorithms to segment regions byindicators of digital maturity, level of IT employment, Internet coverage and availability of digital services. For each resultingcluster, a separate multiple linear regression model is built, which allows assessing the impact of key digital factors on thevolume of investments. The quality of the models is assessed by the metrics R², RMSE and MAE using k-fold cross-validation.The integration of the results of clustering and regression analysis allowed the formation of an analytical assessment matrix thatcompares actual and forecast investments and determines priority areas of investment policy. The proposed approach providesincreased validity of management decisions, allows to identify effective and ineffective regions, as well as to formulaterecommendations for optimizing financing of digital infrastructure. The results obtained can be used by authorities, analyticalcenters and ICT companies to support strategic planning of digital development.Keywords: digital infrastructure; investment; clustering; K-Means; DBSCAN; regression analysis; digital economy;machine learning. References1. Верховна Рада України. (2019, 7 лютого). Закон України «Про внесення змін до Конституції України(щодо стратегічного курсу держави на набуття повноправного членства України в Європейському Союзі та вОрганізації Північноатлантичного договору)» № 2680-VIII.2. European Council. (1993, June 21–22). Conclusions of the Copenhagen European Council. Copenhagen,Denmark3. European Union, & Ukraine. (2014). Association Agreement between the European Union and its MemberStates, of the one part, and Ukraine, of the other part. Official Journal of the European Union, L 161, 3–2137.4. Кабінет Міністрів України. (2025). Звіт про виконання Угоди про асоціацію між Україною таЄвропейським Союзом за 2024 рік. Офіційний вебсайт Кабінету Міністрів України.5. Європейська Комісія. (2025). Звіт щодо виконання Угоди про асоціацію між Україною та ЄС за 2023-2024 роки.6. Рада Європейського Союзу. (2022). Рішення Ради Європейського Союзу щодо кібербезпеки.7. National Institute of Standards and Technology. (2004). Standards for security categorization of federalinformation and information systems (FIPS PUB 199).8. National Institute of Standards and Technology. (2020). Security and privacy controls for information systemsand organizations (NIST Special Publication 800-53, Revision 5).9. National Institute of Standards and Technology. (2020). Protecting controlled unclassified information innonfederal systems and organizations (NIST Special Publication 800-171, Revision 2).10. NATO. (2017, December 20). Confidentiality Metadata Label Syntax (STANAG 4774 Ed 1; ADatP-4774 EdA Ver 1). NATO.11. NATO. (2018, October 26). Metadata Binding Mechanism (ADatP-4778 Ed A Ver 1; STANAG 4778 Ed 1).NATO.12. NATO (SECAN). (2009, August). TEMPEST Product Qualification and Control (SDIP-55).13. NATO (SECAN). (n.d.). Emission Security / Compromising Emanations Standard (SDIP-27).14. NATO (SECAN). (n.d.). Zoning Procedures for Emission Security (SDIP-28).15. NATO. (2002, 17 червня). Security Within the North Atlantic Treaty Organization (Document C-M(2002)49).16. NATO. (2002, July 11). The Management of Non-Classified NATO Information (Document C-M(2002)60).17. НІКС. (2024). Перелік нормативно-методичних документів в галузі захисту інформації.18. Інститут кібернетики імені В. М. Глушкова НАН України. (2025). Історія.19. Верховна Рада України. (1994). Закон України «Про державну таємницю» (№ 3855-XII). Офіційнийвісник України.20. Служба безпеки України. (2020, 23 грудня). Наказ «Про затвердження Зводу відомостей, що становлятьдержавну таємницю» (№ 383).21. The White House. (2009, December 29). Executive Order 13526: Classified National Security Information(Vol. 75, No. 2). Federal Register.22. North Atlantic Council. (2007, December 11). The NATO Information Management Policy (NIMP) (CM(2007)0118)23. North Atlantic Treaty Organization. (рік). STANAG 4779: Confidentiality Metadata Binding. NATOStandardization Office.24. North Atlantic Treaty Organization. (2020). Directive on personnel security (AC/35-D/2000-REV8). NATOSecurity Committee.25. North Atlantic Treaty Organization. (2020). Directive on physical security (AC/35-D/2001-REV3). NATOSecurity Committee.26. North Atlantic Treaty Organization. (n.d.). NATO Security Incident Reporting Procedures [Internal document].NATO Communications and Information Agency.27. Адміністрація Державної служби спеціального зв’язку та захисту інформації України. (2013, 15 квітня).Захист інформації на об’єктах інформаційної діяльності. Положення про категоріювання об’єктів, де циркулюєінформація з обмеженим доступом, що не становить державної таємниці: НД ТЗІ 1.6-005-2013 (Наказ № 215).28. Адміністрація Державної служби спеціального зв'язку та захисту інформації України. (2016). НД ТЗІ3.6-003-2016: Порядок проведення робіт зі створення та атестації комплексів технічного захисту інформації(Наказ № 41/дск).29. Адміністрація Державної служби спеціального зв’язку та захисту інформації України. (2024).НД ТЗІ 2.3-025-24: Методика оцінювання заходів захисту інформації, вимога щодо захисту якої встановленазаконом та не становить державної таємниці, для інформаційних систем (Наказ № 45/дск).30. Адміністрація Державної служби спеціального зв’язку та захисту інформації України. (2023). НД ТЗІ3.7-003-2023: Порядок проведення робіт зі створення комплексної системи захисту інформації в інформаційнокомунікаційній системі (Наказ № 924).31. Державна служба спеціального зв’язку та захисту інформації України. (2003). НД ТЗІ 2.5-010-2003:Вимоги до захисту інформації WEB-сторінки від несанкціонованого доступу. Київ: Держспецзв’язку України.Затверджено наказом ДСТСЗІ СБ України від 02.04.2003 № 33.Генеральна лінія розвитку України полягає в її вступі в ЄС, що вимагає гармонізації законодавчої танормативно-правової бази України до вимог ЄС. В сфері захисту інформації ці процеси почались більше 20-ироків тому, однак їх пік відбувається безпосередньо зараз. Керівництвом держави, в рамках підготовки Українидо вступу до ЄС, поставлене завдання по оновленню всієї нормативно-правової бази з максимальнимврахуванням вимог NIS 2 та NIST. Однак, дія вказаних нормативних документів не розповсюджується наструктуру та алгоритми дії систем безпеки щодо інформації з обмеженим доступом, особливо такої, що мітитьдержавну таємницю. В роботі проведено порівняльний аналіз діючої в Україні нормативно-правової бази звимогами NIS 2, NIST, NIST-SP-800 та відповідними документами НАТО. Результати дослідження показализначну нерівномірність по об’ємам робіт щодо реконфігурації нормативно-правової бази України. Так, впитаннях забезпечення захисту інформації на об’єктах інформаційної діяльності критичної інфраструктуриголовним питанням є підвищення рівня теоретичної підготовки працівників нижньої ланки. Практичні навички,в більшості випадків, у цих працівників знаходяться на високому рівні. При цьому головне питанняреконфігурації полягає в зменшенні рівня формалістики в їх роботі – колосальна кількість звітів, актів,протоколів та інше, що забирають більшість робочого часу. З іншого боку, в сфері кіберзахисту, Україна маєзначні проблеми в нормативно-правовому забезпеченні. Це багато в чому, пов’язане з неможливістюформалізувати звітність по виконаних роботах і небажанням молодих фахівців, що в більшості випадків маютьвисокі теоретичні і практичні навички, до роботи з таким рівнем формалізації звітності. Ці проблеми, багато вчому, вже вирішені в Регламентах ЄС та США щодо побудови систем кібербезпеки. Тим більше, що питанняпобудови систем захисту інформації від загроз кібербезпеці, в більшості випадків, є інваріантним до інформації,що потребує захисту.Ключові слова: системи захисту інформації, НД ТЗІ, NIS 2, NIST, NIST-SP-800, CIS, STANAG. Перелік посилань1. Верховна Рада України. (2019, 7 лютого). Закон України «Про внесення змін до Конституції України(щодо стратегічного курсу держави на набуття повноправного членства України в Європейському Союзі та вОрганізації Північноатлантичного договору)» № 2680-VIII.2. European Council. (1993, June 21–22). Conclusions of the Copenhagen European Council. Copenhagen,Denmark3. European Union, & Ukraine. (2014). Association Agreement between the European Union and its MemberStates, of the one part, and Ukraine, of the other part. Official Journal of the European Union, L 161, 3–2137.4. Кабінет Міністрів України. (2025). Звіт про виконання Угоди про асоціацію між Україною таЄвропейським Союзом за 2024 рік. Офіційний вебсайт Кабінету Міністрів України.5. Європейська Комісія. (2025). Звіт щодо виконання Угоди про асоціацію між Україною та ЄС за 2023-2024 роки.6. Рада Європейського Союзу. (2022). Рішення Ради Європейського Союзу щодо кібербезпеки.7. National Institute of Standards and Technology. (2004). Standards for security categorization of federalinformation and information systems (FIPS PUB 199).8. National Institute of Standards and Technology. (2020). Security and privacy controls for information systemsand organizations (NIST Special Publication 800-53, Revision 5).9. National Institute of Standards and Technology. (2020). Protecting controlled unclassified information innonfederal systems and organizations (NIST Special Publication 800-171, Revision 2).10. NATO. (2017, December 20). Confidentiality Metadata Label Syntax (STANAG 4774 Ed 1; ADatP-4774 EdA Ver 1). NATO.11. NATO. (2018, October 26). Metadata Binding Mechanism (ADatP-4778 Ed A Ver 1; STANAG 4778 Ed 1).NATO.12. NATO (SECAN). (2009, August). TEMPEST Product Qualification and Control (SDIP-55).13. NATO (SECAN). (n.d.). Emission Security / Compromising Emanations Standard (SDIP-27).14. NATO (SECAN). (n.d.). Zoning Procedures for Emission Security (SDIP-28).15. NATO. (2002, 17 червня). Security Within the North Atlantic Treaty Organization (Document C-M(2002)49).16. NATO. (2002, July 11). The Management of Non-Classified NATO Information (Document C-M(2002)60).17. НІКС. (2024). Перелік нормативно-методичних документів в галузі захисту інформації.18. Інститут кібернетики імені В. М. Глушкова НАН України. (2025). Історія.19. Верховна Рада України. (1994). Закон України «Про державну таємницю» (№ 3855-XII). Офіційнийвісник України.20. Служба безпеки України. (2020, 23 грудня). Наказ «Про затвердження Зводу відомостей, що становлятьдержавну таємницю» (№ 383).21. The White House. (2009, December 29). Executive Order 13526: Classified National Security Information(Vol. 75, No. 2). Federal Register.22. North Atlantic Council. (2007, December 11). The NATO Information Management Policy (NIMP) (CM(2007)0118)23. North Atlantic Treaty Organization. (рік). STANAG 4779: Confidentiality Metadata Binding. NATOStandardization Office.24. North Atlantic Treaty Organization. (2020). Directive on personnel security (AC/35-D/2000-REV8). NATOSecurity Committee.25. North Atlantic Treaty Organization. (2020). Directive on physical security (AC/35-D/2001-REV3). NATOSecurity Committee.26. North Atlantic Treaty Organization. (n.d.). NATO Security Incident Reporting Procedures [Internal document].NATO Communications and Information Agency.27. Адміністрація Державної служби спеціального зв’язку та захисту інформації України. (2013, 15 квітня).Захист інформації на об’єктах інформаційної діяльності. Положення про категоріювання об’єктів, де циркулюєінформація з обмеженим доступом, що не становить державної таємниці: НД ТЗІ 1.6-005-2013 (Наказ № 215).28. Адміністрація Державної служби спеціального зв'язку та захисту інформації України. (2016). НД ТЗІ3.6-003-2016: Порядок проведення робіт зі створення та атестації комплексів технічного захисту інформації(Наказ № 41/дск).29. Адміністрація Державної служби спеціального зв’язку та захисту інформації України. (2024).НД ТЗІ 2.3-025-24: Методика оцінювання заходів захисту інформації, вимога щодо захисту якої встановленазаконом та не становить державної таємниці, для інформаційних систем (Наказ № 45/дск).30. Адміністрація Державної служби спеціального зв’язку та захисту інформації України. (2023). НД ТЗІ3.7-003-2023: Порядок проведення робіт зі створення комплексної системи захисту інформації в інформаційнокомунікаційній системі (Наказ № 924).31. Державна служба спеціального зв’язку та захисту інформації України. (2003). НД ТЗІ 2.5-010-2003:Вимоги до захисту інформації WEB-сторінки від несанкціонованого доступу. Київ: Держспецзв’язку України.Затверджено наказом ДСТСЗІ СБ України від 02.04.2003 № 33

    ВИКОРИСТАННЯ МЕТОДІВ ШТУЧНОГО ІНТЕЛЕКТУ ДЛЯ ВИЯВЛЕННЯ ВРАЗЛИВОСТЕЙ НУЛЬОВОГО ДНЯ

    No full text
    Rapid digitalization and widespread use of open-source software significantly increase the risks of new threats insoftware supply chains. Zero-day vulnerabilities are especially dangerous, which can imperceptibly enter projects through thirdparty libraries and remain undetected until their actual operation. In such conditions, it is relevant to find approaches that canprovide proactive dependency analysis and timely detection of potentially dangerous components. The aim of the article is toassess the possibilities of using artificial intelligence methods to identify vulnerable third-party libraries and analyze theeffectiveness of such an approach based on modeling a real incident of compromise of a third-party library. The paper describesthe characteristic properties of zero-day vulnerabilities, and also emphasizes the limitations of traditional security tools that arenot always able to respond promptly to new threats or take into account transitive dependencies. The conducted experimentinvolved the analysis of ten test projects using an agent approach based on various artificial intelligence models, which allowedus to assess their ability to detect compromised components, generate structured reports, and provide recommendations forminimizing risks. The results obtained confirmed the accuracy of the approach and its potential for integration into modernsoftware development and maintenance processes. At the same time, the non-determinism of the work of language models wasemphasized, which necessitates additional verification of the obtained results. The conducted research outlines furtherdevelopment prospects, in particular, improving proactive monitoring mechanisms, as well as developing methods for verifying results obtained using artificial intelligence methods, which will contribute to increasing the reliability and validity of analyticalconclusions.Keywords: artificial intelligence, zero-day vulnerabilities, software security, automation, open libraries, software. References1. Systematic Review of Current Approaches and Innovative Solutions for Combating Zero-Day Vulnerabilitiesand Zero-Day Attacks. (n.d.). Retrieved November 9, 2025, from https://ieeexplore.ieee.org/document/11028033.2. Anasuri, S. (2023). Secure Software Supply Chains in Open-Source Ecosystems. International Journal ofEmerging Trends in Computer Science and Information Technology, 4(1), 62–74. https://doi.org/10.63282/3050-9246.IJETCSIT-V4I1P108.3. Gunasekara, A. (2023). AI-Driven Big Data Analytics for Transforming Cybersecurity for Zero-DayVulnerabilities in E-Commerce Supply Chains. Journal of Advances in Cybersecurity Science, Threat Intelligence, andCountermeasures, 7(12), 17–31.4. Kumar, V., & Sinha, D. (2021). A robust intelligent zero-day cyber-attack detection technique. Complex &Intelligent Systems, 7, 2211–2234. https://doi.org/10.1007/s40747-021-00396-9.5. (PDF) A Comprehensive Review of Open-Source Malware Scanners in the Software Supply Chain. (2025,March 24). ResearchGate. https://www.researchgate.net/publication/395471396_A_Comprehensive_Review_of_OpenSource_Malware_Scanners_in_the_Software_Supply_Chain.6. Pre-Build OSS Compliance: Automated Dependency, License, and CVE Detection. (n.d.). Retrieved November9, 2025, from https://ieeexplore.ieee.org/abstract/document/11136967.7. Shu, C., Chen, W., Fan, G., Yu, H., Huang, Z., & Liang, Y. (2025). Tool or Toy: Are SCA tools ready forchallenging scenarios? Computers & Security, 158, 104624. https://doi.org/10.1016/j.cose.2025.104624.8. Imtiaz, N., Thorne, S., & Williams, L. (2021, August 27). A Comparative Study of Vulnerability Reporting bySoftware Composition Analysis Tools. arXiv.Org. https://doi.org/10.1145/3475716.3475769.9. Software Composition Analysis for Vulnerability Detection: An Empirical Study on Java Projects | Proceedingsof the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of SoftwareEngineering (world). (n.d.). ACM Conferences. https://doi.org/10.1145/3611643.3616299.10. Gunasekara, A. (2023). AI-Driven Big Data Analytics for Transforming Cybersecurity for Zero-DayVulnerabilities in E-Commerce Supply Chains. Journal of Advances in Cybersecurity Science, Threat Intelligence, andCountermeasures, 7(12), 17–31.11. Jiang, L., An, J., Huang, H., Tang, Q., Nie, S., Wu, S., & Zhang, Y. (2024, January 20). BinaryAI: BinarySoftware Composition Analysis via Intelligent Binary Source Code Matching. arXiv.Org. https://arxiv.org/abs/2401.11161v3.12. Sane, P. (2020). Is the OWASP Top 10 List Comprehensive Enough for Writing Secure Code? 58–61. Scopus.https://doi.org/10.1145/3437075.3437089.13. GHSA-8mgj-vmr8-frr6—GitHub Advisory Database. (n.d.). GitHub. Retrieved November 17, 2025, fromhttps://github.com/advisories/GHSA-8mgj-vmr8-frr6.14. debug-js. (n.d.). (RESOLVED) Version 4.4.2 published to npm is compromised · Issue #1005 · debugjs/debug. GitHub. Retrieved November 17, 2025, from https://github.com/debug-js/debug/issues/1005.Стрімка цифровізація та широко поширене використання відкритого програмного забезпечення істотнопідвищують ризики появи нових загроз у ланцюгах постачання ПЗ. Особливо небезпечними є вразливостінульового дня, які можуть непомітно потрапляти у проєкти через сторонні бібліотеки та залишатисяневиявленими до моменту їх фактичної експлуатації. У таких умовах актуальним є пошук підходів, здатнихзабезпечити проактивний аналіз залежностей та своєчасне виявлення потенційно небезпечних компонентів.Метою статті є оцінка можливостей застосування методів штучного інтелекту для ідентифікації вразливихсторонніх бібліотек та аналіз ефективності такого підходу на основі моделювання реального інцидентукомпрометації сторонньої бібліотеки. У роботі описано характерні властивості вразливостей нульового дня, атакож підкреслено обмеження традиційних інструментів забезпечення безпеки, які не завжди здатні оперативнореагувати на нові загрози або враховувати транзитивні залежності. Проведений експеримент передбачав аналіздесяти тестових проєктів із використанням агентного підходу на основі різних моделей штучного інтелекту, щодозволило оцінити їхню здатність виявляти скомпрометовані компоненти, формувати структуровані звіти танадавати рекомендації щодо мінімізації ризиків. Отримані результати підтвердили точність підходу та йогопотенціал для інтеграції в сучасні процеси розробки та супроводу програмного забезпечення. Водночаспідкреслено недетермінованість роботи мовних моделей, що зумовлює необхідність додаткової перевіркиотриманих результатів. Проведене дослідження окреслює подальші перспективи розвитку, зокремавдосконалення механізмів проактивного моніторингу, а також розробку методів верифікації результатів,отриманих із використанням методів штучного інтелекту, що сприятиме підвищенню достовірності та надійностіаналітичних висновків.Ключові слова: штучний інтелект, вразливості нульового дня, безпека ПЗ, автоматизація, відкритібібліотеки, програмне забезпечення. Перелік посилань1. Systematic Review of Current Approaches and Innovative Solutions for Combating Zero-Day Vulnerabilitiesand Zero-Day Attacks. (n.d.). Retrieved November 9, 2025, from https://ieeexplore.ieee.org/document/11028033.2. Anasuri, S. (2023). Secure Software Supply Chains in Open-Source Ecosystems. International Journal ofEmerging Trends in Computer Science and Information Technology, 4(1), 62–74. https://doi.org/10.63282/3050-9246.IJETCSIT-V4I1P108.3. Gunasekara, A. (2023). AI-Driven Big Data Analytics for Transforming Cybersecurity for Zero-DayVulnerabilities in E-Commerce Supply Chains. Journal of Advances in Cybersecurity Science, Threat Intelligence, andCountermeasures, 7(12), 17–31.4. Kumar, V., & Sinha, D. (2021). A robust intelligent zero-day cyber-attack detection technique. Complex &Intelligent Systems, 7, 2211–2234. https://doi.org/10.1007/s40747-021-00396-9.5. (PDF) A Comprehensive Review of Open-Source Malware Scanners in the Software Supply Chain. (2025,March 24). ResearchGate. https://www.researchgate.net/publication/395471396_A_Comprehensive_Review_of_OpenSource_Malware_Scanners_in_the_Software_Supply_Chain.6. Pre-Build OSS Compliance: Automated Dependency, License, and CVE Detection. (n.d.). Retrieved November9, 2025, from https://ieeexplore.ieee.org/abstract/document/11136967.7. Shu, C., Chen, W., Fan, G., Yu, H., Huang, Z., & Liang, Y. (2025). Tool or Toy: Are SCA tools ready forchallenging scenarios? Computers & Security, 158, 104624. https://doi.org/10.1016/j.cose.2025.104624.8. Imtiaz, N., Thorne, S., & Williams, L. (2021, August 27). A Comparative Study of Vulnerability Reporting bySoftware Composition Analysis Tools. arXiv.Org. https://doi.org/10.1145/3475716.3475769.9. Software Composition Analysis for Vulnerability Detection: An Empirical Study on Java Projects | Proceedingsof the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of SoftwareEngineering (world). (n.d.). ACM Conferences. https://doi.org/10.1145/3611643.3616299.10. Gunasekara, A. (2023). AI-Driven Big Data Analytics for Transforming Cybersecurity for Zero-DayVulnerabilities in E-Commerce Supply Chains. Journal of Advances in Cybersecurity Science, Threat Intelligence, andCountermeasures, 7(12), 17–31.11. Jiang, L., An, J., Huang, H., Tang, Q., Nie, S., Wu, S., & Zhang, Y. (2024, January 20). BinaryAI: BinarySoftware Composition Analysis via Intelligent Binary Source Code Matching. arXiv.Org. https://arxiv.org/abs/2401.11161v3.12. Sane, P. (2020). Is the OWASP Top 10 List Comprehensive Enough for Writing Secure Code? 58–61. Scopus.https://doi.org/10.1145/3437075.3437089.13. GHSA-8mgj-vmr8-frr6—GitHub Advisory Database. (n.d.). GitHub. Retrieved November 17, 2025, fromhttps://github.com/advisories/GHSA-8mgj-vmr8-frr6.14. debug-js. (n.d.). (RESOLVED) Version 4.4.2 published to npm is compromised · Issue #1005 · debugjs/debug. GitHub. Retrieved November 17, 2025, from https://github.com/debug-js/debug/issues/1005

    1,003

    full texts

    2,308

    metadata records
    Updated in last 30 days.
    State University of Telecommunications Open Journals System
    Access Repository Dashboard
    Do you manage Open Research Online? Become a CORE Member to access insider analytics, issue reports and manage access to outputs from your repository in the CORE Repository Dashboard! 👇