ANALYSIS OF VULNERABILITIES AND CYBERATTACKS ON INFORMATION RESOURCES PROCESSED WITHIN INFORMATION SYSTEMS

Authors

  • M. Koval Military Institute of Kyiv National Taras Shevchenko University Author
  • O. Kravchenko Military Institute of Kyiv National Taras Shevchenko University Author
  • A. Karpenko Military Institute of Kyiv National Taras Shevchenko University Author
  • N. Shamraii Military Institute of Kyiv National Taras Shevchenko University Author

DOI:

https://doi.org/10.17721/2519-481X/2025/89-05

Keywords:

information resources, information system, cyber threat, information weapons, cyberattack combinations, information security system

Abstract

The article examines the state of security across critical infrastructure and the technosphere as a whole. Typically, four types of facilities are distinguished based on their degree of potential dangers and specific protection requirements: technical control facilities, hazardous industrial facilities, critically significant facilities, and strategically priority military facilities able to affect national security.
Information technologies provide a crucial effect by allowing the precise regulation of informational influence based on the recipient. Multiple variations of virtual reality can be generated; moreover, this environment can be dynamically adapted to the needs of a specific user at the very moment they submit a request.
It is demonstrated that for the effective operation of an information system (IS), an appropriate security assurance subsystem should be integrated into the information resource (IR) management system. This subsystem must be capable of assessing and managing the IS security condition in real time, accounting for the rapidly evolving nature of cyberattacks.
The paper formulates the concept of information weaponry, which combines the electronic and human aspects of information technologies. Consequently, the continuous daily operation of various automated systems (AS) and information systems (IS) is of critical importance. Conversely, humans remain the primary strategic target of information weapons. Information systems must possess the capability to detect and prevent intrusions which are realized by a multitude of attacks of different types in terms of their physical nature. To facilitate this, the information security system (ISS) must incorporate a security information and event management (SIEM) system.

Author Biographies

References

1. Salnyk S.V., Storchak A.S., Herasimov K.K. (2019) Analiz funktsionuvannia system upravlinnia derzhavnymy informatsiinymy resursamy [Analysis of the functioning of state information resource management systems]. Shchokvartalnyi naukovo-tekhnichnyi zhurnal Nauka i tekhnika Povitrianykh Syl Zbroinykh Syl Ukrainy. Vyp. 2(35). S.47-54. (in Ukrainian)

2. Subach I.Yu, Fesokha V.V., Holub O.O, Krykhovetskyi V.V. (2018) Nechitke vyznachennia "typovosti" statystychnoi povedinky u informatsiino-telekomunikatsiinykh merezhakh [ Unclear definition of the "typicality" of statistical behavior in information and telecommunications networks.]. Priorytetni napriamky rozvytku telekomunikatsiinykh system ta merezh spetsialnoho pryznachennia. Zastosuvannia pidrozdiliv, kompleksiv, zasobiv zviazku ta avtomatyzatsii v operatsii Obiednanykh syl : zb. materialiv XI nauk.-prakt. konf., 8-9 lyst. 2018 r. Kyiv : VITI im. Heroiv Krut, 2018. 213. (in Ukrainian)

3. Ukaz Prezydenta Ukrainy (2021) "Pro rishennia Rady natsionalnoi bezpeky i oborony Ukrainy "Pro Stratehichnyi oboronnyi biuleten Ukrainy" № 473/2021 Available at: https:// https://zakon.rada.gov.ua/laws/show/473/2021#Text . (accessed 23 January 2023). (in Ukrainian)

4. Lepikh Ya.I., Hordiienko Yu.O, Dziadevych S.V., Druzhynin A.O., Yevtukh A.A.,. Lienkov S.V., Melnyk V.H., Protsenko V.O., Romanov V.O. (2011). Mikroelektronni datchyky novoho pokolinnia dlia intelektualnykh system. [New generation microelectronic sensors for intelligent systems.] Odesa: "Astroprint". (in Ukrainian)

5. Korpan Ya.V. (2015) Klasyfikatsiia zahroz informatsiinii bezpetsi v kompiuternykh systemakh pry viddalenii obrobtsi danykh Reiestratsiia, zberihannia i obrobka danykh [ Classification of threats to information security in computer systems during remote data processing. Data registration, storage and processing. ]. 2015. Vyp. 17(2). S. 39-46.

6. Horbenko V.I., Kartavykh V.Yu., Subach I.Yu.(2013) Model monitorynhu domenu upravlinnia informatsiinoi merezhi viiskovoho pryznachennia [ Military information network control domain monitoring model ] Systemy obrobky informatsii. Vyp. 4(111). 118-122.

7. Tewari N., Bhardwaj A. (2013) Flow Statistics Based Detection of Low Rate and High Rate DDoS Attacks International Journal of Scientific & Engineering Research. Vol. 4, 5. 348-353. (in English)

8. Xiao P., He J., Chen Y., Fu Y. A(2013) A new trusted roaming protocol in wireless mesh networks .International Journalof Sensor Networks,14, Issue 2. P. 109 -119. (in English) https:// doi.org/ 10.1504/IJSNET.2013.056610 89

9.Ofitsiinyi sait Common Vulnerabilities and Exposures. Rezhym dostupu: http://cve.mitre.org(in English)

10. Ofitsiinyi sait National Vulnerabilities Database. Rezhym dostupu: http://nvd.nist.gov(in English)

11.Ofitsiinyi sait United States Computer Emergency Readiness Team. Rezhym dostupu: http://www.us-cert.gov(in English)

12. Zhang Y., Lee W., Huang Y. (2003) Intrusion detection techniques for mobile wireless networks. Wireless Networks Journal (ACM WINET). 2003. № 9(5). Р. 545–556. (in English)

13. Janakiraman R., Waldvogel M., Zhang Qi. (2003) A peer-to-peer approach to networkintrusion detection and prevention. Enabling Technologies: Infrastructure for Collaborative Enterprises. . Р. 226–231, DOI:10.1109/ENABL. 2003.1231412 (in English)

14. Alshboul Y., Streff K.(2015), Analyzing Information Security Model for Small-Medium Sized Businesses, Twenty-first Americas Conference on Information Systems, Puerto Rico (in English)

15.Safa N.S., Solms R.V., Furnell S.(2016) Information security policy compliance model in organizations. Computers & Security. 2016. Vol. 56. P. 70-82. DOI:10.1016/j.cose.2015.10.006 (in English)

Published

2025-12-18

Issue

Section

INFORMATION TECHNOLOGIES