<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Ontology of Cyber Security of Self-Recovering Smart GRID</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Sergei A. Petrenko</string-name>
          <email>s.petrenko@rambler.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Department of Informatics and Information Technologies Vernadsky Crimean Federal University Yalta</institution>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Information Security Department Saint Petersburg Electrotechnical University (LETI) St. Petersburg</institution>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2003</year>
      </pub-date>
      <fpage>98</fpage>
      <lpage>106</lpage>
      <abstract>
        <p>-The article describes the modern Smart Grid from the standpoint of providing resistance to negative impacts, preventing them, and quickly restoring functions after accidents in accordance with the requirements of energy security. To implement this goal, the developed ontology of cyber-security of self-recovering Smart Grids has been proposed for implementation. A critical analysis of approaches and methods to ensure the sustainability of the functioning of power systems in the event of their destabilization. The ideology of sustainability of Smart Grid power systems on the basis of immunity was developed and a scheme for the formation of immunity for disturbances was proposed.</p>
      </abstract>
      <kwd-group>
        <kwd>Smart Grid</kwd>
        <kwd>ontology</kwd>
        <kwd>self-recovery</kwd>
        <kwd>immunity</kwd>
        <kwd>cyber-security</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>INTRODUCTION</p>
      <p>Currently, in a number of developed countries, the
technology of intelligent power grids Smart Grid
(activeadaptive intelligent network) is widely used to deliver
electricity to the consumer using modern digital technologies.</p>
      <p>
        Smart Grid technologies, when implemented in the energy
systems, both existing and new, designed, can provide the
required innovative properties of the systems. Thanks to Smart
Grid energy saving is provided, costs are reduced, network
reliability and transparency of the management process are
increased. To implement large-scale programs for transforming
electric grids into intelligent ones and developing appropriate
standard solutions, the world's largest companies have
established the Smart Energy Alliance. It includes GE Energy
(General Electric), Capgemini, Cisco Systems, Siemens, HP,
Intel, SAP AG, Oracle, and others [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. However, modern
power systems, which are complex distributed heterogeneous
systems, do not possess the required stability for targeted
operation in the current and anticipated information
confrontation, because of the high complexity of construction
and the potential danger of undeclared functioning of
equipment and system-wide software, including hypervisors of
the enemy. The relevance of the development of the
cybersecurity ontology for self-recovering Smart Grid is explained
by the need to create an intelligent system for ensuring the
sustainability of "smart" energy systems in the context of
information countermeasures.
      </p>
    </sec>
    <sec id="sec-2">
      <title>II. PROBLEMS OF RESTORING THE</title>
      <p>SUSTAINABILITY OF THE SMART GRID</p>
      <p>Today, the most significant projects to create power grids
based on the Smart Grid are carried out in the USA and Russia,
in the countries of the European Union, as well as in Canada,
Australia, China and Korea. In the last decade, various models
have been developed to assess the readiness of electrical
networks to convert to intelligent levels of Smart Grid
technologies.</p>
      <p>
        The first model was developed on the basis of the widely
used software industry maturity model (Maturity Model), led
by IBM, in 2007. As the utility industry embarks on the
transformation of the outdated power grid to the new smart
grid, it has to develop a shared vision for the smart grid
endstate and the path to its development and deployment. The
smart grid maturity model (SGMM) is presenting a consepsion
of the smart grid, the benefits it can bring and the various levels
of development. SGMM is helping numerous utilities
worldwide develop targets for their smart grid strategy, and
build roadmaps of the activities, investments and best practices
that will lead them to their future smart grid state. IBM worked
closely with members of the Intelligent Utility Network
Coalition (IUNC) to develop, discuss and revise several drafts
of the SGMM. Also, this team was assisted by APQC, a
member-based nonprofit organization that provides
benchmarking and best-practice research for approximately
500 organizations worldwide [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>This model was brought to practical use by programmers
from the Carnegie Mellon University, SEI (Software
Engineering Institute). The Carnegie Mellon Software
Engineering Institute was govern the SGMM model, working
in conjunction with Carnegie Mellon University and the
Carnegie Mellon Electricity Industry Center. Then, the institute
was leverage its 20 years of experience with goal of
workingout of the Capability Maturity Model Integration (CMMI).</p>
      <p>In Russia, since 2011, a large-scale project to create an
intelligent power system with an active-adaptive network (IPS
AAN) is being implemented.</p>
      <p>Expert working groups led by the Architectural Committee
at the Scientific and Technical Council of JSC FGC UES and
the Russian Academy of Sciences (RAS) developed the main
provisions and approaches to the creation of a reference
architecture of the said intellectual power system. As part of
the implementation of this project in the UES of the East for
the period until 2014 with the prospect of up to 2020, the IPS
AAN polygon was created, which is a complex of software and
hardware that form the environment for supporting the
development of IPS AAN solutions.</p>
      <p>The main purpose of the Polygon is to support the
implementation of projects in the field of intellectual energy
(Smart Grid) at all stages of the life cycle of these projects, as
well as the implementation of a unique "ecosystem" that
contributes to the sustainable innovation development of the
power grid complex of the Russian Federation.</p>
      <p>It is significant that in these projects the key is to make the
future Smart Grid energy systems and the development of the
following two new capabilities:</p>
      <p>
         Resistance to negative impacts: the availability of special
methods for ensuring sustainability and survivability, reducing
the physical and information vulnerability of all components
of the energy system and contributing to both prevention and
rapid recovery from accidents in accordance with energy
security requirements [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ];
      </p>
      <p> Self-recovery in emergency situations: the power system
and its elements should be able to maintain their technical
condition continuously in an efficient state by identifying,
analyzing and switching from management to the occurrence
of a situation to a preventive (warning) occurrence.
Selfrecovering power system should allow maximum possible to
minimize disruptions (disturbances) with the help of an
intelligent control system, including its most important
component - the subsystem of cyber security.</p>
      <p>Thus, an intelligent grid based on Smart Grid should be
proactive in relation to changing operational conditions and
monitor the impending technical problems before they can
adversely affect its safety and the sustainability of the operation
as a whole. Therefore, the components of the designed
intellectual subsystems of cybersecurity should include the
appropriate components of containment, prevention, detection,
neutralization and self-recovery.</p>
      <p> Multi-agent systems for coordinating control systems
using a transient regimes monitoring system (RTMS) and
FACTS devices, self-recovery of district power plants;
 Artificial intelligence, and, including, neural networks
for solving problems of identification and management; expert
systems for training and conducting training, early detection
and localization of emergency pre-emergency regimes;
 Adaptive vector control of flexible AC systems for
primary and secondary automatic control of voltage and
reactive power, optimization of power modes;</p>
      <p> Adaptive automatic control for renewable energy
sources, including wind, tidal, solar, and in the future, space
solar power plants;</p>
      <p> Intellectual cybersecurity, capable of providing the
required stability of the future Smart Grid energy systems in
the context of information confrontation, etc.</p>
      <p>III.</p>
    </sec>
    <sec id="sec-3">
      <title>ONTOLOGY OF CYBERSECURITY One of the special issues of computer science and artificial intelligence is ontology. 99</title>
      <p>
        In intellectual grids based on Smart Grid, it is advisable to
use ontology (meta-ontology) of cyber-security as a way of
representing knowledge about qualitative characteristics and
quantitative patterns of information confrontation [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>
        The ontology of cybersecurity, according to Thomas
Grubber, is a certain specification of the conceptualization of
the subject area of information confrontation [
        <xref ref-type="bibr" rid="ref4 ref5">4, 5</xref>
        ].
      </p>
      <p>
        Previously, questions of ontological modeling and artificial
intelligence were considered by T. Gruber, N. Guarino, D.
Oberle, and others, and in the Russia by G. S. Pospelov,
D. A. Pospelov, E. V. Popov, L. S. Mussel, A. S. Kleshchev,
I. L. Artemyeva, T. N. Vorozhtsova, D. N. Biryukov,
I. V. Kotenko, A. G. Lomako, and many others [
        <xref ref-type="bibr" rid="ref10 ref11 ref12 ref13 ref14 ref15 ref16 ref17 ref18 ref3 ref6 ref7 ref8 ref9">3, 6-16, 17,
18</xref>
        ]. Presently, knowledge models are known in the form of
frame systems, semantic networks and production systems.
Frame systems and semantic networks allow us to describe the
structure of objects in the domain and the relationship between
them. Systems of products (rules) are used to represent
knowledge of the domain in the form of statements "if-then".
On the basis of these models, various knowledge representation
languages have been developed, which are the input languages
for some universal shells and expert systems.
      </p>
      <p>
        In the works of A. S. Kleschev. and Artemieva I. L. [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]
formulated the main methodological principles for determining
the ontology of the subject area.
      </p>
      <p>1) On the substantive level, ontology is understood to mean
the totality of agreements (definitions of terms of the subject
domain, their interpretation, statements that limit the possible
meaning of these terms, as well as the interpretation of these
statements). Unlike empirical knowledge, these agreements can
not be refuted by empirical observations.</p>
      <p>2) Ontology, conceptualization, knowledge and reality must
be modeled by a single mathematical construction.</p>
      <p>3) An explicit correspondence must be established between
the properties of the subject domains and the elements of this
mathematical construction.</p>
      <p>4) The ontology model of each subject area should contain
both formal elements and their meaningful interpretation in
terms understandable to specialists of this subject area.</p>
      <p>5) The ontology and its model should be observable even
for complex subject areas with a large number of concepts.</p>
      <p>
        In the works of I.V. Kotenko [
        <xref ref-type="bibr" rid="ref12 ref13 ref14">12-14</xref>
        ] considered ontology
and possible multi-agent intellectual mechanisms for managing
cybersecurity in computer systems and networks that allow to:
1) Collection of information on the status of the
information system and its analysis through mechanisms for
processing and merging information from various sources;
2) Proactive prevention of cyberattacks and preventing their
implementation;
      </p>
      <p>3) Detection of abnormal activity and explicit cyberattacks,
as well as illegitimate actions and deviations of users' work
from the security policy, prediction of intentions and possible
actions of violators;
4) Active response to attempts to implement the actions of
violators by automatic reconfiguration of protection
components to reflect the actions of violators in real time;
5) Misinformation of the attacker, concealment and
camouflage of important resources and processes, "enticement"
of the attacker into false (fraudulent) components for the
purpose of disclosing and clarifying its purposes, reflexive
control over the behavior of the attacker;</p>
      <p>6) Monitoring the functioning of the network and
monitoring the correctness of the current security policy and
network configuration;</p>
      <p>7) Support for decision-making on the management of
security policies, including on adaptation to subsequent
incursions and strengthening of critical defense mechanisms.</p>
      <p>
        In the works of D. Biryukov. and Lomako A.G. [
        <xref ref-type="bibr" rid="ref10 ref6">6, 10</xref>
        ] the
ontology and the system image of intellectual systems of
cyber-security with the property of anticipation are grounded.
In particular, a new class of systems to prevent computer
attacks, which are self-learning intellectual systems of
selforganizing gyromas. It is shown that the application of the
proposed intellectual systems in practice allows to more
successfully solve the problems associated with the prevention
of risks of the implementation of cyber threats.
      </p>
      <p>In 2011, based on the RDF language, basic for the Semantic
Web, a general conceptual (reference) model of the Smart Grid
was created, containing structured and unstructured
information (authors and support of researchers from the
Karlsruher Institut für Technologie Institut AIFB). Despite the
fact that this ontology was the most complete, the issues of
information protection in it, as well as in other Smart Grid
ontologies, were not considered.</p>
      <p>
        Russian scientists in [
        <xref ref-type="bibr" rid="ref20 ref21">20, 21</xref>
        ] was developed ontology
Smart Grid information security as a result of the merger of
two ontologies: Gridpedia and ontology of cybersecurity in the
energy sector (e.g. [
        <xref ref-type="bibr" rid="ref22 ref23">22, 23</xref>
        ]). The authors based on the fact that
Gridpedia can be used for a sufficiently detailed description of
the Smart Grid as a power system, and the ontology of
cybersecurity in the power industry allows us to describe the
system from the point of view of information security.
However, the practical implementation of a new ontology, like
Gridpedia, or the addition of Gridpedia with new resources was
not implemented (Gridpedia allows users to jointly define
concepts). In addition, the Gridpedia project was not, in
principle, supplemented or expanded from 2014.
      </p>
      <p>In the context of information confrontation, a more
advanced ontology of cyber security, Smart Grid, is required,
which allows to prevent the reduction of power systems to
catastrophic consequences.</p>
      <p>
        This formulation of the problem required a significant
revision of the well-known concept of providing information
security for Smart Grid. The point is that modern power
systems, which are complex distributed heterogeneous systems,
do not possess the required stability for targeted operation in
the current and prospective information warfare because of the
high complexity of construction and the potential danger of
undeclared operation of equipment and system-wide software,
including, hypervisors. The means of identifying and complex
neutralizing information and technical impacts combining the
possibilities of joint combined use of technologies for
obtaining unauthorized access, hardware-program bookmarks
and malicious software are still not effective enough [
        <xref ref-type="bibr" rid="ref1 ref10 ref20">1, 10,
20</xref>
        ].
      </p>
      <p>Moreover, neither traditional means of information
protection at the levels: Level 4 - ERP; Level 3 - MES; Level 2
- SCADA; Level 1 - Programmable logic controller (PLC) /
Relay protection and automation (RPA); Level 0 - field devices
that include traditional means: protection from unauthorized
access, firewalling, traffic filtering (Modbus, OPC, IEC 104),
detection and prevention of cyberattacks (IDS / IPS), antivirus
protection, cryptographic protection of information, analysis
security, integrity control and cyber security management in
general based on SCIRT / CERT / SOC), nor the known means
of ensuring the stability of power systems using backup,
calibration and reconfiguration capabilities are no longer
suitable for I ensure the required performance of the promising
Smart Grid in the conditions of information confrontation.</p>
      <p>IV.</p>
    </sec>
    <sec id="sec-4">
      <title>DEVELOPMENT OF A NEW ONTOLOGY OF</title>
      <p>CYBER-SECURITY</p>
      <p>
        The analysis of probable scenarios for the purposeful
informational impact on the future Smart Grid energy systems
was conducted with the aim of developing a new ontology of
cybersecurity. The typical structure of the mentioned power
systems is considered and the characteristics of their
vulnerabilities are given. The specifics of the implementation
of security threats and possible risks to the performance of a
typical power system are revealed. The specifics of the
implementation of information and technical impacts on
critical elements of prospective power systems are revealed
[
        <xref ref-type="bibr" rid="ref16">16</xref>
        ].
      </p>
      <p>
        A critical analysis of existing methods and tools for the
detection and neutralization of information and technology
impacts, including targeted or targeted attacks, APT. The
assessment is made of the suitability of traditional means of
protecting information in power systems for the prevention,
detection and neutralization of information and technology
impacts. The shortcomings of the organization of the means of
providing and monitoring the policy of cybersecurity on the
basis of IEC 62351-8 [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] are shown.
      </p>
      <p>As a result, the ontology of cyber-security of
selfrecovering Smart Grid was proposed, which allows describing
the organization of self-recovering of perspective energy
systems in conditions of information confrontation on the basis
of immunity to disturbances by analogy with the immune
system of protection of a living organism.</p>
      <p>The relevance of the new ontology of cyber security Smart
Grid is confirmed by the requirements of the Doctrine of
Information Security of Russia (2016), the federal law On the
Security of the Critical Information Infrastructure of the
Russian Federation (2017), GOSTs of the Federal Agency for
Technical Regulation and Metrology (2016) normative and
methodological documents (2007) and the order of FSTEC of
Russia "On approval of the Requirements for ensuring the
protection of information in automated control systems for
production and technological processes on critical issues ki
important objects ... "(2014) and others.</p>
      <p>In this article, the cyber-security ontology of
selfrecovering Smart Grid (hereinafter - the ontology of
cybersecurity) is understood as the basis for reusable
knowledge of a special kind, or the "specification of
conceptualization" of such a hard-formalized subject area as
ensuring the sustainability of functioning of perspective energy
systems in the context of information confrontation. This
means that in this area, based on the classification of the basic
terms of cybersecurity, it is first necessary to isolate the basic
concepts (concepts), and then to determine the connections
between them (conceptualization). In this case, the ontology of
cybersecurity can be represented both graphically and
analytically (for example, a formal grammar and programming
language or some mathematical model).</p>
      <p>Two methodological approaches were used to develop the
ontology of cybersecurity. In the first, for the graphical
representation of the ontology of cybersecurity, the IDEF5
Schematic Language is used, and for the analytical description
is the text language IDEF5 Elaboration Language. In order to
automate the simulation of this ontology of cyber security, a
demonstration prototype of the SBONT tool of Knowledge
Based Systems, Inc. is used.</p>
      <p>Implementation of the first methodological approach took 5
years (2000-2005). Currently, the ontology of cybersecurity
contains a description of 800 terms from the field of
information security (two volumes with a volume of 1284
pages with text and graphic schemes have been prepared), and
are constantly maintained in the current state.</p>
      <p>For the current version of the ontology of cybersecurity as
the initial data were also used terms and definitions of the
following regulations and recommendations of the best
practice:</p>
      <p>1. Thesaurus of normative documents "The Doctrine of
Information Security of Russia" (2016), "The main directions
of the state policy in the field of ensuring the safety of the
automated control system of the Russian Federation" and the
"System of Critical Objects ..." of the Security Council of the
Russian Federation.</p>
      <p>2. The thesaurus of the Federal Law of the Russian
Federation of July 27, 2006, No. 149-FZ "On Information,
Information Technologies and Information Protection", Federal
Law No. 16-FZ dated February 9, 2007 "On Transport
Security", Federal Law No. 256-FZ of July 21, FZ "On the
Safety of Fuel and Energy Complex Facilities", Federal Law
No. 116-FZ of 21.07.1997 "On Industrial Safety of Hazardous
Production Facilities", Federal Law of the Russian Federation
No. 170-FZ of 21.11.1995 "On the Use of Atomic Energy",
Federal Law " On the Security of the Critical Information
Infrastructure. "
2007 FSTEC documents: "Basic model of threats to
information security in key information infrastructure
systems", "Methodology for determining current threats to
information security in key information infrastructure
systems", "General requirements for ensuring information
security in key information infrastructure systems",
"Recommendations for ensuring information security in key
information infrastructure systems", "Regulations on the
registry of key information infrastructure systems"; draft
documents for 2016: "Protection measures in the automated
process control system", "Methodology for determining threats
to information security in the automated process control
system", "Procedure for identifying and eliminating
vulnerabilities in the automated process control system",
"Procedure for responding to incidents related to the violation
of information security".</p>
      <p>
        4. GOST R 53114-2008 "Ensuring information security in
the organization" and GOST R 50922-2006 "Information
security. Basic terms and definitions "; GOST of the Federal
Agency for Technical Regulation and Metrology - Network
communication industrial. Security (cybersecurity) of the
network and system: GOST R 56205-2014 IEC / TS
62443-11-200. Part 1-1. Terminology, conceptual provisions and
models, GOST R IEC 62443-2-1-2015. Part 2-1. Preparation of
the program for ensuring the security (cybersecurity) of the
control system and industrial automation, GOST R 56498-2015
/ IEC / PAS 62443-3: 2008. Part 3. The security (cybersecurity)
of the industrial measurement and control process; GOST R
56545-2015 "Information security. Vulnerabilities of
information systems. Vulnerability Definition Rules (defines
the content of vulnerability information that security control
vendors should include in their solution database, while the
document takes into account existing practices and
vulnerability description tools such as Common Weakness
Enumeration (CWE), the formal language the Open
Vulnerability and Assessment Language (OVAL), the
Common Vulnerability Scoring System (CVSS) vulnerability
assessment methodology; GOST R 56546-2015 "Information
security. Vulnerabilities of information systems. Classification
of vulnerabilities» (defines the most common types of
vulnerabilities, allowing to unify the terminology used by
pentester) [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ].
      </p>
      <p>
        5. Best practice: ISO / IEC 27000 standards in the general
principles of ensuring the safety of digital control systems,
including ISO / IEC 27032: 2012 "Guidelines for
Cybersecurity" and ISO / IEC 27000 "Information technology.
Methods of ensuring safety. Information security management
systems. General overview and terminology "; IEC TC57
standards: IEC 61850, IEC60870, IEC 62351 regarding the
safety of communication protocols; standard INL Cyber
Security Procurement Language 2008 [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ].
      </p>
      <p>6. Recommendations: NIST-800-82 r.2 "Guide to Industrial
Control Systems (ICS Security) - Guide for the security of
process control systems" dated 05.2015, Control Systems
Security Program / National Cyber Security Division
Recommendations for the developers of the standard), IEC
62443 and ISA 62443 (documents of the International
Electrotechnical Commission (IEC) and 99 of the Committee
for the Development of Safety Standards of the Automated
Automation System (ISA) of the International Automation
Society (ISA), NERC CIP (Critical Infrastructure Protection)
security (NERC), Departament of Homeland Security: Cyber
Security Procurement for ICS, Developments of US-CERT
(manuals, models of threats and infringers, rules for responding
to cybercriminal, vulnerability databases, etc.)</p>
      <p>The development of this ontology of cybersecurity was
carried out in stages:
1) defining the context of the ontology of cybersecurity;
2) data collection - definition of the sources of terms and
selection of terms for the ontology of cybersecurity;
3) data analysis - definition of the main terms and terms of
elements, relationships, verbal description of terms;
4) development of ontology of cybersecurity - creation of a
schematic and analytical description of the mentioned
ontology;</p>
      <p>5) validation of the ontology of cyber-security - checking
the completeness and correctness of the ontology, compliance
with the original requirements.</p>
      <p>The ontology of cybersecurity is represented by graphical
schemes in the language of IDEF5 Schematic Language (524
schemes) schemes and corresponding analytical descriptions in
the text language of IDEF5 Elaboration Language. The above
analytical descriptions of the ontology of cybersecurity are
performed in accordance with the previously developed
methodology:</p>
      <p>1) entering the notation of basic and auxiliary terms of
cybersecurity;</p>
      <p>2) explanation of the terms-elements with the help of
unrelated types;
3) assigning to each term-element a unique identifier;
4) definition of input and output links for each term;</p>
    </sec>
    <sec id="sec-5">
      <title>5) fixing connections of elements;</title>
    </sec>
    <sec id="sec-6">
      <title>6) verification of the correctness of descriptions.</title>
      <p>7) if necessary, updating and clarifying the descriptions.</p>
      <p>In the second methodological approach, the
recommendations of the W3C consortium (The World Wide
Web Consortium) are used to represent the ontology of
cybersecurity in the context of the semantic web (web 3.0). The
second approach took 4 years (2006-2010). To describe the
hierarchy of possible Smart Grid cyber-security ontologies
with memory, OWL is used, which provides a detailed
description of ontology classes, individuals belonging to these
classes, and the existing relationships between them. This
language extends the capabilities of the RDF language, which
provides an opportunity to operate with the basic
"subjectpredicate-object" structures, as well as the RDFS language that
defines the basic structures and relationships between classes
and individuals. At the same time, to ensure the possibility of
describing the complex connections between individuals on the
ontology of cyber-security Smart Grid, the variant of the OWL
DL language is used.</p>
      <p>This allowed us to use enumerated types to describe fixed
vocabulary structures of the knowledge base of the domain,
define multiple links to define many-to-many relationships, and
apply logical (Boolean) combinations of classes to define the
connections of the complex structure of the Smart Grid
ontology of cyber-security with memory. It has been shown
that the OWL language allows you to specify different
representations of the mentioned ontology of cybersecurity.</p>
      <p>It was decided to use the OWL representation in XML
syntax as the most common and convenient for automatic
processing and analysis of the texts of ontologies of
cybersecurity by appropriate software tools. An example of a
description of the ontology of cybersecurity using this syntax is
given (Table 1).</p>
      <p>Integration of separate parts of the cyber-ontology ontology
involves the inclusion of ontologies into each other at the level
of the language (the owl: imports design). This allowed us to
describe the basic concepts, connections and individuals related
to the named subject area.</p>
      <p>To dynamically expand and modify the knowledge base, a
description of the rules for building connections in the SWRL
language, which is integrated into ontologies formed in OWL,
is used. The rules are used to describe the dynamic
relationships between individuals ontologies that arise when
certain conditions exist.</p>
      <p>For example, such relationships can describe the
applicability of the method for solving the problem of ensuring
the required stability of the Smart Grid in the conditions of
information confrontation, depending on the characteristics of
the input data. Using the construction of dynamic relationships
in conjunction with the inclusion of ontology makes it possible
to implement a partial logical inference already at the level of
interpretation of the ontological structure. To do this, a set of
active facts, formed in the process of interaction with the user,
is formalized as a separate ontology using the inclusion of a
basic ontological structure. Interpretation of the received
structure allows to carry out the analysis of the basic
ontological structure taking into account the entered facts.
&lt;!-- Field of knowledge--&gt;
&lt;owl:Class rdf:ID="FieldOfKnowledge"/&gt;</p>
      <p>&lt;!-- Solution method--&gt;
&lt;owl:Class rdf:ID="Method"/&gt;</p>
      <p>&lt;!-- Task--&gt;
&lt;owl:Class rdf:ID="Problem"/&gt;
&lt;!-- A set of data (input or output)--&gt;</p>
      <p>&lt;owl:Class rdf:ID="DataSet"/&gt;
&lt;!-- Generalization of the method--&gt;
&lt;owl:ObjectProperty rdf:ID="generalizedBy"&gt;
&lt;rdf:type
rdf:resource="&amp;owl;TransitiveProperty"/&gt;
&lt;rdfs:domain rdf:resource="#Method"/&gt;
&lt;rdfs:range rdf:resource="#Method"/&gt;</p>
      <p>&lt;/owl:ObjectProperty&gt;
&lt;!-- Parametrization of the method--&gt;
&lt;owl:ObjectProperty rdf:ID="hasParameter"&gt;
&lt;rdfs:domain&gt;</p>
      <p>&lt;owl:Class&gt;
&lt;owl:unionOf rdf:parseType="Collection"&gt;
&lt;owl:Class rdf:about="#Method"/&gt;
&lt;owl:Class rdf:about="#Problem"/&gt;
&lt;/owl:unionOf&gt;
&lt;/owl:Class&gt;
&lt;/rdfs:domain&gt;
&lt;rdfs:range rdf:resource="#DataSet"/&gt;
&lt;/owl:ObjectProperty&gt;
&lt;!-- Input parameter--&gt;
&lt;owl:ObjectProperty rdf:ID="hasInput"&gt;</p>
      <p>&lt;rdfs:subPropertyOf
rdf:resource="#hasParameter"/&gt;</p>
      <p>&lt;/owl:ObjectProperty&gt;
&lt;!-- Output parameter--&gt;
&lt;owl:ObjectProperty rdf:ID="hasOutput"&gt;</p>
      <p>&lt;rdfs:subPropertyOf
rdf:resource="#hasParameter"/&gt;
&lt;/owl:ObjectProperty&gt;</p>
      <p>&lt;/rdf:RDF&gt;</p>
      <p>To perform queries on the ontological structure, the
SPARQL language is used, which allows using the existing
ontological interpretation tools to analyze the Smart Grid
ontology of cyber security with memory (including the
construction of dynamic rule relationships). An example of a
query is shown in Table 2.</p>
      <p>SELECT ?E ?L ?C WHERE {
?E rdf:type escience:DataSet .</p>
      <p>?E rdfs:label ?L .</p>
      <p>OPTIONAL {?E rdfs:comment ?C} .
nano:Hf escience:hasInput ?E .</p>
      <p>?E escience:isValue ?V .
?V rdf:type escience:SelectedValue</p>
      <p>}
V.</p>
    </sec>
    <sec id="sec-7">
      <title>EXAMPLE OF STRUCTURE OF ONTOLOGY</title>
      <p>Here is a possible structure of the ontology of
cybersecurity for describing the set of knowledge used in organizing
the self-recovering of the Smart Grid in an information
confrontation. This structure was tested in 2012 in joint studies
of the scientific schools of cybersecurity LETI, ITMO and the
faculty of Computational Mathematics and Cybernetics of
Lomonosov Moscow State University.</p>
      <p>
        In the ontology we distinguish two main layers: the
description of concepts (classes) and individuals that
implement concepts [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ]. Thus individuals can be connected
by the relations defined at level of concepts. In addition, the
relationship between individual concepts is acceptable (for
example, the generalization ratio). In the simplest case, the set
of relations can be bounded by two-dimensional relations.
Another element of ontology is the attributes (characteristics)
of individuals, detailing their description. In addition, one of
the possible extensions is the association of characteristics not
only with individuals (as class implementations), but also with
the relationships between them (as implementations of classes
of admissible connections).
      </p>
      <p>Formally, the ontology class layer is defined as a graph</p>
      <p>O  C, R
~ ~ ~
O  C, R


where C – is the set of classes, R – is the set of abstract
relations connecting classes.</p>
      <p>Similarly, a layer of individuals ontology is defined as a
graph</p>
      <p>~ ~
where C – is the set of individuals, and R – is the set of
relations between individuals. Thus for each element layer of
individuals identified:
a) generalization ratio

~
gn(C) : C  C </p>
      <p>~
gn(R) : R  R 
which determines the relationship of individuals and the
connections between them with the corresponding classes and
class relationships;</p>
      <p>b) "guard condition", determining the applicability of the
elements in these conditions
~
gc(C) (F ) : C  {0,1} </p>
      <p>~
gc(R) (F ) : R  {0,1} 
where F – is the set of active facts defined for the current
task;
c) criterion estimation function
k (C) (F ) : c~  C | gc(C) (c~)  1 (C) </p>
      <p>~
k (R) (F ) : ~r  R | gc(R) (~r)  1  (R)
~

where (C) and (R), respectively, the space of criteria for
evaluating individuals and the relationships between them.</p>
      <p>The inference block allows us to determine the way of
solving the problem as a tuple S = (s1, s2 ... sN) of a fixed
structure whose i-th element is a set of the form
si  c~  C | gn(C) (c~)  ci </p>
      <p>~
where the sequence of classes ci  C and requirements for
sets si determines the overall structure of the solution. To
evaluate the solution constructed by the criteria system, graph
analysis is used
~ ~ ~ ~ ~
O'  C ', R' : C '   si  CS 
i
where</p>
      <p>C~S  c~S | c~S   si , c~1   si : rch(c~S , c~1 ) </p>
      <p> i i 
it is an attached class system,</p>
      <p>rch(c~1, c~2 ) 
it is the ratio of the reachable on the graph.</p>
      <p>The estimation is carried out in the space of criteria ,
defined by the intersection of the sets of criteria describing the
spaces (C) and (R).</p>
      <p>A possible scheme for the formation of immunity to
disturbances is shown (see Fig. 1 and Fig 2).</p>
      <p>ServiceImplementation - a copy of the service, available as
part of the software package;</p>
      <p>DataSet - a set of input or output data for a given method or
task;</p>
      <p>Value - the size of the domain used as input and output data
for solving problems. There are two specific classes of
quantities that differ in the way they are assigned:</p>
      <p>FileExtractedValue - retrieved from the files of the value.
The extraction method is described as a class (in the
component source code) that implements the
IFileValueExtractor standard interface.</p>
      <p>SelectedValue - values selected from the list of available.
The list of available values is specified in the ontology by
individuals belonging to the subclasses of the
SelectionDictionary class.</p>
    </sec>
    <sec id="sec-8">
      <title>FileType - file containing the</title>
      <p>extraction.
values available for</p>
      <p>The structure of the accumulated immunity database is
specified by the ADO.NET Entity Framework model. To
organize access to the database, a library is built that provides
access to the entity instances stored in the database through the
ADO.NET Entity Framework. This approach provided the
possibility of accessing the database as a set of interrelated
collections storing instances of classes equivalent to database
entities. The implementation of direct access to the ontological
structure using the Pellet API (RunLib variant) is proposed.
The interface implemented by this module includes the
following basic methods of working with an ontological
structure:</p>
      <p>CreateSession () - creates a session, returns the string
identifier of the session.</p>
      <p>AddOWLModel (&lt;session id&gt;, &lt;ontology&gt;) is an
ontological structure extension that is specified in OWL in the
form of a separate ontology with possible references to existing
elements.</p>
      <p>ExecuteQuery (&lt;session id&gt;, &lt;query&gt;) is a request to the
ontological structure extended within the current session. The
query is specified in SPARQL, the result of which is a string
containing the results in XML format.</p>
      <p>The general scheme of interaction of RunLib
implementation with the ontology interpreter is presented (see
Fig. 3).</p>
      <p>VI.</p>
      <p>CONCLUSIONS</p>
      <p>As a result of the work done, the imperfection of the
traditional means of monitoring and restoration of the
operability of the Smart Grid power systems is revealed. The
ways of ensuring the stability of the functioning of power
systems under hostile mass information and technical
influences are investigated. The goals and objectives of
ensuring the sustainability of these prospective power systems
in the context of information confrontation are formalized.</p>
      <p>Fig. 3. Scheme of interaction between implementations</p>
      <p>The choice of a scientific and methodical apparatus suitable
for solving the problems of the organization of self-recovering
of the Smart Grid was carried out. The use of the theory of
formal languages and grammars for the generation and
recognition of possible types of mass perturbation structures is
proposed. The formation of immunity to destructive
disturbances with the use of the results of the theory of control
and restoration of the functioning of the Smart Grid</p>
      <p>The conceptual bases of self-recovery of perspective energy
systems in the conditions of information confrontation are put
forward and substantiated and a new, more perfect, ontology of
cyber-security of self-recovering Smart Grid is developed.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Petrenko</surname>
            <given-names>S.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stupin D.D. Natsional</surname>
          </string-name>
          <article-title>'naya sistema rannego preduprezhdeniya o komp'yuternom napadenii [National system of advance computer attacks alerting]</article-title>
          . Innopolis, Afina Publ.,
          <year>2017</year>
          . 440 p.
          <article-title>(In Russ</article-title>
          .).
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Barabanov</surname>
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V.L. Methodological</given-names>
          </string-name>
          <article-title>Framework for Analysis and Synthesis of a Set of Secure Software Development Controls</article-title>
          ,
          <source>Journal of Theoretical and Applied Information Technology</source>
          ,
          <year>2016</year>
          , vol.
          <volume>88</volume>
          , No 1, pp.
          <fpage>77</fpage>
          -
          <lpage>88</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Massel</surname>
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Voropay</surname>
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Senderov</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Massel</surname>
            <given-names>A</given-names>
          </string-name>
          .
          <article-title>Cyber Danger as One of the Strategic Threats to Russia's Energy Security</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          .
          <source>2016. No</source>
          <volume>4</volume>
          (
          <issue>17</issue>
          ), pp.
          <fpage>2</fpage>
          -
          <lpage>10</lpage>
          . DOI: https://doi.org/10.21681/
          <fpage>2311</fpage>
          -3456-2016-4-2-10.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Gruber</surname>
            <given-names>T.</given-names>
          </string-name>
          <article-title>A translation approach to portable ontology specifications</article-title>
          .
          <source>Knowledge Acquisition</source>
          ,
          <year>1993</year>
          , V. 5,
          <string-name>
            <surname>I.</surname>
          </string-name>
          <year>2</year>
          , pp.
          <fpage>199</fpage>
          -
          <lpage>220</lpage>
          . DOI:
          <volume>10</volume>
          .1006/knac.
          <year>1993</year>
          .
          <volume>1008</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Gruber</surname>
            <given-names>T.</given-names>
          </string-name>
          <string-name>
            <surname>Toward</surname>
          </string-name>
          <article-title>Principles for the Design of Ontologies Used for Knowledge Sharing?</article-title>
          <source>International Journal Human-Computer Studies</source>
          ,
          <year>1995</year>
          ,
          <string-name>
            <surname>V.</surname>
          </string-name>
          <year>43</year>
          , I. 5-
          <issue>6</issue>
          , pp.
          <fpage>907</fpage>
          -
          <lpage>928</lpage>
          . DOI:
          <volume>10</volume>
          .1006/ijhc.
          <year>1995</year>
          .
          <volume>1081</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Biryukov</surname>
            <given-names>D. N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lomako</surname>
            <given-names>A. G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rostovtsev</surname>
            <given-names>Yu. G.</given-names>
          </string-name>
          <article-title>The appearance of anti-cyber systems to prevent the risks of cyber-threat [</article-title>
          <source>Proc. SPIIRAN]</source>
          .
          <year>2015</year>
          , V.
          <volume>39</volume>
          , pp.
          <fpage>5</fpage>
          -
          <lpage>25</lpage>
          . DOI: http://dx.doi.org/10.15622/sp.39.1.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Guarino</surname>
            <given-names>N. Formal</given-names>
          </string-name>
          <string-name>
            <surname>Ontology</surname>
            and
            <given-names>Information</given-names>
          </string-name>
          <string-name>
            <surname>Systems</surname>
          </string-name>
          .
          <source>In Proc. International Conference on Formal Ontology in Information Systems (FOIS'98)</source>
          . Amsterdam, IOS Press, 6-8 June,
          <year>1998</year>
          , pp.
          <fpage>3</fpage>
          -
          <lpage>15</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Guarino</surname>
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Musen</surname>
            <given-names>M.</given-names>
          </string-name>
          <article-title>Applied ontology: The next decade begins</article-title>
          .
          <source>Applied Ontology</source>
          .
          <article-title>-</article-title>
          <year>2015</year>
          . - V.
          <volume>10</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          . DOI:
          <volume>10</volume>
          .3233/AO150143.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Guarino</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          <article-title>Services as Activities: Towards a Unified Definition for (Public</article-title>
          )
          <article-title>Services</article-title>
          .
          <source>In Proc. Enterprise Distributed Object Computing Workshop (EDOCW)</source>
          ,
          <source>2017 IEEE 21st International. Quebec City</source>
          ,
          <string-name>
            <surname>QC</surname>
          </string-name>
          , Canada,
          <fpage>10</fpage>
          -
          <lpage>13</lpage>
          Oct.,
          <volume>10</volume>
          .1109/EDOCW.
          <year>2017</year>
          .
          <volume>25</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Kharzhevskaya</surname>
            ,
            <given-names>A.V</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lomako</surname>
            ,
            <given-names>A.G</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petrenko</surname>
            <given-names>S.A.</given-names>
          </string-name>
          <article-title>Representing programs with similarity invariants for monitoring tampering with calculations</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          .
          <year>2017</year>
          . No.
          <volume>2</volume>
          (
          <issue>20</issue>
          ), pp.
          <fpage>9</fpage>
          -
          <lpage>20</lpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2017-2-9-20.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Kleschev</surname>
            <given-names>A.S. Artemyeva I.L</given-names>
          </string-name>
          .
          <article-title>Mathematical models of ontologies of subject domains. Part 2. Components of the model</article-title>
          .
          <source>Novosibirsk State University Journal of Information Technologies</source>
          ,
          <year>2001</year>
          , ser. 2, no.
          <issue>3</issue>
          , pp.
          <fpage>19</fpage>
          -
          <lpage>29</lpage>
          . (In Russ.).
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Kotenko</surname>
            <given-names>I.</given-names>
          </string-name>
          <article-title>Multi-agent Modelling and Simulation of Cyber-Attacks and Cyber-Defense for Homeland Security</article-title>
          .
          <source>In Proc. IEEE Fourth International Workshop on "Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications"</source>
          (IDAACS'
          <year>2007</year>
          ). Dortmund, Germany,
          <fpage>6</fpage>
          -
          <lpage>8</lpage>
          September,
          <year>2007</year>
          , pp.
          <fpage>614</fpage>
          -
          <lpage>619</lpage>
          . DOI:
          <volume>10</volume>
          .1109/IDAACS.
          <year>2007</year>
          .
          <volume>4488494</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Kotenko</surname>
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Novikova</surname>
            <given-names>E.</given-names>
          </string-name>
          <article-title>Visualization of Security Metrics for Cyber Situation Awareness</article-title>
          .
          <source>In Proc. 2014 Ninth International Conference on Availability, Reliability and Security</source>
          . Fribourg, Switzerland,
          <year>2014</year>
          , pp.
          <fpage>506</fpage>
          -
          <lpage>513</lpage>
          . DOI:
          <volume>10</volume>
          .1109/ARES.
          <year>2014</year>
          .
          <volume>75</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Kotenko</surname>
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Polubelova</surname>
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Saenko</surname>
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Doynikova</surname>
            <given-names>E.</given-names>
          </string-name>
          <article-title>The Ontology of Metrics for Security Evaluation and Decision Support in SIEM Systems</article-title>
          .
          <source>In Proc. 2013 International Conference on Availability, Reliability and Security</source>
          . Regensburg, Germany,
          <year>2013</year>
          , pp.
          <fpage>638</fpage>
          -
          <lpage>645</lpage>
          . DOI:
          <volume>10</volume>
          .1109/ARES.
          <year>2013</year>
          .
          <volume>84</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Mussel</surname>
            <given-names>L.V.</given-names>
          </string-name>
          <article-title>Problems of creating a Smart Grid in Russia from the standpoint of information technology and cyber security</article-title>
          .
          <source>In Proc. AllRussian Seminar with International Participation "Methodological issues of reliability research of large energy systems": Issue</source>
          <volume>64</volume>
          .
          <article-title>Reliability of energy systems: achievements, problems, prospects</article-title>
          . Irkutsk,
          <source>ESI SB RAS</source>
          ,
          <year>2014</year>
          , pp.
          <fpage>171</fpage>
          -
          <lpage>181</lpage>
          . (In Russ.).
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Nardi</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Falbo</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Almeida</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Guizzardi</surname>
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pires</surname>
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sinderen</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Guarino</surname>
            <given-names>N.</given-names>
          </string-name>
          <article-title>An Ontological Analysis of Value Propositions</article-title>
          .
          <source>In: Enterprise Distributed Object Computing Conference (EDOC)</source>
          ,
          <source>2017 IEEE 21st International. Quebec City</source>
          ,
          <string-name>
            <surname>QC</surname>
          </string-name>
          , Canada,
          <fpage>10</fpage>
          -
          <lpage>13</lpage>
          Oct.
          <year>2017</year>
          , pp.
          <fpage>184</fpage>
          -
          <lpage>193</lpage>
          . DOI:
          <volume>10</volume>
          .1109/EDOC.
          <year>2017</year>
          .
          <volume>32</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Pospelov</surname>
            <given-names>D.A</given-names>
          </string-name>
          . Introduction to applied semiotics.
          <source>News of Artificial Intelligence</source>
          ,
          <year>2002</year>
          , no.
          <issue>6</issue>
          . (In Russ.).
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Pospelov</surname>
            <given-names>G.S.</given-names>
          </string-name>
          <article-title>Artificial intelligence is the basis of the new information technology</article-title>
          . Moscow, Nauka,
          <year>1988</year>
          . 280 p.
          <article-title>(In Russ</article-title>
          .).
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Pashchenko</surname>
            <given-names>I. N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vasilyev</surname>
            <given-names>V. I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Guzairov M. B. Smart</surname>
          </string-name>
          <article-title>Grid security system on the basis of intelligent technologies: rule base design</article-title>
          .
          <source>Izvestiya SFedU</source>
          .
          <source>Engineering Sciences [News of SFedU. Technical science]</source>
          ,
          <year>2015</year>
          , pp.
          <fpage>28</fpage>
          -
          <lpage>37</lpage>
          . (In Russ.).
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Vorobiev</surname>
            <given-names>E.G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petrenko</surname>
            <given-names>S.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kovaleva</surname>
            <given-names>I.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Abrosimov</surname>
            <given-names>I.K.</given-names>
          </string-name>
          <article-title>Organization of the entrusted calculations in crucial objects of informatization under uncertainty</article-title>
          .
          <source>In Proceedings of the 20th IEEE International Conference on Soft Computing and Measurements (24-26 May</source>
          <year>2017</year>
          , St. Petersburg, Russia).
          <source>SCM</source>
          <year>2017</year>
          ,
          <year>2017</year>
          , pp.
          <fpage>299</fpage>
          -
          <lpage>300</lpage>
          . DOI:
          <volume>10</volume>
          .1109/SCM.
          <year>2017</year>
          .
          <volume>7970566</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Vorobiev</surname>
            <given-names>E.G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petrenko</surname>
            <given-names>S.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kovaleva</surname>
            <given-names>I.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Abrosimov</surname>
            <given-names>I.K.</given-names>
          </string-name>
          <article-title>Analysis of computer security incidents using fuzzy logic</article-title>
          .
          <source>In Proceedings of the 20th IEEE International Conference on Soft Computing and Measurements (24-26 May</source>
          <year>2017</year>
          , St. Petersburg, Russia).
          <source>SCM</source>
          <year>2017</year>
          ,
          <year>2017</year>
          , pp.
          <fpage>369</fpage>
          -
          <lpage>371</lpage>
          . DOI:
          <volume>10</volume>
          .1109/SCM.
          <year>2017</year>
          .
          <volume>7970587</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <surname>Vorozhtsova</surname>
            <given-names>T.N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pyatkova</surname>
            <given-names>N.I.</given-names>
          </string-name>
          <article-title>Ontology engineering threats to energy security</article-title>
          .
          <source>In: Critical Infrastructures: Contingency Nanagement, Intelligent, Agent-Based, Cloud Computing and Cyber Security Proceeding of International Workshop CI:CM/IACC/CS - 2017</source>
          .
          <year>2017</year>
          . P.
          <volume>24</volume>
          -
          <fpage>26</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>Massel</surname>
            <given-names>A.G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tyuryumin</surname>
            <given-names>V.O.</given-names>
          </string-name>
          <article-title>Events ontologies and their application for description of energy security threats</article-title>
          .
          <source>In Proc. of the Microwave &amp; Telecommunication Technology (CriMiCo)</source>
          ,
          <year>2014</year>
          24th International Crimean Conference,
          <year>2014</year>
          , pp.
          <fpage>443</fpage>
          -
          <lpage>444</lpage>
          . DOI:
          <volume>10</volume>
          .1109/CRMICO.
          <year>2014</year>
          .
          <volume>6959470</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <surname>Markov</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fadin</surname>
            <given-names>A.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V.L. Multilevel</given-names>
          </string-name>
          <article-title>Metamodel for Heuristic Search of Vulnerabilities in The Software Source Code</article-title>
          ,
          <source>International Journal of Control Theory and Applications</source>
          ,
          <year>2016</year>
          , vol.
          <volume>9</volume>
          , No 30, pp.
          <fpage>313</fpage>
          -
          <lpage>320</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <surname>Barabanov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fadin</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shakhalov</surname>
            <given-names>I.</given-names>
          </string-name>
          <article-title>Synthesis of Secure Software Development Controls</article-title>
          .
          <source>In Proceedings of the 8th International Conference on Security of Information and Networks (Sochi, Russian Federation, September 08-10</source>
          ,
          <year>2015</year>
          ).
          <source>SIN '15</source>
          . ACM New York, NY, USA,
          <year>2015</year>
          , pp.
          <fpage>93</fpage>
          -
          <lpage>97</lpage>
          DOI: 10.1145/2799979.2799998.
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <surname>Bazaron</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rukavichnikov</surname>
            <given-names>A</given-names>
          </string-name>
          .
          <article-title>Method specifications subject area discipline based on ontological approach</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          .
          <source>2014. No</source>
          <volume>5</volume>
          (
          <issue>8</issue>
          ), pp.
          <fpage>52</fpage>
          -
          <lpage>58</lpage>
          . DOI: https://doi.org/10.21681/
          <fpage>2311</fpage>
          -3456-2014-5-
          <fpage>43</fpage>
          -46.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>