<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Problem of Developing an Early-Warning Cybersecurity System for Critically Important Governmental Information Assets</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Sergei A. Petrenko</string-name>
          <email>a.petrenko@rambler.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alexey S. Petrenko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Krystina A. Makoveichuk</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Department of Informatics and Information Technologies Vernadsky Crimean Federal University Yalta</institution>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Information Security Department Saint Petersburg Electrotechnical University "LETI" St. Petersburg</institution>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <fpage>112</fpage>
      <lpage>117</lpage>
      <abstract>
        <p>-The article considers possible solutions of to the relatively new scientific-technical problem of developing an earlywarning cybersecurity system for critically important governmental information assets. The solutions proposed are based on the results of exploratory studies conducted by the authors in the areas of Big data acquisition, cognitive information technologies (cogno-technologies), and “computational cognitivism,” involving a number of existing models and methods. The results obtained permitted the design of an early-warning cybersecurity system.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>INTRODUCTION</p>
      <p>Nowadays, the information confrontation plays an
increasingly important role in modern, “hybrid” wars.
Furthermore, victory is often attained not only via military or
numerical superiority, but rather by information influence on
various social groups or by cyberattacks on critically
important governmental infrastructure.</p>
      <p>In this regard, means for detecting and preventing
information and technical impacts should play a crucial role.
Currently, systematic work is being done in Russia to create a
National Cyberattack Early-Warning System. A number of
state and corporate cybersecurity response system centers have
already been organized.</p>
      <p>However, the technologies applied in these centers allow
only the detection and partial reflection of ongoing IT-attacks,
but they do not have the capacity to predict and prevent
attacks that are still in the preparation stage [1].</p>
      <p>Such a situation requires the creation of fundamentally
new information security systems which are capable of
controlling the information space, generating and simulating
scenarios for the development, prevention and deterrence of
destructive information and technical impacts, and to initiate
proactive responses to minimize their negative impact. New
technologies in big data and deep learning as well as in
semantic and cognitive analysis are now capable of
proactively identifying the invader’s hidden meanings and
goals, which the other types of analysis could not discover,
will likely play an instrumental role here. This article aims to
develop these methods and technologies.</p>
      <p>II.</p>
    </sec>
    <sec id="sec-2">
      <title>PROBLEMS OF DEVELOPING AN EARLY</title>
      <p>WARNING CYBERSECURITY SYSTEM</p>
      <p>At the same time, it is impossible to implement a National
Cyberattack Early Warning System without also tackling a
series of related issues. Most notably, this will necessarily
entail the creation of an effective computing infrastructure that
provides the implementation of new methods and technologies
for modeling the development, prevention and deterrence of
destructive information and technical impacts in real-time, or
even preemptively. Clearly, this problem will not be solved
without high-performance computing systems or a
supercomputer.</p>
      <p>We must confess that Russia currently lags far behind
leading Western countries in terms of its supercomputer
technology. Cluster supercomputers primarily used in our
country are usually based on a СKD assembly from
commercially available foreign processing nodes and network
switches. It is well-known that this class of supercomputers
demonstrates its optimal performance when solving loosely
bound problems not requiring intensive data exchange
between processor nodes.</p>
      <p>The actual performance of cluster supercomputers,
however, is significantly reduced when solving. While the
solution of tightly bound problems, in particular semantic and
cognitive analysis of big data. Moreover, the attempts to
increase the cluster system performance by increasing the
number of processing nodes have often not only failed to yield
positive results, but, on the contrary, have had the opposite
effect due to a heightened proportion of non-productive
“overhead” in the total solution time which arises not from
“useful” processing, but from organizing a parallel calculation
process.</p>
      <p>These fundamental disadvantages of modern cluster
supercomputers are a product of their “hard” architecture,
which is implemented at the stage of computer construction
and cannot be modified while being used [1-4].</p>
      <p>Developed by Russian scientists, the concept of creating a
reconfigurable supercomputer made it possible to configure
the architecture setup (adjustment) depending on the structure
of the task’s solution without entailing the aforementioned
disadvantages. In this case, a set of field programmable logic
devices (FPLG) of a large integration degree comprises the
entire computing field and enables the user to create the
taskoriented computing structures similar to the graph algorithm
of the given task; this is used as a supercomputer
computational device, rather than a standard microprocessor.
This approach ensures a “granulated” parallel computing
process as well as a high degree of time efficiency in
organization achieved by adjusting the computing architecture
to the applied task.</p>
      <p>As a result, near-peak performance of the computing
system is achieved and its linear growth is provided, when the
hardware resources of the FPLG computational field are
increased [5-8].</p>
      <p>Today, reconfigurable FPLG-based computing systems are
increasingly finding use in solving a number of topical applied
tasks, primarily computationally labor-intensive and “tightly
coupled” streaming tasks that require mass data processing
(streams), as well as tasks that require the processing of
nonstandard data formats or variable number of bit (e.g. applied
fields of big data semantic and cognitive analysis,
cryptography, images processing and recognition, etc.).</p>
      <p>This allows us to estimate the prospects of using
reconfigurable supercomputers technology when establishing
a National Cyberattack Early-Warning System [1].</p>
      <p>III.</p>
      <p>OF NATIONAL SUPERCOMPUTER GRID</p>
      <p>NETWORK</p>
      <p>At the same time, one supercomputer, even the most
productive one, is not enough to create the computing
infrastructure of the National Cyberattack Early-Warning
System.</p>
      <p>Obviously, such a system should be built based on a
network of supercomputer centers, with each unit having its
owntask focus, while preserving the possibility to combine all
the units into a single computing resource; this would, de
facto, provide a solution to computationally labor-intensive
tasks of real-time and preemptive modeling development
scenarios for prevention and deterrence of the destructive
information and technical impacts. In other words, the
National Cyberattack Early Warning System should be based
on a certain segment (possibly secured from outside users) of
the National Supercomputer GRID network.</p>
      <p>Furthermore, establishing a National Supercomputer
GRID-Network evokes a complex problem of optimal
distribution (dispatching) of computational resources while
solving a stream of tasks on modeling development scenarios
for cyberattack prevention and deterrence [9].</p>
      <p>Nowadays, the problem of dispatching distributed
computer networks is being solved with uniquely allocated
server nodes. However, such centralized dispatching is
effective when working with a small computational capacity
or nearly homogenous computational resources. However, in
cases of numerous, heterogeneous network resources, the
operational distribution (also redistribution) of tasks, not to
mention of informationally relevant subtasks via a single
central dispatcher becomes difficult to implement. Moreover,
using a centralized dispatcher significantly reduces the
reliability and fault tolerance of the GRID network, since a
failure on the part of the service server node that implements
the dispatcher functions will lead to disastrous consequences
for the entire network.</p>
      <p>These disadvantages can be avoided by using the
principles of decentralized multi-agent resource management
of the GRID network. In this case, software agents which are
physically implemented in each computational resource as part
of the GRID network play the main role in the dispatching
process and represent their interests in the dispatching process.
Each agent will know the computing capabilities of “its own”
resource, as well as responsively track all changes (e.g.
performance degradation owing to the failure of numerous
computing nodes).</p>
      <p>Given this information, the agent can “allocate” its
resource for solving tasks where “its” resource will prove most
effective. If the computing resource of one agent is not enough
to solve the problem in the given time duration, then a
community of agents will be created, with each one providing
its resources for solving the various parts of a single task.</p>
      <p>The benefits of a decentralized multi-agent dispatching
system in a National Supercomputer GRID-network are
manifold:
• Ensure efficient loading of all computational resources
included in the GRID network, by using up-to-date
information about their current status and task focus;
• Ensure the adaptation of the computational process to
all resource changes in the cloud environment;
• Reduce the overhead costs for GRID network
organization due to the absence of the need to include
special service servers as a central dispatcher;
• Increase the reliability and fault tolerance of the GRID
network and, as a result, dependable computing, since
the system will not have any elements whose failure
may lead to disastrous consequences for the entire
network [4, 7-8].</p>
      <p>IV.</p>
    </sec>
    <sec id="sec-3">
      <title>DEVELOPMENT EARLY-WARNING CYBER</title>
      <p>SECURITY SYSTEM</p>
      <p>
        As a technological basis for solving this problem, it is
proposed to consider modern software and hardware systems
for analyzing and processing information security events [
        <xref ref-type="bibr" rid="ref13 ref9">10</xref>
        ].
In international practice, these complexes are developed as
part of specialized security centers, known as the Computer
Emergency Response Team (CERT) or the Computer Security
Incident Response Team (CSIRT), or the Security Operation
Center (SOC). Computer Emergency Response Team (CERT)
or Computer Security Incident Response Team (CSIRT), or
Security Operation Center (SOC).
      </p>
      <p>The Russian Federation has already established a number
of state and corporate centers for detecting, preventing, and
recovering from cyber-attacks or centers for responding to
cyber security incidents, which are similar to foreign CERT /
CSIRT / SOC in their functionality. In domestic practice, they
are known as SOPCA. Some examples include, inter alia,
GOV-CERT.RU (FSS of Russia), SOPCA of the Ministry of
Defense of Russia, FinCERT (Bank of Russia),
Rostechnologies CERT, Gazprom SOC, etc.</p>
      <p>The Russian Federation Presidential Decree No 31c of
January 15, 2013 “On the establishment of a state system for
detecting, preventing, and recovering from cyber-attacks on
Russian information resources” establishes that the Russian
FSS is making methodological recommendations on the
organization of protection of the critical information
infrastructure of the Russian Federation and organizes work
on the creation of a State and corporate segments of
Monitoring in the Detection, Prevention and Cyber Security
Incident Response (SOPCA).</p>
      <p>The concept of a state system for detecting, preventing,
and recovering from cyber-attacks on Russian information
resources No K 1274, was approved by the President of the
Russian Federation on December 12, 2014, defines the state
SOPCA system image based on special centers for detecting,
preventing, and recovering from cyber-attacks, divided into
centers:

</p>
      <p>Russian FSS (created to protect information resources
of the public authorities);
State and commercial organizations (created to protect
their own information resources).</p>
      <p>In addition, these centers are coordinated by the National
Coordinating Center for Computer Crimes under the FSS of
Russia.</p>
      <p>At the same time, in practice, the task to develop a
cognitive early warning system for cyber-attacks on the
information resources of the Russian Federation was far from
being trivial.</p>
      <p>
        It was necessary to conduct appropriate scientific research
and solve a series of complex scientific and technical
problems – e.g. input data classification, identifying primary
and secondary signs of cyber-attack, early cyber-attacks
detection, multifactor prediction of cyber-attacks, modeling of
cyber-attack spread, training, new knowledge generation on
quantitative patterns of information confrontation – many of
which did not have ready standard solutions [
        <xref ref-type="bibr" rid="ref14">11</xref>
        ].
      </p>
      <p>
        In addition, it was essential to ensure the collection,
processing, storage of big data, as well as carrying out
analytical calculations on extremely large amounts of
structured and unstructured information from a variety of
Internet / Intranet and IoT / IIoT sources (big data and big data
analytics) [
        <xref ref-type="bibr" rid="ref20">17</xref>
        ]. A possible list of requirements for such
cognitive systems is represented in Table 1.
      </p>
      <p>TABLE I. REQUIREMENTS FOR COGNITIVE SYSTEMS
 detection of incidents
and security threats by applying the
following models to the incoming
data stream:
- various parameters excess /
decrease detection, setting
thresholds for these parameters;
- detection of deviation from
normal values for various
parameters;
- detection of statistical deviations
from standard behavior for various
parameters in the time window;
multifactor analysis;
- parameters correlation and incidents
on selected time interval graphs;
- classification models to detect
correlation of parameters from various
sources with incident occurrence;
- clustering models for detecting
parameters correlation over a given
time interval, etc.</p>
      <p>Appropriate technological solutions for creating a
cognitive early warning for cyber-attacks on Russia's
information resources are represented in [1].</p>
      <p>Here, the choice and implementation of the big data
processing component represented an important task.</p>
      <p>Another important task was the structure of big data
storage structure. Many known solutions (e.g. Cassandra or
HBase), proved to be of little use due to the following
limitations:</p>
      <p> Lack of database components to ensure efficient
storage and retrieval by time series (most known solutions do
not contain integration tools due to their closeness, and those
available (e.g. InfluxDB) do not have a high level of work
stability);</p>
      <p> Absence of the logical connections between the
interfaces of business logic and the database;</p>
      <p> System functionality duplication due to the
database and the processing logic being separated in a
heterogeneous solution environment;</p>
      <p> Limited performance of the HBase solution,
associated with the architectural solution features;</p>
      <p> Significant overhead Cassandra, associated with
the synchronization of data on various nodes, etc.</p>
      <p>Possible system architecture of the cognitive early warning
system for cyber-attacks on information resources of the
Russian Federation based on NBIC technologies is presented
in [1]. The positive experience gained in the creation of a
cognitive early warning system for cyber-attacks of SHC
“Warning-2018” speaks to the expediency of a methodical
approach to solving the task.</p>
      <p>Stage 1. Developing the technical component of a
traditional SOPCA based on big data technologies is the
creation of a high-performance corporate (state) segment of
detecting, preventing, and recovering from cyber-attacks.</p>
      <p>Stage 2. Creation of the SOPCA analytical component
based on “computational cognitivism” is the realization of the
cognitive component of the cyber-attack early warning system
capable of independently extracting and generating useful
knowledge from large volumes of structured and unstructured
information for SOPCA operational support.</p>
      <p>In this case, the above-mentioned technical component of
SOPCA based on big data technologies should be
appropriately allocated with the following functions:
 Big data on the information security state in
controlled information resources collection;</p>
      <p> Data detection and recovery after cyber-attacks on
information resources;</p>
      <p> Software and technical tools for IS events monitoring
support;
 Interaction with the state SOPCA centers;
 Information on the detection, prevention, and
recovery from cyber-attacks, etc. (Fig. 1. Technical component of
SHC “Warning-2016”</p>
      <p>The analytical component based on “computational
cognitivism” should be appropriately allocated with the
following functions:



</p>
      <p>An early warning system for cyber-attacks on
information resources;
Identification and generation of new useful knowledge
about qualitative characteristics and quantitative patterns
of information confrontation;
Prediction of security incidents caused by known and
previously unknown cyber-attacks;
Preparation of scenarios for deterring a cyber-opposition
and planning a response, adequate computer aggression.</p>
      <p>In the following sections on this issue, the practice of using
big data technologies to organize a streaming process of
cybersecurity data, as well as practical questions of semantic
Master Data Management (MDM) will be considered for
building the SOPCA knowledge base.</p>
      <p>The development of a new functional model of a cognitive
high performance supercomputer will also be justified,
possible prototypes of software and hardware complexes for
the early detection and prevention of cyber-attacks will be
presented, examples of solutions to classification and
regression problems will be given, as will be solutions to the
search for associative rules and clustering and possible
directions for the development of artificial cognitive
cybersecurity systems (Table III).</p>
      <p>V.</p>
      <p>CONCLUSIONS</p>
      <p>The article shares valuable insight gained during the
process of designing and constructing open segment
prototypesof an early-warning cybersecurity system for
critical national infrastructure in the Russian Federation. The
results obtained permitted the design of an early-warning
cybersecurity system.</p>
      <p>In addition, prototypes were developed and tested for
software and hardware complexes of stream pre-processing
and processing as well as big data storage security, which
surpass the well-known solutions based on Cassandra and
HBase in terms of performance characteristics.</p>
      <p>
        As such, it became possible, for the first time ever, to
synthesize scenarios of an early-warning cybersecurity system
in cyberspace on extra-large volumes of structured and
unstructured data from a variety of sources: Internet/Intranet
and IoT/IIoT (Big Data and Big Data Analytics) [
        <xref ref-type="bibr" rid="ref19">16</xref>
        ].
vectors method;
 Statistical (correlation) and invariant profilers;
 Complex poly-model representations, etc.
8. Development of guidelines for work with cognitive SOPCA
9. Cyber-training organization to develop skills of early warning for
cyberattacks on information resources of the Russian Federation
10. Development of the necessary normative documents
11. Training and retraining of employees on issues relating to the early
warning for cyber-attacks on information resources of the Russian Federation
12. Elaboration of proposals for the development of a national (and
international) regulatory framework for cyber-attack early warning.
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <given-names>Petrenko S.A.</given-names>
            ,
            <surname>Stupin D.D. Natsional</surname>
          </string-name>
          <article-title>'naya sistema rannego preduprezhdeniya o komp'yuternom napadenii [National system of advance computer attacks alerting]</article-title>
          . Innopolis, Afina Publ.,
          <year>2017</year>
          . 440 p.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <surname>Guarino</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          <article-title>Services as Activities: Towards a Unified Definition for (Public</article-title>
          )
          <article-title>Services</article-title>
          .
          <source>In Proc. Enterprise Distributed Object Computing Workshop (EDOCW)</source>
          ,
          <source>2017 IEEE 21st International. Quebec City</source>
          ,
          <string-name>
            <surname>QC</surname>
          </string-name>
          , Canada,
          <fpage>10</fpage>
          -
          <lpage>13</lpage>
          Oct.,
          <year>2017</year>
          , pp.
          <fpage>102</fpage>
          -
          <lpage>105</lpage>
          . DOI:
          <volume>10</volume>
          .1109/EDOCW.
          <year>2017</year>
          .
          <volume>25</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <given-names>Nardi J.</given-names>
            ,
            <surname>Falbo</surname>
          </string-name>
          <string-name>
            <given-names>R.</given-names>
            ,
            <surname>Almeida</surname>
          </string-name>
          <string-name>
            <given-names>J.</given-names>
            ,
            <surname>Guizzardi</surname>
          </string-name>
          <string-name>
            <given-names>G.</given-names>
            ,
            <surname>Pires</surname>
          </string-name>
          <string-name>
            <given-names>L.</given-names>
            ,
            <surname>Sinderen</surname>
          </string-name>
          <string-name>
            <given-names>M.</given-names>
            ,
            <surname>Guarino</surname>
          </string-name>
          <string-name>
            <surname>N.</surname>
          </string-name>
          <article-title>An Ontological Analysis of Value Propositions</article-title>
          .
          <source>In: Enterprise Distributed Object Computing Conference (EDOC)</source>
          ,
          <source>2017 IEEE 21st International. Quebec City</source>
          ,
          <string-name>
            <surname>QC</surname>
          </string-name>
          , Canada,
          <fpage>10</fpage>
          -
          <lpage>13</lpage>
          Oct.
          <year>2017</year>
          , pp.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          184 -
          <fpage>193</fpage>
          . DOI:
          <volume>10</volume>
          .1109/EDOC.
          <year>2017</year>
          .
          <volume>32</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <string-name>
            <given-names>Izvestiya</given-names>
            <surname>SFedU</surname>
          </string-name>
          .
          <source>Engineering Sciences [News of SFedU. Technical science]</source>
          ,
          <year>2015</year>
          , pp.
          <fpage>28</fpage>
          -
          <lpage>37</lpage>
          . (In Russ.).
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <surname>Pospelov D.A</surname>
          </string-name>
          . Introduction to applied semiotics.
          <source>News of Artificial Intelligence</source>
          ,
          <year>2002</year>
          , no.
          <issue>6</issue>
          . (In Russ.).
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <string-name>
            <surname>Pospelov G.S.</surname>
          </string-name>
          <article-title>Artificial intelligence is the basis of the new information technology</article-title>
          . Moscow, Nauka,
          <year>1988</year>
          . 280 p.
          <article-title>(In Russ</article-title>
          .).
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <article-title>Organization of the entrusted calculations in crucial objects of informatization under uncertainty</article-title>
          .
          <source>In Proceedings of the 20th IEEE International Conference on Soft Computing and Measurements (24-26 May</source>
          <year>2017</year>
          , St. Petersburg, Russia).
          <source>SCM</source>
          <year>2017</year>
          ,
          <year>2017</year>
          , pp.
          <fpage>299</fpage>
          -
          <lpage>300</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          <source>DOI: 10.1109/SCM</source>
          .
          <year>2017</year>
          .
          <volume>7970566</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          <string-name>
            <given-names>Vorobiev E.G.</given-names>
            ,
            <surname>Petrenko</surname>
          </string-name>
          <string-name>
            <given-names>S.A.</given-names>
            ,
            <surname>Kovaleva</surname>
          </string-name>
          <string-name>
            <given-names>I.V.</given-names>
            ,
            <surname>Abrosimov</surname>
          </string-name>
          <string-name>
            <surname>I.K.</surname>
          </string-name>
          <article-title>Analysis of computer security incidents using fuzzy logic</article-title>
          .
          <source>In Proceedings of the 20th IEEE International Conference on Soft Computing and Measurements (24-26 May</source>
          <year>2017</year>
          , St. Petersburg, Russia).
          <source>SCM</source>
          <year>2017</year>
          ,
          <year>2017</year>
          , pp.
          <fpage>369</fpage>
          -
          <lpage>371</lpage>
          . DOI:
          <volume>10</volume>
          .1109/SCM.
          <year>2017</year>
          .
          <volume>7970587</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          <string-name>
            <given-names>Massel L.</given-names>
            ,
            <surname>Voropay</surname>
          </string-name>
          <string-name>
            <given-names>N.</given-names>
            ,
            <surname>Senderov</surname>
          </string-name>
          <string-name>
            <given-names>S.</given-names>
            ,
            <surname>Massel</surname>
          </string-name>
          <string-name>
            <surname>A</surname>
          </string-name>
          .
          <article-title>Cyber Danger as One of the Strategic Threats to Russia's Energy Security</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          .
          <source>2016. No</source>
          <volume>4</volume>
          (
          <issue>17</issue>
          ), pp.
          <fpage>2</fpage>
          -
          <lpage>10</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          DOI: https://doi.org/10.21681/
          <fpage>2311</fpage>
          -3456-2016-4-2-10.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Dorofeev</surname>
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V.L. Social</given-names>
          </string-name>
          <article-title>Media in Identifying Threats to Ensure Safe Life in a Modern City</article-title>
          ,
          <source>Communications in Computer and Information Science</source>
          ,
          <year>2016</year>
          , vol.
          <volume>674</volume>
          , pp.
          <fpage>441</fpage>
          -
          <lpage>449</lpage>
          . DOI:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -49700-6_
          <fpage>44</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Sheremet</surname>
            <given-names>I. A.</given-names>
          </string-name>
          <string-name>
            <surname>Augmented Post</surname>
          </string-name>
          <article-title>Systems: The Mathematical Framework for Data and Knowledge Engineering in Network-centric Environment</article-title>
          . Berlin,
          <year>2013</year>
          . 395 p.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Starodubtsev</surname>
            <given-names>Yu.I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Grechishnikov</surname>
            <given-names>E.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Komolov D</surname>
          </string-name>
          .V.
          <article-title>Use of neural networks to ensure stability of communication networks in conditions of external impacts</article-title>
          .
          <source>Telecommunications and Radio Engineering</source>
          .
          <year>2011</year>
          . V. 70. N 14. P.
          <volume>1263</volume>
          -
          <fpage>1275</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Kozachok</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bochkov</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lai</surname>
            <given-names>M.T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kochetkov</surname>
            <given-names>E.</given-names>
          </string-name>
          <string-name>
            <surname>First</surname>
          </string-name>
          <article-title>Order Logic for Program Code Functional Requirements Description</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          .
          <source>2017. N</source>
          <volume>3</volume>
          (
          <issue>21</issue>
          ), pp.
          <fpage>2</fpage>
          -
          <lpage>7</lpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2017-3
          <issue>-2</issue>
          -7.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Reber</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Malmquist</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shcherbakov</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <year>2014</year>
          .
          <article-title>Mapping the Application Security Terrain</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          .
          <source>2014. N 1</source>
          (
          <issue>2</issue>
          ). P.
          <volume>36</volume>
          -
          <fpage>39</fpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2014-2-
          <fpage>36</fpage>
          - 39.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Barabanov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V</given-names>
          </string-name>
          .
          <article-title>Procedure for Substantiated Development of Measures to Design Secure Software for Automated Process Control Systems</article-title>
          .
          <source>In Proceedings of the 12th International Siberian Conference on Control and Communications</source>
          (Moscow, Russia, May
          <volume>12</volume>
          -14,
          <year>2016</year>
          ).
          <article-title>SIBCON 2016</article-title>
          . IEEE,
          <volume>7491660</volume>
          ,
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          . DOI:
          <volume>10</volume>
          .1109/SIBCON.
          <year>2016</year>
          .
          <volume>7491660</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Petrenko</surname>
            <given-names>S.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Makoveichuk</surname>
            <given-names>K.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chetyrbok</surname>
            <given-names>P.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petrenko</surname>
            <given-names>A.S.</given-names>
          </string-name>
          <article-title>About Readiness for Digital Economy</article-title>
          .
          <source>In Proceedings of the 2017 IEEE II International Conference on Control in Technical Systems</source>
          , IEEE, CTS,
          <year>2017</year>
          , pp.
          <fpage>96</fpage>
          -
          <lpage>99</lpage>
          . DOI:
          <volume>10</volume>
          .1109/CTSYS.
          <year>2017</year>
          .
          <volume>8109498</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Petrenko</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petrenko</surname>
            <given-names>S.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Makoveichuk</surname>
            <given-names>K.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chetyrbok</surname>
            <given-names>P.V.</given-names>
          </string-name>
          <article-title>The IIoT/IoT device control model based on narrow-band IoT (NB-IoT)</article-title>
          .
          <source>In Proceedings of the the 2018 IEEE Conference of Russian Young Researchers in Electrical and Electronic Engineering (29 Jan.-1 Feb</source>
          .
          <year>2018</year>
          , Moscow and St. Petersburg, Russia) EIConRus, IEEE,
          <year>2018</year>
          , pp.
          <fpage>950</fpage>
          -
          <lpage>953</lpage>
          . DOI:
          <volume>10</volume>
          .1109/EIConRus.
          <year>2018</year>
          .
          <volume>8317246</volume>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>