<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Survivability of Organizational Management Systems and the Maintenance of Critical Infrastructure Security</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>Institute for Information Recording of National Academy of Sciences of Ukraine</institution>
          ,
          <addr-line>Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The paper is dedicated to the issue of improving the security of critical infrastructures functioning using the capabilities of their automated organizational management systems. It's substantiated, that security of critical infrastructures functioning depends on the level of survivability of automated organizational management systems (OMS). Increasing the survivability of automated organizational management systems is an essential element of a secure risk management system for critical infrastructures. The survivability property of automated OMS is defined as their ability to retain their functionality by performing the set of functions necessary to achieve the goal of functioning with a given quality, in the context of accumulation of component damages and loss of resources, by changing the behavior of the system. The survivability states of automated OMS are classified. A model is proposed to investigate the survivability of an automated OMS regarding a set of functions aimed at ensuring the security of critical infrastructure functioning. The methodological aspects of the development and implementation of the automated OMS are highlighted, that will function in the conditions of permanent changes of the environment and modernization of the components of the OMS. The criteria of estimation of system qualities of OMS and its components - automated workplaces are offered. An integrated survivability index has been proposed to evaluate the survivability and functional degradation of the OMS. Time constraints for the fulfillment the procedures for building information infrastructure in the OMS are formulated, to ensure the implementation of the functions supporting the critical infrastructure security. The expediency of creation a specialized modeling complex for OMS automation for the development of basic system, design and technological solutions, development of management decisions for the basic processes of organizational management is substantiated. At the specialized modeling complex it is possible to analyze and improve the existing methods of maintaining the security of critical infrastructure functioning, to develop templates for managers' actions in the event of undesirable changes during the critical infrastructure functioning, occurrence and development of emergency situations on the objects of critical infrastructure.</p>
      </abstract>
      <kwd-group>
        <kwd>survivability</kwd>
        <kwd>security</kwd>
        <kwd>critical infrastructure</kwd>
        <kwd>automated organizational management system</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>Introduction
Ensuring the security of critical infrastructures is, first and foremost, a reduction to an
acceptable level of risk of harm to the environment, the individual, society, and the
country. Critical infrastructure objects must be guaranteed to maintain a certain level
of security, avoid emergency situations, prevent their transition to dangerous
conditions.</p>
      <p>Low survivability systems collapse quickly and this can lead to cascading accidents
and significant material losses, while systems with high survivability break down
gradually, retaining in part functionality, limited performance, and time-consuming
adoption for switching to safe mode of operation, emergency shutdown, isolation of damage,
preventing their spread, etc. An important part of the security risk management system
of critical infrastructures is to increase the survivability of organizational management
systems.</p>
      <p>Today, all chains of control of critical objects and infrastructures involve complexes
of hardware and software, information systems and telecommunication networks,
intended to support the solution or solve the problems of operational management and
control over various processes and technical objects within the organization of
production or technological processes. Computer tools have become an integral part of various
management systems, components of complex technical, administrative, economic and
other systems of regional and global scale. Computer systems and technologies provide
advanced communication tools, support a complex structure of resources, production
and management processes automation, various technologies for information
processing. Security of management objects depends on the technologies of automated
organizational management systems, which are complex sociotechnical systems, that
include technical and technological subsystems, relevant systems of activity (systems of
roles and functions of service and management personnel), an environment that actively
interacts with others compound.</p>
      <p>Effective use of the sociotechnical systems components capabilities, taking into
account the synergistic effect allows ensure the functional safety of critical
infrastructures, to reduce the risk of accidents.
2</p>
      <p>
        Critical infrastructure security dependence on the
survivability of organizational management systems
Critical infrastructure security will mean the independence from unacceptable risk [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ],
that is, the ability of infrastructure, as a system, to minimize the risks of disaster.
      </p>
      <p>
        Automated organizational management systems (OMS) for critical infrastructures
should ensure not only the proper functioning of the infrastructure and the desired end
result, but also the adequate response to security incidents occurring at critical
infrastructure objects [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Tools of the automated OMS should ensure timely recognition of
the threat and the moment of occurrence of a critical (emergency) situation, determine
an adequate level of their processing, initiate processes of counteraction, compensation
or adaptation to continue the functioning of the critical infrastructure in full or in part,
and, if necessary, procedures for slow gradual degradation and safe shutdown must be
activated.
      </p>
      <p>
        An analysis of the current trends in the development of automated OMS shows that
there is an increasing number of functions that are critical to the security of critical
infrastructures that rely on information and communication technologies and
computers. Even today, thanks to automation, the implementation of organizational
management processes occurs in such a way as to prevent the transition of infrastructure or its
components into potentially dangerous states [
        <xref ref-type="bibr" rid="ref2 ref3 ref4">2-4</xref>
        ]. As a rule, the shutdown of a
technical object in case of occurrence or realization of a threat of its transition to a
dangerous (emergency) state is automatic. Intelligent software products for predicting,
assessing and minimizing the security risks of critical objects and structures are available
to support and develop management solutions at various levels.
      </p>
      <p>Under the survivability of an organizational management system, we will understand
its ability to retain its functionality by performing the set of functions necessary to
achieve the goal of functioning with a given quality, in the context of accumulation of
component damage and loss of resources, by changing the behavior of the system.</p>
      <p>In the general case, the survivability of the OMS depends on the set of parameters
that characterize the system, the functions performed by it, the effects of the
environment and the type, extent and dynamics of interaction with it. If the OMS is in a "status
of survivability," the system performs the set of functions φ = (φ1,φ2 ,...,φn ) with the
specified quality and required efficiency, that is, the purpose of the function is achieved.
The “status of survivability” is characterized by the stability and predictability of the
functioning of the system, that is, the critical infrastructure OMS fulfills all managerial
functions.</p>
      <p>
        There are three types of system survivability status S = {S t}, t = 1, 2, 3 , to which the
OMS can go, namely [
        <xref ref-type="bibr" rid="ref2 ref5">2, 5</xref>
        ]:
      </p>
      <p>• system survivability status type S
of the set φ = (φ1,φ2,...,φn )
ity and less efficiency in any of the states wj ∈W , that is</p>
      <p>1 , in which the OMS provides all the functions
with given quality and required efficiency or with poor
qual∏ x(φi ) = 1,
i∈I</p>
      <p>1, if φ i is fulfilled
x(φi ) = 
0, otherwise
•
system survivability status type S</p>
      <p>2 , whereby only a certain subset of the
functions are provided by the OMS φ * ⊂φ in any of the states wj ∈W , that is
∏
φi∈φ *</p>
      <p>x(φi ) = 1
•</p>
      <p>system survivability status type S 3 , whereby at least one of the functions of the
set is performed in the OMS φ = (φ1,φ2 ,...,φn ) in any of the states wj ∈W , that is
are violations in the functioning of the system (functional failures of components or
"wrong actions" of managers), and there is a narrowing of the functionality of the OMS.</p>
      <p>Among the functions of the set φ = (φ1,φ2,...,φn ) identify the functions of the OMS,
aimed at ensuring the security of critical infrastructure, φ S ⊂φ , φ S = (φ1s ,φ2s ,...,φrs ) .</p>
      <p>φ S
Functions from the set can be both independent and information related. The ability
of the OMS to maintain the secure functioning of the critical infrastructure can be
characterized by the OMS 's survivability with respect to a set of functions φ S .</p>
      <p>In automated OMS, the automated workstations of managers (AWM) are functional
components. Each AWM is a subsystem, the structure of which is determined by its
functional purpose. AWM specialization is done by installing the appropriate software
and establishing links between system components. The modular principle of software
development makes it quite easy to form the required configuration of the AWM, as a
subsystem of the OMS, to perform certain management functions. AWM functionality
can be expanded as needed by connecting new software modules. This creates a flexible
scalable environment for implementing management functions.
φ S</p>
      <p>To study the survivability of automated OMS with respect to a set of functions ,
to ensure the critical functioning of the critical infrastructure, the following model can
be applied:
ℑ = G,φ S , Tm, Can, Tt
where G – a graph that describes the information and communication links in the OMS
and may be changed during the operatioφnS o=f (tφh1se,φO2s M,...S,φorsr –in athseetcaosfe
foufncchtiaonngsinimgptlheefunctionality of the individual AWM; )
mented in the OMS to maintain the security of critical infrastructure, Tm – some of the
time-deficient functions of the last argument, Can – a matrix of functionalities of the
totality of AWM, which actually represent an automated OMS; Tt – vector that
characterizes the load of the AWM.</p>
      <p>Let us denote the set of managerial tasks performed in the OMS of the
implementation of the set of functions φ S = (φ1s ,φ2s ,...,φrs ) with the required quality and the required
efficiency through</p>
      <p>F =  Fi = { f1, f2 ,, fn} ,</p>
      <p>i∈I
while the AWM Φk
ϕ н : {1, 2,, p} → P ( F ) , where P ( F ) –the set of all subsets F .</p>
      <p>can potentially perform a number of managerial tasks</p>
      <p>Ifϕ н ( k ) = { fi1 , fi2 ,, fij } , 1 ≤ ir ≤ n , then the functional component of the AWM Φk
can perform managerial tasks fi1 , fi2 ,, fij .</p>
      <p>Suppose that all the necessary information and communication links between the
AWM of the OMS to perform the security support functions of the critical infrastructure
can be provided.</p>
      <p>At each specific moment of time specific AWM Φk implements a subset of
managerial tasks ϕ теп : {1, 2,, p} → P ( F ) .</p>
      <p>At the AWM of the OMS the decision of managerial tasks f1, f2 ,, fn is supported,
if ϕ теп (k) = { fi1 , fi2 ,..., fij } . Ifϕ теп ( k ) = ∅ , than AWM of the OMS Φk does not
perthe performance of functions
structure:
form managerial tasks, the solution of which requires the implementation of functions
φ S</p>
      <p>, which support the security operation of critical infrastructure.</p>
      <p>Assuming every managerial task fi ∈ F is characterized by some performance
effic
ciency i , you can define the performance function for the entire automated OMS on
φ S</p>
      <p>which support the security operation of critical
infraψ еф : F ×{1, 2,..., p}× P ( F ) → C</p>
      <p>,where C is a certain number set.</p>
      <p>If the AWM of the OMS Φk is focused on managerial tasks ϕ теп (k) = { fi1 , fi2 ,..., fij } and
performance when fulfilling fi ∈{ fi1 , fi2 ,..., fij } is equal to cik , than: ψ еф ( fi , k,ϕтеп (k )) = cik
(1)
(2)
(3)</p>
      <p>
        To implement by automated OMS the functions , which support the security
operation of critical infrastructure, with the efficiency not lower than the specified, the
managerial tasks f1, f2 ,, fn must be performed with appropriate efficiency, that is,
the following conditions must be met [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]:
φ S
p
k=1ϕ н (k ) ⊇ F ,
ϕpтеп (k ) ⊆ ϕ н (k ) ,
ψ еф ( fi , k,ψ теп (k )) ≥ ci
k=1
∀k = 1, p
, ∀i = 1, n ,
      </p>
      <p>Let us define as a functional failure the impossibility of fulfilling at least one of the
managerial tasks in the OMS fi ∈ F . In the case of functional failure, the status of
Φ
some AWM k changes and the corresponding function ϕ теп also changes. Although
condition (2) cannot be violated by functional failure AWM Φk , but its violation may
be caused by errors in management. If the narrowing of the functionality leads to a
violation of conditions (1) - (3), then the means of ensuring the survivability of the
OMS must be activated and the system must be adjusted so that conditions (1) - (3) are
again fulfilled.</p>
      <p>When reconfiguring the OMS, it is advisable to minimize the number of AWM of
the OMS involved in failure compensation procedures, i.e. to minimize the number of
changesϕ теп . It is because of the conditions (1) - (3) that the minimum quantity of
ϕ теп is changed, the optimality of OMS behavior can be characterized, and the number
of compensated functional failures may serve as a criterion for system survivability.
3</p>
      <p>Development and implementation of automated
highsurvivability OMS for critical infrastructure</p>
      <p>The problem of ensuring the safety of the functioning of critical objects and
infrastructures is complex, but the quality and properties of their automated OMS are of
utmost importance, since the security and safety of critical infrastructures depends on
management decisions, especially in the event of an emergency situation, i.e. in
conditions when there is no possibility of a clear prediction of the results of management
impacts. Functional stability of the OMS itself becomes a factor and condition for
security and safety of critical infrastructure objects.</p>
      <p>
        Already at the initial stage of development and implementation of automated OMS,
it is necessary to define criteria for assessing systemic qualities, in particular, [
        <xref ref-type="bibr" rid="ref6 ref7">6, 7</xref>
        ]:
• criteria for compliance of the OMS and the individual AWM with the specified
indicators of quality of functioning and/or assessment of the degree of its functional
degradation;
      </p>
      <p>• criteria for evaluating the performance of dynamic reconfiguration and
reallocation of resources;</p>
      <p>• criteria for assessing the extent of system recovery after glitches and failures due
to mechanisms of reorganization or reconstruction;</p>
      <p>• criteria that characterize changes in performance, reactivity, system sensitivity in
the conditions of system resources degradation;</p>
      <p>• criteria for assessing the adaptability of the system to external and internal
changes;
• cost-effectiveness criteria for the use of available resources.</p>
      <p>
        Analyzing the survivability of an automated OMS that operates in a constantly
changing external environment and often undergoes modernization, one can obtain the
most objective and adequate indicator of the quality of its functioning, because it is in
the study of survivability that the system's ability to perform its functions over a long
period is revealed, and not just the possibility of continuation of function in gap on
recovery after individual glitches or failures. Quantitative assessment of survivability
is generally performed on the basis of specific metrics that characterize the loss of
functionality (functional degradation) over a certain period of time. Various methodological
approaches to calculating such metrics are possible, in particular through quantitative
assessments of the system's ability to perform mission-critical functions, through the
degree of system degradation, and the like. For example, for the analysis of
survivability and the assessment of functional degradation, it is possible to use the integral
survivability index, determined by the weighted average of the estimates of performance
indicators in the following form [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]:
ξ =
1 N
      </p>
      <p> z j (r)
N j=1
,
where the values of the normalized indicators z j (r), j = 1, N
are calculated as

a j

z j (r) = 

a j

qTВ</p>
      <p>j
qTВ</p>
      <p>j
q*j (r) − qTВ</p>
      <p>j , j = 1, l, for technical requirements (TR) of the form q j ≥ q TjВ
qTjВ (r) − q*</p>
      <p>j , j = l + 1, N for TR of the form q j ≤ q TjВ
where
a</p>
      <p>j – weighting factor characterizing the degree of significance of the j -th
index of survivability for the integrated assessment of the quality of functioning of the
automated OMS; r - the number of accumulated functional failures in the OMS over a
given period of time (taking into account the recovery); j ⊂ –
elq Q = {q1, q2 , ...qS }
for the development of automated OMS;
ement of a set of metrics that should be within the appropriate range, which are defined
by the technical requirements, which are form*ulated, as a rule, in the terms of reference
q j (r )
– the "worst" in understanding the
or</p>
      <p>q j ≤ qTjВ , j = 1, N , then
fulfillment of the terms of reference of the j -th indicator value of the quality of
functioning when r components failure accumulated in the system.</p>
      <p>If there is a restriction for all given survival rates for a given period of time q j ≥ qTjВ
min z j ≥ 0, j = 1, N
j
, and, accordingly, the value of the
integral index</p>
      <p>will be no lower than some critical lower limit ξ kp , the specific value
of which may be specified when determining the functionality of the system for a
certain period of operation, or as the initial value of the integral index ξ . In this case, a
quantitative assessment of the degree of degradation of the system's capabilities may
be, for example, the value:
whereξ n. – quantitative assessment of the initial (design) functionality of an automated
OMS, taking into account the weighting coefficients of the significance of the
survivability indicators; а ξ nom. , ξ втр. – quantification for current (existing) and lost OMS
functionality, respectively.</p>
      <p>
        The automation of the OMS involves the introduction of information and
communication technologies for the collection, processing, accumulation, systematization,
storage, retrieval and dissemination of information [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. The functioning of an automated
OMS can be modeled with help of network model, the nodes of which are the functional
components (AWM), and the arcs are the different communication channels (wired,
wireless, combined).
      </p>
      <p>The implementation of information and communication technology is ensured by the
parallel and sequential operation of a set of functional components that interact with
each other and with the external environment through communication channels.
Technology should provide the development of management decision, for example, over
time Tz , which does not exceed Tдоп (the maximum time allowed for the collection and
processing of information, which depends on the requirements of the subject area).
Therefore,</p>
      <p>Tz = (Tf + Tоб ) ≤ Tдоп ,</p>
      <p>T
where f – time spent for processing information by functional components, Tоб – time
spent on information interaction.</p>
      <p>In the case of undesirable influences on the system or communication channels, the
time for implementation of information technology to develop a management decision
may increase by Tдод . The survivability criterion of the OMS may be the feasibility of
building the necessary information infrastructure as a set of functional components and
communication channels under restrictions</p>
      <p>(Tf + Tоб + Tдод ) ≤ Tдоп .</p>
      <p>For comparison of different variants of automated OMS implementation for the
purpose of choosing the most functionally sustainable one can use the survivability index
- the number of information infrastructures that allow to implement information
technology of management decision making, reducing the risks of occurrence and
development of emergency situations in critical infrastructures.</p>
      <p>
        The practical experience of designing and implementing automated OMS shows that
all basic system, design, software and technological solutions for the created OMS
should be pre-tested, and the managers have to go through the re-education and training
stage. It is advisable to make adjustments and approbations of the AWM on the
specialized modeling complex. The architecture of the complex depends on the features of
the critical infrastructure, systems models and processes involved in the operation of
the objects and infrastructure as a whole. Each management task that arises in the
operation of critical infrastructure can be reproduced in the modeling complex as a
separate functional task, the execution of which in the OMS generates a separate
management process. The input for this process can be either the initial management impact,
or the output or intermediate data of some other management process. The execution
of the management process involves the preparation and development of decisions on
the actions ordering, necessary to perform a functional task, into a certain sequence of
operations implemented within the relevant technology, determining what people
(employees), at what time, what technological processes (operations) perform to ensure the
secure functioning of the critical infrastructure. The implementation of the
technological process requires not only the specialists with the appropriate level of qualification,
but also the technical means, techniques and instructions for their application, software,
information and other services, necessary and sufficient for the fulfillment of the
functional tasks of management [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
      </p>
      <p>On the specialized modeling complex could not only be worked out the basic
processes of organizational management, but also carried out the selection and testing of
practically suitable formalized methods of maintaining the security of critical
infrastructure functioning with high promptness of justified management decisions
development, clarity of results of management and taking into account the existing
systembased subordination and interaction in OMS.</p>
      <p>Traditionally in the process of working out and making decisions, managers use
"subjective" knowledge of certain events, informal experience of experts, who are involved
in the assessment of the current situation in the critical infrastructure.</p>
      <p>
        When working on the specialized modeling complex of basic processes of
organizational management, the transition from intuitive estimates to quantitative is possible,
that significantly objectifies management decisions and helps to improve their quality.
Preliminary analysis of emergency situations on the modeling complex, crashes in the
operation of critical infrastructure and erroneous management decisions allows create
specific templates of managers’ actions, which is important in the conditions of time
resource criticality in accidents at the management object [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>In the future, the specialized modeling complex can become an analytical resource
for the OMS, its toolkit can be used to develop strategic management decisions and
substantiate current management decisions.
4</p>
      <p>Conclusions and recommendations</p>
      <p>The use of automated high-survivability OMS in critical infrastructures will reduce
the risks of infrastructure transition to disaster states, as such OMS are guaranteed to
perform their functions over a long period in the face of permanent environmental
change and many frequent upgrades.</p>
      <p>The analytical resource developed during the AWM OMS creation, formalized
methods of maintaining the security of the functioning of critical infrastructures will allow
to increase the efficiency and validity of management decisions, the clarity of the results
of management even in the context of unwanted changes in the system of subordination
and interaction in OMS, caused by changes in the functioning of critical infrastructure.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Dodonov</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gorbachyk</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kuznietsova</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Increasing the survivability of automated systems of organizational management as a way to security of critical infrastructures</article-title>
          .
          <source>In: XVIII International Scientific and Practical Conference «Information Technologies and Security» (ITS</source>
          <year>2018</year>
          ),
          <source>CEUR Workshop Proceeding (ISSN 1613-0073)</source>
          . Vol.
          <volume>2318</volume>
          , p.
          <fpage>261</fpage>
          -
          <lpage>270</lpage>
          (
          <year>2018</year>
          ), http://ceur-ws.
          <source>org/</source>
          Vol-
          <volume>2318</volume>
          //, last accessed
          <year>2019</year>
          /11/15.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Kharchenko</surname>
            ,
            <given-names>V.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yakovlev</surname>
            ,
            <given-names>S.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gorbachyk</surname>
            ,
            <given-names>O.S.</given-names>
          </string-name>
          ,etal.:
          <source>Provision of Functional Safety of Critical Information-control Systems. Kharkov: Konstanta</source>
          , 272 p.
          <source>Ukr</source>
          .
          <article-title>(</article-title>
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Kuznietsova</surname>
            ,
            <given-names>N. V.</given-names>
          </string-name>
          :
          <article-title>Information Technologies for Clients' Database Analysisand Behaviour Forecasting</article-title>
          .
          <source>CEUR Workshop Proceeding (ISSN 1613-0073)</source>
          . Vol.
          <year>2067</year>
          , p.
          <fpage>56</fpage>
          -
          <lpage>62</lpage>
          (
          <year>2017</year>
          ), http://ceur-ws.
          <source>org/</source>
          Vol-2067/, last accessed
          <year>2019</year>
          /11/15.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Churyumov</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tkachov</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tokariev</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Diachenko</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          :
          <article-title>Method for Ensuring Survivability of Flying Ad-hoc Network Based on Structural and Functional Reconfiguration</article-title>
          .
          <source>In: XVIII International Scientific and Practical Conference «Information Technologies and Security» (ITS</source>
          <year>2018</year>
          ),
          <source>CEUR Workshop Proceeding (ISSN 1613-0073)</source>
          . Vol.
          <volume>2318</volume>
          , p.
          <fpage>64</fpage>
          -
          <lpage>76</lpage>
          , (
          <year>2018</year>
          ) http://ceur-ws.
          <source>org/</source>
          Vol-
          <volume>2318</volume>
          //, last accessed
          <year>2019</year>
          /11/15.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Dodonov</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kuznietsova</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Gorbachyk</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          :
          <source>Complex Systems Survivability: Analysis and Modeling. Kyiv: NTUU “KPI”</source>
          ,
          <volume>264</volume>
          p.
          <source>Ukr</source>
          .
          <article-title>(</article-title>
          <year>2009</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Dodonov</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gorbachyk</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kuznietsova</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>System Research of Survivability andSafety for Complex Technical Systems</article-title>
          . Data Rec.,
          <source>Storage&amp;Processing</source>
          . Vol.
          <volume>12</volume>
          , N 2, p.
          <fpage>202</fpage>
          -
          <lpage>208</lpage>
          . Ukr. (
          <year>2010</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Dodonov</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gorbachyk</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kuznietsova</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <source>Organizational Management Systems: Information Technology and Security In: XIII International Scientific and Practical Conference «Information Technologies and Security» (ITS</source>
          <year>2013</year>
          ). V.
          <volume>13</volume>
          , p.
          <fpage>5</fpage>
          -
          <lpage>11</lpage>
          . (
          <year>2013</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Dodonov</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          : Computer Modelling of the Process of Organizing Management // Visnyk NANU, N1, p.
          <fpage>69</fpage>
          -
          <lpage>77</lpage>
          . (
          <year>2016</year>
          ).
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>