<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Cyber Resilience and Fault Tolerance of Artificial Intelligence Systems: EU Standards, Guidelines, and Reports</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>Kharkiv National University of Radio Electronics</institution>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>0000</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>The problem of ensuring cyber resilience and fault tolerance of artificial intelligence systems is urgent. The paper proposes methods for ensuring cyber resilience and fault tolerance of an artificial intelligence system based on existing European standards, recommendations, and reports. Collectively, the use of these methods and recommendations will make it possible to ensure complex cyber resilience and fault tolerance of the artificial intelligence system, namely databases (knowledge bases), the functionality of the system itself as a whole. The considered methods are based on the aspects of ensuring cyber resilience and fault tolerance of data centers or clouds as platforms for the deployment and implementation of artificial intelligence systems. Using the proposed solutions will increase the trust of artificial intelligence systems and will allow them to be implemented more intensively in many industries.</p>
      </abstract>
      <kwd-group>
        <kwd>Cyber Resilience</kwd>
        <kwd>Fault Tolerance</kwd>
        <kwd>Cybersecurity</kwd>
        <kwd>Artificial Intelligence</kwd>
        <kwd>Database</kwd>
        <kwd>Personal Data</kwd>
        <kwd>Data Center</kwd>
        <kwd>Cloud</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Given increasingly widespread and implemented computer systems, information
security occupies an important place in the modern world. Therefore, existing security
technologies require constant revision and modernization. One of the most effective
areas of cybersecurity development, which allows detailed detection of attacks and
preventing them faster than specialists in this field, is artificial intelligence [
        <xref ref-type="bibr" rid="ref1 ref2 ref3">1–3</xref>
        ].
      </p>
      <p>
        Today, there are several classes of solutions that successfully apply modern
technologies, which are part of the field of artificial intelligence. These classes include
User and Entity Behavior Analytics (UEBA), Next-Generation Firewall (NGFW).
Also, modern information security services (ISSs) from the unauthorized access are
ready to recognize objects through a webcam and record facts of violation of security
policies in real-time, for example, to detect an illegitimate person, a smartphone
photographing a screen, an IP camera [
        <xref ref-type="bibr" rid="ref4 ref5 ref6 ref7 ref8 ref9">4–9</xref>
        ], etc. These capabilities are especially
important today when many organizations relocated their employees to work remotely,
but do not want to lose control over them. Moreover, in almost all classes of ISSs,
machine learning is actively used, which allows us to take a serious step in the
development of cybersecurity and increase the resulting security level of organizations.
Also, along with the advent of new machine learning algorithms, their scope has
expanded. For several years now, machine learning in the field of information security
has been used not only to detect attacks but also to carry them out. However, despite
many advantages of AI, the artificial intelligence system (AIS) itself is susceptible to
attacks such as model theft, framework vulnerabilities, the substitution of data for
training, logical vulnerabilities. It is also worth noting that data processing using
artificial intelligence methods leads to the fact that the final decision depends not only
on the decision-making algorithm but also on the data processed earlier and currently
being processed. As a result, two completely new types of attacks on AISs arise data
poisoning, which characterizes the manipulation of input data during training to change
the subsequent decision-making process; and data evasion, which characterizes the
selection of input data at the decision-making stage, leading to their misclassification.
Also, the processing of large amounts of data in machine learning systems certainly
jeopardizes, first of all, the data of the users themselves. Hence, at present, there already
are attempts to combine systems of this class with such actively developing promising
directions in cryptography as homomorphic encryption and confidential computing
protocols. However, these mechanisms are only at the stage of development and have
not yet been implemented. Based on this, it follows that despite the many advantages
of using artificial intelligence, the vulnerabilities of the AIS are the data processing
system and data storage, i.e. the knowledge base based on which the entire artificial
intelligence system is trained. Following this, the following urgent tasks arise:
 Ensuring the security of the AIS performance.
 Ensuring the protection of the AIS data storage.
 Ensuring the cyber resilience and fault tolerance of the AIS throughout its life cycle.
This paper is devoted to the analysis of existing solutions to each of the above tasks, as
well as the subsequent review of the development and application of standards and
recommendations in this area in Ukraine and at the International level.
2
      </p>
      <p>Analysis of Existing Methods for Protecting Data</p>
      <p>
        Centers and Clouds
As a rule, data centers (DCs) and cloud technologies are used as data storages for
deploying an AI system (infrastructure) for modern solutions. The probability of an
attack on the network of a cloud hosting provider or a DC is high. This is caused by the
large volume of resources placed there. In the DC case, due to the nature of the
information placed, its high price, and criticality, we cannot exclude the threat of a
professionally prepared and performed attack aimed at obtaining or destroying
information, as well as achieving control over the resource [
        <xref ref-type="bibr" rid="ref10 ref11 ref12">10–12</xref>
        ].
      </p>
      <p>Mandatory protection methods for DCs are shown in Fig. 1.
Integration with well-known virtualization tools, container and cloud environments
• VMware, AWS, Azure, Docker, Google Cloud, IBM Cloud
Support for multi-level analysis of traffic
• Incoming and outgoing, as well as intranet traffic to identify
threats that could bypass existing security barriers
Detection, prevention and blocking of threats in real time
• Protection of software and equipment from attacks using a
system of virtual patches that close the vulnerabilities of
virtual machines before their operators install the appropriate
updates
Systems control
• Detecting unacceptable changes in the server parameters
settings
Providing anti-virus scanning and fixing the state of systems
• Prevent running any unknown applications</p>
      <p>
        The following are the mandatory properties of the cloud protection system [
        <xref ref-type="bibr" rid="ref13 ref14 ref15 ref16">13–16</xref>
        ]:
 The ability to classify and manage cloud assets, which implies the classification,
labeling, and processing of information.
 Security issues related to personnel; adding information security issues to job
responsibilities, confidentiality agreements; educating and training of personnel in
the field of information security.
 Physical protection of cloud storage, including perimeter protection and access
control.
 Management of data transfer and operational activities, including operational
procedures and responsibilities, isolation of development and production
environments; control of information processing facilities by third parties and/or
organizations; planning the performance and load of systems; protection against
malicious software.
 Access control, including business requirements for control over logical access; user
registration, control over user passwords; user identification and authentication;
management of user privileges and access rights; protection of diagnostic ports
during remote access; the principle of separation in networks; control of network
connections; network routing management; security of using network services;
control of access to the operating system; control of access to applications;
restriction of continuous access to information.
 Monitoring of system access and use, including work with portable devices and work
in the remote mode; measures to ensure information security when auditing systems.
 Development and maintenance of systems, including requirements for security and
resiliency of systems, taking into account cyber resilience; information protection
measures related to the use of cryptography, encryption, digital signatures, the
security of system files; software control; hidden channels of data leakage and
      </p>
    </sec>
    <sec id="sec-2">
      <title>Trojans, etc.</title>
      <p>
        Particular attention should be paid to the International Recommendations, namely
ANSI/TIA-942-B Telecommunications Infrastructure Standard for Data Centers [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ],
as well as the document “Cloud Computing Benefits, risks and recommendations for
information security” by The European Network and Information Security Agency
(ENISA) [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ].
3
      </p>
      <sec id="sec-2-1">
        <title>Methods of Data Storage Security of AIS</title>
        <p>
          Usually, when discussing the security of databases, the risk of compromising and losing
confidential information unwittingly comes to the fore. Modern conditions make us
consciously approach security issues, obliging us to use more and more advanced
methods of protecting the database [
          <xref ref-type="bibr" rid="ref19 ref20">19, 20</xref>
          ].
        </p>
        <p>Basic database protection is setting up firewalls in front of the DBMS to block any
access attempts from dubious sources, setting up and maintaining up to date password
policy and role-based access model followed by auditing user actions. Today, there is
a more effective approach—the use of specialized information security systems in the
field of database protection—solutions of the Database Activity Monitoring (DAM)
and Database Firewall (DBF) classes.</p>
        <p>At the same time, DAM is a solution for independent monitoring of user actions in
a DBMS. Moreover, independence denotes the absence of the need to reconfigure and
tune the DBMS themselves. Systems of this class can be deployed passively, working
with a copy of the traffic and not having any effect on business processes, the part of
which the databases are.</p>
        <p>
          DBF is a related solution, which also can “proactively” protect information. This is
achieved by blocking unwanted requests. To solve this problem, it is no longer enough
to work with a copy of the traffic, and it is necessary to install the protection system
components “in the gap.” In other words, database security mechanisms can be
implemented in various ways: from designing a database with built-in security
mechanisms to integrating the database with third-party products. The main direction
in the development of methods for ensuring database security is the analysis of existing
threats and risks. Thus, the existing international standards NIST, ISO/IEC, and COBIT
constantly carry out such an analysis and put forward ever higher requirements for
methods of ensuring security [
          <xref ref-type="bibr" rid="ref21 ref22 ref23 ref24 ref25 ref26 ref27 ref28 ref29">21–29</xref>
          ].
4
        </p>
        <p>Methods for Ensuring Cyber Resilience and Fault</p>
        <p>
          Tolerance of AIS and Its Databases
Based on the above requirements for the protection of data centers and clouds, as well
as the basic protection of databases and knowledge bases of the AIS, we can conclude
that despite the use of various architectures, systems, virtualization tools, operating
systems and software, the functionality of the AIS, the given means for data storing and
processing need to ensure their continued functioning and provision of services, which
is determined by their fault tolerance and cyber resilience [
          <xref ref-type="bibr" rid="ref21 ref22 ref23 ref24">21–24</xref>
          ].
        </p>
        <p>Thus, there arises a task of ensuring integrated security, including the AIS, its
databases, and knowledge bases by ensuring the cyber resilience of the AIS and the
fault tolerance of the data storage. Thus, we can conclude the direct dependence of the
AIS functioning on its security and fault tolerance, which is shown in Fig. 2.</p>
        <sec id="sec-2-1-1">
          <title>Training data input</title>
          <p>Artificial Intelligence System (AIS)</p>
        </sec>
        <sec id="sec-2-1-2">
          <title>Artificial Intelligence DataBase (AIDB) and</title>
        </sec>
        <sec id="sec-2-1-3">
          <title>Knowledge Base (AIKB)</title>
        </sec>
        <sec id="sec-2-1-4">
          <title>Artificial Intelligence Training System (AITS)</title>
          <p>Security
Cyber resilience</p>
          <p>Fault tolerance
Data center And Clouds</p>
          <p>In other words, the DB and DBMS must be a cyber-resilient and fault-tolerant system
that must maintain its operability when at least one node fails.</p>
          <p>In this regard, the following requirements are put forward for a professional data
storage system, shown in Fig. 3.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Storage requirements</title>
      <sec id="sec-3-1">
        <title>Fault tolerance of hardware media</title>
      </sec>
      <sec id="sec-3-2">
        <title>Fault tolerance of Internet channels</title>
      </sec>
      <sec id="sec-3-3">
        <title>Fault tolerance of servers</title>
      </sec>
      <sec id="sec-3-4">
        <title>Fault tolerance of gateways, proxy servers and remote access</title>
      </sec>
      <sec id="sec-3-5">
        <title>Fault tolerance of domain controllers</title>
      </sec>
      <sec id="sec-3-6">
        <title>Fault tolerance of the storage system</title>
        <p>At the same time, the fault tolerance of Internet channels means a recommendation to
connect two stable Internet channels from two independent providers. To ensure fault
tolerance of gateways, proxy servers, and remote access, it is recommended to create a
DBMS on professional hardware solutions with the ability to combine devices with
synchronization of their configuration files into a failover cluster. Such an architecture
will be able to ensure the stability of the Internet connection and uninterrupted access
to internal and external key services. Fault tolerance of hardware media is provided by
a single cluster of virtual machines with “live migration” technology through VMware,
Hyper-V, etc.</p>
        <p>Server fault tolerance refers to ensuring the continuous operation of all types of
servers, such as terminal servers, DBMS servers, application servers, file, mail, and
document servers, as well as Web servers. This task is solved through reservation and
duplication.</p>
        <p>Fault tolerance of domain controllers is achieved through the standard mechanism
of the primary and backup domain controller roles.</p>
        <p>Thus, the implementation of the recommendations shown in Fig. 3 will provide
online reservations for critical services. In other words, if any problems with the main
resources will appear, the entire system instantly switches to backup resources, almost
imperceptibly for the user. At the same time, clusters are self-sufficient systems. In the
event of emergencies, the cluster is designed for automatic actions to eliminate them
and maintain the efficiency of services. The structure of a fault-tolerant DBMS is built
in such a way that all important data, for example, personal data of customers, is
centrally located in a reliable data storage system. The rest of the servers are required
only for operational information processing and interactive work with the system. This
means that if one of the servers fails, it can be easily replaced without the risk of losing
or damaging company information. Also, along with fault tolerance, the distribution of
the operational load among all cluster members is provided.
5</p>
        <p>International Recommendations for Cyber Resilience
and Fault Tolerance of Artificial Intelligence Systems
Analyzing the requirements for the AIS, it is important to note that to ensure the security
of these systems, should be guided by the complex recommendations, aimed at
protecting the functionality of the AIS, data storage, their overall cyber resilience, and
fault tolerance. Based on this, there is a classification of recommendations for the
development, implementation, and effective functioning of AIS. This classification of
the main International standards is presented in Table 1.</p>
        <p>International information security standards constitute an extensive system, which
includes both mandatory provisions and provisions-recommendations for ensuring
information security. At the same time, the development of new standards is an ongoing
process that responds to all new challenges and incidents of information security and is
aimed at designing a universal and reliable model for protecting personal data and
information, including in cyberspace.</p>
        <p>Application area
Data center security and</p>
        <p>protection</p>
        <p>Cloud protection</p>
        <p>Personal data protection
System security and protection
Artificial Intelligence Security



























</p>
        <p>Standards, guidelines, and reports
ISO / IEC 27001:2005
ISO / IEC 27001:2017
Telecommunications Infrastructure Standard for Data Centers
(TIA-942B)
NIST 800-53
SSAE 18 Audit Standard &amp; Certification
ISO-27001 / ISO-27002
ISO/IEC 27017:2015
ISO/IEC 27018:2017
CSA. Cloud Controls Matrix
CSA. Security Guidance for Critical Areas of Focus in Cloud
Computing
NIST. SP 800-146. Cloud Computing Synopsis and
Recommendations
ENISA. Cloud Computing: Benefits, Risks, and
Recommendations for Information Security
ISACA. IT Control Objectives for Cloud Computing: Controls
and Assurance in the Cloud
LCCA. Legal Cloud Computing Association: (SECTION II)
HIPAA Cloud storage security
General Data Protection Regulation (GDPR)
Payment Card Industry Data Security Standard (PCI DSS) PCI
compliance checklist 3.2
Health Insurance Portability and Accountability Act (HIPAA)
System and Organisation Controls (SOC) Reporting
CIS AWS Foundations v1.2
CIS Controls Top 20
ACSC Essential Eight
ETSI GS NFV-SEC 001 “Security Problem Statement”
The ETSI Industry Specification Group on Securing Artificial
Intelligence (ISG SAI)
ENISA’s WP2020 Output O.1.1.3 on Building knowledge on
Artificial Intelligence Security
ENISA EC White Paper on Artificial Intelligence
Policy recommendations for safe and secure use of artificial
intelligence, automated decision-making, robotics, and
connected devices in a modern consumer world;
The Information Technology Industry (ITI) AI Policy
Principles</p>
        <p>The Malicious Use of Artificial Intelligence
At the moment, according to the Cybersecurity Strategy of Ukraine (2016–2020), the
main task of developing the cybersecurity system is to ensure the cyber resilience and
cybersecurity of the national information infrastructure, in particular in the context of
digital transformation. Technical and applied recommendations are provided by
“achieving compatibility with the relevant standards of the European Union and
NATO,” as well as taking into account “the best world practices and international
standards on cybersecurity and cyber defense.” Existing such documents in Ukraine in
the field of cybersecurity does not meet the requirements of today's cyber defense, and
in the field of artificial intelligence are absent. Therefore, the main direction of
development in the field of cybersecurity is artificial intelligence is the study of
recommendations for their further implementation, operation, monitoring, analysis both
at the state level and in individual sectors and industries.
6</p>
        <sec id="sec-3-6-1">
          <title>Conclusions</title>
          <p>This paper examines the main methods of ensuring the security and protection of an
artificial intelligence system, including data storage, system functionality, as well as
the cyber resilience and fault tolerance of artificial intelligence systems in general.
Analysis of the existing International recommendations in this area showed the need
for the development of relevant regulatory documents in Ukraine, due to their
discrepancy or absence. In this regard, the introduction of AI systems in Ukraine is
slow, which entails a lag in many industries.</p>
        </sec>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>White</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Banks</surname>
          </string-name>
          , E.:
          <article-title>Computer networking problems and solutions: An innovative approach to building resilient, modern networks (</article-title>
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Palhares</surname>
            ,
            <given-names>R. M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yuan</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>Q.</given-names>
          </string-name>
          :
          <source>Artificial Intelligence in Industrial Systems. IEEE Trans. Ind. Electron</source>
          .
          <volume>66</volume>
          (
          <issue>12</issue>
          ):
          <fpage>9636</fpage>
          -
          <lpage>9640</lpage>
          (
          <year>2019</year>
          ). https://doi.org/10.1109/TIE.
          <year>2019</year>
          .2916709
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Bresniker</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          , et al.:
          <source>Grand Challenge: Applying Artificial Intelligence and Machine Learning to Cybersecurity. Comput</source>
          .
          <volume>52</volume>
          (
          <issue>12</issue>
          ):
          <fpage>45</fpage>
          -
          <lpage>52</lpage>
          (
          <year>2019</year>
          ). https://doi.org/10.1109/
          <string-name>
            <surname>MC</surname>
          </string-name>
          .
          <year>2019</year>
          .2942584
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Smelyakov</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          , et al.:
          <article-title>Efficiency of Image Convolution</article-title>
          .
          <source>IEEE 8th International Conference on Advanced Optoelectronics and Lasers:</source>
          <fpage>578</fpage>
          -
          <lpage>583</lpage>
          (
          <year>2019</year>
          ). https://doi.org/10.1109/CAOL46282.
          <year>2019</year>
          .9019450
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Smelyakov</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          , et al.:
          <article-title>Comparative efficiency analysis of gradational correction models of highly lighted image</article-title>
          . IEEE International Scientific-Practical Conference Problems of Infocommunications, Science and Technology:
          <fpage>703</fpage>
          -
          <lpage>708</lpage>
          (
          <year>2019</year>
          ). https://doi.org/10.1109/PICST47496.
          <year>2019</year>
          .9061356
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Smelyakov</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chupryna</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hvozdiev</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sandrkin</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Gradational correction models efficiency analysis of low-light digital image</article-title>
          . Open Conference of Electrical, Electronic and Information Sciences:
          <fpage>34</fpage>
          -
          <lpage>39</lpage>
          (
          <year>2019</year>
          ). https://doi.org/10.1109/eStream.
          <year>2019</year>
          .8732174
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Hu</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Buriachok</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bogachuk</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sokolov</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ageyev</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Development and operation analysis of spectrum monitoring subsystem 2.4-2.5 GHz range</article-title>
          .
          <source>Lect. Notes Data Eng. Commun. Technol</source>
          .
          <volume>48</volume>
          :
          <fpage>675</fpage>
          -
          <lpage>709</lpage>
          (
          <year>2020</year>
          ). https://doi.org/10.1007/978-3-
          <fpage>030</fpage>
          -43070-2_
          <fpage>29</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Lemeshko</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yevsieieva</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yevdokymenko</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Tensor flow-based model of quality of experience routing</article-title>
          .
          <source>14th International Conference on Advanced Trends in Radioelectronics</source>
          , Telecommunications and Computer Engineering:
          <fpage>1005</fpage>
          -
          <lpage>1008</lpage>
          (
          <year>2018</year>
          ). https://doi.org/1010.1109/TCSET.
          <year>2018</year>
          .8336364
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Kuzminykh</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Carlsson</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yevdokymenko</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sokolov</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          :
          <article-title>Investigation of the IoT device lifetime with secure data transmission</article-title>
          .
          <source>Lect. Notes Comput. Sci</source>
          .
          <volume>11660</volume>
          :
          <fpage>16</fpage>
          -
          <lpage>27</lpage>
          (
          <year>2019</year>
          ). https://doi.org/10.1007/978-3-
          <fpage>030</fpage>
          -30859-
          <issue>9</issue>
          _
          <fpage>2</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Kant</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Le</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jajodia</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Security considerations in data center configuration management</article-title>
          .
          <source>4th Symposium on Configuration Analytics and Automation:</source>
          <fpage>1</fpage>
          -
          <lpage>9</lpage>
          (
          <year>2011</year>
          ). https://doi.org/10.1109/SafeConfig.
          <year>2011</year>
          .6111676
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Alhenaki</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Alwatban</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Alamri</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Alarifi</surname>
          </string-name>
          , N.:
          <article-title>A survey on the security of cloud computing</article-title>
          .
          <source>2nd International Conference on Computer Applications</source>
          and Information Security:
          <fpage>1</fpage>
          -
          <lpage>7</lpage>
          (
          <year>2019</year>
          ). https://doi.org/10.1109/CAIS.
          <year>2019</year>
          .8769497
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Tipper</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Resilient network design: challenges and future directions</article-title>
          .
          <source>Telecommun. Syst</source>
          .
          <volume>56</volume>
          (
          <issue>1</issue>
          ):
          <fpage>5</fpage>
          -
          <lpage>16</lpage>
          (
          <year>2014</year>
          ). https://doi.org/10.1007/s11235-013-9815-x
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Ganesh</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sandhya</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shankar</surname>
            ,
            <given-names>S.:</given-names>
          </string-name>
          <article-title>A study on fault tolerance methods in cloud computing</article-title>
          .
          <source>IEEE International Advance Computing Conference:</source>
          <fpage>844</fpage>
          -
          <lpage>849</lpage>
          (
          <year>2014</year>
          ). https://doi.org/10.1109/IAdCC.
          <year>2014</year>
          .6779432
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Devi</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Paulraj</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          <article-title>: Multi level fault tolerance in cloud environment</article-title>
          .
          <source>International Conference on Intelligent Computing and Control Systems:</source>
          <fpage>824</fpage>
          -
          <lpage>828</lpage>
          (
          <year>2017</year>
          ). https://doi.org/10.1109/ICCONS.
          <year>2017</year>
          .8250578
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Amoon</surname>
            ,
            <given-names>M.:</given-names>
          </string-name>
          <article-title>A framework for providing a hybrid fault tolerance in cloud computing</article-title>
          .
          <source>Science and Information Conference:</source>
          <fpage>844</fpage>
          -
          <lpage>849</lpage>
          (
          <year>2015</year>
          ). https://doi.org/10.1109/SAI.
          <year>2015</year>
          .7237242
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16. Cloud Security Alliance:
          <article-title>Security Guidance for Critical Areas of Focus in Cloud Computing (</article-title>
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <article-title>European Network and Information Security Agency: Benefits, risks and recommendations for information security (</article-title>
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18. NIST SP 800-
          <article-title>145: A NIST definition of cloud computing (</article-title>
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Kumar</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          , Hamed Said Al Hasani,
          <string-name>
            <surname>M.</surname>
          </string-name>
          :
          <article-title>Database security-risks and control methods</article-title>
          .
          <source>First IEEE International Conference on Computer Communication and the Internet</source>
          :
          <fpage>334</fpage>
          -
          <lpage>340</lpage>
          (
          <year>2016</year>
          ). https://doi.org/10.1109/CCI.
          <year>2016</year>
          .7778937
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <string-name>
            <surname>Firdhous</surname>
            ,
            <given-names>M. F. M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hussien</surname>
            ,
            <given-names>N. A.</given-names>
          </string-name>
          :
          <article-title>Data security implementations in cloud computing: A critical review</article-title>
          .
          <source>3rd International Conference on Information Technology Research</source>
          :
          <fpage>1</fpage>
          -
          <lpage>5</lpage>
          (
          <year>2018</year>
          ). https://doi.org/10.1109/ICITR.
          <year>2018</year>
          .
          <volume>8736153</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <surname>Lemeshko</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yeremenko</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yevdokymenko</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Tensor model of fault-tolerant QoS routing with support of bandwidth and delay protection</article-title>
          .
          <source>13th International Scientific and Technical Conference Computer Sciences and Information Technologies</source>
          :
          <fpage>135</fpage>
          -
          <lpage>138</lpage>
          (
          <year>2018</year>
          ). https://doi.org/10.1109/stc-csit.
          <year>2018</year>
          .8526707
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <surname>Lemeshko</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          , et al.:
          <article-title>Design of the fast reroute QoS protection scheme for bandwidth and probability of packet loss in software-defined WAN</article-title>
          .
          <source>15th International Conference the Experience of Designing and Application of CAD Systems in Microelectronics:</source>
          <fpage>72</fpage>
          -
          <lpage>76</lpage>
          (
          <year>2019</year>
          ). https://doi.org/10.1109/CADSM.
          <year>2019</year>
          .
          <volume>8779321</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <surname>Lemeshko</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          , et al.:
          <article-title>Cyber resilience approach based on traffic engineering fast reroute with policing</article-title>
          .
          <source>10th IEEE International Conference on Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications:</source>
          <fpage>117</fpage>
          -
          <lpage>122</lpage>
          (
          <year>2019</year>
          ). https://doi.org/10.1109/IDAACS.
          <year>2019</year>
          .8924294
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>Yevdokymenko</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shapovalova</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Voloshchuk</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Carlsson</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Proactive approach for security of the infocommunication network based on vulnerability assessment</article-title>
          .
          <source>International Scientific-Practical Conference on Problems of Infocommunications Science and Technology:</source>
          <fpage>609</fpage>
          -
          <lpage>612</lpage>
          (
          <year>2019</year>
          ). https://doi.org/10.1109/INFOCOMMST.
          <year>2018</year>
          .8632079
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          25. ISO/IEC 27005:
          <article-title>Information technology-security techniques-information security risk management (</article-title>
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          26. ISO/IEC 27017:
          <article-title>Information technology-security techniques-code of practice for information security controls based on ISO/IEC 27002 for cloud services (</article-title>
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          27.
          <string-name>
            <surname>Newman</surname>
            ,
            <given-names>J. C.</given-names>
          </string-name>
          :
          <string-name>
            <surname>Toward AI</surname>
          </string-name>
          <article-title>Security: Global Aspirations for a More Resilient Future. Berkeley Center for Long-Term Cybersecurity (</article-title>
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          28.
          <source>National Security Commission on Artificial Intelligence: First Quarter Recommendations</source>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          29. ANSI/TIA-942
          <article-title>-A: Telecommunications Infrastructure Standard for Data Centers (</article-title>
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          30.
          <article-title>ISACA: IT Control Objectives for Cloud Computing: Controls and Assurance in the Cloud (</article-title>
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          31. LCCA:
          <article-title>Legal Cloud Computing Association: (SECTION II) HIPAA Cloud storage security (</article-title>
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          32. CSA:
          <article-title>Security Guidance for Critical Areas of Focus in Cloud Computing (</article-title>
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          33.
          <source>NIST: SP 800-146. Cloud Computing Synopsis and Recommendations</source>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>