<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Resilient Computer Systems Development for Cyberattacks Resistance</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Sergii Lysenko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Kira Bobrovnikova</string-name>
          <email>bobrovnikova.kira@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Piotr Gaj</string-name>
          <email>piotr.gaj@polsl.pl</email>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Tomas Sochor</string-name>
          <email>tomas.sochor@osu.cz</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Iryna Forkun</string-name>
          <email>ivforkun@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Khmelnitsky National University</institution>
          ,
          <addr-line>Khmelnitsky</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Prigo University</institution>
          ,
          <addr-line>Havirov</addr-line>
          ,
          <country country="CZ">Czech Republic</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Silesian University of Technology</institution>
          ,
          <addr-line>Gliwice</addr-line>
          ,
          <country country="PL">Poland</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The dynamic growth of cyberattacks amount makes the antivirus developers to construct and involve new approaches to not only detect, but mitigate the impact of the attacks. One of new direct to ensure such possibility is the concept of construction of a resilient computer system, that will be able to resist the attacks. This paper presents some principles concerning the computer systems' resilience for cyberattacks resistance. In particular, we describe the concept of resilience as the set of requirements to the computer system. Thus, to ensure the resilient functioning of the computer system in the conditions of cyberattacks, it must be prepared for possible cyberattacks, protected, able to detect cyberattacks, able to respond cyberattacks and to adsorb the cyberattacks' impact, be adaptive, be recoverable. In addition, paper presents experimental issues concerning the techniques are to be used to ensure computer system's resilience under the cyberattacks.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Resilience</kwd>
        <kwd>Cyberattack</kwd>
        <kwd>Computer Network</kwd>
        <kwd>Cybersecurity</kwd>
        <kwd>Computer system</kwd>
        <kwd>Malware</kwd>
        <kwd>Malicious traffic</kwd>
        <kwd>Cyberattacks Detection</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Today we are observers of the dynamic growth of the cyberattacks amount. Attacks impact every
sphere where the computer systems are used. Thus, the very strong challenge is to develop new
techniques not only to detect the attacks, but also to mitigate, adsorb and resist the attacks. The very
new approach to do this is to develop resilient computer systems, able to resist the known and
unknown attacks [
        <xref ref-type="bibr" rid="ref1 ref2 ref3 ref4 ref5 ref6 ref7 ref8 ref9">1-5</xref>
        ]. The concept of resilience has been widely used in many contexts, and some of
these researches are already applied to critical infrastructures. For example, in the ecological context
[
        <xref ref-type="bibr" rid="ref10 ref11 ref12 ref13 ref14">6-10</xref>
        ] resilience is a property of the population, which can be considered in terms of the properties of
equilibrium and oscillations caused by the disturbances of the system. Also, resilience interpretation is
applied in economics [
        <xref ref-type="bibr" rid="ref15 ref16 ref17 ref18 ref19 ref20">11-16</xref>
        ]. The construction of buildings includes the property of resisting
disasters [
        <xref ref-type="bibr" rid="ref21">17-18</xref>
        ]. In the context of protection of critical infrastructure, system resistance is presented
in [19]. From the point of view of cybersecurity, computer system resilience is the ability to
anticipate, resist, restore and adapt under the influences caused by cyberattacks [20-21]. So, it is very
important to develop the concept of resilient computer system functioning under the cyberattacks.
      </p>
    </sec>
    <sec id="sec-2">
      <title>2. Related work</title>
      <p>Nowadays, a great variety of approaches [22] and techniques [23] for identification and object
classification [24] are employed. In the paper [25] a comprehensive set of current challenges of
phishing attacks and literature review of different Artificial Intelligence (AI) based detection
techniques: Scenario-based, Machine Learning, Deep Learning, Hybrid Learning were provided. Also
the comparison of different works devoted to detection the phishing attack for these AI technique as
well as their advantages and disadvantages were highlighted. In [26] the pros and cons of all aspects
of the concept of moving target defense (MTD): key roles, principles of design, classifications,
common attacks, basic methodologies and algorithms, metrics and evaluation methods were
discussed. The goal of this work is to provide the common trends of the concept of moving target
defense research in terms of critical aspects of systems defense for researchers who seek to develop
adaptive, proactive mechanisms of MTD.nWith aim of insights into the aspects of proactive
defensein-depth strategies in work [27] a dynamic game framework to model an interaction between a
proactive defender and a stealthy attacker was proposed. The deceptive and stealthy behaviors take
place by the multi-stage game with incomplete information, where each player has his own unknown
to the other information and act according to their convictions which are formed by the learning based
on multi-stage observation. In [28] a solution for visual analytics and analysis the possible
cyberattacks and identifying suitable mitigations was developed. This solution allows security
operators to improve the network security by make decisions on the possible countermeasures.
Developed system allows presenting visually the relevant information for a better understand of the
attack and its probable evolution. In the paper [29] intrusion detection system (IDS) for a proactive
network security monitoring for a computing infrastructure was presented. It includes an intelligent
module with using deep learning modeling in order to monitoring network traffic flows in near
realtime. In the work [30] a system for cyberattack detection and corrective action in the distribution
system was proposed. The developed framework allows detecting abnormal behaviors and identifies
them as internal failure or cyberattack. It based on two algorithms: to identify anomalies in the
distribution system and provide a corrective control using smart inverters. In addition, this framework
includes geographic community smart devices measurements based cyberattack detection mechanism.</p>
      <p>In [31] the approach for defense a cyber-physical system under various types of attacks, including
actuator and sensor attacks was proposed. A novel integral Bellman-based IDS to detect and mitigate
the cyberattacks by collecting data online and without knowledge of the systems physical
interpretation was developed. The proposed IDS consist of proactive and reactive components. With
aim to neutralize the efforts of attackers the proactive component based on the principles of moving
target defense and a stochastic switching changes dynamically behavior of system. In order efficiency
increasing this component uses the entropy based unpredictability metric. The reactive component
blocks the compromised system components.</p>
      <p>The presented in [32] IDS for cyber-physical systems is based on an approximate dynamic
programming technique that learns the policies for optimal tracking and optimal regulation for the
detection and mitigation against actuator and sensor cyberattacks in a model-free fashion. Switching
rules are used to force proactive and reactive defense mechanisms and increase of the stability.</p>
      <p>The research [33] devoted to detection, prediction, prevention and recover from cyber-attacks in
the railway industry by using defensive controls called the Railway Defender Kill Chain (RDKC).
With this aim the proposed approach uses an extended cyber kill chain (CKC) model and an industrial
control system (ICS) cyber kill chain. The CKC model includes internal and external CKC. Early
breaking of these chains allows stopping the cyber-attacks. Also, an OSA (open system architecture)
with the cybersecurity OSA-CBM (open system architecture for condition-based maintenance)
architecture was developed. The OSA-CBM architecture includes eight layers: collection, processing
and analysis of data; detection, assessment and prognostics of incident; decision support.</p>
      <p>In [34] a proactive defense approach for protection a group of related users against lateral
spearphishing was proposed. The proposed technique is based on frequently randomly mutation of sender
email address that can only be verified by trusted users. Also corresponding algorithm, protocol and
implementation for any email service providers such as Gmail, Apple iCloud, etc were presented.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Operational Cycle of the Resilient Computer System under cyberattacks</title>
    </sec>
    <sec id="sec-4">
      <title>3.1. Requirement to the resilient computer system under cyberattacks</title>
      <p>where sprep – preparation for the functioning of the system under the cyberattacks; sprot – system
protection; sdetect – attack detection; sabsorb – attack absorption; srespond – attack response; srecovery –
system recovery after the attack; sadapt – system adaptation based on knowledge about previous
cyberattacks.</p>
      <p>Let us consider the initial moment of computer system functioning C as t0, in which the system
functions normally, ta – the moment when the attack A starts, tdeg – the moment when the system
began to degrade under attack A, trec – the moment when computer system begins to recover, tnorm –
the moment when the system has reached a normal state after the recovery. Then let us determine the
set of time intervals that characterize the resilience of system C under attacks:</p>
      <p>τ = {τ 0 ,τatt ,τ inf ,τrec } , (2)
where τ 0 is the interval of normal functioning of the system, τ 0 (C, A) = [t0 , ta ) ; τ att – the interval
of resilient functioning of the system when an attack is carried out, but the degradation system is not
yet affected, τ att (C, A) = [ta , tdeg ) ; τ inf – system degradation interval under the influence of destructive
τ inf (C, A) = [tdeg , trec ) ; τ rec – system recovery interval after the attack,
actions of the attack,
τ rec (C, A) = [trec , tnorm ) .
(1)
(3)</p>
      <p>To ensure the resilient functioning of the computer system in the conditions of cyberattacks, the
system must be:
1. prepared for possible cyberattacks.
2. protected;
3. able to detect cyberattacks;
4. able to respond cyberattacks and to adsorb the cyberattacks’ impact;
5. be adaptive;
6. be recoverable.</p>
      <p>Let us consider a set A of destructive actions am against the computer system C, A = {am}mNm=1 .
Then operational cycle of the resilient computer system under the cyberattacks we will consider as a
set of information and technical states that the system passes (Fig. 2):</p>
      <p>S = {s prep , s prot , sdetect , s absorb , s respond , s recovery , s adapt ,
}
Each state of computer system is characterized by a set of values of parameters</p>
      <p>∀s j ∈S :s j = {X j ,Z j ,F j }
where X j = {Xsys , Xenv , Xreq , Xfail} ; Xsys – system parameters, Xsys = {x j}Nj=X1sys , NXsys – number
NXreq ; NXreq
of system parameters; Xreq – system requirements, Xreq = {x j}j=1
- number of system
requirements; Xenv – environment parameters, Xenv = {x j}Nj=X1env ; NXenv – the number of parameters
NXfail ; NXfail – number of failure parameters;
of the environment; Xfail – fail parameters, Xfail = {x j}j=1
Fj = {Fprep , Fprot , Fdetect , Fabsorb , Frespond , Frecovery , Fadapt } – set of mechanisms Fj, which have to be applied
depending on the state of the system</p>
      <p>C and in the conditions of attack Ak, Ci × Ak → Fj ;
Z j = {Zprep , Zprot , Zdetect , Zabsorb , Zrespond , Zrecovery , Zadapt } – a set of system parameters obtained as a
result of the use of mechanisms Fj.</p>
      <p>From the point of view of the operating cycle, the resilience of computer system C will be
influenced by a set of indicators w, which reflect different aspects of the uncertainty of states S
W
=(w1; w2 ;…) , wi (i =1, 2,…) .</p>
      <p>P (W ) =P (W prep ) ∪P (W detect ) ∪P (Wabsorb ) ∪</p>
      <p>Since the information and technical states S are independent, the probability P of successful
implementation of operational cycle of the functioning of the computer system C will be presented as:
(4)
∪P (Wrespond )∪P (Wre covery )∪P (Wadapt ) ,P (W ) =w ∑∈ Pi ,
i W
where P(wprep) is the probability that the system is timely prepared and protected; P(wdetect) is the
probability that the system is capable of detecting threats; P(wabsorb) is the probability that the system
is capable of absorbing threats; P(wrespond) is the probability that the system is capable of responding
to a threat; P(w) is the probability that the system is capable to recover after the attack.</p>
    </sec>
    <sec id="sec-5">
      <title>3.2. Stages of the resilient computer system functioning under the cyberattacks</title>
      <p>Let us consider the stages of the resilient computer system functioning under the cyberattacks.</p>
      <p>Preparation. To build a resilient system C that is under cyberattack A and we are to apply a set of
preparatory measures Gprep to predict the prevention of possible cyberattacks:</p>
      <p>G prep = {Ar , Com , Seg , Mon , SS , Res } , (5)
where Ar is a set of measures for customizing the architectural components of the system,</p>
      <p>NAr , NAr – the number of measures; Com – a set of measures to configure the connection
Ar = {arj}j=1
between the computer system components, Com = {com j}Nj=C1om , NCom – the number of measures; Seg –
a set of measures to adjust the segmentation of the computer system, Seg = {seg j}Nj=S1eg , NSeg – the
number of segmentation measures; Mon – a set of measures to ensure monitoring of the computer
system,</p>
      <p>NMon , NMon – the number of monitoring measures; SS – a set of security</p>
      <p>Mon = {mon j}j=1
scenarios, which are to be applied to attacked system, SS = {ss j}Nj=S1S , NSS– number of scenarios; Res –
a set of measures to ensure the critical data and system information backup execution,
Re s = {res j}Nj=R1es , NRes – the number of backup measures.</p>
      <p>Other aspects of the resilient computer system functioning are the preparedness, that is the
implementation of actions:
1. understanding and evaluating cyber risk by analyzing and simulating cyberattacks;
2. identifying and eliminating known vulnerabilities in computer systems by which
cybercriminals carry out cyberattacks;
3. raising awareness of the signs of known cyber threats and understanding how to recognize
them;
4. appropriate backup and restore strategies.</p>
      <p>Protection. The protection stage involves the development and implementation of a set of
methods and measures of Gprot for the computer system security C in order to limit or determine the of
cyberattacks impact.</p>
      <p>The goal of this stage is to protect the computer system’ infrastructure and minimize the likelihood
that an attack can be successful and, if that happens, the ability to respond quickly to reduce the
damage.</p>
      <p>The assessment of the security of the system should reveal any vulnerabilities in existing
protection methods.</p>
      <p>Detection. The purpose of detection stage is to develop and implement a set of methods GDetect,
GDetect = {GhDoesttect , GlDanetect } to quickly detect attack A, to evaluate the affected system, and to ensure
timely response, where GhDoesttect – a set of methods for detecting host type cyberattacks, GlDanetect – a set
of methods for detecting network type cyberattacks.</p>
      <p>Absorption. Continued functioning of computer system under cyberattacks may require
unpredictable changes in the basic architecture of the system, depending on what exactly is degraded
by means of a cyberattack.</p>
      <p>To describe the process of system degradation under the of cyberattacks, let us consider a function
ξ that will reflect the current performance of the computer system. Any destructive action a m of
attack A will affect the computer system, then ξ (t | am ) will indicate the value of the computer system
performance at the time t when it performs the action am. Given the impact of destructive actions of
attack A on system C, which functioned in the time interval from t0 to tnorm, let us consider the set of
actions of attack A as A =:ξ {am (t | am ) ≠ ξ (t0 )} , t ∈[t0 , tnorm ) .</p>
      <p>Respond. The respond stage of the resilient computer system has to contain a set of Gresp methods
for activities that can speed up the time to mitigate the impact of attack after it was detected.</p>
      <p>Recovery. The final and most important stage of ensuring the resilience computer system under
the attack is recovery stage.</p>
      <p>Adaptation. To increase the system's resistance, adaptation involves a set of methods Gadapt,
Gadapt = {Rstr , Rcnf } , where Rstr is a set of restructuring methods, Rcnf is a set of methods for
reconfiguring system components based on knowledge about previous cyberattacks.</p>
    </sec>
    <sec id="sec-6">
      <title>4. Experiments</title>
      <p>In order to determine the efficiency of the proposed technique a set of experiments were carried
out. To do this the framework named BotGRABBER was employed [35].</p>
      <p>In this article we present as a case the process of resilient functioning of the computer system
under the Man-in-the-middle (MitM) attack [36]. This type of attack may occur when an attacker
performs the communications insertion between a client and a server. In our case, attack involved the
hijacking of the communication session between a trusted client and network server. The computer
system infected by MitM substitutes its IP address for the trusted client. At this moment the
infrastructural server continues its session and does not know about intrusion.</p>
      <p>Consider the operating cycle of the computer system under the MitM attack let it present as
AMitM : sprep → sdetect С × АMitM → FMitM , τ att (C, AMitM ) = [ta , tdeg ) .</p>
      <p>MitM attack mitigation relies on performing of a set of mechanisms and measures:
1. Strong WEP/WAP Encryption on Access Points.
transfer the computer system to the response and recovery stages: sdetect → sresp → sreq . Depending on
the intensity of the attack and the effectiveness of the mitigation measures at the time of treq, the
system goes into a state of recovery sreq → snorm ,τ rec (C, AMitM ) = [trec , tnorm ) .</p>
      <p>In order to assess the assurance of the network' s resilience, the integrated resilience metric
presented in [37] was used:</p>
      <p>=  ( ,     ,      ,   ,   )= ×     ×  1  ×   (6)
where R – computer system resistance, which indicates a value of the compute system
performance value between some period of time and is normalized between 0 and 1 (where 0 - a total
compute system operation’s degradation under attacks and 1 – value for the normal network
functioning); SRAPDP - the attack’s rapidity; SRAPRP – the computer system reconfiguration stage
rapidity; TMPL – averaged value of the computer system performance degradation; RCAB – the
reconfiguration ability to apply the security scenario in order to recover after the attack.</p>
      <p>We will consider that the computer system recover was successful if GR&gt; δ, where δ - the
predefined threshold.</p>
      <p>Based on the above-described concept of resistance and its attributes, we have involved the set of
techniques able to perform needed action for preparation [38-39], detection [40-42], respond [43-46]
and recovery [47-48]. During the experiments, the 357 attacks of different types against the hosts,
server and routers were performed [49-52]. The rates of the successful computer system
reconfigurations that leads to the mitigation of the attacks are presented in a table 1. Thus, the
involvement of the proposed approach has demonstrated the ability to ensure the computer system
resilient functioning under the cyberattacks at the rate of 73%.</p>
      <p>Table 1</p>
      <sec id="sec-6-1">
        <title>Results of the experiments</title>
      </sec>
      <sec id="sec-6-2">
        <title>Attack’s target</title>
      </sec>
      <sec id="sec-6-3">
        <title>Network hosts</title>
      </sec>
      <sec id="sec-6-4">
        <title>Server</title>
        <p>routers
total</p>
      </sec>
      <sec id="sec-6-5">
        <title>Number of</title>
        <p>attacks</p>
      </sec>
    </sec>
    <sec id="sec-7">
      <title>5. Conclusion</title>
      <p>This article gives an approach concerning the construction of the computer systems’ resilience for
cyberattacks resistance. It presents the main principles to assure resilience as the set of needed
requirements to construct such computer system. Thus, to ensure the resilient functioning for the
computer system under the cyberattacks, it has to be prepared for possible cyberattacks, protected,
able to detect cyberattacks, able to respond cyberattacks and to adsorb the cyberattacks’ impact, be
adaptive, be recoverable. Article also paper presents experimental section with the analysis of
possible computer system resistance under attacks. Thus, approach involves the set of techniques to
not only detect the attacks, but to mitigate it performing the computer system reconfiguration
scenarios according to the cyberattacks. Experimental results showed that the implemented principals
ensured the resilient functioning under the cyberattacks by botnets at the rate at about 73%.</p>
      <p>The further work may be devoted to the development of the techniques that involve machine
learning algorithms for increasing the efficiency of the computer system resilience.</p>
    </sec>
    <sec id="sec-8">
      <title>6. References</title>
      <p>[18] Larkin, S., Fox-Lent, C., Eisenberg, D. A., Trump, B. D., Wallace, S., Chadderton, C., &amp; Linkov,
I. (2015). Benchmarking agency and organizational practices in resilience decision making.</p>
      <p>Environment Systems and Decisions, 35(2), 185–195.
[19] Kott., et al. A Reference Architecture of an Autonomous Intelligent Agent for Cyber Defense
(Tech.l Rep.). US Army Research Laboratory, Aberdeen Proving Ground, United States(2018).
[20] Ganin, A. A., Quach, P., Panwar, M., Collier, Z. A., Keisler, J. M., Marchese, D., &amp; Linkov, I..</p>
      <p>Multicriteria decision framework for cybersecurity risk assessment and management. Risk
Analysis. (2017).
[21] Gao, J., Barzel, B., &amp; Barabási, A. L. Universal resilience patterns in complex networks. Nature,
(2016).530(7590), 307–312.
[22] Savenko, O., Sachenko, A., Lysenko, S., Markowsky, G., and Vasylkiv, N. Botnet detection
approach based on the distributed systems. International Journal of Computing, 2020.19(2),
190198. https://doi.org/10.47839/ijc.19.2.1761.
[23] A. V. Barmak et al.: Information technology of separating hyperplanes synthesis for linear
classifiers. J. Autom. Inf. Sci. 51(5), 54–64 (2019). doi:10.1615/JAutomatInfScien.v51.i5.50.
[24] Krak, Iu.V. Barmak, O.V., Romanyshyn, S.O. The method of generalized grammar structures for
text to gestures computer-aided translation. Cybern. Syst. Anal. 50(1), 116–123 (2014).
doi:10.1007/s10559-014-9598-4.
[25] Basit, A., Zafar, M., Liu, X., Javed, A. R., Jalil, Z., &amp; Kifayat, K. A comprehensive survey of
AIenabled phishing attacks detection techniques. Telecommunication Systems, pp. 1-16 (2020).
[26] Cho, J. H., Sharma, D. P., Alavizadeh, H., Yoon, S., Ben-Asher, N., Moore, T. J., &amp; Nelson, F.</p>
      <p>F. Toward proactive, adaptive defense: A survey on moving target defense. IEEE
Communications Surveys &amp; Tutorials, 22(1), 709-745 (2020).
[27] Huang, L., &amp; Zhu, Q. A dynamic games approach to proactive defense strategies against
advanced persistent threats in cyber-physical systems. Computers &amp; Security, 89, 101660 (2020).
[28] Angelini, M., Bonomi, S., Lenti, S., Santucci, G., &amp; Taggi, S. MAD: A visual analytics solution
for Multi-step cyber Attacks Detection. Journal of Computer Languages, 52, pp. 10-24 (2019).
[29] Nguyen, G., Dlugolinsky, S., Tran, V., &amp; García, Á. L. Deep learning for proactive network
monitoring and security protection. IEEE Access, 8, 19696-19716 (2020).
[30] Fard, A. Y., Easley, M., Amariucai, G. T., Shadmand, M. B., &amp; Abu-Rub, H. Cybersecurity
analytics using smart inverters in power distribution system: Proactive intrusion detection and
corrective control framework. In 2019 IEEE International Symposium on Technologies for
Homeland Security (HST) (pp. 1-6). IEEE (2019).
[31] Kanellopoulos, A., &amp; Vamvoudakis, K. G. Entropy-based proactive and reactive cyber-physical
security. In Proactive and Dynamic Network Defense, pp. 59-83. Springer, Cham (2019).
[32] Zhai, L., &amp; Vamvoudakis, K. G. Data-based and secure switched cyber–physical systems.</p>
      <p>Systems &amp; Control Letters, 148, 104826 (2021).
[33] Kour, R., Thaduri, A., &amp; Karim, R. Railway defender kill chain to predict and detect
cyberattacks. Journal of Cyber Security and Mobility, pp. 47-90 (2020).
[34] Islam, M. M., Al-Shaer, E., &amp; Rahim, M. A. B. U. Email address mutation for proactive
deterrence against lateral spear-phishing attacks. In International Conference on Security and
Privacy in Communication Systems, pp. 1-22. Springer, Cham (2020).
[35] Lysenko S., Bobrovnikova K., Savenko O., Kryshchuk A. BotGRABBER: SVM-Based
SelfAdaptive System for the Network Resilience Against the Botnets' Cyberattacks. In: Gaj P.,
Sawicki M., Kwiecien A. (eds) Computer Networks. CN 2019. Communications in Computer
and Information Science, vol 1039, p. 127-143. Springer, Cham (2019), doi:
10.1007/978-3-03021952-9 10.
[36] Jeff Melnick. Top 10 Most Common Types of Cyber Attacks Updated: October 8, 2020 URL:
https://blog.netwrix.com/2018/05/15/top-10-most-common-types-of-cyber-attacks/#Man-in-themiddle%20(MitM)%20attack.
[37] Lysenko, S., Savenko, O., Bobrovnikova, K., Kryshchuk, A.: Self-adaptive System for the
Corporate Area Network Resilience in the Presence of Botnet Cyberattacks. In: International
Conference on Computer Networks, pp. 385-401. Springer, Cham (2018).
[38] Lysenko, S., Savenko, O., Bobrovnikova, K., Kryshchuk, A., Savenko, B.: Information
Technology for Botnets Detection Based on Their Behaviour in the Corporate Area Network. In:
International Conference on Computer Networks, pp. 166-181. Springer, Cham (2017).
[39] O. Savenko, S. Lysenko, A. Kryschuk, Multi-agent based approach of botnet detection in
computer systems Communications in Computer and Information Science, 291 (2012) 171-180
[40] Pomorova, O., Savenko, O., Lysenko, S., Kryshchuk, A., Bobrovnikova, K.: Antievasion
technique for the botnets detection based on the passive DNS monitoring and active DNS
probing. In: International Conference on Computer Networks: Springer International Publishing,
pp. 83-95. Springer, Cham (2016).
[41] Lysenko, S., Pomorova, O., Savenko, O., Kryshchuk, A. and Bobrovnikova, K. DNS-based
antievasion technique for botnets detection. 2015 IEEE 8th International Conference on Intelligent
Data Acquisition and Advanced Computing Systems: Technology and Applications (IDAACS),
Warsaw, 2015, pp. 453-458 (2015), doi: 10.1109/IDAACS.2015.7340777.
[42] Savenko, O., A. Nicheporuk, Ivan Hurman and S. Lysenko. “Dynamic Signature-based Malware</p>
      <p>Detection Technique Based on API Call Tracing.” ICTERI Workshops (2019).
[43] Melnyk, A., Melnyk, V. Remote Synthesis of Computer Devices for FPGA-Based IoT Nodes.
2020 10th International Conference on Advanced Computer Information Technologies, ACIT
2020 – Proceedings 9208882, pp. 254-259.
[44] Melnyk, A., Melnyk, V. Specialized Processors Automatic Design Tools-the Basis of
SelfConfigurable Computer and Cyber-Physical Systems. 2019 IEEE International Conference on
Advanced Trends in Information Theory, ATIT 2019 - Proceedings, pp. 326-335.</p>
      <p>DOI:10.1109/ATIT49449.2019.9030481.
[45] C. Shu, D. Dosyn, V. Lytvyn, V. Vysotska, A. Sachenko and S. Jun, "Building of the Predicate
Recognition System for the NLP Ontology Learning Module," 2019 10th IEEE International
Conference on Intelligent Data Acquisition and Advanced Computing Systems: Technology and
Applications (IDAACS), Metz, France, 2019, pp. 802-808, doi:
10.1109/IDAACS.2019.8924410.
[46] Ivasiev S., Kasyanchuk M., Yakymenko I., Gomotiuk O., Shylinska I., Bilovus L. Algorithmic
Support for Rabin Cryptosystem Implementation Based on Addition. Advanced Computer
Information Technology (ACIT–2020): Proceedings of the International Conference. Deggendorf
(Germany). 2020. P. 779-782 (Scopus).
[47] Yakymenko I., Kasianchuk M., Gomotiuk, O., Ivasiev S., Basistyi P. Elgamal cryptoalgorithm
on the basis of the vector-module method of modular exponentiation and multiplication
Proceedings - 15th International Conference on Advanced Trends in Radioelectronics,
Telecommunications and Computer Engineering, TCSET 2020, 2020, pp. 926–929.
[48] O. Drozd, K. Zashcholkin, O. Martynyuk, O. Ivanova, J. Drozd. Development of Checkability in
FPGA Components of Safety-Related Systems. CEUR Workshop Proceedings, vol. 2762, pp.
3042 (2020). Online http://ceur-ws.org/Vol-2762/paper1.pdf.
[49] O. Drozd, V. Antoniuk, V. Nikul, M. Drozd, “Hidden faults in FPGA-built digital components of
safety-related systems,” Proc. of the 14th International Conference “TCSET’2018 Conference
“Modern problems of radio engineering, telecommunications and computer science”,
LvivSlavsko, Ukraine, 2018, pp. 805-809. DOI: 10.1109/TCSET.2018.8336320.
[50] Drozd O., Perebeinos I., Martynyuk O., Zashcholkin K., Ivanova O., Drozd M.: Hidden fault
analysis of FPGA projects for critical applications. In: IEEE International Conference TCSET.</p>
      <p>Paper 142, Lviv-Slavsko, Ukraine, (2020) doi: 10.1109/TCSET49122.2020.235591.
[51] S. Lysenko, K. Bobrovnikova &amp; O. Savenko, A botnet detection approach based on the clonal
selection algorithm. In 2018 IEEE 9th International Conference on Dependable Systems,
Services and Technologies (DESSERT). IEEE (2018) 424-428.
[52] S. Lysenko, K. Bobrovnikova, S. Matiukh, I. Hurman &amp; O. Savenko, Detection of the botnets'
low-rate DDoS attacks based on self-similarity. International Journal of Electrical &amp; Computer
Engineering, 2020, 10, 2088-8708. DOI: http://doi.org/10.11591/ijece.v10i4.pp3651-3659.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          2.
          <string-name>
            <given-names>Strong</given-names>
            <surname>Router</surname>
          </string-name>
          Login Credentials.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>3. Virtual Private Network.</mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          4.
          <string-name>
            <surname>Force</surname>
            <given-names>HTTPS</given-names>
          </string-name>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          5.
          <source>Public Key Pair Based Authentication.</source>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>R.</given-names>
            <surname>Leizerovych</surname>
          </string-name>
          , G. Kondratenko,
          <string-name>
            <given-names>I.</given-names>
            <surname>Sidenko</surname>
          </string-name>
          and
          <string-name>
            <given-names>Y.</given-names>
            <surname>Kondratenko</surname>
          </string-name>
          ,
          <article-title>"IoT-complex for Monitoring and Analysis of Motor Highway Condition Using Articial Neural Networks,"</article-title>
          <source>2020 IEEE 11th International Conference on Dependable Systems, Services and Technologies (DESSERT)</source>
          , Kyiv, Ukraine, pp.
          <fpage>207</fpage>
          -
          <lpage>212</lpage>
          (
          <year>2020</year>
          ), doi:10.1109/DESSERT50317.
          <year>2020</year>
          .
          <volume>9125004</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Sokol</surname>
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zuzcak</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sochor</surname>
            <given-names>T.</given-names>
          </string-name>
          <article-title>Denition of attack in the context of low-level interaction server honeypots</article-title>
          .
          <source>Lecture Notes in Electrical Engineering 330</source>
          , pp.
          <fpage>499</fpage>
          -
          <lpage>504</lpage>
          (
          <year>2015</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Potii</surname>
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Illiashenko</surname>
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Komin</surname>
            <given-names>D</given-names>
          </string-name>
          .
          <source>Advanced Security Assurance Case Based on ISO/IEC 15408</source>
          . In: Zamojski W.,
          <string-name>
            <surname>Mazurkiewicz</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sugier</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Walkowiak</surname>
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kacprzyk</surname>
            <given-names>J</given-names>
          </string-name>
          . (eds)
          <article-title>Theory and Engineering of Complex Systems and Dependability</article-title>
          .
          <source>DepCoS-RELCOMEX. Advances in Intelligent Systems and Computing</source>
          , Springer, Cham, Vol.
          <volume>365</volume>
          , pp.
          <fpage>391</fpage>
          -
          <lpage>401</lpage>
          (
          <year>2015</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Drozd</surname>
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kharchenko</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rucinski</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kochanski</surname>
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Garbos</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <source>Maevsky D. Development of Models in Resilient Computing, Proc. of 10th IEEE International Conference on Dependable Systems, Services and Technologies</source>
          (DESSERT'
          <year>2019</year>
          ), Leeds,
          <string-name>
            <surname>UK</surname>
          </string-name>
          , June 5-7
          <year>2019</year>
          , pp.
          <fpage>2</fpage>
          -
          <lpage>7</lpage>
          (
          <year>2019</year>
          ), doi: 10.1109/DESSERT.
          <year>2019</year>
          .
          <volume>8770035</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Zuzcak</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sochor</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          <article-title>Behavioral analysis of bot activity in infected systems using honeypots</article-title>
          .
          <source>Communications in Computer and Information Science</source>
          : Springer,
          <year>2017</year>
          , Vol.
          <volume>718</volume>
          , pp.
          <fpage>118</fpage>
          -
          <lpage>133</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Cimellaro</surname>
            <given-names>G. P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dueñas-Osorio</surname>
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Reinhorn</surname>
            <given-names>A.M.</given-names>
          </string-name>
          <article-title>Introduction to special issue on resiliencebased analysis and design of structures and infrastructure systems</article-title>
          .
          <source>Structural Engineering</source>
          ,
          <year>2016</year>
          , No.
          <volume>142</volume>
          (
          <issue>8</issue>
          ), pp.
          <fpage>1</fpage>
          -
          <lpage>5</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Linkov</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Eisenberg</surname>
            ,
            <given-names>D. A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Plourde</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Seager</surname>
            ,
            <given-names>T. P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Allen</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kott</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <article-title>Resilience metrics for cyber systems</article-title>
          .
          <source>Environment Systems and Decisions</source>
          ,
          <year>2013</year>
          , No.
          <volume>33</volume>
          (
          <issue>4</issue>
          ), pp.
          <fpage>471</fpage>
          -
          <lpage>476</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Bodeau</surname>
            ,
            <given-names>D.J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Graubart</surname>
          </string-name>
          , R. D.
          <article-title>Cyber resiliency design principles: selective use throughout the lifecycle and in conjunction with related disciplines</article-title>
          .
          <source>MITRE Corp</source>
          .,
          <source>Tech. Rep.</source>
          ,
          <year>2017</year>
          , p.
          <fpage>98</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Zashcholkin</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Drozd</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sulima</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ivanova</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Perebeinos</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          <article-title>Detection method of the probable integrity violation areas in FPGA-based safety-critical systems</article-title>
          .
          <source>International Journal of Computing</source>
          ,
          <year>2020</year>
          .
          <volume>19</volume>
          (
          <issue>2</issue>
          ),
          <fpage>282</fpage>
          -
          <lpage>289</lpage>
          . https://doi.org/10.47839/ijc.19.2.1772.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Strigini</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          <article-title>Resilience: What is it, and how much do we want?</article-title>
          <source>In: IEEE Security &amp; Privacy</source>
          ,
          <year>2012</year>
          , No.
          <volume>10</volume>
          (
          <issue>3</issue>
          ), pp.
          <fpage>72</fpage>
          -
          <lpage>75</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Alexeev</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Henshel</surname>
            ,
            <given-names>D. S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Levitt</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>McDaniel</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rivera</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Templeton</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Weisman</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Constructing</surname>
          </string-name>
          <article-title>a science of cyber-resilience for military systems</article-title>
          .
          <source>In: NATO IST-153 Workshop on Cyber Resilience</source>
          ,
          <year>2017</year>
          , p.
          <fpage>13</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Leslie</surname>
            ,
            <given-names>N. O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Harang</surname>
            ,
            <given-names>R. E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Knachel</surname>
            ,
            <given-names>L. P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kott</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <article-title>Statistical models for the number of successful cyber intrusions</article-title>
          .
          <source>Defense Modeling and Simulation</source>
          ,
          <year>2017</year>
          , No.
          <volume>15</volume>
          (
          <issue>1</issue>
          ), pp.
          <fpage>49</fpage>
          -
          <lpage>63</lpage>
          . doi:
          <volume>10</volume>
          .1177/1548512917715342.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Bostick</surname>
            ,
            <given-names>T. P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Connelly</surname>
            ,
            <given-names>E. B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lambert</surname>
            ,
            <given-names>J. H.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Linkov</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          (
          <year>2018</year>
          ).
          <article-title>Resilience Science, Policy and Investment for Civil Infrastructure</article-title>
          .
          <source>Reliability Engineering &amp; System Safety</source>
          <volume>175</volume>
          :
          <fpage>19</fpage>
          -
          <lpage>23</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Colbert</surname>
            ,
            <given-names>E. J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kott</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Knachel</surname>
            <given-names>III</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            , &amp;
            <surname>Sullivan</surname>
          </string-name>
          ,
          <string-name>
            <surname>D. T.</surname>
          </string-name>
          (
          <year>2017</year>
          ).
          <source>Modeling Cyber Physical War Gaming (Technical Report No. ARL-TR-8079)</source>
          . US Army Research Laboratory, Aberdeen Proving Ground, United States.
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Roege</surname>
            ,
            <given-names>P. E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Collier</surname>
            ,
            <given-names>Z. A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chevardin</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chouinard</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Florin</surname>
            ,
            <given-names>M. V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lambert</surname>
            ,
            <given-names>J. H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nielsen</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nogal</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Todorovic</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          (
          <year>2017</year>
          ).
          <article-title>Bridging the gap from cyber security to resilience</article-title>
          . In I. Linkov &amp;
          <string-name>
            <surname>J. M.</surname>
          </string-name>
          Palma-Oliveira (Eds.),
          <article-title>Resilience and risk: Methods and application in environment, cyber, and social domains</article-title>
          (pp.
          <fpage>383</fpage>
          -
          <lpage>414</lpage>
          ). Dordrecht: Springer.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Roege</surname>
            ,
            <given-names>P. E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Collier</surname>
            ,
            <given-names>Z. A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chevardin</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chouinard</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Florin</surname>
            ,
            <given-names>M. V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lambert</surname>
            ,
            <given-names>J. H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nielsen</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nogal</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Todorovic</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          (
          <year>2017</year>
          ).
          <article-title>Bridging the gap from cyber security to resilience</article-title>
          . In I. Linkov &amp;
          <string-name>
            <surname>J. M.</surname>
          </string-name>
          Palma-Oliveira (Eds.),
          <article-title>Resilience and risk: Methods and application in environment, cyber, and social domains</article-title>
          (pp.
          <fpage>383</fpage>
          -
          <lpage>414</lpage>
          ). Dordrecht: Springer.
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Marchese</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Reynolds</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bates</surname>
            ,
            <given-names>M. E.</given-names>
          </string-name>
          , Morgan,
          <string-name>
            <given-names>H.</given-names>
            ,
            <surname>Clark</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. S.</given-names>
            , &amp;
            <surname>Linkov</surname>
          </string-name>
          ,
          <string-name>
            <surname>I.</surname>
          </string-name>
          (
          <year>2018</year>
          ).
          <article-title>Resilience and sustainability: Similarities and differences in environmental management applications</article-title>
          .
          <source>Science of the Total Environment</source>
          ,
          <volume>613</volume>
          ,
          <fpage>1275</fpage>
          -
          <lpage>1283</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>