<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Investigation of the Secure Paths Set Calculation Approach Based on Vulnerability Assessment</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Maryna Yevdokymenko</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oleksandra Yeremenko</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Anastasiia Shapovalova</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Maryna Shapoval</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Volodymyr Porokhniak</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Natalja Rogovaya</string-name>
          <email>nataljarogovaja35@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Poltava University of Economics and Trade</institution>
          ,
          <addr-line>3, Koval St., Poltava, 36000</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>An approach to the calculation of secure paths based on the routing model taking into account information security risks using the basic vulnerability criticality metrics is proposed and investigated. The approach for calculating route metrics uses obtained expressions, which characterize the information security risk in network links in the case of existing vulnerabilities. The results of the investigation showed that within the approach of calculating secure paths with increasing packet traffic, the paths in the network that contained links with the lowest weights, i.e. had the least weight of compromise, were loaded first. The transmission of the packet flow after overloading the more secure path was carried out in the following paths according to the values of the weights of the communication links. The paths in the network that contained the links with the highest weights were loaded last. Infocommunication network, secure path, information security risks, vulnerability, base score Today the task of information security of infocommunication networks (ICN) in conditions of increasing number of attacks and intrusions is relevant. This is due to the fact that the construction of secure networks in the constant development of infocommunication technologies and, consequently, the growing number of heterogeneous attacks is unfortunately not possible and requires constant implementation of protection mechanisms at all levels of the Open Systems Interconnection model (OSI). The “bottleneck” is the rapid response to emerging intrusions and minimizing the spread of network attacks and the resulting damages. The successful conduct of information security violations of ICN can be caused by many reasons: from the presence of vulnerabilities in the operating systems of network equipment to the incorrect hardware and software configurations when configuring protection mechanisms, and so on. In this regard, information on the network it is necessary to transmit along more secure paths.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Ukraine
EMAIL:
(M.</p>
      <p>Yevdokymenko);
oleksandra.yeremenko.ua@ieee.org
(O.</p>
      <p>Yeremenko);
(A.</p>
      <p>Shapovalova);
volodymyr.porokhniak@nure.ua</p>
      <p>2021 Copyright for this paper by its authors.







consideration of information about the state of ICN: network topology, flow characteristics, bandwidth
and network security indicators of elements (nodes and links).</p>
      <p>To address the shortcomings and corresponding further improvement protocols and secure routing
models formulated the following requirements:
taking into account the features of the structural and functional construction of the ICN;
support of the flow-based nature of various types of traffic;
taking into account the security parameters of both individual network elements and the ICN
as a whole;
vulnerabilities on network elements;
taking into account the information security risks based on existing and identified
redirect traffic to more secure paths;
support of recommended quality of service indicators;
acceptable computational complexity and scalability of final solutions for further protocol
implementations.</p>
      <p>Based on the above requirements, an urgent task arises to develop and investigate secure paths set
calculation approach based on a routing model. At the same time, the calculation of secure paths is
based on the methodology for assessing information risks through the criticality of vulnerabilities that
are present on network nodes.</p>
      <p>The method of assessing information security risks using basic metrics for criticality of network
node vulnerabilities was chosen because to assess the spread of an attack in the infocommunication
network it is necessary to understand the cause of the attack, as a result of exploiting an existing
vulnerability in the network, and possible damage.</p>
      <p>When analyzing the existing solutions [21-23] for vulnerability assessment and subsequent damage,
it was found that their main drawback is their narrow focus on certain network elements, individual
applications, services and resources. As a result, it is difficult to assess the risks in the network as a
whole. Based on this, the paper proposes to assess vulnerabilities at the level of network elements.
2. Secure Paths Set Calculation Approach Based on Vulnerability</p>
      <sec id="sec-1-1">
        <title>Assessment</title>
        <p>The proposed approach based on a routing model, in which the network structure is described by the
graph 
= ( ,  ), where</p>
        <p>= {  ;  = ̅1̅̅,̅̅̅} is a set of vertices simulated by routers and  =
{  , ;  ,  = ̅1̅̅,̅̅̅,  ≠  } the set of edges representing communication links in the ICN [24-27]. Then
each edges   , ∈  is matched to its bandwidth   , (1/s).</p>
        <p>Let a set of packet flows</p>
        <p>circulate in the ICN, which are generated by the respective network
applications. For each  th flow the following initial data are known:


 is the average intensity of  th flow, which is measured in packets per second (1/s);
 and   is the source and destination nodes of packets of the  th flow, respectively.</p>
        <p>Then the order of routing in the network is determined by route variables  
 , each of which
characterizes the portion of the  th flow in the link between the  th and  th nodes (routers) of the</p>
        <p>Based on the physical content of the used route variables, depending on the implemented routing
strategy, the conditions of the form are imposed on them.
network.
or</p>
        <p>
          , ∈ {0; 1}
0 ≤   , ≤ 1.
(
          <xref ref-type="bibr" rid="ref1">1</xref>
          )
(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )
        </p>
        <p>
          The introduction of condition (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) is responsible for the implementation of a single path routing
simultaneous use of single path solutions), in which variables   , can take the extreme of their possible
values – zero or one (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ).
        </p>
        <p>
          If conditions (
          <xref ref-type="bibr" rid="ref3">3</xref>
          ) are met, the absence of packet loss on each router and in the network as a whole is
guaranteed, and the connectivity of the calculated routes between the source and the destination nodes
of the packets of the  th flow is ensured.
        </p>
        <p>To prevent congestion of ICN communication links, the following conditions need to be met [28]:
∑    
 ∈</p>
        <p>, ≤   , ,   , ∈  .
of the network, which in physical terms is the probability of compromise.</p>
        <p>
          The number of conditions (
          <xref ref-type="bibr" rid="ref4">4</xref>
          ) corresponds to the number of communication links in the network.
        </p>
        <p>To assess information security risks, the following conventions are additionally introduced into the
model. 
the ICN, where 
node of the ICN; 
= {   ;  = ̅1̅,̅̅̅̅,  = ̅1̅̅,̅̅̅} is a set of vulnerabilities that are detected on the nodes (routers) of
 is the  th vulnerability on the  th node;   ∗ ∈  is the set of vulnerabilities on the  th</p>
        <p>is the criticality index of the  th vulnerability on the  th node, calculated using
the basic metrics of the vulnerability assessment system, which are presented in the recommendation
NIST CVSS v3.1 [28], and characterizes the contingent damages from the use of the vulnerability 
by the attacker;    is the probability of exploiting the  th vulnerability by an attacker on the  th node</p>
        <p>The Common Vulnerability Assessment System (CVSS) is widely accepted as the primary method
for assessing the criticality of software vulnerabilities. Because it is not possible to effectively manage
what cannot be measured as an industry standard, CVSS provides accurate measurements. The system
allows users to see the main characteristics of the vulnerability and quantitative models for the
formation of scores that were used in it. CVSS manages to assess vulnerabilities in terms of their
criticality. It consists of three metrics: basic, temporal and user environment [28].</p>
        <p>Each group consists of a set of indicators. Base score metrics determine the criticality of a
vulnerability. Thus, each of the vulnerability indicators must be evaluated against the vulnerable
component, and reflect the properties that lead to a successful attack.</p>
        <p>Then to calculate the information security risk based on exploiting of existing vulnerabilities on the
 th node of the ICN used the following expression:</p>
        <p>In addition, the flow conservation conditions are introduced for the routing variables:
∑
 :  , ∈</p>
        <p>, −
∑
 :  , ∈
∑</p>
        <p>, −
 
 , −</p>
        <p>∑
 :  , ∈</p>
        <p>∑
 :  , ∈
∑
 :  , ∈
{  :  , ∈
= 0;  ∈  ,   ≠   ,   ;
= 1;  ∈  ,   =   ;
= −1;  ∈  ,   =   .</p>
        <p>
          (
          <xref ref-type="bibr" rid="ref3">3</xref>
          )
(
          <xref ref-type="bibr" rid="ref4">4</xref>
          )
(
          <xref ref-type="bibr" rid="ref5">5</xref>
          )
(
          <xref ref-type="bibr" rid="ref6">6</xref>
          )
  =
∑    ∙   .
        </p>
        <p>+ 0,4 ∙   − 1,5) ⋅  (

 )

where 
of the network; 
0on a network node.</p>
        <p>is the potential damage from the use of the  th vulnerability by an attacker on the  th node
 is the complexity of exploiting the  th vulnerability by an attacker on the  th node
Thus, the potential damage from the use of the vulnerability is calculated as [28]:
  = 20 ∙   ∙ 
 ∙ 

 ,
vector);
requirements;
i.e.  (
(
(7)
(8)
(9)
(10)
where   is the indicators of vulnerability assessment, describing the complexity of access (access
  is the indicator of the vulnerability assessment system that is responsible for authentication
  is the indicator of the vulnerability assessment system, which reflects the method of exploiting the
 th vulnerability on the  th node, which is physically characterized by the "remoteness" of the attacker,
i.e. the number of devices and/or access restrictions through which the attacker can reach the  th node
in the ICN to attack.</p>
        <p>These indicators are the basic metrics [28], which characterize the overall complexity of the attack
in the use of a vulnerability on the  th node of the network.</p>
        <p>≠ 0). That is, in further calculations it is used 
 = 1.176.</p>
        <p>The potential damage function  (

 ) according to [28] takes the value 0, if there is no damage,

 ) = 0. In this case, the scenario where the potential damage is present will be considered
Then to quantify the worst case scenario, the information security risk in case of compromise of the
link   , ∈  leaving the  th node, characterizes the following expression of exponential nature [28]:

 = 10,41[1 − (1 − 

 ) ∙ (1 − 
 ) ⋅ (1 −   )],

vulnerability on the  th node of ICN.
where</p>
        <p>is the damage from violation of confidentiality of information transmitted by the network
destruction of information by an unauthorized user (attacker) in the ICN;
and cannot be obtained by an unauthorized, for example, external, user (attacker);</p>
        <p>is the damage from violation of network integrity, characterized by modification, change and
  is the damage from violation of network resource availability in case of exploiting the  th
The values of these metrics presented in the recommendation NIST CVSS v.3 [28].
The complexity of exploiting the vulnerability is calculated using the following expression:
  , =   , ∙ ln</p>
        <p>∑   

∑    ∙</p>
        <p>=   , ∙ ln

where   , is the weights (weight of compromise), which are used to assess the risk posed by the use of
vulnerabilities on the  th node of the network. In fact, the weights   , quantitatively characterize the
potential damage in the case of exploiting the existing vulnerabilities on the  th node of the network.</p>
        <p>Note that in the case when the compromise of the link   , ∈ 
occurs only due to the use of
vulnerabilities on the  th node, then the information security risks of the node and the link are identically
equal, i.e.</p>
        <p>The calculation of the weights   , is based on the assumption that the communication link   , ∈ 
will be compromised due to the compromise of the  th node, i.e. by exploiting the existing
vulnerabilities on this node.</p>
        <p>In this case, the probability of compromising the  th node depends on the presence and exploiting
of vulnerabilities on it and is calculated as an information security risk.</p>
        <p>
          Considering (
          <xref ref-type="bibr" rid="ref5">5</xref>
          )–(10), the value of each of the weights   , can be calculated using the following
expression:
        </p>
        <p>To calculate secure paths, the following linear optimality criterion was chosen [29]:
  , =
∑ ∈ ∗</p>
        <p>ln ∑  ∈ ∗ 

 ∙</p>
        <p>∈   , ∈
 
 , ⇒ 
,
(11)
(12)
where weights   , are route metrics that have to take into account the basic security characteristics of
links.
3. Investigation of the Secure Paths Set Calculation Approach</p>
      </sec>
      <sec id="sec-1-2">
        <title>Based on Vulnerability Assessment</title>
        <p>The investigation of the proposed approach flow model of secure routing for confirmation of its
efficiency and adequacy of the received results of calculation is carried out. Within the calculation
example, the structure of the infocommunication network shown in Fig. 1.</p>
        <p>R1
310
100
220</p>
        <p>R6</p>
        <p>R2
250
270
200</p>
        <p>R4
R5</p>
        <p>R3
320
250
i.e.  = 1, when the source node of packets was a router  1, and the destination node is a router  6.</p>
        <p>The intensity of the packet flow varied from 0 to 710 1/s. The breaks in the communication links
(Fig. 1) show their bandwidth (1/s).
shown in table 1.</p>
        <p>
          Expression (11) was used together with expressions (
          <xref ref-type="bibr" rid="ref5">5</xref>
          ) – (10) to calculate the weights   , (  , ∈
the basic metrics of the vulnerability assessment system, was determined for different routers with the
corresponding probability of exploiting this  th vulnerability on the  th node of the network   , as
        </p>
        <p>In table 1 each node (router) of the network had a special description of the existing vulnerability
according to the database of well-known vulnerabilities of information security CVE. This CVE
database is designed to collect, store and disseminate information about identified vulnerabilities. Each
vulnerability is provided with an identification number, a description, and a number of publicly
available descriptive links.</p>
        <p>For example, the first node  1, which is the Cisco RV042 router, is characterized by vulnerability
CVE-2020-3294. In this case, CVE-2020-3294 is a unique number that describes a vulnerability in the
Cisco RV042 router management web interface. Exploiting this vulnerability allows an authenticated
remote attacker with administrative privileges to execute arbitrary code on the affected device and send
large requests to the damaged device, causing the stack to overflow.</p>
        <p>
          To assess the effectiveness, a comparative analysis of the proposed approach (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) – (12) (model 1),
with the flow model, based on the metrics of the EIGRP protocol (model 2). The results of solving the
routing problem using the developed model 1 and model 2 are given in table 2 and in fig. 2 and fig. 3,
respectively, on which the communication links with the highest critical weights are indicated in red.
The results of comparative analysis of model 1 and model 2 (with intensity 450 1/s)
Link
 1,2
 1,4
 1,5
 2,3
 2,4
 3,6
 4,6
 5,6
        </p>
        <p>Bandwidth
  , (1/s)
310
250
270
200
100
220
300
intensity,
1/s
200
250
0
0
200
200
250
R3
300
----250
---0,29
250
----250
---0,09</p>
        <p>R2</p>
        <p>As shown in Fig. 2, due to the solution of the route problem using the proposed model (model 1), the
total weight (weight of compromise) of routes in the network was as follows, as shown in table 3.
The weight of path compromise depends on the criticality of nodes and communication links</p>
        <sec id="sec-1-2-1">
          <title>Paths</title>
          <p>R1R4R6</p>
          <p>R1R5R6
R1R2R3R6</p>
        </sec>
        <sec id="sec-1-2-2">
          <title>The total weight of compromise relative to the</title>
          <p>critical vulnerabilities of network nodes
0.38
0.78
0.57</p>
          <p>In general, the results of the use of paths in the ICN for different packet flow intensities when using
models 1 and 2 are given in table 4.</p>
          <p>As shown in Fig. 2, as a result of solving the route problem using the proposed approach (model 1),
the packet flow with an intensity of 250 1/s was transmitted by the route R1R4R6, which contained
the least vulnerable communication links. During the congestion of this route, the rest of the flow was
transmitted in the following vulnerable paths: R1R2R3R6 (150 1/s) and R1R2R4R6 (50 1/s).</p>
          <p>At the same time, it should be noted that the path R1R5R6, which contained the most
weightvulnerable communication links at an intensity of 450 1/s, was not used at all.</p>
          <p>Unlike model 1, when using model 2, the best in terms of bandwidth, number of interceptions (hops)
and in this case the least vulnerable path R1R5R6 was loaded first (up to 260 1/s inclusive). As a result,
the most vulnerable path R1R5R6, the links of which had the best bandwidth, transmitted the packet
flow with higher intensity and amounted to 230 1/s, compared to other paths.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>4. Conclusion</title>
      <p>
        An approach to the calculation of secure paths based on the routing model taking into account
information security risks using the basic vulnerability criticality metrics is proposed and investigated.
The approach is based on a routing model (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) – (12). The model is based on the conditions of
implementation of single- and multipath routing (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ), (
        <xref ref-type="bibr" rid="ref2">2</xref>
        ), flow conservation (
        <xref ref-type="bibr" rid="ref3">3</xref>
        ) and prevention of
congestion of communication links of the ICN (
        <xref ref-type="bibr" rid="ref4">4</xref>
        ). Within the proposed approach, the problem of secure
routing is formulated in an optimization form with the criterion of optimality (
        <xref ref-type="bibr" rid="ref5">5</xref>
        ).
      </p>
      <p>In the process of describing the proposed approach, the apparatus of operations research and set
theory was used. Graph theory was used to describe the topology of infocommunication networks. In
order to form route metrics during the organization of secure routing, elements of risk theory were used.
Linear programming methods implemented in the MATLAB Optimization Toolbox were used to solve
secure routing optimization problems.</p>
      <p>The validity and reliability of the proposed approach was confirmed by the results of analytical
modeling and the correct use of mathematical apparatus. The adequacy of the obtained solutions was
confirmed by the correctness of the choice of initial data in accordance with the NIST recommendations.</p>
      <p>The advantage of the approach is that the calculation of route metrics uses expressions (12), which
characterize the risk of information security in ICN communication links and in accordance with the
recommendations of NIST CVSS v.3 take into account losses from breach of confidentiality and
integrity of information. case of use of existing vulnerabilities; take into account indicators of the
complexity of the application of vulnerabilities at network nodes and access to network elements in
particular and the network in general due to the use of these vulnerabilities.</p>
      <p>The paper compares the proposed approach and model with the metrics of the EIGRP protocol. The
results of the study showed that within the approach of calculating secure paths with increasing packet
traffic, the paths in the network that contained communication links with the lowest weights, i.e. had
the least weight of compromise, were loaded first. The transmission of the packet flow after overloading
the more secure path was carried out in the following paths according to the values of the weights of
the communication links. The paths in the network that contained the communication links with the
highest weights were loaded last.</p>
      <p>In contrast to the proposed approach, paths within the EIGRP multipath routing model were loaded
according to their bandwidth and number of hops, without taking into account the risks of information
security in general.</p>
      <p>It should be noted that for the worst case scenario in the process of exploiting the vulnerability at
the network node, i.e. under the condition of 100% compromise of the communication link with the
highest weight, the gain compared to traditional models in the area of low loads ICN was 37%, in the
area of medium loads - 25 % and gradually decreased.</p>
      <p>The practical value of the proposed result is that the proposed approach can be the basis of
mathematical and algorithmic support of promising secure routing protocols in both traditional
infocommunication and software-defined networks. Prospects for the development of the obtained
solutions should be recognized as a synthesis of models and methods of secure routing that can
guarantee a given level of network security based on the calculation and use of appropriate routes in
ICN. The proposed approach to the formation of route metrics can be applied comprehensively in the
process of solving routing problems of both network security indicators and service quality indicators.</p>
    </sec>
    <sec id="sec-3">
      <title>5. References</title>
      <p>[7] A. A. Sagare, R. Khondoker, Security Analysis of SDN Routing Applications, SDN and NFV
Security, Lecture Notes in Networks and Systems, Springer, Cham, Vol. 30. 2018. P.1–17.
doi: 10.1007/978-3-319-71761-6_1
[8] S. Pattanavichai, Comparison for network security scanner tools between GFI LanGuard and
Microsoft Baseline Security Analyzer (MBSA), International Conference on ICT and Knowledge
Engineering (ICT&amp;KE): Proceedings of the 15th, International Conference, Bangkok, 2017. P. 1–
7. doi: 10.1109/ICTKE.2017.8259628.
[9] J. Li, Z. Yang, X. Yi, T. Hong, X. Wang, A Secure Routing Mechanism for Industrial Wireless
Networks Based on SDN, International Conference on Mobile Ad-Hoc and Sensor Networks
(MSN): Proceedings of the 14th International Conference, China, 2018. P. 158–164.
doi: 10.1109/MSN.2018.000-2.
[10] M. Wang, J. Liu, J. Mao, H. Cheng, J. Chen, C. Qi, Route Guardian: Constructing secure routing
paths in software-defined networking, Tsinghua Science and Technology, Vol. 22. 2017. No. 4. P.
400–412. doi: 10.23919/TST.2017.7986943.
[11] A. Snihurov, V. Chakrian, Improvement of EIGRP Protocol Routing Algorithm Based on
Information Security Metrics. International Scientific-Practical Conference Problems of
Infocommunications Science and Technology (PIC S&amp;T-2015): Proceedings of the Second
International Conference, Kharkiv, 2015. P. 263–265.
doi: 10.1109/INFOCOMMST.2015.7357331.
[12] O. Lemeshko, M. Yevdokymenko, O. Yeremenko, T. Radivilova, D. Ageyev, N. Kryvinska, Fast
ReRoute Tensor Model with Quality of Service Protection Under Multiple Parameters,
DataCentric Business and Applications. Lecture Notes on Data Engineering and Communications
Technologies, Springer, Cham, 2020. No. 48. P. 489–512. doi:10.1007/978-3-030-43070-2_22.
[13] Q. Gu, H.C.A. Tilborg, S. Jajodia, Secure Routing Protocols, Encyclopedia of Cryptography and</p>
      <p>Security, Springer, Boston, MA, 2011. doi: 10.1007/978-1-4419-5906-5_641.
[14] W. Lou, W. Liu, Y. Fang, SPREAD: enhancing data confidentiality in mobile ad hoc networks,
IEEE Computer and Communications Societies (INFOCOM): Proceedings of the International
Conference, Hong Kong, China, 2004. No. 4. P. 2404–2413.
doi: 10.1109/INFCOM.2004.1354662.
[15] A. Aggarwal, S. Gandhi, N. Chaubey, Trust Based Secure on Demand Routing Protocol (TSDRP)
for MANETs, International Conference on Advanced Computing &amp; Communication Technologies
(ACCT): Proceedings of the Fourth International Conference, Rohtak, India, 2014. P. 432–438.
doi: 10.1109/ACCT.2014.95.
[16] R. Shashikala, C. Kavitha, Secured data integrity routing for Wireless Sensor
Networks, International Conference on Advances in Electronics Computers and Communications
(ICAECC): Proceedings of the International Conference, Bangalore, India, 2014. P. 1–6.
doi: 10.1109/ICAECC.2014.7002419.
[17] G. K. Wadhwani, S. K. Khatri, S. K. Muttoo, Critical Evaluation of Secure Routing Protocols for
MANET, International Conference on Advances in Computing, Communication Control and
Networking (ICACCCN): Proceedings of the International Conference, Greater Noida, India, 2018.</p>
      <p>
        P. 202–206. doi: 10.1109/ICACCCN.2018.8748725.
[18] J. Govindasamy, S. Punniakody, A comparative study of reactive, proactive and hybrid routing
protocol in wireless sensor network under wormhole attack. Electrical Systems and Information
Technology, 2018. No. l 5(
        <xref ref-type="bibr" rid="ref3">3</xref>
        ). P. 735–744. doi: 10.1016/j.jesit.2017.02.002.
[19] D. Medhi, K. Ramasamy, Network Routing, Second Edition: Algorithms, Protocols, and
Architectures. The Morgan Kaufmann Series in Networking, 2nd Edition, Cambridge, MA, USA,
Elsevier Inc. 2018.
[20] K. Sinchana, C. Sinchana, H. L. Gururaj, B. R. Sunil Kumar, Performance Evaluation and
Analysis of various Network Security tools, International Conference on Communication and
Electronics Systems (ICCES): Proceedings of the International Conference, Coimbatore, India,
2019. P. 644–650. doi: 10.1109/ICCES45898.2019.9002531.
[21] W. Streilein, K. Kratkiewicz, M. Sikorski, K. Piwowarski, S. Webster, PANEMOTO: Network
Visualization of Security Situational Awareness Through Passive Analysis, SMC Information
Assurance and Security Workshop (IAW): Proceedings of Security Workshop, West Point, NY,
USA, 2007. P. 284–290. doi: 10.1109/IAW.2007.381945.
[22] J. Li, M. Huo and S. Chao, "A Study of Information Security Evaluation and Risk
Assessment," 2015 Fifth International Conference on Instrumentation and Measurement,
Computer, Communication and Control (IMCCC), 2015, pp. 1909-1912,
doi: 10.1109/IMCCC.2015.405.
[23] A. Hamed and H. K. Ben Ayed, "Privacy risk assessment for Web tracking: A user-oriented
approach toward privacy risk assessment for Web tracking," 2016 IEEE Canadian Conference on
Electrical and Computer Engineering (CCECE), 2016, pp. 1-6,
doi: 10.1109/CCECE.2016.7726741.
[24] E. Mauro, "Best Practice and Common Practice in Risk Assessment," 2019 Petroleum and
Chemical Industry Conference Europe (PCIC EUROPE), 2019, pp. 1-11,
doi: 10.23919/PCICEurope46863.2019.9011636.
[25] ISO/IEC 15408-1:2009. Information technology, Security techniques Evaluation criteria for
IT security, Part 1: Introduction and general model. URL:
https://www.iso.org/standard/50341.html.
[26] Abedin M., Nessa S., Al-Shaer E., Khan L. Vulnerability analysis For evaluating quality of
protection of security policies. Quality of Protection (QoP): Proceedings of the 2nd ACM
Workshop, 2006. P. 49–52. doi: 10.1145/1179494.1179505.
[27] O. Lemeshko, M. Yevdokymenko, O. Yeremenko, A. Shapovalova, Z. Hu, S. Petoukhov, I.
      </p>
      <p>Dychka, M. He, Investigation of Load-Balancing Fast ReRouting Model with Providing Fair
Priority-Based Traffic Policing. Advances in Computer Science for Engineering and Education III.
ICCSEEA 2020. Advances in Intelligent Systems and Computing. Springer, Cham. Vol. 1247.
2020. P. 108–119. doi: 10.1007/978-3-030-55506-1_10.
[28] K. Scarfone, K. Scarfone, P. Mell, NIST Special Publication 800-94 Revision 1 (Draft) Guide
to intrusion detection and prevention systems (IDPS)., National Institute of Standards and
Technology, 2012. URL: http://csrc.nist.gov/publications/drafts/800-94-
rev1/draft_sp80094-rev1.pdf.
[29] R. Roehrkasse, "Linear programming in operations research," in IEEE Potentials, vol. 9, no. 4, pp.
39-40, Dec. 1990, doi: 10.1109/45.65868.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>C.</given-names>
            <surname>Chapman</surname>
          </string-name>
          ,
          <article-title>Network Performance and Security (Testing and Analyzing Using Open Source and Low-Cost Tools), 1st edition</article-title>
          , Syngress,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>T.</given-names>
            <surname>Edgar</surname>
          </string-name>
          , D. Manz,
          <article-title>Research Methods for Cyber Security, 1st edition</article-title>
          . Syngress,
          <year>2017</year>
          . 428 p
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>O.</given-names>
            <surname>Yeremenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Lemeshko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Persikov</surname>
          </string-name>
          ,
          <article-title>Secure Routing in Reliable Networks: Proactive and Reactive Approach, Advances in Intelligent Systems</article-title>
          and
          <string-name>
            <surname>Computing</surname>
            <given-names>II</given-names>
          </string-name>
          ,
          <source>CSIT 2017, Advances in Intelligent Systems and Computing</source>
          , Springer, Cham. Vol.
          <volume>689</volume>
          .
          <year>2018</year>
          . P.
          <volume>631</volume>
          -
          <fpage>655</fpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -70581-1_
          <fpage>44</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>M.</given-names>
            <surname>Yevdokymenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Manasse</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Zalushniy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Sleiman</surname>
          </string-name>
          ,
          <article-title>Analysis of Methods for Assessing the Reliability and Security of Infocommunication Network, Problems of Infocommunications Science</article-title>
          and
          <string-name>
            <surname>Technology (PIC S&amp;T)</surname>
          </string-name>
          :
          <source>Proceedings of the Fourth International Scientific-Practical Conference</source>
          , Kharkov, Ukraine,
          <fpage>10</fpage>
          -
          <lpage>13</lpage>
          October,
          <year>2017</year>
          . P.
          <volume>199</volume>
          -
          <fpage>202</fpage>
          . doi:
          <volume>10</volume>
          .1109/INFOCOMMST.
          <year>2017</year>
          .
          <volume>8246379</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>М.</given-names>
            <surname>Yevdokymenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Shapovalova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Voloshchuk</surname>
          </string-name>
          ,
          <string-name>
            <surname>A. Carlsson,</surname>
          </string-name>
          <article-title>Proactive Approach for Security of the Infocommunication Network Based on Vulnerability Assessment. Problems of Infocommunications Science</article-title>
          and
          <string-name>
            <surname>Technology (PIC S&amp;T)</surname>
          </string-name>
          :
          <source>Proceedings of the Fifth International Scientific-Practical Conference, Kharkov, Ukraine</source>
          ,
          <fpage>9</fpage>
          -
          <issue>12</issue>
          <year>October 2018</year>
          . P.
          <volume>609</volume>
          -
          <fpage>612</fpage>
          . doi:
          <volume>10</volume>
          .1109/INFOCOMMST.
          <year>2018</year>
          .
          <volume>8632079</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>O.</given-names>
            <surname>Lemeshko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Yeremenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Yevdokymenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Shapovalova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. M.</given-names>
            <surname>Hailan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Mersni</surname>
          </string-name>
          ,
          <article-title>Cyber Resilience Approach Based on Traffic Engineering Fast ReRoute with Policing</article-title>
          .
          <source>Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications (IDAACS): Proceedings of the 10th IEEE International Conference</source>
          , Metz, France,
          <year>2019</year>
          . P.
          <volume>117</volume>
          -
          <fpage>122</fpage>
          . doi:
          <volume>10</volume>
          .1109/IDAACS.
          <year>2019</year>
          .
          <volume>8924294</volume>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>