<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Managing the Security of the Critical Infrastructure Information Network</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Serhii Toliupa</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Anatolii Shevchenko</string-name>
          <email>tolyamixailshevchenko75@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Serhii Buchyk</string-name>
          <email>buchyk@knu.ua</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Ihor Pampukha</string-name>
          <email>pamp@ukr.net</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andrii Kulko</string-name>
          <email>kulko.andrii@gmail.com</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Military Institute of Taras Shevchenko National University of Kyiv</institution>
          ,
          <addr-line>60 Volodymyrska str., Kyiv, 01033</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Taras Shevchenko National University of Kyiv</institution>
          ,
          <addr-line>60 Volodymyrska str., Kyiv, 01033</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>131</fpage>
      <lpage>142</lpage>
      <abstract>
        <p>Critical infrastructure has a multi-level structure, encompassing technical components, social aspects, organizational elements, and government involvement, all interconnected through a distributed information system that demands protection. The development and implementation of cutting-edge information technologies have created unprecedented conditions for the gathering and utilization of data, resulting in a fundamental reliance on their uninterrupted operation across various sectors of society and the state, including the economy, politics, national security, and international affairs. This dependence also exposes vulnerabilities in the functionality of critical national infrastructure systems, enabling adversarial entities and groups to exploit it for illegal activities in cyberspace. They do so by compromising the integrity, availability, and confidentiality of information, thereby inflicting damage upon information resources and systems. This article proposes a method for managing information system security based on internal cyberattacks. The method relies on modifications to the support vector method, utilizing parameters typical for internal cyberattacks on information systems. Its primary objective is to identify the input parameters of internal cyberattacks and enhance the reliability of decision-making in assessing the state of IP security, all within the timeframe comparable to existing methods. The mathematical framework employed in this method reduces the volume of input data required for managing information system security while bolstering the reliability of decision-making in evaluating the security status of critical infrastructure's information resources.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Сybersecurity</kwd>
        <kwd>critical infrastructure</kwd>
        <kwd>threat</kwd>
        <kwd>cyberspace</kwd>
        <kwd>information resource</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Many countries are implementing the concept
of critical infrastructure, allowing them to
focus on systems, networks, and individual
facilities that could have profound adverse
effects on national security if destroyed or
disrupted [1–3]. The rapid development of
information and communication technologies
over the past two decades has significantly
impacted the operation of critical
infrastructure facilities. These technologies
are no longer just tools for exchanging and
processing information; they have become
instruments for causing harm. Critical
infrastructure comprises multiple levels,
including technical components (equipment
and devices), the social level (personnel
responsible for maintaining technical
components), the organizational level
(interaction among the services operating
critical infrastructure), and the level of state
administration (regulatory and supervisory
bodies overseeing critical infrastructure).
These levels are all interconnected through a
distributed information system that requires
protection. The complexity of critical
infrastructures arises from the intricate
structure intricate interdependencies and
nonlinear relationships among components
and levels of the system [4–6].</p>
      <p>The development and implementation of
cutting-edge information technologies have
created unprecedented conditions for data
accumulation and utilization, leading to
fundamental dependence on their continuous
operation across various aspects of society and
the state, such as the economy, politics, and
national and international security. This
dependence exposes vulnerabilities in the
functioning of critical national infrastructures,
enabling adversarial entities and groups to
exploit them for illegal activities in cyberspace
by compromising the integrity, availability,
and confidentiality of information, resulting in
damage to information resources and systems.
Furthermore, the potential use of information
technologies in cyberspace for
militarypolitical power struggles, terrorism, and
hacker attacks is a significant concern,
especially in times of martial law [7].</p>
    </sec>
    <sec id="sec-2">
      <title>2. Issues</title>
      <p>The existence of close interconnections
between critical infrastructure components is
a fundamentally important feature that has a
decisive impact on the nature of their
functioning in regular and emergencies. On the
one hand, the interconnection of the CI
elements increases their efficiency and
survivability, allowing the rational use and
redistribution of available resources and
capacities, and on the other hand, it makes
them vulnerable to a large-scale disaster, the
huge amount of damage that cannot be
ignored regardless of the low probability of
the risks. The analysis of modern hybrid
warfare in the world and cyber operations
shows the evolution of forms, methods, and
techniques used to conduct cyberattacks on
critical infrastructure management systems.
Studies have shown that for the effective
functioning of the information system, it is
advisable to use an appropriate security
subsystem as part of the IP management
system with the ability to assess and manage
the security status of the information system
in real-time and in conditions of the constantly
changing character of cyberattacks [8].</p>
      <p>The critical infrastructure information
system possesses distinct features, including
varying network dimensions, geographically
scattered information system components,
and elements that extend beyond controlled
areas. These features make it suitable for
facilitating rapid interaction among
geographically dispersed critical
infrastructure units. However, they also
render it vulnerable to exploitation by
intruders who can conduct cyberattacks,
causing destructive actions against the system
and the management of critical infrastructure
information resources in general. The
operation of the information system in
cyberspace is influenced by a range of factors,
encompassing natural, human-made, and
anthropogenic elements that disrupt the
information transfer process. Nevertheless,
the most significant harm to the information
system can result from deliberate attacks that
exploit current security weaknesses. These
attacks can occur at various levels of the basic
reference model for open system interaction
[9–10].</p>
      <p>Hence, one of the most critical challenges in
operating the critical infrastructure
information system is ensuring the security of
information, software, and hardware. To
effectively manage the security of information
resources, it is imperative to utilize specialized
equipment, algorithms, and methods that
guarantee the secure operation of nodes,
components, and the entire information
system.</p>
      <p>The existing methods of managing the state
of the information system security do not take
into account the peculiarities of cyberattacks
by internal and external intruders and also
have low reliability in making a management
decision on assessing the state of the
information system security and
implementing security measures. At the same
time, the main requirements for the methods
of managing the state of the information
resources security in an information system
are real-time operation; consideration of
threats characteristic of information and
telecommunication systems; adaptive
functioning of the information security system
with self-organization; decentralization of
management and hierarchical distribution
structure; increase in the reliability and
completeness of management
decisionmaking; reduction of mathematical complexity
and resource burden of methods; flexibility of
the mathematical apparatus; application of
special samples on the state of the information
system security; possibility of application in
systems with high dynamics of topology
change; decentralisation of management and
availability of a hierarchical distribution
structure; minimum network load with service
information [11].</p>
      <p>As a result, today there is a discrepancy
between the above capabilities of the existing
methods of managing the state of the
information resources security and the
requirements for methods of managing the
state of the information resources security in
the information system, to solve this scientific
task, namely: development of methods of
managing the state of the IP security against
external and internal cyber-attacks on the
information system using identification
methods, dynamic programming and support
vectors.</p>
      <p>Due to the complex structure of the critical
infrastructure facilities and the complex
nature of the interactions between a significant
number of elements, the possibilities of
conducting scenario analysis using traditional
tools (event trees, fault trees, Bayesian
networks, neural networks) are limited [11].
To describe the development of disruptions in
critical infrastructure, network models are
applied, which extensively use the
mathematical tool of graph theory. Networks
are an extremely flexible notion that can be
widely used in the study of infrastructure
systems. In this case, a hierarchy of
mathematical models of varying complexity
can be built to describe various aspects of
infrastructure system risks about potentially
initiating impacts. With the help of these
models, it is possible to describe many
properties and characteristics of network
systems: chaos, self-organization, statistical
distributions, and criticality.
3. Quantum Authentication
The peculiarity of modern critical
infrastructures is that they are becoming
cross-border and, in some cases, global. The
spatial dimension of critical infrastructures,
along with the existence of close
interconnections between them, makes their
functioning dependent on a huge number of
factors related to the state of the natural,
technogenic, and social environment in
different regions of the world. A significant
amount of hazardous substances, energy, and
information stored, transported, and
processed by critical infrastructures, as well as
their huge role in the economy and human life,
determine the possibility of large-scale
accidents at critical infrastructures and the
severity of the consequences arising from such
accidents for the population and economic
facilities. The complexity of critical
infrastructures significantly impedes the
creation of effective protection systems, as it
becomes almost impossible to conduct a
detailed scenario analysis of the system,
identify all major hazard scenarios, and
determine a set of protection measures and
barriers aimed at parrying all possible threats
[12].</p>
      <p>At the same time, an analysis of the current
practice in the field of critical infrastructure
functioning shows that their design,
construction, and operation are carried out by
the traditional paradigm of ensuring the
security of technical systems (technical
services) and information security systems.
This paradigm includes: analyzing possible
failure scenarios in the system; identifying the
most critical scenarios; and creating
protective barriers to prevent these scenarios.</p>
      <p>It should be noted that efforts to protect
critical infrastructure facilities are
traditionally focused on technical aspects. In
virtue of that significant progress has been
made in ensuring the reliability of technical
components of critical infrastructure.
However, the capabilities of this approach are
close to being exhausted. This is because
critical infrastructures can no longer be
considered as predominantly technical
systems, but are becoming more and more
techno-social systems.</p>
      <p>Due to the rapid development of
information technology in recent decades,
critical infrastructure facilities are becoming
more complex. Thus, there are a lot of factors
to consider when assessing the security of
critical infrastructure, and some operating
modes of critical infrastructure are fully
applied. The reason for this is the complex
nonlinear interactions between critical
infrastructure components, the strong degree
of interconnectedness between different
subsystems, and the fact that critical
infrastructure and the environment are
beginning to change faster than they can be
described and studied. This creates a situation
where there is a lack of information about
critical infrastructures and, as a result, limited
opportunities to predict their performance
and manage them. At the same time, in certain
modes, it is impossible to describe in detail the
principles of critical infrastructure functioning
and develop management rules [13].</p>
      <p>The distinction between fully determined
and underdetermined systems becomes
extremely important in developing a set of
security measures. The peculiarity of
underdetermined systems is that it is
impossible to fully describe their performance
and predict their state under different
conditions and in different operating modes.
As a result, for complex systems such as
critical infrastructures, it is almost impossible
to create a closed list of projected impacts to
which the system may be exposed during its
operation. In this regard, the traditional
strategy of ensuring critical infrastructure
security, based on the development of a set of
protective barriers designed to shut back
projected impacts, cannot be successful [14].</p>
      <p>In our case, we consider the situation of an
equiprobability of the system being in a state
of security breaches of the Information System
(IS) of critical infrastructure. At the same time,
there are both security breaches from internal
cyberattacks on the information resource of
critical infrastructure, the protection of which
is required by law, in the information system,
and the search for countermeasures to detect
changes in the state of security. To simulate
this situation, a training sample is created that
contains 20% of normal messages and 80% of
anomalous messages with the types of attacks.
A base with response options for a variety of
detected breaches is also being built.</p>
      <p>The input data are: X = XH  XM  XL —
parameters of inbound traffic;</p>
      <p>XM = {xm (t), m = 1, 18} is a set of traffic
parameters that are specific to external
cyberattacks;</p>
      <p>XH = {xh (t), h = 1, 15} is a set of traffic
parameters that are specific to internal
cyberattacks;</p>
      <p>XL is a set of traffic parameters that are not
used in the implementation of a method;
S (t), s = 1,10
are
parameters
of
cybersecurity sensors;</p>
      <p>XV = {XH  S (t)} is input data specific to
internal cyberattacks.</p>
      <p>Limitations and assumptions: Attack types
are identified: DoS, U2R, R2L, Probe, and Side.
To identify the behavior, the attack signatures
that are threats to the information system are
considered. Abnormal behavior is identified as
a newly detected security status. The process
of managing the security status is
quasistationary on a time frame (t0...Т ) .</p>
      <p>It is required: to increase the reliability of
management decision-making regarding the
assessment of the security status of the critical
infrastructure information resource, the
requirement to protect which is established by
law from external cyberattacks, if the time for
management decision-making will not exceed
that of similar methods.</p>
      <p>The principle of the method is to distribute
control of the security status of the information
system based on a set of input parameters
specific to internal cyberattacks and a set of
parameters of cybersecurity sensors using the
description of the information system and the
support vector machines.</p>
      <p>Support Vector Machine (SVM) is a set of
similar algorithms of the “supervised learning”
models used in analyzing data for classification
and regression analysis. This method belongs
to a family of linear classifiers. A peculiarity of
the support vector machine is a continuous
minimization of the empirical classification
error and maximizing the width of the gap
between the classes. Hence, this method is
often called the maximum margin classifier
[15].</p>
      <p>The method searches for elements located
on the boundaries between two classes, which
are called support vectors.
The support vector machine searches for a
linear function that enables to assignment of
the elements of a dataset to one of two classes.
The task of binary classification can be defined
as the search for a linear function f(x) that
takes a value less than zero for elements of one
class and greater than zero for elements of
another [16].</p>
      <p>The separating hyperplane has the
following form:</p>
      <p>
        f (x) =  x − b = 0 , (
        <xref ref-type="bibr" rid="ref1">1</xref>
        )
where w is a vector perpendicular to the
separating hyperplane, the parameter b
determines the distance of the hyperplane
from the origin.
      </p>
      <p>The hyperplane parallel to the optimal
hyperplane and closest to the support vectors
of the two classes can be defined by the
following equations:
 x − b = 1
 x − b = −1</p>
      <p>If the training data is linearly inseparable,
then we can select hyperplanes to prevent data
points from falling into the margin between
them and then maximize the distance between
the hyperplanes. In this case, the distance
(2)
between the planes is
2 , so we should

minimize it  . To exclude all points from the
line, the following conditions must be satisfied
[11]:
ci ( xi − b)  1, 1In,
(3)
where сі is a class label that takes a value –1
and +1, and xi is a sample vector with class label
сі.</p>
      <p>This quadratic optimization problem is
equivalent to the problem of finding the saddle
point of the Lagrange function [12]:</p>
      <p>n  + 1
−L( ) = i=1 i 2 in=1i jcicj (xi xj ) → min
(4)
i  0,1  i  n
in=1ici = 0
where L is the Lagrange function, λ are
Lagrange multipliers.</p>
      <p>To generalize the SVM to the case of linear
inseparability, the constant C is introduced—
an internal parameter of the method that
allows you to adjust the ratio between
maximizing the width of the separation band
and minimizing the total error.</p>
      <p>The main problem of using the support vector
method in a binary classification task is the
difficulty of finding a linear boundary between
two classes. If it is not able to construct such a
boundary, one solution is to increase the
dimensionality (transferring data to another
space of higher dimensionality), where it is
possible to construct a plane that divides the set
of elements into two classes [17].</p>
      <p>Thus, the problem of timely detection of
changes in the state of information security of
the critical infrastructure and information
system’s object is solved by managing the state
of information system security based on a set
of parameters of internal attacks in the
conditions of limited samples of current
observation data.</p>
      <p>Management of the state of protection of the
information system of critical infrastructure
facilities against internal cyberattacks occurs
in the case of identification of the parameters
of violations that are realized by a set of
multidirectional and different attacks.</p>
      <p>Identify the input data (data parameters) of
the traffic.</p>
      <p>I. By identification, we mean finding a model
that is optimal in some sense, based on the
results of observations of the input and output
variables of the object, namely, a set of traffic
parameters. Identification is the reverse task of
system synthesis.</p>
      <p>Parametric identification will be used to
identify input data based on parameters that
are typical of internal cyberattacks.</p>
      <p>In parametric identification, data about a
critical infrastructure facility is processed to
obtain posterior information about it. The
parameters of the selected model are estimated.
In the simplest cases, such an assessment can be
performed using a transient response graph.</p>
      <p>The task of parametric identification can be
formulated as follows: to select such values X
on the set of {X } possible parameter values so
that the differences of the indicators reach their
minimums, i.e. the purpose of this analysis is to
search:</p>
      <p>18
X (t) = arg min  ( yi (t) − xi (t))2
yXˆ i=1
(5)
where Xˆ is traffic parameters described in the
database; xi (t) is parameters that describe the
flow of incoming traffic data and are obtained
from the data distribution block.</p>
      <p>ІІ. The next step is to retrieve from the
database a set of data on the state of the
information system security X (t) = {x1,..., x25}, a
set of possible security breaches  = {1,...,n} ,
and a set of possible means of counteracting
breaches (management decisions) U = {u1,...,un} ,
where n is the number of options in the sets
contained in the database; assessing security
based on the dependence of the average value of
the set of optimal values of means of
counteracting breaches U on the value  and
establishing the state of security.</p>
      <p>Pattern recognition is taught as follows.
There is a set of observations (security states)
that belong to p different classes. The
components of the vector are individual
security threats to the information system’s
elements. Using information about
observations and their classification, it is
necessary to find a rule that would allow
classifying changes in the security state (new
observations) with a minimum number of
errors.</p>
      <p>Classes of observations can be situations of
changes in the state of security of information
system elements. For example, for two classes:
the state of security of information system
elements is deteriorating; the state of security
of information system elements is improving.
An example for three classes: the state of
protection of information system elements is
deteriorating; the state of protection of
information system elements remains
unchanged; the state of protection of
information system elements is improving.
The number of classes can be arbitrary and
determined by the condition of unambiguous
classification of the current situation.</p>
      <p>We assume that the observation is given by
the vector x , and its classification is given by
the number  ( can take p values: 0, 1, ...,
p −1 ). In practice, the vector of observations
will be a vector whose components will be
numerical estimates of the information
system’s security. The dimension of the vector
will correspond to the number of threats
submitted for consideration.</p>
      <p>Thus, given a sequence of l observations and
classifications x1,1;...; xl ,l , it is necessary to
construct a decisive rule  = F ( x) that would
classify new observations with the least possible
number of errors.</p>
      <p>To formalize the word “error”, we assume
that there exists (although it is unknown) some
rule  that defines for each vector x a
classification  =  ( x) , which is called “true”.
An error in the classification of the vector x
using the rule F ( x ) is a classification in which
F ( x ) and  ( x ) do not coincide.</p>
      <p>To be able to use mathematical analysis, we
will assume that the rule F ( x) is one of the
functions of some given set of functions
F ( x) , and the classification rule  ( x ) is
determined by the conditional probability
P ( x ) .</p>
      <p>
        It is commonly assumed that there exists an
unknown probability measure on the space of
x vectors (we denote it by the density P ( x ) ).
By P ( x ) , situations x appear randomly and
independently, which are classified using the
P ( x ) rule. Thus, the training sequence is
determined
x1,1;...; xl ,l .
(
        <xref ref-type="bibr" rid="ref6">6</xref>
        )
      </p>
      <p>For any deciding F ( x) rule, let’s define
quality
as
the
probability
of
different
classifications using rule F ( x) and rule P ( x) .
The lower this probability, the higher the quality.
Formally, the quality of the deciding rule can be
written in the form:</p>
      <p>p−1
I ( F ) =   ( F ( x) −i )P (i x) P ( x) dx (7)
i=0</p>
      <p>0, z = 0
where  ( z ) = 
1, z  0
.</p>
      <p>It is not possible to calculate directly the
probability of an error-free classification for
any deciding rule F ( x ) , since the densities
P ( x ) and P ( x ) are not known.</p>
      <p>
        Using the sample (
        <xref ref-type="bibr" rid="ref6">6</xref>
        ), find a rule in the class
F ( x) that minimizes the functionality (7).
      </p>
      <p>For convenience, we will assume that:
1. The variable  takes only two values: 0
and 1 (i.e., that the situation x belongs to one
of the two classes); this restriction is not
fundamental, since a sequential division into
two classes can be obtained by dividing into
any finite number of classes.</p>
      <p>2. The class of indicator functions F ( x) ,
i.e. functions that take two values: 0 and 1, is
parametric F ( x, ) (here  is a parameter
that belongs to the set  , the specific value of
which  =  * determines a specific function
F ( x, * ) of the class F ( x, ) ; to find the
required function in the class means to set the
required value of the parameter in the class;
studying only the parametric class of functions
does not reduce the generality in the definition
of the class of functions, since the set  is
arbitrary: it can be a set of scalar values, a set
of vectors, or a set of abstract elements).</p>
      <p>
        3. Write the functionality (2) in the form
I ( ) =  ( − F ( x, ))2 P ( x, ) dxd , (
        <xref ref-type="bibr" rid="ref7">8</xref>
        )
where the function P ( x, ) = P ( x ) P ( x ) is
called the joint density of pairs x, given on
the space X ,  .
      </p>
      <p>
        Thus, the task of pattern recognition
training is to find one in the class of indicator
functions F ( x, ) that would minimize the
functional (
        <xref ref-type="bibr" rid="ref7">8</xref>
        ) under conditions when the joint
density P ( x, ) is unknown, but a probable
and independent sample of pairs obtained
according to this density is given.
      </p>
      <p>
        Pattern recognition learning algorithms are
based on a special method of finding a decisive
rule based on the construction of a separating
hyperplane.
(
        <xref ref-type="bibr" rid="ref10">11</xref>
        )
(
        <xref ref-type="bibr" rid="ref11">12</xref>
        )
      </p>
      <p>To build the guide vector 0 we will use the
results of our work. Consider the finite set of
vectors Z , which consists of all possible
differences formed by the vectors of the set X
and the vectors of the set X :</p>
      <p>Z = {zij = xi − x j} , i = 1, a , j = 1, b
( a b elements in total).</p>
      <p>Let’s find the minimal module vector  0
that satisfies the inequality:</p>
      <p>
        zij  1, zij  Z . (
        <xref ref-type="bibr" rid="ref8">9</xref>
        )
The vector  0 coincides in direction with
1
the optimal vector 0 , and the value is the
 0
distance between the projections of the sets X
and X the direction of the vector  0 .
      </p>
      <p>Thus, to find the vector  0 and use it to
construct the optimal separating hyperplane, it
is necessary to minimize the functional</p>
      <p>
        I = T , (
        <xref ref-type="bibr" rid="ref9">10</xref>
        )
when the constraints (
        <xref ref-type="bibr" rid="ref8">9</xref>
        ) are met.
      </p>
      <p>
        Finding the minimum of (
        <xref ref-type="bibr" rid="ref9">10</xref>
        ) under the
constraints (
        <xref ref-type="bibr" rid="ref8">9</xref>
        ) is a quadratic programming
problem, the solution of which is based on the
Kuhn-Tucker theorem, which specifies the
necessary and sufficient conditions for the
minimum. The following theorem follows from
the above.
      </p>
      <p>
        Theorem 1. The minimal module vector  0
satisfying (
        <xref ref-type="bibr" rid="ref8">9</xref>
        ) can be given as
      </p>
      <p>a b
 0 =   zij i0j ,  i0j  0 ,</p>
      <p>i=1 j=1
and
 i0j  ziTj −1 = 0 , i = 1, a , j = 1, b .</p>
      <p>
        Among all the vectors  satisfying (7), the
vector  given in the form (
        <xref ref-type="bibr" rid="ref10">11</xref>
        ) and (
        <xref ref-type="bibr" rid="ref11">12</xref>
        ) is
minimal in the module.
      </p>
      <p>Let us call vectors zi*j , for which conditions
are being made zi*j 0 = 1 extreme vectors.
According to Theorem 1, a minimal modulo
directing vector can be provided in the form of
a linear combination of extreme vectors.
Vectors xi* , x *j , forming extreme vectors zi*j ,
will be called informative.</p>
      <p>Let us consider the problem, a solution that
is equivalent to the composition of the optimal
directing vector. Assume that  is parameters
vector  ij . Consider the function</p>
      <p>
        a b
W ( ) =   ij − 1 T , (
        <xref ref-type="bibr" rid="ref12">13</xref>
        )
i=1 j=1 2
a b
where  =   zij ij .
      </p>
      <p>i=1 j=1</p>
      <p>In this case,  0 is the maximum point of a
function W ( ) in a positive quadrant ( i0j  0
) and determines the optimal separating
vector.</p>
      <p>Indeed, necessary and sufficient condition
for function W ( ) maximum in the point  0
are the following</p>
      <p> 0,
W ( 0 ) = 
 ij  0, if  i0j = 0, j = 1, b
if  i0j  0, i = 1, a .</p>
      <p>Let us write these conditions down and mark
a b
 0 =   zij i0j .</p>
      <p>i=1 j=1
We will obtain:</p>
      <p> 0, if  i0j  0, i = 1, a
1− ziTj 0 = 
 0, if  i0j = 0, j = 1, b
.</p>
      <p>These conditions may be rewritten in the
form of inequation
zij 0  1 ,  i0j  0 , i = 1, a , j = 1, b</p>
      <p>T
and the equations  i0jT (1− zij 0 ) = 0 ,
i = 1, a , j = 1, b .</p>
      <p>According to the theorem 1 assertion, these
conditions determine the optimal directing
vector.</p>
      <p>Thus, the problem of building a hyperarea
that divides two vectors’ multiplicities has
been reduced to the search for the function
maximum W ( ) in the positive quadrant.</p>
      <p>
        An important issue for the search for a
maximum for quadratic form (
        <xref ref-type="bibr" rid="ref12">13</xref>
        ) is the
following.
      </p>
      <p>
        Theorem 2. If dividing hyperarea exists
(that is vector  0 , for which inequation is
fulfilled (
        <xref ref-type="bibr" rid="ref12">13</xref>
        )), then the function maximum
W ( ) in a positive quadrant equals half of the
squared absolute value of the optimal directing
vector W ( 0 ) =  0 2 .
      </p>
      <p>2</p>
      <p>From the theorem arises consequence
which is important for algorithm development.</p>
      <p>Consequence. Valid estimate</p>
      <p>
        1
 ( ) 
2W ( 0 )
,
(
        <xref ref-type="bibr" rid="ref13">14</xref>
        )
where  ( ) —distance between set projections
X and X to the direction  .
      </p>
      <p>
        In this case, estimate equality (
        <xref ref-type="bibr" rid="ref13">14</xref>
        ) is
reached if  = 0 or if  =  0 .
      </p>
      <p>This consequence is used for the criteria
construction of vector inseparability. Two
finite sets of vectors are virtually not separated
by hyperarea, or simply inseparable if the
distance between these set projections in any
direction is less than preassigned 0 . This
means there is no inseparability, if  i*j  0 , that
W ( * )  1
202</p>
      <p>= W0 .</p>
      <p>Therefore, when generating an optimal
directing vector it is necessary to calculate
maximum of positively obtained quadratic
form W ( ) of a positive quadrant  ij  0 or
find out that the function maximum W ( )
exceeds a prescribed value W0 . The latter
means that the generation of separating
hyperarea is impossible.</p>
      <p>One of the most effective maximization
algorithms of nonpositively defined quadratic
form is a method of conjugate gradients. Using
it one can attain maximum in n steps ( n is
form dimensionality). Let us consider the
conjugate gradients method to maximize
negative square form F ( y ) = bT y − yT Ay ,
where A is positively determined matrix, b ,
y are vectors.</p>
      <p>
        Using conjugate gradient, function maximum
search begins with an arbitrary point y0 = y (0)
. The first step is taken in the direction of the
gradient of function F ( y ) at the point of y (0) .
Let us mark the gradient of a function at the point
y (0) through g (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) , and motion direction from
the point y (0) through z (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) .
      </p>
      <p>
        Therefore, z (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) = g (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) .
      </p>
      <p>
        A step is being taken in the direction of
z (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) attaining a maximum in this direction.
Direction z (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) maximum is set by equation
zT (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) g (
        <xref ref-type="bibr" rid="ref1">1</xref>
        )
y (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) = y (0) + zT (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) Az (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) z (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) .
(15)
      </p>
      <p>Beginning with the second step, motion
direction is obtained by vector
z (t +1) = g (t +1) +
z (t ) ,</p>
      <p>(16)
g (t +1) 2
g (t ) 2
where g (t +1) and g (t ) is gradient of function
F ( y ) at the points y (t +1) та y (t ) respectively;
z (t ) is motion direction at the point y (t −1) .</p>
      <p>Motion in the direction of z (t ) is made
before attaining conditional maximum. This
maximum is reached at the point
y (t ) = y (t −1) + h (t ) z (t ) ,
(17)
where the motion step is provided by the
value:
h (t ) =
zT (t ) g (t )
zT (t ) Az (t )</p>
      <p>Thus, formulas (15)–(18) assign a search
algorithm for the maximum quadratic form
F ( y ) .</p>
      <p>Method modification is guided to limit the
region of search by a positive quadrant.</p>
      <p>Define the function
F ( y) F ( y)
 yi , if yi  0 чи yi
gˆi (t ) = 
 0 if yi = 0 та Fy(iy)
 0;</p>
      <sec id="sec-2-1">
        <title>Vector</title>
        <p>gˆ ( y ) = ( gˆ1 ( y ) ,..., gˆn ( y ))</p>
        <p>T
is a
conditional gradient of the function F ( y ) on
the multitude yi  0 .</p>
        <p>We conduct ascendancy to the maximum
using formulas (15)–(18), where g ( y ) is
replaced with gˆ ( y ) . Motion begins with an
arbitrary point of the positive quadrant and
continues until it reaches the restriction in the
point y0 . Then ascendancy begins again by the
method of conjugate gradients, but from the
point y0 . The search for maximum ends if
inequity is solved gˆi ( y )   .</p>
        <p>To keep the trajectory within the borders of
the positive quadrant, step size hˆ (t ) is
selected if two dimensions are minimal:</p>
        <p>hˆ (t ) = min ( h (t ) , h* (t )) ,
where h* (t ) = min
i</p>
        <p>yi (t )
zi (t +1)</p>
        <p>When calculating h* (t ) minimum is only
determined by the coordinates i , for which
zi  0 . If zi  0 , step equals h (t ) .</p>
        <p>To form an optimal directing vector it is
necessary either to determine that the function
a b 1
maximum W ( ) =   ij −  T , where
i=1 j=1 2
in
the
positive
a b
 =   ij ( xi − x j ) ,</p>
        <p>i=1 j=1
quadrant is bigger than a prescribed value W0
(this means that faultless vectors’ separation is
possible), or, if it is not this way, to find a point
 0 of maximum W ( ) in the positive
quadrant. In this case equation of separating
hyperarea is xT = c0 , where
c0 = mxiiXn xiT 0 + max x Tj 0
xjX</p>
        <p>.</p>
        <p>2</p>
        <p>We will maximize quadratic form W ( ) in
the positive quadrant using a modified method
 0. of conjugate gradients, where we take into
account that</p>
        <p>1− T ( xi − xj ), if ij  0 or 1− T ( xi − xj )  0;
gˆi (t ) = </p>
        <p> 0 if ij = 0 and 1− T ( xi − xj )  0.
and that zT Az = T .</p>
        <p>Let us determine a maximum point W ( )
through iterations. For the first iteration, we
point out the group of Z1 vectors zii = xi − xi ,
made up of l1 vectors x1,..., xl1 of learning
consequence which belong to the first class,
and l1 vectors x1,..., xl1 of learning
consequence which belong to the second class.
By vectors zii we build a quadratic formula
W ( ) , find its maximum point  i0i1 in the
pick out among the vectors of learning
consequence such vectors as x* and x* where
extreme values are achieved:
x*T 01 = mxiiXn xiT 01 , x*T 01 = max x Tj 01 .
xjX</p>
      </sec>
      <sec id="sec-2-2">
        <title>If it turns out, that inequities done</title>
        <p>x* 01  min xT 01 −1 ,</p>
        <p>T
xX
(19)
x*T 01  mxaXx x T 01 + 2 , (20)
where in the right members minimum and
maximum are computed only by vectors of
teaching sequence,  1 and  2 are algorithm
parameters, vector  01 , and number
min xT 01 + max xT 01
c0 = x x</p>
        <p>2
separation of hyperarea. If only one of the
inequities (19), (20) is not performed, we form
a vector z** = x* − x* , add it to the
distinguished group Z2 , and execute a new
iteration (i.e. form a new quadratic form
W ( ) , find its maximum point  0*2 and
assign
optimal
determine vector  02 ).</p>
        <p>We will keep on until either both inequities
are resolved (19), (20), or it turns out that
separation is impossible. (W ( )  W , W0 —
0
assigned value).</p>
        <p>Using this analyzed basic algorithm
separating hyperarea is built, which minimizes
the number of incorrectly classified vectors.
Principally this problem can be solved in a
precise manner but requires much more
enumeration. That is why to form “close to the
optimal” hyperarea, a standard method of
“sequential minimization” is used.</p>
        <p>If accurate separation by hyperarea is
impossible, one element that “hinders mostly
to separation” is excluded from the learning
sequence. If separation is still impossible,
another element is excluded from the
remaining multitude. All in all, having excluded
m vectors that hinder separation, it is possible
to separate a multitude of the remaining
vectors.</p>
        <p>According to the admitted assessment,
chances of incorrect classification using
formed hyperarea are assessed from above:
d  ln l +1 − ln  
P   d  1+ 1+ 4m  + m ,
2l  d  ln dl +1 − ln  l
 =
where d = min  n,   2  +1, r  is the “internal
  D2 
 
dimension of the problem” ( n is space
dimension, D is multitude diameter,
1</p>
        <p>, r is several informative
2W ( )
vectors xi* , x *j ).</p>
        <p>Therefore, algorithm singularity is based on
the vector of learning sequence determination
x* or x* , which “hinders separation the most”.
In the capacity of such vector, the vector x* or
x* is selected which is, at the time of the halt,
according to the condition W ( * )  W0
contributing the most to the dimension
a b
W ( * ) = i=1 j=1 i*j − 12 *T * , where
a b
 * =   i*j ( xi − x j ) .</p>
        <p>i=1 j=1</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>4. Conclusions</title>
      <p>Unlike known methods of managing critical
infrastructure IS security, which does not
envisage separation of order assessment
system including operational characteristics of
IS components, and as a result, use the
sequential algorithm of the assessment
process, which leads to the big mathematical
complexity of calculation. The proposed IS
security management method is based on
internal cyberattack data. As a basis, a method
of support vector modification based on
parameters, which are specific for internal [7]
cyberattacks on IS. This method is designed to
distribute and identify the input parameters of
internal cyberattacks and increase the reliability
of making a management decision to assess the
state of IP security, provided that the time for
making a management decision will not exceed
the time required by existing methods. The
employed mathematical apparatus reduces the
amount of input data for managing the state of
the information system security and increases
the reliability of making a management
decision on assessing the state of security of
information resources of critical
infrastructure.
Assesment, 3rd Int. Conf. Adv. Inf.</p>
      <p>Commun. Technol. (2019) 463–468.
[15] N. Cristianini, J. Shawe-Taylor, An
Introduction to Support Vector Machines
and Other Kernel-based Learning
Methods, Cambridge University Press
(2000).
[16] V. Kecman, Learning and Soft Computing
— Support Vector Machines, Neural
Networks, Fuzzy Logic Systems, The MIT</p>
      <p>Press, Cambridge, MA (2001).
[17] A. Ben-Hur, et al., Support Vector
Clustering, J. Mach. Learn. Res. 2 (2001)
125–137.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <source>[1] [2] [3] [4]</source>
          [5]
          <string-name>
            <given-names>V.</given-names>
            <surname>Grechaninov</surname>
          </string-name>
          , et al.,
          <source>Formation of Dependability and Cyber Protection Model in Information Systems of Situational Center, in: Workshop on Emerging Technology Trends on the Smart Industry and the Internet of Things</source>
          , vol.
          <volume>3149</volume>
          (
          <year>2022</year>
          )
          <fpage>107</fpage>
          -
          <lpage>117</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <given-names>P.</given-names>
            <surname>Anakhov</surname>
          </string-name>
          , et al.,
          <article-title>Increasing the Functional Network Stability in the Depression Zone of the Hydroelectric Power Station Reservoir</article-title>
          ,
          <source>in: Workshop on Emerging Technology Trends on the Smart Industry and the Internet of Things</source>
          , vol.
          <volume>3149</volume>
          (
          <year>2022</year>
          )
          <fpage>169</fpage>
          -
          <lpage>176</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3188, no.
          <issue>2</issue>
          (
          <year>2022</year>
          )
          <fpage>197</fpage>
          -
          <lpage>206</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <given-names>D.</given-names>
            <surname>Biryukov</surname>
          </string-name>
          ,
          <article-title>Protection of Critical Infrastructure: Problems and Prospects of Implementation in Ukraine</article-title>
          ,NISD,
          <string-name>
            <surname>Kyiv</surname>
          </string-name>
          (
          <year>2012</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <string-name>
            <given-names>O.</given-names>
            <surname>Dovgan</surname>
          </string-name>
          ,
          <article-title>Critical Infrastructure as an Object of Protection Against Cybernetic Attacks, Information Security: Challenges and Threats of Modernity: Materials of a Scientific and Practical Conference (</article-title>
          <year>2013</year>
          )
          <fpage>17</fpage>
          -
          <lpage>20</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>S.</given-names>
            <surname>Hnatiuk</surname>
          </string-name>
          ,
          <article-title>Criteria for Determining the Elements of the Critical Infrastructure of the State</article-title>
          , Innovative Potential of World Science-21st
          <string-name>
            <surname>Century</surname>
          </string-name>
          (
          <year>2013</year>
          )
          <fpage>55</fpage>
          -
          <lpage>57</lpage>
          . S. Tolіupa,
          <source>Intrusion Detection Systems and Functional Stability of Distributed Information Systems Against Cyber Threats</source>
          , Brailovsky: Monograph,
          <string-name>
            <surname>Format</surname>
          </string-name>
          (
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>S.</given-names>
            <surname>Salnyk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Storchak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Mykytyuk</surname>
          </string-name>
          ,
          <source>Model of Violation of the Security of Information Resources of Communication Systems, Inf. Technol. Secur</source>
          .
          <volume>7</volume>
          (
          <issue>1</issue>
          ) (
          <year>2019</year>
          )
          <fpage>25</fpage>
          -
          <lpage>34</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>V.</given-names>
            <surname>Buriachok</surname>
          </string-name>
          , et al.,
          <article-title>Invasion Detection Model using Two-Stage Criterion of Detection of Network Anomalies</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>2746</volume>
          (
          <year>2020</year>
          )
          <fpage>23</fpage>
          -
          <lpage>32</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>I.</given-names>
            <surname>Kuzminykh</surname>
          </string-name>
          , et al.,
          <article-title>Investigation of the IoT Device Lifetime with Secure Data Transmission, Internet of Things, Smart Spaces, and Next Generation Networks and Systems</article-title>
          , vol.
          <volume>11660</volume>
          (
          <year>2019</year>
          )
          <fpage>16</fpage>
          -
          <lpage>27</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>030</fpage>
          -30859-
          <issue>9</issue>
          _
          <fpage>2</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>S.</given-names>
            <surname>Tolіupa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Pliushch</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Parkhomenko</surname>
          </string-name>
          ,
          <source>Construction of Attack Detection Systems in Information Networks Based on Neural Network Structures, Cybersecur. Educ. Sci. Technol</source>
          .
          <volume>2</volume>
          (
          <issue>10</issue>
          ) (
          <year>2020</year>
          )
          <fpage>169</fpage>
          -
          <lpage>183</lpage>
          . doi:
          <volume>10</volume>
          .28925/
          <fpage>2663</fpage>
          -
          <lpage>4023</lpage>
          .
          <year>2020</year>
          .
          <volume>10</volume>
          .169183.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>A.</given-names>
            <surname>Storchak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Salnyk</surname>
          </string-name>
          ,
          <article-title>A Method of Assessing the Level of Security of the Network Part of a Special Purpose Communication System Against Cyber Threats, Inf</article-title>
          . Proces. Syst.
          <volume>3</volume>
          (
          <issue>158</issue>
          ) (
          <year>2019</year>
          )
          <fpage>98</fpage>
          -
          <lpage>109</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>L.</given-names>
            <surname>Slipachuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Toliupa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Nakonechnyi</surname>
          </string-name>
          ,
          <article-title>The Process of the Critical Infrastructure Cyber Security Management using the Integrated System of the National Cyber Security Sector Management in Ukraine, 3rd</article-title>
          <string-name>
            <surname>Int. Conf. Adv. Inf. Commun. Technol.</surname>
          </string-name>
          (
          <year>2019</year>
          )
          <fpage>451</fpage>
          -
          <lpage>454</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>S.</given-names>
            <surname>Toliupa</surname>
          </string-name>
          , I. Parkhomenko,
          <string-name>
            <given-names>H.</given-names>
            <surname>Shvedova</surname>
          </string-name>
          ,
          <article-title>Security and Regulatory Aspects of the Critical Infrastructure Objects Functioning</article-title>
          and Cyberpower Level
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>