<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>Cybersecurity Providing in Information and Telecommunication Systems, February</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Method of Ensuring the Functional Stability of the Information System based on Detection of Intrusions and Reconfiguration of Virtual Networks</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Iryna Zamrii</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Viktor Vyshnivskyi</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Valentyn Sobchuk</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>State University of Information and Communication Technologies</institution>
          ,
          <addr-line>7 Solomianska str., Kyiv, 03110</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Taras Shevchenko National University of Kyiv</institution>
          ,
          <addr-line>64 Volodymyrska str., Kyiv, 01033</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2024</year>
      </pub-date>
      <volume>28</volume>
      <issue>2024</issue>
      <fpage>0000</fpage>
      <lpage>0001</lpage>
      <abstract>
        <p>The functioning of the information system takes place in conditions of constant interaction with the external environment under the influence of various destabilizing factors. Informational conflicts that provide information about bilateral interaction and have a destructive effect on the elements of the opposite party deserve special attention, which allows for obtaining, storing, and processing information necessary to achieve the goals of the entire system and even counteract the processes that have arisen under the influence of an informational conflict. Destabilizing factors and conflicts in the system lead to failures in the functional processes of the information system. Prevention of these effects occurs by ensuring the functional stability of the information system, that is, the ability of the system to preserve or restore certain system functions during the action of destabilizing factors. The article develops a method for ensuring the functional stability of the information system using software-defined wide area networks, which is aimed at solving the problem of increasing the stability and security of the information system against violations based on the detection of intrusions and the reconfiguration of virtual networks in virtual cloud environments.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Information system</kwd>
        <kwd>software-defined wide area networks</kwd>
        <kwd>reconfiguration</kwd>
        <kwd>functional stability</kwd>
        <kwd>security</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>In today’s environment, companies are forced to
transform all areas of their activities, using digital
technologies to increase efficiency, speed of
execution, and cost optimization [1, 2]. As a result
of these changes, the traditional approach of
centralizing applications, network centers, and
security services no longer guarantees the
performance of these applications [3–6].</p>
      <p>Another factor that has affected the provision
of network and security services is the location of
workers and users. Traditionally, users worked
from a central office or branch office from where
security and network services could be
effectively delivered. But for now, users need to
be able to access apps regardless of location. This
means that enhanced security services must now
be provided in all locations.</p>
      <p>As technology evolves, it makes sense to consider
enabling users to securely access applications
from anywhere, whether they are hosted in the
cloud or on a private host, locally or remotely,
ensuring consistent security and transparency
for users regardless of access method, as well as
protecting the company’s digital assets [7]. For
this purpose, the integration of technologies
necessary to provide users with secure access to
data and programs regardless of location is
increasingly used [8–11]. At the same time, an
important component remains the maintenance
of the normal functioning of the information
system in conditions of constant destabilizing
factors. The essence of this is to adopt
countermeasures against various destabilizing
factors [12], adapt functional algorithms to new
conditions, organize functional restoration or
ensure continued functioning in conditions of
survives external failures and attacks through
autonomous
reconfiguration.</p>
      <p>As
a
result,
research [25] proposed an intelligent
decisionmaking model supported by edge computing to
address the problem of real-time failures and
attacks.</p>
      <p>However, there is a need to develop a
performance,
configuration,
and
security
management apparatus to effectively use the
information and hardware resources of the
methodology should be developed to ensure the
effectiveness
of
the
functioning
of
the
information system from the point of view of
functional stability.</p>
    </sec>
    <sec id="sec-2">
      <title>2. The Method of Increasing the</title>
    </sec>
    <sec id="sec-3">
      <title>Functional</title>
    </sec>
    <sec id="sec-4">
      <title>Stability</title>
    </sec>
    <sec id="sec-5">
      <title>Information System of the</title>
      <p>→ 
Consider the objective function of the top of the
information system (IS) hierarchy graph:
where for each</p>
      <p>vertex that continues to
function without failure, the IS continues to
function at full capacity:
,   )| (  ) ,
system failures, perform analysis and reliability
assessment, and, based on these data, assess the
stability of the information system [13–15].</p>
      <p>Analysis and assessment of stability allow
timely support and restoration of the main
functions of the system in the required amount
and even allow for the influence of the external
environment as a result of the effects of
destabilizing factors and changes in algorithms,
operating conditions, and system structure [16,</p>
      <p>The development of approaches to solving
the problem of synthesizing functionally stable
systems is a complex process. One of the
methods is the formation of a system of rules for
effective management of the functional stability
of
the
system
[18–20],
and
its
implementation, in
particular, for
specific
solving
optimization problems. That is, in the problem of
system stability synthesis, the development of
principles
and
methods
of
ensuring
the
functional stability of the system is carried out to
solve the problem of its improvement.</p>
      <p>The analysis of recent studies shows that one</p>
      <p>methods of increasing security and
stability is the reconfiguration of the information
system network. The article [21] discusses the
problem of dependent reconfiguration of NFV. A
distributed approach is proposed to guarantee
consistency during dependent reconfiguration.
This approach consists of a distributed
multidomain model that establishes the interaction
between federation
objects
and
a
causalcoherent distributed orchestration algorithm
based on this model.</p>
      <p>The paper [22] aims to enhance the reliability
and quality of service of power smart grids by
searching for and applying
reconfigurationoriented solutions. A novel definition of recovery
performance is provided in terms of automatic
recoverability and unavailability rates.</p>
      <p>The paper [23] presents a performance
optimization
reconfiguration
algorithm</p>
      <p>for
in
fault-tolerant</p>
      <p>controller
distributed
model predictive control for large-scale systems.</p>
      <p>Thе аrticle [24] exploits the potential benefits
of a
blockchain system
integrated
software-defined
network.</p>
      <p>A
new
with a
clusterstructured routing protocol for IoT networks
using blockchain-based architecture for SDN
controllers is proposed. This helped solve
performance and security issues.</p>
      <p>
        An intelligent decision-making framework is
necessary to ensure that the system as a whole
(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )
(2)
(3)
(4)
(5)
 = {01,, ioftherwexiseec,utes on   ,
 (  ) = ∑      ,
      </p>
      <p>where  (  ) is the general solution of the
optimal
scenario
under
the influence
of
destabilizing factors, which is the sum of the
products
of vertices   associated
with an
abnormal situation for solving the problem  
and the scenario of making the best decision for
solving the given problem    , ℳф( 
,   ) is
the
matrix of functioning
of vertices and
problems of the IS hierarchy graph.</p>
      <p>If the set of executable functions is a
constant for the objective function, then</p>
      <p>If some vertex is unable to withstand an
abnormal situation and continue to function in
the
same
mode, the
system
imposes a
constraint  0 (  )</p>
      <p>for failure to perform
assigned tasks on the vertex in the form of a
function that acquires negative values. The
   =  ∗ .
controller of the system, depending on how
critical the failure of the vertex to complete or
partially perform the assigned tasks, adjusts
the restrictions on it.

 is the execution period of the user
algorithm.</p>
      <p>The periods and execution times of the
specified algorithms are shown in Error!
method of forming restrictions is
Reference source not found..
proposed as follows:  0∗ (  ) is a restriction in
the case of a partial loss of productivity, that is,
of the assigned functions, and  ×  1∗ (  ) is a
restriction in the case of a proportional loss of
productivity α. Then
(6)
 0 (  ) =  0∗ (  ) +  ×  1∗ (  ).</p>
      <p>If the functions perform tasks with different
quality, then, accordingly, they are predicted to
win in this strategy  0(  ), that is, in the
scenario of making the best decision for   .</p>
      <p>It is obvious that if the function consumes
resources, then it ensures the fulfillment of
tasks, such as data transfer, management of
processing in distributed databases, etc. That
is, the more the function consumes resources,
the better the result. And the size of the
restriction will depend on the quality of the
performance of each of the tasks   .</p>
      <p>Thus, the objective function for the top-level
vertex of the IS network hierarchy will be to
maximize the wins in each of the strategies and
minimize the constraints:
where  (  ) is a weighting factor that allows
the controller to determine the priority of the
performed functions in the system.</p>
      <p>Consider the case in which the IS is unable to
perform the amount of tasks and functions that
arose as a result of extraordinary situations. In
this case, there is a possibility that there are both
server problems and problems arising as a result
of user actions, so restrictions can be imposed on
both components.
following conditions:</p>
      <p>In this regard, within the framework of the
proposed methodology, algorithms have been
developed both for users and for problems
related to equipment, and their execution does
not necessarily have to be simultaneous.</p>
      <p>
        For the server algorithm, we denote the
period of its execution by  с and impose the
(7)
 с =   +    ,
(
        <xref ref-type="bibr" rid="ref8">8</xref>
        )
where   is the execution time of the task
decision,  is the number of times the user
algorithm is executed during the period  с.
The values of  с,   ,   ,  determine the order of
application of algorithms in the methodology.
      </p>
      <p>The developed technique consists of the
following steps:
1.</p>
      <p>Definition of source data.
2. Using the Prisma Access infrastructure
for
and
to bypass failed connections, including
dynamic
routing
using</p>
      <p>BGP
and
information
about new IP
address
subnets on the user connection side of
the Prisma Access infrastructure to
bypass
failed
connections
when
multiple routes exist
between the
client network and Prisma Access.
3. Checking whether all tasks  
been completed. If not all  
completed, then we proceed to the next
step of the method.
4. Determination of  с,   ,   ,  using the
IS controller reading the values of these
have
are
parameters.
5. For each function  , the following are
determined:  0(  ),  (  ),  0(  )
and methods are set.
6.  с,</p>
      <p>,   ,  are defined. The order of
application and execution time of the
7. Selection of the  value of the partial
methods is set.
productivity of the IS.
moment
controller.
8. Implementation of method ℬ1.
9.</p>
      <p>Implementation of method ℬ2.
10. Evaluation of the level of functional
stability of the IS</p>
      <p>at the current
using the SD-WAN cloud
11. Determination
In this methodology, ℬ1 is an algorithm for the
functional reconfiguration of the top of the
graph of the top level of the IS network
hierarchy, and ℬ2 is an algorithm for the
functional reconfiguration of the hierarchical IS
network in real-time.</p>
      <p>Visualization and order of interaction of the
steps are presented in Fig. 2.</p>
    </sec>
    <sec id="sec-6">
      <title>3. Algorithm of Functional</title>
    </sec>
    <sec id="sec-7">
      <title>Reconfiguration of the Top of the Graph of the Upper Level of the Hierarchy of the</title>
    </sec>
    <sec id="sec-8">
      <title>Information System Network</title>
      <p>The selection of methods and mathematical
apparatus for ensuring the functioning of the
vertices of the graph of the hierarchical
configuration of the network of the information
system involves:
• Each of the functional levels must be able
to make changes to the configuration and
structural connections and take into
account the possibility of breaking the
connection with the top of the higher
level of the hierarchy.
• The ability to quickly make changes in
real time.
• Possibility of scaling.
• Possibility of use in dynamic models.</p>
      <p>The need to ensure the specified
requirements determines the possibility of
applying the model of self-organizing systems
in crises and the method of operational
management of the theory of active systems.</p>
      <p>According to the theory of active systems [26],
a parameter called the incentive fund is
introduced, the task of which is to be distributed
among the vertices of the network. The optimal
solution is to distribute the parameter between
performers who have not yet performed their
function. This distribution mechanism is
centralized, which creates certain difficulties for
the survivability of the system, in addition, even
in distributed systems there are problems with
the operation and distribution of this parameter.</p>
      <p>The possibility of applying the distribution
of this parameter due to the anticipatory
selfmonitoring approach solves the problem of
timely response to failures in the vertices of the
network graph and edges, that is, the
connections associated with these vertices.</p>
      <p>That is, during the performance of the
functions assigned to the top, its behavior
should be structured in such a way as to
minimize restrictions (penalties in game
theory [26]) and maximize decision-making
strategies (incentives), due to which the
system’s efficiency increases. In addition, this
approach is applicable during the functioning
of the system in real-time.</p>
      <p>Let’s define tasks and connections between
them in the hierarchical configuration of the
information system network for algorithm ℬ1.</p>
      <p>The algorithm is designed to provide three
types of functional restructuring of the
information system network, namely:
•  1 is a functional rearrangement that will
allow saving the set of all performed
functions in the IC.
•  2 is a functional restructuring, which
does not take into account the possible
decrease in the quality of performance of
specified functions under the influence of
such restructuring.
•  ∗ is a functional rearrangement that is a
union of  1 and  2.</p>
      <p>Since for the functioning of the IS in
different periods, sets of different tasks and
functions that have different levels of
productivity can be performed, but despite
everything, none of the functions can be
neglected, the ℬ1 algorithm is based on the
priority execution of the functional
rearrangement  1 and only under the condition
the impossibility of ensuring the functioning of
the system without losing the quality of part of
the functions, the transition to functional
restructuring  ∗.</p>
      <p>The steps of performing the algorithm ℬ1
include:</p>
      <p>1. Entering input data, which includes the
collection and processing of information about
the vertices and the configuration of the
network of the IS, namely: updating the data
 (  ,  ) and  с(  ,  ) by each of the
vertices for tasks   ; update of current data
from the network controller of the IS about the
values of  с,  c.</p>
      <p>2. Determination of the number of tasks
performed by the vertex according to the
formula:
ℛ = ∑ ∑ ∑  |ℳф(  ,   )| (  )</p>
      <p>=1  =1  =1
to calculate the complexity of
decisionmaking in the performance of tasks to ensure
the functioning of the IS network and the
algorithm for further actions.</p>
      <p>3. Determination of the tasks performed
by the vertex at the current time. If the vertex
does not perform tasks, then the method is not
applied to this vertex.</p>
      <p>
        4. Analysis of configurations
ℳф(  ,   )( ) at the current time and
(
        <xref ref-type="bibr" rid="ref9">9</xref>
        )
comparison with the previous configuration
      </p>
      <p>,   )( − 1). Analysis and comparison
take place sequentially for each task at a given
top of the hierarchy. If ℳф( 
,   )( ) and</p>
      <p>,   )( − 1) are identical, i.e. have no
differences, then a check of changes in the
system state is started.</p>
      <p>5.</p>
      <p>Analysis of changes in the state of the IS
network. If there have been changes in the
network of the information system, that is, an
increase or decrease in the total maximum
speed of information transmission through
specific
vertices, then it is
necessary to
implement the main part of the algorithm.
6.</p>
      <p>Application
configuration for the top-level vertex of the
hierarchy, it is
necessary
to
perform
a
restructuring depending on each of the tasks.
Then, the top of the network executes a set of
tasks to implement the best configuration in
terms of performance and survivability, while
its selection for each of the tasks is made taking
into
account the
maximum
speed in the
network and the amount of system resources
required for the calculation.</p>
      <p>6.1. Searching</p>
      <p>for
configurations with lower requirements for
computing and channel resources. If there is no
simplification of the configuration, then the
network is forced to stop performing part of
the tasks.</p>
      <p>6.2. Determination of the time  
for the
execution of one step of the approach with a
review
of
all configuration
options
and
determination of the time   of the execution of
the solution of the task by the server algorithm
using two-dimensional packaging with a full
review of all options using the formula:
all
possible
=  
  
current configuration into action;   
configuration for the task   ;   
condition
of
the
at least one of the functions of the task   . The
for different vertices in the
time  с</p>
      <p>
        equality (
        <xref ref-type="bibr" rid="ref10">10</xref>
        ).
network may be different, but  с
      </p>
      <p>Calculation of  с
≤  с.
according to</p>
      <p>Determining whether a functional
reconstruction of  1 is possible for the IS
network, based on  0 is the maximum possible
assessment of the quality of execution of   in
the configuration   
, and at this stage of
execution, the most important thing is to
maximize the total value of these estimates:
   
where  0 is a non-decreasing function of the
best possible value of the assessment of the
with the configuration
quality of the task  
  0 ,   0</p>
      <p>= 1,   .</p>
      <p>All configurations have a number that
depends on the growth of the
maximum
possible assessment of the quality of the task  0
and the following conditions are imposed on
them:
{</p>
      <p>
        ≥     −1,
 0 (  ,     ) ≥  0 (  ,     −1) ,
(
        <xref ref-type="bibr" rid="ref12">12</xref>
        )
   
impossible, and therefore a genetic method is
performed,
which
ensures
that
the
enumeration of configurations is interrupted at
an arbitrary step and provides a result no
worse than the current one.
10.
the
      </p>
      <p>Solving during the time  
  
the problem of maximizing the total
benefit of choosing configurations
without
exceeding the maximum permissible loss of
functions. For this, a complete enumeration of
all possible configuration options is used, and
the result of the decision is a vector of
configurations.</p>
      <p>11. Setting the initial time  
=  for the
genetic method of sorting configurations  ⃗⃗ .
 
12. We set the required number of steps
for the counter in the execution of the
genetic method, after which the cycle is reset.</p>
      <p>
        13. Execution of one step of the  
problem by the genetic algorithm for finding
the vector  ⃗⃗ for which inequalities (
        <xref ref-type="bibr" rid="ref13">13</xref>
        ) hold.
14. We set the value  
+ 1 for the
counter.
      </p>
      <p>15. We check the restrictions:
( 
+ 1)( −   )
&gt;   .</p>
      <p>
        (
        <xref ref-type="bibr" rid="ref14">14</xref>
        )


16. We perform the description of the
search results using the genetic algorithm and
inequalities (
        <xref ref-type="bibr" rid="ref13">13</xref>
        ) by entering the parameter 
into the matrix  (
      </p>
      <p>,   ,  ) such that:  = 1
for network restrictions;  = 2 for resource
constraints. If there is a lack of resources, then
the value in the matrix is 1, otherwise, it is 0.</p>
      <p>17. We calculate the lack of resources for
vertices located below in the hierarchy:
[
 (  ,   
 (  ,   
  −1, 1) = 1,
  −1, 1) = 2.</p>
      <p>18. We set the zero configuration in the
presence of a lack of resources in step 17:
 0(</p>
      <p>−1) = 0.</p>
      <p>19. We determine whether a functional
network similarly to step 8.
reorganization of  1 is possible for the IS
20. If the functional reconstruction of  1 for
the
information
system
network
is
not
possible, then the possibility of functional
reconstruction of  2 is determined. To do this,
the
configuration is
sent to
all vertices.</p>
      <p>Implementation of  2 occurs in steps 21–31.</p>
      <p>21. Setting the initial values for the system
function selection algorithm.</p>
      <p>22. Setting the initial values for the current
tasks sorting algorithm.</p>
      <p>23. Setting
the
initial
values for the
algorithm for sorting the tops of the hierarchy
for the current task and function.</p>
      <p>24. We set the system function counter to
25.</p>
      <p>We set the system task counter to
increase by one.
increase by one.
decrease by one.</p>
      <p>27. The verification of the possibility of
performing functions by vertices is carried out.</p>
      <p>28. A vertex that cannot perform a function
is assigned a configuration of zero, and the value
of consumption of computing resources is 0.</p>
      <p>29. The resulting condition for the system
function selection algorithm is determined.</p>
      <p>30. The resulting condition for the task
selection algorithm is defined.</p>
      <p>31. The resulting condition is determined
by the algorithm for sorting the tops of the
hierarchy for the current task and function.</p>
      <p>32. Configuration application block: in the
block, not updated data is sent to the nodes.</p>
      <p>The
block
diagram
reconfiguration of the top of the graph of the
top level of the information system network
hierarchy is shown in Fig. 3</p>
      <p>We will evaluate the correctness of this
algorithm according to the following criteria:
the possibility of obtaining a solution for a
finite number of steps; stability according to
input data; and stability in calculations.</p>
      <p>To check the fulfillment of the criteria, we
will perform the following steps:</p>
      <p>1. We define the critical sections of the
algorithm. These include:
• Steps 13–14 for the  max problem.
• Step 15, since it is critical to determine
whether the genetic algorithm for the
 max the problem has been resolved.
• Steps 24–31 for three loop algorithms.
number of counter steps is set to  gm = 0, and
in step 14,  gm = 1. In this case, the counter
will iterate over values from [1, + ∞) and
ensure the condition  gm ≠ 0.</p>
      <p>For steps 24-31, conditions  = 0,  =   ,
 = ℓ must be met.
lim
t→∞ 
limit goes to ∞, and the right-hand side of the
equality remains a constant number. Thus, in
the cyclic genetic algorithm, the number of
steps necessarily remains a constant number at</p>
      <p>For step 15, the correctness conditions are
defined in steps 11 and 14.</p>
      <p>For steps 24–31, і is a natural number, so the
number of configurations   
≥ 2.</p>
      <p>For step 30, the correct initial condition is  
is a natural number for the postcondition, and for
step 31   is a natural number and ℓ &gt; 0.
 =
 
≥ 0,
≥ 2,
≥ 1,
{
ℓ &gt; 0.</p>
      <p>
        (
        <xref ref-type="bibr" rid="ref15">15</xref>
        )
      </p>
      <p>
        Conditions (
        <xref ref-type="bibr" rid="ref15">15</xref>
        ) determine the execution of at
least one function from a set of tasks. In addition,
each of the tasks must have at least two levels of
hierarchy to ensure a hierarchical configuration.
The check is carried out in step 6.2.
= const. Then, in the last equality, the
      </p>
      <p>Then the system of correctness conditions has
of the top of the graph of the upper level of the
IS network hierarchy is correct.
is the tenth step of the method, in which a
complete enumeration of configurations is
carried out, the number of which can be
defined as  (2 ), the use of which for small
values of  leads to a reduction in the execution
time of the part of the algorithm, where  is
defined as the product of the set of tasks of
network functions by the set of vertices and the
set of assumed configurations. If k acquires
sufficiently large values, then the part of the
method based on the genetic algorithm is
executed. The complexity of the calculation
depends on the number of transformations
and the dimensions of the source data. The
computational complexity of the algorithm due
to the time limitation is inversely proportional
to the computing power of the top of the
information system network hierarchy graph.</p>
    </sec>
    <sec id="sec-9">
      <title>4. Algorithm of Functional</title>
    </sec>
    <sec id="sec-10">
      <title>Reconfiguration of the</title>
    </sec>
    <sec id="sec-11">
      <title>Hierarchical Network of the</title>
    </sec>
    <sec id="sec-12">
      <title>Information System in Real</title>
    </sec>
    <sec id="sec-13">
      <title>Time</title>
      <p>To ensure that external and internal influences
on the IS will not lead to malfunctions, network
reserves, computing reserves, and temporary
reserves are provided, which are also called
compensatory measures, and the mechanisms
for their implementation are compensatory
mechanisms
[27].</p>
      <p>In
this
method,
in
connection with the operation of IS in
realtime, the temporary reserve is excluded.</p>
      <p>In IS, the number and configuration of
vertices and connections at the structural level
can change, as can the number of functional
elements and the list of functions they perform.
The IS must quickly react to changes, therefore,
of vertices
during reconfiguration, the  
and connections is recalculated.</p>
      <p>Let’s
denote the
number of functions
performed by the IS in the current state by  =

∑</p>
      <p>=1   , where   is the number of functions
performed by the  -th functional element.</p>
      <p>To be able to respond quickly, each vertex
must have several solutions to choose the best,
they</p>
      <p>provide a reserve of the necessary
network and computing resources. In doing so,
each vertex tries to perform the most “useful”
function to try to maximize performance.</p>
      <p>But according to the emerging various
destabilizing
factors, the
vertices
cannot
always predict which of the solutions, in this
case, will be better, therefore it is important to
develop a
method in
which the adopted
decision will be better for at least one of the
vertices, and will not cause harm or damage to
the rest. In addition, in real-time systems, it is
necessary to ensure fast decision-making, and
this
can
be ensured
by
pre-generated
strategies.</p>
      <p>It should be noted that with decentralized
management, the
system
operates
under
conditions of uncertainty and therefore makes
changes based on the data available to each
node of the system. Therefore, it is necessary
to check how it affects the vertices with which
there is a direct connection and the system as
a whole.</p>
      <p>Let the decision regarding the presence of a
reserve vertex be made at the level of the
functional element  .</p>
      <p>For minor changes in the system not to lead
to permanent reconfiguration, we will set the
following requirements:
• Before starting the IS, the value of the
minimum
and
maximum
quality
of
performance of the functions is set, as
well as the possibility of receiving a
“reward”, that is, a reserve of resources,
in</p>
      <p>proportion to the quality of the
performed function.
• “Bonus rewards” in the form of excess
resources are also received for the
performance of 
functions.</p>
      <p>certain
sets of
• Restrictions are introduced for partial or
complete loss of functionality.</p>
      <p>These requirements are created in the
function
reconfiguration
step
for
the
corresponding</p>
      <p>and are determined by the
following sequence of actions.</p>
      <p>At the beginning, a list of functions up to 
is received. Combinations of functions by
individual elements are added to this list in
case of additional evaluations. This is followed
by assigning a score to each feature based on
priority to encourage support for existing
functionality. The value of the extra point is
small enough to prevent the system from
making changes to the list based on available
resources, performance, or other reasons.</p>
      <p>It is necessary to introduce mechanisms for
collecting information about the network and
channel resources of  vertices, synchronizing
the list of functions, as well as redistributing
additional estimates between the vertices of
the hierarchy graph.</p>
      <p>The
method
of complete
selection of
configurations or genetic is used for the 
problem of maximizing the total benefit of
choosing configurations without exceeding the
maximum allowable loss of functions in the
case when each of the vertices has both a
computing and a network resource. The choice
of the method is due to strict limitations on the
max
time of execution of the functions.</p>
      <p>The choice of the most suitable strategy is
made to preserve the functionality, so each
vertex checks the list of actions to ensure the
performance of the set functions.
During the execution of a new cycle by the
system, the vertices analyze the results of the
changes
made to
the
and
calculate new combinations of functions and
their possible additional evaluation.</p>
      <p>Therefore, the IS network is organized in
such a way that allows  and vertices to make
decisions independently, refusing centralized
management and ensuring efficient operation
in conditions of functional degradation.</p>
      <p>We will describe the steps of the algorithm
of
functional
reconfiguration
of
the
hierarchical
network
of the information
system in real-time.</p>
      <p>2. The vertex</p>
      <p>We fix the start time   .</p>
      <p>is determined for the
implementation of the configuration,
by selecting neighboring vertices and
some remote vertices of the same
functional level, which can perform the
same functions and between
which
connections are formed. In addition,
the number of neighboring vertices is
inversely proportional to the number
of remote ones.
3. The
vertices
selected in
step 2
exchange the matrices of functioning</p>
      <p>,   ) and matrices of functional
possibilities ℳм( 
,   ).
4. It is determined which of the functions
placed on the vertex q_fi, it is capable of
performing:
,   ) = ℳф(</p>
      <p>,   )
× ℳм( 
,   ).
5. The number of tasks for the vertex  
that it can perform is determined by
the formula:</p>
      <p>ℛ = ∑
and
their</p>
      <p>connections
initiated. If a solution is found, the
search result is implemented in steps
7–9,
otherwise,
the
results
is
of
calculations from the neighboring node
are expected.
7. The reference point for performing the
is determined.</p>
      <p>genetic method for the  max problem
8. The solutions of the  max the problem
is
supplemented
by
restrictions
imposed on the choice of configuration
and
the
volume
of tasks
to
be
performed. At the same time, the
genetic method is used, since these
constraints require an increase in
computing
resources
and
time
to
search for a solution, and the result is
no worse than the initial one.
9. Checking the maximum possible time
for the implementation of the solution:
 ( + 1) − (  +  ∗)

&gt;   .</p>
      <p>(18)
10. Calculation results are exchanged.
11. The top with the highest additional
score is determined. If there is more
than one such vertex, then the vertex
that initiated the reconfiguration is
12. The</p>
      <p>reconfiguration process is in
selected.</p>
      <p>progress.
13. Updating information in the vertices of
the zero level of the hierarchy for each
of the changed tasks.</p>
      <p>The
block
diagram
of the described
algorithm is shown in Fig. 4.</p>
      <p>Let’s
evaluate
the
correctness of the
algorithm. Critically important steps in the
real-time
hierarchical
network
functional
reconfiguration
algorithm
are
the
sixth
through the eighth. In this case, the completion
of the cycle is possible only when (19) is
executed. That is, correctness is determined by
the following conditions:
where


reconfiguration, 

 ≠ ∞, 
is
the
≠ 0,
period</p>
      <p>(19)
of functional
is the number of counter
steps in the genetic method.</p>
      <p>Since the conditions are checked in step 9, but
first for the genetic</p>
      <p>method, then (19) are
performed regardless of the obtained result.</p>
      <p>Algorithm</p>
      <p>complexity assessment. For a
complete search of all possible configurations,
the complexity of the solution is defined as
 (2 ), but it is rational to implement it only for
small values of  . For large values of  , a
genetic</p>
      <p>method is used, the complexity of
which is limited by the number of operations.
Thus, the complexity of the calculation for one
step can be defined as  ( 2). In steps 2–3, the
complexity of the method is  ( ) for each of
them, which in sum gives  (2 ).</p>
      <p>
        Then,
with
a
complete
search, the
complexity is  (2 + 2 2
) and
genetic method, it is  (2 + 2 2).
with the
(
        <xref ref-type="bibr" rid="ref16">16</xref>
        )
(17)
The other steps do not significantly affect the
computational complexity.
      </p>
      <p>The accuracy of the algorithm depends on
the time of determination of the decision by the
genetic method.</p>
    </sec>
    <sec id="sec-14">
      <title>5. Conclusions</title>
      <p>The conducted analysis of the requirements for
functionally stable information systems
revealed the expediency of implementing
software-defined wide area networks, which
help ensure security, productivity, reliability,
providing flexibility and manageability to
network services.</p>
      <p>A method of ensuring the functional
stability of the information system using
software-defined wide area networks has been
developed, which differs from the existing ones
in that it is based on the detection of
destabilizing factors and the reconfiguration of
the information system network into which the</p>
      <p>Prisma Access solution is integrated.
The use of this method helps ensure the
functional stability of the information system by
ensuring availability, integrity, confidentiality,
and protection against unauthorized access, as
well as preserving network bandwidth.
[17] V. Zavgorodnii, et al., Methods and Int. J. Thermofluids (2024) 100580. doi:
Models for Assessment of Reliability of 10.1016/j.ijft.2024.100580.
Structural-Complex Systems, World Sci. [26] O. Dodonov, M. Kuznetsova, O. Horbachyk,
(2018) 5–14. doi: 10.31435/rsglobal_ Survivability of Complex Systems:
ws/30112018/6227. Analysis and Modeling, 2nd ed.,
[18] O. Mashkov, et al., Application of the Polytechnic (2009).</p>
      <p>Theory of Functional Stability in the [27] S. Gao, J. Wang, J. Zhang, Reliability
Problems of Covering Territories by Analysis of a Redundant Series System
Sensory Networks, Lecture Notes on with Common Cause Failures and
Data Engineering and Communications Delayed Vacation, Reliability Eng. Syst.
Technologies 149 (2023) 266–285. doi: Safety (2023),109467. doi: 10.1016/j.
10.1007/978-3-031-16203-9_16. ress.2023.109467.
[19] V. Sobchuk, et al., Methodology for</p>
      <p>Building a Functionally Stable Intelligent
Information System of a Manufacturing
Enterprise, Bulletin of the Taras
Shevchenko National University of Kyiv,
Physics and Mathematics 4 (2021) 116–
127. doi: 10.17721/1812-5409.2021/4.</p>
      <p>18.
[20] V. Sobchuk, I. Zamrii, S. Laptiev,</p>
      <p>Ensuring Functional Stability of
Technological Processes as
Cyberphysical Systems Using Neural
Networks, Smart Technologies in Urban
Engineering, LNNS 536 (2023) 581–592.</p>
      <p>doi: 10.1007/978-3-031-20141-7_53.
[21] J. Castañeda, et al., VNF-Based Network</p>
      <p>Service Consistent Reconfiguration in
Multi-Domain Federations: A
Distributed Approach, J. Netw. Comput.</p>
      <p>Appl. (2021) 103226. doi:
10.1016/j.jnca.2021.103226.
[22] S. Meskina, et al., Reconfiguration-Based</p>
      <p>Methodology for Improving Recovery
Performance of Faults in Smart Grids, Inf.</p>
      <p>Sci. (2018) 73–95. doi: 10.1016/j.ins.</p>
      <p>2018.04.010.
[23] A. Zakharov, et al., A Performance</p>
      <p>Optimization Algorithm for Controller
Reconfiguration in Fault Tolerant
Distributed Model Predictive Control, J.</p>
      <p>Process Control (2015) 56–69. doi:
10.1016/j.jprocont.2015.07.006.
[24] S. Latif, et al., AI-Empowered, Blockchain
and SDN Integrated Security
Architecture for IoT Network of Cyber
Physical Systems, Comput. Commun.
(2021) 274–283. doi: 10.1016/j.</p>
      <p>comcom.2021.09.029
[25] Y. Yuan, et al., Model Exploration of Grid</p>
      <p>Adjustment and Restoration Strategy
Based on Intelligent Decision System,</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <source>[1] [2] [3] [4] [5] [6]</source>
          [7]
          <string-name>
            <given-names>F.</given-names>
            <surname>Kipchuk</surname>
          </string-name>
          , et al.,
          <source>Assessing Approaches of IT Infrastructure Audit, in: IEEE 8th International Conference on Problems of Infocommunications, Science and Technology</source>
          (
          <year>2021</year>
          ). doi:
          <volume>10</volume>
          .1109/ picst54195.
          <year>2021</year>
          .
          <volume>9772181</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <given-names>V.</given-names>
            <surname>Buriachok</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Sokolov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Skladannyi</surname>
          </string-name>
          ,
          <article-title>Security Rating Metrics for Distributed Wireless Systems</article-title>
          ,
          <source>in: Workshop of the 8th International Conference on “Mathematics. Information Technologies. Education:” Modern Machine Learning Technologies and Data Science</source>
          , vol.
          <volume>2386</volume>
          (
          <year>2019</year>
          )
          <fpage>222</fpage>
          -
          <lpage>233</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <given-names>P.</given-names>
            <surname>Anakhov</surname>
          </string-name>
          , et al.,
          <article-title>Protecting Objects of Critical Information Infrastructure from Wartime Cyber Attacks by Decentralizing the Telecommunications Network</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3550</volume>
          (
          <year>2023</year>
          )
          <fpage>240</fpage>
          -
          <lpage>245</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <given-names>H.</given-names>
            <surname>Hulak</surname>
          </string-name>
          , et al.,
          <article-title>Dynamic Model of Guarantee Capacity and Cyber Security Management in the Critical Automated System</article-title>
          ,
          <source>in: 2nd International Conference on Conflict Management in Global Information Networks</source>
          , vol.
          <volume>3530</volume>
          (
          <year>2023</year>
          )
          <fpage>102</fpage>
          -
          <lpage>111</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <string-name>
            <given-names>V.</given-names>
            <surname>Grechaninov</surname>
          </string-name>
          , et al.,
          <source>Formation of Dependability and Cyber Protection Model in Information Systems of Situational Center, in: Workshop on Emerging Technology Trends on the Smart Industry and the Internet of Things</source>
          , vol.
          <volume>3149</volume>
          (
          <year>2022</year>
          )
          <fpage>107</fpage>
          -
          <lpage>117</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          3188, no.
          <issue>2</issue>
          (
          <year>2022</year>
          )
          <fpage>197</fpage>
          -
          <lpage>206</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <string-name>
            <given-names>P.</given-names>
            <surname>Johnson</surname>
          </string-name>
          , et al.,
          <source>Digital Innovation and the Effects of Artificial Intelligence on Firms' Research and DevelopmentAutomation or Augmentation</source>
          ,
          <source>Exploration or Exploitation? Technol. Forecast. Social Change</source>
          <volume>179</volume>
          (
          <year>2022</year>
          )
          <article-title>121636</article-title>
          . doi:
          <volume>10</volume>
          .1016/j.techfore.
          <year>2022</year>
          .
          <volume>121636</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>K.</given-names>
            <surname>Basu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Hamdullah</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Ball</surname>
          </string-name>
          ,
          <article-title>Architecture of a Cloud-based FaultTolerant Control Platform for improving the QoS of Social Multimedia Applications on SD-WAN, 13th</article-title>
          <source>International Conference on Communications (COMM)</source>
          (
          <year>2020</year>
          )
          <fpage>495</fpage>
          -
          <lpage>500</lpage>
          . doi:
          <volume>10</volume>
          .1109/COMM48946.
          <year>2020</year>
          .
          <volume>9142038</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>G.</given-names>
            <surname>Blokdyk</surname>
          </string-name>
          ,
          <string-name>
            <surname>Software-Defined WAN SDWAN A Clear and Concise Reference</surname>
          </string-name>
          ,
          <year>5STARCooks</year>
          (
          <year>2018</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>G.</given-names>
            <surname>Blokdyk</surname>
          </string-name>
          ,
          <string-name>
            <surname>SD-WAN A Complete Guide</surname>
          </string-name>
          ,
          <year>5STARCooks</year>
          (
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>O.</given-names>
            <surname>Lemeshko</surname>
          </string-name>
          , et al., Research of Improved Traffic Engineering FaultTolerant Routing Mechanism in
          <string-name>
            <surname>SDWAN</surname>
          </string-name>
          ,
          <source>IEEE 3rd Ukraine Conference on Electrical and Computer</source>
          Engineering (UKRCON) (
          <year>2021</year>
          )
          <fpage>187</fpage>
          -
          <lpage>190</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>V.</given-names>
            <surname>Oglih</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Patoka</surname>
          </string-name>
          ,
          <article-title>Formation of Information Security System Under Conditions of Uncertainty of Influence of Destabilization Factors on the Basis of Neurofacle Networks, Econom</article-title>
          .
          <source>Scope</source>
          (
          <year>2022</year>
          )
          <fpage>76</fpage>
          -
          <lpage>81</lpage>
          . doi:
          <volume>10</volume>
          .32782/
          <fpage>2224</fpage>
          - 6282/
          <fpage>177</fpage>
          -
          <lpage>13</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>P.</given-names>
            <surname>Zuiev</surname>
          </string-name>
          , et al.,
          <article-title>Development of Complex Methodology of Processing Heterogeneous Data in Intelligent Decision Support Systems</article-title>
          ,
          <source>EasternEuropean J. Enterprise Technol</source>
          . (
          <year>2020</year>
          )
          <fpage>14</fpage>
          -
          <lpage>23</lpage>
          . doi:
          <volume>10</volume>
          .15587/
          <fpage>1729</fpage>
          -
          <lpage>4061</lpage>
          .
          <year>2020</year>
          .
          <volume>208554</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>S.</given-names>
            <surname>Yevseiev</surname>
          </string-name>
          , et al.,
          <source>Synergy of Building Cybersecurity Systems</source>
          (
          <year>2021</year>
          ). doi:
          <volume>10</volume>
          .15587/
          <fpage>978</fpage>
          -617-7319-31-2.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>D.</given-names>
            <surname>Denyer</surname>
          </string-name>
          , et al.,
          <source>Exploring Reliability in Information Systems Programmes, Int. J. Project Manag</source>
          . (
          <year>2011</year>
          )
          <fpage>442</fpage>
          -
          <lpage>454</lpage>
          . doi:
          <volume>10</volume>
          .1016/j.ijproman.
          <year>2011</year>
          .
          <volume>02</volume>
          .002.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>W.</given-names>
            <surname>Zheng</surname>
          </string-name>
          , et al.,
          <article-title>Robust Stability Analysis and Feedback Control for Networked Control Systems with Additive Uncertainties and Signal Communication Delay Via Matrices Transformation Information Method, Inf</article-title>
          . Sci. (
          <year>2022</year>
          )
          <fpage>258</fpage>
          -
          <lpage>286</lpage>
          . doi:
          <volume>10</volume>
          .1016/j.ins.
          <year>2021</year>
          .
          <volume>09</volume>
          . 005.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>