<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Methods of Modeling Database System Security</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Svitlana Rzaieva</string-name>
          <email>rzaiev@kneu.edu.ua</email>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Dmytro Rzaiev</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Yuliya Kostyuk</string-name>
          <email>kostyuk_yu@knute.edu.ua</email>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Hennadii Hulak</string-name>
          <email>h.hulak@kubg.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oleksandr Shcheblanin</string-name>
          <email>oleksandr.shcheblanin@gmail.com</email>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Borys Grinchenko Kyiv Metropolitan University</institution>
          ,
          <addr-line>18/2 Bulvarno-Kudriavska str., Kyiv, 04053</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Kyiv National Economic University of Kyiv</institution>
          ,
          <addr-line>54/1 Beresteysky prospect, Kyiv, 030</addr-line>
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>State University Of Trade And Economics of Kyiv</institution>
          ,
          <addr-line>19 Kyoto str., Kyiv, 02156</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>University Passau</institution>
          ,
          <addr-line>41 Innstraße, Passau, 94032</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
      </contrib-group>
      <fpage>384</fpage>
      <lpage>390</lpage>
      <abstract>
        <p>Ensuring the protection of information stored in databases from unauthorized access, loss, and damages, as well as ensuring the confidentiality, integrity, and availability of data is a fundamental task of database security. The article explores the identification of potential threats and their analysis, the determination of possible consequences, and the development of protection strategies to prevent these threats. The identification of threats is closely linked to the process of threat modeling to enhance the security of databases. The article explores various threat modeling methods, such as threat analysis, scenario modeling, mathematical modeling, vulnerability analysis, risk analysis, and others. Each of these methods helps determine which threats may impact the database system and what security measures can be taken to prevent them. The article also describes a security model for a database system, including data vulnerability analysis, attack modeling, analysis of data from previous attacks, access rights analysis, determination of protective measures, and security method testing. This model serves as a tool for effectively managing risks and ensuring information security in today's world, where cyber threats are becoming increasingly serious and widespread.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Database security</kwd>
        <kwd>potential threat identification</kwd>
        <kwd>threat modeling</kwd>
        <kwd>vulnerability analysis</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Methods for modeling the security of database
systems are recognized as extremely
important in the modern digital world, where
information has become one of the most
valuable assets for many organizations and
institutions. The increasing volume and
significance of data for business and scientific
research make databases a target for various
cyber threats. Attackers actively seek to gain
access to this valuable information, making
data protection a serious daily task for every
organization. The rapid development of
technologies such as cloud computing and the
Internet of Things (IoT) expands the range of
attacks on database systems and creates new
opportunities for malicious actors,
emphasizing the importance of developing
effective security modeling methods [
        <xref ref-type="bibr" rid="ref1 ref2 ref3">1–3</xref>
        ].
      </p>
      <p>
        High public and regulatory attention to data
privacy protection, such as the General Data
Protection Regulation (GDPR) in the EU,
imposes significant requirements on companies
and organizations regarding the protection of
personal data. This necessitates project
developers to design and implement effective
modeling and risk management methods to
ensure compliance with relevant legislation [
        <xref ref-type="bibr" rid="ref4 ref5">4,
5</xref>
        ].
      </p>
      <sec id="sec-1-1">
        <title>The increasing level of professionalism</title>
        <p>
          among cybercriminals and the complexity of
attacks underscore the need for continuous
improvement of security measures [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. The
relevance of the article lies in the development
and enhancement of threat modeling methods
for the timely detection and prevention of that is, dangerous events or situations that may
attacks on database systems [
          <xref ref-type="bibr" rid="ref7 ref8">7, 8</xref>
          ]. occur and lead to loss, damage, or
unauthorized access to information stored in
2. Previous Research the database. These threats can include various
aspects, such as technical attacks from
In [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ], various threats faced by almost all intruders, software bugs, improper security
software systems are discussed as technologies settings, natural disasters, or internal threats
evolve. These threats can originate from from employees. To effectively manage these
external or internal sources, and their impact potential risks, it is necessary to identify them,
can be devastating. Systems may cease to understand their possible consequences, and
function entirely, or there may be a leakage of develop protection strategies.
confidential information, affecting consumer Identifying potential threats is closely
trust in the system provider. To prevent the related to the process of threat modeling to
exploitation of system vulnerabilities by improve database security. The first step in
threats, the authors suggest using threat this process is to identify the various possible
modeling methods to think defensively. threats that may arise in the context of the
[
          <xref ref-type="bibr" rid="ref10">10</xref>
          ] addresses security issues in enterprise database. This includes analyzing external and
systems based on the MITRE Enterprise internal factors that can create potential risks
ATT&amp;CK matrix. This matrix focuses on to information security. This analysis may
describing system assets, attack steps, defense include assessing potential attacks, identifying
mechanisms, and asset associations. The entity- system vulnerabilities, and assessing the
relationship model describes enterprise IT possible consequences of possible threats to
systems as a whole, using available tools, the confidentiality, integrity, and availability of
allowing the simulation of attacks on instances data.
of the system model. These simulations can be Once identified, threats can be used to
used to investigate security configurations and create a threat model that describes their
architectural changes for more effective system nature, potential attack vectors, and risk
protection. assessment. The threat model can then be used
[
          <xref ref-type="bibr" rid="ref11">11</xref>
          ] explores traditional approaches to to develop protection strategies, prioritize
threat modeling, such as Microsoft’s STRIDE, security measures, and establish access control
where Data Flow Diagrams (DFD) are used as rules to help prevent or mitigate potential
the primary input material for threat analysis. threats. Thus, identifying potential threats and
[
          <xref ref-type="bibr" rid="ref12">12</xref>
          ] discusses various threats and modeling them are key steps in implementing
vulnerabilities that may arise in the effective database security measures.
development, management, and maintenance of Threat modeling methods are approaches
different databases and database management and techniques used to analyze identified
systems. The article aims to analyze the threats and risks in the areas of security,
described threats and provide the most information security, cybersecurity, and other
appropriate solutions for database security. fields. These methods help to assess what
threats may affect an organization, system, or
project, and what measures can be taken to
3. Issues prevent or mitigate those threats. Here are
some basic threat modeling techniques.
        </p>
        <p>The threat analysis method includes the
identification of existing threats, their
characteristics, and the ability to affect the
system or organization. Standard SWOT
analysis (analysis of strengths, weaknesses,
opportunities, and threats) and other
approaches to identify threats.</p>
        <p>The scenario modeling method provides the
creation of various scenarios based on known
threats and their impact. Scenarios help to
Database system security includes a wide
range of issues and aspects aimed at protecting
data stored in the database from unauthorized
access, loss, damage, confidentiality, integrity,
and availability of data. Database security
includes the identification of potential threats
and the development of protection measures
to prevent these threats.</p>
        <p>Identification of potential threats is the
process of identifying and analyzing various
possible threats, both external and internal,
prepare action plans for different possible
conditions.</p>
        <p>Mathematical modeling is used to analyze
threats and their impact on systems, including
modeling probable threat cases, identifying
risks, and calculating possible losses.</p>
        <p>Vulnerability analysis method—assesses
existing vulnerable systems or organizations
that can be exploited by attackers to implement
a threat. After identifying vulnerabilities,
protection strategies are developed.</p>
        <p>The risk analysis method involves assessing
the likelihood of threats and the impact of
these threats on a system or organization. As a
result of risk analysis, specific risks and their
level of danger can be identified.</p>
        <p>The attack modeling method provides a
simulation-type attack model. Simulation
confirms what methods can be used by
attackers to interfere with the system and how
it can affect its operation.</p>
        <p>Creating a risk matrix, developed to
systematize and compare different risks based
on their probabilistic nature and impact on the
system. This allows the authorized person to
make decisions about the prioritization of risk
management.</p>
        <p>The protection cost analysis method
estimates the costs that may be associated with
preventing or remediating the consequences of
threats. By taking into account the costs, the
authorized person can make informed
decisions about investing in security controls.</p>
        <p>Business impact analysis method—this
method assesses the possible consequences of
a threat and its impact on the organization’s
operations. Taking this impact into account,
the organization can develop strategies to
ensure business continuity.</p>
        <p>Monitoring and updating. Threat and risk
models need to be constantly updated, after
which new threats are reflected, and known
threats can change the existing characteristics.</p>
        <p>It is also important to monitor and evaluate the
effectiveness of protection measures to ensure
that they are effective.</p>
        <p>Threat modeling techniques are an
important part of a risk management and
security strategy in today’s world, where cyber
threats and other forms of threats are becoming
increasingly complex and widespread.</p>
        <p>Database security modeling is an essential
aspect of ensuring the security of information
and data. It helps identify external and internal
threats to the database system and develop
strategies for their protection. For a better
understanding of the methods of modeling
database security, the authors used the tools of
the Mind Map programming platform to
construct a corresponding model. This model
consists of the following key modeling methods:
1. Data vulnerability analysis.
2. Database attack modeling.
3. Analysis of data on previous attacks.
4. Database access rights analysis.
5. Determination of protective measures
and the creation of a response plan to
external and internal threats.</p>
        <p>6. Security methods testing.
Let’s delve into each modeling method in the
model of threats. Data Vulnerability Analysis
involves addressing identified weaknesses in
the isolation and protection of data in the
database system. The first step in data
vulnerability analysis is identifying potential
vulnerabilities in the database system, such as
software deficiencies, inadequate access rules,
or insufficient password protection. This stage
includes the following steps:
• Conducting a system scan to identify
vulnerabilities in the database
configuration and software.
• Evaluating security parameters, including
access rights, password policies, table
and view access permissions, file settings,
and other database security parameters.
• Identifying potential threats that could be
used to breach the database system,
including external and internal attacks, as
well as other threat scenarios.
• Assessing the impact of vulnerabilities on After simulating attacks, an assessment of
the database system and their likelihood, the effectiveness of the defense measures is
and identifying critical vulnerabilities conducted to identify the most effective
requiring immediate resolution. current security measures for the database
• Determining specific measures to address system. This helps identify problematic areas
vulnerabilities, including patches, and weaknesses that need improvement.
software updates, changes to access Using Results to Enhance Database Security.</p>
        <p>The final step in the attack modeling process is
rights, and other measures. seeking ways to improve the protection of the
• Developing a plan and setting priorities database system. Based on the obtained
for implementing recommendations to results, decisions can be made regarding
ensure a phased improvement in data enhancing security policies, making changes to
security. software, implementing security monitoring,
Attack Modeling on a database system and even increasing user awareness regarding
involves the process of defining and simulating data security.
potential attacks on the database system. In Attack modeling on a database system
attack modeling, a model is created that occurs during the information security
generates the process of system intrusion, how provisioning stage, assuming that threats can
attackers may attempt to breach the system, impact the system and how these impacts can
and the methods they may use. This process be prevented or mitigated.
may include SQL injections, session hijacking, Data analysis of previous attacks is a
password attacks, exploiting software process of studying and analyzing information
vulnerabilities, and more. This approach about previous attacks or security incidents
provides a deep understanding of potential that occurred in a database system or similar
threats and identifies weaknesses in the organizations. This stage concludes with
database system’s security. Let’s explore this obtaining valuable experience and insights
process in more detail. that can be used to enhance future protection.</p>
        <p>The first step in the attack modeling process This method includes the following steps:
is defining selected attacks, which means • Collecting data on previous attacks,
identifying various types of attacks that may be incidents, or security events that
involved in malicious attempts to breach the occurred in the database system or other
database system. This may include external similar organizations. The process may
attacks such as SQL injections, session hijacking, involve information from event log
and password attacks, as well as insider attacks records, incident reports, investigation
involving malicious actions by employees or
unauthorized users. results, etc.</p>
        <p>The next step in the attack modeling process • Analyzing typical attack scenarios,
is developing attack scenarios. Detailed where typical attack scenarios identified
scenarios must be created for each identified in previous incidents are studied. this
attack, describing how the attack may occur. includes an analysis of the methods used
This includes the sequence of actions needed for by attackers to infiltrate the system,
a successful attack, including SQL queries that their objectives, and goals.
may be used and other critical details. • Identifying common vulnerabilities</p>
        <p>Another crucial step is assessing the impact involves the analysis of common
of the attack, meaning evaluating the impact of vulnerabilities or weaknesses exploited
each attack on the database system, including by attackers in previous attacks, and
aspects of data confidentiality, integrity, and identifying patterns indicating specific
availability. types of vulnerabilities that require
Attack Simulation. At this stage, simulation
tools and techniques are used to reproduce attention.
attack scenarios in a controlled environment. • Studying and analyzing the scale of
Specialized tools can be employed to execute damage caused by previous attacks,
SQL injections or session hijacking to verify if including data loss, recovery costs, and
such intrusions are possible. other consequences. this analysis helps
improve risk assessment and make
decisions regarding security measures.
• Evaluating the effectiveness of
implemented measures, where the
effectiveness of security measures
implemented as a result of previous
incidents is analyzed. studying this step
helps improve and/or rectify security
flaws in the database system.
• Developing a security improvement
plan, which includes improvement
procedures, implementation of new
technologies and security measures, as
well as staff training.</p>
        <p>Continuous monitoring and updating of
information about previous attacks should be
carried out by the security service or database
administrator. This process allows for timely
responses to new threats and keeps the
database system secure.</p>
        <p>The analysis of data from previous attacks is
a component of enhancing the security of
database systems, after which problematic
areas need to be identified and informed
decisions regarding protective measures made.</p>
        <p>Access rights analysis in a database system
is the process of assessing and verifying the
rights of users, user groups, and objects in
databases. The assessment of access rights to
the database, as well as control over them, is
the culmination of the stage. It is crucial to
verify who has access to the database, and
what actions they can perform, and severely
restrict these rights.</p>
        <p>Identification of users and groups, which
verifies identification data such as user logins
and passwords, roles, and groups.</p>
        <p>Authorization of users and groups, which
verifies access rights to database objects,
determines the actions users can perform in
the database system, such as reading, writing,
deleting, or modifying data, taking into account
access levels and restrictions for different
users and roles.</p>
        <p>Access audit of database systems, which
involves configuring the audit system to log
access events to the database, including user
logins and logouts, data changes, and other
actions.</p>
        <p>Monitoring and analysis of users include:
• Monitoring and analyzing audit events to
detect suspicious or unusual activities.</p>
        <p>• Continuous monitoring of user actions</p>
        <p>for abnormal or unusual activities.
• Analysis and response to negative
actions, such as unauthorized access
attempts or data modifications.</p>
        <p>In light of the previous two processes
(access auditing and user monitoring), the
database system administrator needs to
constantly review access rights, periodically
checking and updating user and group access
rights to changes in the organization, role
structure, and security needs. It is important to
remove or modify access rights for users who
should no longer have access to the system.</p>
        <p>Access rights analysis is a key component of
ensuring the security of the database system,
as it allows control and tracking of user access
to data and protects the system from potential
internal threats.</p>
        <p>The method of determining protective
measures and creating a response plan for
external and internal threats. After identifying
threats and assessing risks, a protection plan
should be developed. Determining protective
measures is a step in ensuring the security of
the database system and answers the question,
“How will we protect our data and
infrastructure from external and internal
threats?”</p>
        <p>Determining protective measures is a stage
in the risk modeling process where specific
measures and strategies to reduce risk are
defined to ensure the security of the database
system. This stage requires careful analysis and
planning and may include the following actions:
selecting database protection measures,
defining the responsibilities of security
personnel, assessing the cost and resources of
protection, and developing an implementation
schedule for protective measures.</p>
        <p>The selection of database protection
measures involves defining specific security
measures and technologies that can be
implemented to protect the database system.</p>
        <p>This may include network protection, data
encryption, authentication systems, and other
measures.</p>
        <p>Defining the responsibilities of security
personnel involves assigning responsible
individuals who will manage, implement, and
monitor the security measures developed by
the specified legislation for database security.</p>
      </sec>
      <sec id="sec-1-2">
        <title>The assessment of the cost and resources of</title>
        <p>protection involves evaluating the costs
associated with the implementation of selected
security measures. This includes the cost of
technologies, processes, personnel training,
and other resources.</p>
        <p>The development of an implementation
schedule for protective measures is created to
determine the timeframes for the
implementation plan of necessary security
measures and the sequence of their
implementation, prioritizing security measures
according to their importance and deadlines.</p>
        <p>The incident response plan is a documented
set of procedures and actions to ensure the
security of operations in the event of a security
incident. Creating an incident response plan
involves developing a plan of action in the
event of the detection of threats or security
incidents, including recovery procedures and a
return to normal operation. Such a plan
includes the following elements:
• identification of incidents, defining what
constitutes a security incident, and the
events or actions that should trigger the
activation of the response plan.
• response procedures for incidents,
including a detailed description of the
steps to be taken in the event of an
incident, including contact persons to be
notified and the sequence of actions to
stop the incident and minimize damage.
• recovery plan detailing step-by-step
actions for restoring normal operations
after an incident. the improvement plan
for security measures involves changing
the security strategy, if necessary, based
on updated risk data, in response to
changes in threats and technologies.
• training and qualification enhancement
for personnel regarding new security
measures and security procedures for
database systems.</p>
        <p>Security testing is a fundamental process
during which various types of attacks and
intentional actions are carried out on a system
to verify its resilience and the effectiveness of
security measures, and to check its
vulnerability and stability.</p>
        <p>Examining security methods for database
systems involves.</p>
        <p>Penetration testing, where security experts
attempt to enter the database using various
attack methods, including SQL injections,
session hijacking, authentication attacks, etc.</p>
        <p>Vulnerability analysis involves identifying
vulnerabilities and weaknesses in the database
system that could be exploited by attackers.</p>
        <p>Testing and assessing the effectiveness of
protection involves conducting tests and
checks of new security measures to determine
their effectiveness and compliance with
security requirements; addressing identified
issues and improving security measures based
on test results.</p>
        <p>Testing also includes evaluating responses
to incidents, assessing the system’s protection,
and how it reacts to different incidents. This
evaluation includes checking the functionality
of the event logging system and its monitoring.</p>
        <p>Based on the results of security testing, plans
for fixes and improvements are developed to
eliminate identified vulnerabilities and enhance
the security system. Continuous monitoring of
security measures for abnormal activities and
threat analysis, along with data analysis on
security measures, allows for ongoing response
to new threats.</p>
        <p>Continuous Monitoring and Updates.
Continuous monitoring and updates are
extremely important aspects of ensuring the
security of a database system. The database
system needs to be constantly monitored to
detect abnormal events and vulnerabilities.
This may include monitoring event logs,
analyzing network traffic, and other methods.
The goal is to detect certain threats and
respond to them before they can cause harm.
Continuous monitoring and updates ensure
that the database system remains resilient to
new threats and provides a high level of data
security. This allows organizations to operate
in a reliable and secure environment, reducing
the risks of data leaks and enhancing security.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>4. Conclusions</title>
      <sec id="sec-2-1">
        <title>Security modeling methods for database</title>
        <p>systems are a crucial component of
contemporary practical information security.
Analyzing data vulnerabilities helps identify
weak points that malicious actors could exploit
for unauthorized data access or database
manipulation. Modeling attacks on the
database system extends this analysis, aiding
in predicting methods and strategies that
attackers might employ.</p>
        <p>Analyzing data from past attacks and
incidents serves as a valuable source of
information for studying patterns and threats
targeting database systems. Approaches to
access rights analysis assist in managing user
privileges and developing access restriction
strategies for database objects. Risk modeling
and the identification of protective measures
help assess existing threats and formulate
plans to mitigate risks and enhance the
security level of the database system.</p>
        <p>Continuous monitoring and updates are
essential since threats constantly evolve, and
database systems must be prepared to detect
and respond to incidents, as well as update
security measures to adapt to new threats.
These practices ensure reliable information
protection and support data security in the
modern information environment.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>I.</given-names>
            <surname>Kuzminykh</surname>
          </string-name>
          , et al.,
          <article-title>Investigation of the IoT Device Lifetime with Secure Data Transmission, Internet of Things, Smart Spaces, and Next Generation Networks and Systems</article-title>
          , vol.
          <volume>11660</volume>
          (
          <year>2019</year>
          )
          <fpage>16</fpage>
          -
          <lpage>27</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>030</fpage>
          -30859-
          <issue>9</issue>
          _
          <fpage>2</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>V.</given-names>
            <surname>Sokolov</surname>
          </string-name>
          , et al.,
          <article-title>Method for Increasing the Various Sources Data Consistency for IoT Sensors</article-title>
          , in: IEEE 9th International Conference on Problems of Infocommunications,
          <source>Science and Technology (PICST)</source>
          (
          <year>2023</year>
          )
          <fpage>522</fpage>
          -
          <lpage>526</lpage>
          . doi:
          <volume>10</volume>
          .1109/PICST57299.
          <year>2022</year>
          .
          <volume>10238518</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Hu</surname>
          </string-name>
          , et al.,
          <source>Bandwidth Research of Wireless IoT Switches, in: IEEE 15th International Conference on Advanced Trends in Radioelectronics, Telecommunications and Computer Engineering</source>
          (
          <year>2020</year>
          ). doi:
          <volume>10</volume>
          .1109/tcset49122.
          <year>2020</year>
          .2354922
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>F.</given-names>
            <surname>Kipchuk</surname>
          </string-name>
          , et al.,
          <source>Assessing Approaches of IT Infrastructure Audit, in: IEEE 8th International Conference on Problems of Infocommunications, Science and Technology</source>
          (
          <year>2021</year>
          ). doi:
          <volume>10</volume>
          .1109/ picst54195.
          <year>2021</year>
          .9772181
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>H.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <source>Information Security Risk Analysis SWOT, Cybersecurity Providing in Information and Telecommunication Systems</source>
          <volume>2923</volume>
          (
          <year>2021</year>
          )
          <fpage>309</fpage>
          -
          <lpage>317</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>V.</given-names>
            <surname>Grechaninov</surname>
          </string-name>
          , et al.,
          <article-title>Decentralized Access Demarcation System Construction in Situational Center Network</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems II</source>
          , vol.
          <volume>3188</volume>
          , no.
          <issue>2</issue>
          (
          <year>2022</year>
          )
          <fpage>197</fpage>
          -
          <lpage>206</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>V.</given-names>
            <surname>Astapenya</surname>
          </string-name>
          , et al.,
          <article-title>Last Mile Technique for Wireless Delivery System using an Accelerating Lens</article-title>
          , in: 2020 IEEE International Conference on Problems of Infocommunications.
          <source>Science and Technology</source>
          (
          <year>2020</year>
          ). doi:
          <volume>10</volume>
          .1109/picst51311.
          <year>2020</year>
          .
          <volume>9467886</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>V.</given-names>
            <surname>Astapenya</surname>
          </string-name>
          , et al.,
          <article-title>Analysis of Ways and Methods of Increasing the Availability of Information in Distributed Information Systems</article-title>
          , in: 2021
          <source>IEEE 8th International Conference on Problems of Infocommunications, Science and Technology</source>
          (
          <year>2021</year>
          ). doi:
          <volume>10</volume>
          .1109/ picst54195.
          <year>2021</year>
          .
          <volume>9772161</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>N.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <source>Threat Modeling: A Summary of Available Methods</source>
          , Carnegie Mellon University Software Engineering Institute Pittsburgh United States (
          <year>2018</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>W.</given-names>
            <surname>Xiong</surname>
          </string-name>
          , et al.,
          <source>Cyber Security Threat Modeling Based on the MITRE Enterprise ATT&amp;CK Matrix, Softw. Syst. Modeling</source>
          <volume>21</volume>
          (
          <issue>1</issue>
          ) (
          <year>2022</year>
          )
          <fpage>157</fpage>
          -
          <lpage>177</lpage>
          . doi:
          <volume>10</volume>
          .1007/s10270-021-00898-7.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>V.</given-names>
            <surname>Grechaninov</surname>
          </string-name>
          , et al.,
          <article-title>Decentralized Access Demarcation System Construction in Situational Center Network</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems</source>
          II Vol.
          <volume>3188</volume>
          (
          <year>2022</year>
          )
          <fpage>197</fpage>
          -
          <lpage>206</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>V.</given-names>
            <surname>Pevnev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Kapchynskyi</surname>
          </string-name>
          . Database Security: Threats and
          <string-name>
            <given-names>Preventive</given-names>
            <surname>Measures</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Modern</given-names>
            <surname>Inf</surname>
          </string-name>
          .
          <source>Syst</source>
          .
          <volume>2</volume>
          (
          <issue>1</issue>
          ) (
          <year>2018</year>
          )
          <fpage>69</fpage>
          -
          <lpage>72</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>