<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Decision-making support of emergency risk identification in complex hierarchical control systems⋆</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Volodymyr Sabat</string-name>
          <email>v_sabat@ukr.net</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Bohdan Durnyak</string-name>
          <email>bohdan.durnyak@gmail.com</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Myroslava Kulynych</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Yurii Lozynskyi</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Pavlo Hibey</string-name>
          <email>pavlo.hibey@gmail.com</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Lviv State University of Internal Affairs</institution>
          ,
          <addr-line>26 Horodotska Str., Lviv, 79007</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Ukrainian Academy of Printing</institution>
          ,
          <addr-line>19 Pid Holoskom Str., Lviv, 79061</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>An analysis of a complex man-made hierarchical structure with an automated control and document management system is carried out in the conditions of active information and resource attacks, using the category algebra, which allows detecting attacks on a dynamic system, determining the risk levels of emergency situations and creating appropriate countermeasures. For the first time, the methodology of constructing categorical models for the representation of a dynamic hierarchical structure in the space of states is substantiated and developed, diagrams of energy-active objects of a dynamic system are provided, taking into account the effect of resource and information attacks on it, and methods of decision-making in emergency situations using risk assessment. For the first time, a structural diagram of the balance of the game between threats and control in the system is formed, taking into account the factors of threats and their influence on the objects of the system, on the basis of which a functional diagram of the information-resource hierarchy of the aggregated system control in the mode of countering threats is proposed. For the first time, the categorical diagram of an information attack is substantiated and the systemology of the formation of the object structure and the assessment of the dynamic state under resource threats and information attacks is proposed. As a result of the research, a hierarchical structure of the control system of the technological complex is formed under the risk of emergency situations, with the selection of security features of the document flow in the formation of control decisions at the techno-aggregate, operational administrative and strategic levels, which allows the use of the proposed methodology in the conditions of decision-making support during the functioning of complex hierarchical control systems.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Decision-making support</kwd>
        <kwd>categorical models</kwd>
        <kwd>man-made systems</kwd>
        <kwd>threats</kwd>
        <kwd>risk assessment</kwd>
        <kwd>hierarchical systems control</kwd>
        <kwd>1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>The structure of the hierarchical man-made control system has a complex organization, so it
is not an easy task to cover all aspects of its functioning, to present and identify
energyinformation connections. The problem is especially complicated if the dynamic system is
affected by negative factors in the form of information and resource attacks, which can lead to
uncontrolled changes in the state of aggregates and objects in the technological cycle of
system control. In addition, the action of information and infrastructure attacks of an
aggressive type can lead to the destruction of hierarchical connections and the system
structure, which, in turn, threatens the emergence of emergency situations with a high level
of accident risk. These problems are not fully solved both in the classical control theory and in
modern approaches based on system analysis. Only the use of the category algebra by
constructing diagrams of the structure of connections and determining the cores of influence
on the system space of states allows detecting attacks on a dynamic system and creating
means of countering possible attacks.</p>
      <p>To achieve the goal of scientific research, it is necessary to solve the following tasks:
•
•
•
•
to justify the use of the category algebra methods for solving the problems of
constructing the structures of hierarchical dynamic systems with complex connections
and under external negative influences;
to construct categorical structural diagrams of transformations in an energy-active
system under the threats, in the space of states and dynamics in time of a complex
system;
to propose a categorical representation of the model of threats to the system and to
develop a structural diagram of the game between threats and control in the system;
to develop a functional scheme of information-resource countermeasures against
threats in the hierarchy of the man-made system and the hierarchical structure of the
control system of the technological complex at risk.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Related works</title>
      <p>
        The analysis of the problem of emergency and risk situations under the influence of active
threats and attacks has shown the importance of building models for detecting attacks by the
way they affect system objects. The textbook of domestic scientists [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] substantiates the use of
risk assessment methods in determining the reliability of technical systems and humans,
reveals the basic concepts, essence, goals and methods of information protection;
multicriteria methods for assessing the correctness of decisions in crisis situations are considered in
the scientific work [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], which proposes a solution to this problem, which allows us to assert
that the decision was made correctly in this particular case when ensuring the information
security of a particular object; article [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] provides an overview of the concept of industry 4.0
concept with equivalent terms, basic technologies and reference structures for its
implementation, it is substantiated that this paradigm is a promising result of the merger and
integration of both existing and revolutionary technologies; categorized models for
representing the structure and dynamic state of hierarchical systems to identify attack factors
and risks are given in the collective work [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]; the theory of digital control systems that
describes the functionality of the system, explains the modeling process, presents a solution to
the problem, and discusses the results of hierarchical system management processes is
proposed in [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]; paper [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] presents research on assessing the occurrence of risk situations for
automated control systems of metallurgical enterprises under active threats and attacks. With
the help of the above-mentioned works, structural representations of hierarchical dynamic
systems with complex connections and under the influence of external attacks have been
developed, using also international standards in the field of information security [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], methods
of software and hardware protection of network technologies. based on big data [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] and
preventive security measures [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
      <p>
        The concept of smart manufacturing and its impact on the future automation of labor with
decision-making technology is proposed in [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. The author identifies three possible future
scenarios of production automation: digital production flows, self-organized production
network, and cloud-based production equipment as a service.
      </p>
      <p>
        The scientific article [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] describes methods for building risk models in a threat system using
semantic analysis of the text of documents for the presence of anomalies in their semantic
parameters. Paper [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] analyzes the concepts of risk and safety of subway passengers in cases of
malicious man-made incidents. As a result, using the example of the Athens subway system, the
importance of passenger protection to improve safety and avoid threatening conditions is
proved. These studies reveal the essence of hierarchical systems and their vulnerability to
manmade disasters under the influence of external attacks and internal threats.
      </p>
      <p>Modern developed methods for analyzing general industrial control systems for
hierarchical technogenic structures are presented in [13, 14]. Work [15] consider applied
decision support systems based on risk analysis of complex systems.</p>
      <p>Paper [16] presents the use of an object-oriented Bayesian network for scenario risk
assessment. A model of probabilistic coverage of key factors affecting accidents in
fragmented structures is developed. The study in [17] proposes a model-based methodology
for hybrid management of risk assessment of reliability, availability, maintainability, and
safety for critical systems. The result is a method for analyzing cybersecurity risks for
industrial control systems. Agrawal et al. [18] defined an ontology to represent ISO/IEC
27,005, 2018 standards to provide a step-by-step understanding of the meaning of security
concepts and their interrelationships. Researchers such as Blanco et al. [19] reviewed 31
security ontologies. Both studies group security ontologies into three categories: general,
specific, and theoretical.</p>
      <p>Two popular risk assessment methods tested for the nuclear industry use probabilistic risk
assessment [20, 21], while others use dynamic Bayesian networks [22, 23]. The human factor
and reliability in risk assessment and management in the context of threats and attacks are
considered in the scientific paper [24]. Paper [25] presents a model of a dynamic and iterative
process in which experts discuss a multi-criteria decision-making problem in complex
management structures. The considered methods of modeling fuzzy preferences are aimed at
evaluating, comparing, selecting, prioritizing and/or organizing alternatives.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Materials and Methods</title>
      <p>
        Let one construct the structure of the hierarchical system in a categorical form. To do this,
its main elements and parameters should be defined: [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] Т is the set of moments of time on the
ordered set Z of cyclic numbers;
      </p>
      <p>⊂   is the set of values of control actions on the
mdimensional vector space; Y is the set of values of input parameters on  0; X is the space of
states on  0; Ω is the space of input actions for which   : 
→  ,   ∈ Ω; Г is the space of
output parameters Г:  →  ; α is the display of the transition when the system status changes
α: (</p>
      <p>×  ×  × Ω) →  .</p>
      <p>For the moment of each transition one has:
( + 1,  ,  ,  ) ⟼  ( + 1,  ,  ,  ) =  ( ) + 
( ),
(1)
where  ,  are matrices ( ×  ), ( ×  ) over K;  is the output representation  ×  →  for
which ( ,  ) ⟼  ( ,  ) =  ( ) is true.</p>
      <p>To study the dynamics of the system for each component, it is necessary to identify the
model (input-output function) as a transfer function that connects the initial state of the
system  ( ) with the input control signal   ( ,  ) through the parametric-time operator
 ( ,  ):  ( ,  ) →  ( ,  + ∆ ).</p>
      <p>
        For linear systems in the classical theory, the "input-output" representation function  is
associated with the concept of the transfer function [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
the power series. [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]
      </p>
      <p>If there is some homomorphism for the transfer function  in the structure of dynamic

systems   then it can be represented in the form:  ( ) = ∑ =1  
 (  ), where  (  ) describes</p>
      <p>
        If there is a factorization for  which is described by a commutative diagram  [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] is a
homomorphism, then the system   ( , Ω, Г) will have a realized structure in the space   ⊂
 , i.e. Ψ ∙  
=   ∙  
Ψ ∙
      </p>
      <p>(Fig. 1).</p>
      <p>The implementation of the matrix transfer function for an object with interconnected
technological aggregates, with a common space of states 〈  =   11,  12, … ,   〉 in a
dynamic system has the form: 
=   × {  },  ( ) =  : ( ×  ×  × Ω), Ω: { : 
→  }/</p>
      <p>Let one construct a diagram for an energy-active object of a dynamic system, taking into
account the channels of action of active threats (Fig. 2).
→   ) are functions of energy transformations; ( 
→   ) are kinetic and,
accordingly, electromagnetic operators of energy transformations; IMS are information and
measurement systems.</p>
      <p>The channels of resource and information attacks (  ,   ) have a complex structure and
their representations, methods of influencing the system and the identification require a
systematic and categorical approach.</p>
      <p>The decomposition procedure will be carried out for a complex dynamic system IIS with a
hierarchical structure into subsystems, blocks and aggregates:
 =1,</p>
      <p>〈  〉 →   | =1, =1 →   | == 1,1   | =1,
→ {
   
}.</p>
      <p>(2)</p>
      <p>Accordingly, a scheme of internal and external connections of aggregate and hierarchical
subsystems is obtained when resource and information flows are transformed (Fig. 3).</p>
      <p>Procedures for forming the structure of the object are constructed using data and
knowledge processing processes in accordance with the problem based on the concept of
systemology and categories. From the structure of the man-made system, the basic structures
are singled out that describe and show the functions, targets and dynamics of the object
according to the specific target task it performs {  }.</p>
      <p>To achieve the target task in the system, the basic functional structure of the control object
is selected, which at its level ensures the achievement of the target:
{  +3}
 
  +2|  +2|   | = 1, 
,
(4)
due to the decomposition procedure of the system into aggregates {  +2}     .</p>
      <p>To get further information about the functional structure of the technological object and
the control process, the aggregates are decomposed into components with selected and
predefined spaces of states, targets, modes and parameters in Fig. 4.</p>
      <p>Designations in Fig. 3, 4: ( ,  ,   ) are dynamic characteristics of the function; (  ,   ,   ) are
class models of process trajectories at the input and output of the system; ( ,  ,  ) is the division
of the space of states into alternatives; (  ,   ,   ) are areas in the space of targets, mode, state of
the object and system; (П , П , П ) are spaces of states, targets, the initial parameter Y;
(  П ,   П  ) are situations in the space of targets and states according to ( ).</p>
      <p>On the basis of the given description of the categorical structure of the system in the
terminal time base and the system structure of dynamics, a categorical representation of the
action model of active threats to the system (informational and resource) is developed (Fig. 5).</p>
      <p>Designations in Fig. 5:     is a generator of the trend of changes in the constant
component of the reliability of aggregates;    ( ) is a generator of impulse discrete active
influence on the object of the structure of the document management system,   is a targets.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Experimental research</title>
      <p>To assess the parameters of the system dynamics, under the control action and the influence
of threats, a parametric-temporal representation of the behavior of structure objects in the
spaces of input parameters, control, the mode of the object according to the load and changing
its trajectory is used based on the analysis of the interaction balance &lt;control ↔ threats&gt; (Fig.
6), that is, the system information-resource game.</p>
      <p>The following main systems in the structure of the game are highlighted:
a man-made aggregated system with control hierarchy;
a system of external influence   with a subsystem of active attacks  
complex of interrelated factors of influence on the aggregate sub-structure, as well as
which forms a
information and management, strategic one.</p>
      <p>Based on the game concept, a functional scheme of active countermeasures against threats
and attacks is developed (Fig. 7).
hierarchy of a man-made system</p>
      <p>The designations in Fig 7: {   } are factors of external influence;    is an information

attack; SAC is a system of automated control of aggregated sub-structure {   | =1}IMS is an
information measuring system; П (  ,   ,   ) is a flow of technological and energy
resources;
П( ), П( )
re spaces of states and the system targets; 
 (  ) is a
coordination of targets in the mode of threats; (
,  
) are data and knowledge bases of
automated document management system,   (  ) is an activator of attacks.</p>
      <p>According to the functional scheme</p>
      <p>of the information-resource hierarchy, the
substructure (  ) of the attack initiation system is considered, which includes: (   ) attack
resources;    an initiator of attacks;</p>
      <p>the target task of the attack;   a complex formation
of threat factors, which reflect the activation process and the action of influencing factors on
the system control.</p>
      <p>In accordance with the strategy of the information-resource game, a categorical diagram of
the attack on the ACS is constructed (Fig. 8).</p>
      <p>Designations in Fig 8:   is an attack activator;   is a generator of a random process
 ( ,  );   is an energy attack resource;   is an information attack resource;   is a
component modulator;   (  ) is a generator of active action;   (  ) is a generator of target
task of an active threat, attack; ⊗   (  ) is a component shaper of the factor (of the
information-resource class);  (  ⁄  ) is an activator of the factor action on the system;   is
a channel of influence on the ACS system.</p>
      <p>To obtain the control situational information about the object state, it is necessary to
decompose the object into the following components, which ensure the achievement of the
local target:
{  +1}</p>
      <p>+1|  +1|
  →  
.</p>
      <p>At the lower level of the object states 〈  +3,   +2,   +1,   〉the process of identification of
elementary structures and knowledge is carried out, which reflect the peculiarities of the
complex functioning   | =+11,, .</p>
      <p>To analyze the general state of the system, taking into account the above, it is not possible
to present the information essence of the situation that has developed in the system (Fig. 9).</p>
      <p>
        In Fig. 9, the following information-resource components and procedures are denoted:
•
•
•
•
•
the procedure for identifying a critical situation in the object under external influences
and attacks on the control structure [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ];
the procedure for forming a target task to resolve a critical situation;
the procedure for selecting the method of identifying the situation and state for
comparison, research and formation of information about the critical state in the data
and knowledge base;
the implementation of a system model of the process of solving critical situation
identification problems using an intelligent logical system processor (ILSP) according
to [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ];
the procedure for assessing the dynamics of changes in the state of the object using an
intelligent research agent to identify risk factors. affiliation mark: a superscript
number following the author's last name.
      </p>
      <sec id="sec-4-1">
        <title>4.1. Results</title>
        <p>
          The evaluation of the results of the objects and aggregates state can be carried out using
systemology, information technology and intelligent decision-making procedures and rules in the
control process, which ensure the achievement of the target in the mode of the current situation
assessment. The use of systemology methods is used to create a theoretical representation of the
formation of the object structure, to determine the space of its possible states and changes in the
object under the influence of threat factors in the target control process. With the help of the
concepts developed in works [
          <xref ref-type="bibr" rid="ref3 ref4 ref5">3-5</xref>
          ], let us consider the component structure of a man-made
system and the interaction of information, resource and energy flows that determine the
general state of a dynamic system.
        </p>
        <p>Common components of a dynamic system with a hierarchical structure include (Fig. 10):
•
•
•
aggregates, blocks, energy-active objects that ensure the process of resource
transformation into energy and are characterized by the operating mode and
dynamics;
dynamic characteristics of technological processes at all stages of functioning (power,
mode: limit - standard);
information control procedures and algorithms for describing situations, data flows in
the control process.</p>
        <p>Resource, information, control, dynamic processes, channels of flows transfer and
exchange cannot be isolated using classical technologies of synthesis and analysis of systems,
which in turn complicates the process of identifying crisis nodes and channels through which
the redistribution of resources, energy, data flows and control teams occurs. That is, with the
help of classical methods and technologies, in the structure of a man-made system it is
impossible to single out agents of influence on the way the system functions, the most
vulnerable places of attacks on the control process and system goals, therefore it is impossible to
describe the control process using game models. To solve the problem, the concepts of
targetoriented systemology of constructing the structure of the object and assessing the dynamic state
are developed as a basis for forming a strategy of active game against threats (Fig. 10).
under resource threats and information attacks</p>
        <p>The designations in Fig. 10: IA an intelligent agent; Fci a target activation factor; DKMS a
database and knowledge management system; ILSSP an intelligent logic synthesis system
processor; 
(  (</p>
        <p>⁄ ) ) a unit for processing the system situation in the control object
(
) at the moment of time t in the interval  ;   a criterion of quality requirements;  ̂

current quality;   reference quality;   :  ̂</p>
        <p>≥  
the synthesis product to the target task; 
  ∗ a factor of influence activation on the system.
⇒ [ 
(</p>
        <p>) ↔  (  )] compliance of
 a quality criterion in the system dynamics process;</p>
        <p>Based on the systemology of the formation of the structure of the man-made system, a
model of the hierarchy of the control process and the channels of transfer of threats and
attacks is developed, which includes the following levels (Fig. 10):  1 - models of the
manmade process (active, thermodynamic, physical);  2 - the level of automatic control;  3 - the
level of operational control;  4 - the level of threats to the control;  5 - the level of threats to
the target orientation of the control system;  6 - the level of information assessment of the
dynamic situation in the system;  7 - a mathematical apparatus for analyzing the structure
and the system dynamics under threats in the target control process;  8 - the level of
formation of the target control task in the conditions of threats;  9 - the level of processing of
situational information under threats (USP - a unit of signals processing);  10 - the level of the
model of the process of solving a problematic situational problem;  11 - the level of project
formation of the defense system against attacks and threats.</p>
        <p>Based on the system method of forming the security system structure, a hierarchical
structure of the man-made complex control system under threats is constructed (Fig. 11).</p>
        <p>In the man-made hierarchy (production, transport, organizational-administrative control
units, printing industry, media), the formation of the structure of the security system is based
on systemology and methods of target-oriented decision-making to solve the problems of
crisis situations.</p>
        <p>Let me emphasize the security features of document circulation when formulating control
decisions at the techno-aggregate, operational, administrative, and strategic levels (Fig. 11):
 1 - a technological structure, which is provided by normative and regulatory documents;
 2 - documents of current control and data storage from information and measurement
systems;
 3 - operational control documents and mode maps and reports for ACS-TP;
 4 - documents and reports in the operational-administrative control system;
 5 - documents that determine the strategic control of the man-made complex;
 6 -documents of the strategic level for forecasting the situation and target orientation of
the man-made complex;</p>
        <p>⁄  - the core of controlling data exchange processes; DS - diagnostic system for
ACSTP; MT - management team; DM - decision-making;    - information threats.</p>
        <p>To develop systems for the protection of the strategic structure and the design process, it is
necessary to take into account the peculiarities of data accounting between all levels, which
are the basis for the formation of documents (correction, management, coordination, target
orientation, assessment of situations in the system), which determines the appropriate
protection measures.</p>
      </sec>
      <sec id="sec-4-2">
        <title>4.2. Discussion</title>
        <p>A methodology for constructing categorical representations of models, structures,
components, and systems, which is necessary for detecting the coordinates of intrusion
attacks, is proposed, and a generalized representation of structures in a hierarchical system in
the category algebra is substantiated. This makes it possible to detect vulnerabilities and
threats that lead to information and resource attacks, and as a result - emergency situations in
the process of functioning and control of complex hierarchical systems.</p>
        <p>When assessing the parameters of the system dynamics, in the process of controlling
hierarchical structures and the influence of active threats, a parametric-temporal
representation of the behavior of the structure objects in the spaces of input parameters,
control, mode of the object according to the load and change of its trajectory is used. Based on
the analysis of the interaction balance &lt;control ↔ threats&gt; in the form of a system
information-resource game and the study of the functioning of the hierarchical system on a
certain terminal cycle, it is found that the game model coincides with the real processes of
man-made system control under threats. Based on this, a structural diagram of the balance
between threats and control in the system is developed and substantiated, an aggregate
diagram of a hierarchical system with internal connections is constructed to identify the cores
of attacks on it, which can be used in the context of decision-making support.</p>
        <p>A method of structuring man-made systems is developed based on the assessment of the
dynamics of changes in the state of objects to identify critical situations in the form of attacks
and negative disturbances on the control process and structural organization of man-made
systems. It is shown that the risks of accidents are determined on the basis of the assessment
of changes in the state of objects relative to standards, specified limits and normative modes
of the system functioning in the conditions of transition of the trajectory of the state through
the limit line of the functioning mode of the energy-active object.</p>
        <p>The general concept of this approach can be applied to any company and man-made
structure with a hierarchical control structure. Quantitative estimates of losses obtained
according to the analysis of possible threats and vulnerabilities are submitted to the input of
the model, for example, organizational assets, cognitive characteristics of factors affecting the
man-made structure, taking into account risk coefficients, characteristics of various control
risk components and linguistic considerations of experts in the field of security and system
control and decision-making. Risks of production losses are formed in the terminal production
cycle and can also be changed under the influence of active threats in the production and
control process. It is necessary to take into account all the threats and vulnerabilities of such
man-made hierarchical systems, and only then it is possible to determine a comprehensive
indicator of the risk of system failure under the influence of active threats.</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5. Conclusions</title>
      <p>The paper solves the scientific and applied task of developing a methodology for constructing
a model of the structure of hierarchical control systems of complex man-made objects under
threats and attacks based on the use of the category algebra. The possibility of constructing
procedures for the structuring of man-made systems (current and at the design stage) is
substantiated based on the use of system analysis and the theory of categories.</p>
      <p>The scientific novelty of the study is as follows:
1. for the first time, categorical structural diagrams of transformations in an
energyactive system under threats, in the space of states and dynamics in time of a complex
system are developed;
2. the categorical representation of the model of the effect of threats on the system is
improved and a structural diagram of the game between threats and the control process in
the hierarchical system is developed;
3. for the first time, a functional scheme of information-resource countermeasures
against threats in the hierarchy of man-made systems is developed;
4. for the first time, the hierarchical structure of a technological complex control system
is developed under risk conditions;
5. the proposed categorical representations for assessing the risk of failure of the control
system and document flow are tested and verified as part of a hierarchical production
system for the example of risk assessment of printing productions, and also a
systemcategory diagram of interaction is proposed as a training in the information-resource game
&lt;control ↔ threats&gt;.</p>
      <p>The practical significance of the obtained results is that the proposed method of
determining the coordinates of attacks based on changes in the state of objects in a dynamic
hierarchical system allows determining the risk of emergency situations, which has been
tested in the control and document management system as part of the hierarchical system of
printing production and can be used in various man-made hierarchical systems when solving
control decision-making tasks, designing and improving protection systems.</p>
      <p>Further research of the problem can be seen in the development of software for assessing
the risk of system functioning under the influence of active threats to man-made hierarchical
structures.
[13] F. Sicard, É. Zamai, J. M. Flaus. An approach based on behavioral models and critical states
distance notion for improving cybersecurity of industrial control systems. Reliab Eng Syst
Saf, 188 (2019): 584-603, doi:10.1016/J.RESS.2019.03.020
[14] A. Cormier, C. Ng. Integrating cybersecurity in hazard and risk analyses. J Loss Prev</p>
      <p>Process Ind, 64 (2020), Article 104044, doi:10.1016/j.jlp.2020.104044
[15] D. H. Alahmadi, A. A. Jamjoom. Decision support system for handling control decisions
and decision‑maker related to supply chain. Journal of Big Data, 9:114 (2022): 1-14,
doi:10.1186/s40537-022-00653-9
[16] V. Domeh, F. Obeng, F. Khan, N. Bose, E. Sanli, Risk analysis of man overboard scenario in
a small fishing vessel. Ocean Engineering, 229 (2021) 108979,
doi:10.1016/j.oceaneng.2021.108979
[17] J. Alanen, J. Linnosmaa, T. Malm, N. Papakonstantinou, T. Ahonen, E. Heikkilä, R.</p>
      <p>Tiusanen, Hybrid ontology for safety, security, and dependability risk assessments and
Security Threat Analysis (STA) method for industrial control systems. Reliability
Engineering &amp; System Safety, 220 (2022) 108270, doi:10.1016/j.ress.2021.108270
[18] V. Agrawal, A comparative study on information security risk analysis methods. In:
International Conference on Computer Science and Information Technology (ICCSIT 2015)
At: Amsterdam 12 (2017): 57-67, doi:10.17706/jcp.12.1.57-67
[19] F. De Rosa, N. Maunero, L. Nicoletti, P. Prinetto, M. Trussoni, Ontology for Cybersecurity
Governance of ICT System s. ITASEC'22: Italian Conference on Cybersecurity, June 20-23,
2022, https://ceur-ws.org/Vol-3260/paper4.pdf
[20] T. Zhou, M. Modarres, E. L. Droguett, Multi-unit nuclear power plant probabilistic risk
assessment: a comprehensive survey. Reliab Eng Syst Saf, 213 (2021), Article 107782,
doi:10.1016/j.ress.2021.107782.
[21] M. Modarres, T. Zhou, M. Massoud, Advances in multi-unit nuclear power plant
probabilistic risk assessment. Reliab Eng Syst Saf, 157 (2017): 87-100,
doi:10.1016/j.ress.2016.08.005
[22] J. Kim, A.U.A. Shah, H.G. Kang, Dynamic risk assessment with bayesian network and
clustering analysis. Reliab Eng Syst Saf, 201 (2020), 106959, doi:10.1016/j.ress.2020.106959
[23] J. DeJesus Segarra, M. Bensi, M. Modarres. A bayesian network approach for modeling
dependent seismic failures in a nuclear power plant probabilistic risk assessment. Reliab
Eng Syst Saf, 213 (2021), Article 107678, doi:10.1016/j.ress.2021.107678
[24] M. Cepin, R. Bris, Safety and Reliability. Theory and Applications. CRC Press. 2017,
doi:10.1201/9781315210469
[25] M. A. Dorna, L. C. Ribeiro, H. S. Schuffner, M. P. Liborio &amp; P. I. Ekel. Fuzzy-Set-Based
Multi-Attribute Decision-Making, Its Computational Implementation, and Applications.
Axioms 13(3) (2024): 142, doi:10.3390/axioms13030142</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Ya. Bobalo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I. V.</given-names>
            <surname>Gorbaty</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. P.</given-names>
            <surname>Bondarev</surname>
          </string-name>
          . Information security. Lviv: Lviv Polytechnic University,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>V.</given-names>
            <surname>Khoroshko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Brailovskyi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Kapustian</surname>
          </string-name>
          <article-title>. Multi-criteria assessment of the correctness of decision-making in information security tasks</article-title>
          .
          <source>International scientific journal «Computer systems and information technologies»</source>
          ,
          <volume>4</volume>
          (
          <year>2023</year>
          ):
          <fpage>81</fpage>
          -
          <lpage>86</lpage>
          , doi:10.31891/csit-2023
          <source>-4-11</source>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>F. J.</given-names>
            <surname>Folgado</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Calderón</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. González</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. J.</given-names>
            <surname>Calderón</surname>
          </string-name>
          .
          <article-title>Review of Industry 4.0 from the Perspective of Automation and Supervision Systems: Definitions, Architectures and Recent Trends</article-title>
          .
          <source>Electronics</source>
          <volume>13</volume>
          ,
          <issue>782</issue>
          (
          <year>2024</year>
          ):
          <fpage>1</fpage>
          -
          <lpage>33</lpage>
          , doi:10.3390/electronics13040782
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>V.</given-names>
            <surname>Sabat</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Sikora</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Durnyak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Matsiuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Hibey</surname>
          </string-name>
          .
          <article-title>Methods for assessing the risk of an emergency in the security system for the information complex of printing enterprises</article-title>
          .
          <source>IntelITSIS'2024: 3rd International Workshop on Intelligent Information Technologies and Systems of Information Security. Khmelnytskyi</source>
          ,
          <string-name>
            <surname>Ukraine</surname>
          </string-name>
          , V.
          <volume>3675</volume>
          (
          <year>2024</year>
          ):
          <fpage>305</fpage>
          -
          <lpage>317</lpage>
          , https://ceur-ws.
          <source>org/</source>
          Vol-
          <volume>3675</volume>
          /paper22.pdf
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>A.</given-names>
            <surname>Veloni</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Miridakis</surname>
          </string-name>
          .
          <source>Digital Control Systems Theoretical Problems and Simulation Tools</source>
          . CRC Press,
          <year>2021</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>V.</given-names>
            <surname>Sabat</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Durnyak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Sikora</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Polishchuk</surname>
          </string-name>
          .
          <article-title>Research on the assessment of the risk situations emergence for automated control systems of the metallurgical industry companies</article-title>
          .
          <source>Acta Montanistica Slovaca</source>
          .
          <volume>28</volume>
          (
          <issue>1</issue>
          ) (
          <year>2023</year>
          ):
          <fpage>201</fpage>
          -
          <lpage>213</lpage>
          , doi:10.46544/AMS.
          <year>v28i1</year>
          .
          <fpage>16</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7] ISO/IEC 27001:
          <year>2022</year>
          <article-title>(en</article-title>
          ).
          <source>Online Browsing Platform (OBP)</source>
          , https://www.iso.org/obp/ui#iso:std:iso-iec:27001:ed-3:v1:en
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>Min</given-names>
            <surname>Jin</surname>
          </string-name>
          .
          <source>Computer Network Information Security and Protection Strategy Based on Big Data Environment</source>
          .
          <source>International Journal of Information Technologies and Systems Approach</source>
          ,
          <volume>16</volume>
          (
          <issue>2</issue>
          ) (
          <year>2023</year>
          ):
          <fpage>1</fpage>
          -
          <lpage>14</lpage>
          , doi:10.4018/IJITSA.319722
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Jiaqi</given-names>
            <surname>Sun</surname>
          </string-name>
          .
          <source>Computer Network Security Technology and Prevention Strategy Analysis. Procedia Computer Science</source>
          ,
          <volume>208</volume>
          (
          <year>2022</year>
          ):
          <fpage>570</fpage>
          -
          <lpage>576</lpage>
          , doi:10.1016/j.procs.
          <year>2022</year>
          .
          <volume>10</volume>
          .079
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Yuqian</surname>
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Xun</surname>
            <given-names>X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lihui</surname>
            <given-names>W.</given-names>
          </string-name>
          <article-title>Smart manufacturing process and system automation - A critical review of the standards and envisioned scenarios</article-title>
          .
          <source>Journal of Manufacturing Systems</source>
          ,
          <volume>56</volume>
          (
          <year>2020</year>
          ):
          <fpage>312</fpage>
          -
          <lpage>325</lpage>
          , doi:10.1016/j.jmsy.
          <year>2020</year>
          .
          <volume>06</volume>
          .010
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>V.</given-names>
            <surname>Sabat</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Durnyak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Kulynych</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Havrylyshyn</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Hibey</surname>
          </string-name>
          .
          <article-title>Using semantic analysis of document text in building risk models in the threats system</article-title>
          .
          <source>IntelITSIS'2024: 3rd International Workshop on Intelligent Information Technologies and Systems of Information Security. Khmelnytskyi</source>
          ,
          <string-name>
            <surname>Ukraine</surname>
          </string-name>
          , V.
          <volume>3675</volume>
          (
          <year>2024</year>
          ):
          <fpage>330</fpage>
          -
          <lpage>342</lpage>
          , https://ceurws.org/Vol-
          <volume>3675</volume>
          /paper24.pdf
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Ch. Milioti</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          <string-name>
            <surname>Kepaptsoglou</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Deloukas</surname>
          </string-name>
          , E. Apostolopoulou,
          <article-title>Valuation of man-made incident risk perception in public transport: The case of the Athens metro</article-title>
          ,
          <source>International Journal of Transportation Science and Technology</source>
          ,
          <volume>11</volume>
          (
          <issue>3</issue>
          ) (
          <year>2022</year>
          ):
          <fpage>578</fpage>
          -
          <lpage>588</lpage>
          , doi:10.1016/j.ijtst.
          <year>2021</year>
          .
          <volume>07</volume>
          .003
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>