<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Method for managing IT incidents in critical information infrastructure facilities ⋆</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Sergiy Gnatyuk</string-name>
          <email>s.gnatyuk@nau.edu.ua</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Viktoria Sydorenko</string-name>
          <email>v.sydorenko@ukr.net</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Artem Polozhentsev</string-name>
          <email>artem.polozhentsev@nau.edu.ua</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Volodymyr Sokolov</string-name>
          <email>v.sokolov@kubg.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Borys Grinchenko Kyiv Metropolitan University</institution>
          ,
          <addr-line>18/2 Bulvarno-Kudryavska str., 04053 Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>CPITS-II 2024: Workshop on Cybersecurity Providing in Information and Telecommunication Systems II</institution>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>National Aviation University</institution>
          ,
          <addr-line>1 Liubomyra Huzara ave., 03058 Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>326</fpage>
      <lpage>333</lpage>
      <abstract>
        <p>Protecting Critical Information Infrastructure (CII) is essential in today's digitized world, where the growing number of cyber threats poses significant risks to national security, the economy, and public safety. CII includes vital sectors such as energy, transport, finance, and healthcare. Disruptions to these systems can have serious consequences, requiring effective identification, assessment, and management of IT threats. Despite the importance of IT security to CII, existing methods for managing IT threats remain underdeveloped. This paper presents a novel method for IT incident management in CII, combining the STRIDE model and TODIM multi-criteria decision-making. The method is designed to identify, assess, and prioritize threats, taking into account the criticality of CII objects at different levels. Through experimental validation, this method demonstrates its ability to improve CII security by providing a systematic approach to prioritizing and managing IT threats. This study provides a practical solution for improving CII protection against evolving cyber risks.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;critical infrastructure</kwd>
        <kwd>critical information infrastructure facilities</kwd>
        <kwd>cybersecurity</kwd>
        <kwd>incident management</kwd>
        <kwd>STRIDE</kwd>
        <kwd>TODIM 1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Protecting critical infrastructure facilities is one of the most
important tasks for organizations and governments in
today’s digitized world. The growing number of cyber
threats associated with the development of information
technologies has increased the need to implement reliable
security measures. Critical Information Infrastructure (CII)
includes systems and networks that are vital to the
functioning of society in the areas of energy, transport,
finance, communications, and healthcare [1, 2].</p>
      <p>The failure or compromise of such components can have
serious consequences for national security, the economy
and public welfare. To effectively protect CII, it is necessary
to properly identify, assess and manage IT threats,
especially in the context of limited defense resources. This
highlights the important scientific task of developing and
implementing an effective method for managing IT
incidents in CII facilities (CIIF).</p>
      <p>Despite the importance of ensuring the IT security of
CII, there is currently a lack of scientific research on the
development and implementation of IT threat management
methodologies, both internationally and domestically
(Fig. 1) [2]. However, during the analysis, the authors
examined threat management approaches in various areas
of CII.</p>
      <p>0000-0003-4992-0564 (S. Gnatyuk);
0000-0002-5910-0837 (V. Sydorenko);
0000-0003-0139-0752 (A. Polozhentsev);
0000-0002-9349-7946 (V. Sokolov)
© 2024 Copyright for this paper by its authors. Use permitted under
Creative Commons License Attribution 4.0 International (CC BY 4.0).</p>
    </sec>
    <sec id="sec-2">
      <title>2. Literature review</title>
      <p>
        In studies [
        <xref ref-type="bibr" rid="ref3 ref4 ref5">4–6</xref>
        ], the authors developed an algorithm for
assessing cybersecurity threats to Learning Management
Systems (LMS). By combining the STRIDE model with the
TODIM multi-criteria decision support method and
providing fuzzy sets, they evaluated LMS platforms, namely
Moodle, Atutor, and Ilias. The study involved three cyber
security experts who assessed security using linguistic
variables, demonstrating the effectiveness of the algorithm
in detecting and ranking cyber threats in LMS
environments. This study is particularly relevant for
cybersecurity professionals responsible for the security of
educational technologies and provides a methodology that
can be used to strengthen the security of LMSs.
      </p>
      <p>
        In article [
        <xref ref-type="bibr" rid="ref6">7</xref>
        ], the authors explore the application of the
STRIDE model for assessing cybersecurity threats in the
critical infrastructure transportation industry. The article
highlights how the integration of STRIDE with the Hazard
Analysis and Risk Assessment (HARA) method, called the
SAHARA approach, provides a comprehensive framework
for assessing security risks in the early stages of
development. This combined approach enables security
threats to be identified and categorized, ensuring that
appropriate countermeasures are implemented to protect
automotive systems from advanced cyber-attacks, thereby
supporting consistent and secure product development
throughout the lifecycle.
      </p>
      <p>
        The study [
        <xref ref-type="bibr" rid="ref7">8</xref>
        ] addresses the issues of improving security
and privacy, as well as the vulnerability of 5G networks,
with a focus on CI protection. Despite advances over
previous generations, 5G networks still have technical
security weaknesses that can be exploited. The paper uses
the STRIDE threat classification model to identify and
analyze eleven threat scenarios in the 5G ecosystem,
highlighting the importance of implementing robust
security measures to mitigate these risks.
      </p>
      <p>
        The study [
        <xref ref-type="bibr" rid="ref8">9</xref>
        ] described that critical infrastructure and
industrial control systems are complex cyber-physical
systems. Ensuring the reliable operation of such systems
requires comprehensive threat modeling during system
design and validation. Also, the following articles [
        <xref ref-type="bibr" rid="ref10 ref9">10, 11</xref>
        ]
present a comprehensive threat modeling methodology
using STRIDE, a systematic approach to ensuring system
security at the component level. The methodology is applied
to a real-world testbed of a synchronous isolated system
based on a synchro phasor. The study identifies the types of
threats that can occur in each component of the system and
how vulnerabilities in one component can compromise the
security of the whole system. STRIDE has proven to be a
simple and effective threat modeling methodology that
simplifies the task for security analysts.
      </p>
      <p>It has been found that there is currently no implemented
method that would allow effective management of IT
threats for CII. Therefore, the development of such a method
is extremely necessary to ensure a more reliable protection
against potential IT threats and to increase the level of
security of Critical Information Systems (CIS). Thus, the
purpose of this paper is to develop and experimentally study
a method for managing IT threats for CII.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Analysis of international methodologies for IT threat modeling</title>
      <p>Since the preliminary analysis of existing studies on the
identification, assessment, and management of IT threats
did not allow the identification of a formalized approach, the
authors decided to develop their method for the
management of IT threats for CIIF.</p>
      <p>This requires conducting additional analysis of the
effectiveness of international practices and threat modeling
methodologies according to the following criteria Ease of
Use (EU)—an assessment of the ease of use of the method in
practice, Comprehensiveness (CM)—the extent to which the
method covers all aspects of IT threat management,
Integration with other systems (IS)—the extent to which the
method allows integration with other security and
management systems, CI focus (CI)—if the method takes
into account the specifics of the ICS, Objectivity (OB)—the
extent to which the method reduces subjectivity in the
decision-making process, Time to Use (ET)—the time
required to apply the method.</p>
      <p>
        The STRIDE threat classification methodology [
        <xref ref-type="bibr" rid="ref11">12</xref>
        ] is a
popular security threat analysis tool developed by
Microsoft. The acronym stands for Spoofing, Tampering,
Repudiation, Information disclosure, Denial of service, and
Elevation of privilege. This methodology helps identify
vulnerabilities in information systems, allowing developers
and security professionals to take proactive measures to
eliminate them. The benefits of STRIDE include its
comprehensiveness in covering a wide range of threats, its
clarity and structure with clearly defined threat categories,
and its ability to integrate with other security
methodologies and tools. However, in-depth knowledge of
IT security is required to use this methodology effectively.
      </p>
      <p>
        The National Institute of Standards and Technology’s
NIST SP 800-30 [
        <xref ref-type="bibr" rid="ref12">13</xref>
        ] standard provides a comprehensive
approach to identifying, assessing, and managing risk while
taking into account the specifics of an organization’s
processes and assets. The key benefits of NIST SP 800-30 are
a comprehensive approach that covers all stages of risk
management, from threat identification to response strategy
development, and the recognition of the standard in many
organizations. However, implementation of this standard
can require significant resources and time and can be
difficult for small organizations due to limited resources.
      </p>
      <p>
        The international standard ISO/IEC 27005 [
        <xref ref-type="bibr" rid="ref13">14</xref>
        ] provides
guidance on information security risk management and
provides a structured approach to identifying, assessing,
and managing risks. The advantages of ISO/IEC 27005 are
its consistency with other ISO standards, which allows risk
management to be integrated into an organization’s overall
management system and its structured approach.
Disadvantages include the resources required to implement
the standard and its complexity for small organizations,
which may find it difficult to implement.
      </p>
      <p>
        The OCTAVE (Operationally Critical Threat, Asset, and
Vulnerability Evaluation) methodology [
        <xref ref-type="bibr" rid="ref14 ref15">15, 16</xref>
        ] is designed
to assess and manage information security risks by focusing
on an organization’s critical assets. It allows you to identify
and protect the organization’s most important assets and
perform a self-assessment using internal resources.
However, OCTAVE requires significant involvement of
staff at all levels of the organization and can be difficult to
coordinate in large organizations.
      </p>
      <p>
        The Control Objectives for Information and Related
Technologies (COBIT) framework [
        <xref ref-type="bibr" rid="ref16">17</xref>
        ] is an IT governance
framework that includes risk management aspects and
ensures the integration of IT with business objectives. The
benefits of COBIT include integration with business
processes, which helps to align IT management with the
overall business objectives of the organization, and a
comprehensive approach that covers all aspects of IT
management. However, implementing a framework can be
resource-intensive, and small organizations may face
difficulties due to insufficient resources for full
implementation.
      </p>
      <p>Table 1 compares approaches to prioritize IT threats
according to the following criteria: EU is ease of use, CM is
complexity, IS is integration with other systems, CI is focus
on CI, OB is objectivity, and ET is time to application.
STRIDE
NIST SP 800-30
ISO/IEC 27005
OCTAVE
COBIT</p>
      <p>EU
+</p>
      <p>CM
+
+
+
+
+</p>
      <p>IS
+
+</p>
      <p>OB
+
+</p>
      <p>ET
+
+
+
+
SC
+
+
+
CR
+
Based on the analysis of these criteria, the STRIDE approach
is a highly effective and comprehensive approach to
identifying IT threats. Its clear structure, ability to integrate
with other methods, and emphasis on different types of
threats make it an ideal tool for improving the security of
information systems. STRIDE enables organizations not
only to identify threats, but also to assess their criticality,
develop appropriate protection methods, and ensure a
comprehensive approach to risk management.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Analysis of decision-making methods</title>
      <p>
        To prioritize IT threats, it is necessary to consider
decisionmaking methodologies—approaches that help to analyze
complex problems and select the best course of action,
taking into account various possible alternatives. These
methods include a range of techniques and tools to help
evaluate different parameters and weight criteria to arrive
at an objective, balanced decision [
        <xref ref-type="bibr" rid="ref17">18</xref>
        ].
      </p>
      <p>
        The Analytic Hierarchical Process (AHP) [
        <xref ref-type="bibr" rid="ref18">19</xref>
        ],
developed by Thomas Saaty in the 1980s, helps to break
down a decision problem into a hierarchy of smaller
components, including objectives, criteria, sub-criteria, and
alternatives. By using mathematical principles to evaluate
the importance of criteria and select the best option [
        <xref ref-type="bibr" rid="ref19">20</xref>
        ],
AHP is intuitive and able to combine quantitative and
qualitative criteria. However, the method can be subject to
subjectivity in weighting and requires a significant amount
of time and data for analysis.
      </p>
      <p>
        TODIM [
        <xref ref-type="bibr" rid="ref20">21</xref>
        ] is a multicriteria decision analysis method
based on the prospect theory of Daniel Kahneman and
Amos Tversky. The method uses the principles of utility
theory to model the preferences of a decision-maker under
conditions of uncertainty and associated risks. The main
steps of the method include identifying criteria and
alternatives, evaluating alternatives for each criterion,
assigning weights to the criteria, calculating the dominance
of each alternative over the others based on the weights,
using a prospective value function to account for risk
attitudes, summing the prospective values to obtain a utility
score, and selecting the alternative with the highest utility
score. The method incorporates risk and uncertainty and is
intuitive, but requires complex calculations and subjective
judgement of weights.
      </p>
      <p>
        The Technique of Options Selection and Review
(TOPSIS) [
        <xref ref-type="bibr" rid="ref21">22</xref>
        ] determines the optimal alternative by
selecting the alternative closest to the ideal point. The
method takes into account the distances to the ideal (best)
and anti-ideal (worst) solutions. TOPSIS is easy to
implement and clearly identifies the best alternative, but it
is sensitive to the relative values of the criteria and can be
influenced by incorrect scaling.
      </p>
      <p>Table 2 shows a comparison of the decision methods
that can be used to assess IT threats. The analysis is based
on the following criteria CI—CI applicability, FL—flexibility,
SC—scalability, CR—risk and uncertainty consideration,
EU—ease of use.</p>
      <p>EU
+
+
+
Based on the analysis of these criteria, the TODIM approach
is the most suitable for use in the area of CII. The method
effectively takes into account risk and uncertainty, which is
an important aspect of CII, and demonstrates a high degree
of flexibility in considering different criteria.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Method for managing IT incidents in critical information infrastructure facilities</title>
      <p>The method developed by the authors consists of 7 stages,
each of which is described in more detail below.</p>
      <p>Step 1: Identification of IT threats to CII.</p>
      <p>The identification of IT threats is an important stage in
the process of managing IT threats to CII. The purpose of
this stage is to identify potential threats that could affect the
normal operation of critical information systems. At this
stage you can select threats according to various
international approaches such as STRIDE, NIST SP 800-30,
ISO/IEC 27005, OCTAVE, or COBIT, depending on the
characteristics of the CII. The set of potential IT threats is
called the Ui set:</p>
      <p>Ui  {U1,U2 ,,Un} (1)
where Ui is a set of identified potential IT threats,
U1,U2,,Un are potential IT threats.</p>
      <p>Step 2: Define criteria for evaluating IT threats to CII.</p>
      <p>For each threat Ui and each criterion k, let’s introduce a
set of evaluation criteria K:</p>
      <p>K  {k1, k2,, km}
(2)
where K is a set of criteria against which IT threats are
assessed, k1, k2,, km —are specific assessment criteria.</p>
      <p>Each potential threat Ui should be assessed against
criteria K to determine its impact and priority.</p>
      <p>Step 3. Collect and normalize data on IT threats to CII.</p>
      <p>At this step, it is necessary to collect, assess, and
normalize data on IT threats to CII. This process ensures an
objective and balanced approach to threat assessment. Each
threat Ui is evaluated according to the defined criteria K. For
example, experts may evaluate the likelihood of a threat
occurring, the potential damage, the complexity of
implementation, etc. Each evaluation criterion k has a
corresponding weight. Each evaluation criterion k has a
corresponding weighting factor wk, where the sum of all
coefficients is 1:</p>
      <p>K
k  1, (3)
k 1
where K is the total number of criteria, wk is the weighting
factor for criterion k.</p>
      <p>Step 4. Determine the weight of the CII IT threat criteria.</p>
      <p>Determining the weighting factors for each IT threat
assessment criterion is an important step that allows you to
consider the relative importance of different aspects of the
threat. This helps to ensure objectivity and balance in the IT
threat assessment process. Each criterion is rated on a
predetermined scale. In their paper, the authors suggest using
a scale of 1 to 5, with 5 being the highest probability,
damage, or complexity and 1 being the lowest. This scale is
intuitive and easy to use, which simplifies the assessment
process for experts. For each criterion, we calculate the
average of the geometric scores provided by the experts as
follows:</p>
      <p>n
k  ( k j )1/n
j1
(4)
(5)
(7)
where vkj is the evaluation of criterion k by expert j, n is the
number of experts.</p>
      <p>Next, at this stage, a vector of weighting coefficients
should be created and calculated by normalizing the average
geometric scores:</p>
      <p>W  (W1,W2 ,,Wn )T
where Wi is the weighting factor for each criterion i.</p>
      <p>Wj
Wjr  nWr (6)</p>
      <p>r1
where Wj is the geometric mean for criterion j, Wr is the sum
of geometric means for all criteria.</p>
      <p>Step 5. Perform pairwise comparisons of alternative
threats to CII.</p>
      <p>In a pairwise comparison, the dominance of each threat
over the others is determined using a prospective value
function that takes into account the weights of the criteria
and the ratings of the alternatives for each criterion.</p>
      <p> Ui , k  U j , k 
Dom(Ui ,U j , k)  k   1  a  U j , k 
 ,
where Ui and Uj are the threats to be compared; k is the
criterion by which the comparison is made; Wk is the weight
of the criterion; vUi,k and vUj,k are the threat ratings by the
criterion; α is a parameter reflecting the attitude toward
risk.</p>
      <p>Consideration of CI Categories</p>
      <p>
        According to the Law of Ukraine “On Critical
Infrastructure” [
        <xref ref-type="bibr" rid="ref22">23</xref>
        ], in particular, Article 10 “Categorization
of CI”, CI are divided into categories depending on their
importance and potential impact on the security of the state
or region. The introduction of the criticality variable C
allows the integration of these categories as additional
criteria into the multicriteria analysis according to the
developed method, which increases the accuracy of the
assessment of the potential impact of threats on different
levels of criticality.
      </p>
      <p>The criticality variable C takes values from 1 to 4,
reflecting the level of criticality of the infrastructure object:
Category I (C=1): Critical facilities of national importance.
Disruption of their functioning can cause a national crisis.
Category II (C=2): Critical facilities whose disruption could
cause a regional crisis. Category III (C=3): Critical facilities
whose disruption could cause a local crisis. Category IV
(C=4): Essential facilities whose disruption could cause a
local crisis.</p>
      <p>Step 6. Obtain an integrative assessment of alternative IT
threats to CII.</p>
      <p>At this stage, it is necessary to calculate the value of the
future value to obtain a utility score for each threat.</p>
      <p>K
Score(Ui )    Dom(Ui ,U j , k ) (8)</p>
      <p>ji k 1
where Score(Ui) is the integrative utility score for threat a,
Ui and Uj are the threats being compared, k is the criterion
by which the comparison is made, and Dom(Ui, Uj,k) is the
prospective value function for determining the dominance
of each threat over the others.</p>
      <p>Step 7. Prioritize and make decisions about IT threats to
At this step, it is necessary to prioritize the identified IT
threats and make appropriate decisions on actions to
eliminate or minimize them. This should be done by
calculating the relative importance of each threat and
ranking them based on the estimates obtained.</p>
      <p>Score(Ui )
p(Ui )  n
 Score(Ui )
i1
(9)
where p(Ui ) is the relative importance of each potential IT
threat, and Score(Ui) is an integrative assessment of the
utility for threat a.</p>
      <p>Next, the IT threats should be ranked from highest to
lowest. Threats with the highest scores are the most critical
and require priority response. Based on the results of the
threat ranking, decisions are made on the necessary
measures to eliminate or minimize each threat. Measures
may be technical, organizational, or procedural.</p>
    </sec>
    <sec id="sec-6">
      <title>6. Experimental Study of the Method of IT Incident Management in CII</title>
      <p>
        Let’s apply this method to the CII sector “Digital
Technologies”, namely the sub-sector “Electronic
Communications”, according to [
        <xref ref-type="bibr" rid="ref23 ref24 ref25">24–26</xref>
        ].
      </p>
      <p>Step 1: Identification of IT threats to CII</p>
      <p>
        According to the STRIDE methodology, and analyzed
studies [
        <xref ref-type="bibr" rid="ref10 ref11 ref26 ref9">10–12, 27</xref>
        ], the following IT threats were identified
to improve the IT security of CII:






      </p>
      <p>Spoofing. The threat of interfering with the system
by using false data or identity to gain unauthorized
access. For example, a hacker could use forged
certificates to gain access to an energy company’s
network.</p>
      <p>Tampering. Making unauthorized changes to data
or system configurations. This can include
changing logical control commands to OCI, which
can lead to physical failures.</p>
      <p>Repudiation. The inability to trace or prove that a
user’s actions were performed. For example, the
lack of audit logs can allow attackers to deny that
malicious actions were taken on a water
management network.</p>
      <p>Information disclosure. Unauthorized access to
sensitive information. For example, leakage of
classified information from government databases
can have serious national security implications.</p>
      <p>Denial of Service (DoS). Attacks are designed to
prevent the normal operation of a system,
particularly by overloading resources. For
example, a DoS attack on transportation
infrastructure management systems could bring
all traffic to a halt.</p>
      <p>Elevation of Privilege. A threat that allows an
attacker to gain greater privileges than they have
and use them to gain inappropriate access to
systems or data. For example, an attacker could
gain administrator privileges in health
management systems and abuse those privileges.
Step 2: Define Criteria for Assessing IT Threats to CII
This stage involves a detailed definition of the criteria
for assessing each IT threat to CII. The evaluation criteria
are key parameters that allow a comprehensive analysis of
threats and prioritization for further management. For each
IT threat Ui and each criterion k, it is proposed to apply the
following parameters according to (1, 2):


</p>
      <p>Threat Probability (TP): An estimate of the
likelihood that a specific IT threat will occur. This
allows you to determine how often the threat can
be expected to occur.</p>
      <p>Potential damage from the threat (P): An estimate
of the potential damage that could be caused to CII
if the threat is realized. Both financial loss and
potential impact on the security and operation of
the system are considered.</p>
      <p>Threat complexity (C): An assessment of the
technical difficulty of implementing the threat by
attackers. This includes an analysis of the
knowledge, tools and resources required to carry
out the attack.</p>
      <p>
        Properly defining the criteria allows for a deeper and
more comprehensive threat analysis, increasing the
effectiveness of risk management and CII protection. The
optimal number of criteria for assessing IT threats to CII
depends on the complexity of the problem and the data
available. According to [
        <xref ref-type="bibr" rid="ref13 ref27">14, 28</xref>
        ], the use of 3–7 criteria is
standard practice to ensure a comprehensive analysis. This
allows different aspects of threats and risks to be considered
and provides a balanced approach to CII protection
decision-making.
      </p>
      <p>Step 3. Collect and normalize IT threat data for CII
This stage involves a detailed process of collecting,
assessing, and normalizing IT threat data for CII. An
important part of this phase is to determine the weighting
factors for each assessment criterion, which will allow for
an objective and balanced approach to threat assessment.</p>
      <p>
        The weighting factors for assessing IT threats to CII
should be determined based on their relative importance.
The likelihood of a threat occurring was given a high
coefficient because it has a significant impact on the risk of
the threat being realized. The potential damage from the
threat has the highest coefficient because the potential
losses from the threat are critical to the functioning of the
CII. The complexity of the threat realization received a
lower coefficient due to its relatively lower importance
compared to other criteria, but it is still important for
assessing the technical aspects of protection [
        <xref ref-type="bibr" rid="ref28">29</xref>
        ].
      </p>
      <p>By the previous steps, each evaluation criterion k has a
corresponding weighting factor wk, where the sum of all
coefficients is 1 according to (3), as shown in Table 3 below:
Step 4. Determine the weight of the CII IT threat criteria.</p>
      <p>
        A rating scale from 1 to 5 is used to further define the
criteria, with 1 being the lowest level (low probability,
minimal damage, low complexity) and 5 being the highest
level (high probability, maximum damage, high
complexity). These scores are then used to compare threats
in pairs to determine their relative importance and
criticality to CII. Based on these criteria, an integrative
assessment and prioritization of threats is performed, which
is the basis for management decisions on security and
protection measures [
        <xref ref-type="bibr" rid="ref29">30</xref>
        ].
      </p>
      <p>Therefore, according to (4, 5, 6), we will apply the above
scale to evaluate the alternatives according to the specified
criteria. Below is a table of alternatives evaluated by criteria
(Table 4).
The values are then used to compare threats in pairs to
determine their relative importance and criticality to the
CII. This comparison helps determine which threats are the
most serious and require priority protection measures. An
integrative assessment and prioritization of threats based on
the results is then performed, providing the basis for
management decisions on security and protection measures
for the CII.</p>
      <p>Step 5. Perform pairwise comparisons of alternative
threats to CII.</p>
      <p>According to (7), in this step, the method of pairwise
comparisons is used to determine the dominance of each
threat over the others. This method allows the relative
importance and criticality of each threat to be assessed by
comparing them according to certain criteria. The
application of the prospective value function takes into
account the weights of the criteria and the scores of the
alternatives for each criterion.</p>
      <p>
</p>
      <p>Data Entry: After all threats have been evaluated
according to the criteria defined in the previous
step, the data is entered into specially developed
software to perform the calculations.</p>
      <p>Determine the α parameter: The α parameter is set
to account for risk attitudes. The value of α can
take on any value depending on the specific
situation but is usually between 0 and 1. Low


values of α reduce the impact of the risk, while
high values increase its significance.</p>
      <p>Pairwise comparison of threats: Each threat is
compared to the others across all criteria. For each
pair of threats, a dominance value is calculated
using the formula above.</p>
      <p>Overall Dominance Calculation: After all threat
pairs are compared for each criterion, a total
dominance value is calculated for each threat. This
value is used to rank and prioritize threats.</p>
      <p>Thus, this phase provides a detailed and objective
analysis of the threats, providing a reliable basis for
management decisions regarding CII protection.</p>
      <p>Step 6. Obtain an integrative assessment of alternative IT
threats to CII.</p>
      <p>To automate this process and increase the accuracy of
the calculations, the developed IT Threat Management
Methodology software application is used at this stage. This
application integrates all the data, pairwise comparisons,
and weighting factors to calculate the final utility scores.
According to (8), we summarize the prospective values to
obtain a utility score for each threat. Using the developed IT
threat management software, the following result was
obtained (Fig. 2).
Step 7. Prioritize and make decisions about IT threats to CII.</p>
      <p>
        According to (9) and based on the analysis performed by
the developed method, the threats were ranked according to
their total dominance. Let us present the prioritization of
threats, where threats with higher values of total dominance
should be addressed as the most critical (Table 5):
Thus, according to the results obtained with the help of the
special software developed, the following recommendations
have been made about IT threats [
        <xref ref-type="bibr" rid="ref30">31</xref>
        ]:






      </p>
      <p>Denial of Service (DoS): The most critical threat
that needs to be addressed as a matter of priority
is to reduce the risk of denial of service, which can
lead to significant disruptions in CI operations. It
is recommended to implement resilient systems
against DoS attacks using load balancing and
network-level protection techniques.</p>
      <p>Repudiation: Requires improved logging and
auditing systems to ensure accountability and
transparency of operations. Reliable mechanisms
for logging and retaining user activity logs should
be implemented, as well as regular audits to detect
and prevent attempts to deny activity.</p>
      <p>Spoofing: It is necessary to strengthen
authentication procedures and improve
identification and verification systems to prevent
unauthorized access. The use of multi-factor
authentication and advanced user verification
methods is recommended.</p>
      <p>Information disclosure: Data protection
mechanisms should be strengthened, especially for
sensitive information, to prevent unauthorized
disclosure. Data encryption should be
implemented both in transit and at rest, as well as
monitoring and leak detection systems.</p>
      <p>
        Tampering: Protection should be provided against
unauthorized interference with data, although this
threat is not as critical as the others. Data integrity
controls should be used and systems should be
implemented to detect changes to data [
        <xref ref-type="bibr" rid="ref31">32</xref>
        ].
      </p>
      <p>Elevation of privilege: Although this is a serious
threat, it has the lowest dominance score and can be
addressed after more pressing issues. To prevent
privilege escalation, it is necessary to implement the
principle of least privilege, regularly review access
rights, and use tools to detect and block attempts to
elevate user privileges.</p>
    </sec>
    <sec id="sec-7">
      <title>7. Conclusions</title>
      <p>In conclusion, this paper has analyzed the existing methods
of IT threat management at CIIF. It was found that the
problem of IT threat management at CIIF has not been
sufficiently studied, and the existing methods do not
provide a complete solution to the problems of IT threat
assessment for such facilities. Therefore, the authors have
developed a new method for managing IT threats at CIIF by
synthesizing the multi-criteria decision-making method
TODIM and the threat model STRIDE, which allows them to
effectively identify, assess, and prioritize threats, taking into
account their probability, potential damage, and complexity
of implementation. The developed method consists of the
following stages: identification of threats, determination of
evaluation criteria, data normalization, determination of
criteria weights, pairwise comparison of alternative threats,
obtaining an integrative evaluation, prioritization, and
decision-making, and provides an effective approach to
improving the level of CII security.</p>
      <p>An experimental study of the developed method,
conducted for the CII sub-sector “electronic
communications”, showed that the method effectively
contributes to the management of IT threats by prioritizing
these threats. This ensures a high level of CII security and
allows the optimization of security measures to respond
effectively to potential IT threats.</p>
      <p>In addition, thanks to the special software developed, it
was found that for the CII sub-sector “electronic
communications”, the threat of denial of service has the
highest level of criticality. This indicates the need for
priority action to neutralize it. In general, the prioritization
of IT threats in the process of ensuring the protection of CII
can ensure the effective allocation of resources and the
application of the necessary measures to prevent potential
attacks.</p>
      <p>Further research will aim to optimize the method, in
particular by:</p>
      <p>Determine normalized coefficients for selected
threat criteria.</p>
      <p>Extend the recommendations for IT incident
management according to the results obtained.</p>
      <p>Improving the method to allow the assessment of
combined threats.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <given-names>O.</given-names>
            <surname>Mykhaylova</surname>
          </string-name>
          , et al.,
          <article-title>Mobile Application as a Critical Infrastructure Cyberattack Surface</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems II, CPITS-II</source>
          , vol.
          <volume>3550</volume>
          (
          <year>2023</year>
          )
          <fpage>29</fpage>
          -
          <lpage>43</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <given-names>A.</given-names>
            <surname>Zahynei</surname>
          </string-name>
          , et al.,
          <article-title>Method for Calculating the Residual Resource of Fog Node Elements of Distributed Information Systems of Critical Infrastructure Facilities</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems, CPITS</source>
          , vol.
          <volume>3654</volume>
          (
          <year>2024</year>
          )
          <fpage>432</fpage>
          -
          <lpage>439</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>T.</given-names>
            <surname>Lechachenko</surname>
          </string-name>
          , et al.,
          <article-title>Cybersecurity Assessments based on Combining TODIM Method and STRIDE Model for Learning Management Systems</article-title>
          , in: Computer Information Technologies in Industry, vol.
          <volume>3468</volume>
          (
          <year>2023</year>
          )
          <fpage>250</fpage>
          -
          <lpage>256</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>T.</given-names>
            <surname>Lechachenko</surname>
          </string-name>
          , et al.,
          <source>Cybersecurity Aspects of Smart Manufacturing Transition to Industry 5.0 Model</source>
          , in: Information Technologies:
          <source>Theoretical and Applied Problems</source>
          , vol.
          <volume>3628</volume>
          (
          <year>2023</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>J.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Wei</surname>
          </string-name>
          ,
          <string-name>
            <surname>M.</surname>
          </string-name>
          <article-title>Lu, TODIM Method for Multiple Attribute Group Decision Making under 2-Tuple Linguistic Neutrosophic Environment</article-title>
          , Symmetry,
          <volume>10</volume>
          (
          <issue>10</issue>
          ) (
          <year>2018</year>
          )
          <article-title>486</article-title>
          . doi:
          <volume>10</volume>
          .3390/sym10100486
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>G.</given-names>
            <surname>Macher</surname>
          </string-name>
          , et al.,
          <article-title>Threat and Risk Assessment Methodologies in the Automotive Domain, Procedia Comput</article-title>
          . Sci.
          <volume>83</volume>
          (
          <year>2016</year>
          )
          <fpage>1288</fpage>
          -
          <lpage>1294</lpage>
          . doi:
          <volume>10</volume>
          .1016/j.procs.
          <year>2016</year>
          .
          <volume>04</volume>
          .268.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>G.</given-names>
            <surname>Holtrup</surname>
          </string-name>
          , et al.,
          <article-title>Modeling 5G Threat Scenarios for Critical Infrastructure Protection</article-title>
          ,
          <source>in: 15th International Conference on Cyber Conflict: Meeting Reality</source>
          (
          <year>2023</year>
          )
          <fpage>161</fpage>
          -
          <lpage>180</lpage>
          . doi:
          <volume>10</volume>
          .23919/CyCon58705.
          <year>2023</year>
          .
          <volume>10</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>R.</given-names>
            <surname>Khan</surname>
          </string-name>
          , et al.,
          <article-title>STRIDE-based Threat Modeling for Cyber-Physical Systems</article-title>
          ,
          <string-name>
            <surname>IEEE PES Innovative Smart Grid Technologies Conference Europe (ISGT-Europe)</surname>
          </string-name>
          (
          <year>2017</year>
          )
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . doi:
          <volume>10</volume>
          .1109/ISGTEurope.
          <year>2017</year>
          .
          <volume>8260283</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>M.</given-names>
            <surname>Abomhara</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Gerdes</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. M.</given-names>
            <surname>Koien</surname>
          </string-name>
          ,
          <article-title>A STRIDEbased Threat Model for Telehealth Systems</article-title>
          , NISK (
          <year>2015</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>A.</given-names>
            <surname>Shostack</surname>
          </string-name>
          , Experiences Threat Modeling at Microsoft, in: Modeling Security, vol.
          <volume>413</volume>
          (
          <year>2024</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Microsoft</surname>
            <given-names>Corporation</given-names>
          </string-name>
          , “SDL Process Introduction”, URL: http://msdn.microsoft.com/en-us/library/cc3074 06.aspx
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>R.</given-names>
            <surname>Ross</surname>
          </string-name>
          ,
          <article-title>Guide for Conducting Risk Assessments, Special Publication (NIST SP) 800-30 Rev 1</article-title>
          ,
          <string-name>
            <given-names>National</given-names>
            <surname>Institute</surname>
          </string-name>
          of Standards and Technology, Gaithersburg, MD. Available at NIST (
          <year>2012</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [14] International Organization for Standardization,
          <source>ISO/IEC 27005:2022 Information Security, Cybersecurity and Privacy Protection-Guidance on Managing Information Security Risks</source>
          ,
          <string-name>
            <surname>ISO</surname>
          </string-name>
          , Available at ISO (
          <year>2022</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>R. A.</given-names>
            <surname>Caralli</surname>
          </string-name>
          , et al.,
          <string-name>
            <surname>Introducing</surname>
            <given-names>OCTAVE</given-names>
          </string-name>
          <article-title>Allegro: Improving the Information Security Risk Assessment Process</article-title>
          . Carnegie Mellon University, Software Engineering Institute. Available at SEI CMU (
          <year>2007</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>A.</given-names>
            <surname>Shukla</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E. A.</given-names>
            <surname>Solbakken</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Steen</surname>
          </string-name>
          ,
          <article-title>On the CyberEmergency Preparedness in a Resilient Organization</article-title>
          ,
          <source>in: 33rd European Safety and Reliability Conference</source>
          (
          <year>2023</year>
          ). doi:
          <volume>10</volume>
          .3850/
          <fpage>981</fpage>
          -973-0000-00-0.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [17]
          <string-name>
            <surname>ISACA</surname>
          </string-name>
          ,
          <article-title>COBIT 2019 Framework: Governance and Management Objectives</article-title>
          .
          <source>Information Systems Audit and Control Association (ISACA)</source>
          , Available at ISACA (
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>V.</given-names>
            <surname>Astapenya</surname>
          </string-name>
          , et al.,
          <article-title>Conflict Model of Radio Engineering Systems under the Threat of Electronic Warfare</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems, CPITS</source>
          , vol.
          <volume>3654</volume>
          (
          <year>2024</year>
          )
          <fpage>290</fpage>
          -
          <lpage>300</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>T. L.</given-names>
            <surname>Saaty</surname>
          </string-name>
          ,
          <article-title>Decision Making with the Analytic Hierarchy Process</article-title>
          ,
          <source>Int. J. Services Sci</source>
          .
          <volume>1</volume>
          (
          <issue>1</issue>
          ) (
          <year>2008</year>
          )
          <article-title>83</article-title>
          . doi:
          <volume>10</volume>
          .1504/ijssci.
          <year>2008</year>
          .
          <volume>017590</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>H.</given-names>
            <surname>Taherdoost</surname>
          </string-name>
          ,
          <article-title>Decision Making using the Analytic Hierarchy Process (AHP); A Step by Step Approach, Int</article-title>
          .
          <string-name>
            <surname>J. Econom. Manag. Syst.</surname>
          </string-name>
          (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>B.</given-names>
            <surname>Llamazares</surname>
          </string-name>
          ,
          <article-title>An Analysis of the Generalized TODIM Method</article-title>
          ,
          <source>European J. Operational Res</source>
          .
          <volume>269</volume>
          (
          <issue>3</issue>
          ) (
          <year>2018</year>
          )
          <fpage>1041</fpage>
          -
          <lpage>1049</lpage>
          . doi:
          <volume>10</volume>
          .1016/j.ejor.
          <year>2018</year>
          .
          <volume>02</volume>
          .054.
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>G. H.</given-names>
            <surname>Tzeng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. J.</given-names>
            <surname>Huang</surname>
          </string-name>
          ,
          <article-title>Multiple Attribute Decision Making: Methods and Applications</article-title>
          , CRC press (
          <year>2011</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [23]
          <article-title>Law of Ukraine on Critical Infrastructure, Verkhovna Rada of Ukraine</article-title>
          . URL: https://zakon.rada.gov.ua/laws /show/
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          <source>[24] Cabinet of Ministers of Ukraine, Certain Issues of Critical Infrastructure Objects: Resolution No. 1109 dated October 9</source>
          ,
          <year>2020</year>
          . URL: https://zakon.rada.gov. ua/laws/
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>M.</given-names>
            <surname>Al Hadidi</surname>
          </string-name>
          , et al.,
          <source>Adaptive Regulation of Radiated Power Radio Transmitting Devices in Modern Cellular Network Depending on Climatic Conditions</source>
          , Contemporary Engineering Sciences,
          <volume>9</volume>
          (
          <issue>10</issue>
          ) (
          <year>2016</year>
          )
          <fpage>473</fpage>
          -
          <lpage>485</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>M.</given-names>
            <surname>Zaliskyi</surname>
          </string-name>
          , et al.,
          <source>Statistical Data Processing During Wind Generators Operation</source>
          ,
          <source>International Journal of Electrical and Electronic Engineering and Telecommunications</source>
          ,
          <volume>8</volume>
          (
          <issue>1</issue>
          ) (
          <year>2019</year>
          )
          <fpage>33</fpage>
          -
          <lpage>38</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>O.</given-names>
            <surname>Solomentsev</surname>
          </string-name>
          , et al.,
          <source>Sequential Procedure of Changepoint Analysis during Operational Data Processing, IEEE Workshop on Microwave Theory and Techniques in Wireless Communications, MTTW</source>
          (
          <year>2020</year>
          )
          <fpage>168</fpage>
          -
          <lpage>171</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>X.</given-names>
            <surname>Hu</surname>
          </string-name>
          , et al.,
          <source>Statistical Techniques for Detecting Cyberattacks on Computer Networks based on an Analysis of Abnormal Traffic Behavior, Int. J. Comput. Netw. Inf. Secur</source>
          .
          <volume>12</volume>
          (
          <issue>6</issue>
          ) (
          <year>2020</year>
          )
          <fpage>1</fpage>
          -
          <lpage>13</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>O.</given-names>
            <surname>Solomentsev</surname>
          </string-name>
          , et al.,
          <article-title>Data Processing Method for Deterioration Detection during Radio Equipment Operation, IEEE Microwave Theory and Techniques in Wireless Communications</article-title>
          ,
          <string-name>
            <surname>MTTW</surname>
          </string-name>
          (
          <year>2019</year>
          )
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Hassan</surname>
          </string-name>
          , et al.,
          <article-title>Detection of Distributed Denial of Service Attacks Using Snort Rules in Cloud Computing &amp; Remote Control Systems</article-title>
          ,
          <source>in: IEEE 5th International Conference on Methods and Systems of Navigation and Motion Control</source>
          (
          <year>2018</year>
          )
          <fpage>119</fpage>
          -
          <lpage>122</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [31]
          <string-name>
            <given-names>I.</given-names>
            <surname>Ostroumov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Kuzmenko</surname>
          </string-name>
          ,
          <article-title>Statistical Analysis and Flight Route Extraction from Automatic Dependent Surveillance-Broadcast Data, Integrated Communications, Navigation</article-title>
          and Surveillance
          <string-name>
            <surname>Conference</surname>
          </string-name>
          (
          <year>2022</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [32]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Averyanova</surname>
          </string-name>
          , et al.,
          <source>UAS Cyber Security Hazards Analysis and Approach to Qualitative Assessment, Lecture Notes in Networks and Systems</source>
          ,
          <volume>290</volume>
          (
          <year>2021</year>
          )
          <fpage>258</fpage>
          -
          <lpage>265</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>