2025
Постійне посилання на фонд
Переглянути
Перегляд 2025 за Назва
Зараз показуємо 1 - 20 з 37
Результатів на сторінці
Налаштування сортування
Документ Відкритий доступ A Formal Model for Constructing Sensitive Data Graphs from Cyber Reports using Large Language Models(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Turskyi, ViktorUnstructured cyber threat intelligence (CTI) reports present major challenges for systematic analysis, particularly when accuracy and reliability are critical. This paper introduces a formal, four-stage mathematical model for constructing canonical knowledge graphs from sensitive textual data. The model integrates the advanced extraction and reasoning capabilities of GPT-5 with deterministic rule-based inference and network analysis to bridge the “formalization gap” between probabilistic large language model (LLM) outputs and verifiable analytical structures. Using a corpus of 204 official CERT-UA incident reports as a test case, the methodology successfully normalized thousands of raw entities, identified central threat actors and high-value targets, and revealed distinct operational ecosystems within Ukraine’s cyber threat landscape. Theoretically, the study contributes a replicable and mathematically defined framework for integrating next-generation LLMs into formalized knowledge graph pipelines. Practically, it provides a scalable and reliable tool for analysts in cybersecurity, national security, and related fields, enabling the transformation of unstructured reports into actionable intelligenceДокумент Відкритий доступ A method for assessing risk with accounting for the structure of threat and vulnerability relationships in a complex system(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Polutsyhanova, Viktoriia Igorivna; Smyrnov, SerhiiThe article presents a novel approach to risk assessment in complex information systems, which takes into account the structural relationships between threats, vulnerabilities, and system components. The primary focus is on developing a formalized model that enables the construction of a simplicial complex of dependencies among potential threats and vulnerabilities, as well as identifying their impact pathways on the integrity, availability, and confidentiality of the system. The use of a simplicial complex model is proposed to represent these interconnections and to determine critical nodes that are most vulnerable to compound attacks. The methodology allows for quantitative risk evaluation by calculating threat levels, the probabilities of vulnerability exploitation, and their impact on the system. A key feature of the approach is the consideration of not only individual vulnerabilities but also their interactions, which significantly enhances the accuracy of risk assessment. The results of modeling and applied analysis confirm the effectiveness of the proposed method in identifying the most critical security elements and in justifying protection priorities under limited resource conditions. The proposed method can be integrated into information security management systems to improve the protection level of complex technical infrastructures.Документ Відкритий доступ A Review of modern methods for steganalysis and localization of embedded data in digital images(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Yatsura, Pavlo; Progonov, DmytroThe article provides a systematic review of modern steganalysis methods for digital images based on artificial neural networks. The primary stages of development of advanced cover-image models, from widely used artificial neural networks to contemporary hybrid models, are considered. Advantages and limitations of various types of neural networks for constructing stegodetectors for digital images are investigated. Based on comparative analysis of steganalysis accuracy, it is established that the use of advanced artificial neural networks achieves a detection accuracy of steganograms exceeding 90%, even at low embedding rates (less than 20%). Additionally, applying complex methods of processing both examined images, and feature vectors in multidimensional spaces with studied neural networks allows reducing the computational complexity of configuring stegodetectors without significant losses in stego images detection accuracy.Документ Відкритий доступ An Iterative Algorithm for Interdependent Estimation of Node and Link Weights in Corporate Networks for Cyber Risk Analysis(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Alekseichuk, Lesia; Lande, DmytroThe paper proposes a new iterative algorithm MRRW-PageRank (Mutually-Reinforced Risk-Weighted PageRank) for assessing cyber risks in corporate information systems based only on network topology. The algorithm solves the problem of determining link weights, which remains insufficiently solved in existing approaches to centrality analysis. Unlike traditional methods, where link weights are given or assumed to be the same, MRRW-PageRank establishes an interdependence between the importance of nodes and the probability of using paths to them, which models the nature of malicious paths. Node weights are updated according to the modified PageRank based on weighted links, and link weights are recalculated as a function of the importance of the target node and its input degree. The process is repeated iteratively until convergence. The algorithm is implemented as a codeless prompt based on a minimal logical framework, which provides the ability to execute in no-code environments and integrate with LLM agents. A simulation on a model network with 12 objects is presented, demonstrating the effectiveness of the method in prioritizing critical resources and identifying vulnerable penetration paths. The proposed approach is especially relevant at the stages of system design, topology audit, or initial security assessment, when there is no empirical data on vulnerabilities or behavior.Документ Відкритий доступ Automating Cybersecurity Decision‑Making with AI and the Analytic Hierarchy Process(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Svoboda, IgorCybersecurity decisions in large organizations routinely require the integration of heterogeneous qualitative and quantitative considerations. The Analytic Hierarchy Process (AHP) offers a principled framework for such multi-criteria settings, yet reliance on human expert panels constrains scalability and cadence. This study examines whether large language model (LLM) agents can substitute for human panels within AHP without compromising methodological discipline. Seven GPT-4 personas are instantiated as virtual experts and coordinated by an AHP guide to structure and evaluate defenses against social-engineering attacks on a corporate data center. The agents elicit criteria and sub-criteria, construct pairwise comparison matrices, and synthesize priorities under standard AHP procedures. Aggregated judgments exhibit strong internal coherence (top-level consistency ratio CR = 0.016; λ_max = 7.13), yielding a stable ranking of alternatives: comprehensive employee training (0.2774), advanced intrusion detection (0.2240), cloud-based data backup (0.1938), targeted refresher training for security staff (0.1795), and physical barrier enhancements (0.1254). The results indicate that GPT-4 agents can emulate expert judgment for multi-criteria cybersecurity decisions at materially lower cost than human panels, while preserving the methodological rigor of AHP.Документ Відкритий доступ Bit-sliced Algorithm for the 512-point Number Theoretic Transform(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Kripaka, Illia; Fesenko, AndriiA method for computing the 512-digit number theoretic transform used in the Vershyna digital signature scheme, employing bitwise digit operations, is proposed. The correctness of the developed algorithm and its efficient constant-time performance have been proven. The obtained results indicate that the proposed approach is adaptive and can be applied to computations with other polynomials. This enables its easy integration into various cryptosystems to ensure protection against side-channel attacks. The proposed method does not require changes to the digital signature scheme itself, introducing modifications only to the polynomial multiplication function.Документ Відкритий доступ Construction of secure direct communication protocols in the topological quantum computing model(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Fesenko, Andrii; Zatsarenko, AnastasiaThis paper presents an implementation of the six-state quantum key distribution protocol and theLM05 quantum secure direct communication protocol based on anyonic systems. We consider therepresentation of logical qubits and operations of the protocol through the manipulation of abeliananyons of the Kitaev model and non-abelian Fibonacci anyons. A comparative analysis of the anyonicimplementations with the classical photonic approach is carried out in terms of key characteristics suchas accuracy, stability, and complexity. The advantages and experimental challenges of anyonic platformsfor quantum information exchange are discussed.Документ Відкритий доступ Cryptographic attacks on AES based on side-channel information(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Tolmachov, YevheniiThe topic of this work is the refinement of side-channel attacks, using the AES cipher as an example.Most such attacks are based on statistical methods and physical measurements of side-channel infor-mation, which is why the key obtained as a result of the attack may contain errors. The goal of thiswork is to investigate error correction algorithms for the key found during the attack. In the course ofthe work, two cryptographic models and attack algorithms on them are considered. The probability ofsuccess and the complexity of the attacks are theoretically derived and calculated.Документ Відкритий доступ Cybersecurity of Intellectual Information Aggregation Processes into Digital Archives(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Tsyrulnev, YuriyThe article addresses the problem of cybersecurity in intellectual information aggregation (IIA) processes within digital archives, which arise during the automated collection, structuring, semantic enrichment, and analysis of heterogeneous data using artificial intelligence (AI), machine learning (ML), and large language models (LLMs). The study focuses on identifying vulnerabilities of IIA processes and their mathematical formalization across stages such as digitization, image processing, optical character recognition (OCR), classification, indexing, and archival system creation. Particular attention is given to formalizing cyber threats, including unauthorized access, integrity violations, metadata forgery, adversarial attacks on AI/ML models, data manipulation, prompt injection, data exfiltration, and digital signature forgery. For each threat category, mathematically grounded countermeasures are proposed, including encryption, multi‑factor authentication, monitoring, anomaly detection, access control, metadata protection, and adversarial training. The paper emphasizes the emergent properties of combined defenses, highlighting the resilience of digital archives against cyber threats that arise from the interaction of individual safeguards. The proposed models can be applied to the assessment and strengthening of information system security in the context of state and societal digital transformation.Practical aspects of implementing digital archive creation processes have been validated through patented solutions for converting large collections of paper documents into digital information resources [15]. To support the functioning of intellectual information aggregation processes, specialized software packages are employed, themodules of Digital Docs®Technology, registered as a copyrighted work [16]. Practical deployment of the proposed solutions is carried out within the activitiesof DIGITAL DOCS®,registered as a trademark [17].Документ Відкритий доступ Detecting the operation of keyloggers using the dendritic cell algorithm with multiple resolutions(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Shybaiev, Hennadii; Galchynskyi, LeonidThroughout time, criminologists (or their colleagues in history) have tried to develop the most reliable methods of protecting information. Currently, the most common method of information processing is the computer, so today's information protection specialists face the task of protecting data in computers, in which the most common method of information input is data input from the keyboard by the user. Keystroke logging, also known as keylogging, consists in intercepting keystroke codes from the user. This data may contain passwords, personal correspondence, or other confidential information. Therefore, it is very important to pay attention to this method of user interaction with your "machine", because it is through this method that an attacker can steal information directly from the keyboard. Unlike traditional malware such as worms or viruses, some types of keyloggers cannot be detected by modern antivirus protection methods. The paper presents the results of a study of the application of the dendritic cell algorithm with multiple resolutions for the task of determining the presence of a keylogger in the system. Based on the simulation, a new effective model for determining the presence of a keylogger is proposedДокумент Відкритий доступ Determination of Cyberattack Parameters on the Measurements System of Critical Infrastructure Facility(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Novikov, Oleksii; Ilin, Mykola; Ovcharuk, Mykola; Stopochkina, Iryna; Voitsekhovskyi, AndriiThe paper solves the problem of determination and researching the parameters of stealth attacks on the linear Kalman filter data measurement system that bypasses the standard fault diagnosis detector. The relevance of the research is determined not only by the importance of solving cyber security problems, but also by the active use of the Kalman filter in large industrial power supply networks to evaluate the indicators of system nodes, in industrial automation systems, and others. A cyber attack on the measuring system of the Kalman filter is under consideration, the purpose of which is to disrupt the normal functioning of the filter by distorting the measurement signal, which is a mandatory component of the filter. The filtering system is equipped with a fault detector, which detects the presence of an attack on the measurement signals. The condition of the attack is invisibility for the fault detector, that is, the attacker implements a class of stealth attacks on the integrity of the information that circulates and is processed in the system. The task of finding a distorted measurement signal was solved using the variational optimization method and the gradient method of the fastest descent. A computational experiment was conducted, the quantitative characteristics of the algorithm were obtained and analyzed. The proposed method and the corresponding algorithm for determining the parameters of stealth attacks on the measurement system of critical infrastructure objects can be used to solve the problems of testing cyber defense systemsДокумент Відкритий доступ Differential Attack on IDEA Block Cipher Based on Its Key-Adding Function(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Parshyn, Oleksandr; Khmelnytskyi, MykolaThis paper examines a new theoretical differential attack on the IDEA block cipher and several relatedciphers from the same design family, such as PES and MESH. We present an analysis of the mostprobable differentials, which characterise the ciphers’ security against the proposed attack. We alsopropose a design modification targeting the cipher’s key-adding function to enhance its security againstthe attackДокумент Відкритий доступ Dynamic Detection and Classification of Critical Attention Objects under Crisis Events(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Lande, Dmytro; Danyk, YuriyThis article presents the development of a universal methodology for selecting and classifying Critical Objects of Attention (COAs) during crisis events, replacing static, standardized approaches with a dynamic, substantiated model. The authors propose formalizing criticality as an emergent property of the “world–governance–observer” system, where criticality is determined not by an object’s intrinsic attributes, but by its role within crisis dynamics. Leveraging graph theory, information theory, and models of cognitive salience, a phase space of attention is constructed, equipped with a dynamic criticality function κ(o, t) and an attentional energy functional L, enabling optimal selection of a compact subset of COAs. A five-stage methodology–DCSC (Dynamic Criticality Selection & Classification)–is introduced, implemented, and validated on a simulated cyberattack scenario. The model is unsupervised, interoperable with existing monitoring systems (e.g., SIEM, digital twins), and applicable across domains including cybersecurity, critical infrastructure management, and digital public governanceДокумент Відкритий доступ Estimation of the Probability of Success of a Suppression Attack(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Vykhlo, Anton; Kovalchuk, LyudmilaThis work presents the results of research on suppression attacks, which are a specific case of fron-trunning attacks. We provide a formal step-by-step algorithm for executing the attack, along with amathematical model and explicit analytical formulas for calculating an upper bound on the successprobability of such an attack with numerical examples.This study continues the research presented in [1], which investigated insertion and displacementattacks.Документ Відкритий доступ Forecasting Cyber Threat Intelligence with Memory Augmented Transformer(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Feher, AnatoliiCyber threat intelligence data are volatile, irregular, and shaped by abrupt regime shifts, making accurate forecasting particularly challenging. Motivated by this, we explore the potential of a memory-augmented Transformer forecaster that integrates an evolving memory mechanism andconfidence-regulated attention. Introducing complementary design that enables the model to balance adaptability with stability, remaining robust under noise and structural changes in the threat landscape. Building on and re-architecting the original ACWA-based approach, the resulting ChronoTensor introduced enhanced model achieves parity with state-of-the-art forecasting methods while introducing transparent memory and attention pathways that enhance the interpretability and explainability of its predictions.Документ Відкритий доступ Identification of the malicious group’s digital trace using cryptography tools(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Kozlenko, Oleh; Nakonechna, Yuliia; Mokhonko, MykhailoEvery year, information about a new data leak or compromise of a public or private organization becomes more commonplace in everyday life. The most dangerous and effective in this field are special hacker groups whose funding is associated with special government agencies or services. The study of the activities of these groups has led to identification of each unique method (or tactics, techniques and procedures - TTP) and systematization of the findings. The advantage of creating a digital fingerprint of APT groups is to quickly identify similarities in TTPs and compare these intervention attempts with known groups or compare the means of existing groups with new ones for which there is little informationДокумент Відкритий доступ Image steganography – classic and promising methods: a study(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Zubok, Vitaly; Kazmidi, IvanSteganography, the art and science of hiding information within digital media, remains a dynamic and increasingly vital discipline in the age of pervasive digital communication and cybersecurity threats. Images, in particular, serve as highly adaptable carriers for covert data due to their ubiquity and rich payload capacity. This paper presents a comprehensive classification of image-based steganographic techniques, surveying both time-tested methods (e.g., LSB modification, wavelet transform) and cutting-edge approaches. We highlight how artificial intelligence—through deep learning models, generative adversarial networks, and AI-driven compression/enhancement—can greatly improve embedding robustness and evasion of detection. Furthermore, we explore the nascent frontier of quantum steganography, leveraging superposition, entanglement, and quantum key distribution to achieve unprecedented levels of security. Finally, we outline promising research directions that fuse classical methods with next-generation AI and quantum technologies, setting the agenda for the next wave of advances in secure information hiding.Документ Відкритий доступ Influence of SRM filters preprocessing on stego data localization in digital images(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Yatsura, Pavlo; Progonov, DmytroEarly detection and counteraction to unauthorized transmission of sensitive information via publicly available networks are topical tasks today. Of special interest are steganalysis methods aimed for effective destruction of hidden messages embedded into innocuous media files, like digital images. However, practical usage of such methods introduces significant changes into statistical and spectralparameters of processed images, thus revealing the intrusion into stego channels. There are proposed novel methods for localization positions of embedded stego bits into cover images and pointwise processing only these positions. The article quantifies the impact of cover images preprocessing on accuracy of stego bits localization. The case of Spatial Rich Model (SRM) filters usage is considered, while stego bits position detection is performed using novel deep neural networks, such as Unet, LinkNet, PSPNet and FPN models. The results of comparative analysis of localization accuracy proved effectiveness of SRM filters usage, namely to increase of localization accuracy up to five times (from 2.01% to 10.9% of Intersection-over-Union metric values) even for modern adaptive embedding (like MG and MiPOD) and low cover image payload values (about of 3%-5%). Obtained results create preconditions for development of high-accuracy methods for localization positions of stego bits embedded into cover images according to novel embedding methods.Документ Відкритий доступ Information Security Challenges in an Enterprise-Grade Software Development Lifecycle(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Mahomedov, KamilIn an era of escalating cyber threats and digital complexity, the integration of information security into the software development lifecycle (SDLC) is imperative for building trustworthy enterprise-grade software systems. This literature review synthesizes and critically evaluates over 30 scholarly and industry sources to identify current practices, frameworks, and tools for SLDC implementation. It explores prominent cybersecurity frameworks, such as Microsoft’s SDL, OWASP SAMM, NIST SSDF, and assesses how well they accommodate modern cloud security practices within contemporary SDLCs. Special attention is given to the DevSecOps paradigm, which integrates automated security checks and developer engagement into continuous integration and delivery pipelines, and to SBOMs as a means of exposing and managing third-party component risks in complex supply chains. Findings reveal persistent challenges related to integration with agile workflows, cost, lack of standardized metrics, and organizational resistance (i.e. the human factor). The overall result is the amalgamation of software security best practices extracted from the examined literature into a concise overview to assist further research in this area. The paper concludes with a call for more adaptable, scalable, and measurable security practices that align with modern software development methodologies aimed at facilitating the enterprise-grade integration and delivery of code.Документ Відкритий доступ Intrusion detecting systems and blockchain technology(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Sikolenko, EduardIn this article, the information about intrusion detection systems and intrusion prevention systems was analyzed. General information, differences, main advantages and disadvantages of intrusion detection and prevention systems were described. The blockchain technology was analyzed as well. The main information on the blockchain technology was shown: the history of creation, sphere of application, working principle, potential threats and specifics of consensus mechanism. Based on the information given, it is planned to apply the blockchain technology in intrusion detection systems to increase the level of security