Theoretical and Applied Cybersecurity
Постійне посилання на фонд
ISSN 2708-1397 (Online), ISSN 2664-2913 (Print)
Періодичність: 4 рази на рік
Рік заснування: 2018
Тематика: теоретичні та криптографічні проблеми кібернетичної безпеки; математичні методи, моделі та технології дослідження безпечного функціонування кіберпростору; алгоритми та методи запобігання і протидії кібератакам; безпека промислових систем та систем критичної інфраструктури; кібербезпека Інтернету речей; інтелектуальні методи забезпечення кібербезпеки; проблемні питання сервісів анонімізації; дослідження вразливостей програмного коду і розробка безпечних програм; соціальний інжиніринг та методи протидії деструктивним впливам на свідомість у кіберпросторі; державна політика у сфері кібернетичної безпеки.
Офіційний сайт: https://tacs.ipt.kpi.ua/
Рік заснування: 2018
Тематика: теоретичні та криптографічні проблеми кібернетичної безпеки; математичні методи, моделі та технології дослідження безпечного функціонування кіберпростору; алгоритми та методи запобігання і протидії кібератакам; безпека промислових систем та систем критичної інфраструктури; кібербезпека Інтернету речей; інтелектуальні методи забезпечення кібербезпеки; проблемні питання сервісів анонімізації; дослідження вразливостей програмного коду і розробка безпечних програм; соціальний інжиніринг та методи протидії деструктивним впливам на свідомість у кіберпросторі; державна політика у сфері кібернетичної безпеки.
Офіційний сайт: https://tacs.ipt.kpi.ua/
Переглянути
Перегляд Theoretical and Applied Cybersecurity за Назва
Зараз показуємо 1 - 20 з 138
Результатів на сторінці
Налаштування сортування
Документ Відкритий доступ A Formal Model for Constructing Sensitive Data Graphs from Cyber Reports using Large Language Models(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Turskyi, ViktorUnstructured cyber threat intelligence (CTI) reports present major challenges for systematic analysis, particularly when accuracy and reliability are critical. This paper introduces a formal, four-stage mathematical model for constructing canonical knowledge graphs from sensitive textual data. The model integrates the advanced extraction and reasoning capabilities of GPT-5 with deterministic rule-based inference and network analysis to bridge the “formalization gap” between probabilistic large language model (LLM) outputs and verifiable analytical structures. Using a corpus of 204 official CERT-UA incident reports as a test case, the methodology successfully normalized thousands of raw entities, identified central threat actors and high-value targets, and revealed distinct operational ecosystems within Ukraine’s cyber threat landscape. Theoretically, the study contributes a replicable and mathematically defined framework for integrating next-generation LLMs into formalized knowledge graph pipelines. Practically, it provides a scalable and reliable tool for analysts in cybersecurity, national security, and related fields, enabling the transformation of unstructured reports into actionable intelligenceДокумент Відкритий доступ A method for assessing risk with accounting for the structure of threat and vulnerability relationships in a complex system(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Polutsyhanova, Viktoriia Igorivna; Smyrnov, SerhiiThe article presents a novel approach to risk assessment in complex information systems, which takes into account the structural relationships between threats, vulnerabilities, and system components. The primary focus is on developing a formalized model that enables the construction of a simplicial complex of dependencies among potential threats and vulnerabilities, as well as identifying their impact pathways on the integrity, availability, and confidentiality of the system. The use of a simplicial complex model is proposed to represent these interconnections and to determine critical nodes that are most vulnerable to compound attacks. The methodology allows for quantitative risk evaluation by calculating threat levels, the probabilities of vulnerability exploitation, and their impact on the system. A key feature of the approach is the consideration of not only individual vulnerabilities but also their interactions, which significantly enhances the accuracy of risk assessment. The results of modeling and applied analysis confirm the effectiveness of the proposed method in identifying the most critical security elements and in justifying protection priorities under limited resource conditions. The proposed method can be integrated into information security management systems to improve the protection level of complex technical infrastructures.Документ Відкритий доступ A Review of modern methods for steganalysis and localization of embedded data in digital images(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Yatsura, Pavlo; Progonov, DmytroThe article provides a systematic review of modern steganalysis methods for digital images based on artificial neural networks. The primary stages of development of advanced cover-image models, from widely used artificial neural networks to contemporary hybrid models, are considered. Advantages and limitations of various types of neural networks for constructing stegodetectors for digital images are investigated. Based on comparative analysis of steganalysis accuracy, it is established that the use of advanced artificial neural networks achieves a detection accuracy of steganograms exceeding 90%, even at low embedding rates (less than 20%). Additionally, applying complex methods of processing both examined images, and feature vectors in multidimensional spaces with studied neural networks allows reducing the computational complexity of configuring stegodetectors without significant losses in stego images detection accuracy.Документ Відкритий доступ Algebraic immunity of vectorial Boolean functions and Boolean Groebner bases(Igor Sikorsky Kyiv Polytechnic Institute, 2020) Alekseychuk, A. N.Документ Відкритий доступ An Algorithm for Analyzing the Ethereum Network Blockchain to Detect Illegal Activities(Igor Sikorsky Kyiv Polytechnic Institute, 2024) Abdullaieva, Esmira; Galchynsky, LeonidThis work is devoted to the research of the blockchain network, in particular, aimed at detecting illegal activity in the Ethereum network using forensic methods. The paper describes the concepts and basic vulnerabilities related to the Ethereum network and the integration of graph analysis to develop an algorithm that scrutinizes Ethereum's transaction structure for illegal activities, including money laundering. In addition, the study includes an analysis of the very structure of Ethereum and the blockchain, which allows insight into the identification and analysis of various aspects of their functioning. The research results are used for the software implementation of the study and improvement of the security level of the blockchain network, including the creation of advanced software solutions for network analysis and protection of the integrity of the blockchain ecosystem. This integrated methodology aims to protect the integrity of blockchain ecosystems.Документ Відкритий доступ An example of fuzzy ontology usage for risk assessment and attack impact(Igor Sikorsky Kyiv Polytechnic Institute, 2024) Kozlenko, OlehThe article discusses the use of fuzzy ontology for assessing risks and impacts of attacks in the field of information security. Fuzzy ontology, which is a formalized way of representing knowledge, offers effective solutions for processing complex and informal processes. The article substantiates the significance of fuzzy logic in structural analysis and presents an example of how new types of attacks influence the ontology. Key findings include the identification of risks associated with attacks through the application of fuzzy sets and entropy theory. The discussion highlights how these methods can enhance threat response and risk management in information systems.Документ Відкритий доступ An Iterative Algorithm for Interdependent Estimation of Node and Link Weights in Corporate Networks for Cyber Risk Analysis(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Alekseichuk, Lesia; Lande, DmytroThe paper proposes a new iterative algorithm MRRW-PageRank (Mutually-Reinforced Risk-Weighted PageRank) for assessing cyber risks in corporate information systems based only on network topology. The algorithm solves the problem of determining link weights, which remains insufficiently solved in existing approaches to centrality analysis. Unlike traditional methods, where link weights are given or assumed to be the same, MRRW-PageRank establishes an interdependence between the importance of nodes and the probability of using paths to them, which models the nature of malicious paths. Node weights are updated according to the modified PageRank based on weighted links, and link weights are recalculated as a function of the importance of the target node and its input degree. The process is repeated iteratively until convergence. The algorithm is implemented as a codeless prompt based on a minimal logical framework, which provides the ability to execute in no-code environments and integrate with LLM agents. A simulation on a model network with 12 objects is presented, demonstrating the effectiveness of the method in prioritizing critical resources and identifying vulnerable penetration paths. The proposed approach is especially relevant at the stages of system design, topology audit, or initial security assessment, when there is no empirical data on vulnerabilities or behavior.Документ Відкритий доступ Analysis of the core research for vendor email compromise filtering model using machine learning(Igor Sikorsky Kyiv Polytechnic Institute, 2023) Zibarov, Dmytro; Kozlenko, OlehVendor email compromise became one of most sophisticated types of social engineering attacks. Strengths of this malicious activity rely on basis of impersonating vendor that company working with. Thus, it is easy for attacker to exploit this trust for doing different type of data exfiltration or ransom. To mitigate risks, that come with these challenges, information security specialist should consider using different types of approaches, including machine learning, to identify anomalies in email, so further damages can be prevented. The purpose of this work lies in the identification of optimal approach for VEC-style attacks detection and optimizing these approaches with least amount of falsepositive (FP) parameters. The object of this research is different methods of text processing algorithms, including machine learning methods for detecting VEC emails. The subject of research in this paper mainly considers impact of mentioned text processing algorithms and its relation with efficiency of VEC email classification, identifying most effective approach and, also, how to improve results of such detections. Results of this paper consists of details for VEC-email attacks detection, challenges that comes with different approaches and proposed solution, that lies in using text processing techniques and agentrelated approach with main sphere of implication – machine-learning systems, that are used for identifying social-engineering attacks through email.Документ Відкритий доступ Application of Large Language Models for Assessing Parameters and Possible Scenarios of Cyberattacks on Information and Communication Systems(Igor Sikorsky Kyiv Polytechnic Institute, 2024) Lande, Dmitry; Novikov, Oleksii; Alekseichuk, LesiaThis paper explores the use of large language models (LLMs) to evaluate parameters and identify potential hostile penetration scenarios in corporate networks, considering logical and probabilistic relationships between network nodes. The developed methodology is based on analyzing the network structure, which includes components such as the Firewall, Mail Server, Web Server, administrator and client workstations, application server, and database server. The probabilities of transitions between these nodes during adversarial attacks are determined using a swarm of virtual experts and two sets of prompts aimed at different LLMs. Among the results obtained through the swarm approach are average transition probabilities, which enable modeling the most likely attack paths from both external and internal network origins. Based on logical-probabilistic analysis, penetration scenarios are ranked according to probabilities, execution time, and resource minimization required by attackers. The proposed methodology facilitates rapid response to threats and ensures an adequate level of cybersecurity by focusing on the most probable and dangerous attack scenarios.Документ Відкритий доступ Application of Ternary Pattern-based Truncated Differential Cryptanalysis to Specific Block Ciphers(Igor Sikorsky Kyiv Polytechnic Institute, 2024) Yakymchuk, Oleksii; Medvedtskyi, KostiantynIn the previous work [1], we proposed a formalized approach to truncated differential cryptanalysisbased on ternary masks which separately consider unchanged, obligatory changed and unknown bitsin differences. A security parameter for S-boxes and encryption mappings that bounds the probabilityof truncated differentials from below was also proposed in the previous paper. The subsequent stepinvolves applying the proposed method to existing real-world ciphers, calculating the defined securityparameter, and assessing the method’s effectiveness and potential applications. Additionally, this paperextends the applicability of the proposed approach by formalizing the𝑋𝑂𝑅operation rules for ternarymasks. This allows us to apply the proposed method to ciphers with a structure of Feistel network.Документ Відкритий доступ Aspects of blockchain reliability considering its consensus algorithms(Igor Sikorsky Kyiv Polytechnic Institute, 2020) Gorniak, K. S.; Kudin, A. M.Документ Відкритий доступ Asymptotic Distributions for S-Box Heterogeneous Differential Probabilities(Igor Sikorsky Kyiv Polytechnic Institute, 2019) Yakovliev, S. V.; Bakhtigozin, V. Yu.Документ Відкритий доступ Automating Cybersecurity Decision‑Making with AI and the Analytic Hierarchy Process(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Svoboda, IgorCybersecurity decisions in large organizations routinely require the integration of heterogeneous qualitative and quantitative considerations. The Analytic Hierarchy Process (AHP) offers a principled framework for such multi-criteria settings, yet reliance on human expert panels constrains scalability and cadence. This study examines whether large language model (LLM) agents can substitute for human panels within AHP without compromising methodological discipline. Seven GPT-4 personas are instantiated as virtual experts and coordinated by an AHP guide to structure and evaluate defenses against social-engineering attacks on a corporate data center. The agents elicit criteria and sub-criteria, construct pairwise comparison matrices, and synthesize priorities under standard AHP procedures. Aggregated judgments exhibit strong internal coherence (top-level consistency ratio CR = 0.016; λ_max = 7.13), yielding a stable ranking of alternatives: comprehensive employee training (0.2774), advanced intrusion detection (0.2240), cloud-based data backup (0.1938), targeted refresher training for security staff (0.1795), and physical barrier enhancements (0.1254). The results indicate that GPT-4 agents can emulate expert judgment for multi-criteria cybersecurity decisions at materially lower cost than human panels, while preserving the methodological rigor of AHP.Документ Відкритий доступ Basic concepts, approaches and fundamentals of cyber threat intelligence(Igor Sikorsky Kyiv Polytechnic Institute, 2022) Makovska, Maryna; Kozlenko, OlehДокумент Відкритий доступ Bit-sliced Algorithm for the 512-point Number Theoretic Transform(Igor Sikorsky Kyiv Polytechnic Institute, 2025) Kripaka, Illia; Fesenko, AndriiA method for computing the 512-digit number theoretic transform used in the Vershyna digital signature scheme, employing bitwise digit operations, is proposed. The correctness of the developed algorithm and its efficient constant-time performance have been proven. The obtained results indicate that the proposed approach is adaptive and can be applied to computations with other polynomials. This enables its easy integration into various cryptosystems to ensure protection against side-channel attacks. The proposed method does not require changes to the digital signature scheme itself, introducing modifications only to the polynomial multiplication function.Документ Відкритий доступ Comparative analysis of machine learning methods for detecting malicious files(Igor Sikorsky Kyiv Polytechnic Institute, 2021) Nafiiev, Alan; Kholodulkin, Hlib; Rodionov, AndriiNowadays, one of the most critical cyber security problems is the fight against malicious software, precisely, the problem of detecting it. Every year, new modern computer viruses are created that are capable of mutation and changing while running. But unfortunately, the developers of antivirus software do not have time to quickly add all types of malicious programs to the signature databases. In this regard, it is sensible to use heuristic detection methods based on algorithms of machine learning. The purpose of this paper is to present several classification methods based on machine learning techniques for detecting zero-day attacks. In particular, the following algorithms were tested: random forest classifier, support vector classifier, greed search in svc, and k-nearest neighbors. The dataset was taken from the Kaggle website. It consists of 19611 executable files of the PE format, 14599 of which are malicious, and 5012 files are benign. This article presents recommended classification and detection methods with advanced analysis of important metrics that allow you to assess and compare machine learning algorithms’ effectiveness and performance for detecting malware.Документ Відкритий доступ Comparative Analysis of the Cybersecurity Indices and Their Applications(Igor Sikorsky Kyiv Polytechnic Institute, 2019) Kravets, V. M.Документ Відкритий доступ Comparison analysis between strict ontologies and fuzzy ontologies(Igor Sikorsky Kyiv Polytechnic Institute, 2024) Kozlenko, OlehOntological modeling has been important in the field of cybersecurity, but with the growing use of artificial intelligence in various processes related to cybersecurity, it has become an increasingly relevant area for research every new year. Ontologies can serve as a primary source of knowledge for artificial intelligence models and as a "sequence of actions" in different processes. Typically, strictontologies were used due to their formalized structure, but they did not fully capture processes that involve fuzzy contexts of actions or results. The aim of this article is to present and analyze different ontologies, both strict and fuzzy, that are used or could be used in the field of cybersecurity and related processes, demonstrating their similarities, differences, and areas of application.Документ Відкритий доступ Comparison of Efficiency of Statistical Models Used for Formation of Feature Vectors by JPEG Images Steganalysis(Igor Sikorsky Kyiv Polytechnic Institute, 2020) Koshkina, NataliyaДокумент Відкритий доступ Comparison of Tools for Web-Application Brute Forcing(Igor Sikorsky Kyiv Polytechnic Institute, 2022) Chalyi, Oleksii; Kolomytsev, MyhailoFor a long time, threat of web-application authentication break remained a problem not only for users but also for business. This threat still exists, since broken authentication provides a blackhat with full access to accounts of users and business data. This article analyzes software tools for breaking authentication as well as it defines time required for breaking-in depending on different conditions. Based on the results of the analysis, the fastest tool was determined. In order to complete this analysis and determine the fastest tool, own web-application was created.