FORMALIZATION AND QUANTITATIVE EVALUATION OF THE CYBER RESILIENCE OF CRITICAL INFRASTRUCTURE FACILITIES: A SET-THEORETIC APPROACH USING ARTIFICIAL INTELLIGENCE

Authors

DOI:

https://doi.org/10.15407/dopovidi2026.04.032

Keywords:

cybersecurity, cyber resilience, critical infrastructure, set-theoretic model, MITRE CREF, phishing, quantitative evaluation, security metrics

Abstract

The article develops and justifies a comprehensive scientific and methodological framework for formalizing and quantitatively assessing the cyber resilience of critical infrastructure objects (CIO) based on set-theoretic and the MITRE Cyber Resiliency Engineering Framework (CREF) methodology. A set-theoretic data model (STDM) has been developed that formalizes the interrelationships between sets of cybersecurity objectives, strategic tasks, subtasks, key protective measures, cyberthreat vectors (including phishing attacks, APTs, DDoS, and destructive attacks on ICS/SCADA systems) and the structural elements of the CIO. An hierarchical system of quantitative evaluation metrics is proposed, covering time indicators of detection and response, functionality preservation levels, service degradation degrees, and system adaptability coefficients. Detailed mathematical dependencies for calculating the integral cyber resilience index of CIO, taking into account the weight coefficients of business process criticality and resource constraints, are presented. Practical testing of the developed model was carried out on the example of assessing the resilience of an energy enterprise’s information and telecommunications network to combined cyberattacks. It has been proven that applying the proposed approach allows objectifying the selection of an optimal set of cybersecurity measures, increasing the level of incident preparedness by 28—34 %, and minimizing potential damage from destructive impacts.

Downloads

Download data is not yet available.

References

Yevseiev, S., Ponomarenko, V., Laptiev, O., Milov, O. (Eds.). (2021). Synergy of building cybersecurity systems. Kharkiv: PC Technology Center. https://doi.org/10.15587/978-617-7319-31-2

Korchenko, O., Khokhlachova, Yu. & Skvortsov, S. (2026, May). Formalization of cyber resilience assessment of critical infrastructure facilities to phishing attacks based on a set-theoretic approach. Proceedings of the 15th International Scientific Conference ITSec-2026 (pp. 19-20). Ternopil, Kyiv: TNTU-DUICT. https://itsec-conf.org/ua/handle/17.itsec/article.202636a

Bodeau, D., Graubart, R., McQuaid, R. & Woodill, J. (2018). Cyber resiliency metrics, measures of effectiveness, and scoring: Enabling systems engineers and program managers to select the most useful assessment methods (Technical Report). Bedford, MA: The MITRE Corporation.

Bodeau, D. J. & Graubart, R. (2011). Cyber resiliency engineering framework (Technical Report MTR110237). Bedford, MA: The MITRE Corporation.

Bodeau, D., Brtis, J., Graubart, R. & Salwen, J. (2015). Cyber resiliency engineering aid — The updated cyber resiliency engineering framework and guidance on applying cyber resiliency techniques (Technical Report MTR150264). Bedford, MA: The MITRE Corporation.

Ross, R., Pillitteri, V., Graubart, R., Bodeau, D. & McQuaid, R. (2021). Developing cyber-resilient systems: A systems security engineering approach. NIST Special Publication 800-160, Vol. 2, Rev. 1. Gaithersburg, MD: National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-160v2r1

Fedorenko, A. A., Osadchyy, B. I. & Korzhyk, V. V. (2023). Analysis of methods for detecting vulnerabilities of Web resources to SQL injections. Modern Information Security, No. 3, pp. 57-61. https://doi.org/10.31673/2409-7292.2023.030008

Khoroshko, V., Khokhlachova, Yu., Vyshnevska, N., Chobal, O. & Vengerskyi, P. (2023). Quantitative assessment of cyber protection of information. Ukrainian Information Security, 25, No. 2, pp. 70-76. https://doi.org/10.18372/2410-7840.25.17674

Ivanchenko, Y., Korchenko, O., Zarytskyi, O., Zybin, S. & Vishnevska, N. (2023). Analysis of the concept of cyber resilience of critical infrastructure. Ukrainian Information Security, 25, No. 4, pp. 221-233. https://doi.org/10.18372/2410-7840.25.18228

ISO/IEC 27001:2022. Information security, cybersecurity and privacy protection. Information security management systems. Requirements. Geneva: International Organization for Standardization, 2022.

Korchenko. O. G. (2025). Methods and models for assessing the state of cyber defense of critical infrastructure facilities of the state (transcript of scientific report at the meeting of the Presidium of NAS of Ukraine, June 18, 2025). Visn. Nac. Akad. Nauk Ukr., No. 8, pp. 59-62. https://doi.org/10.15407/visn2025.08.059

Lubis, M., Safitra, M. F., Fakhrurroja, H. & Muttaqin, A. N. (2025). Guarding our vital systems: a metric for critical infrastructure cyber resilience. Sensors, 25, No. 15, 4545. https://doi.org/10.3390/s25154545

Published

31.08.2026

How to Cite

Korchenko, O., & Khokhlachova, Y. (2026). FORMALIZATION AND QUANTITATIVE EVALUATION OF THE CYBER RESILIENCE OF CRITICAL INFRASTRUCTURE FACILITIES: A SET-THEORETIC APPROACH USING ARTIFICIAL INTELLIGENCE. Reports of the National Academy of Sciences of Ukraine, (4), 32–42. https://doi.org/10.15407/dopovidi2026.04.032

Issue

Section

Information Science and Cybernetics