FORMALIZATION AND QUANTITATIVE EVALUATION OF THE CYBER RESILIENCE OF CRITICAL INFRASTRUCTURE FACILITIES: A SET-THEORETIC APPROACH USING ARTIFICIAL INTELLIGENCE
DOI:
https://doi.org/10.15407/dopovidi2026.04.032Keywords:
cybersecurity, cyber resilience, critical infrastructure, set-theoretic model, MITRE CREF, phishing, quantitative evaluation, security metricsAbstract
The article develops and justifies a comprehensive scientific and methodological framework for formalizing and quantitatively assessing the cyber resilience of critical infrastructure objects (CIO) based on set-theoretic and the MITRE Cyber Resiliency Engineering Framework (CREF) methodology. A set-theoretic data model (STDM) has been developed that formalizes the interrelationships between sets of cybersecurity objectives, strategic tasks, subtasks, key protective measures, cyberthreat vectors (including phishing attacks, APTs, DDoS, and destructive attacks on ICS/SCADA systems) and the structural elements of the CIO. An hierarchical system of quantitative evaluation metrics is proposed, covering time indicators of detection and response, functionality preservation levels, service degradation degrees, and system adaptability coefficients. Detailed mathematical dependencies for calculating the integral cyber resilience index of CIO, taking into account the weight coefficients of business process criticality and resource constraints, are presented. Practical testing of the developed model was carried out on the example of assessing the resilience of an energy enterprise’s information and telecommunications network to combined cyberattacks. It has been proven that applying the proposed approach allows objectifying the selection of an optimal set of cybersecurity measures, increasing the level of incident preparedness by 28—34 %, and minimizing potential damage from destructive impacts.
Downloads
References
Yevseiev, S., Ponomarenko, V., Laptiev, O., Milov, O. (Eds.). (2021). Synergy of building cybersecurity systems. Kharkiv: PC Technology Center. https://doi.org/10.15587/978-617-7319-31-2
Korchenko, O., Khokhlachova, Yu. & Skvortsov, S. (2026, May). Formalization of cyber resilience assessment of critical infrastructure facilities to phishing attacks based on a set-theoretic approach. Proceedings of the 15th International Scientific Conference ITSec-2026 (pp. 19-20). Ternopil, Kyiv: TNTU-DUICT. https://itsec-conf.org/ua/handle/17.itsec/article.202636a
Bodeau, D., Graubart, R., McQuaid, R. & Woodill, J. (2018). Cyber resiliency metrics, measures of effectiveness, and scoring: Enabling systems engineers and program managers to select the most useful assessment methods (Technical Report). Bedford, MA: The MITRE Corporation.
Bodeau, D. J. & Graubart, R. (2011). Cyber resiliency engineering framework (Technical Report MTR110237). Bedford, MA: The MITRE Corporation.
Bodeau, D., Brtis, J., Graubart, R. & Salwen, J. (2015). Cyber resiliency engineering aid — The updated cyber resiliency engineering framework and guidance on applying cyber resiliency techniques (Technical Report MTR150264). Bedford, MA: The MITRE Corporation.
Ross, R., Pillitteri, V., Graubart, R., Bodeau, D. & McQuaid, R. (2021). Developing cyber-resilient systems: A systems security engineering approach. NIST Special Publication 800-160, Vol. 2, Rev. 1. Gaithersburg, MD: National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-160v2r1
Fedorenko, A. A., Osadchyy, B. I. & Korzhyk, V. V. (2023). Analysis of methods for detecting vulnerabilities of Web resources to SQL injections. Modern Information Security, No. 3, pp. 57-61. https://doi.org/10.31673/2409-7292.2023.030008
Khoroshko, V., Khokhlachova, Yu., Vyshnevska, N., Chobal, O. & Vengerskyi, P. (2023). Quantitative assessment of cyber protection of information. Ukrainian Information Security, 25, No. 2, pp. 70-76. https://doi.org/10.18372/2410-7840.25.17674
Ivanchenko, Y., Korchenko, O., Zarytskyi, O., Zybin, S. & Vishnevska, N. (2023). Analysis of the concept of cyber resilience of critical infrastructure. Ukrainian Information Security, 25, No. 4, pp. 221-233. https://doi.org/10.18372/2410-7840.25.18228
ISO/IEC 27001:2022. Information security, cybersecurity and privacy protection. Information security management systems. Requirements. Geneva: International Organization for Standardization, 2022.
Korchenko. O. G. (2025). Methods and models for assessing the state of cyber defense of critical infrastructure facilities of the state (transcript of scientific report at the meeting of the Presidium of NAS of Ukraine, June 18, 2025). Visn. Nac. Akad. Nauk Ukr., No. 8, pp. 59-62. https://doi.org/10.15407/visn2025.08.059
Lubis, M., Safitra, M. F., Fakhrurroja, H. & Muttaqin, A. N. (2025). Guarding our vital systems: a metric for critical infrastructure cyber resilience. Sensors, 25, No. 15, 4545. https://doi.org/10.3390/s25154545
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Reports of the National Academy of Sciences of Ukraine

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.

