VLDB 2026 Research / reviewers in the wild / expert
Igor V. Kotenko
dblp:57/3022
· DBLP profile ↗
80ranked-venue papers
36as first author
20since 2021 · last 2026
0000-0001-6859-7120ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 12 first-author · 4 since 2021Artificial intelligence and machine learning · 10 · 5 first-author · 4 since 2021Systems, architecture and hardware · 5 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 4 · 4 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorComputer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Flexible Multi-Task Learning Framework for IoT Network Intrusion Detection: Soft Parameter Sharing and Adaptive Resampling
Huiyao Dong, Igor V. Kotenko |
Future Gener. Comput. Syst. | 2 |
| 2025 | Investigating the Proximity Metric of Program Assembler Code for Genetic Reverse EngineeringabstractThe paper is devoted to solving the problem of assessing the similarity of two programs, which can be used in various areas of information security and cyber forensics, such as malware search, code reuse, authorship verification, and genetic reverse engineering. For this purpose, a corresponding metric is proposed, the value of which is in the range from 0 to 1 (inclusive). The prerequisites for creating the metric are indicated, the idea is described, and an algorithm for calculating it is given, which is then implemented in the Python programming language. The metric is applied to 10 synthetic tests, which shows its overall performance and sensitivity to differences in the assembler code of programs. In addition, a series of experiments is carried out with a direct application of the metric to the assembler code of real mathematical expressions in the $\mathbf{C}$ programming language. Comparison of metric values with the Jaccard Index shows its significant advantage. The importance of using the metric in the authors’ direction of genetic reverse engineering, intended to obtain the source code of a program from its machine or assembler code by using genetic algorithms, is substantiated. The main shortcomings of the research are indicated, their justifications, and ways of elimination are given. Konstantin E. Izrailov, Igor V. Kotenko |
PDP | 2 |
| 2025 | A Noise-Based Approach Augmented with Neural Cleanse and JPEG Compression to Counter Adversarial Attacks on Image Classification SystemsabstractAdversarial attacks are now becoming quite a dangerous means of disrupting image processing systems that use machine learning methods for decision making. Therefore, developing effective countermeasures against adversarial attacks is becoming quite an important area of cybersecurity. The paper proposes a noise-based approach to countering adversarial attacks that is augmented with neural-cleanse and jpeg-compression technologies. The idea of the proposed approach is that adding noise distorts the effect of an adversarial attack, and neural cleaning and jpeg compression eliminate the consequences of such an effect. The paper examines the three most well-known types of adversarial attacks: Fast Gradient Sign Method, Zeroth Order Optimization and One Pixel Attack. These attacks manipulate input data, resulting in misclassification or incorrect predictions by exploiting high-frequency components that are undetectable to humans. The research was carried out on two datasets: MNIST-JPG and PC Parts Images. Two types of noise were used: Gaussian and Poisson. During the experiments, optimal parameters for these types of noise were found, ensuring maximum accuracy of image recognition after exposure to adversarial attacks. Igor V. Kotenko, Igor Saenko 0001, Oleg Lauta, Nikita Vasiliev, Vladimir Sadovnikov |
PDP | 1 |
| 2025 | Modeling of smart additive manufacturing processes for attack analysis and detectionabstractThe paper proposes an approach to modelling the processes of smart industrial additive manufacturing and related types of attacks in laboratory conditions. The objective of such modelling is to analyze potentially relevant types of attacks on such systems and to evaluate their feasibility. A typical customer-oriented 3D printer BQ Prusa i3 Hephestos 2 is taken as a basis for the proposed approach, as it enables the additive printing of end products and individual parts of complex technical products, e.g. Unmanned Aerial Vehicle (UAV) parts, using plastic spools. In the simulated scenario, the printer operates in conjunction with a personal computer (PC). PC sends digital models of the products to print using G-commands transmitted as part of the Universal Serial Bus (USB) traffic. In this scenario, a range of potential forms of unauthorized interference are examined. In particular, an attack on the digital model of the printed product, whereby the model is modified without due authorization, is simulated by using a built testbed. Such an attack assumes that, upon completion of the printing process, the printed product will appear visually almost indistinguishable from the expected one. However, it will have internal design defects that could significantly affect the reliability of the subsequent operation of this product. The experimental part of the work confirms the feasibility of this type of attack, proposes a way of express detection of such modifications by restoring the model based on G-code analysis. Aleksei Meleshko, Vasily Desnitsky, Igor V. Kotenko |
PDP | 3 |
| 2025 | ForecaState: Framework for industrial Internet of Things state forecasting using recurrent neural networks with hyperparameters optimization
Diana Levshun, Dmitry Levshun, Igor V. Kotenko |
Eng. Appl. Artif. Intell. | 3 |
| 2025 | What are your privacy risks? Privacy risk assessment based on privacy policies analysis
Evgenia Novikova, Elena Fedorchenko, Igor V. Kotenko |
Expert Syst. Appl. | 3 |
| 2025 | Cybersecurity in the AI era: analyzing the impact of machine learning on intrusion detection
Huiyao Dong, Igor V. Kotenko |
Knowl. Inf. Syst. | 2 |
| 2025 | Next-generation IIoT security: Comprehensive comparative analysis of CNN-based approaches
Huiyao Dong, Igor V. Kotenko, Dmitry Levshun |
Knowl. Based Syst. | 2 |
| 2024 | Enhancing Security in EV Charging Systems: A Hybrid Detection and Mitigation ApproachabstractThe rapid proliferation of electric vehicles (EVs) necessitates advanced charging infrastructure, which is increasingly reliant on cloud-based technologies and the Internet of Things (IoT). However, these systems are vulnerable to cyber attacks that could have severe repercussions, including power grid failures. This paper addresses the security vulnerabilities inherent in the EV charging system. We propose a novel hybrid security solution tailored for cloud-based EV charging systems that integrates time-series-based regression models with classification algorithms to detect and mitigate both power consumption anomalies and network intrusions effectively. Our approach includes a comprehensive analysis to identify vulnerabilities and threats for cloud-based EV systems, a dual-model system for anomaly and intrusion detection, and a feedback-based threshold adjustment mechanism to assist overflow and anomaly identification. We provide a detailed analysis of data communication threats from a cloud perspective, design a robust security model, and evaluate various models to select the most effective ones for real-time security management. The finally decided models present excellent accuracy and practical value. Our findings contribute to enhancing the resilience of EV charging systems against cyber-physical threats, ensuring more reliable and secure operations. Huiyao Dong, Igor V. Kotenko |
CloudCom | 2 |
| 2024 | Modelling user notification scenarios in privacy policiesabstractAbstract The processing of personal data gives a rise to many privacy concerns, and one of them is to ensure the transparency of data processing to end users. Usually this information is communicated to them using privacy policies. In this paper, the problem of user notification in case of data breaches and policy changes is addressed, besides an ontology-based approach to model them is proposed. To specify the ontology concepts and properties, the requirements and recommendations for the legislative regulations as well as existing privacy policies are evaluated. A set of SPARQL queries to validate the correctness and completeness of the proposed ontology are developed. The proposed approach is applied to evaluate the privacy policies designed by cloud computing providers and IoT device manufacturers. The results of the analysis show that the transparency of user notification scenarios presented in the privacy policies is still very low, and the companies should reconsider the notification mechanisms and provide more detailed information in privacy policies. Mikhail Kuznetsov, Evgenia Novikova, Igor V. Kotenko |
Cybersecur. | 3 |
| 2024 | Multi-task learning for IoT traffic classification: A comparative analysis of deep autoencoders
Huiyao Dong, Igor V. Kotenko |
Future Gener. Comput. Syst. | 2 |
| 2023 | VAE-GAN for Robust IoT Malware Detection and Classification in Intelligent Urban Environments: An Image Analysis Approach
Huiyao Dong, Igor V. Kotenko |
CRiSIS | 2 |
| 2023 | Intelligent state assessment of complex autonomous objects based on wavelet analysisabstractThe evolutionary development of complex autonomous technical objects (CATOs), which include bodynets, unmanned vehicles , aircraft, and other robotic systems , is characterized by increased requirements for the quality of their functioning, security, and reliability under the influence of various kinds of destabilizing factors. This determines the importance of the problem of assessing their technical state, including monitoring degradation (aging) and supporting the dynamic adaptation of CATOs. To solve this problem, the article proposes a new method for intelligent assessment of the CATO technical state. The method is based on the representation of knowledge about the results of interval estimation of controlled parameters in the knowledge base of the system for assessing the CATO technical state. In this case, the process of estimating the controlled parameters is based on the application of wavelet analysis . The article discusses the architecture and implementation issues of the intelligent system for assessing the CATO technical state. A special place in this system is occupied by the knowledge base containing information about the emergency and normal states of controlled parameters. An experimental evaluation of the proposed assessment method showed that the joint use of knowledge representation processes in the knowledge base and wavelet analysis for the formation of CATO operability regions increases the accuracy and credibility of the state identification results. In addition, this approach expands the possibilities of applying technical means of control and diagnostics concerning evolving CATO. Igor V. Kotenko, Igor Saenko 0001, Alexey Vinogradenko, Nikita Budko |
Eng. Appl. Artif. Intell. | 1 |
| 2022 | An approach to formal desription of the user notification scenarios in privacy policiesabstractNowadays the collection and usage of users' personal data have become an extremely common scenario. The users actively provide their personal data to customize or improve the quality of various digital services. Privacy policies are the only official way to inform data owners how their personal data are processed. There are different approaches for increasing the transparency of privacy policies and user agreements. This paper discusses ontology-based approaches and proposes formal descriptions of data processors' obligations relating to policy change and notification in case of a data breach. Mikhail Kuznetsov, Evgenia Novikova, Igor V. Kotenko |
PDP | 3 |
| 2022 | Towards Resilient and Efficient Big Data Storage: Evaluating a SIEM Repository Based on HDFSabstractBuilding an efficient, scalable, distributed storage system is challenging in a variety of industries. Currently, the most promising and efficient way to organize this method of data storage is using the Hadoop Distributed File System (HDFS). It is of interest to develop an approach to optimize the distribution of replicas across storage nodes, which allows one to provide the required resilience and efficiency of storing big data in distributed systems based on HDFS. The analysis showed that in the well-known works on processing big data, the issues of simultaneous provision of resilient and efficient data storage are practically not raised. The paper proposes an approach based on the application of the developed probabilistic models for assessing the resilience and efficiency of data storage. The models take into account the random and deterministic modes of distribution of data blocks across the network nodes and allow one to solve the task of providing resilient and efficient big data storage in three kinds of criteria: resilience maximization, efficiency maximization, and restrictions of resilience and efficiency. The objective of the experiment was to optimize the variables of the the security information and event management (SIEM) system. Experiments have confirmed the effectiveness of the proposed approach and the possibility of solving with its help the assigned tasks to satisfy the three selected species. At the same time, genetic algorithms (GAs) were used for the deterministic mode, in which some improvements were introduced regarding the construction of chromosomes and types of fitness functions. Igor Saenko 0001, Igor V. Kotenko |
PDP | 2 |
| 2021 | Selection of Deep Neural Network Models for IoT Anomaly Detection ExperimentsabstractThis research is about selection of deep neural network models for anomaly detection in Internet of Things network traffic. We are experimentally evaluating deep neural network models using the same software, hardware and the same subsets of the UNSW-NB 15 dataset for training and testing. The assessment results are quality metrics of anomaly detection and the time spent on training models. Diana Levshun, Igor V. Kotenko |
PDP | 2 |
| 2021 | A technique for early detection of cyberattacks using the traffic self-similarity property and a statistical approachabstractThe paper discusses a technique for detecting cyberattacks on computer networks, based on identifying anomalies in network traffic by assessing its self-similarity and determining the impact of cyber attacks using statistical methods. The proposed technique includes three stages, at which the analysis of the self-similarity property for the reference traffic is performed (using the methods of the Dickey-Fuller test, rescaled range, and detrended fluctuation), the analysis of the self-similarity property for the real traffic (by the same methods) and additional processing of time series with statistical methods (methods of moving average, Z-Score, and CUSUM). The issues of software implementation of the proposed approach and the formation of a dataset containing network packets are considered. The experimental results demonstrated the presence of self-similarity in network traffic and confirmed the high efficiency of the proposed method. This technique allows detecting cyberattacks in real or near real time. Igor V. Kotenko, Igor Saenko 0001, Aleksander Kribel, Oleg Lauta |
PDP | 1 |
| 2021 | Situational Control of a Computer Network Security System in Conditions of Cyber AttacksabstractModern cyberattacks are the most powerful disturbance factor for computer networks, as they have a complex and devastating impact. The impact of cyberattacks is primarily aimed at disrupting the performance of computer network protection means. Therefore, managing this defense system in the face of cyberattacks is an important task. The paper examines a technique for constructing an effective control system for a computer network security system operating in real time in the context of cyber attacks. It is supposed that it is built on the basis of constructing a system state space and a stack of control decisions. The probability of finding the security system in certain state at each control step is calculated using a finite Markov chain. The technique makes it possible to predict the number of iterations for managing the security system when exposed to cyber attacks, depending on the segment of the space of its states and the selected number of transitions, as well as automatically generate control decisions. An algorithm has been developed for situational control of a computer network security system in conditions of cyber attacks. The experimental results obtained using the generated dataset demonstrated the high efficiency of the developed technique and the ability to use it to determine the parameters that are most susceptible to abnormal deviations during the impact of cyber attacks. Igor V. Kotenko, Igor Saenko 0001, Oleg Lauta, Mikhail Karpov |
SIN | 1 |
| 2021 | Towards Security Decision Support for large-scale Heterogeneous Distributed Information SystemsabstractThe paper considers the challenge of security decision support for automated intrusion prevention within large-scale heterogeneous distributed information systems. The authors outline the main types of modern information systems, their features, and interconnections. They analyse existing research and solutions in the area of security decision support for the different types of large-scale heterogeneous distributed information systems, their functionality, used models, methods and metrics, advantages and disadvantages, and compare them. Finally, the authors outline the main challenges and tasks in the area and propose a common approach for security decision support. In the future work the authors plan to detail and implement the proposed approach. Ivan Murenin, Elena Fedorchenko, Igor V. Kotenko |
SIN | 3 |
| 2021 | LSTM Neural Networks for Detecting Anomalies Caused by Web Application Cyber AttacksabstractDetecting anomalies in the traffic of computer networks is an important step in protecting and countering various types of cyber attacks. Among the many methods and approaches for detecting anomalies in network traffic, the most popular are machine learning methods that allow one to achieve high accuracy with minimal errors. One of the ways to improve the efficiency of anomaly detection using machine learning is the use of artificial neural networks of complex architecture, in particular, networks with long short-term memory (LSTM), which have demonstrated high efficiency in many areas. The paper is devoted to the study of the capabilities of LSTM neural networks for detecting network anomalies. It proposes using LSTM neural networks to detect network anomalies caused by cyber attacks to bypass Web Application Firewall vulnerabilities that are very difficult to detect by other means. For this purpose, it is proposed to use LSTM in conjunction with an autoencoder. The issues of software implementation of the proposed approach are considered. The experimental results obtained using the generated dataset confirmed the high efficiency of the developed approach. Experiments have shown that the proposed approach allows detecting cyber attacks in real or near real time. Igor V. Kotenko, Oleg Lauta, Kseniya Kribel, Igor Saenko 0001 |
SoMeT | 1 |
| 2020 | Towards Attacker Attribution for Risk Analysis
Elena Fedorchenko, Evgenia Novikova, Diana Levshun, Igor V. Kotenko |
CRiSIS | 4 |
| 2020 | Selection of Countermeasures against Harmful Information based on the Assessment of Semantic Content of Information Objects in the Conditions of UncertaintyabstractThe paper suggests models, an algorithm and a common technique for selection of countermeasures against harmful information based on the assessment of semantic content of information objects in the conditions of uncertainty. The methods of processing of incomplete, conflicting and fuzzy knowledge are used. A version of the common algorithm for eliminating the uncertainties of assessment and categorization of information objects' semantic content while detecting harmful information is analysed. The results of operation of the technique to determine the list of available countermeasures considering the responsibility areas are discussed. Igor B. Parashchuk, Elena Fedorchenko, Igor Saenko 0001, Igor V. Kotenko |
INISTA | 4 |
| 2020 | Graph-based evaluation of probability of disclosing the network structure by targeted attacksabstractProtecting data transmission networks from targeted attacks is currently a priority cyber security goal in critical infrastructures. The paper considers the approach to the evaluation of the probability of disclosing the structure of the data transmission network when the attacker implements targeted attacks. The approach is based on graph theory. The conceptual model of the targeted attack is presented. Algorithms for estimating the structural secrecy of data transmission networks are developed. They include an algorithm for evaluating the probability of compromising a network node and recognizing the structure of the data transmission network, as well as a generalized algorithm for estimating the structural secrecy. Implementation and results of the experimental evaluation of the proposed approach are discussed. Andrei Privalov, Ekaterina Skudneva, Igor V. Kotenko, Igor Saenko 0001 |
NOMS | 3 |
| 2020 | Augmented reality for visualizing security data for cybernetic and cyberphysical systemsabstractThe paper discusses the use of virtual (VR) and augmented (AR) reality for visual analytics in information security. Paper answers two questions: “In which areas of information security visualization VR/AR can be useful?” and “What is the difference of the VR/AR from similar methods of visualization at the level of perception of information?”. The first answer is based on the investigation of information security areas and visualization models that can be used in VR/AR security visualization. The second answer is based on experiments that evaluate perception of visual components in VR. Maxim Kolomeets, Andrey Chechulin, Ksenia Zhernova, Igor V. Kotenko, Diana Levshun |
PDP | 4 |
| 2020 | Optimizing Secure Information Interaction in Distributed Computing Systems by the Sequential Concessions MethodabstractThe paper proposes a new approach to multicriteria optimization of the structure of secure information interaction in distributed computing systems. A distinguishing feature of the approach is the use of the sequential concessions method. This approach provides the acceptable flexibility in comparing the system construction variants by taking into account not only the priority of the system according to efficiency indicators, but also the relationships of the indicators. The mathematical basis of the proposed method is considered. The procedure of implementation of the proposed method for ensuring security of information interaction in a distributed hierarchical automated control system is demonstrated, and its experimental assessment is given. Igor V. Kotenko, Yury Sineshchuk, Igor Saenko 0001 |
PDP | 1 |
| 2020 | Social networks bot detection using Benford's lawabstractThe paper considers the task of bot detection in social networks. It checks the hypothesis that bots break Benford’s law much more often than users, so one can identify them. A bot detection approach is proposed based on experiments where the test results for bot datasets of different classes and real-user datasets of different communities are evaluated and compared. The experiments show that automatically controlled bots possibly can be identified by disagreement with Benford’s law, while human-orchestrated bots are not. Maksim Kalameyets, Dmitry Levshun, Sergei Soloviev 0001, Andrey Chechulin, Igor V. Kotenko |
SIN | 5 |
| 2020 | Intelligent support for network administrator decisions based on combined neural networksabstractIt is difficult to imagine the administration of computer networks without constant monitoring of the state of their individual nodes, segments and networks as a whole. The number of nodes in modern networks is constantly increasing; the topology is becoming more complicated. It is increasingly difficult for a network administrator to timely identify and resolve abnormal situations. Specialized intelligent support systems or specialized knowledge bases can help in this task. The paper discusses the implementation option of the analytical unit of the network administrator's intelligent support system built on the basis of artificial neural networks. The paper considers the structure of a combined neural network, focused on solving the problem of assessing the state of computer network elements. Three training methods are considered: the stochastic gradient descent, the adaptive learning rate method, and the adaptive inertia method. The results of the experiments demonstrated a sufficiently high accuracy of the proposed solution, good adaptability and the possibility of its application in a wide range of network configurations. Igor V. Kotenko, Igor Saenko 0001, Fadey Skorik |
SIN | 1 |
| 2020 | GRIDHPC: A decentralized environment for high performance computingabstractSummary This paper presents GRIDHPC, a decentralized environment dedicated to high performance computing. It relies on the reconfigurable multi network protocol RMNP to support data exchange between computing nodes on multi network systems with Ethernet, Infiniband, Myrinet, and on OpenMP for the exploitation of computing resources of multicore CPU. We report on scalability of several parallel iterative schemes of computation combined with GRIDHPC. In particular, the experimental results show that GRIDHPC scales up when combined with asynchronous iterative schemes of computation. Bilal Fakih, Didier El Baz, Igor V. Kotenko |
Concurr. Comput. Pract. Exp. | 3 |
| 2020 | Latest advances in parallel, distributed, and network-based processingabstractAbstract This editorial introduces the articles selected for the special issue concerning the International Conferences on Parallel, Distributed, and Network‐Based Processing, which provided insights related to the efficient exploitation of parallel and distributed architectures, including power‐aware computing, application scheduling, and application development for GPUs. Ivan Merelli, Pietro Liò, Igor V. Kotenko, Daniele D'Agostino |
Concurr. Comput. Pract. Exp. | 3 |
| 2020 | Stateful RORI-based countermeasure selection using hypergraphs
Gustavo Gonzalez Granadillo, Elena Fedorchenko, Joaquín García 0001, Igor V. Kotenko, Andrey Fedorchenko |
J. Inf. Secur. Appl. | 4 |
| 2020 | Stateful RORI-based countermeasure selection using hypergraphs
Gustavo Gonzalez Granadillo, Elena Fedorchenko, Joaquín García 0001, Igor V. Kotenko, Andrey Fedorchenko |
J. Inf. Secur. Appl. | 4 |
| 2019 | Ontology of Metrics for Cyber Security AssessmentabstractDevelopment of metrics that are valuable for assessing security and decision making is an important element of efficient counteraction to cyber threats. The paper proposes an ontology of metrics for cyber security assessment. The developed ontology is based on determining the concepts and relations between primary features of initial security data and forming a set of hierarchically interconnected security metrics. The paper describes the main classes of the proposed ontology, the revealed relations, the involved security metrics, and the used data sources. The publicly available sources of security data are analyzed to get primary security metrics. Application of the approach is shown on a case study. The main feature of the proposed ontology is representation of security metrics as separate instances of ontology. It allows using the relations between the concepts of ontology for calculating integral metrics reflecting the security state. Elena Fedorchenko, Andrey Fedorchenko, Igor V. Kotenko |
ARES | 3 |
| 2019 | Access Control Visualization Using Triangular MatricesabstractThe paper proposes an approach for visualization of access control systems based on triangular matrices. The approach is used for visualization of access control security model that based in methods of RBAC and Take-Grant. In comparison with regular access matrices, the sparseness of triangular matrices is less, and the approach is able to visualize nesting at the level of rights. The paper outlines a new triangular visualization model, its interpretation, management methods, and the results of experiments for visualization of an access control system in an IT company. Maxim Kolomeets, Andrey Chechulin, Igor V. Kotenko, Igor Saenko 0001 |
PDP | 3 |
| 2019 | Attack Detection in IoT Critical Infrastructures: A Machine Learning and Big Data Processing ApproachabstractThe paper presents an approach to detection of attacks against Internet-of-Things networks and devices which can be used in critical infrastructures. It is based on use of machine learning and big data processing. Feature of the offered approach is using the method of reduction of output data sets and application of various algorithms of machine learning based on distributed data processing. The paper compares the speed and accuracy of attack detection on the basis of machine learning algorithms in the local and distributed modes. Igor V. Kotenko, Igor Saenko 0001, Alexey Kushnerevich, Alexander Branitskiy |
PDP | 1 |
| 2019 | Combining spark and snort technologies for detection of network attacks and anomalies: assessment of performance for the big data frameworkabstractThe paper proposes an approach to security information processing in order to detect computer attacks and network anomalies based on big data technologies. The main contribution of the work is in the development, implementation and investigation of the proposed combined framework for processing security data using parallel computing environment and measuring the performance of the implemented system for detection of network attacks and anomalies. The research goal is to increase the performance of attack detection (under the given requirements for accuracy of solutions) compared to the traditional IDS application. The implemented approach is built using the open source systems Snort and Spark. The paper discusses the capabilities and performance assessment of parallel data processing in order to detect computer attacks and network anomalies, as well as key principles of working with big data. The presented main results of an experimental performance evaluation of the applied approach confirm its high efficiency for analyzing network traffic and security events. Igor V. Kotenko, Nikolay Komashinsky |
SIN | 1 |
| 2019 | Optimization of the cyber security system structure based on accounting of the prevented damage costabstractSearching the optimum structure of cyber security systems is an important problem which should be solved to realize security mechanisms (means) in computing systems, especially when there are significant resource restrictions (small enterprises, built-in systems, cyber-physical systems, etc.). The complexity of this problem is caused by its uncertain, probabilistic, and nonlinear character. The paper proposes a mathematical model for determination of the cost of the damage prevented by cyber security means and the costs of installation and maintenance of the cyber security system under analysis. The optimization criterion is the minimal cost of the prevented damage. The variables of the problem are the quantities of the security means of various types installed in the security system. The paper considers a method to solve the problem and the features of its implementation. The possibilities of using various methods to increase the accuracy of initial data for the proposed model are analyzed. Igor V. Kotenko, Igor Saenko 0001, Yury Sineshchuk, Valery Kuvatov, Oleg Chudakov |
SIN | 1 |
| 2019 | An Approach for Intelligent Evaluation of the State of Complex Autonomous Objects Based on the Wavelet AnalysisabstractIncreasing requirements for the quality of functioning of complex autonomous technical objects (bodynets, robotic complexes, unmanned cars and aerial vehicles, etc.), as well as their security and reliability, made the problem of assessing their state particularly relevant given the impact of various types of attacks and destabilizing factors, aging and technological dispersion of parameters. The paper proposes a new approach to intelligent evaluation of the state of such objects. The approach is based on interval assessment of parameters, use of a knowledge base about critical and state conditions, and application of wavelet analysis. The architecture and realization of an intelligent system for evaluation of the state of complex autonomous technical objects is considered. The carried-out experimental assessment of the offered approach showed that use of wavelet analysis when forming areas of objects' operability allows one to make accurate differentiation of classes of their technical states that increases the accuracy and reliability of state identification and also to expand possibilities of technical means of control and diagnostics. Igor V. Kotenko, Pavel Budko, Alexey Vinogradenko, Igor Saenko 0001 |
SoMeT | 1 |
| 2019 | Hierarchical fuzzy situational networks for online decision-making: Application to telecommunication systems
Igor V. Kotenko, Igor Saenko 0001, Sergey Ageev |
Knowl. Based Syst. | 1 |
| 2018 | Determination of Security Threat Classes on the basis of Vulnerability Analysis for Automated Countermeasure SelectionabstractCurrently the task of automated security monitoring and responding to security incidents is highly relevant. The authors propose an approach to determine weaknesses of the analyzed system on the basis of its known vulnerabilities for further specification of security threats. It is relevant for the stage of determining the necessary and sufficient set of security countermeasures for specific information systems. The required set of security response tools and means depends on the determined threats. The possibility of practical implementation of the approach follows from the connectivity between open databases of vulnerabilities, weaknesses, and attacks. The authors applied various classification methods for vulnerabilities considering values of their properties. The paper describes source data used for classification, their preprocessing stage, and the classification results. The obtained results and the methods for their enhancement are discussed. Elena Fedorchenko, Andrey Fedorchenko, Igor V. Kotenko |
ARES | 3 |
| 2018 | Image Clustering Method based on Particle Swarm OptimizationabstractTo implement efficient computer vision mechanisms, efficient image clustering methods are important.The paper elaborates a clustering method based on particle swarm optimization (PSO) which provides automatic establishment of clustering parameters.The developed PSO based clustering method was tested on 860 images for a car vision system and its results and contribution to the pattern recognition quality improvement were assessed in comparison with fuzzy C-means and k-means.The results do not differ significantly, but distinction in average time of work for these methods was noted.The PSO clustering method is faster than k-means and slower than fuzzy C-means.However, fuzzy C-means method does not guarantee correct results during the further analysis, so the PSO clustering method can be more efficient for implementation in computer vision systems. Igor V. Kotenko, Iuliia Kim, Anastasia Matveeva, Ilya I. Viksnin |
FedCSIS | 1 |
| 2018 | The Multi-Layer Graph Based Technique for Proactive Automatic Response Against Cyber AttacksabstractThe paper evolves an approach for proactive automatic cyber security incident response. The approach is based on usage of data from open sources, analytical modeling and a hierarchical integrated set of heterogeneous security metrics. The paper outlines the features of the analytical models that are crucial for countermeasure selection. It determines a set of security metrics for countermeasure selection. The algorithms that implement the suggested multi-layer countermeasure selection technique are specified. Introduction of the layers allows getting the result at any time with the maximum accuracy depending on the available data. The experiments that demonstrate the efficiency of the suggested technique are outlined. Elena Fedorchenko, Igor V. Kotenko |
PDP | 2 |
| 2018 | Parallelization of Security Event Correlation Based on Accounting of Event Type LinksabstractThe paper proposes a novel approach to parallel data processing for solving security event correlation problems based on Big Data technologies. Different security event correlation methods and problems, as well as big data technologies applicable for security monitoring are considered. The main attention is paid to the problems of identifying the links between security event types and assessing the dependence of the link strength on event distribution in time. Implementation of correlation problem solutions on the Spark platform is described, and the results of experimental assessment of security event correlation processes are given. Igor V. Kotenko, Andrey Fedorchenko, Igor Saenko 0001, Alexey Kushnerevich |
PDP | 1 |
| 2018 | Software Tool for Testing the Packet Analyzer of Network Attack Detection SystemsabstractThe paper is devoted to a model, technique and software tool for testing network attack detection systems (ADSs) from the point of view of the correct functioning of their internal packet analyzer. A client-server architecture of the software tool for generating the low-level network attacks is described. The paper outlines the experimental results of testing several ADSs by using the implemented software tool. The results of experiments, aimed at testing the ADSs on the ability to detect evasion and insertion attacks, are presented. We analyze the reaction of ADSs in response to various network packets subjected to various transformations at the levels both of IP and TCP protocols. Recommendations aimed at detecting and preventing such situations in computer networks are proposed. Alexander Branitskiy, Igor V. Kotenko |
SIN | 2 |
| 2018 | Implementation of Intelligent Agents for Network Traffic and Security Risk Analysis in Cyber-Physical SystemsabstractThe paper offers an approach for implementation of intelligent agents intended for network traffic and security risk analysis in cyber-physical systems. The agents are based on the algorithm of pseudo-gradient adaptive anomaly detection and fuzzy logical inference. The suggested algorithm operates in real time. The fuzzy logical inference is used for regulation of algorithm parameters. The variants of the implementation are proposed. The experimental assessment of the approach confirms its high speed and adequate accuracy for network traffic analysis. Igor V. Kotenko, Sergey Ageev, Igor Saenko 0001 |
SIN | 1 |
| 2018 | Hierarchical Fuzzy Situational Networks for Online Decision Support in Distributed Cyber-Physical SystemsabstractThe paper suggests a new approach to create online decision support systems (ODSSs) to control distributed cyber-physical systems (DCPSs). We consider ODSSs which are based on applying hierarchical fuzzy situational networks together with fuzzy mathematical programming and fuzzy logical inference. These methods allow one to make efficient decisions in the conditions of dynamically changing external factors. The conceptual principles to create ODSSs are provided. The generalized algorithm of ODSS' functioning is developed. As a case study we consider a multi-service communication network which is a communication basis of DCPSs and one of the most complicated subsystem operating with fuzzy data. The performed evaluation of the proposed approach demonstrates its significant gain in comparison with known statistical methods and methods based on the application of reference situations. Based on the results of the evaluation, the structure of intelligent agents' software implementing ODSS for DCPSs is developed. Igor V. Kotenko, Igor Saenko 0001, Sergey Ageev |
SoMeT | 1 |
| 2018 | Genetic Algorithms for Solving Problems of Access Control Design and Reconfiguration in Computer NetworksabstractTo create solutions for providing the required access control in computer networks it is not sufficient to have only tools and protocols in the network that are needed for it. It is necessary to create corresponding configuration, or scheme, of such tools, which will allow us to satisfy the existing security requirements. At the same time, the problems of creating an access control scheme, as a rule, are NP-complete and require heuristic models for their solving. In this article, we propose a unified approach to creation of control access schemes, based on usage of genetic algorithms. The approach is applied not only to original schemes configuration but to reconfiguration as well. Successful testing of the suggested approach on RBAC, VLAN, and VPN schemes allows us to suppose that it may be applied to other types of access control schemes as well. Experimental testing of suggested genetic algorithms, performed on a specially designed test bed, showed their sufficiently high efficiency. Igor Saenko 0001, Igor V. Kotenko |
ACM Trans. Internet Techn. | 2 |
| 2017 | CVSS-based Probabilistic Risk Assessment for Cyber Situational Awareness and Countermeasure SelectionabstractThe paper suggests several techniques for computer network risk assessment based on Common Vulnerability Scoring System (CVSS) and attack modeling. Techniques use a set of integrated security metrics and consider input data from security information and event management (SIEM) systems. Risk assessment techniques differ according to the used input data. They allow to get risk assessment considering requirements to the accuracy and efficiency. Input data includes network characteristics, attacks, attacker characteristics, security events and countermeasures. The tool that implements these techniques is presented. Experiments demonstrate operation of the techniques for different security situations. Elena Fedorchenko, Igor V. Kotenko |
PDP | 2 |
| 2017 | Parallel Processing of Big Heterogeneous Data for Security Monitoring of IoT NetworksabstractNetworks of the Internet of Things (IoT) nowadays find greater widespread in many domains. Particularities of creation of IoT make the problem of their security monitoring rather actual, it is caused by necessity of processing of big amounts of heterogeneous data in real time. The problem may be solved by means of implementation of the parallel system for security data processing within IoT on the fly basing on complex event processing (CEP) technology. The paper considers basic solutions for creating such a system. The proposed system is oriented for usage of software environment Hadoop and includes data collection, data storage, data normalization and analysis, and data visualization components. The paper discusses the issues of architecture of this system, its implementation and experimental estimation. The experiments showed that the proposed approach to creation of the system on the basis of CEP technology provides suitable scalability and is capable to meet the requirements of processing data on security events in real time in IoT. Igor Saenko 0001, Igor V. Kotenko, Alexey Kushnerevich |
PDP | 2 |
| 2016 | Application of Hybrid Neural Networks for Monitoring and Forecasting Computer Networks States
Igor Saenko 0001, Fadey Skorik, Igor V. Kotenko |
ISNN | 3 |
| 2016 | Application of a Technique for Secure Embedded Device Design Based on Combining Security Components for Creation of a Perimeter Protection SystemabstractFrom information security point of view embedded devices are the elements of complex systems operating in a potentially hostile environment. Therefore development of embedded devices is a complex task that often requires expert solutions. The complexity of the task of developing secure embedded devices is caused by various types of threats and attacks that may affect the device, as well as that in practice security of embedded devices is usually considered at the final stage of the development process in the form of adding additional security features. The paper proposes a design technique and its application that will facilitate development of secure and energy-efficient embedded devices. The technique organizes the search for the best combinations of security components on the basis of solving an optimization problem. The efficiency of the proposed technique is demonstrated by development of a room perimeter protection system. Vasily Desnitsky, Andrey Chechulin, Igor V. Kotenko, Dmitry Levshun, Maxim Kolomeets |
PDP | 3 |
| 2016 | Dynamical Calculation of Security Metrics for Countermeasure Selection in Computer NetworksabstractThe paper considers the issue of countermeasures selection for ongoing computer network attacks. The suggested technique is based on the countermeasure model that was defined on the base of the open standards, the family of interrelated security metrics and the security analysis technique based on attack graphs and service dependencies. The technique was implemented in a security assessment and countermeasure selection system. This technique was validated on case studies. It is applicable for security information and event management systems. Igor V. Kotenko, Elena Fedorchenko |
PDP | 1 |
| 2015 | Countermeasure Selection Based on the Attack and Service Dependency Graphs for Security Incident Management
Elena Fedorchenko, Igor V. Kotenko |
CRiSIS | 2 |
| 2015 | Design of Integrated Vulnerabilities Database for Computer Networks Security AnalysisabstractIntegration of existing open vulnerabilities databases allows to increase the probability of detection of vulnerable software and hardware that are used in computer networks and improve the quality of security analysis. The paper is dedicated to investigation of open vulnerabilities databases and of process of their integration for further application in the security analysis system. The object of investigation is the process of integration of vulnerabilities databases. The main distinct of the designed integrated vulnerabilities database is its orientation to operative receiving of results of appropriate vulnerabilities search. The model of the process of the vulnerabilities database generation and the structure of the integrated vulnerabilities database are suggested. The description of the designed prototype and the results of its testing are outlined. Andrey Fedorchenko, Igor V. Kotenko, Andrey Chechulin |
PDP | 2 |
| 2015 | Countermeasure Selection in SIEM Systems Based on the Integrated Complex of Security MetricsabstractThe paper considers a technique for countermeasure selection in security information and event management (SIEM) systems. The developed technique is based on the suggested complex of security metrics. For the countermeasure selection the set of security metrics is extended with an additional level needed for security decision support. This level is based on the countermeasure effectiveness metrics. Key features of the suggested technique are application of the attack and service dependencies graphs, the introduced model of the countermeasure and the suggested metrics of the countermeasure effectiveness, cost and collateral damage. Other important feature of the technique is providing the solution on the countermeasure implementation in any time on the base of the current security state and security events. Igor V. Kotenko, Elena Fedorchenko |
PDP | 1 |
| 2014 | Visualization of Security Metrics for Cyber Situation AwarenessabstractOne of the important direction of research in situational awareness is implementation of visual analytics techniques which can be efficiently applied when working with big security data in critical operational domains. The paper considers a visual analytics technique for displaying a set of security metrics used to assess overall network security status and evaluate the efficiency of protection mechanisms. The technique can assist in solving such security tasks which are important for security information and event management (SIEM) systems. The approach suggested is suitable for displaying security metrics of large networks and support historical analysis of the data. To demonstrate and evaluate the usefulness of the proposed technique we implemented a use case corresponding to the Olympic Games scenario. Igor V. Kotenko, Evgenia Novikova |
ARES | 1 |
| 2014 | Security Metrics Based on Attack Graphs for the Olympic Games ScenarioabstractAnalysis of security risks and calculation of security metrics is an important task for Security Information and Events Management (SIEM) systems. It allows recognizing the current security situation and necessary countermeasures. The paper considers technique for calculation of security metrics on the base of attack graphs and service dependencies. The technique uses several assessment aspects or levels (topological, attack graph level, attacker level, events level and system level) and allows customization according to different parameters of SIEM system operation. We discuss also the application of this technique for the "Olympic Games" case study. Igor V. Kotenko, Elena Fedorchenko, Andrey Chechulin |
PDP | 1 |
| 2014 | Creation of a Fuzzy Knowledge Base for Adaptive Security SystemsabstractTo design next generation adaptive security systems the powerful intelligent components should be developed. The paper describes the fuzzy knowledge base specifying relationships between threats and protection mechanisms by Mathworks MATLAB Fuzzy Logic Toolbox. The goal is to increase the effectiveness of the system reactions by minimization of neural network weights. We demonstrate a technique for creation of a fuzzy knowledge base to improve the system protection via rules monitoring and correction. Philipp G. Nesteruk, Lesya Nesteruk, Igor V. Kotenko |
PDP | 3 |
| 2013 | The Ontology of Metrics for Security Evaluation and Decision Support in SIEM SystemsabstractAnalysis of computer network security is a serious challenge. Many security metrics has been proposed for this purpose, but their effective use for rapid and reliable security evaluation and generation of countermeasures in SIEM systems remains an important problem. The use of ontologies for security information representation in SIEM systems contributes largely to the success of this task. However, most of works on ontological security data representation does not take into account the ontologies of security metrics. This paper proposes a new approach on using security metrics which is based on their ontological representation and serves for comprehensive security evaluation and subsequent countermeasure generation. The novelty of the proposed approach is that ontology of security metrics is viewed as a core component of a countermeasure decision support system. The proposed solutions are tested on a specific example. Igor V. Kotenko, Olga Polubelova, Igor Saenko 0001, Elena Fedorchenko |
ARES | 1 |
| 2013 | Experiments With Simulation Of Botnets And Defense Agent TeamsabstractBotnets allow malefactors manage millions of infected computers simultaneously and provide large-scale successful attacks. The paper suggests an approach for multi-agent simulation of botnets and botnet protection mechanisms. The main contribution of the paper is an improved simulation environment for agent based simulation of botnets and experimentation with this environment for analysis of different botnets and protection mechanisms. Experiments demonstrate the capabilities of the simulation environment for investigating various stages of the botnet lifecycle and the efficiency of different protection mechanisms. Igor V. Kotenko |
ECMS | 1 |
| 2013 | Simulation of Protection Mechanisms Based on "Nervous Network System" against Infrastructure AttacksabstractThe paper is devoted to the analysis of the network protection mechanism "nervous network system" based on the bio-inspired metaphor. Packet-level simulation is proposed in order to investigate the "nervous network system" protection mechanism. We describe the architecture of the protection system based on the given mechanism, its operation algorithms and present results of the experiments. Using obtained results the efficiency of the protection mechanism "nervous network system" against infrastructure attacks is analyzed. Igor V. Kotenko, Andrey Shorov, Evgenia Novikova |
PDP | 1 |
| 2013 | Analytical Visualization Techniques for Security Information and Event ManagementabstractThe paper proposes the architecture of the visualization component for the Security Information and Event Management (SIEM) system. The SIEM systems help to comprehend large amounts of the security data. Visualization is the essential part of the SIEM systems. The suggested architecture of the visualization component allows incorporating different visualization technologies and extending easily the application functionality. To illustrate the approach, we developed the prototype of the SIEM visualization component. The paper demonstrates the graphical user interface of the attack modeling component. To increase the efficiency of the visualization techniques we applied principles of the human information perception and interaction issues when designing graphical components. Evgenia Novikova, Igor V. Kotenko |
PDP | 2 |
| 2012 | A Methodology for the Analysis and Modeling of Security Threats and Attacks for Systems of Embedded ComponentsabstractThe development of systems based on embedded components is a challenging task because of their distributed, reactive and real-time nature. From a security point of view, embedded devices are basically systems owned by a certain entity, used frequently as part of systems owned by other entities and operated in a potentially hostile environment. The development of security-enhanced systems of embedded components is a difficult task due to different types of threats that may affect such systems, and because the security in systems of embedded devices is currently added as an additional feature when the development is advanced, or avoided as a superfluous characteristic. We present in this paper a methodology for the analysis and modeling of threats and attacks for systems of embedded components. The Intruder Model allows us to describe possible actions a potential intruder can accomplish, depending on his/her capabilities, resources, etc. Using this information, we can define a Threat Model that will specify the threats and attacks that affect different security properties in specific domains. José Fran. Ruiz, Rajesh Harjani, Antonio Maña, Vasily Desnitsky, Igor V. Kotenko, Andrey Chechulin |
PDP | 5 |
| 2012 | Design and Performance Evaluation of Improved Genetic Algorithm for Role Mining ProblemabstractRole Mining Problem (RMP) is an important issue in RBAC design and development. Genetic algorithm (GA) can be an effective method for solving RMP, but known usual GAs used for RMP have low performance at high dimensions. The paper proposes an improved GA for solving RMP. This algorithm is based on implementing some changes applied to the usual GAs. The main upgrades are the representation of algorithm chromosomes as strings of variable lengths with complex gene structures, the modernization of crossover operation, and the local optimization of chromosome structures after crossover execution on the basis of proposed rules. The performance evaluation results show that improved GA has better performance then usual GA. Moreover, the improved GA has a larger performance gain, when the required access control scheme is characterized by greater role severity. Igor Saenko 0001, Igor V. Kotenko |
PDP | 2 |
| 2012 | Attack Modelling and Security Evaluation for Security Information and Event Management
Igor V. Kotenko, Andrey Chechulin, Evgenia Novikova |
SECRYPT | 1 |
| 2012 | Data Repository for Security Information and Event Management in Service Infrastructures
Igor V. Kotenko, Olga Polubelova, Igor Saenko 0001 |
SECRYPT | 1 |
| 2012 | Simulation of Protection Mechanisms against Botnets on the Basis of "Nervous Network" Framework
Igor V. Kotenko, Andrey Shorov |
SIMULTECH | 1 |
| 2012 | Agent-based simulation of cooperative defence against botnetsabstractSUMMARY The paper outlines a framework and software tool intended for simulation of cooperative defence mechanisms against botnets. These framework and software tool are based on agent‐oriented approach and packet‐level network simulation. They are intended to evaluate and compare different cooperative distributed attacks and defence mechanisms. Botnet and defence components are represented in the paper as a set of collaborating and counteracting agent teams. Agents are supposed to collect information from various network sources, operate different situational knowledge, and react to actions of other agents. The paper describes the results of experiments aimed to investigate botnets and distributed denial of service defence mechanisms. We explore various botnet attacks and counteraction against them on the example of defence against distributed denial of service attacks. Copyright © 2011 John Wiley & Sons, Ltd. Igor V. Kotenko, Alexey Konovalov, Andrey Shorov |
Concurr. Comput. Pract. Exp. | 1 |
| 2011 | Security Analysis of Information Systems Taking into Account Social Engineering AttacksabstractThe paper suggests an attack trees based approach to security analysis of information systems. The approach considers both software-technical and social engineering attacks. It extends the approach to network security analysis based on software-technical attacks which was suggested earlier by the authors of this paper. The main difference is in generalizing the suggested approach for information systems and in use of different conceptions, models and frameworks related to social-engineering attacks. In particular, we define conceptions of legitimate users and control areas. Besides, social-engineering attacks and attacks that require physical access to control areas are included to the attack trees used for security analysis. The paper also describes a security analysis toolkit based on the approach suggested and experiments with it to define the security level of information system. Igor V. Kotenko, Mikhail Stepashkin, Elena Fedorchenko |
PDP | 1 |
| 2011 | Genetic Algorithms for Role Mining ProblemabstractThe paper proposes a new approach to solve role mining problem in role-based access control systems. This approach is founded on applying genetic algorithms as heuristic optimization methods that are effectively used when the search space is too huge to be fully explored. To realize genetic algorithms, we propose some important novelties: having many chromosomes by individuals, presentation of genes as complex objects, dividing selection and mutation into several phases, accounting data confidentiality and availability in fitness functions and other. Proposed genetic algorithms were tested on randomly generated data sets for "basic" and "edge" role mining problems. The test results allow to assert that genetic algorithms may be successfully applied to efficiently solve main kinds of role mining problems. Igor Saenko 0001, Igor V. Kotenko |
PDP | 2 |
| 2010 | Malware Detection by Data Mining Techniques Based on Positionally Dependent FeaturesabstractThe challenges being thrown to modern world by the need to counteract against malicious software (malware) are going on to increase own importance. This fact stays actual, in spite of obvious great results in improving the efficacy of procedures of malware propagation detection, analysis and updating the bases of signatures and detection rules. The important aspect of this problem is looking for more reliable heuristic detection methods. These methods focus on recognition of new (unknown before) malicious programs which can not be detected by using traditional signature- and rule-based detection techniques, oriented on search for concrete malware samples and families. Virtually, just these heuristic methods provide counteraction against targeted and zero-day attacks, since the rate of detecting such relatively new types of threats by traditional techniques is not enough. The presented paper is devoted to using Data Mining methods for constructing heuristic malware detectors. The approach described below differs from others by focusing on processing static positionally dependent features which consider the specificities of object's file format of potential malware containers. The paper describes the realization and investigation of the common methodology for design of Data Mining-based malware detectors' using positionally dependent static information. Dmitriy Komashinskiy, Igor V. Kotenko |
PDP | 2 |
| 2009 | Simulation Of Agent Teams: Application Of A Domain-Independent Framework To Computer Network SecurityabstractThe paper proposes an approach for multi-agent simulation of intelligent agent teams’ collaboration and competition. This approach is for representing the complex processes ongoing in different subject domains by using various types of agent teams and their interactions. Teams can be in relations of indifference, antagonistic and non-antagonistic competing or (and) various kinds of cooperation, and may adapt to the actions of opponents or collaborators. The domainindependent multi-agent framework and common simulation environment are proposed. The suggested approach differs from other related approaches by attempting to formalize main components needed for agent teamwork and team collaboration and competition. The approach is applicable for the tasks of competitive activity in commerce, counteraction in the Internet, simulation of rescue operations, coalition actions, military conflicts, etc. We consider the theoretical models, implementation and investigations of the proposed approach on an example of simulation of distributed Internet attacks and defense. Igor V. Kotenko |
ECMS | 1 |
| 2009 | Framework for Integrated Proactive Network Worm Detection and ResponseabstractThe paper considers an integrated proactive framework for defense against spreading network worms in the Internet. The framework is intended for network worm detection (by recognizing the actions on scanning of network hosts) and containment of worm spreading (by limiting and blocking the packets transmitted by infected hosts). The framework is based on application of different heuristic detection and response mechanisms, their combination and automatic dynamic adaptation according to current network conditions. The paper describes the software system for simulation and evaluation of defense mechanisms investigated against spreading network worms and the results of experiments on detection and containment of network worms. Igor V. Kotenko |
PDP | 1 |
| 2008 | Packet Level Simulation of Cooperative Distributed Defense against Internet AttacksabstractNowadays we see an increasing number of global network attacks. These attacks are realized due to joint efforts of many distributed malicious software components (bots). It is very hard to investigate the effectiveness and efficiency of defense mechanisms against such attacks in practice. However these mechanisms might be simulated with the necessary fidelity. The paper outlines a framework and software tool intended for simulation of the Internet attacks and defense mechanisms against them. They are based on packet-level simulation and agent-oriented approach and intended to evaluate and compare different cooperative distributed defense mechanisms. The paper describes the simulation framework and software tool developed and their usage to analyze cooperative defense mechanisms against DDoS (Distributed Denial of Service) attacks. We investigate as mechanisms based on partial cooperation of distributed defense components, including DefCOM (Defensive Cooperative Overlay Mesh) and COSSACK (coordinated suppression of simultaneous attacks) as well as the approach based on full cooperation. Igor V. Kotenko, Alexander Ulanov |
PDP | 1 |
| 2007 | Investigation of Cooperative Defense against DDoS
Igor V. Kotenko, Alexander Ulanov |
SECRYPT | 1 |
| 2006 | Agent Teams in Cyberspace: Security Guards in the Global InternetabstractThe paper presents an approach to design a cyberworld intended for the research of security systems functioning in the Internet. These systems are represented as the complex of various interacting teams of intelligent agents. The agents can be in the state of antagonistic counteraction or cooperation. The general conceptual model of agent teams' antagonistic counteraction and cooperation is suggested. The task of developing the agent cyberworld, where agents realize the distributed attacks and defense, is investigated on the example of "distributed denial of service" attack subject domain. The architecture and implementation of research environment for agent-oriented simulation is presented. The environment is implemented on the basis of discrete-event simulation system that allowed to combine the agent-oriented and network protocol based simulation Igor V. Kotenko, Alexander Ulanov |
CW | 1 |
| 2006 | Antagonistic Agents in the Internet: Computer Network Warfare SimulationabstractIn the paper the approach for the simulation of counteraction between malefactors and defense systems in the Internet is considered. We try to model these antagonistic actors as software agents' teams. To simulate the teams' warfare it is proposed to use various computational models (from analytical and packet-based to virtual and testbeds). The main attention is drawn to the application of agent-oriented simulation based on the packet-based imitation of network security processes. Such approach provides acceptable fidelity and scalability in representing the attack and defense mechanisms. The approach is examined on an example of "distributed denial of service" attacks and defense simulation. We consider different phases of antagonistic teams' operations-learning, decision making and counteracting, including the adaptation of one team to the actions of opposite team Igor V. Kotenko, Alexander Ulanov |
FUSION | 1 |
| 2006 | Simulation of Internet DDoS Attacks and Defense
Igor V. Kotenko, Alexander Ulanov |
ISC | 1 |
| 2006 | Network Security Evaluation Based on Simulation of Malfactor's Behavior
Igor V. Kotenko, Mikhail Stepashkin |
SECRYPT | 1 |
| 2002 | Attacks Against Computer Network: Formal Grammar-Based Framework and Simulation Tool
Vladimir I. Gorodetski, Igor V. Kotenko |
RAID | 2 |
| 2000 | Integrated Multi-Agent Approach to Network Security Assurance: Models of Agents' Community
Vladimir I. Gorodetski, Igor V. Kotenko, Victor A. Skormin |
SEC | 2 |