Model of functional resilience reserve of an information system in the conditions of zero-day incidents
Abstract
The work is devoted to the creation of a model of the functional stability reserve of an information system in the conditions of zero-day incidents. The relevance of the research is determined by the increase in the number of functional stability incidents of information systems, in particular the increase in zero-day incidents. The purpose of the work is to develop a model of the functional stability reserve in the conditions of zero-day incidents. The work proposes a model of a system for ensuring the functional stability of an information system based on a hybrid additive-minimizing convolution with a parameter controlling the level of inter changeability of subsystems from full interchangeability to full non-interchangeability. The indicators of func tional stability, functional stability reserve, useful effect and system efficiency are used as quality criteria. Detection of zero-day incidents is performed by identifying anomalies in the system behavior using a set of clustering methods. For clustering the system states, a set of agglomerative clustering methods in weighted and unweighted forms (nearest neighbor, farthest neighbor, pairwise average, centroid, Ward's method and its modifications) were used, as well as various distance metrics (Chebyshev, Hamming, Euclidean and square of the Euclidean metric). All methods and metrics are used to perform the same task many times in different ways. If at least one check reveals a cluster that would be determined as anomalous, then such a cluster would necessarily be investigated additionally and in more detail. The approach was tested on model, real training and control data. To determine the level of cluster danger, an estimate of the functional stability reserve was used based on the distances of the current cluster to previously identified clusters. An algorithm for determin ing the functional stability reserve of an information system is proposed.
Problems in programming 2026; 3: 45-52
Keywords
Full Text:
PDF (Українська)References
2026 Data Breach Investigation Report. Public Sector snapshot. Verizon business.
2026 Data Breach Investigations Report.
Chandola V., Banerjee A., Kumar V. Anomaly Detection: A Survey // ACM Computing Surveys. – 2009. – Vol. 41, No. 3. – Article 15. P. 1-58.
Pang G., Shen C., Cao L., van den Hengel A. Deep Learning for Anomaly Detection: A Review // ACM Computing Surveys. 2021/2022. – Vol. 54, No. 2. – Article 38. – P. 1–38.
Liu F.T., Ting K.M., Zhou Z.-H. Isolation Forest // Proceedings of the 2008 Eighth IEEE International Conference on Data Mining (ICDM 2008). – Pisa, Italy, 15–19 December 2008. P. 413–422.
Liu F.T., Ting K.M., Zhou Z.-H. Isolation Based Anomaly Detection // ACM Transactions on Knowledge Discovery from Data.– 2012. Vol. 6, No. 1. – Article 3. – P. 1–39.
Burbeck K., Nadjm-Tehrani S. Adaptive Real Time Anomaly Detection with Incremental Clustering // Information Security Technical Report. –2007. – Vol. 12, No. 1. – P. 56–67.
Song J., Takakura H., Okabe Y., Kwon Y. Unsupervised Anomaly Detection Based on Clustering and Multiple One-Class SVM // IEICE Transactions on Communications. 2009. – Vol. E92-B, No. 6. – P. 1981-1990.
Tang C., Xiang Y., Wang Y., Qian J., Qiang B. Detection and Classification of Anomaly Intrusion Using Hierarchy Clustering and SVM // Security and Communication Networks. 2016. – Vol. 9. – P. 3401-3411.
Shin G., Kim D., Kim S., Han M. Unknown Attack Detection: Combining Relabeling and Hybrid Intrusion Detection // Computers, Materials & Continua. – 2021. – Vol. 68, No. 3. P. 3289–3303.
Nguyen T.-L., Kao H., Nguyen T.-T., Horng M.-F., Shieh C.-S. Unknown DDoS Attack Detection with Fuzzy C-Means Clustering and Spatial Location Constraint Prototype Loss // Computers, Materials & Continua. – 2024. Vol. 78, No. 2. – P. 2181–2205.
Cevallos M. J.F., Rizzardi A., Sicari S., Coen Porisini A. HERO: From High-Dimensional Network Traffic to zERO-Day Attack Detection // Computer Networks. – 2025. Vol. 265. Article 111264.
Refbacks
- There are currently no refbacks.








