<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">tuzsut</journal-id><journal-title-group><journal-title xml:lang="ru">Труды учебных заведений связи</journal-title><trans-title-group xml:lang="en"><trans-title>Proceedings of Telecommunication Universities</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">1813-324X</issn><issn pub-type="epub">2712-8830</issn><publisher><publisher-name>СПбГУТ</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.31854/1813-324X-2025-11-1-99-112</article-id><article-id custom-type="edn" pub-id-type="custom">OOPJJR</article-id><article-id custom-type="elpub" pub-id-type="custom">tuzsut-657</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>ИНФОРМАЦИОННЫЕ ТЕХНОЛОГИИ И ТЕЛЕКОММУНИКАЦИИ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>INFORMATION TECHNOLOGIES AND TELECOMMUNICATION</subject></subj-group></article-categories><title-group><article-title>Анализ и прогнозирование временных рядов кибератак на информационную систему ведомственного вуза: возможности и ограничения методов</article-title><trans-title-group xml:lang="en"><trans-title>Analyzing and Predicting the Time Series of Cyberattacks on Higher Education Departmental Institution Information System: Methods Opportunities and Limitations</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-0385-3530</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Наумов</surname><given-names>В. Н.</given-names></name><name name-style="western" xml:lang="en"><surname>Naumov</surname><given-names>V. N.</given-names></name></name-alternatives><bio xml:lang="ru"><p>доктор военных наук, профессор, заведующий кафедрой бизнес-информатики Северо-Западного института управления ‒ филиала РАНХиГС</p></bio><email xlink:type="simple">naumov122@list.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0001-8146-0022</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Буйневич</surname><given-names>М. В.</given-names></name><name name-style="western" xml:lang="en"><surname>Buinevich</surname><given-names>M. V.</given-names></name></name-alternatives><bio xml:lang="ru"><p>доктор технических наук, профессор, профессор кафедры прикладной математики и безопасности информационных технологий Санкт-Петербургского университета ГПС МЧС России</p></bio><email xlink:type="simple">bmv1958@yandex.ru</email><xref ref-type="aff" rid="aff-2"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0005-8108-3198</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Синещук</surname><given-names>М. Ю.</given-names></name><name name-style="western" xml:lang="en"><surname>Sineshchuk</surname><given-names>M. Y.</given-names></name></name-alternatives><bio xml:lang="ru"><p>заместитель начальника центра информационных и коммуникационных технологий Санкт-Петербургского университета ГПС МЧС России</p></bio><email xlink:type="simple">smaxim@igps.ru</email><xref ref-type="aff" rid="aff-2"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0004-2496-7117</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Тукмачева</surname><given-names>М. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Tukmacheva</surname><given-names>M. A.</given-names></name></name-alternatives><bio xml:lang="ru"><p>адъюнкт факультета подготовки кадров высшей квалификации Санкт-Петербургского университета ГПС МЧС России</p></bio><email xlink:type="simple">mtukmacheva@mail.ru</email><xref ref-type="aff" rid="aff-2"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru">Северо-Западный институт управления ‒ филиал РАНХиГС<country>Россия</country></aff><aff xml:lang="en">North-West Institute of Management of the Russian Presidential Academy of National Economy and Public Administration<country>Russian Federation</country></aff></aff-alternatives><aff-alternatives id="aff-2"><aff xml:lang="ru">Санкт-Петербургский университет ГПС МЧС России<country>Россия</country></aff><aff xml:lang="en">Saint Petersburg University of State Fire Service of Emercom of Russia<country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2025</year></pub-date><pub-date pub-type="epub"><day>03</day><month>03</month><year>2025</year></pub-date><volume>11</volume><issue>1</issue><fpage>99</fpage><lpage>112</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Наумов В.Н., Буйневич М.В., Синещук М.Ю., Тукмачева М.А., 2025</copyright-statement><copyright-year>2025</copyright-year><copyright-holder xml:lang="ru">Наумов В.Н., Буйневич М.В., Синещук М.Ю., Тукмачева М.А.</copyright-holder><copyright-holder xml:lang="en">Naumov V.N., Buinevich M.V., Sineshchuk M.Y., Tukmacheva M.A.</copyright-holder><license license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://tuzs.sut.ru/jour/article/view/657">https://tuzs.sut.ru/jour/article/view/657</self-uri><abstract><p>Актуальность статьи обусловлена ростом угроз компьютерной безопасности критических информационных ресурсов, в том числе в системе образования, разнообразием видов и направлений кибератак, требующих дифференциации известных методов анализа и прогнозирования, в том числе на основе использования теории временных рядов. Целью статьи является исследование возможностей и ограничений использования методов теории временных рядов для анализа и прогнозирования динамики кибератак на примере ведомственного вуза, готовящего специалистов многим видам безопасности: техносферной, пожарной, информационной и проч. Высказана и проверена гипотеза о влиянии характера исходных данных на выбор методов анализа и прогнозирования временных рядов числа кибератак, о первичности исходных данных на результативность решения указанных задач. Выполнен анализ логов мониторинга межсетевого экрана корпоративной информационной системы; на их основе построены временные ряды числа различных видов атак и решены задачи текущего прогнозирования. Новизна полученных результатов обусловлена применением известных методов теории прогнозирования временных рядов к задаче исследования динамики кибератак на корпоративную информационную систему ведомственного вуза. Теоретическая значимость состоит в установлении границ возможности их применения в силу вариативности исследуемых временных рядов, а также в подтверждении первичности качества исходных данных над существующими методами и моделями. Практическая ценность определяется построением моделей временных рядов, позволяющих решать задачи текущего прогнозирования числа кибератак.</p></abstract><trans-abstract xml:lang="en"><p>The article relevance is due to the growing threats to computer security of critical information resources, including in the education system, cyberattacks types and trends diversity, requiring known analysis and forecasting methods differentiation, including those based on the use of time series theory. The article aim is to study the possibilities and limitations of using time series theory methods to analyses and predict the cyber attacks dynamics on the departmental university example that trains specialists in many security types: technosphere, fire, information and other. Hypothesis about the influence of the initial data nature on the methods for cyberattacks number time series analyzing and forecasting choice, and primacy of initial data on the solving these tasks effectiveness was stated and tested. Analyses of the corporate information system firewall monitoring logs are performed. On their basis, time series number of different types of attacks are constructed. The tasks of building mathematical models and current forecasting have been solved. An integrated approach to their solution based on preliminary processing, testing of statistical hypotheses about DS- and TS-stationarity and use of different forecasting methods was applied. The obtained results novelty is due to known methods of time series forecasting theory application to studying the dynamics of cyberattacks on the departmental university corporate information system. Theoretical significance consists in establishing the limits of their application possibility due to the studied time series variability, as well as in confirming the initial data primary quality over the existing methods and models. The practical value is determined by the time series models construction that allow solving tasks of cyberattacks number current forecasting.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>кибератаки</kwd><kwd>ведомственная информационная система</kwd><kwd>логи программно-аппаратного межсетевого экрана</kwd><kwd>временные ряды</kwd><kwd>анализ и прогнозирование</kwd><kwd>стационарность временных рядов</kwd><kwd>фильтры экспоненциального сглаживания</kwd><kwd>модели авторегрессии проинтегрированного скользящего среднего</kwd><kwd>метод Prophet</kwd></kwd-group><kwd-group xml:lang="en"><kwd>cyberattacks</kwd><kwd>departmental information system</kwd><kwd>firewall logs</kwd><kwd>time series</kwd><kwd>analysis and forecasting</kwd><kwd>stationarity of time series</kwd><kwd>exponential smoothing filters</kwd><kwd>auto-regression models of the pro-integrated moving average</kwd><kwd>Prophet method</kwd></kwd-group><funding-group xml:lang="ru"><funding-statement>Работа выполнена в рамках НИР «Кибермониторинг» рег. № НИОКТР 1024040800041-6-2.2.66</funding-statement></funding-group><funding-group xml:lang="en"><funding-statement>The work was carried out under the R&amp;D "Cybermonitoring" Reg. No. NIOCTR 1024040800041-6-2.2.66</funding-statement></funding-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Глазьев С.Ю. Теория долгосрочного технико-экономического развития. М.: ВлаДар, 1993. EDN:YSXIUV</mixed-citation><mixed-citation xml:lang="en">Glazyev S.Yu. Theory of Long-Term Technical and Economic Development. Moscow: VlaDar Publ.; 1993. (in Russ.) EDN:YSXIUV</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Нильсен Э. Практический анализ временных рядов. Прогнозирование со статистикой и машинное обучение. СПб.: Диалектика, 2021. 544 с.</mixed-citation><mixed-citation xml:lang="en">Nielsen E. Practical Time Series Analysis. Forecasting with Statistics and Machine Learning. St. Petersburg: Dialektika Publ.; 2021. 544 p. (in Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Хайндман Р., Атанасопулос Дж. Прогнозирование: принципы и практика. Пер. с англ. М.: ДМК Пресс, 2023. 458 с.</mixed-citation><mixed-citation xml:lang="en">Hyndman R.J., Athanasopoulos G. Forecasting: principles and practice. OTexts; 2017. 292 p.</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Исаев С.В., Кононов Д.Д. Исследование динамики и классификация атак на веб-сервисы корпоративной сети // Сибирский аэрокосмический журнал. 2022. Т. 23. № 4. С. 593–601. DOI:10.31772/2712-8970-2022-23-4-593-601. EDN:RUSJWB</mixed-citation><mixed-citation xml:lang="en">Isaev S.V., Kononov D.D. A Study of Dynamics and Classification of Attacks on Corporate Network Web Services. The Siberian Aerospace Journal. 2022;23(4):593–601. (in Russ.) DOI:10.31772/2712-8970-2022-23-4-593-601. EDN:RUSJWB</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Zuzčák M., Bujok P. Using honeynet data and a time series to predict the number of cyber attacks // Computer Science and Information Systems. 2021. Vol. 18. Iss. 4. PP. 1197–1217. DOI:10.2298/CSIS200715040Z</mixed-citation><mixed-citation xml:lang="en">Zuzčák M., Bujok P. Using honeynet data and a time series to predict the number of cyber attacks. Computer Science and Information Systems. 2021;18(4):1197–1217. DOI:10.2298/CSIS200715040Z</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Ларионов К.О. Прогнозирование статистических данных атак на прикладное программное обеспечение // Проблемы современной науки и образования. 2021. № 6(163). С. 57‒63. DOI:10.24411/2304-2338-2021-10606. EDN:PGVALC</mixed-citation><mixed-citation xml:lang="en">Larionov K.O. Forecasting Attack Statistics on Applied Software. Problemy sovremennoi nauki i obrazovaniia. 2021;6(163):57‒63. (in Russ.) DOI:10.24411/2304-2338-2021-10606. EDN:PGVALC</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Hobijn B., Franses P.H., Ooms M. Generalization of the KPSS-test for stationarity // Statistica Neerlandica. 2004. Vol. 58. Iss. 4. PP. 482‒502. DOI:10.1111/j.1467-9574.2004.00272.x</mixed-citation><mixed-citation xml:lang="en">Hobijn B., Franses P.H., Ooms M. Generalization of the KPSS-test for stationarity. Statistica Neerlandica. 2004;58(4): 482‒502. DOI:10.1111/j.1467-9574.2004.00272.x</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Phillips P.C.B., Perron P. Testing for a Unit Root in Time Series Regression // Biometrika. 1988. Vol. 75. Iss. 2. PP. 335‒346. DOI:10.1093/biomet/75.2.335. EDN:ILNEET</mixed-citation><mixed-citation xml:lang="en">Phillips P.C.B., Perron P. Testing for a Unit Root in Time Series Regression. Biometrika. 1988;75(2):335‒346. DOI:10.1093/biomet/75.2.335. EDN:ILNEET</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Hersbach H. Decomposition of the Continuous Ranked Probability Score for Ensemble Prediction Systems // Weather and Forecast. 2000. Vol. 15. Iss. 5. PP. 559–570. DOI:10.1175/1520-0434(2000)015&lt;0559:DOTCRP&gt;2.0.CO;2</mixed-citation><mixed-citation xml:lang="en">Hersbach H. Decomposition of the Continuous Ranked Probability Score for Ensemble Prediction Systems. Weather and Forecast. 2000;15(5):559–570. DOI:10.1175/1520-0434(2000)015&lt;0559:DOTCRP&gt;2.0.CO;2</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Dawid A.P., Sebastiani P. Coherent Dispersion Criteria for Optimal Experimental Design // Annals of Statistics. 1999. Vol. 27. Iss. 1. PP. 65‒81.</mixed-citation><mixed-citation xml:lang="en">Dawid A.P., Sebastiani P. Coherent Dispersion Criteria for Optimal Experimental Design. Annals of Statistics. 1999; 27(1):65‒81.</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Bickel P.J., Doksum K.A. An Analysis of Transformations // Journal of the American Statistical Association. 1981. Vol. 76. Iss. 374. PP. 296‒311. DOI:10.2307/2287831</mixed-citation><mixed-citation xml:lang="en">Bickel P.J., Doksum K.A. An Analysis of Transformations. Journal of the American Statistical Association. 1981;76(374): 296‒311. DOI:10.2307/2287831</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Hyndman R.J., Koehler A.B., Snyder R.D., Grose S. A state space framework for automatic forecasting using exponential smoothing methods // International Journal Forecasting. 2002. Vol. 18. Iss. 3. PP. 439–454.</mixed-citation><mixed-citation xml:lang="en">Hyndman R.J., Koehler A.B., Snyder R.D., Grose S. A state space framework for automatic forecasting using exponential smoothing methods. International Journal Forecasting. 2002;18(3):439–454.</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">Cleveland R.B., Cleveland W.S., McRae J.E., Terpenning I.J. STL: A Seasonal-Trend Decomposition Procedure Based on Loess // Journal of Official Statistics. 1990. Vol. 6. Iss. 1. PP. 3–33.</mixed-citation><mixed-citation xml:lang="en">Cleveland R.B., Cleveland W.S., McRae J.E., Terpenning I.J. STL: A Seasonal-Trend Decomposition Procedure Based on Loess. Journal of Official Statistics. 1990;6(1):3–33.</mixed-citation></citation-alternatives></ref><ref id="cit14"><label>14</label><citation-alternatives><mixed-citation xml:lang="ru">Scott S., Varian H.R. Predicting the Present with Bayesian Structural Time Series // SSRN Electronic Journal. 2014. Vol. 5. Iss. 1/2. PP. 4–23. DOI:10.1504/IJMMNO.2014.059942</mixed-citation><mixed-citation xml:lang="en">Scott S., Varian H.R. Predicting the Present with Bayesian Structural Time Series. SSRN Electronic Journal. 2014;5(1/2):4–23. DOI:10.1504/IJMMNO.2014.059942</mixed-citation></citation-alternatives></ref><ref id="cit15"><label>15</label><citation-alternatives><mixed-citation xml:lang="ru">Мастицкий С.Э. Анализ временных рядов с помощью R. 2020. URL: https://ranalytics.github.io/tsa-with-r (дата обращения 19.12.2024)</mixed-citation><mixed-citation xml:lang="en">Mastitsky S.E. Time series analysis using R. 2020. URL: https://ranalytics.github.io/tsa-with-r [Accessed 19.12.2024]</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
