ДВОШАРОВА МОДЕЛЬ ЗАХИСТУ ВЕБЗАСТОСУНКІВ НА ОСНОВІ OWASP TOP 10:2025 ТА МЕТОДІВ ШТУЧНОГО ІНТЕЛЕКТУ

Автор(и)

DOI:

https://doi.org/10.28925/2663-4023.2026.34.1230

Ключові слова:

безпека вебзастосунків, OWASP Top 10, штучний інтелект, виявлення аномалій, графові нейронні мережі, виявлення вторгнень, двошарова модель безпеки, захист від кіберзагроз

Анотація

Вебзастосунки залишаються основною мішенню для кібератак, зокрема SQL-ін'єкцій (SQLi), міжсайтового скриптингу (XSS), підробки міжсайтових запитів (CSRF) та розподілених атак типу «відмова в обслуговуванні» (DDoS). Традиційні методи захисту - зіставлення сигнатур, статичні набори правил і периметровий контроль - вже не встигають за динамічними загрозами, з якими сучасні хмарні та API-орієнтовані системи стикаються щодня. У цій статті пропонується двошарова модель безпеки, покликана усунути цю прогалину. Система організована у два взаємодоповнювальні рівні. Перший рівень використовує детерміновані засоби контролю безпеки, узгоджені зі стандартом OWASP Top 10:2025, що забезпечує стабільний і придатний до аудиту базовий захист. Другий рівень інтегрує три взаємодоповнювальні методи штучного інтелекту: вбудовування HTTP-запитів (HTTP2vec) для семантичного представлення трафіку, графові нейронні мережі (GNN) для моделювання реляційних шаблонів між користувачами, сесіями й кінцевими точками, а також автокодувальник Kitsune для онлайн-виявлення аномалій, що адаптується до змін трафіку в реальному часі. У дослідженні застосовується структурований аналітичний підхід: спочатку аналізуються нещодавні наукові роботи та реальні галузеві звіти про інциденти, а потім систематично порівнюються різні методи виявлення загроз за показниками точності, затримки і операційних витрат. Результати свідчать про те, що традиційні засоби залишаються ефективними проти відомих сигнатур атак, тоді як методи на основі ШІ значно краще виявляють вразливості нульового дня та скоординовані повільні кампанії, які системи на основі правил зазвичай пропускають. Галузеві звіти показують, що інтеграція ШІ в платформи SIEM і SOAR дозволяє скоротити кількість хибнопозитивних сповіщень приблизно на 60% та пришвидшити розслідування інцидентів приблизно на 40%, вивільняючи аналітиків для виконання більш важливих завдань. Також обґрунтовується, що криві Precision–Recall і Numenta Anomaly Benchmark (NAB) є більш відповідними інструментами оцінювання, ніж ROC-AUC, для даних із безпеки, де шкідливий трафік часто становить менше 0,1% від загального обсягу і дисбаланс класів спотворює традиційні метрики. Головний висновок простий, але важливий: ШІ найкраще працює не як замінник традиційних засобів контролю, а як підсилювач, що їх зміцнює, формуючи багаторівневий захист, одночасно стійкий і адаптивний.

Завантаження

Дані завантаження ще не доступні.

Посилання

International Telecommunication Union. (2024). Facts and figures 2024: Internet use. ITU. https://www.itu.int/itu-d/reports/statistics/2024/11/10/ff24-internet-use/

OWASP Foundation. (2025). OWASP Top 10:2025. https://owasp.org/Top10/2025/

Verizon Business. (2024). 2024 data breach investigations report. https://www.verizon.com/business/resources/reports/dbir.html

Tolkachov, M. Yu. (2024). Mechanisms of traffic protection in cyberspace. Suchasnyi Zakhyst Informatsii, 4(60), 85-99. https://doi.org/10.31673/2409-7292.2024.040009

Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207

IBM Security. (2023). Cost of a data breach report 2023. IBM. https://d110erj175o600.cloudfront.net/wp-content/uploads/2023/07/25111651/Cost-of-a-Data-Breach-Report-2023.pdf

Dilmegani, C. (2025). Top 13 AI cybersecurity use cases with real examples in 2025. AIMultiple Research. https://research.aimultiple.com/ai-cybersecurity-use-cases/

Gniewkowski, M., Maciejewski, H., Surmacz, T., & Walentynowicz, W. (2021). HTTP2vec: Embedding of HTTP requests for detection of anomalous traffic (arXiv:2108.01763). arXiv. https://doi.org/10.48550/arXiv.2108.01763

Bilot, T., Legay, A., & Rønne, P. B. (2023). Graph neural networks for intrusion detection: A survey. IEEE Access, 11, 45589-45612. https://doi.org/10.1109/ACCESS.2023.3275789

Mirsky, Y., Doitshman, T., Elovici, Y., & Shabtai, A. (2018). Kitsune: An ensemble of autoencoders for online network intrusion detection. In Proceedings of the Network and Distributed System Security Symposium (NDSS 2018). Internet Society. https://doi.org/10.14722/ndss.2018.23204

Razzaq, A., Hur, A., Ahmad, H. F., & Masood, M. (2013). Cyber security: Threats, reasons, challenges, methodologies and state-of-the-art solutions for industrial applications. In 2013 IEEE 11th International Symposium on Autonomous Decentralized Systems (ISADS) (pp. 1–6). IEEE. https://doi.org/10.1109/ISADS.2013.6513420

Liao, H. J., Lin, C. H. R., Lin, Y. C., & Tung, K. Y. (2013). Intrusion detection system: A comprehensive review. Journal of Network and Computer Applications, 36(1), 16–24. https://doi.org/10.1016/j.jnca.2012.09.004

Clincy, V., & Shahriar, H. (2018). Web application firewall: Network security models and configuration. In 2018 IEEE 42nd Annual Computer Software and Applications Conference (COMPSAC) (pp. 835–836). IEEE. https://doi.org/10.1109/COMPSAC.2018.00144

OWASP Foundation. (2025). OWASP Top 10:2025-Introduction. https://owasp.org/Top10/2025/0x00_2025-Introduction/

Park, S., Kim, M., & Lee, S. (2018). Anomaly detection for HTTP using convolutional autoencoders. IEEE Access, 6, 70884-70901. https://doi.org/10.1109/ACCESS.2018.2881003

Davis, J., & Goadrich, M. (2006). The relationship between precision-recall and ROC curves. In Proceedings of the 23rd International Conference on Machine Learning (ICML '06) (pp. 233-240). https://ftp.cs.wisc.edu/machine-learning/shavlik-group/davis.icml06.pdf

Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18(2), 1153-1176. https://doi.org/10.1109/COMST.2015.2494502

Saito, T., & Rehmsmeier, M. (2015). The precision-recall plot is more informative than the ROC plot when evaluating binary classifiers on imbalanced datasets. PLOS ONE, 10(3), e0118432. https://doi.org/10.1371/journal.pone.0118432

Lavin, A., & Ahmad, S. (2015). Evaluating real-time anomaly detection algorithms: The Numenta Anomaly Benchmark. In 2015 14th IEEE International Conference on Machine Learning and Applications (ICMLA) (pp. 38-44). IEEE. https://doi.org/10.48550/arXiv.1510.03336

Sharafaldin, I., Lashkari, A. H., & Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. In Proceedings of the International Conference on Information Systems Security and Privacy (ICISSP 2018) (pp. 108–116). https://www.scitepress.org/papers/2018/66398/66398.pdf

National Institute of Standards and Technology. (2022). Security and privacy controls for information systems and organizations (NIST Special Publication 800-53, Rev. 4). https://doi.org/10.6028/NIST.SP.800-53r4

Sommer, R., & Paxson, V. (2010). Outside the closed world: On using machine learning for network intrusion detection. In 2010 IEEE Symposium on Security and Privacy (pp. 305–316). IEEE. https://doi.org/10.1109/SP.2010.25

Ahmad, Z., Shahid Khan, A., Wai Shiang, C., Abdullah, J., & Ahmad, F. (2021). Network intrusion detection system: A systematic study of machine learning and deep learning approaches. Transactions on Emerging Telecommunications Technologies, 32(1), e4150. https://doi.org/10.1002/ett.4150

Li, J., Zhang, H., & Wei, Z. (2020). The weighted Word2Vec paragraph vectors for anomaly detection over HTTP traffic. IEEE Access, 8, 141787-141798. https://doi.org/10.1109/ACCESS.2020.3013849

Vartouni, A. M., Kashi, S. S., & Teshnehlab, M. (2018). An anomaly detection method to detect web attacks using stacked auto-encoder. In 2018 6th Iranian Joint Congress on Fuzzy and Intelligent Systems (CFIS) (pp. 131-134). IEEE. https://doi.org/10.1109/CFIS.2018.8336654

Tolkachov, M. Yu., Dzheniuk, N. V., Zakharzhevskyi, A. H., Pohasii, S. S., & Hlukhov, S. I. (2024). Method of protecting information resources based on a semiotic model of cyberspace. Suchasnyi Zakhyst Informatsii, 1(57), 57-68. https://doi.org/10.31673/2409-7292.2024.010007

Tolkachov, M., Dzheniuk, N., Yevseiev, S., et al. (2024). Development of a method for protecting information resources in a corporate network by segmenting traffic. Eastern-European Journal of Enterprise Technologies, 5(9(131)), 63-78. https://doi.org/10.15587/1729-4061.2024.313158

OWASP Foundation. (2021). OWASP Top 10:2021. https://owasp.org/Top10/2021/

Cisco. (2020). Cisco annual Internet report (2018-2023). https://www.deeprogram.org/library-v2/cisco-annual-internet-report-2018-2023-/5H7BUBW2

Sandvine. (2024). The global Internet phenomena report 2024. https://www.sandvine.com

International Organization for Standardization. (2023). ISO/IEC 27032:2023. Information technology-Cybersecurity-Guidelines for Internet security. ISO. https://cdn.standards.iteh.ai/sist-preview/76070/be57667fdd0b432490c253ca538c9938/ISO-IEC-27032-2023.pdf

Milevskyi, S. V., Kostiak, M. Yu., Milov, O. V., & Pohasii, S. S. (2019). Means of modeling agent behavior in information and communication systems. Systems of Navigation, Management, Communication and Control, 6(58), 63-70. https://doi.org/10.26906/SUNZ.2019.6.063

Downloads


Переглядів анотації: 7

Опубліковано

2026-09-24

Як цитувати

Савчук, К., & Нємкова, О. (2026). ДВОШАРОВА МОДЕЛЬ ЗАХИСТУ ВЕБЗАСТОСУНКІВ НА ОСНОВІ OWASP TOP 10:2025 ТА МЕТОДІВ ШТУЧНОГО ІНТЕЛЕКТУ. Електронне фахове наукове видання «Кібербезпека: освіта, наука, техніка», 2(34), 90–100. https://doi.org/10.28925/2663-4023.2026.34.1230

Статті цього автора (авторів), які найбільше читають