ФРЕЙМВОРК БЕЗПЕКИ НА ОСНОВІ ТЕХНОЛОГІЇ БЛОКЧЕЙН ДЛЯ МЕРЕЖЕВОЇ ВЗАЄМОДІЇ ЗА МОДЕЛЛЮ OSI У СИСТЕМАХ КРИТИЧНОЇ ІНФРАСТРУКТУРИ
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1303Ключові слова:
кібербезпека, критична інфраструктура, модель OSI, блокчейн, консенсус PBFT, смарт-контракти, системи виявлення вторгненьАнотація
Статтю присвячено розробленню та експериментальному обґрунтуванню фреймворку кібербезпеки для мережевої взаємодії систем критичної інфраструктури, який поєднує кросрівневий моніторинг за моделлю OSI, дозволений блокчейн, консенсус PBFT, смарт-контракти виявлення інцидентів та автоматизоване реагування. Актуальність дослідження зумовлена тим, що об’єкти енергетики, водопостачання, транспорту, телекомунікацій та інших секторів критичної інфраструктури дедалі частіше зазнають багатоетапних кібератак, які охоплюють кілька рівнів мережевої взаємодії та можуть поєднувати маніпуляції з трафіком, ін’єкцію хибних команд, відмову в обслуговуванні та модифікацію журналів подій. Традиційні централізовані системи виявлення вторгнень залишаються вразливими до компрометації сховищ журналів і створюють єдину точку відмови, що обмежує доказову цінність зібраних подій безпеки. Метою статті є формування цілісної архітектури, у якій агенти моніторингу збирають метадані протокольних блоків даних рівнів L2–L7, хеші та стислі ознаки подій фіксуються в незмінному розподіленому реєстрі, а смарт-контракти виконують кросрівневу кореляцію та ініціюють сценарії реагування. У роботі формалізовано модель загроз, описано структуру блокчейн-реєстру, механізм адаптивної оцінки довіри вузлів, інтегральну оцінку аномальності подій та алгоритм функціонування фреймворку. Експериментальна перевірка на емуляційному стенді показала, що запропонований підхід забезпечує вищу F1-міру виявлення порівняно із сигнатурною IDS, RF-IDS та централізованим варіантом зберігання подій, зберігаючи прийнятну наскрізну затримку для сценаріїв моніторингу критичної інфраструктури. Отримані результати підтверджують доцільність використання дозволених блокчейн-мереж як довіреного шару журналювання, верифікації та координації реагування на інциденти у розподілених кіберфізичних середовищах
Завантаження
Посилання
Kim, K., Alshenaifi, I. M., Ramachandran, S., Kim, J., Zia, T., & Almorjan, A. (2023). Cybersecurity and cyber forensics for smart cities: A comprehensive literature review and survey. Sensors, 23(7), 3681. https://doi.org/10.3390/s23073681
National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29
European Union Agency for Cybersecurity. (2025). ENISA threat landscape 2025. ENISA. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025
International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection-Information security management systems-Requirements. ISO. https://www.iso.org/standard/27001
Sharafaldin, I., Habibi Lashkari, A., & Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. In Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP 2018) (pp. 108-116). SciTePress. https://doi.org/10.5220/0006639801080116
Nakamoto, S. (2008). Bitcoin: A peer-to-peer electronic cash system. https://bitcoin.org/bitcoin.pdf
Androulaki, E., Barger, A., Bortnikov, V., et al. (2018). Hyperledger Fabric: A distributed operating system for permissioned blockchains. In Proceedings of the 13th EuroSys Conference (EuroSys 2018) (Article 30, pp. 1-15). ACM. https://doi.org/10.1145/3190508.3190538
Castro, M., & Liskov, B. (2002). Practical Byzantine fault tolerance and proactive recovery. ACM Transactions on Computer Systems, 20(4), 398–461. https://doi.org/10.1145/571637.571640
Wang, W., Mosse, D., Sun, Y., & Zhang, L. (2021). Industrial control malicious traffic anomaly detection system based on improved deep autoencoder. Frontiers in Energy Research, 8, 555145. https://doi.org/10.3389/fenrg.2020.555145
Supeno, B. A., Mohamed Radzi, N. A. B., & Al-Haiqi, A. (2025). Machine learning-based anomaly detection for Modbus and DNP3 protocols in industrial control systems. In 2025 International Conference on Technology and Policy in Energy and Electric Power (ICT-PEP). IEEE. https://doi.org/10.1109/ICT-PEP67281.2025.11232367
Azhar, M., Perveen, S., Iqbal, A., & Lee, B. (2024). IDRandom-Forest: Advanced Random Forest for real-time intrusion detection. IEEE Access, 12, 113842-113854. https://doi.org/10.1109/ACCESS.2024.3443408
Wood, G. (2014). Ethereum: A secure decentralised generalised transaction ledger. Ethereum Yellow Paper. https://ethereum.github.io/yellowpaper/paper.pdf
Rathee, G., Ahmad, F., Jaglan, N., & Konstantinou, C. (2023). A secure and trusted mechanism for Industrial IoT network using blockchain. IEEE Transactions on Industrial Informatics, 19(2), 1894–1902. https://doi.org/10.1109/TII.2022.3182121
Ghadi, Y. Y., et al. (2025). A hybrid AI-blockchain security framework for smart grids. Scientific Reports, 15, 05257. https://doi.org/10.1038/s41598-025-05257-w
Georgiades, M., et al. (2025). An explainable AI approach for interpretable cross-layer intrusion detection. Electronics, 14(16), 3218. https://doi.org/10.3390/electronics14163218
Maosa, H., et al. (2024). A hierarchical security event correlation model for real-time intrusion detection. Cybersecurity, 4(1), 4. https://doi.org/10.3390/cyber4010004
Karlzén, H., & Sommestad, T. (2023). Automatic incident response solutions: A review of proposed solutions’ input and output. In Proceedings of the 18th International Conference on Availability, Reliability and Security (ARES 2023) (Article 37, pp. 1–9). ACM. https://doi.org/10.1145/3600160.3605066
Chu, H., Zhang, P., Dong, H., Xiao, Y., Ji, S., & Li, W. (2023). A survey on smart contract vulnerabilities: Data sources, detection and repair. Information and Software Technology, 159, 107221. https://doi.org/10.1016/j.infsof.2023.107221
MITRE Corporation. (2026). MITRE ATT&CK® knowledge base. https://attack.mitre.org/
Al-Sada, B., Sadighian, A., & Oligeri, G. (2024). MITRE ATT&CK: State of the art and way forward. ACM Computing Surveys, 57(2), Article 39. https://doi.org/10.1145/3687300
Guggenberger, T., Sedlmeir, J., Fridgen, G., & Luckow, A. (2022). An in-depth investigation of the performance characteristics of Hyperledger Fabric. Computers & Industrial Engineering, 173, 108716. https://doi.org/10.1016/j.cie.2022.108716
Liu, W., Zhang, X., Feng, W., Huang, M., & Xu, Y. (2022). Optimization of PBFT algorithm based on QoS-aware trust service evaluation. Sensors, 22(12), 4590. https://doi.org/10.3390/s22124590
Ahakonye, L. A. C., Nwakanma, C. I., & Kim, D.-S. (2024). Tides of blockchain in IoT cybersecurity. Sensors, 24(10), 3111. https://doi.org/10.3390/s24103111
Ortmann, M., et al. (2024). Zero trust architectures for interconnected industry. Fraunhofer Institute for Production Technology IPT. https://doi.org/10.24406/publica-3778
Barreto, N. E. M., et al. (2025). Cyber-physical power system digital twins – A study on resilience, flexibility and cybersecurity. Energies, 18(22), 5960. https://doi.org/10.3390/en18225960
Novikova, E., Doynikova, E., & Golubev, S. (2022). Federated learning for intrusion detection in the critical infrastructures: Vertically partitioned data use case. Algorithms, 15(4), 104. https://doi.org/10.3390/a15040104
Castiglione, A., Esposito, J. G., Loia, V., Nappi, M., Pero, C., & Polsinelli, M. (2025). Integrating post-quantum cryptography and blockchain to secure low-cost IoT devices. IEEE Transactions on Industrial Informatics, 21(2), 1674–1683. https://doi.org/10.1109/TII.2024.3485796
Опубліковано
Як цитувати
Номер
Розділ
Ліцензія
Авторське право (c) 2026 Дмитро Прокопович-Ткаченко

Ця робота ліцензується відповідно до Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.