MULTILEVEL ARCHITECTURE FOR BEHAVIORAL ARTIFACT COLLECTION IN HETEROGENEOUS NETWORKS TO FORM DIGITAL FOOTPRINTS
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1249Keywords:
behavioral artifacts, digital footprints, heterogeneous networks, post-quantum security, sensor hierarchy, data aggregationAbstract
The object of research is the process of generating a digital evidence array within heterogeneous information and communication systems under post-quantum cyber threats. The subject of research encompasses architectural solutions and methods for the multilevel collection of behavioral artifacts for decision support systems (DSS). The relevance of this work stems from the need to develop alternative security verification methods for network nodes in cases where current cryptographic identification (TLS, PKI) may be compromised by an adversary with access to quantum resources. Unlike existing methods focused on analyzing individual log types, this paper proposes the concept of a sensor hierarchy covering the network, system, and application levels of the infrastructure. The scientific novelty of the results lies in the formalization of the procedure for transforming disparate raw security events into structured "digital footprints." Specifically, a multilevel monitoring architecture has been developed, enabling flexible adjustments to the intensity of artifact collection depending on the network segment type and the predicted attack vector (EDoS impacts, Supply Chain Attacks). For the first time, a methodology for weighting behavioral features based on their informativeness is described, ensuring the minimization of computational costs for data processing while maintaining high reliability in forming input parameters for game-theoretic security models. The practical significance of the work lies in the development of software module structures for data aggregation that can be integrated into existing SIEM/IDS platforms. The implementation of the proposed architecture using the Python language has enabled the automation of detecting anomalous deviations in node behavior, even when digital certificates formally remain valid. Experimental validation of the architecture confirmed its ability to ensure the integrity of the DSS information base, even under conditions of changing heterogeneous environment topology and significant network noise levels.
Downloads
References
Khan, M. Z. A., Khan, M. M., & Arshad, J. (2022). Anomaly detection and enterprise security using user and entity behavior analytics (UEBA). In 2022 3rd International Conference on Innovations in Computer Science & Software Engineering (ICONICS) (pp. 1-9).
Singer, P. W., & Friedman, A. (2013). Cybersecurity and cyberwar: What everyone needs to know. Oxford University Press.
Paananen, H., Lapke, M., & Siponen, M. (2020). State of the art in information security policy development. Computers & Security, 88, 101608. https://doi.org/10.1016/j.cose.2019.101608
Ahmad, Z., Khan, A. S., Shiang, C. W., Abdullah, J., & Ahmad, F. (2021). Network intrusion detection system: A systematic study of machine learning and deep learning approaches. Transactions on Emerging Telecommunications Technologies, 32(1), e4150. https://doi.org/10.1002/ett.4150
Keshavarzian, A., Sharifian, S., & Seyedin, S. (2019). Modified deep residual network architecture deployed on serverless framework of IoT platform based on human activity recognition application. Future Generation Computer Systems, 101, 14-28. https://doi.org/10.1016/j.future.2019.06.009
Li, H., Li, Z., Peng, S., Li, J., & Tungom, C. E. (2020). Mining the frequency of time-constrained serial episodes over massive data sequences and streams. Future Generation Computer Systems, 110, 849-863. https://doi.org/10.1016/j.future.2019.11.008
Qureshi, K. N., Jeon, G., & Piccialli, F. (2021). Anomaly detection and trust authority in artificial intelligence and cloud computing. Computer Networks, 184, 107647. https://doi.org/10.1016/j.comnet.2020.107647
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
Ashfaq, S., Patil, S. A., Borde, S., Chandre, P., Shafi, P. M., & Jadhav, A. (2023). Zero trust security paradigm: A comprehensive survey and research analysis. Journal of Electrical Systems, 19(2).
Boyens, J., Paulsen, C., Moorthy, R., & Bartol, N. (2022). Supply chain risk management practices for federal information systems and organizations (NIST Special Publication 800-161 Revision 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-161r1
Reichert, B. M., & Obelheiro, R. R. (2024). Software supply chain security: A systematic literature review. International Journal of Computers and Applications, 46(10), 853-867. https://doi.org/10.1080/1206212X.2024.2390978
Chen, L., Jordan, S., Liu, Y.-K., Moody, D., Peralta, R., Perlner, R., & Smith-Tone, D. (2016). Report on post-quantum cryptography (NIST Interagency/Internal Report 8105). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.IR.8105
Joseph, D., Misoczki, R., Manzano, M., Tricot, J., Pinuaga, F. D., Lacombe, O., ... Hansen, R. (2022). Transitioning organizations to post-quantum cryptography. Nature, 605(7909), 237-243. https://doi.org/10.1038/s41586-022-04623-2
Chandola, V., Banerjee, A., & Kumar, V. (2009). Anomaly detection: A survey. ACM Computing Surveys, 41(3), Article 15. https://doi.org/10.1145/1541880.1541882
Pang, G., Shen, C., Cao, L., & van den Hengel, A. (2021). Deep learning for anomaly detection: A review. ACM Computing Surveys, 54(2), Article 38. https://doi.org/10.1145/3439950
Casey, E. (2011). Digital evidence and computer crime: Forensic science, computers, and the Internet (3rd ed.). Academic Press.
Lakhno, V., Voloshyn, S., Mamchenko, S., Kulinich, O., & Kasatkin, D. (2024). Cluster analysis for studying digital traces of students in educational institutions. Cybersecurity: Education, Science, Technique, 3(23), 31-41. https://doi.org/10.28925/2663-4023.2024.23.3141
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Валерій Лахно, Валерій Гладких, Андрій Сагун

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.