AUTOMATION OF A PROJECT SOLUTION FOR SOFTWARE RECOVERY AFTER CYBERATTACKS
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1264Keywords:
cybersecurity, cyberattacks, software recovery, automation, formalization, mathematical model, decision-making, artificial intelligenceAbstract
This article examines the pressing scientific and practical problem of automating the recovery of software damaged by cyberattacks, an issue that is becoming particularly important given the growing number and complexity of cyber threats. An analysis of current scientific research was conducted, which showed that the main areas of development are the formalization of recovery processes based on mathematical models, as well as the application of artificial intelligence and machine learning methods. A representation of the process of recovering damaged software is proposed in the form of a set of interrelated tasks organized according to the principle of multilevel decomposition. Each task is described as a system of sets, including input data, constraints, solution options, evaluation criteria, models, and procedures for their implementation. This allows for the formalization of the decision-making process, the identification of dependencies between tasks, and the assurance of their algorithmic implementation. The paper also presents an example of a mathematical model for selecting the optimal method of software recovery following ransomware attacks. The model accounts for the structure of the software system, the set of defects, their properties and criticality, as well as available recovery methods, taking into account time, resource, and risk costs. An optimization objective function with weighting coefficients is proposed, which allows determining the most effective recovery strategy, taking into account the specified criteria. The results obtained demonstrate the feasibility of using formalized approaches
Downloads
References
Kozlovskyi, V. V., & Kopiika, O. O. (2020). Analysis of modern cyber threats and methods of information systems protection. Information Protection, 22(3), 45-52.
Lytvynenko, O. V., & Kovalenko, A. P. (2021). Cybersecurity of critical infrastructure: Current state and development prospects. Information Processing Systems, (2), 120-126.
Ilau, M.-C., Baldwin, A., Caulfield, T., & Pym, D. (2025). Modelling and simulating organizational ransomware recovery: Structure, methodology, and decisions. Journal of Cybersecurity, 11(1), Article tyaf035. https://doi.org/10.1093/cybsec/tyaf035
Zhao, M., & Chen, R. (2025). Automated cybersecurity incident response: A reinforcement learning approach. AI and Data Science Journal, 2(1), 23-28.
Leventopoulos, S., Pipyros, K., & Gritzalis, D. (2024). Retaliating against cyber-attacks: A decision-taking framework for policy-makers and enforcers of international and cybersecurity law. International Cybersecurity Law Review, 5, 237-262.
Bondarenko, O. I. (2020). Intelligent decision support systems in cybersecurity. Information Technologies and Security, (1), 15-22.
Zhang, Q., & Chen, M. (2020). AI-driven self-healing cloud systems. IEEE Cloud Computing, 7(3), 40-50.
Kenmogne, L. A., & Mocanu, S. (2024). Explainable AI for process-aware attack detection in industrial control systems. In Proceedings of the 2024 IEEE 10th International Conference on Network Softwarization (NetSoft) (pp. 363-368). IEEE. https://doi.org/10.1109/NETSOFT60951.2024.10588940
Kasali, K., Orekha, P., & Usoro, S. (2025). AI-driven strategies for mitigating cybersecurity threats in U.S. small and medium enterprises (SMEs). International Journal of Computer Science and Information Technologies, 16(3), 110-116.
Petrenko, S. O. (2022). Formalization of software recovery method selection after cyberattacks. Bulletin of the National Technical University of Ukraine "Igor Sikorsky Kyiv Polytechnic Institute". Series: Informatics, Control and Computer Engineering, (75), 78-85.
Dolhova, N. H., Shapovalova, O. O., & Solodovnyk, H. V. (2025). Decision support system for cybersecurity design of critical infrastructure. Cybersecurity: Education, Science, Technique, 1(29), 348-368.
Dobryshyn, Yu. Ye., Sydorenko, S. M., & Vorokhob, M. V. (2023). Automated decision support system for recovering software damaged by cyberattacks. Cybersecurity: Education, Science, Technique, 4(20), 174-180.
Van der Kleij, R., Cadet, B., & Young, H. (2022). Developing decision support for cybersecurity threat and incident managers. Computers & Security, 113, Article 102535. https://doi.org/10.1016/j.cose.2021.102535
Lu, P., Zhang, L., Liu, M., et al. (2024). Recovery from adversarial attacks in cyber-physical systems: Shallow, deep and exploratory works. ACM Computing Surveys. https://doi.org/10.1145/3653974
Kott, A., Weisman, M. J., & Vandekerckhove, J. (2022). Mathematical modeling of cyber resilience. In Proceedings of the MILCOM 2022 IEEE Military Communications Conference. IEEE. https://doi.org/10.1109/MILCOM55135.2022.10017731
Sözer, H., Tekinerdogan, B., & Aksit, M. (2014). Optimizing decomposition of software architecture for local recovery. Software Quality Journal, 22(4), 703-736.
Tonon, A., Zhang, M., Caglayan, B., Shen, F., Gui, T., Wang, M., & Zhou, R. (2025). RADICE: Causal graph based root cause analysis for system performance diagnostic [Preprint]. arXiv. https://doi.org/10.48550/arXiv.2501.11545
Li, J., Yang, G., & Shao, Y. (2023). Ransomware detection method based on TextGCN. In Proceedings of the 6th International Conference on Artificial Intelligence and Big Data (ICAIBD). Chengdu, China.
Wei, R., Cai, L., Yu, A., & Meng, D. (2021). DeepHunter: A graph neural network based approach for robust cyber threat hunting. In Security and Privacy in Communication Networks (pp. 3-24). https://arxiv.org/abs/2104.09806
Rabzelj, M., Bohak, C., Južnič, L., Kos, A., & Sedlar, U. (2023). Cyberattack graph modeling for visual analytics. IEEE Access, 11, 1-34. https://doi.org/10.1109/ACCESS.2023.3304640
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Юрій Добришин

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.