doi: 10.17586/2226-1494-2026-26-3-486-494


Big data in the processes of ensuring the security of critical information infrastructure facilities

M. Y. Tolstykh, P. D. Korataev


Read the full article  ';
Article in Russian

For citation:
Tolstykh M.Yu., Korataev P.D. Big data in the processes of ensuring the security of critical information infrastructure facilities. Scientific and Technical Journal of Information Technologies, Mechanics and Optics, 2026, vol. 26, no. 3, pp. 486–494 (in Russian). doi: 10.17586/2226-1494-2026-26-3-486-494


Abstract
The role of big data technology in the processes of ensuring the security of objects of the critical information infrastructure (CII) of the Russian Federation in the context of increasing cyber-attacks and digital transformation is investigated. The task of moving from a reactive to a proactive protection model is being actualized. The scientific novelty of the research lies in the development of original directions for integrating Big Data into CII security systems: modeling cascading cyber-physical incidents on intersystem dependency graphs, analyzing the “dark data” of industrial equipment as a source of compromise indicators, and a hybrid architecture of federated learning for interdisciplinary cooperation of CII subjects without transferring confidential data beyond the organization perimeter. A mathematical apparatus for constructing resilient security systems is proposed, based on the representation of a cyber-physical infrastructure in the form of a dynamic weighted oriented time multigraph with Bayesian updating of weights in real time. The dynamics of impact propagation is modeled by continuous Markov chains with absorption, and optimization of the placement of protective equipment is formalized as a stochastic defender–attacker game with the search for an e-approximate Nash equilibrium using reinforcement learning methods. A two-stage iteratively refining algorithm for maximizing sustainability under budgetary, resource, and regulatory constraints has been developed. A closed data-driven loop of proactive security management of CII facilities has been formed, in which big data flows ensure continuous updating of model parameters and adaptation of protective mechanisms. Approach verification on a distribution grid digital twin demonstrated 94.3 % incident classification accuracy. Unlike traditional Security Information and Event Management and User and Entity Behavior Analytics solutions focused on the correlation of known events, the proposed approach provides predictive modeling of the cyber-physical consequences of attacks, taking into account interlayer dependencies. The architecture of federated learning allows for the formation of cross-industry threat models without violating the requirements of information protection legislation. The prospects for application are related to the regulatory consolidation of the developed mechanisms as mandatory elements of security systems at significant CII facilities and the creation of a national platform for the exchange of impersonal threat models.

Keywords: Big Data, critical information infrastructure, cybersecurity, digital transformation, resilient systems

References
1. Yakushev N.O., Ustinova K.A., Kochnev A.A. Import substitution as a factor in the development of domestic digital technology. Economic and Social Changes: Facts, Trends, Forecast, 2024, vol. 17, no. 3, pp. 82–101. (in Russian). doi: 10.15838/esc.2024.3.93.5
2. Davies Ph., Fritzsche A., Parry G., Wood Z. Data, resilience, and identity in the digital age. Strategic Change, 2023, vol. 32, no. 6, pp. 169–174. doi: 10.1002/jsc.2560
3. Dedousis P., Stergiopoulos G., Arampatzis G., Gritzalis D. A security-aware framework for designing industrial engineering processes. IEEE Access, 2021, vol. 9, pp. 163065–163085. doi: 10.1109/access.2021.3134759
4. Zarochentsev A., Espinal X., Kiryanov A., Schovancova J. Federated data storage evolution in HENP: data lakes and beyond. Journal of Physics: Conference Series, 2020, vol. 1525, pp. 012071. doi: 10.1088/1742-6596/1525/1/012071
5. Nguyen Q.V.H., Zheng K., Weidlich M., Zheng B.L., Yin H., Nguyen T.T., Stantic B. What-if analysis with conflicting goals: recommending data ranges for exploration. Proc. of the IEEE 34th International Conference on Data Engineering (ICDE), 2018, pp. 89–100. doi: 10.1109/icde.2018.00018
6. Kosov N.A., Gelfand A.M., Laptev A.A. Analysis of dark data to ensure sustainability information systems from breach of privacy or unauthorized actions. Colloquium-Journal, 2019, no. 13-2 (37), pp. 100–103. (in Russian)
7. Renskov D.A. Research of methods of development of data management systems, including databases, data warehouses and data lakes. Proc. of the Scientific Research and Technological Sovereignty in the Modern World, 2025, pp. 59–64. (in Russian)
8. Tom A.K., Khraisat A., Jan T., Whaiduzzaman M., Nguyen T.D., Alazab A. Survey of federated learning for cyber threat intelligence in industrial IoT: techniques, applications and deployment models. Future Internet, 2025,vol. 17, no. 9, pp. 409. doi: 10.3390/fi17090409
9. Kostenko V.A., Selezneva A.E. Types of attacks on federated neural networks and methods of protection. Proceedings of the Institute for System Programming of the RAS (Proceedings of ISP RAS), 2024, vol. 36, no.1, pp. 35-44. (in Russian). doi: 10.15514/ISPRAS-2024-36(1)-3
10. Borovkov A.I., Ryabov Yu.A., Shcherbina L.A., Martynets E.A., Korchevskaya A.A. Digital Twins in the High-Technology Manufacturing Industry. St. Petersburg, POLITEKH-PRESS Publ., 2022, 492 p. (in Russian)
11. Kishkovich Yu.P. Discrete Mathematics and Elements of Network Analysis in R Language. Moscow, KnoRus Publ., 2023, 24 p. (in Russian)
12. Zhou H., Chen X., Yuan Y. A novel Extended-Kalman-Filter-Incorporated Latent Feature model on dynamic weighted directed graphs. Proc. of the IEEE International Conference on Systems, Man, and Cybernetics (SMC), 2024, pp. 191–196. doi: 10.1109/smc54092.2024.10832044
13. Bure V.M., Parilina E.M. Probability Theory and Mathematical Statistics. St. Petersburg, Lan' Publ., 2025, 416 p. (in Russian)
14. Kang P. Evaluation of GPU-Accelerated edge platforms for stochastic simulations: performance and energy efficiency analysis. Mathematics, 2025, vol. 13, no. 20, pp. 3305. doi: 10.3390/math13203305
15. Miao L., Li S. Cyber security based on mean field game model of the defender: Attacker strategies. International Journal of Distributed Sensor Networks, 2017, vol. 13, no. 10, pp. 1–10. doi: 10.1177/1550147717737908
16. KochenderferM.J., Wheeler T.A., Wray K.H. Algorithms for Decision Making. The MIT Press, 2022, 700 p.
17. Moghimi M., Ku H. Risk-sensitive actor-critic with static spectral risk measures for online and offline reinforcement learning. arXiv, 2025. arXiv:2507.03900. doi: 10.48550/arXiv.2507.03900
18. Zelentsov B.P. Aggregation of states of Markov processes by modeling reliability of technical systems. Reliability & Quality of Complex Systems, 2021, no. 2 (34), pp. 36–52. (in Russian). doi: 10.21685/2307-4205-2021-2-4
19. Gasnikov A.V. Modern Numerical Optimization Methods. Universal Gradient. Moscow, MIPT Publ., 2018, 286 p. (in Russian)
20. Gitman I.B. Introduction to Stochastic Optimization. Perm, PNIPU Publ., 2014, 104 p. (in Russian)


Creative Commons License

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License
Copyright 2001-2026 ©
Scientific and Technical Journal
of Information Technologies, Mechanics and Optics.

Яндекс.Метрика