Intelligent Monitoring and Cryptographic Protection of Machine Code in Critical Infra-structure Systems

I. Martyniuk, N. Zaika

https://doi.org/10.15407/elmodel.48.04.017

Èlektron. model. 2026, 48(4):17-27

ABSTRACT

Intelligent monitoring of cyber-physical systems based on a combination of continuous observation and machine learning models to detect anomalies and enhance the proactiveness of cyber defense is examined. The effectiveness of such approaches is determined by the quality of the data and the accuracy of the models, which are built on monitoring systems where cryptographic mechanisms are integrated directly into the process of data exchange between agents and the server. Cryptographic protection is designed to ensure the integrity of the security system at the machine code level. Algorithm verification is performed using test vectors in accordance with National Institute of Standards and Technology (NIST) practices. Collectively, this forms a comprehensive approach to the cyber resilience of critical infrastructure.

Full text: PDF

KEYWORDS

intelligent monitoring, cyber-physical systems, critical infrastructure, machine learning, anomaly detection, cryptographic protection, cyber resilience.

REFERENCES

  1. National Institute of Standards and Technology. Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations (NIST SP 800-137). URL: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-137.pdf (accessed: 11.01.2026).
  2. European Union Agency for Cybersecurity (ENISA). Threat Landscape 2023. URL: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023. (accessed: 13.01.2026).
  3. (2024). Data Breach Investigations Report. URL: https://www.verizon.com/business/resources/reports/dbir/. (accessed: 15.01.2026).
  4. Chandola, V., Banerjee, A., Kumar, V. (2009). Anomaly Detection: A Survey. ACM Computing Surveys. (accessed: 16.01.2026).
    https://doi.org/10.1145/1541880.1541882
  5. National Institute of Standards and Technology. Recommendation for Key Management (NIST SP 800-57). URL: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP. 800-57pt1r5.pdf. (accessed: 01.02.2026).
  6. Unified Extensible Firmware Interface Forum. UEFI Specification. URL: https://uefi.org/ specifications. (accessed: 24.01.2026).
  7. National Institute of Standards and Technology. Guide to Industrial Control Systems (ICS) Security (NIST SP 800-82 Rev.2). URL: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-82r2.pdf. (accessed: 11.02.2026).
  8. Trusted Computing Group. Trusted Platform Module Library Specification. URL: https://trustedcomputinggroup.org/resource/tpm-library-specification. (accessed: 09.03.2026).
  9. Transport Layer Security (TLS). URL: https://en.wikipedia.org/wiki/Transport_Layer_Security. (accessed: 16.02.2026).
  10. Ministry of Economic Development and Trade of Ukraine. (2014). DSTU 7564:2014. Information security. Cryptographic hash function “Kupyna”. Kyiv. URL: https://usts.kiev.ua/ wp-content/uploads/2020/07/dstu-7564-2014.pdf. (accessed: 13.03.2026).
  11. National Institute of Standards and Technology. Secure Hash Standard (SHS) (FIPS PUB 180-4). URL: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf. (accessed: 19.02.2026).
  12. Kelsey, J., Schneier, B. Second Preimages on n-bit Hash Functions for Much Less than 2^n Work. URL: https://www.schneier.com/wp-content/uploads/2016/02/paper-preimages.pdf. (accessed: 14.01.2026).
  13. Firmware Security Analysis. URL: https://eclypsium.com/research/. (accessed: 27.02.2026).
  14. SHA-2 Cryptographic Hash Functions. URL: https://en.wikipedia.org/wiki/SHA-2. (accessed: 12.03.2026).
  15. Zabbix SIA. Zabbix Documentation — Encryption. URL: https://www.zabbix.com/documentation/current/en/manual/encryption. (accessed: 06.02.2026).
  16. Cyber Security Standards and Best Practices. URL: https://www.scribd.com/document/ 936566211. (accessed: 15.03.2026).
  17. Challenges of Monitoring Encrypted Traffic. URL: https://arxiv.org/abs/2104.09828 (accessed: 07.03.2026).
  18. Elia, P. Real-Time Automated Forensic Evidence Collection in Critical Infrastructure. URL:  https://webthesis.biblio.polito.it/37933/1/tesi.pdf. (accessed: 02.03.2026).

Received 14.04.2026