350 rub
Journal Highly available systems №3 for 2025 г.
Article in number:
Cybersecurity of systems implementing data intensive domains. New methods and system solutions for building a secure data processing and analysis environment using the example of an environment that takes into account the specifics of information processing in the healthcare industry
Type of article: scientific article
DOI: https://doi.org/10.18127/j20729472-202503-02
UDC: 681.3
Authors:

V.I. Budzko1, V.G. Belenkov2

1, 2 Federal Research Center «Computer Science» of the Russian Academy Sciences (Moscow, Russia)
1 vbudzko@frccsc.ru, 2 vbelenkov@frccsc.ru

Abstract:

The current stage of development of Russian society is characterized by digital transformation of all its spheres, including healthcare. One of the areas of such transformation is the widespread use of systems implementing data intensive domains (DID systems), technologies and artificial intelligence systems. The increasingly widespread use of these systems, their functioning in the field of healthcare entails new risks of ensuring information security, which can negatively affect individuals, groups and organizations and society as a whole. Methods of ensuring cybersecurity taking into account the specifics of these systems and technologies require development. New methods for the field of information protection (IP) and system solutions for building a secure Distributed Environment of DID systems in the healthcare industry are considered in the article taking into account the current regulatory and technical framework in the field of IP in the country.

Pages: 18-30
References
  1. Budzko V.I., Korolev V.I., Belenkov V.G., Kejer P.A. Kiberbezopasnost' sistem, realizuyushchih intensivnoe ispol'zovanie dannyh. Mesto kiberbezopasnosti v zashchite informacii. Sistemy vysokoj dostupnosti. 2024. T. 20. № 1. S. 16–29. DOI: https://doi.org/10.18127/ j20729472-202401-02
  2. Budzko V.I., Medennikov V.I., Korolev V.I., Belenkov V.G., Kejer P.A. Osobennosti sistem s intensivnym ispol'zovaniem dannyh kak ob"ektov obespecheniya bezopasnosti informacii na primere ASU agrotekhnologicheskimi processami. Sistemy vysokoj dostupnosti. 2024. T. 20. № 2. S. 28–39. DOI: https://doi.org/10.18127/j20729472-202402-02
  3. Budzko V.I., Korolev V.I., Belenkov V.G., Kejer P.A. Kiberbezopasnost' sistem, realizuyushchih intensivnoe ispol'zovanie dannyh. Bezopasnost' informacionnoj infrastruktury oblasti s intensivnym ispol'zovaniem dannyh. Sistemy vysokoj dostupnosti. 2024. T. 20. № 3. S. 5–18. DOI: https://doi.org/10.18127/j20729472-202403-01
  4. Budzko V.I., Korolev V.I., Belenkov V.G., Kejer P.A. Kiberbezopasnost' sistem, realizuyushchih intensivnoe ispol'zovanie dannyh. Bezopasnost' Raspredelennoj Sredy sistemy, realizuyushchej intensivnoe ispol'zovanie dannyh. Sistemy vysokoj dostupnosti. 2024. T. 20. № 4.
    S. 15–23. DOI: https://doi.org/10.18127/j20729472-202404-02
  5. Budzko V.I., Belenkov V.G. Kiberbezopasnost' sistem, realizuyushchih intensivnoe ispol'zovanie dannyh, ispol'zuyushchih tekhnologii iskusstvennogo intellekta. Sistemy vysokoj dostupnosti. 2025. T. 21. № 1. S. 52–62. DOI: https://doi.org/10.18127/j20729472-202501-05
  6. Budzko V.I., Belenkov V.G., Kejer P.A. Kiberbezopasnost' sistem, realizuyushchih intensivnoe ispol'zovanie dannyh. Podhody k primeneniyu metodov iskusstvennogo intellekta dlya avtomatizacii processov obnaruzheniya uyazvimostej, vyyavleniya, predotvrashcheniya, reagirovaniya i vosstanovleniya posle atak. Sistemy vysokoj dostupnosti. 2025. T. 21. № 3. S. 21–34. DOI: https://doi.org/10.18127/j20729472-202502-02
  7. Polozhenie o Edinoj gosudarstvennoj informacionnoj sisteme v sfere zdravoohraneniya (v red. Postanovlenij Pravitel'stva RF ot 30.11.2022 N 2199, ot 11.12.2023 N 2111, ot 04.03.2024 N 261). Utverzhdeno postanovleniem Pravitel'stva Rossijskoj Federacii ot 9 fevralya 2022 g. N 140.
  8. Prikaz Ministerstva zdravoohraneniya RF ot 24 dekabrya 2018 g. N 911n «Ob utverzhdenii Trebovanij k gosudarstvennym informacionnym sistemam v sfere zdravoohraneniya sub"ektov Rossijskoj Federacii, medicinskim informacionnym sistemam medicinskih organizacij i informacionnym sistemam farmacevticheskih organizacij». https://www.garant.ru/products/ipo/prime/doc/72117630/
  9. Koncepciya sozdaniya Edinoj gosudarstvennoj informacionnoj sistemy v sfere zdravoohraneniya. Prilozhenie k Prikazu Ministerstva zdravoohraneniya i social'nogo razvitiya Rossijskoj Federacii ot 28 aprelya 2011 g. N 364.
  10. Anfinogenov I. Informacionnaya bezopasnost' MIS: kak ne dopustit' utechki dannyh pacientov. https://archimed.pro/blog/ informatsionnaya-bezopasnost-mis-kak-ne-dopustit-utechki-dannykh-patsientov/ (vylozhen 21.02.2020 10:00:00).
  11. Healthcare System Cybersecurity Readiness and Response Considerations. Originally Published February 2021, Updated October 2022. https://files.asprtracie.hhs.gov/documents/aspr-tracie-healthcare-system-cybersercurity-readiness-response.pdf
  12. KII v zdravoohranenii. https://www.ec-rs.ru/blog/kii/kii-v-zdravookhranenii-kak-opredelit-i-chto-delat-dalshe/
  13. KEDU. Information security: metody obespecheniya. https://kedu.ru/press-center/articles/info-information-security-metody-obespecheniya/
  14. Savina A. Kiberbezopasnost' i cifrovaya transformaciya: 3 glavnyh tendencii zashchity dannyh. https://cloudnetworks.ru/ analitika/kiberbezopasnost-i-tsifrovaya-transformatsiya-3-glavnyh-tendentsii-zashhity-dannyh/. (opublikovano 22.09.2023).
  15. Informacionnaya bezopasnost' (trendy). Stat'ya vhodit v obzor TAdviser «Rossijskij rynok IB». https://www.tadviser.ru/ index.php/Stat'ya:Glavnye_tendencii_v_zashchite_informacii#.D0.90.D0.BA.D1.82.D1.83.D0.B0.D0.BB.D1.8C.D0.BD.D1.8B.D0.B5_.D1.82.D0.B5.D1.85.D0.BD.D0.BE.D0.BB.D0.BE.D0.B3.D0.B8.D1.87.D0.B5.D1.81.D0.BA.D0.B8.D0.B5_.D1.82.D1.80.D0.B5.D0.BD.D0.B4.D1.8B_.D0.B8_.D0.BF.D0.B5.D1.80.D1.81.D0.BF.D0.B5.D0.BA.D1.82.D0.B8.D0.B2.D0.BD.D1.8B.D0.B5_.D0.BD.D0.B0.D0.BF.D1.80.D0.B0.D0.B2.D0.BB.D0.B5.D0.BD.D0.B8.D1.8F_.D1.80.D0.B0.D0.B7.D0.B2.D0.B8.D1.82.D0.B8.D1.8F_.D1.81.D0.B8.D1.81.D1.82.D0.B5.D0.BC_.D0.98.D0.91
  16. Mahabubur Rahman, Imran Uddin, Rana Das, Tuhalika Saha, Engr. S.K. Moududul Haque, Nahid Reza Shatu, Shafiqul Islam Shafi. Application of Artificial Intelligence in Detecting and Mitigating Cyber Threats. International Research Journal of Innovations in Enginee­ring and Technology (IRJIET) ISSN (online): 2581-3048. V. 9. Iss. 1. P. 17–26. January-2025 https://doi.org/10.47001/ IRJIET/2025.90100
  17. Guma Ali, Maad M. Mijwi, Bosco Apparatus Buruga, Mostafa Abotaleb , Ioannis Adamopoulos Survey on Artificial Intelligence in Cybersecurity for Smart Agriculture: State-ofthe-Art, Cyber Threats, Artificial Intelligence Applications, and Ethical Concerns. Mesopotamian journal of Computer Science. 2024. P. 71–121. DOI: https://doi.org/10.58496/MJCSC/2024/007; https://mesopotamian.press/ journals/index.php/cs
  18. Piskov A.A., Ovasapyan T.D., Moskvin D.A. Avtomatizirovannyj analiz povedeniya pol'zovatelej v DDP-sistemah s ispol'zovaniem metodov mashinnogo obucheniya / Mater. 33-j nauchno-tekhn. konf. №Metody i tekhnicheskie sredstva obespecheniya bezopasnosti informacii» (24–27iyunya 2024 g). Sankt-Peterburg, ISSN 2305-994x. S. 24–26.
  19. Zavadskij E.V., Kalinin M.O. Metod sozdaniya cifrovogo dvojnika dlya povysheniya zashchishchennosti setej kriticheskoj informacionnoj infrastruktury / Mater. 31-j nauchno-tekhn. konf. «Metody i tekhnicheskie sredstva obespecheniya bezopasnosti informacii» (27–30 iyunya 2022 g.). Sankt-Peterburg, ISSN 2305-994x. S. 13–14.
  20. Danilov V.D., Ovasapyan T.D. Analiz metodov generirovaniya sinteticheskih dannyh v kontekste sozdaniya HONEYPOT-sistem / Mater. 31-j nauchno-tekhn. konf. «Metody i tekhnicheskie sredstva obespecheniya bezopasnosti informacii» (27–30 iyunya 2022 g.). Sankt-Peterburg, ISSN 2305-994x. S. 46–47.
  21. Pavlenko E.Yu. Obespechenie informacionnoj bezopasnosti slozhnyh sistem na osnove iskusstvennoj immunizacii / Mater. 31-j nauchno-tekhn. konf. «Metody i tekhnicheskie sredstva obespecheniya bezopasnosti informacii» (27–30 iyunya 2022 g.). Sankt-Peterburg, ISSN 2305-994x. S. 26–28.
  22. Balyabin A.A., Novikov V.A., Petrenko S.A. Metod immunnogo otveta na ranee neizvestnye vredonosnye vozdejstviya / Mater. 31-j nauchno-tekhn. konf. «Metody i tekhnicheskie sredstva obespecheniya bezopasnosti informacii» (27–30 iyunya 2022 g.). Sankt-Peterburg, ISSN 2305-994x. S. 1–13.
  23. Al'shanskaya T.V. Perspektivy kvantovyh tekhnologij, osobennosti standartizacii / Mater. 33-j nauchno-tekhn. konf. «Metody i tekhni­cheskie sredstva obespecheniya bezopasnosti informacii» (24–27 iyunya 2024 g.). Sankt-Peterburg, ISSN 2305-994x. S. 145–147.
  24. Krasheninnikov E.A., Yarmak A.V., Aleksandrova E.B. Kontrol' dostupa k dannym oblachnogo hranilishcha na osnove izogenij / Mater. 31-j nauchno-tekhn. konf. «Metody i tekhnicheskie sredstva obespecheniya bezopasnosti informacii» (27–30 iyunya 2022 g.). Sankt-Peterburg, ISSN 2305-994x. S. 139–141.
  25. Yugaj P.E, Moskvin D.A., Ovasapyan T.D. Obnaruzhenie razvedki setevoj infrastruktury putem vyyavleniya anomalij v setevom trafike / Mater. 33-j nauchno-tekhn. konf. «Metody i tekhnicheskie sredstva obespecheniya bezopasnosti informacii» (24–27 iyunya 2024 g.). Sankt-Peterburg, ISSN 2305-994x. S. 40–41.
  26. Malyavko A.A. Strukturnaya i funkcional'naya organizaciya samoobuchaemoj samomodificiruyushchejsya nejronnoj seti. Izvestiya Samarskogo nauchnogo centra Rossijskoj akademii nauk. 2016. T. 18. № 2(3). S. 922–927. https://cyberleninka.ru/article/n/ strukturnaya-i-funktsionalnaya-organizatsiya-samoobuchaemoy-samomodifitsiruyuscheysya-neyronnoy-seti
  27. Chris Gilbert, Mercy Abiola Gilbert. Artificial Intelligence (AI) and Machine Learning (ML) for PredictiveCyber Threat Intelligence (CTI). International Journal of Research Publica-tion and Reviews. 2025. V. 6. Iss. 3. P. 584–617. www.ijrpr.com, ISSN 2582-7421
  28. Chadaev K.R., Makarov A.S., Zubkov E.A. Vyyavlenie DEEPFAKE-kontenta na osnove ansamblya nejronnyh setej / Mater. 33-j nauchno-tekhn. konf. «Metody i tekhnicheskie sredstva obespecheniya bezopasnosti informacii» (24–27 iyunya 2024 g.). S. 66–68.
  29. Krundyshev V.M. Sistema upravleniya obnaruzheniem komp'yuternyh atak na baze nejro-nechetkoj logiki v kriticheskoj informacionnoj infrastrukture / Mater. 31-j nauchno-tekhn. konf. «Metody i tekhnicheskie sredstva obespecheniya bezopasnosti informacii» (27–30 iyunya 2022 g.). Sankt-Peterburg, ISSN 2305-994x. S. 38–39.
  30. Ot CNAPP do CTEM – IB-terminy prostymi slovami. Obzor. https://habr.com/ru/companies/mws/articles/864874/
Date of receipt: 31.07.2025
Approved after review: 11.08.2025
Accepted for publication: 29.08.2025