V.A. Melnikov1, P.Yu. Pushkin2, A.A. Melnikova3, Yu.A. Konysheva4, D.S. Perevezentsev5, A.S. Grachev6
1 National University of Oil and Gas «Gubkin University» (Moscow, Russia)
2 FSUE NTC «Orion» (Moscow, Russia)
3 OOO «GK «Innotech» (Moscow, Russia)
4–6 RTU MIREA (Moscow, Russia)
1 melnikov.va@gubkin.ru, 2 pushkin@mirea.ru, 3 pershinaaa16@mail.ru, 4 konysheva@mirea.ru, 5 perevezentsev@mirea.ru, 6 grachyov@mirea.ru
The rapid advancement of digital technologies, the widespread adoption of Industry 4.0 and 5.0 concepts, and the growing dependence of critical infrastructures on information systems have significantly complicated the challenges of ensuring their security. Under these conditions, the detection of destructive actions and events capable of disrupting the stable operation of industrial, corporate, and distributed information systems acquires particular importance. The broad spectrum of existing research and the diversity of underlying methods and technologies necessitate a systematic review of the evolution of scientific approaches and their comparative analysis – from expert-based classifiers to hybrid architectures integrating machine learning, probabilistic models, and domain-specific knowledge.
This article aims to conduct a comprehensive analysis of contemporary approaches to destructive event detection, encompassing formal threat models, scenario-based and graph-based methods, statistical and clustering algorithms, deep learning techniques, domain-oriented solutions, as well as approaches related to event correlation, the robustness of detection systems, and attack attribution.
The paper examines the advantages and limitations of traditional formal threat models and expert classifiers, scenario-based, graph-based, statistical, and probabilistic models, deep learning methods, and hybrid architectures. Particular attention is given to the constraints of existing methods, challenges of interpretability, resistance to adversarial attacks, and the necessity of integrating heterogeneous data sources. The review emphasizes that no universal method for destructive event detection exists, and that the most promising direction lies in the development of adaptive hybrid systems capable of accounting for environment-specific characteristics and threat dynamics. The article demonstrates the potential of Markov Decision Processes (MDP) for detecting multi-step attacks in information systems. The practical significance of the work consists in substantiating the applicability of Markov Decision Processes as a foundation for developing adaptive detection systems targeting multi-step attacks.
The approaches to detecting destructive actions in information systems combine theoretical rigor and practical applicability, adapting detection strategies to dynamically changing threat conditions. Their functionality encompasses formal and probabilistic modeling, deep learning for pattern extraction, event correlation for multi-step attack analysis, and domain-specific adaptation for industrial and IoT environments. The presented analytical framework overcomes the limitations of static signature-based and scenario-based models, integrates with existing security management platforms, and enables interpretable forecasting of adversary behavior. As a result, the level of detection effectiveness and system resilience is significantly improved compared to isolated single-method approaches, with Markov decision processes emerging as the most promising foundation for adaptive and explainable destructive action detection systems.
Melnikov V.A., Pushkin P.Yu., Melnikova A.A., Konysheva Yu.A., Perevezentsev D.S., Grachev A.S. Approaches to detecting destructive actions and events in information systems // Highly Available Systems. 2026. V. 22. № 3. P. 112−125. DOI: https://doi.org/10.18127/j20729472-202603-10
- Tolkachev S.A. Kiberfizicheskie komponenty` povy`sheniya konkurentosposobnosti obrabaty`vayushhix otraslej promy`shlennosti. E`konomicheskoe vozrozhdenie Rossii. 2019. T. 3. № 61. S. 127–145. (in Russian).
- Lola I.S., Bakeev M.B. Cifrovaya transformaciya v otraslyax obrabaty`vayushhej promy`shlennosti Rossii: rezul`taty` kon``yunkturny`x obsledovanij. Vestnik Sankt-Peterburgskogo universiteta. E`konomika. 2019. T. 35. № 4. S. 628–657. (in Russian).
- Gladilina I.P., Litvenko I.Yu., Kiryuxina E.O. Sovremenny`e upravlencheskie texnologii i industriya 4.0. Finansovy`e ry`nki i banki. 2021. № 12. S. 21–23. (in Russian).
- Cichonski P., Millar T., Grance T., Scarfone K. Computer securityincident handling guide: Special publication 800–61. NIST: National Institute of Standards and Technology. 2012. 70 p.
- Stouffer K., Stouffer K., Zimmerman T., Tang C., Lubell J., Cichonski J., McCarthy J. Cybersecurity framework manufacturing profile. NISTIR 8183 Rev. 1. US Department of Commerce, National Institute of Standards and Technology, Gaithersburg, 2017. 57 p.
- Force J.T. Risk management framework for information systems and organizations Special publication 800–37 rev. 2. NIST Spec Publ 800:1–37. NIST: National Institute of Standards and Technology. 2018. 183 p.
- GOST R 59548–2022 Zashhita informacii. Registraciya soby`tij bezopasnosti. Trebovaniya k registriruemoj informacii. Oformlenie. FGBU «RST». 2022. 70 s. (in Russian).
- GOST R ISO/ME`K 27000–2021 Informacionny`e texnologii. Metody` i sredstva obespecheniya bezopasnosti. Sistemy` menedzhmenta informacionnoj bezopasnosti. Obshhij obzor i terminologiya. 2021. 28 s. (in Russian).
- ISO/IEC 27039:2015. Information technology – Security techniques – Selection, deployment and operations of intrusion detection systems (IDPS). ISO/IEC International Standards Organization. 2015. 48 p.
- Vlahakis G., Apostolou D., Kopanaki E. Enabling situation awareness with supply chain event management. Expert Systems with Applications. 2018. V. 93. P. 86–103.
- Kent K.A., Souppaya M. Guide to Computer Security Log Management: Recommendations of the National Institute of Standards and Technology. Special Publication 800–92. NIST special publication, 2006. 72 p.
- Kromkowski P., Li S., Zhao W., Abraham B., Osborne A., Brown D.E. Evaluating statistical models for network traffic anomaly detection. Proceedings of the 2019 Systems and Information Engineering Design Symposium (SIEDS). 2019. P. 1–6.
- Limmer T., Dressler F. Survey of event correlation techniques for attack detection in early warning systems. University of Erlangen, Dept. of Computer Science, Technical Report. 2008. 37 p.
- Dwivedi N., Tripathi A. Event correlation for intrusion detection systems. 2015 IEEE International Conference on Computational Intelligence & Communication Technology. 2015. P. 133–139.
- Cinque M., Della Corte R., Pecchia A. Contextual filtering and prioritization of computer application logs for security situational awareness. Future Generation Computer Systems. 2020. V. 111. P. 668–680.
- Kushwah D., Singh R.R., Tomar D.S. An approach to meta–alert generation for anomalous TCP traffic. Security and Privacy: Second ISEA International Conference, ISEA–ISAP 2018. Springer Singapore. 2018. P. 193–216.
- Nasir M., Muhammad K., Bellavista P., Lee M.Y., Sajjad M. Prioritization and alert fusion in distributed IoT sensors using kademlia based distributed hash tables. IEEE Access. 2020. V. 8. P. 175194–175204.
- Navarro J., Deruyver A., Parrend P. A systematic survey on multi–step attack detection. Computers & Security. 2018. V. 76. P. 214–249.
- Kotenko I.V., Xmy`rov S.S. Analiz modelej i metodik, ispol`zuemy`x dlya atribucii narushitelej kiberbezopasnosti pri realizacii celevy`x atak. Voprosy` kiberbezopasnosti. 2022. T. 4. № 50. S. 52–79. (in Russian).
- Li G., Nguyen T.H., Jung J.J. Traffic incident detection based on dynamic graph embedding in vehicular edge computing. Applied Sciences. 2021. V. 11. № 13. P. 5861.
- Marty`nov V.E., Selivanov S.G. Modelirovanie ugroz bezopasnosti dlya postroeniya kompleksnoj sistemy` zashhity` informacii na ob``ektax informatizacii. Voprosy` kiberbezopasnosti. 2021. № 5 (45). S. 2–15. (in Russian).
- Ivanov A.A., Petrov I.V. Modeli informacionnoj bezopasnosti. Informacionny`e texnologii i vy`chislitel`ny`e sistemy`. 2020. № 3. S. 45–58. (in Russian).
- Schneier B. Threat Modeling with Attack Trees. Dr. Dobb’s Journal. 1999. V. 24. № 12. P. 21–29.
- McQueen M., McQueen J., Boyer W., Flynn M. Attacker modeling and simulation for network security analysis. Proceedings of the 2006 Winter Simulation Conference. Monterey, CA, USA, 2006. P. 1741–1748.
- Kuzneczov D.A., Orlov A.S. Klassifikatory` destruktivny`x vozdejstvij v cifrovom prostranstve. Informacionnaya bezopasnost`. 2022. T. 28. № 4. S. 33–49. (in Russian).
- Kotenko I.V., Yusupov R.M. Aktual`ny`e ugrozy` i narushiteli informacionnoj bezopasnosti. Trudy` SPIIRAN. 2019. T. 18. № 2. S. 5–32. (in Russian).
- Sidorov A.A., Belyaev N.A. Destruktivnoe informacionnoe vozdejstvie v seti Internet: postanovka problemy`. Informacionnoe obshhestvo. 2020. № 6. S. 77–89. (in Russian).
- Saalbach H. Cyberwar: Threat Landscape and Strategic Challenges. Proceedings of the International Conference on Cyber Warfare. Saalbach, Austria. 2024. P. 1–25.
- Wang L., Zhu Q., Başar T. A Markov model of non-mutually exclusive cyber threats. IEEE Transactions on Information Forensics and Security. 2018. V. 13. № 11. P. 2735–2748.
- Canadian Centre for Cyber Security. National Cyber Threat Assessment 2025–2026. Ottawa: Communications Security Establishment Canada. 2024. 78 p.
- Jain A., Ross A. A taxonomy of threats to face recognition systems. IEEE Security & Privacy. 2019. V. 17. № 5. P. 40–48.
- Buczak A.L., Guven E. A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials. 2016. V. 18. № 2. P. 1153–1176.
- Golubev A.V., Semyonov K.V. Sravnenie sistemy` obnaruzheniya vtorzhenij na osnove mashinnogo obucheniya s signaturny`mi sredstvami zashhity` informacii. Informacionnaya bezopasnost` regionov. 2021. № 2. S. 91–104. (in Russian).
- Nasir M., Muhammad K., Bellavista P., Lee M.Y., Sajjad M. Intrusion detection system based on network behavior analysis. Journal of Network and Computer Applications. 2019. V. 145. P. 102–113.
- Aggarwal C.C., Sathe S. Statistical and density-based clustering techniques in the context of anomaly detection in network systems. ACM Computing Surveys. 2017. V. 50. № 3. P. 1–38.
- Yang Q., Liu Y., Chen T., Tong Y. Federated machine learning: Concept and applications. ACM Transactions on Intelligent Systems and Technology. 2019. V. 10. № 2. P. 1–19.
- Ferrag M.A., Maglaras L., Moschoyiannis S., Janicke H. Deep learning for cyber security intrusion detection: A comprehensive review. IEEE Access. 2020. V. 8. P. 177228–177252.
- Ahmed M., Mahmood A.N., Hu J. A survey of network anomaly detection techniques. Journal of Network and Computer Applications. 2016. V. 60. P. 19–31.
- Tang T.A., Mhamdi L., McLernon D., Zaidi S.A.R., Ghogho M. Deep learning approach for network intrusion detection in software-defined networking. IEEE Wireless Communications and Networking Conference (WCNC). 2018. P. 1–6.
- Zhang J., Zulkernine M. Anomaly based network intrusion detection with unsupervised outlier detection. Proceedings of the IEEE International Conference on Communications. 2006. P. 2388–2393.
- Yin C., Zhu Y., Fei J., He X. A deep learning approach for intrusion detection using recurrent neural networks. IEEE Access. 2017. V. 5. P. 21954–21961.
- Zhang W., Chen Q., Li J., Zhang Z. Anomaly detection in industrial IoT systems using autoencoder neural networks. IEEE Internet of Things Journal. 2020. V. 7. № 10. P. 9900–9912.
- Li Y., Wang S., Tian Y., Li J. Defending intrusion detection systems against adversarial attacks using denoising autoencoders. Computers & Security. 2021. V. 103. Article 102178.
- Biggio B., Roli F. Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognition. 2018. V. 84. P. 317–331.
- Hodo E., Bellekens X., Hamilton A., Tachtatzis C., Atkinson R. Threat analysis of IoT networks using artificial neural network intrusion detection system. IEEE World Forum on Internet of Things (WF-IoT). 2016. P. 1–6.
- Ferrag M.A., Maglaras L., Janicke H. Detection of distributed denial of service attacks using deep learning. Journal of Network and Computer Applications. 2018. V. 122. P. 1–15.
- Bradshaw S., Bailey H., Howard P.N. Industrialized disinformation: 2020 global inventory of organized social media manipulation. Computational Propaganda Research Project. Oxford University, 2020. 95 p.
- Savinov A.N. Razrabotka metodov i sredstv intellektual`noj obrabotki mul`timodal`ny`x danny`x iz seti Internet: diss. … kand. texn. nauk. M.: MGTU im. N.E`. Baumana. 2021. 168 s. (in Russian).
- Gusev A.V., Fyodorov A.A. Metodologiya sbora danny`x dlya analiza bezopasnosti promy`shlenny`x kiberfizicheskix system. Vestnik komp`yuterny`x i informacionny`x texnologij. 2021. № 10. S. 22–34. (in Russian).
- Romanov K.S., Abramov D.V. O kiberbezopasnosti sistem Interneta veshhej. Informacionnaya bezopasnost`. 2020. T. 26. № 3. S. 41–55. (in Russian).
- Smirnov P.N., Kozlov I.A. Obnaruzhenie nesankcionirovannogo vtorzheniya v besprovodny`e odnorangovy`e seti. Izvestiya vy`sshix uchebny`x zavedenij. Radioe`lektronika. 2019. T. 62. № 8. S. 489–501. (in Russian).
- Polyakov M.V., Ershov S.D. Realizaciya sistemy` obnaruzheniya vtorzhenij s ispol`zovaniem nejronnoj seti. Voprosy` zashhity` informacii. 2018. № 4. S. 58–67. (in Russian).
- Moustafa N., Slay J. UNSW-NB15: A comprehensive data set for network intrusion detection systems. Military Communications and Information Systems Conference (MilCIS). 2015. P. 1–6.
- Sergeev V.I., Klimov A.N. Protokoly` setevoj bezopasnosti: analiz sovremenny`x ugroz i metodov ix predotvrashheniya. Informacionny`e texnologii. 2019. T. 25. № 12. S. 720–731. (in Russian).
- Alcaraz C., Zeadally S. Critical infrastructure protection: Requirements and challenges for the 21st century. International Journal of Critical Infrastructure Protection. 2015. V. 8. P. 53–66.
- Abramov A.N., Il`in V.O. Obnaruzhenie priznakov anomal`nogo povedeniya trafika na osnove metodov iskusstvennogo intellekta. Programmny`e sistemy` i vy`chislitel`ny`e metody`. 2021. № 2. S. 44–59. (in Russian).
- Kirillov I.S., Lapin P.A. Razrabotka sistemy` obnaruzheniya vredonosnogo trafika dlya povy`sheniya kolichestva obnaruzhenny`x anomalij. Informacionnaya bezopasnost` regionov. 2020. № 3. S. 12–26. (in Russian).
- Nikolaev D.A., Orexov V.P. Obnaruzhenie incidentov informacionnoj bezopasnosti na osnove texnologii nejronny`x setej. Vestnik SibGUTI. 2019. № 1. S. 88–101. (in Russian).
- Kalinin R.M., Shubin A.V. Model` sistematizacii klassifikatorov destruktivny`x i konstruktivny`x vozdejstvij. Sistemy` upravleniya i informacionny`e texnologii. 2022. № 4. S. 97–110. (in Russian).
- Kotov I.E., Lebedev S.N. Klassifikatory` destruktivny`x vozdejstvij v cifrovom prostranstve. Informacionnoe pravo. 2021. № 2. S. 63–74. (in Russian).
- Aljawarneh S., Aldwairi M., Yassein M.B. Anomaly-based intrusion detection system through feature selection analysis and building hybrid efficient model. Journal of Computational Science. 2018. V. 25. P. 152–160.
- Zhang Y., Chen X., Li J. Security event analysis in sensor-based systems using deep learning. Sensors. 2022. V. 22. № 18. P. 6842.
- Golubev A.V., Sokolov N.N. Sostyazatel`noe testirovanie modelej mashinnogo obucheniya, prednaznachenny`x dlya obnaruzheniya SQL-in``ekcij. Voprosy` kiberbezopasnosti. 2021. № 6 (46). S. 31–45. (in Russian).
- Chen J., Yang X., Li Z. Data poisoning attacks and defenses in machine learning systems. Sensors. 2023. V. 23. № 9. P. 4185.
- Ivanov D.S., Petrov A.A. Reliability metrics for intelligent security monitoring systems. Journal of Systems and Software. 2022. V. 189. Article 111290.
- Kuz`min A.S., Vorob`yov P.A. Vliyanie ranzhirovaniya indikatorov atak na kachestvo modelej mashinnogo obucheniya v agentny`x sistemax neprery`vnoj autentifikacii. Informacionnaya bezopasnost`. 2022. T. 28. № 2. S. 14–29. (in Russian).
- Guidotti R., Monreale A., Ruggieri S., Turini F., Giannotti F., Pedreschi D. A survey of methods for explaining black box models. ACM Computing Surveys. 2019. V. 51. № 5. Article 93.
- Minaei-Bidgoli B., Grossklags J. Model of social influence in analysis of socio-engineering attacks. Computers & Security. 2018. V. 73. P. 89–103.
- Howard P.N., Woolley S., Bradshaw S. State-sponsored information operations in the digital age. International Journal of Communication. 2018. V. 12. P. 195–216.
- Ivanov V.G., Lebedev A.N. Problemy` protivodejstviya kiberprestupnosti v Rossijskoj Federacii. Zhurnal rossijskogo prava. 2020. № 11. S. 97–112.
- Behl A., Behl K. Cybersecurity and cyberwar: What everyone needs to know. Oxford University Press, Oxford. 2017. 296 p.
- Kumar R., Singh S., Kaur M. Cryptographic ransomware encryption detection: A survey. IEEE Access. 2022. V. 10. P. 112345–112370.
- Sharafaldin I., Lashkari A.H., Ghorbani A.A. Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP). 2018. P. 108–116.
- Tsai C.F., Hsu Y.F., Lin C.Y., Lin W.Y. Intrusion detection by machine learning: A review. Expert Systems with Applications. 2009. V. 36. № 10. P. 11994–12000.
- Zhou Y., Cheng G., Jiang S. Robustness evaluation of security monitoring systems under adversarial conditions. Journal of Information Security and Applications. 2023. V. 70. Article 103315.
- Sarker I.H. Deep learning-based intrusion detection systems: A systematic review. Applied Sciences. 2023. V. 13. № 15. P. 8794.
- Kumar S., Mishra A. Early warning systems for cyber threat detection. International Journal of Information Security Science. 2020. V. 9. № 3. P. 112–126.
- Chandola V., Banerjee A., Kumar V. Anomaly detection: A survey. ACM Computing Surveys. 2009. V. 41. № 3. Article 15.
- Satton R.S., Barto E`.Dzh. Obuchenie s podkrepleniem: vvedenie. 2-e izd. M.: DMK Press. 2020. 552 s.
- Mazengia D.H. Forecasting Spot Electricity Market Prices Using Time Series Models. Thesis for the degree of Master of Science in Electric Power Engineering. Gothenburg: Chalmers University of Technology. 2008. 89 p. [E`lektronny`j resurs]. Rezhim dostupa: https://arxiv.org/abs/2002.08957 (data obrashheniya: 11.02.2026).
- Podtopel`ny`j V.V. Issledovanie specifiki modelirovaniya komp`yuterny`x atak s ispol`zovaniem markovskix processov prinyatij reshenij i q-obucheniya. Informaciya i bezopasnost`. 2024. T. 27. Vy`p. 3. S. 421–441. (in Russian).

