<?xml version='1.0' encoding='UTF-8'?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN" "https://jats.nlm.nih.gov/publishing/1.2/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" article-type="research-article" xml:lang="ru" dtd-version="1.2">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">tis</journal-id>
      <journal-title-group><journal-title xml:lang="ru">Телекоммуникации и связь</journal-title><trans-title-group xml:lang="en"><trans-title>Telecommunications and Communications</trans-title></trans-title-group></journal-title-group>
      <issn pub-type="epub">3034-4050</issn>
      <publisher><publisher-name>ФГБУ «16 ЦНИИИ»</publisher-name></publisher>
    </journal-meta>
    <article-meta><article-id pub-id-type="doi">10.21681/3034-4050-2026-5-12-20</article-id><title-group><article-title xml:lang="ru">РАЗРАБОТКА МЕТОДОЛОГИИ АНАЛИЗА И ПОВЫШЕНИЯ СТРУКТУРНОЙ СКРЫТНОСТИ СЕТЕЙ ПЕРЕДАЧИ ДАННЫХ</article-title><trans-title-group xml:lang="en"><trans-title>DEVELOPMENT OF A METHODOLOGY FOR ANALYZING AND IMPROVING THE STRUCTURAL SECRECY OF DATA TRANSMISSION NETWORKS</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author"><name><surname>Слами</surname><given-names>Али Юсуф</given-names></name><contrib-id contrib-id-type="orcid">0009-0004-6819-2798</contrib-id><aff id="aff1"><institution xml:lang="ru">адъюнкт Военной академии связи им. Маршала Советского Союза С. М. Буденного. Санкт-Петербург, Российская Федерация. ORCID: 0009_0004_6819_2798.</institution><institution xml:lang="en">Adjunct of the Military Academy of Communications named after Marshal of the Soviet Union S. M. Budyonny. St. Petersburg, Russian Federation. ORCID: 0009_0004_6819_2798.</institution><country>Россия</country></aff><email>alisalame654@gmail.com</email></contrib></contrib-group><pub-date><year>2026</year></pub-date><issue>5 (14)</issue><fpage>12</fpage><lpage>20</lpage><self-uri content-type="pdf" xlink:href="../TiS_5_2026-12-20.pdf"/><abstract xml:lang="ru"><p>Цель работы: систематизация основных угроз информационной безопасности: перехват и анализ трафика, сканирование сети, компрометация паролей, подмена доверенного объекта и отказ в обслуживании.</p><p>Метод: анализ классификаций, обобщение демаскирующих признаков по уровням модели OSI.</p><p>Результат: выявлены и классифицированы демаскирующие признаки на физическом, канальном, сетевом, транспортном и прикладном уровнях. Установлено, что наиболее информативными для нарушителя являются сетевой и транспортный уровни (топология, временные паттерны трафика). Выявлено, что целевые атаки последнего десятилетия сместили фокус на критическую инфраструктуру, включая системы промышленной автоматизации. Предложенные методы маскирования информационного обмена позволяют разорвать связь между наблюдаемым трафиком и реальными технологическими процессами. В статье систематизированы основные угрозы информационной безопасности: перехват и анализ трафика, сканирование сети, компрометация паролей, подмена доверенного объекта и отказ в обслуживании. Особое внимание уделено APT- атакам, которые характеризуются многоэтапностью, длительным скрытым присутствием и нацеленностью на промышленные системы. Материалами исследования послужили открытые данные о компьютерных атаках за 1998–2025 гг., включая инциденты Stuxnet, NotPetya, TRITON и атаку на Colonial Pipeline. Результаты: выявлены и классифицированы демаскирующие признаки на физическом, канальном, сетевом, транспортном и прикладном уровнях. Установлено, что наиболее информативными для нарушителя являются сетевой и транспортный уровни (топология, временные паттерны трафика).</p><p>Научная новизна: разработаны комплексная вероятностно-временная модель оценки скрытности, методика формирования ложных портретов на основе генетических алгоритмов и количественный показатель структурной скрытности.</p><p>Практическая значимость: возможность количественной оценки защищенности сетей, выявления уязвимых элементов и реализации активных мер маскирования при проектировании защищенных систем передачи данных.</p></abstract><abstract xml:lang="en"><p>Goal: systematization of the main threats to information security: interception and analysis of traffic, network scanning, compromise of passwords, spoofing of a trusted object, and denial of service.</p><p>Method: analysis of classifications, generalization of unmasking features by levels of the OSI model.</p><p>Result: unmasking signs at the physical, channel, network, transport and application layers are identified and classified. It is established that the network and transport layers (topology, temporal traffic patterns) are the most informative for the attacker. It is revealed that targeted attacks of the last decade have shifted the focus to critical infrastructure, including industrial automation systems. The proposed methods of masking information exchange make it possible to break the connection between the observed traffic and real technological processes. Particular attention is paid to APT attacks, which are characterized by multi-stage, long-term covert presence, and targeting industrial systems. The study materials were based on open data on computer attacks for 1998–2025, including the Stuxnet, NotPetya, TRITON incidents, and the attack on the Colonial Pipeline. Results: unmasking signs at the physical, channel, network, transport, and application layers were identified and classified.</p><p>Scientific novelty : a complex probabilistic-temporal model for assessing stealth, a method for forming false portraits based on genetic algorithms and a quantitative indicator of structural secrecy have been developed.</p><p>Practical significance: the ability to quantify the security of networks, identify vulnerable elements and implement active masking measures in the design of secure data transmission systems.</p></abstract><kwd-group xml:lang="ru"><kwd>информационная безопасность</kwd><kwd>сеть передачи данных</kwd><kwd>целевые атаки (APT)</kwd><kwd>демаскирующие признаки</kwd><kwd>анализ сетевого трафика</kwd></kwd-group><kwd-group xml:lang="en"><kwd>information security</kwd><kwd>data transmission network</kwd><kwd>targeted attacks (APT)</kwd><kwd>unmasking signs</kwd><kwd>analysis of network traffic</kwd></kwd-group></article-meta></front>
  <back><ref-list><title>Список литературы</title><ref id="ref1"><label>1</label><mixed-citation>Privalov A. A., Laut O. S. Modelirovanie komp'yuternyh atak i narushitelya. – M.: Voenizdat, 2015. – 234 p.</mixed-citation></ref><ref id="ref2"><label>2</label><mixed-citation>Petrov P. P. Ugrozy informacionnoj bezopasnosti v voennyh setyah // Kiberbezopasnost'. – 2021. – No. 3. Pp. 45–52.</mixed-citation></ref><ref id="ref3"><label>3</label><mixed-citation>Sidorov S. S. Metody tehnicheskoj razvedki v kiberprostranstve. SPb.: Nauka, 2019.</mixed-citation></ref><ref id="ref4"><label>4</label><mixed-citation>Kuznecov K. K. Analiz setevogo trafika dlya vskrytiya struktury upravleniya // Voprosy zashchity informacii. – 2022. – No. 1. – Pp. 33–40.</mixed-citation></ref><ref id="ref5"><label>5</label><mixed-citation>Sokolov A. V. Teoreticheskie osnovy skrytnosti informacionnyh sistem. M.: Goryachaya liniya–Telekom, 2018.</mixed-citation></ref><ref id="ref6"><label>6</label><mixed-citation>Smith J., Brown T. Graph-based analysis of network security // Computer Networks. – 2019. – Vol. 158. – P. 1–15.</mixed-citation></ref><ref id="ref7"><label>7</label><mixed-citation>Garcia M. Vulnerability assessment of IP-based military networks // Military Communications Conference. – 2022. – Pp. 1–6.</mixed-citation></ref><ref id="ref8"><label>8</label><mixed-citation>Chen L. Rapid source detection in adversarial network environments // IEEE Transactions on Information Forensics and Security. – 2020. – Vol. 15. – Pp. 2345–2356.</mixed-citation></ref><ref id="ref9"><label>9</label><mixed-citation>Korneev G. A. Teoriya grafov v zadachah raspoznavaniya struktur. M.: Fizmatlit, 2017.</mixed-citation></ref><ref id="ref10"><label>10</label><mixed-citation>SpiderNet: Enabling Bot Identification in Network Topology Obfuscation Against Link Flooding Attacks // IEEE/ACM Transactions on Networking. – 2025. – Vol. 33. – No. 1. – Pp. 99–113.</mixed-citation></ref><ref id="ref11"><label>11</label><mixed-citation>WADCS: Weibull-attentive deep learning model for enhanced cyber security // Journal of King Saud University – Computer and Information Sciences. – 2025. – Vol. 37. – No. 1.</mixed-citation></ref><ref id="ref12"><label>12</label><mixed-citation>Stallings W. Cryptography and Network Security: Principles and Practice. 8th ed. New York: Pearson, 2020. – 832 p.</mixed-citation></ref></ref-list></back></article>
