OPTIMIZATION OF DATABASE PROTECTION MANAGEMENT PROCESSES AT CRITICAL INFRASTRUCTURE FACILITIES
DOI:
https://doi.org/10.31673/2409-7292.2026.028416Abstract
This paper addresses the problem of securing databases within information systems of critical infrastructure
facilities in Ukraine under conditions of increasing cyber threats and ongoing digital transformation of management
processes. An analysis of existing approaches to database protection is conducted, revealing the limitations of traditional
access control mechanisms based on static security policies. An approach to optimizing management processes for
database security is proposed, based on an adaptive risk assessment model for data access operations. A mathematical
model of an integrated risk indicator is developed, taking into account key security factors such as user privilege level,
SQL query type, access time, and volume of processed data. Based on the proposed model, a prototype system named
Adaptive Secure Database Management System (ASDBMS) is developed. The system is designed to provide automated
monitoring of database access and support decision-making processes in the field of information security. The architecture
of the system includes modules for access event collection, user behavior analysis, risk assessment, and decision support.
Experimental evaluation of the proposed approach demonstrates its effectiveness in detecting potentially malicious
database operations and improving the overall level of protection of critical information resources. The results of the
study can be applied to enhance information security management in government information systems, energy sector
infrastructures, telecommunications networks, and other critical infrastructure domains.
Keywords: database, critical infrastructure objects, models, modules, security, risks.
References
1. Закон України «Про основні засади забезпечення кібербезпеки України». №2163-VIII.
2. Гарасимчук О., Бужович О. Стратегії та інноваційні підходи до захисту баз даних в епоху зростаючих
кіберзагроз. Безпека iнформацii. 2024. DOI: 10.18372/2225-5036.30.18618.
3. Мануїлов Я. С. Забезпечення кібербезпеки об’єктів критичної інфраструктури в умовах кібервійни.
Інформація і право. 2023. DOI: https://doi.org/10.37750/2616-6798.2023.1(44).287780.
4. Ільєнко, А., Телющенко, В., Дубчак , О. (2025). Сучасні кіберзагрози критичної інфраструктури україни
та світу. Електронне фахове наукове видання «Кібербезпека: освіта, наука, техніка», 3(27), 150–164. https://doi.
org/10.28925/2663-4023.2023.27.719.
5. Будзинський О.В. (2025). Метод виявлення вразливостей та автоматизованого реагування в системах
захисту корпоративних баз даних.Сучасний захист інформації, 2(62), 180–186. DOI: 10.31673/2409-7292.2025.
029259, https://doi.org/10.31673/2409-7292.2025.029259180.
6. Щавінський, Ю., & Будзинський, О. (2025). Аналіз актуальних проблем безпеки корпоративних баз
даних в умовах сучасної інфраструктури та шляхи їх вирішення. Електронне фахове наукове видання
«Кібербезпека: освіта, наука, техніка», 3(27), 390–405. https://doi.org/10.28925/2663-4023.2025.27.726.
7. Казьмірук С.Д, Леонов Б.Д. Забезпечення кібербезпеки об’єктів критичної інфраструктури на основі
використання штучного інтелекту в умовах воєнного стану. Юридичний науковий електронний журнал. №
6/2024.- с. 201-206. DOI https://doi.org/10.32782/2524-0374/2024-6/49.
8. Антоненко Н. В., Граболюк М. С., Семенченко Н. О.(2021). Проблеми захисту інформації в сучасних
базах даних. Науковий вісник Полтавського університету економіки і торгівлі. Серія «Економічні науки». 2021.
Випуск № 2–1 (103), с.106–110. https://doi.org/10.37734/2409-6873-2021-2-18.
9. Гайдур Г. І., Гахов С. О., Скибун О. Ж. Оцінка стану кібербезпеки критичної інфраструктури з
використанням штучного інтелекту. Сучасний захист інформації. 2025. DOI: https://doi.org/10.31673/2409-
7292.2025.020831.
10. Легомінова, С. В., Щавінський, Ю. В., & Будзинський, О. В. (2024). Аналіз сучасних підходів до
забезпечення кібербезпеки корпоративних баз даних. Сучасний захист інформації, 2(58), 50–58.
https://doi.org/10.31673/2409-7292.2024.020006.
11. Bertino E., Sandhu R. Database security – concepts, approaches and challenges. IEEE Transactions on
Dependable and Secure Computing. 2005. Vol. 2, No. 1. P. 2–19. URL: https://doi.org/10.1109/TDSC.2005.9.
12. Hu V., Ferraiolo D., Kuhn D. Assessment of access control systems. NIST Special Publication 800-192. 2018.
URL: https://doi.org/10.6028/NIST.SP.800-192.
13. Sandhu R., Coyne E., Feinstein H., Youman C. Role-based access control models. IEEE Computer. 1996. Vol.
29. No. 2. P. 38–47. URL: https://doi.org/10.1109/2.485845.
14. Peltier T. Information Security Risk Analysis. Auerbach Publications, 2016.
15. ENISA. Securing critical infrastructures in the digital age. European Union Agency for Cybersecurity. 2022.
URL: https://www.enisa.europa.eu.
16. NIST Cybersecurity Framework Version 2.0. National Institute of Standards and Technology. 2024. URL:
https://www.nist.gov/cyberframework.
17. Scarfone K., Mell P. Guide to intrusion detection and prevention systems (IDPS). NIST Special Publication
800-94. 2007. URL: https://doi.org/10.6028/NIST.SP.800-94.
18. Garcia-Teodoro P., Diaz-Verdejo J., Macia-Fernandez G., Vazquez E. Anomaly-based network intrusion
detection: techniques, systems and challenges. Computers & Security. 2009. Vol. 28. P. 18–28. URL:
https://doi.org/10.1016/j.cose.2008.08.003.
19. Постанова КМУ України від 13 листопада 2025 р. № 1470 затверджено зміни постанови № 518
“Загальні вимоги до кіберзахисту об’єктів критичної інфраструктури (ОКІ).
20. Наказ Адміністрації Держспецзв’язку від 30.08.2023 №773 «Про затвердження Методичних
рекомендацій щодо підвищення рівня кіберзахисту систем електронного документообігу».
21. Держспецзв’язку та СБУ № 627/772 від 19 грудня 2024 року Нові рекомендації та форму плану захисту
від кіберзагроз для ОКІ.