Please use this identifier to cite or link to this item:
https://er.chdtu.edu.ua/handle/ChSTU/10011| Title: | Mesh architectures and immune-inspired mechanisms in defending critical infrastructure |
| Other Titles: | Сітчасті архітектури та імунно-натхненні механізми у захисті критичної інфраструктури |
| Authors: | Semerenska, Viktoriia Семеренська, Вікторія |
| Keywords: | resilience;operational technology;distributed enforcement;segmentation;cyber resilience;digital twins;стійкість;операційні технології;розподілений контроль;сегментація;кіберстійкість;цифрові двійники |
| Issue Date: | 2026 |
| Publisher: | Вісник Черкаського державного технологічного університету |
| Abstract: | Critical infrastructure increasingly operates in interconnected, software-defined environments and is
simultaneously subject to targeted cyberattacks that disrupt key services. Traditional perimeter approaches
are proving insufficient as they allow attackers to remain in systems for long periods of time and leave
recovery mechanisms vulnerable. The article explored the applicability of the principles of mesh cybersecurity
architecture and digital immune systems, which have been developed in cloud environments, to the public
and industrial sectors. The aim of the study was to evaluate the transfer of mesh and immune approaches to
the water supply, energy, and municipal services sectors and to demonstrate their impact on resilience in real
incidents. The methodology combined a review of cloud security patterns, comparative case studies, and threat
scenario modeling. Two events were considered: a cyberattack on the municipal infrastructure of a large US city
and a transnational campaign against operational technologies in the water and gas sector. In the first case, the
lack of segmentation allowed the virus to spread unhindered between network segments, while in the second,
the lack of automated monitoring led to a delay in detecting the intrusion. For each event, the progression of
the attack was compared with control points where distributed control nodes, identity-based segmentation,
and feedback loops could limit the impact and initiate automated recovery. The results confirmed that mesh
combined with immune-like responses provided faster isolation, controlled degradation, and recovery based on
behavioral signals such as abnormal commands or configuration changes. Simulation modeling showed that
the average system recovery time was reduced by 35-40% in scenarios with a mesh architecture, and the spread
of the attack was limited to one segment instead of four. The practical value of this work lies in providing a
roadmap for the gradual improvement of monitoring systems without a complete redesign, which is useful for
operators of critical infrastructure and industrial enterprises. Критична інфраструктура дедалі більше функціонує у взаємопов’язаних, програмно-орієнтованих середовищах і водночас зазнає цілеспрямованих кібератак, що зупиняють ключові сервіси. Традиційні периметральні підходи виявляються недостатніми, оскільки дозволяють атакувальникам перебувати в системах тривалий час і залишають вразливими механізми відновлення. Метою дослідження було оцінювання перенесення mesh- та immune-підходів у сфери водопостачання, енергетики та муніципальних послуг і демонстрація їхнього впливу на стійкість у реальних інцидентах. Методологія поєднувала огляд шаблонів безпеки у хмарі, порівняльний аналіз кейсів та сценарне моделювання загроз. Було розглянуто дві події: кібератаку на муніципальну інфраструктуру великого міста США та транснаціональну кампанію проти операційних технологій у сфері води й газу. У першому випадку відсутність сегментації дозволила вірусу безперешкодно поширитися між мережевими сегментами, тоді як у другому брак автоматизованого моніторингу призвів до затримки у виявленні вторгнення. Для кожної події прогресія атаки була зіставлена з контрольними точками, де розподілені вузли контролю, сегментація на основі ідентичності та петлі зворотного зв’язку могли б обмежити наслідки та ініціювати автоматизоване відновлення. Отримані результати підтвердили, що mesh у поєднанні з імуноподібними реакціями забезпечував швидшу ізоляцію, контрольовану деградацію та відновлення на основі поведінкових сигналів, таких як аномальні команди чи зміни конфігурацій. Симуляційне моделювання показало, що середній час відновлення системи скорочувався на 35-40 % у сценаріях із сітчастою архітектурою, а поширення атаки обмежувалося одним сегментом замість чотирьох. Практична цінність роботи полягає у наданні дорожньої карти для поступового вдосконалення систем моніторингу без повного редизайну, що є корисним для операторів критичної інфраструктури та промислових підприємств. |
| URI: | https://er.chdtu.edu.ua/handle/ChSTU/10011 |
| ISSN: | 2306-4412 (print) 2708-6070 (online) |
| DOI: | https://doi.org/10.62660/bcstu/1.2026.118 |
| Volume: | 31 |
| Issue: | 1 |
| First Page: | 118 |
| End Page: | 127 |
| Appears in Collections: | том 31, №1/2026 |
Files in This Item:
| File | Description | Size | Format | |
|---|---|---|---|---|
| 11.pdf | 383.78 kB | Adobe PDF | ![]() View/Open | |
| зміст.pdf | 149.89 kB | Adobe PDF | ![]() View/Open | |
| титул.pdf | 283.8 kB | Adobe PDF | ![]() View/Open |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.


