INTEGRATED RISK ASSESSMENT MODEL FOR CYBER THREATS TO CRITICAL INFRASTRUCTURE
DOI:
https://doi.org/10.68302/std2026.vol1.134Keywords:
critical infrastructure, cybersecurity, hybrid threats, railway systemsAbstract
Critical infrastructure has become increasingly vulnerable to complex cyber threats characteristic of the contemporary hybrid security environment. The convergence of digital attacks, information operations, and potential physical disruptions necessitates integrated risk assessment approaches that capture both technological and operational dimensions of infrastructure systems. This study presents an integrated risk assessment model for cyber threats targeting critical infrastructure, combining artificial intelligence (AI) techniques with expert transport-system analysis, with a specific focus on railway infrastructure as a key component of national security. The proposed model comprises: (1) an AI-based anomaly detection module; (2) probabilistic hybrid-threat modeling; and (3) a transport-logistics resilience assessment. Simulation results demonstrate higher accuracy in risk prediction, earlier detection of critical deviations, and more effective planning of protective measures. The model supports identifying the most vulnerable infrastructure elements and developing adaptive response strategies.
Downloads
References
[1] ENISA, “Railway cybersecurity: Good practices and recommendations,” EU Agency for Cybersecurity, Heraklion, Greece, Tech. Rep., 2021. [Online]. Available: https://www.enisa.europa.eu. Accessed: Apr. 2026.
[2] UIC, “Cybersecurity for rail digital transformation,” Int. Union of Railways, Paris, France, Tech. Rep., 2020. [Online]. Available: https://uic.org. Accessed: Apr. 2026.
[3] A. Humayed, J. Lin, F. Li, and B. Luo, “Cyber-physical systems security—a survey,” IEEE Internet Things J., vol. 4, no. 6, pp. 1802–1831, 2017. https://doi.org/10.1109/JIOT.2017.2703172
[4] M. Cheminod, L. Durante, and A. Valenzano, “Review of security issues in industrial networks,” IEEE Trans. Ind. Inform., vol. 9, no. 1, pp. 277–293, 2013. https://doi.org/10.1109/TII.2012.2198666
[5] IMARC Group, “Railway Cyber Security Market: Global Industry Trends, Share, Size, Growth, Opportunity and Forecast 2026–2036,” IMARC Group, New York, Tech. Rep., 2024. [Online]. Available: https://www.imarcgroup.com/railway-cyber-security-market
[6] UniDatos Market Insights, “Railway Cybersecurity Market: Current Analysis and Forecast (2024–2032)” [Eisenbahn-Cybersecurity-Markt: Aktuelle Analyse und Prognose (2024–2032)], UniDatos, Tech. Rep., Apr. 2025. [Online]. Available: https://univdatos.com/de/reports/railway-cybersecurity-market. Accessed: Apr. 2026.
[7] M. Yilmaz et al., “Non-local attention enhanced deep learning for robust cyberattack detection in industrial IoT-based SCADA systems,” Scientific Reports, vol. 16, no. 1, 2026, Art. no. 37146, doi: 10.1038/s41598-026-37146-1.
[8] S. Karnouskos, "Stuxnet worm impact on industrial cyber-physical system security," in IECON 2011 - 37th Annual Conference of the IEEE Industrial Electronics Society, Melbourne, VIC, Australia, 2011, pp. 4490-4494, doi: 10.1109/IECON.2011.6120048.
[9] E. Luiijf, M. Klaver, and A. Nieuwenhuijs, “Empirical findings on critical infrastructure dependencies in Europe,” in Critical Information Infrastructure Security (CRITIS 2008, Lect. Notes Comput. Sci., vol. 5508), R. Setola and S. Geretshuber, Eds. Berlin: Springer, 2009, pp. 3–14. doi: 10.1007/978-3-642-03552-4_28
[10] U. Rahman, H. Ahmed, M. R. I. Khan, M. Saqlain, S. A. Siddiqui, and S. Akhtar, “Comprehensive cybersecurity risk assessment framework for industrial control systems (ICS) and SCADA environments: Identifying threats, vulnerabilities, and mitigation strategies,” Global Res. J. Nat. Sci. Technol., vol. 3, no. 3, pp. 134–153, 2025. https://doi.org/10.53762/grjnst.03.03.07
[11] W. K. Brotby and G. Hinson, PRAGMATIC Security Metrics: Applying Metametrics to Information Security. Boca Raton, FL: CRC Press/Auerbach Publications, 2013. ISBN 978-1-4398-8152-0. https://doi.org/10.1201/b14047
[12] M. M. Tuaama, “Security for Cyber-Physical Systems Using Machine Learning-Based Anomaly Detection: A Survey,” Zenodo [Preprint], 2024. doi: 10.5281/zenodo.13369313.
[13] DataGuard, “Risk Mitigation and Risk Minimization: Protection Against Cyber Threats” [Risk Mitigation & Risikominimierung: Schutz vor Cyberbedrohungen], DataGuard Blog, 2024. [Online]. Available: https://www.dataguard.de/blog/risk-mitigation-und-risikominimierung/. Accessed: Apr. 2026.
[14] Riskonnect, “The Role of Cybersecurity Risk Assessment Software in Mitigating Cyber Threats,” Riskonnect IT Risk Management Blog, 2024. [Online]. Available: https://riskonnect.com/it-risk-management/the-role-of-cybersecurity-risk-assessment-software-in-mitigating-cyber-threats/
[15] F. Flammini, Ed., Resilience of Cyber-Physical Systems: From Risk Modelling to Threat Counteraction. Cham, Switzerland: Springer International Publishing, 2019. doi: 10.1007/978-3-319-95597-1
[16] S. Rass, S. Schauer, S. König, and Q. Zhu, Cyber-Security in Critical Infrastructures: A Game-Theoretic Approach. Cham, Switzerland: Springer International Publishing, 2020. doi: 10.1007/978-3-030-46908-5
[17] A. Hahn, A. Ashok, S. Sridhar, and M. Govindarasu, “Cybersecurity testbeds for industrial control systems,” IEEE Security & Privacy, vol. 11, no. 4, pp. 36–44, 2013. doi: 10.1109/MSP.2013.49.
[18] C. Wang, N. Du, and H. Yang, “Generation and Analysis of Attack Graphs,” Procedia Eng., vol. 29, pp. 4053–4057, 2012. doi: 10.1016/j.proeng.2012.01.618
[19] Cyble, “Cyber Threats Surge Against Maritime Industry in 2025,” Cyble Research and Intelligence Labs, Jul. 2025. [Online]. Available: https://cyble.com/blog/cyberattacks-targets-maritime-industry/
[20] Industrial Cyber, “Hacktivists, nation-state hackers target global maritime infrastructure as cyberattacks, GPS spoofing surge,” Industrial Cyber, Jul. 2025. [Online]. Available: https://industrialcyber.co/transport/hacktivists-nation-state-hackers-target-global-maritime-infrastructure-as-cyberattacks-gps-spoofing-surge/
[21] CNN Business, “European air traffic control says attack by pro-Russian hackers not affecting flights,” CNN, Apr. 21, 2023. [Online]. Available: https://www.cnn.com/2023/04/21/business/eurocontrol-russia-hackers/
[22] EUROCONTROL, “Air Traffic Management: A Cybersecurity Challenge,” EUROCONTROL, Brussels, Belgium, Tech. Rep., Dec. 2021. [Online]. Available: https://www.eurocontrol.int/sites/default/files/2021-12/eurocontrol-atm-cybersecurity-report.pdf. Accessed: Apr. 2026.
[23] P. Marks, “Russia hacked an American satellite company one hour before the Ukraine invasion,” MIT Technology Review, May 10, 2022. [Online]. Available: https://www.technologyreview.com/2022/05/10/1051973/russia-hack-viasat-satellite-ukraine-invasion/
[24] SEC Consult, “Cyber Threats to Public Charging Infrastructure: Risks and Protective Measures Through Penetration Testing” [Cyber-Bedrohungen für die öffentliche Ladeinfrastruktur: Risiken und Schutzmaßnahmen durch Penetrationstests], SEC Consult Blog, Jan. 2025. [Online]. Available: https://sec-consult.com/de/blog/detail/cyber-bedrohungen-fuer-die-oeffentliche-ladeinfrastruktur-risiken-und-schutzmassnahmen-durch-penetrationstests/. Accessed: Apr. 2026.
[25] M. Ghafouri et al., “Online Recursive Detection and Adaptive Fuzzy Mitigation of Cyber-Physical Attacks Targeting Topology of IMG: An LFC Case Study,” IEEE Trans. Smart Grid, vol. 15, no. 2, pp. 2129–2145, Mar. 2024. doi: 10.1109/TSG.2023.3304537
[26] М. Maranco et al., “Cyber Security for Intelligent Transportation Systems Protecting Critical Infrastructure,” in Urban Mobility and Challenges of Intelligent Transportation Systems, K. Bellam et al., Eds. IGI Global Scientific Publishing, 2025, pp. 403–420. doi: 10.4018/979-8-3693-7984-4.ch022
[27] N. Ibadah, C. Benavente-Peces, and M.-O. Pahl, “Securing the future of railway systems: A comprehensive cybersecurity strategy for critical on-board and track-side infrastructure,” Sensors, vol. 24, Art. no. 8218, Dec. 2024. https://doi.org/10.3390/s24248218
[28] E. Pencheva, I. Atanasov, and V. Trifonov, “Identity Management in Future Railway Mobile Communication System,” Appl. Sci., vol. 12, no. 9, Art. no. 4293, Apr. 2022. [Online]. Available: https://doi.org/10.3390/app12094293
[29] H. Hindy et al., "A Taxonomy of Network Threats and the Effect of Current Datasets on Intrusion Detection Systems," IEEE Access, vol. 8, pp. 104650-104675, 2020, doi: 10.1109/ACCESS.2020.3000179
[30] Z. Wang et al., “Explaining the Attributes of a Deep Learning Based Intrusion Detection System for Industrial Control Networks,” Sensors, vol. 20, no. 14, Art. no. 3817, 2020. doi: 10.3390/s20143817
[31] D. Dimitrov and I. Manchev, “Methodological and technical aspects of models for digital management of transport systems,” Environment. Technology. Resources, vol. 1, pp. 39–44, 2024. https://doi.org/10.17770/etr2024vol2.8049
[32] I. S. Stankov, A. P. Aleksieva-Petrova, and G. K. Hristov, “CyberAttacks and Artificial Intelligence: A Systematic Mapping,” in Proc. 2023 Intl. Scientific Conf. on Computer Science (COMSCI), Sozopol, Bulgaria, Nov. 2023, pp. 1–7. doi: 10.1109/COMSCI59259.2023.10315929
[33] Z. Wang and X. Liu, “Cyber security of railway cyber-physical system (CPS) – A risk management methodology,” Communications in Transportation Research, vol. 2, 2022, Art. no. 100078. doi: 10.1016/j.commtr.2022.100078
[34] D. Dimitrov, P. Zlateva, and D. Velev, “A methodology for designing an information system for road infrastructure monitoring,” IOP Conf. Ser.: Earth Environ. Sci., vol. 167, no. 1, Art. no. 012044, 2018. https://doi.org/10.1088/1755-1315/167/1/012044
[35] S. M. Ali, A. Razzaque, H. Abbass, M. Yousaf, and S. S. Ali, “A novel AI-based integrated cybersecurity risk assessment framework and resilience of national critical infrastructure,” IEEE Access, Early Access, 2024. https://doi.org/10.1109/ACCESS.2024.3524884
[36] “Public Transport Act” [Закон за обществения транспорт], State Gazette (D.V.), no. 32, 2026. [Online]. Available: https://dv.parliament.bg/DVWeb/showMaterialDV.jsp?idMat=242220. Accessed: Apr. 2026.
[37] European Parliament and Council of the EU, “Directive (EU) 2022/2555 (NIS 2 Directive),” Official Journal of the EU, L 333, pp. 80–152, Dec. 2022. [Online]. Available: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
[38] “Cybersecurity Act (2018), as amended in State Gazette no. 17, 13 Feb. 2026” [Закон за киберсигурността (2018), изм. и доп. ДВ бр. 17 от 13 февруари 2026 г.]. [Online]. Available: https://dv.parliament.bg/DVWeb/showMaterialDV.jsp?idMat=241234. Accessed: Apr. 2026.
[39] D. Abshari and M. Sridhar, “A survey of anomaly detection in cyber-physical systems,” submitted for publication, 2025.
[40] D. Bhamare et al., “Cybersecurity for industrial control systems: A survey,” Comput. Secur., vol. 89, Art. no. 101677, Feb. 2020. doi: 10.1016/j.cose.2019.101677
[41] M. Ibrahim et al., “Attack Graph Implementation and Visualization for Cyber Physical Systems,” Processes, vol. 8, Art. no. 12, 2020. doi: 10.3390/pr8010012
[42] A. A. Dosunmu and P. O. Ogundele, “Integrated threat intelligence automation and simulation models for next generation cyber defense,” Engineering and Technology Journal, vol. 11, no. 1, pp. 8451–8462, 2026. https://doi.org/10.47191/etj/v11i01.05
[43] B. S. Ntsiepdjap, “Dynamic risk assessment for critical infrastructures under attack,” Int. J. Adv. Res., vol. 10, no. 9, pp. 868–908, 2022. https://doi.org/10.21474/IJAR01/15433
[44] D. Dimitrov and K. Lalov, “Intelligent rail transport management systems—methodological essence, goals and tasks,” Environment. Technology. Resources, vol. 2, pp. 33–38, 2024. https://doi.org/10.17770/etr2024vol2.8050
[45] S. Gatlan, “Cyber Partisans hacktivists claim credit for cyberattack on Belarusian Railways,” The Record from Recorded Future News, Jan. 24, 2022. [Online]. Available: https://therecord.media/cyber-partisans-hacktivists-claim-credit-for-cyberattack-on-belarusian-railways
[46] T. Starks, “Belarusian hacktivist group attacks Belarusian Railways as military frictions mount,” CyberScoop, Jan. 24, 2022. [Online]. Available: https://cyberscoop.com/cyber-partisans-belarus-russia-ukraine/
[47] Y. Pan and Q. Yang, “A survey on transfer learning,” IEEE Trans. Knowl. Data Eng., vol. 22, no. 10, pp. 1345–1359, 2010. https://doi.org/10.1109/TKDE.2009.191
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Irena Petrova, Kostadin Trifonov

This work is licensed under a Creative Commons Attribution 4.0 International License.