<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">kaz44</journal-id><journal-title-group><journal-title xml:lang="ru">Вестник Университета Шакарима. Серия технические науки</journal-title><trans-title-group xml:lang="en"><trans-title>Bulletin of Shakarim University. Technical Sciences</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">2788-7995</issn><issn pub-type="epub">3006-0524</issn><publisher><publisher-name>«Шәкәрім университеті» КеАҚ</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.53360/2788-7995-2026-1(21)-12</article-id><article-id custom-type="elpub" pub-id-type="custom">kaz44-2434</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>АВТОМАТИЗАЦИЯ И ИНФОРМАЦИОННЫЕ ТЕХНОЛОГИИ (ОРИГИНАЛЬНАЯ СТАТЬЯ)</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>AUTOMATION AND INFORMATION TECHNOLOGY (ORIGINAL ARTICLE)</subject></subj-group></article-categories><title-group><article-title>МНОГОВЕКТОРНЫЕ АТАКИ НА КИБЕРФИЗИЧЕСКИЕ СИСТЕМЫ: МЕХАНИЗМЫ, ОБНАРУЖЕНИЕ И ПРИМЕРЫ ЗАЩИТЫ</article-title><trans-title-group xml:lang="en"><trans-title>MULTI-VECTOR ATTACKS ON CYBER-PHYSICAL SYSTEMS: MECHANISMS, DETECTION, AND PROTECTION EXAMPLES</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0001-9324-9259</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Сагиндыков</surname><given-names>К. М.</given-names></name><name name-style="western" xml:lang="en"><surname>Sagindykov</surname><given-names>K. M.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Каким Молдабекович Сагиндыков – к.т.н., доцент кафедры «Информационная безопасность» </p><p>010008, г. Астана, ул. Сатпаева, 2</p></bio><bio xml:lang="en"><p>Kakim Moldabekovich Sagindykov – Candidate of Technical Sciences (Ph.D.), Associate Professor of the Department of Information Security </p><p>0100008, 2 Satpayev Street, Astana</p></bio><email xlink:type="simple">sagindykov_km@enu.kz</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0003-3315-798X</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Тебуева</surname><given-names>Ф. Б.</given-names></name><name name-style="western" xml:lang="en"><surname>Tebueva</surname><given-names>F. B.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Фариза Биляловна Тебуева – доктор ф-м.н, профессор кафедры вычислительной математики и кибернетики </p><p>355017, г. Ставрополь, ул. Пушкина, 1</p></bio><bio xml:lang="en"><p>Fariza Bilyalovna Tebuyeva – Doctor of Physical and Mathematical Sciences, Professor of the Department of Computational Mathematics and Cybernetics </p><p>355017, 1 Pushkina Street, Stavropol</p></bio><email xlink:type="simple">ftebueva@ncfu.ru</email><xref ref-type="aff" rid="aff-2"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0001-5015-3617</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Мукушева</surname><given-names>Н. Ж.</given-names></name><name name-style="western" xml:lang="en"><surname>Mukusheva</surname><given-names>N. Zh.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Назым Жумагельдыевна Мукушева – докторант кафедры «Информационная безопасность» </p><p>010008, г. Астана, ул. Сатпаева, 2</p></bio><bio xml:lang="en"><p>Nazym Zhumageldyevna Mukusheva – PhD student (Doctoral student) of the Department of Information Security </p><p>0100008, 2 Satpayev Street, Astana</p></bio><email xlink:type="simple">nazym9_1@mail.ru</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Евразийский национальный университет имени Л.Н. Гумилева</institution><country>Россия</country></aff><aff xml:lang="en"><institution>L.N. Gumilyov Eurasian National University</institution><country>Russian Federation</country></aff></aff-alternatives><aff-alternatives id="aff-2"><aff xml:lang="ru"><institution>Северо-Кавказский федеральный университет</institution><country>Россия</country></aff><aff xml:lang="en"><institution>North Caucasus Federal University</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>25</day><month>05</month><year>2026</year></pub-date><volume>1</volume><issue>1(21)</issue><fpage>110</fpage><lpage>118</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Сагиндыков К.М., Тебуева Ф.Б., Мукушева Н.Ж., 2026</copyright-statement><copyright-year>2026</copyright-year><copyright-holder xml:lang="ru">Сагиндыков К.М., Тебуева Ф.Б., Мукушева Н.Ж.</copyright-holder><copyright-holder xml:lang="en">Sagindykov K.M., Tebueva F.B., Mukusheva N.Z.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://tech.vestnik.shakarim.kz/jour/article/view/2434">https://tech.vestnik.shakarim.kz/jour/article/view/2434</self-uri><abstract><p>В статье представлен комплексный и углублённый обзор многовекторных кибератак, реализуемых в киберфизических системах (КФС). В ходе исследования подробно анализируются ключевые архитектурные предпосылки КФС, модели угроз на стыке информационных и операционных технологий (IT/OT), а также механизмы координации кибер- и физического воздействия. Систематизируются основные типы атак, включая внедрение ложных данных (FDI/FDIA), вредоносное программное обеспечение для промышленных систем управления и PLC, атаки на цепочки поставок (supply-chain), ransomware, атаки отказа в обслуживании (DoS), инсайдерские угрозы и прямое физическое вмешательство. Показаны их взаимосвязь и эффект усиления в рамках единого сценария компрометации. Опираясь на открытые научные исследования и отраслевые отчёты, рассматриваются кейсы Stuxnet, атаки на энергетическую инфраструктуру Украины, CrashOverride/Industroyer, TRITON/Trisis, а также инциденты ransomware в промышленной среде. Кроме того, предложена рискориентированная матрица, основанная на принципе «Тип атаки – уровень КФС». Описан практический пайплайн выявления аномалий с использованием корреляции IT/OT-событий и методов машинного обучения. Работа включает таблицы, схемы и графики, отражающие архитектуру КФС, жизненный цикл многовекторных операций, а также инженерные меры защиты в соответствии со стандартами СТ РК ISO/IEC 27001, NIST, ISA/IEC 62443 и MITRE ATT&amp;CK for ICS.</p></abstract><trans-abstract xml:lang="en"><p>The article presents a comprehensive and in-depth review of multi-vector cyberattacks implemented in cyber-physical systems (CPS). The study provides a detailed analysis of the key architectural prerequisites of CPS, threat models at the intersection of information technology and operational technology (IT/OT), as well as the mechanisms for coordinating cyber and physical impacts. The main types of attacks are systematized, including false data injection (FDI/FDIA), malware targeting industrial control systems and PLCs, supply-chain attacks, ransomware, denial-of-service (DoS) attacks, insider threats, and direct physical interference. Their interconnection and amplification effects within a unified compromise scenario are demonstrated. Based on open scientific studies and industry reports, the paper analyzes notable cases such as Stuxnet, cyberattacks on Ukraine’s energy infrastructure, CrashOverride/Industroyer, TRITON/Trisis, and ransomware incidents in industrial environments. In addition, a risk-oriented matrix based on the principle «Attack Type – CPS Layer» is proposed. A practical anomaly-detection pipeline using IT/OT event correlation and machine-learning methods is described. The work includes tables, diagrams, and graphs illustrating CPS architecture, the lifecycle of multivector operations, and engineering security measures aligned with the standards ST RK ISO/IEC 27001, NIST, ISA/IEC 62443, and MITRE ATT&amp;CK for ICS.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>многовекторные атаки</kwd><kwd>FDI</kwd><kwd>supply-chain</kwd><kwd>ransomware</kwd><kwd>TRITON</kwd><kwd>Industroyer</kwd><kwd>обнаружение аномалий</kwd></kwd-group><kwd-group xml:lang="en"><kwd>multi-vector attacks</kwd><kwd>FDI</kwd><kwd>supply-chain</kwd><kwd>ransomware</kwd><kwd>TRITON</kwd><kwd>Industroyer</kwd><kwd>anomaly detection</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Cyber-Physical Systems Security – A Survey / A. Humayed et al // IEEE Internet of Things Journal. – 2017. – Vol. 4, № 6. – P. 1802-1831. https://arxiv.org/abs/1701.04525.</mixed-citation><mixed-citation xml:lang="en">Cyber-Physical Systems Security – A Survey / A. Humayed et al // IEEE Internet of Things Journal. – 2017. – Vol. 4, № 6. – P. 1802-1831. https://arxiv.org/abs/1701.04525.</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Liu Y. False Data Injection Attacks against State Estimation in Electric Power Grids / Y. Liu, P. Ning, M.K. Reiter // Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS 2009). – New York: ACM, 2009. – P. 21-32.</mixed-citation><mixed-citation xml:lang="en">Liu Y. False Data Injection Attacks against State Estimation in Electric Power Grids / Y. Liu, P. Ning, M.K. Reiter // Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS 2009). – New York: ACM, 2009. – P. 21-32.</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">СТ РК ISO/IEC 27001-2023. Информационные технологии. Методы обеспечения безопасности. Системы менеджмента информационной безопасности. Требования. – Астана: Комитет технического регулирования и метрологии, 2023.</mixed-citation><mixed-citation xml:lang="en">СТ РК ISO/IEC 27001-2023. Информационные технологии. Методы обеспечения безопасности. Системы менеджмента информационной безопасности. Требования. – Астана: Комитет технического регулирования и метрологии, 2023.</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">NIST SP 800-82 Rev. 3. Guide to Operational Technology (OT) Security. – Gaithersburg: National Institute of Standards and Technology, 2023. https://doi.org/10.6028/NIST.SP.800-82r3.</mixed-citation><mixed-citation xml:lang="en">NIST SP 800-82 Rev. 3. Guide to Operational Technology (OT) Security. – Gaithersburg: National Institute of Standards and Technology, 2023. https://doi.org/10.6028/NIST.SP.800-82r3.</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">ISA/IEC 62443. Industrial Automation and Control Systems Security: Series of Standards. – Research Triangle Park: International Society of Automation, 2023. https://www.iec.ch/dyn/www/f?p=103:85:0::::FSP_LANG_ID:25 (дата обращения: 25.01.2026).</mixed-citation><mixed-citation xml:lang="en">ISA/IEC 62443. Industrial Automation and Control Systems Security: Series of Standards. – Research Triangle Park: International Society of Automation, 2023. https://www.iec.ch/dyn/www/f?p=103:85:0::::FSP_LANG_ID:25 (дата обращения: 25.01.2026).</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">MITRE ATT&amp;CK® Framework. Knowledge Base for Adversary Tactics and Techniques (ICS Domain). – Версия 18. – MITRE Corporation, 2025. https://attack.mitre.org (дата обращения: 25.01.2026).</mixed-citation><mixed-citation xml:lang="en">MITRE ATT&amp;CK® Framework. Knowledge Base for Adversary Tactics and Techniques (ICS Domain). – Версия 18. – MITRE Corporation, 2025. https://attack.mitre.org (дата обращения: 25.01.2026).</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Karnouskos S. Stuxnet Worm Impact on Industrial Cyber-Physical System Security / S. Karnouskos // Proceedings of the 37th Annual Conference of the IEEE Industrial Electronics Society. – Melbourne, 2011. – P. 4490-4494.</mixed-citation><mixed-citation xml:lang="en">Karnouskos S. Stuxnet Worm Impact on Industrial Cyber-Physical System Security / S. Karnouskos // Proceedings of the 37th Annual Conference of the IEEE Industrial Electronics Society. – Melbourne, 2011. – P. 4490-4494.</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Langner R. To Kill a Centrifuge: A Technical Analysis of What Stuxnet’s Creators Tried to Achieve. – Hamburg: The Langner Group, 2011. – 32 p.</mixed-citation><mixed-citation xml:lang="en">Langner R. To Kill a Centrifuge: A Technical Analysis of What Stuxnet’s Creators Tried to Achieve. – Hamburg: The Langner Group, 2011. – 32 p.</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">TRITON: How It Disrupted Safety Systems and Changed the Threat Landscape of Industrial Control Systems / А. Carcano еt al // Black Hat USA 2018 Proceedings. – Las Vegas, 2018.</mixed-citation><mixed-citation xml:lang="en">TRITON: How It Disrupted Safety Systems and Changed the Threat Landscape of Industrial Control Systems / А. Carcano еt al // Black Hat USA 2018 Proceedings. – Las Vegas, 2018.</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">CISA. MAR-17-352-01 HatMan (TRITON/TRISIS) – Safety System Targeted Malware (Update A). – Washington, DC: Cybersecurity and Infrastructure Security Agency, 2017. https://www.cisa.gov (дата обращения: 25.01.2026).</mixed-citation><mixed-citation xml:lang="en">CISA. MAR-17-352-01 HatMan (TRITON/TRISIS) – Safety System Targeted Malware (Update A). – Washington, DC: Cybersecurity and Infrastructure Security Agency, 2017. https://www.cisa.gov (дата обращения: 25.01.2026).</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Google Cloud Threat Intelligence. TRITON Threat Actor Profile and Detection Methods. – Google, 2023. https://cloud.google.com/security (дата обращения: 25.01.2026).</mixed-citation><mixed-citation xml:lang="en">Google Cloud Threat Intelligence. TRITON Threat Actor Profile and Detection Methods. – Google, 2023. https://cloud.google.com/security (дата обращения: 25.01.2026).</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Dragos Inc. CRASHOVERRIDE: Analysis of the Threat to Electric Grid Operations. – Hanover: Dragos, 2017.</mixed-citation><mixed-citation xml:lang="en">Dragos Inc. CRASHOVERRIDE: Analysis of the Threat to Electric Grid Operations. – Hanover: Dragos, 2017.</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">CISA. CrashOverride Malware Alert and Mitigations. – Washington, DC, 2017. https://www.cisa.gov (дата обращения: 25.01.2026).</mixed-citation><mixed-citation xml:lang="en">CISA. CrashOverride Malware Alert and Mitigations. – Washington, DC, 2017. https://www.cisa.gov (дата обращения: 25.01.2026).</mixed-citation></citation-alternatives></ref><ref id="cit14"><label>14</label><citation-alternatives><mixed-citation xml:lang="ru">ESET Research. Industroyer2: Industroyer Reloaded. – Bratislava: ESET, 2022. https://www.welivesecurity.com (дата обращения: 25.01.2026).</mixed-citation><mixed-citation xml:lang="en">ESET Research. Industroyer2: Industroyer Reloaded. – Bratislava: ESET, 2022. https://www.welivesecurity.com (дата обращения: 25.01.2026).</mixed-citation></citation-alternatives></ref><ref id="cit15"><label>15</label><citation-alternatives><mixed-citation xml:lang="ru">CISA. IR-ALERT-H-16-056-01: Cyber-Attack Against Ukrainian Critical Infrastructure. – Updated 20.07.2021. – Washington, DC. https://www.cisa.gov (дата обращения: 25.01.2026).</mixed-citation><mixed-citation xml:lang="en">CISA. IR-ALERT-H-16-056-01: Cyber-Attack Against Ukrainian Critical Infrastructure. – Updated 20.07.2021. – Washington, DC. https://www.cisa.gov (дата обращения: 25.01.2026).</mixed-citation></citation-alternatives></ref><ref id="cit16"><label>16</label><citation-alternatives><mixed-citation xml:lang="ru">SANS Institute, E-ISAC. Analysis of the Cyber Attack on the Ukrainian Power Grid. – Bethesda, 2016.</mixed-citation><mixed-citation xml:lang="en">SANS Institute, E-ISAC. Analysis of the Cyber Attack on the Ukrainian Power Grid. – Bethesda, 2016.</mixed-citation></citation-alternatives></ref><ref id="cit17"><label>17</label><citation-alternatives><mixed-citation xml:lang="ru">Tuptuk N. Security of Smart Manufacturing Systems / N. uptuk, S. Hailes // Journal of Manufacturing Systems. – 2018. – Vol. 47. – P. 93-106. https://doi.org/10.1016/j.jmsy.2018.04.007.</mixed-citation><mixed-citation xml:lang="en">Tuptuk N. Security of Smart Manufacturing Systems / N. uptuk, S. Hailes // Journal of Manufacturing Systems. – 2018. – Vol. 47. – P. 93-106. https://doi.org/10.1016/j.jmsy.2018.04.007.</mixed-citation></citation-alternatives></ref><ref id="cit18"><label>18</label><citation-alternatives><mixed-citation xml:lang="ru">Ransomware on Cyber-Physical Systems: Taxonomies, Case Studies, Security Gaps and Open Challenges / M. Benmalek et al // Computers &amp; Security. – 2023. – Vol. 124.</mixed-citation><mixed-citation xml:lang="en">Ransomware on Cyber-Physical Systems: Taxonomies, Case Studies, Security Gaps and Open Challenges / M. Benmalek et al // Computers &amp; Security. – 2023. – Vol. 124.</mixed-citation></citation-alternatives></ref><ref id="cit19"><label>19</label><citation-alternatives><mixed-citation xml:lang="ru">Securing the Industrial Internet of Things against Ransomware Attacks // Journal of Network and Computer Applications. – 2023. – Vol. 212.</mixed-citation><mixed-citation xml:lang="en">Securing the Industrial Internet of Things against Ransomware Attacks // Journal of Network and Computer Applications. – 2023. – Vol. 212.</mixed-citation></citation-alternatives></ref><ref id="cit20"><label>20</label><citation-alternatives><mixed-citation xml:lang="ru">False Data Injection Attack in Smart Grid CPS: Issues and Detection Algorithms // Computers &amp; Security. – 2023. – Vol. 122.</mixed-citation><mixed-citation xml:lang="en">False Data Injection Attack in Smart Grid CPS: Issues and Detection Algorithms // Computers &amp; Security. – 2023. – Vol. 122.</mixed-citation></citation-alternatives></ref><ref id="cit21"><label>21</label><citation-alternatives><mixed-citation xml:lang="ru">False Data Injection Attack in Smart Grid: Model and Detection Based on Deep Reinforcement Learning // Frontiers in Energy Research. – 2022. – Vol. 10.</mixed-citation><mixed-citation xml:lang="en">False Data Injection Attack in Smart Grid: Model and Detection Based on Deep Reinforcement Learning // Frontiers in Energy Research. – 2022. – Vol. 10.</mixed-citation></citation-alternatives></ref><ref id="cit22"><label>22</label><citation-alternatives><mixed-citation xml:lang="ru">ENIGMA: An Explainable Digital Twin Security Solution for Cyber-Physical Systems // Computers &amp; Security. – 2023. – Vol. 123.</mixed-citation><mixed-citation xml:lang="en">ENIGMA: An Explainable Digital Twin Security Solution for Cyber-Physical Systems // Computers &amp; Security. – 2023. – Vol. 123.</mixed-citation></citation-alternatives></ref><ref id="cit23"><label>23</label><citation-alternatives><mixed-citation xml:lang="ru">A Survey on Security-Enhancing Digital Twins: Models, Applications and Challenges // Computer Communications. – 2025. – Vol. 214.</mixed-citation><mixed-citation xml:lang="en">A Survey on Security-Enhancing Digital Twins: Models, Applications and Challenges // Computer Communications. – 2025. – Vol. 214.</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
