<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">kaz29</journal-id><journal-title-group><journal-title xml:lang="ru">Вестник Казахстанско-Британского технического университета</journal-title><trans-title-group xml:lang="en"><trans-title>Herald of the Kazakh-British Technical University</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">1998-6688</issn><issn pub-type="epub">2959-8109</issn><publisher><publisher-name>Казахстанско-Британский Технический Университет</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.55452/1998-6688-2026-23-3-144-159</article-id><article-id custom-type="elpub" pub-id-type="custom">kaz29-3181</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>КОМПЬЮТЕРНЫЕ НАУКИ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>COMPUTER SCIENCE</subject></subj-group></article-categories><title-group><article-title>ГИБРИДНАЯ ИНТЕЛЛЕКТУАЛЬНАЯ СИСТЕМА ПОДДЕРЖКИ ПРИНЯТИЯ РЕШЕНИЙ ДЛЯ ОЦЕНКИ КИБЕРРИСКОВ И ВЫБОРА ЗАЩИТНЫХ МЕР</article-title><trans-title-group xml:lang="en"><trans-title>HYBRID INTELLIGENT DECISION-SUPPORT SYSTEM FOR CYBERSECURITY RISK ASSESSMENT AND SECURITY ACTION SELECTION</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0009-3180-2990</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Амирбаева</surname><given-names>А. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Amirbayeva</surname><given-names>A.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Магистрант</p><p>Алматы</p></bio><bio xml:lang="en"><p>Master’s</p><p>Almaty</p></bio><email xlink:type="simple">adinaxanova2@gmail.com</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Казахстанско-Британский технический университет</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Kazakh-British Technical University</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>25</day><month>09</month><year>2026</year></pub-date><volume>23</volume><issue>3</issue><fpage>144</fpage><lpage>159</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Амирбаева А.А., 2026</copyright-statement><copyright-year>2026</copyright-year><copyright-holder xml:lang="ru">Амирбаева А.А.</copyright-holder><copyright-holder xml:lang="en">Amirbayeva A.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://vestnik.kbtu.edu.kz/jour/article/view/3181">https://vestnik.kbtu.edu.kz/jour/article/view/3181</self-uri><abstract><p>Выбор подходящих систем информационной безопасности представляет собой сложную задачу, зави­сящую от организационных рисков, характеристик инфраструктуры, киберугроз и нормативных требований. Традиционные подходы, основанные на экспертной оценке и ручном анализе, часто обладают ограниченной адаптивностью и масштабируемостью. В данной работе предлагается гибридная интеллектуальная система поддержки принятия решений, объединяющая нечеткую логику, машинное обучение и стандарты ISO в области информационной безопасности. Модуль нечеткого вывода выполняет оценку риска в условиях неопределенности с использованием параметров частоты атак, уровня уязвимости и эффективности защиты. На основе вычисленного уровня риска система формирует рекомендации по реагированию в соответствии с международными стандартами ISO/IEC. Дополнительно используется модель Random Forest для оценки эффективности выбранных мер защиты. Экспериментальные результаты показали высокую точность и адаптивность предложенной архитектуры.</p></abstract><trans-abstract xml:lang="en"><p>Selecting appropriate information security systems is a complex task influenced by organizational risks, infrastructure characteristics, evolving cyber threats, and regulatory requirements. Traditional approaches based on manual analysis and expert judgment often lack adaptability, scalability, and consistency in dynamic cybersecurity environments. This study proposes a hybrid intelligent decision-support system that combines fuzzy logic, machine learning, and ISO-based cybersecurity standards for risk assessment and security action recommendation. The fuzzy inference module evaluates cybersecurity events under uncertainty using parameters such as attack frequency, vulnerability level, and defense efficiency. Based on the calculated risk level, the system generates standardized response actions aligned with international ISO/IEC standards. In addition, a Random Forest machine learning model is used to evaluate whether the selected actions are likely to mitigate the attack successfully. Experimental evaluation performed on a synthetic dataset demonstrated that the proposed hybrid architecture achieves high predictive performance and improves both interpretability and adaptability of cybersecurity decision support systems in complex operational environments.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>кибербезопасность</kwd><kwd>нечеткая логика</kwd><kwd>машинное обучение</kwd><kwd>оценка риска</kwd><kwd>системы поддержки принятия решений</kwd><kwd>информационная безопасность</kwd></kwd-group><kwd-group xml:lang="en"><kwd>cybersecurity</kwd><kwd>decision support systems</kwd><kwd>fuzzy logic</kwd><kwd>machine learning</kwd><kwd>risk assessment</kwd><kwd>information security</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Apruzzese, G., et al. The Role of Machine Learning in Cybersecurity. Digital Threats: Research and Practice, 4 (1), 1–38 (2022). https://doi.org/10.1145/3545574</mixed-citation><mixed-citation xml:lang="en">Apruzzese, G., et al. The Role of Machine Learning in Cybersecurity. Digital Threats: Research and Practice, 4 (1), 1–38 (2022). https://doi.org/10.1145/3545574</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Kerimkhulle, S., et al. Fuzzy Logic and Its Application in the Assessment of Information Security Risk of Industrial Internet of Things. Symmetry, 15 (10), 1958 (2023). https://doi.org/10.3390/sym15101958</mixed-citation><mixed-citation xml:lang="en">Kerimkhulle, S., et al. Fuzzy Logic and Its Application in the Assessment of Information Security Risk of Industrial Internet of Things. Symmetry, 15 (10), 1958 (2023). https://doi.org/10.3390/sym15101958</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Merola, F., Bernardeschi, C., Lami, G. A Risk Assessment Framework Based on Fuzzy Logic for Automotive Systems. Safety, 10 (2), 41 (2024). https://doi.org/10.3390/safety10020041</mixed-citation><mixed-citation xml:lang="en">Merola, F., Bernardeschi, C., Lami, G. A Risk Assessment Framework Based on Fuzzy Logic for Automotive Systems. Safety, 10 (2), 41 (2024). https://doi.org/10.3390/safety10020041</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Soori, M., et al. AI-Based Decision Support Systems in Industry 4.0: A Review. Journal of Economy and Technology, 4, 206–225 (2024). https://doi.org/10.1016/j.ject.2024.08.005</mixed-citation><mixed-citation xml:lang="en">Soori, M., et al. AI-Based Decision Support Systems in Industry 4.0: A Review. Journal of Economy and Technology, 4, 206–225 (2024). https://doi.org/10.1016/j.ject.2024.08.005</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Singer, P., Friedman, A. Cybersecurity and Cyberwar: What Everyone Needs to Know. Oxford University Press (2014). https://doi.org/10.1093/wentk/9780199918096.001.0001</mixed-citation><mixed-citation xml:lang="en">Singer, P., Friedman, A. Cybersecurity and Cyberwar: What Everyone Needs to Know. Oxford University Press (2014). https://doi.org/10.1093/wentk/9780199918096.001.0001</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Peltier, T.R. Information Security Policies, Procedures, and Standards. CRC Press (2021).</mixed-citation><mixed-citation xml:lang="en">Peltier, T.R. Information Security Policies, Procedures, and Standards. CRC Press (2021).</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Ahmed, M., Mahmood, A., Hu, J. A Survey of Network Anomaly Detection Techniques. Journal of Network and Computer Applications, 60, 19–31 (2015). https://doi.org/10.1016/j.jnca.2015.11.016</mixed-citation><mixed-citation xml:lang="en">Ahmed, M., Mahmood, A., Hu, J. A Survey of Network Anomaly Detection Techniques. Journal of Network and Computer Applications, 60, 19–31 (2015). https://doi.org/10.1016/j.jnca.2015.11.016</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Wang, M., et al. Machine Learning for Networking: Workflow, Advances and Opportunities. IEEE Network, 32 (2), 92–99 (2018). https://doi.org/10.1109/MNET.2017.1700200</mixed-citation><mixed-citation xml:lang="en">Wang, M., et al. Machine Learning for Networking: Workflow, Advances and Opportunities. IEEE Network, 32 (2), 92–99 (2018). https://doi.org/10.1109/MNET.2017.1700200</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Ludonga, A., Singo, S. Systematic Review Cyber Risk Management: Frameworks, Strategies, and Case Studies in Cybersecurity (2025). https://doi.org/10.5281/zenodo.17372361</mixed-citation><mixed-citation xml:lang="en">Ludonga, A., Singo, S. Systematic Review Cyber Risk Management: Frameworks, Strategies, and Case Studies in Cybersecurity (2025). https://doi.org/10.5281/zenodo.17372361</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Zadeh, L.A. Fuzzy Sets. Information and Control, 8 (3), 338–353 (1965). https://doi.org/10.1016/S0019-9958(65)90241-X</mixed-citation><mixed-citation xml:lang="en">Zadeh, L.A. Fuzzy Sets. Information and Control, 8 (3), 338–353 (1965). https://doi.org/10.1016/S0019-9958(65)90241-X</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">ISO/IEC 27001:2022 Information Security Management Systems (2022). https://www.iso.org/standard/27001</mixed-citation><mixed-citation xml:lang="en">ISO/IEC 27001:2022 Information Security Management Systems (2022). https://www.iso.org/standard/27001</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Tukaram, L. Deep Learning in Cybersecurity: Applications, Challenges, and Future Prospects. International Journal of Innovations in Science Engineering and Management, 4 (2), 27–33 (2025). https://doi.org/10.69968/ijisem.2025v4i227-33</mixed-citation><mixed-citation xml:lang="en">Tukaram, L. Deep Learning in Cybersecurity: Applications, Challenges, and Future Prospects. International Journal of Innovations in Science Engineering and Management, 4 (2), 27–33 (2025). https://doi.org/10.69968/ijisem.2025v4i227-33</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
