Юлія Володимирівна КОСТЮК, Ellana Molchanova, Павло Миколайович СКЛАДАННИЙ, Volodymyr Sokolov, Karyna Khorolska · Information 2026 · 2026
DOI: 10.3390/info17100958
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
This paper proposes a semantically oriented knowledge-representation method for transforming primary cyber-event data into structured semantic knowledge to support explainable reasoning in cybersecurity decision-making. The core contribution is a transformation mechanism from primary semantic information (PSI) to secondary semantic information (SSI), based on a frame model of network events and attack patterns and followed by rule-based logical inference. This inference process maps semantic predicates to MITRE Adversarial Tactics, Techniques, and Common Knowledge (MITRE ATT&CK) techniques and reconstructs causal attack chains. The method is implemented within an Information-Semantic System (ISS) and integrated with explainable artificial intelligence (XAI), thereby ensuring that each decision can be traced to the rules and semantic relationships that produced it. Evaluation on the CICIDS2017 dataset, using a binary classification task (Normal vs. Attack), a stratified 60/20/20 train–validation–test split, and five experimental runs, yielded a precision of 0.94, a recall of 0.91, and an F1-score of 0.92. These results are comparable to those achieved by strong neural-network-based baselines, while the proposed method provides substantially greater interpretability and decision traceability. In two anonymised operational SOC/SIEM environments, the method reduced incident triage time by 22–38% and the false-positive rate by 18–34% compared with a baseline machine learning-only pipeline. The paper further examines transferability across additional datasets, presents ablation analyses, incorporates short-term-memory (STM)-based temporal context, and discusses explainability mechanisms and alignment with relevant cybersecurity standards.
No comments yet — start the discussion below.