<?xml version="1.0" encoding="UTF-8"?><xml><records><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">George Sharkov</style></author><author><style face="normal" font="default" size="100%">Wim Mees</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Enhanced Collaboration for Cyber Security and Resilience</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">artificial intelligence</style></keyword><keyword><style  face="normal" font="default" size="100%">Collaborative Network Organization</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber digital skills</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber range</style></keyword><keyword><style  face="normal" font="default" size="100%">digital transformation</style></keyword><keyword><style  face="normal" font="default" size="100%">ECHO project</style></keyword><keyword><style  face="normal" font="default" size="100%">human factor</style></keyword><keyword><style  face="normal" font="default" size="100%">privacy</style></keyword><keyword><style  face="normal" font="default" size="100%">Situational awareness</style></keyword><keyword><style  face="normal" font="default" size="100%">threat intelligence</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2022</style></year></dates><volume><style face="normal" font="default" size="100%">53</style></volume><pages><style face="normal" font="default" size="100%">7-8</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">This editorial article introduces the structure and content of articles accepted for presentation at the Fourth International Scientific Conference “Digital Transformation, Cyber Security and Resilience, DIGILIENCE 2022. The volume includes articles presenting results on six particular topics: Advanced Threat Intelligence and Information Sharing; Digitalization and Privacy Preservation; Governing Cybersecurity Networks and Ecosystems; Developing Critical Cyber Skills; Human Factors for Safety and Resilience to Cyber/Hybrid Influence; and Cyber Ranges, Simulation and Training.</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue><section><style face="normal" font="default" size="100%">7</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Todor Tagarev</style></author><author><style face="normal" font="default" size="100%">Nikolai Stoianov</style></author><author><style face="normal" font="default" size="100%">George Sharkov</style></author><author><style face="normal" font="default" size="100%">Yantsislav Yanakiev</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">AI-driven Cybersecurity Solutions, Cyber Ranges for Education &amp; Training, and ICT Applications for Military Purposes</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">artificial intelligence</style></keyword><keyword><style  face="normal" font="default" size="100%">collaborative network organisation</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber range</style></keyword><keyword><style  face="normal" font="default" size="100%">cybersecurity ethics</style></keyword><keyword><style  face="normal" font="default" size="100%">digital transformation</style></keyword><keyword><style  face="normal" font="default" size="100%">ECHO project</style></keyword><keyword><style  face="normal" font="default" size="100%">human factors</style></keyword><keyword><style  face="normal" font="default" size="100%">intrusion detection</style></keyword><keyword><style  face="normal" font="default" size="100%">Situational awareness</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2021</style></year></dates><volume><style face="normal" font="default" size="100%">50</style></volume><pages><style face="normal" font="default" size="100%">5-8</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">This editorial article introduces the reader to the Third International Scientific Conference “Digital Transformation, Cyber Security and Resilience,” DIGILIENCE 2021, and summarises the results from four of its sessions: AI-driven Cybersecurity Solutions; Organisational and Ethical Considerations in Providing Cybersecurity; Cyber Ranges for Innovative Education &amp; Training; and Advanced ICT Solutions with Military Applications.</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Nikolai Stoianov</style></author><author><style face="normal" font="default" size="100%">Maya Bozhilova</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">A Model of a Cyber Defence Awareness System of Campaigns with Malicious Information</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Cyber defence</style></keyword><keyword><style  face="normal" font="default" size="100%">CyRADARS</style></keyword><keyword><style  face="normal" font="default" size="100%">malicious information</style></keyword><keyword><style  face="normal" font="default" size="100%">Situational awareness</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2020</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2020</style></date></pub-dates></dates><volume><style face="normal" font="default" size="100%">46</style></volume><pages><style face="normal" font="default" size="100%">182-197</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">Many organizations experience cyberattacks with the aim of the dissemination of malicious information. Situational awareness is a tool to counteract the campaigns of malicious information and reduce its dissemination. This article proposes a conceptual model for a cyber defence awareness system, which aims to support human operators to avoid this type of threat. The system will identify (classify) three campaign types of malicious information operations – malicious information injections in web content, malicious information injections in fake social network accounts, and malicious information dissemination via email messages. A model for identification of the type of campaign of malicious information operations based on Dempster-Shafer evidence theory is proposed. The work presented here is a part of the Cyber Rapid Analysis for Defence Awareness of Real-time Situation - CyRADARS project.</style></abstract><issue><style face="normal" font="default" size="100%">2</style></issue><section><style face="normal" font="default" size="100%">182</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">George Sharkov</style></author><author><style face="normal" font="default" size="100%">Yavor Papazov</style></author><author><style face="normal" font="default" size="100%">Christina Todorova</style></author><author><style face="normal" font="default" size="100%">Georgi Koykov</style></author><author><style face="normal" font="default" size="100%">Georgi Zahariev</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">MonSys: A Scalable Platform for Monitoring Digital Services Availability, Threat Intelligence and Cyber Resilience Situational Awareness</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">cyber risk</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber threat</style></keyword><keyword><style  face="normal" font="default" size="100%">early warning</style></keyword><keyword><style  face="normal" font="default" size="100%">resilience</style></keyword><keyword><style  face="normal" font="default" size="100%">scalability</style></keyword><keyword><style  face="normal" font="default" size="100%">Situational awareness</style></keyword><keyword><style  face="normal" font="default" size="100%">vulnerability analysis</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2020</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2020</style></date></pub-dates></dates><volume><style face="normal" font="default" size="100%">46</style></volume><pages><style face="normal" font="default" size="100%">155-167</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">Today’s digital society implies interconnectivity between the online operations of different sectors of everyday life and economy alike. As a consequence, malicious activities targeted towards a single online service could hurt entire indus¬tries and multiple private and public organizations. This interdependence be¬tween online services and economic units is an imperative for targeted efforts ensuring the integrity and availability of individual systems and complex systems-of-systems alike. This article presents MonSys, a flexible, robust, and scalable monitoring platform, implement-ed as a cloud-based service and an on-premise solution, specifically de-signed to ad¬dress the need for ensuring service availability at an individual level. MonSys provides several standardized services availability checks, such as web-based services from multiple geographical locations, and a flexible platform and tools for defining customized complex services. Particular attention is paid to the processes of metrics collection, processing, storage, and querying. MonSys can perform custom availability checks for different types of infrastructures, such as various black-box, grey-box, and white-box availability checks/metrics. The article presents also results from piloting the platform on performance and scalability and options for integration in early-warning and intelligent signaling, based on behavioral pattern analysis and predictive simulations.</style></abstract><issue><style face="normal" font="default" size="100%">2</style></issue><section><style face="normal" font="default" size="100%">155</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Jussi Simola</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Comparative Research of Cybersecurity Information Sharing Models</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">cooperation</style></keyword><keyword><style  face="normal" font="default" size="100%">Early Warnings</style></keyword><keyword><style  face="normal" font="default" size="100%">ECHO project</style></keyword><keyword><style  face="normal" font="default" size="100%">indicators</style></keyword><keyword><style  face="normal" font="default" size="100%">information sharing</style></keyword><keyword><style  face="normal" font="default" size="100%">Situational awareness</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2019</style></year></dates><volume><style face="normal" font="default" size="100%">43</style></volume><pages><style face="normal" font="default" size="100%">175-195</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">&lt;p&gt;Cyber threats are on the increase. Authorities need to respond to growing challenges by increasing cooperation. Information sharing or information exchange in the EU level and between the countries is a main facility when the objective is to prevent hybrid threats. Intensifying relationships with private sector companies has become very important function and operating model to authorities to provide cyber-safe atmosphere. The main purpose of this study is to find out separating and combining factors concerning cyber information sharing models. The aim is also to find out nation level factors, which affect the utilization of a common Early Warning system by the ECHO stakeholders.&lt;/p&gt;&lt;p&gt;&lt;em&gt;Summary of findings&lt;/em&gt;: unclear allocation of responsibilities in national government departments prevents authorities from fighting together against cyber and physical threats. Cybersecurity responsibilities have been spread too widely. Operational work concerning cyber threat prevention between European public safety authorities should be more standardized, with more centralized management. When the purpose is to protect vital functions of society, public safety organizations in EU member states need proactive features in their information systems. An essential factor in information exchange is the place of registration of organizations or companies. Unclear standardization concerning cyber emergency procedures between authorities and organizations and lack of co-operation between cyber situation centres and cyber emergency response centres prevent common situational awareness.&lt;/p&gt;</style></abstract><issue><style face="normal" font="default" size="100%">2</style></issue><section><style face="normal" font="default" size="100%">175</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Jouni Pöyhönen</style></author><author><style face="normal" font="default" size="100%">Viivi Nuojua</style></author><author><style face="normal" font="default" size="100%">Martti Lehto</style></author><author><style face="normal" font="default" size="100%">Jyri Rajamäki</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Cyber Situational Awareness and Information Sharing in Critical Infrastructure Organizations</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Critical Infrastructure</style></keyword><keyword><style  face="normal" font="default" size="100%">Cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">information sharing</style></keyword><keyword><style  face="normal" font="default" size="100%">Situational awareness</style></keyword><keyword><style  face="normal" font="default" size="100%">vital societal functions</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2019</style></year></dates><volume><style face="normal" font="default" size="100%">43</style></volume><pages><style face="normal" font="default" size="100%">236-256</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">Cybersecurity-related capabilities play an ever-growing role in national security, as well as securing the functions vital to society. The national cyber capability includes the resilience of companies running critical infrastructures, their cyber situational awareness (SA) and the sharing of cybersecurity information required for cyber SA. As critical infrastructures become more complex and interdependent, ramifications of incidents multiply. The EU Network and Information Security Directive calls for cybersecurity collaboration between EU member states regarding critical infrastructures and places the most crucial service providers and digital service providers under security-related obligations. Developing better SA requires information sharing between the different interest groups and enhances the preparation for and management of incidents. The arrangement is based on drawing correct situation-specific conclusions and, when needed, on sharing critical knowledge in the cyber networks. The target state is achieved with an efficient process that includes a three-level—strategic, operational and technical/tactical—operating model to support decision-making by utilizing national and international strengths. In the dynamic cyber environment strategic agility and speed are needed to prepare for incidents. </style></abstract><issue><style face="normal" font="default" size="100%">2</style></issue><section><style face="normal" font="default" size="100%">236</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Konrad Wrona</style></author><author><style face="normal" font="default" size="100%">Tamsin Moye</style></author><author><style face="normal" font="default" size="100%">Philippe Lagadec</style></author><author><style face="normal" font="default" size="100%">Michael Street</style></author><author><style face="normal" font="default" size="100%">Peter Lenk</style></author><author><style face="normal" font="default" size="100%">Frederic Jordan</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Cybersecurity Innovation in NATO: Lessons Learned and Recommendations</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Cybersecurity Innovation</style></keyword><keyword><style  face="normal" font="default" size="100%">Data Fusion</style></keyword><keyword><style  face="normal" font="default" size="100%">Mobile Security</style></keyword><keyword><style  face="normal" font="default" size="100%">NATO Industry Cyber Partnership</style></keyword><keyword><style  face="normal" font="default" size="100%">Situational awareness</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2017</style></year></dates><volume><style face="normal" font="default" size="100%">36</style></volume><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">In the ever-increasing pace of technological development and the emergence of new stateless adversaries and threat vectors, the traditional NATO approach to the technical capability development struggles to address the emerging security challenges in cyberspace. In order to mitigate this situation, we describe an incubator framework, which provides a physical and virtual environment enabling industry, in particular small and medium sized enterprises, science and technology organizations, academia, and national defence labs, to collaborate on innovation projects on the basis of either voluntary, nationally funded, or NATO commonly funded contributions. The proposed incubator framework has been practically validated and technical results have confirmed the feasibility as well as the benefits of setting up a cyber incubator within NATO. This disruptive approach to capability development requires the updating of several internal processes and procedures and the adoption of a new innovation-friendly and risk-tolerant organizational culture within the Organization. We describe the main lessons learned from our experiment and the recommendations regarding required changes to the internal and external NATO processes and procedures.</style></abstract></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">George Sharkov</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">A System-of-Systems Approach to Cyber Security and Resilience</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">collaboration-oriented architecture</style></keyword><keyword><style  face="normal" font="default" size="100%">composite cyber risk</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber picture</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber resilience</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber risks</style></keyword><keyword><style  face="normal" font="default" size="100%">cyber threats</style></keyword><keyword><style  face="normal" font="default" size="100%">de-perimetrization</style></keyword><keyword><style  face="normal" font="default" size="100%">Situational awareness</style></keyword><keyword><style  face="normal" font="default" size="100%">system-of-systems</style></keyword><keyword><style  face="normal" font="default" size="100%">zero trust model</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2017</style></year></dates><volume><style face="normal" font="default" size="100%">37</style></volume><pages><style face="normal" font="default" size="100%">69-94</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">To address the cybersecurity, safety, and reliability aspects of the entire digitalized ecosystems, we need first to understand and possibly model how the respective computer systems of different participating entities interoperate and collaborate. Modern computer systems and emerging applications are not just largescale and complex in the digitally connected world. We categorize them also as decentralized, distributed, networked, interoperable compositions of heterogeneous and (semi)autonomous systems and/or elements. These new types of composite systems with emergent behavior have been defined as “Systems of Systems” (SoS). This paper explores different types of SoS and analyzes the interdependencies to manage cybersecurity threats and risks and achieve cyber resilience. We review various definitions and types of SoS and the application of SoS approach to situational awareness, threat intelligence, and composite risk assessment. An SoS view on managing the supply/value chain cyber risks is also outlined.</style></abstract></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Frederic Jordan</style></author><author><style face="normal" font="default" size="100%">Geir Hallingstad</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Towards Multi-National Capability Development in Cyber Defence</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">CERT</style></keyword><keyword><style  face="normal" font="default" size="100%">correlation infrastructure</style></keyword><keyword><style  face="normal" font="default" size="100%">distributed sensor networks</style></keyword><keyword><style  face="normal" font="default" size="100%">experimentation</style></keyword><keyword><style  face="normal" font="default" size="100%">information sharing</style></keyword><keyword><style  face="normal" font="default" size="100%">NATO Computer Incident Response Capability</style></keyword><keyword><style  face="normal" font="default" size="100%">NCIRC</style></keyword><keyword><style  face="normal" font="default" size="100%">Situational awareness</style></keyword><keyword><style  face="normal" font="default" size="100%">validation</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2011</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2011</style></date></pub-dates></dates><volume><style face="normal" font="default" size="100%">27</style></volume><pages><style face="normal" font="default" size="100%">81-89</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">With NATO and the NATO Nations being heavily dependent on their communication and information systems, ensuring their proper operation is a critical task. Establishing appropriate cyber defence capabilities is a major endeavour and one which a lot of nations are currently putting increased focus on. The multi-national approach to cyber defence capability development presented in this paper is an approach to leverage the common interest nations have in this area to efficiently develop high-quality capabilities through cooperation and coordination. The paper goes on to present initial topics where the approach could be immediately leveraged, including information sharing, situational awareness, and distributed sensor collection and coordination capabilities. The paper concludes that this way forward could significantly improve our cyber defence capabilities and contribute to the overall security of the Alliance</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue></record></records></xml>