Mathematical modelling and hybrid cyber-incident management in the educational environment based on WSHEdSec
DOI:
https://doi.org/10.5281/zenodo.21875358Keywords:
stochastic risk assessment, adaptive response, digital resilience, learning infrastructure, fuzzy logic, continuity of education, security operations, decision support.Abstract
Objective. The study aims to substantiate and formalise the WSHEdSec model for hybrid cyber-incident management in an educational environment by combining automated detection, mathematical risk assessment and accountable human decision-making. Methods. The research employs systems analysis, set theory, Markov processes, fuzzy evaluation, multi-criteria optimisation, scenario modelling and expert weighting. Educational digital infrastructure is represented as a dynamic graph of assets, users, services and dependencies. Each incident is described by a feature vector including asset criticality, signal confidence, propagation scale, impact on learning continuity, data sensitivity and expected loss. Results. The proposed WSHEdSec model calculates an incident-priority index as a weighted nonlinear composition of normalised indicators and selects a response through a hybrid loop integrating an analytical module, security rules and a responsible decision maker. A total-loss function combines direct damage, downtime, pedagogical consequences, reputational risk and countermeasure costs. A transition matrix is formulated for the states of normal operation, suspicious event, confirmed incident, containment, recovery and post-incident improvement. Thresholds are defined for automatic response, escalation and mandatory human supervision. Scenario experiments indicate that the hybrid scheme can reduce expected containment time and the probability of disruptive false-positive actions compared with purely manual or purely automated approaches. Conclusions. WSHEdSec provides a methodological basis for educational security operations centres, cyber-exercise design, alert prioritisation and alignment of technical response with continuity-of-learning requirements. Its practical value lies in calibration for different levels of digital maturity, incorporation of expert and empirical data, and support for evidence-based post-incident learning.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Ганна Сергіївна Кашина, Андрій Анатолійович Краснік, Ілона Вікторівна Бацуровська

This work is licensed under a Creative Commons Attribution 4.0 International License.