<?xml version="1.0" encoding="UTF-8"?>
<article xml:lang="ru" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="1.1">
<front>
<journal-meta>
<journal-title-group>
<journal-title xml:lang="ru">Правовая информатика</journal-title>
<trans-title-group xml:lang="en">
<trans-title>Legal Informatics</trans-title>
</trans-title-group>
</journal-title-group>
</journal-meta>
<article-meta>
<article-id pub-id-type="doi">10.24412/1994-1404-2026-2-62-72</article-id>
<title-group>
<article-title xml:lang="ru">СТАТИСТИЧЕСКАЯ ОЦЕНКА ЛОКАЛЬНОЙ КОРРЕКЦИИ СЕТЕВОЙ ДЕГРАДАЦИИ В ЛАБОРАТОРНОЙ СЕТИ ИНФОРМАЦИОННОЙ БЕЗОПАСНОСТИ</article-title>
<trans-title-group xml:lang="en">
<trans-title>STATISTICAL ASSESSMENT OF THE LOCAL CORRECTION OF NETWORK DEGRADATION IN THE LABORATORY INFORMATION SECURITY NETWORK</trans-title>
</trans-title-group>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<name-alternatives>
<name xml:lang="ru">
<surname>Исаев</surname>
<given-names>Николай Александрович</given-names>
</name>
<name xml:lang="en">
<surname>Isaev</surname>
<given-names>Nikolay A.</given-names>
</name>
</name-alternatives>
<email>supercopen@yandex.ru</email>
<xref ref-type="aff" rid="lbrr-1"/>
</contrib>
<aff-alternatives id="lbrr-1">
<aff>
<institution xml:lang="ru">Московский университет имени С.Ю. Витте</institution>
<city xml:lang="ru">Москва</city>
<country xml:lang="ru">Российская Федерация</country>
</aff>
<aff>
<institution xml:lang="en">Moscow Witte University</institution>
<city xml:lang="en">Moscow</city>
<country xml:lang="en">Russian Federation</country>
</aff>
</aff-alternatives>
</contrib-group>
<self-uri xlink:href="http://uzulo.su/prav-inf/pdf-jpg/pi-2026-2-st07-s062-072.pdf">http://uzulo.su/prav-inf/pdf-jpg/pi-2026-2-st07-s062-072.pdf</self-uri>
<kwd-group xml:lang="ru">
<kwd>сетевая наблюдаемость</kwd>
<kwd>сетевые метрики</kwd>
<kwd>доверительные интервалы</kwd>
<kwd>критерий Стьюдента</kwd>
<kwd>UDP-потоки</kwd>
<kwd>интегральный критерий качества режима</kwd>
<kwd>адресная коррекция</kwd>
<kwd>интегральный критерий качества режима</kwd>
<kwd>физическая топология сети</kwd>
</kwd-group>
<kwd-group xml:lang="en">
<kwd>network observability</kwd>
<kwd>network metrics</kwd>
<kwd>confidence intervals</kwd>
<kwd>Student’s t-test</kwd>
<kwd>UDP streams</kwd>
<kwd>integral quality criterion of the mode</kwd>
<kwd>targeted correction</kwd>
<kwd>physical network topology</kwd>
<kwd></kwd>
</kwd-group>
<abstract xml:lang="ru">
<p>Цель статьи. Разработать и проверить подход, позволяющий оценивать, как локальное изменение сетевой обработки влияет на совокупное состояние лабораторной сети, используемой в задачах информационной безопасности. Основная задача состоит в том, чтобы связать ухудшение сетевых показателей с измеряемой причиной и проверить результат коррекции не по одному признаку, а по группе взаимосвязанных метрик.</p><p>Методы исследования. Работа выполнена на контролируемой сетевой конфигурации из передающего узла, четырёх принимающих узлов, управляемого коммутатора канального уровня и двух логических сегментов трафика. Нагрузка формировалась параллельными однонаправленными потоками протокола пользовательских датаграмм, а измерения проводились на стороне получателей и передающего узла. Сравнивались исходное состояние сети, состояние после расширения наблюдаемости и состояние после адресной коррекции. Для обработки применялись повторные прогоны, средние значения, доверительные интервалы и критерий Стьюдента для связанных выборок.</p><p>Результаты исследования. Сравнение режимов R0, R1 и R2 показало, что расширение наблюдаемости является диагностическим, но не достаточным корректирующим этапом: оно позволило выявить связь деградации с состоянием очередей, загрузкой узла-источника и признаками сетевой обработки, однако наилучшие значения показателей были получены только после адресной коррекции выявленного участка.</p><p>Наибольший эффект достигается после выявления локального источника деградации и коррекции соответствующего участка сетевой обработки. В измеренной серии уменьшились потери пакетов и задержка, сократилась загрузка передающего узла, увеличилась фактическая скорость приёма данных и стабилизировалось состояние очередей. Интегральная оценка подтвердила согласованное улучшение группы показателей, а не отдельной метрики. Это даёт возможность использовать предложенный подход в области информационной безопасности для экспериментальной диагностики сетевых участков, где необходимо обосновать корректирующее действие до замены оборудования, изменения топологии или снижения заданной нагрузки. В прикладном плане работа показывает, как переход от наблюдения к проверенной коррекции делает сетевой анализ более доказательным.</p>
</abstract>
<trans-abstract xml:lang="en">
<p>Purpose of work. To develop and verify an approach that makes it possible to assess how a local change in network processing affects the overall state of a laboratory network used in information security tasks. The main task is to link the deterioration of network indicators with a measurable cause and to verify the correction result not based on a single indicator, but based on a group of interrelated metrics.</p><p>Research methods. The work was carried out on a controlled network configuration consisting of a transmitting node, four receiving nodes, a managed link-layer switch, and two logical traffic segments. The load was generated by parallel unidirectional streams of the User Datagram Protocol (UDP), and measurements were taken at the receivers’ side and the transmitting node. The initial state of the network, the state after expanding observability, and the state after targeted correction were compared. For data processing, repeated runs, mean values, confidence intervals, and Student’s t-test for related samples were applied.</p><p>Results of the study. The comparison of R0, R1 and R2 showed that expanding observability plays a diagnostic rather than corrective role. It made it possible to identify the local degradation section using queue, interface and CPU indicators, but the best network state was achieved only after targeted correction. Compared with R1, R2 reduced UDP packet loss from about 10.0 to 5.0%, increased the actual receiving rate from 54.0 to 57.5 Mbit/s, decreased RTT from 110 to 100 ms, and reduced the transmitter CPU load from 65 to 60%. Therefore, expanding observability alone should be considered a necessary diagnostic stage, but not a sufficient condition for improving the network state. The greatest effect is achieved after identifying the local source of degradation and correcting the corresponding section of network processing. In the measured series, packet loss and latency decreased, the load on the transmitting node reduced, the actual data reception rate increased, and the queue state stabilized. The integral assessment confirmed a consistent improvement in a group of indicators, rather than in a single metric. This makes it possible to use the proposed approach in the field of information security for experimental diagnostics of network segments where it is necessary to justify corrective action before replacing equipment, changing the topology, or reducing the specified load. In practical terms, the work demonstrates how the transition from observation to verified correction makes network analysis more evidence-based.</p>
</trans-abstract>
</article-meta>
</front>
<back>
<ref-list>
<ref id="rfr-1">
<label>1.</label>
<citation-alternatives>
<mixed-citation>Alkenani J. Network Monitoring Measurements for Quality of Service: A Review / J. Alkenani, K.A. Nassar // Iraqi Journal for Electrical and Electronic Engineering. 2022. Vol. 18, № 2. P. 33-42. DOI: 10.37917/ijeee.18.2.5</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-2">
<label>2.</label>
<citation-alternatives>
<mixed-citation>Graf F. Monitoring Performance Metrics in Low Power Wireless Systems / F. Graf, T. Watteyne, M. Villnow // ICT Express. 2024. Vol. 10, № 5. P. 989-1018. DOI: 10.1016/j.icte.2024.08.004</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-3">
<label>3.</label>
<citation-alternatives>
<mixed-citation>Polverini M. Reducing the In Band Network Telemetry Overhead through the Spatial Sampling: Theory and Experimental Results / M. Polverini [et al.] // Computer Networks. 2024. Vol. 242. Article 110269. DOI: 10.1016/j.comnet.2024.110269</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-4">
<label>4.</label>
<citation-alternatives>
<mixed-citation>Zeng X. INT MC: Low Overhead In Band Network Wide Telemetry Based on Matrix Completion / X. Zeng [et al.] // Proceedings of the ACM on Measurement and Analysis of Computing Systems. 2024. Vol. 8, № 3. P. 1-30. DOI: 10.1145/3700433</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-5">
<label>5.</label>
<citation-alternatives>
<mixed-citation>Xu Z. Information Sensitive In Band Network Telemetry in P4 Based Programmable Data Plane / Z. Xu, Z. Lu, Z. Zhu // IEEE/ACM Transactions on Networking. 2024. Vol. 32. P. 5081-5096. DOI: 10.1109/TNET.2024.3448244</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-6">
<label>6.</label>
<citation-alternatives>
<mixed-citation>Alshahrani A. A Fully Adaptive Active Queue Management Method for Congestion Prevention at the Router Buffer / A. Alshahrani [et al.] // Computers, Materials and Continua. 2023. Vol. 77, № 2. P. 1679-1698. DOI: 10.32604/cmc.2023.043545</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-7">
<label>7.</label>
<citation-alternatives>
<mixed-citation>Abdel Jaber H. Performance Analysis of Diverse Active Queue Management Algorithms / H. Abdel Jaber // International Journal of Networked and Distributed Computing. 2025. Vol. 13. Article 15. DOI: 10.1007/s44227-025-00056-1</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-8">
<label>8.</label>
<citation-alternatives>
<mixed-citation>Singha S. Active Queue Management in RED Considering Critical Point on Target Queue / S. Singha, B. Jana, N.K. Mandal // Journal of Interconnection Networks. 2021. Vol. 21, № 3. Article 2150017. DOI: 10.1142/S0219265921500171</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-9">
<label>9.</label>
<citation-alternatives>
<mixed-citation>Najmi A. How to Choose and Interpret a Statistical Test? An Update for Budding Researchers / A. Najmi, B. Sadasivam, A. Ray // Journal of Family Medicine and Primary Care. 2021. Vol. 10, № 8. P. 2763-2767. DOI: 10.4103/jfmpc.jfmpc_433_21</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-10">
<label>10.</label>
<citation-alternatives>
<mixed-citation>Ponce Renova H.F. Comparing Effect Sizes and Their Confidence Intervals: A Primer on Equivalence Testing in Educational Research / H.F. Ponce Renova // Journal of New Approaches in Educational Research. 2022. Vol. 11, № 2. P. 209-225. DOI: 10.7821/naer.2022.7.930</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-11">
<label>11.</label>
<citation-alternatives>
<mixed-citation>Manzanares Lopez P. Passive In Band Network Telemetry Systems: The Potential of Programmable Data Plane on Network Wide Telemetry / P. Manzanares Lopez, J.P. Munoz Gea, J. Malgosa Sanahuja // IEEE Access. 2021. Vol. 9. P. 20391-20409. DOI: 10.1109/ACCESS.2021.3055462</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-12">
<label>12.</label>
<citation-alternatives>
<mixed-citation>Yaseen N. From Counters to Telemetry: A Survey of Programmable Network Wide Monitoring / N. Yaseen // Network. 2025. Vol. 5, № 3. Article 38. DOI: 10.3390/network5030038</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-13">
<label>13.</label>
<citation-alternatives>
<mixed-citation>Tan L. In Band Network Telemetry: A Survey / L. Tan [et al.] // Computer Networks. 2021. Vol. 186. Article 107763. DOI: 10.1016/j.comnet.2020.107763</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-14">
<label>14.</label>
<citation-alternatives>
<mixed-citation>Yang Z. A Systematic Literature Review of Methods and Datasets for Anomaly Based Network Intrusion Detection / Z. Yang [et al.] // Computers &amp; Security. 2022. Vol. 116. Article 102675. DOI: 10.1016/j.cose.2022.102675</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-15">
<label>15.</label>
<citation-alternatives>
<mixed-citation>Schummer P. Machine Learning Based Network Anomaly Detection: Design, Implementation, and Evaluation / P. Schummer [et al.] // AI. 2024. Vol. 5, № 4. P. 2967-2983. DOI: 10.3390/ai5040143</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-16">
<label>16.</label>
<citation-alternatives>
<mixed-citation>Котенко И.В. Динамическая модель контроля функционирования для предупреждения компьютерных атак / И.В. Котенко, И.Б. Саенко, Р.И. Захарченко, Д.В. Величко // Правовая информатика. 2024. № 2. С. 35-43. DOI: 10.21681/1994-1404-2024-2-35-43.</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-17">
<label>17.</label>
<citation-alternatives>
<mixed-citation>Котенко И.В. Методика обнаружения сетевых вторжений на основе интеграции методов вейвлет-анализа и математической статистики / И.В. Котенко, И.Б. Саенко, П.В. Бортникер // Правовая информатика. 2024. № 4. С. 23-31. DOI: 10.24412/1994-1404-2024-4-23-31.</mixed-citation>
</citation-alternatives>
</ref>
</ref-list>
</back>
</article>
