<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="en">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">4</article-id>
      <article-id pub-id-type="doi">10.66424/2071-8217-2026-1-4</article-id>
      <title-group>
        <article-title>Forecasting multistage attacks in Kubernetes from Falco alerts using State-Space Models</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Прогнозирование многостадийных атак в Kubernetes по оповещениям Falco на основе State-Space-моделей</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0009-0154-5153</contrib-id>
          <name>
            <surname>Zdornikov</surname>
            <given-names>Egor</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>eozdornikov@itmo.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">ITMO University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-03-30">
        <day>30</day>
        <month>03</month>
        <year>2026</year>
      </pub-date>
      <issue>1</issue>
      <fpage>58</fpage>
      <lpage>68</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2026_1_7-8.pdf"/>
      <abstract xml:lang="en">
        <p>The article discusses the problem of proactive detection and forecasting of multi-stage cyberattacks in Kubernetes clusters based on the analysis of security event streams. As a mathematical framework, the use of Selective State-Space Models (SSM) is proposed, which allows for effective processing of long sequences of Falco alerts, taking into account the context of system calls and orchestrator metadata. It is demonstrated that the developed architecture outperforms baseline recurrent neural networks (LSTM/GRU) in the task of binary incident classification, achieving a ROC-AUC score of 0.93 and an F1-score of 0.84 on a test dataset generated using MITRE ATT&amp;CK scenarios. It is established that the proposed method enables early threat detection (on average at 57 % of the attack episode length), which facilitates the application of proactive response mechanisms, such as container migration, before critical consequences occur.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Kubernetes</kwd>
        <kwd>Falco</kwd>
        <kwd>attack forecasting</kwd>
        <kwd>multi-stage attacks</kwd>
        <kwd>State-Space Models</kwd>
        <kwd>Intrusion Detection</kwd>
        <kwd>proactive defense</kwd>
        <kwd>MITRE ATT&amp;CK</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
