Preview

Civil Aviation High Technologies

Advanced search

Protection of corporate information systems of aviation enterprises from zero-day attacks: an intrusion detection approach based on deep unsupervised learning

https://doi.org/10.26467/2079-0619-2026-29-3-59-70

Abstract

The paper considers the urgent task of detecting zero-day attacks in corporate information systems of aviation enterprises classified as critical information infrastructure (CII). It is shown that traditional signature-based protection tools, including classical intrusion detection systems (IDS), have fundamentally limited effectiveness in conditions of previously unknown and targeted cyberattacks, which is confirmed by real incidents in the aviation sector. The search for effective methods of detecting zero-day attacks, as well as advanced persistent threats (APT) remains an urgent task, since their secrecy and uniqueness minimize the effectiveness of signature-based detection methods. In this paper a neural-network intrusion detection model is proposed, focused on application in aviation security operation centers (SOC) of aviation enterprises and based on deep unsupervised learning methods. The model is implemented in the form of a deep autoencoder trained exclusively on legitimate network traffic, which makes it possible to form a stable representation of normal behavior of the system and identify statistical deviations without prior knowledge of attack signatures. Experimental validation was performed on the CICIDS2018 dataset using the metrics F1-score, ROC-AUC, precision, and recall. The proposed approach demonstrated the F1-measure of 0.81 and a ROC-AUC of 0.844, exceeding the performance of classical unsupervised algorithms for uncontrolled anomaly detection (Isolation Forest and OneClass SVM). The results obtained confirm the applicability of the developed model as a proactive analytical component of hybrid intrusion detection systems and its potential to increase the cyber resilience of aviation-sector information systems. The model can be integrated into existing SOC platforms of aviation enterprises to complement signature-based analysis with a behavioral context. 

About the Authors

N. O. Mashoshin
SoftTelematika LLC
Russian Federation

Nikita O. Mashoshin, Machine Learning Engineer; Postgraduate Student of the Radio Engineering Fundamentals and Information Security Chair, Moscow State Technical University of Civil Aviation, 

Moscow.



A. A. Kuleshov
Scientific-Production Enterprise “Aerosila”, JSC
Russian Federation

Alexander A. Kuleshov, Doctor of Technical Sciences, Deputy General Director for Civil Aviation Products,

Stupino.



References

1. Avramchikov, V.M., Timokhovich, A.S., Rozhnov, I.P. (2024). Digital transformation in the aviation industry: opportunities and prospects. The Eurasian Scientific Journal, vol. 16, no. 3, 13 p. Available at: https://esj.today/PDF/04ECVN324.pdf (accessed: 23.11.2025). (in Russian)

2. Scarfone, K., Mell, P. (2007). Guide to intrusion detection and prevention systems (IDPS): NIST Special Publication 800-94. Gaithersburg: National Institute of Standards and Technology, 127 p.

3. Ahmed, M., Mahmood, A.N., Hu, J. (2016). A survey of network anomaly detection techniques. Journal of Network and Computer Applications, vol. 60, pp. 19–31. DOI: 10.1016/j.jnca.2015.11.016

4. Buczak, A.L., Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. Communications Surveys & Tutorials, vol. 18, no. 2, pp. 1153–1176. DOI: 10.1109/COMST.2015.2494502 (accessed: 23.11.2025).

5. Chalapathy, R., Chawla, S. (2021). Deep learning for anomaly detection: A survey. ACM Computing Surveys, vol. 54, no 2, 50 p. DOI: 10.48550/arXiv.1901.03407 (accessed: 23.11.2025).

6. Pang, G., Shen, C., Cao, L., van den Hengel, A. (2020). Deep learning for anomaly detection: A review. ACM Computing Surveys, 36 p. DOI: 10.1145/3439950 (accessed: 23.11.2025).

7. Ruff, L., Vandermeulen, R., Görnitz, N., Deecke, L. (2018). Deep one-class classification. In: Proceedings of the 35th International Conference on Machine Learning (ICML), vol. 80, pp. 4393–4402.

8. Zhou, C., Paffenroth, R. (2017). Robust deep autoencoders for unsupervised anomaly detection. In: Proceedings of the 23rd ACM SIGKDD Conference on Knowledge Discovery and Data Mining (KDD), pp. 665–674. DOI: 10.1145/3097983.3098052

9. Mirsky, Y., Doitshman, T., Elovici, Y., Shabtai, A. (2018). Kitsune: an ensemble of autoencoders for online network intrusion detection. In: Network and Distributed Systems Security (NDSS) Symposium, 15 p. DOI: 10.14722/ndss.2018.23204 (accessed: 23.11.2025).

10. Javaid, A., Niyaz, Q., Sun, W., Alam, M. (2016). A deep learning approach for network intrusion detection system. In: 9th EAI International Conference on Bio-inspired Information and Communications Technologies. DOI: 10.4108/eai.3-12-2015.2262516 (accessed: 23.11.2025).

11. Shone, N., Ngoc, T.N., Phai, V.D., Shi, Q. (2018). A deep learning approach to network intrusion detection. In: IEEE transactions on emerging topics in computational intelligence, vol. 2, no. 1, pp. 41–50. DOI: 10.1109/TETCI.2017.2772792 (accessed: 23.11.2025).

12. Goldstein, M., Uchida, S. (2016). A comparative evaluation of unsupervised anomaly detection algorithms for multivariate data. PLoS ONE, vol. 11, no. 4, ID: e0152173. DOI: 10.1371/journal.pone.0152173 (accessed: 23.11.2025).

13. Sakurada, M., Yairi, T. (2014). Anomaly detection using autoencoders with nonlinear dimensionality reduction. In: Proceedings of the MLSDA 2014 2nd Workshop on Machine Learning for Sensory Data Analysis, pp. 4–11. DOI: 10.1145/2689746.2689747 (accessed: 23.11.2025).

14. Kumar, A. (2024). A survey of CICIDS 2017 and CSE-CIC-IDS2018 datasets. In: AIP Conference Proceedings, vol. 3085. ID: 050001. DOI: 10.1063/5.0222131 (accessed: 23.11.2025).

15. Schölkopf, B., Platt, J.C., ShaweTaylor, J., Smola, A.J., Williamson, R.C. (2001). Estimating the support of a highdimensional distribution. Neural Computation, vol. 13, no. 7, pp. 1443–1471. DOI: 10.1162/089976601750264965

16. Liu, F.T., Ting, K.M., Zhou, Z.-H. (2008). Isolation Forest. In: 2008 Eighth IEEE International Conference on Data Mining (ICDM), pp. 413–422. DOI: 10.1109/ICDM.2008.17 (accessed: 23.11.2025).


Review

For citations:


Mashoshin N.O., Kuleshov A.A. Protection of corporate information systems of aviation enterprises from zero-day attacks: an intrusion detection approach based on deep unsupervised learning. Civil Aviation High Technologies. 2026;29(3):59-70. (In Russ.) https://doi.org/10.26467/2079-0619-2026-29-3-59-70

Views: 99

JATS XML


Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.


ISSN 2079-0619 (Print)
ISSN 2542-0119 (Online)