Theoretical and Methodological Approaches to the Development of an Artificial Intelligence Driven Cybersecurity Protection Model for the Defense Sector of Mongolia

Authors

Keywords:

Machine Learning, Anomaly Detection, Risk Assessment, Automated Response, Information Security Architecture, Strategic Decision-Making

Abstract

In the context of accelerating digital transformation, network-centric operations, and the growing interdependence of information infrastructures, cyberspace has become an integral component of national security and defense systems. Under these conditions, traditional defensive mechanisms alone are no longer sufficient, and the importance of artificial intelligence (AI)-based cybersecurity solutions is rapidly increasing. The purpose of this paper is to define the theoretical and methodological foundations for developing an AI-based cybersecurity model tailored to the specific characteristics of Mongolia’s defense sector. The study examines the integration of AI into cybersecurity systems by applying risk management theory, systems theory, information security architecture theory, game theory, and organizational resilience theory. It also investigates the applications of machine learning, deep learning, anomaly detection, malware classification, risk prediction, automated response mechanisms, and cyber intelligence data processing. As a result, a methodological framework for implementing an AI-based cybersecurity model in Mongolia’s defense sector is proposed, consisting of key stages such as risk assessment, data collection and processing, machine learning model development, real-time monitoring, and automated response. Furthermore, an architectural model is introduced, comprising a data collection layer, threat intelligence repository, machine learning analytics module, risk assessment module, automated decision-making system, SOAR platform, and strategic management dashboard. This model provides both theoretical and practical significance for enhancing early threat detection, reducing cyber risks, supporting decision-making processes, and strengthening national defense capabilities.

Монгол Улсын батлан хамгаалах салбарын кибер аюулгүй байдлын хиймэл оюунд суурилсан хамгаалалтын загвар боловсруулах онол, арга зүйн асуудал

Дижитал шилжилт, сүлжээ төвтэй ажиллагаа болон мэдээллийн дэд бүтцийн хамаарал өсөн нэмэгдэж буй өнөө үед кибер орчин нь үндэсний аюулгүй байдал, батлан хамгаалах тогтолцооны салшгүй бүрэлдэхүүн хэсэг болж байна. Ийм нөхцөлд уламжлалт хамгаалалтын арга хэрэгслүүд дангаараа хангалттай үр дүн үзүүлэхгүй болсон бөгөөд хиймэл оюунд суурилсан кибер хамгаалалтын шийдлүүдийн ач холбогдол эрчимтэй нэмэгдэж байна. Энэхүү өгүүллийн зорилго нь Монгол Улсын батлан хамгаалах салбарын онцлогт нийцсэн хиймэл оюунд суурилсан кибер хамгаалалтын загвар боловсруулах онол, арга зүйн үндсийг тодорхойлоход оршино. Өгүүлэлд эрсдэлийн удирдлагын онол, системийн онол, мэдээллийн аюулгүй байдлын архитектурын онол, тоглоомын онол болон байгууллагын тогтвортой байдлын онолыг ашиглан хиймэл оюуныг кибер хамгаалалтын тогтолцоонд нэгтгэх боломжийг шинжилсэн. Мөн машин сургалт, гүн сургалт, аномали илрүүлэлт, хортой кодын ангилал, эрсдэлийн урьдчилсан таамаглал, автомат хариу арга хэмжээ болон кибер тагнуулын мэдээлэл боловсруулах чиглэл дэх хэрэглээг судалсан. Судалгааны үр дүнд Монгол Улсын батлан хамгаалах салбарт хэрэгжүүлэх хиймэл оюунд суурилсан хамгаалалтын загварын арга зүйг эрсдэлийн үнэлгээ, өгөгдөл цуглуулах ба боловсруулах, машин сургалтын загвар хөгжүүлэх, бодит цагийн хяналт, автомат хариу арга хэмжээ гэсэн үндсэн үе шатуудаар тодорхойлсон. Түүнчлэн өгөгдөл цуглуулах давхарга, аюул заналын тагнуулын сан, машин сургалтын аналитик хэсэг, эрсдэлийн үнэлгээний модуль, автомат шийдвэр гаргалтын систем, “Аюулгүй байдлын уялдуулалт, автоматжуулалт ба хариу арга хэмжээ (SOAR)”-ний платформ болон стратегийн удирдлагын самбараас бүрдэх архитектурын загварыг санал болгосон. Энэхүү загвар нь кибер халдлагыг эрт илрүүлэх, эрсдэлийг бууруулах, шийдвэр гаргалтыг дэмжих, үндэсний батлан хамгаалах чадавхыг бэхжүүлэх онолын болон практик ач холбогдолтой юм.

Түлхүүр үгс: Машин сургалт; Аномали илрүүлэлт; Эрсдэлийн үнэлгээ; Автоматжуулсан хариу арга хэмжээ; Мэдээллийн аюулгүй байдлын архитектур; Стратегийн шийдвэр гаргалт

Abstract
0
PDF
0

References

1. Bertalanffy, L. von. 1968. General system theory: Foundations, development, applications. George Braziller.

2. Brumaghin, E., et al. 2019. Automatic cyber defense systems and response orchestration in enterprise networks. IEEE Security & Privacy Publications.

3. Buczak, A. L., Guven, E. 2016. "A survey of data mining and machine learning methods for cyber security intrusion detection, IEEE Communications Surveys & Tutorials, 18(2) 1153-1176. https://doi.org/10.1109/COMST.2015.2494502

4. Chandola, V., Banerjee, A., Kumar, V. 2009. "Anomaly detection: A survey, " ACM Computing Surveys, 41(3) 1-58. https://doi.org/10.1145/1541880.1541882

5. Craigen, D., Diakun-Thibault, N., Purse, R. 2014. Defining cybersecurity, Technology Innovation Management Review, 4(10) 13-21. https://doi.org/10.22215/timreview/835

6. Goodfellow, I., Bengio, Y., Courville, A. 2016. Deep learning. MIT Press.

7. Javaid, A., Niyaz, Q., Sun, W., Alam, M. 2016. "A deep learning approach for network intrusion detection system" Proceedings of the 9th EAI International Conference on Bio-inspired Information and Communications Technologies 21-26. https://doi.org/10.4108/eai.3-12-2015.2262516

8. Linkov, I., Bridges, T., Creutzig, F., Decker, J., Fox-Lent, C., Kröger, W., Lambert, J. H., Levermann, A., Montreuil, B., Nathwani, J., Nyer, R., Renn, O., Scharte, B., Scheffran, J., Schreurs, M., Thiel-Clemen, T. 2013. "Changing the resilience paradigm," Nature Climate Change, 4(6) 407-429. https://doi.org/10.1038/nclimate2227

9. McGraw, G. 2006. Software security: Building security in. Addison-Wesley. https://doi.org/10.1109/ISSRE.2006.43

10. Moustafa, N., Creech, G., Sitnikova, E. 2019. "Learning-based models for automatic cyber defense and intrusion response" IEEE Access, 7 102-118.

11. National Institute of Standards and Technology. 2024. Cybersecurity framework (CSF) . 2.0, U.S. Department of Commerce.

12. National Institute of Standards and Technology. 2012. Guide for conducting risk assessments, https://nvlpubs.nist.gov/nistpubs/Legacy/SP/ nistspecialpublication800-30r1.pdf. (SP 800-30 Rev. 1), U.S. Department of Commerce.

13. Pita, J., Jain, M., Ordóñez, F., Tambe, M., et al. 2010. "Using game theory for real-world security problems." ACM Computing Surveys,(3) 1-34. 14. Russell, S., Norvig, P. 2021. Artificial intelligence: A modern approach (4th ed.). Pearson.

15. Sarker, I. H., Kayes, A. S. M., Badsha, S., Alqahtani, H., Watters, P., Ng, A. 2020. "Cybersecurity data science: An overview from machine learning perspective" Journal of Big Data, 7(1) 41.https://doi.org/10.1186/s40537-020-00318-5

16. Shoham, Y., Leyton-Brown, K. 2009. Multiagent systems: Algorithmic, game-theoretic, and logical foundations. Cambridge: Cambridge University Press. https://doi.org/10.1017/CBO9780511811654

17. Shone, N., Ngoc, T. N., Phai, V. D., Shi, Q. 2018. "A deep learning approach to network intrusion detection" IEEE Transactions on Emerging Topics in Computational Intelligence, 2(1) 41-50. https://doi.org/10.1109/TETCI.2017.2772792

18. Singer, P. W., Friedman, A. 2014. Cybersecurity and cyberwar: What everyone needs to know. Oxford: Oxford University Press. https://doi.org/10.1093/wentk/9780199918096.001.0001

19. Sommer, R., Paxson, V. 2010. "Outside the closed world: On using machine learning for network intrusion detection" 2010 IEEE Symposium on Security and Privacy 305-316. https://doi.org/10.1109/SP.2010.25

20. Souri, A., Hosseini, R. 2018. "A state-of-the-art survey of malware detection approaches using data mining techniques" Human-centric Computing and Information Sciences, 8(1) 3-17. https://doi.org/10.1186/s13673-018-0125-x

21. Stallings, W. 2024. Effective cybersecurity: A guide to using best practices and standards (2nd ed.). Pearson.

22. -. 2018. Effective cybersecurity: A guide to using best practices and standards. . Addison-Wesley.

23. Whitman, M. E., Mattord, H. J. 2022. Principles of information security (7th ed.). Cengage Learning.

24. Yuan, Z., Lu, Y., Wang, Z., Xue, Y. 2014. "Droid-Sec: Deep learning in Android malware detection" Proceedings of the ACM SIGCOMM Workshop on Security and Privacy in Smartphones and Mobile Devices 371-372.https://doi.org/10.1145/2619239.2631434

Downloads

Published

2026-07-28

Issue

Section

Articles

How to Cite

Baatar, C. (2026). Theoretical and Methodological Approaches to the Development of an Artificial Intelligence Driven Cybersecurity Protection Model for the Defense Sector of Mongolia. Journal of Security and Defense Studies, 44, 114-132. https://doi.org/10.65816/jsds.2026.02.009