Интеграция информационной безопасности и системной инженерии в мультиязычную обучающую игру по жестовым языкам
Работая с сайтом, я даю свое согласие на использование файлов cookie. Это необходимо для нормального функционирования сайта, показа целевой рекламы и анализа трафика. Статистика использования сайта обрабатывается системой Яндекс.Метрика
Научный журнал Моделирование, оптимизация и информационные технологииThe scientific journal Modeling, Optimization and Information Technology
Online media
issn 2310-6018

Integrating information security and systems engineering into a multilingual sign language learning game

idAshrafi A., idPhilippovich Y.S., idMokhnachev V.S., idMakhmud A.A.

UDC 004.056.5
DOI: 10.26102/2310-6018/2026.59.8.014

  • Abstract
  • List of references
  • About authors

The development of accessible and secure digital tools is critical for inclusive education. While our prior work demonstrated the pedagogical efficacy of a multilingual sign language learning game-evidenced by a 35 % improvement in sign recognition and a System Usability Scale (SUS) score of 90/100-the transition to a production-ready, internet-connected platform introduces significant security and operational risks. To address this, this paper presents a unified framework that integrates four core disciplines-web application security analysis, software lifecycle automation (CI/CD), secure digital document workflows, and security information and event management (SIEM)-to systematically harden the platform and ensure its long-term resilience. We implement an integrated approach where continuous security testing, protected data workflows, and threat-informed development work in concert to ensure platform integrity. Results demonstrate the elimination of critical vulnerabilities, an 87.5 % reduction in high-severity issues within three months, and a 65.4 % improvement in mean time to remediate (MTTR). The secure certificate system achieved a 99.6 % issuance success rate and 100 % forgery detection, with public verification in under one second. This lab-validated methodology provides a practical blueprint for transforming innovative educational tools into resilient, production-ready systems.

1. Ashrafi A., Philippovich Y.N., Mokhnachev V., et al. Development of the Multilingual Sign Language Learning Game for Interactive Education. International Journal of Open Information Technologies. 2026;14(2):128–133.

2. Ashrafi A., Mokhnachev V.S., Makhmud A.A., et al. Developing an information security policy for an educational game. In: The III International Congress "Russian Engineer". Artificial Intelligence in Automated Control and Data Processing Systems (AIACS'25): Collection of Articles of the IV All‑Russian Scientific Conference, 29–30 October 2025, Moscow, Russia. Moscow: Publishing House of Bauman Moscow State Technical University; 2026. P. 483–491. (In Russ.).

3. Ashrafi A., Mokhnachev V.S. An information-theoretic metric for automated lexicographic selection in Bengali Sign Language. Modeling, Optimization and Information Technology. 2026;14(6). https://doi.org/10.26102/2310-6018/2026.57.6.011

4. Biswas J., Hasan M., Saiful M., et al. A review on mitigating security risks: Effective strategies to prevent cross-site request forgery vulnerabilities. In: Cyber Intelligence and Information Retrieval, 14–15 December 2023, Kolkata, India. Singapore: Springer; 2025. P. 309–317. https://doi.org/10.1007/978-981-97-7603-0_27

5. De Ryck Ph., Desmet L., Joosen W., et al. Automatic and precise client-side protection against CSRF attacks. In: Computer Security – ESORICS 2011: 16th European Symposium on Research in Computer Security, 12–14 September 2011, Leuven, Belgium. Berlin, Heidelberg: Springer; 2011. P. 100–116. https://doi.org/10.1007/978-3-642-23822-2_6

6. Simplice I., Fidel O., Kennedy Ch.G., et al. Enhancing information system security: A vulnerability assessment of a web application using OWASP top 10 list. In: Proceedings of 3rd International Conference on Smart Computing and Cyber Security: Strategic Foresight, Security Challenges and Innovation (SMARTCYBER 2023), 05–06 December 2023, South Korea. Singapore: Springer; 2024. P. 385–397. https://doi.org/10.1007/978-981-97-0573-3_31

7. Khazal I.F., Ghaib A.A., Shareef A., et al. Cross Site Scripting Attacks (XSS): A Review. In: Software Engineering: Emerging Trends and Practices in System Development: Proceedings of 14th Computer Science On-line Conference 2025: Volume 7, 01–03 April 2025, Czech Republic. Cham: Springer; 2025. P. 342–359. https://doi.org/10.1007/978-3-032-04581-2_24

8. Li K., Liu H., Zhang L., et al. Automatic inspection of static application security testing (SAST) reports via large language model reasoning. In: Artificial Intelligence Logic and Applications: 4th International Conference, AILA 2024, 10–11 August 2024, Lanzhou, China. Singapore: Springer; 2025. P. 128–142. https://doi.org/10.1007/978-981-96-0354-1_11

9. Hüther L., Sohr K., Berger B.J., et al. Machine Learning for SAST: A Lightweight and Adaptable Approach. In: Computer Security – ESORICS 2023: 28th European Symposium on Research in Computer Security: Part IV, 25–29 September 2023, The Hague, The Netherlands. Cham: Springer; 2024. P. 85–104. https://doi.org/10.1007/978-3-031-51482-1_5

10. Melis A., Giovine A., Rinieri L. Time-Sensitive Networking Digital Twin for STRIDE-based security testing. EURASIP Journal on Information Security. 2025;2025:26. https://doi.org/10.1186/s13635-025-00213-7

11. Shahrivar P., Millar S. Detecting Web Application DAST Attacks in Large-Scale Event Data. In: Artificial Intelligence for Security: Enhancing Protection in a Changing World. Cham: Springer; 2024. P. 325–343. https://doi.org/10.1007/978-3-031-57452-8_14

12. Machap K., Ang X.Y. Case study for implementation of host-based intrusion detection system in cyber security. In: Evolution in Signal Processing and Telecommunication Networks: Proceedings of Ninth International Conference on Microelectronics Electromagnetics and Telecommunications (ICMEET 2024): Volume 2, 19–20 December 2024, India. Singapore: Springer; 2026. P. 591–595. https://doi.org/10.1007/978-981-96-7241-7_47

13. Carruthers A., Ahmed S. Security Monitoring. In: Maturing the Snowflake Data Cloud: A Templated Approach to Delivering and Governing Snowflake in Large Enterprises. Berkeley: Apress; 2023. P. 105–144. https://doi.org/10.1007/978-1-4842-9340-9_3

14. Kumar U.D., Crocker J., Knezevic J., et al. Analysis of Reliability, Maintenance and Supportability Data. In: Reliability, Maintenance and Logistic Support: A Life Cycle Approach. New York: Springer; 2000. P. 423–471. https://doi.org/10.1007/978-1-4615-4655-9_12

Ashrafi Arifa

Scopus | ORCID | eLibrary |

Mocow Polytechnic University

Moscow, Russian Federation

Philippovich Yuriy Sergeevich
Candidate of Engineering Sciences, Professor

Scopus | ORCID | eLibrary |

Mocow Polytechnic University

Moscow, Russian Federation

Mokhnachev Viktor Sergeevich

Scopus | ORCID | eLibrary |

Mocow Polytechnic University

Moscow, Russian Federation

Makhmud Ali Aimanovich

ORCID | eLibrary |

Mocow Polytechnic University

Moscow, Russian Federation

Keywords: sign language, educational game, web application security, CI/CD automation, secure document flow, SIEM, data privacy, inclusive educational technologies

For citation: Ashrafi A., Philippovich Y.S., Mokhnachev V.S., Makhmud A.A. Integrating information security and systems engineering into a multilingual sign language learning game. Modeling, Optimization and Information Technology. 2026;14(8). URL: https://moitvivt.ru/ru/journal/article?id=2396 DOI: 10.26102/2310-6018/2026.59.8.014 .

© Ashrafi A., Philippovich Y.S., Mokhnachev V.S., Makhmud A.A. Статья опубликована на условиях лицензии Creative Commons Attribution-NonCommercial 4.0 International (CC BY-NS 4.0)
39

Full text in PDF

Скачать JATS XML

Received 09.06.2026

Revised 31.07.2026

Accepted 19.08.2026

Published 31.08.2026