<?xml version="1.0" encoding="UTF-8"?>
<article article-type="research-article" dtd-version="1.3" xml:lang="ru" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="https://metafora.rcsi.science/xsd_files/journal3.xsd">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">moitvivt</journal-id>
      <journal-title-group>
        <journal-title xml:lang="ru">Моделирование, оптимизация и информационные технологии</journal-title>
        <trans-title-group xml:lang="en">
          <trans-title>Modeling, Optimization and Information Technology</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2310-6018</issn>
      <publisher>
        <publisher-name>Издательство</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.26102/2310-6018/2026.59.8.014</article-id>
      <article-id pub-id-type="custom" custom-type="elpub">2396</article-id>
      <title-group>
        <article-title xml:lang="ru">Интеграция информационной безопасности и системной инженерии в мультиязычную обучающую игру по жестовым языкам</article-title>
        <trans-title-group xml:lang="en">
          <trans-title>Integrating information security and systems engineering into a multilingual sign language learning game</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author" corresp="yes">
          <contrib-id contrib-id-type="orcid">0000-0002-5753-6135</contrib-id>
          <name-alternatives>
            <name name-style="eastern" xml:lang="ru">
              <surname>Ашрафи</surname>
              <given-names>Арифа</given-names>
            </name>
            <name name-style="western" xml:lang="en">
              <surname>Ashrafi</surname>
              <given-names>Arifa</given-names>
            </name>
          </name-alternatives>
          <email>arifaa13@gmail.com</email>
          <xref ref-type="aff">aff-1</xref>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0001-9419-2282</contrib-id>
          <name-alternatives>
            <name name-style="eastern" xml:lang="ru">
              <surname>Филиппович</surname>
              <given-names>Юрий Николаевич</given-names>
            </name>
            <name name-style="western" xml:lang="en">
              <surname>Philippovich</surname>
              <given-names>Yuriy Sergeevich</given-names>
            </name>
          </name-alternatives>
          <email>y_philippovich@mail.ru</email>
          <xref ref-type="aff">aff-2</xref>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0001-6520-0386</contrib-id>
          <name-alternatives>
            <name name-style="eastern" xml:lang="ru">
              <surname>Мохначев</surname>
              <given-names>Виктор Сергеевич</given-names>
            </name>
            <name name-style="western" xml:lang="en">
              <surname>Mokhnachev</surname>
              <given-names>Viktor Sergeevich</given-names>
            </name>
          </name-alternatives>
          <email>gagashaggy@inbox.ru</email>
          <xref ref-type="aff">aff-3</xref>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0008-1402-8617</contrib-id>
          <name-alternatives>
            <name name-style="eastern" xml:lang="ru">
              <surname>Махмуд</surname>
              <given-names>Али Айманович</given-names>
            </name>
            <name name-style="western" xml:lang="en">
              <surname>Makhmud</surname>
              <given-names>Ali Aimanovich</given-names>
            </name>
          </name-alternatives>
          <email>Makhmud_ali22@mail.ru</email>
          <xref ref-type="aff">aff-4</xref>
        </contrib>
      </contrib-group>
      <aff-alternatives id="aff-1">
        <aff xml:lang="ru">Московский политехнический университет</aff>
        <aff xml:lang="en">Mocow Polytechnic University</aff>
      </aff-alternatives>
      <aff-alternatives id="aff-2">
        <aff xml:lang="ru">Московский политехнический университет</aff>
        <aff xml:lang="en">Mocow Polytechnic University</aff>
      </aff-alternatives>
      <aff-alternatives id="aff-3">
        <aff xml:lang="ru">Московский политехнический университет</aff>
        <aff xml:lang="en">Mocow Polytechnic University</aff>
      </aff-alternatives>
      <aff-alternatives id="aff-4">
        <aff xml:lang="ru">Московский политехнический университет</aff>
        <aff xml:lang="en">Mocow Polytechnic University</aff>
      </aff-alternatives>
      <pub-date pub-type="epub">
        <day>01</day>
        <month>01</month>
        <year>2026</year>
      </pub-date>
      <volume>1</volume>
      <issue>1</issue>
      <elocation-id>10.26102/2310-6018/2026.59.8.014</elocation-id>
      <permissions>
        <copyright-statement>Copyright © Авторы, 2026</copyright-statement>
        <copyright-year>2026</copyright-year>
        <license license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/">
          <license-p>This work is licensed under a Creative Commons Attribution 4.0 International License</license-p>
        </license>
      </permissions>
      <self-uri xlink:href="https://moitvivt.ru/ru/journal/article?id=2396"/>
      <abstract xml:lang="ru">
        <p>Разработка доступных и безопасных цифровых инструментов имеет очень важное значение для инклюзивного образования. Хотя в нашей предыдущей работе была продемонстрирована педагогическая эффективность мультиязычной обучающей игры по жестовым языкам, о чем свидетельствует улучшение распознавания жестов на 35 % и оценка по шкале юзабилити системы (SUS) 90 из 100, переход на готовую к промышленному использованию платформу, подключенную к интернету, создает значительные риски с точки зрения безопасности и эксплуатации. Для решения этой проблемы в данной работе представлена унифицированная методология, интегрирующая четыре ключевых направления: анализ безопасности веб-приложений, автоматизация жизненного цикла ПО (CI/CD), организация защищенных цифровых документооборотов и управление информацией и событиями безопасности (SIEM). Данная интеграция позволяет систематически усиливать защиту платформы и обеспечивать ее долгосрочную отказоустойчивость. В работе реализуется комплексный подход, при котором непрерывное тестирование безопасности, защищенные потоки данных и разработка с учетом угроз (threat-informed development) действуют согласованно для обеспечения целостности платформы. Результаты демонстрируют полную ликвидацию критических уязвимостей, снижение количества проблем высокой степени серьезности на 87,5 % в течение трех месяцев, а также сокращение среднего времени на устранение уязвимостей (MTTR) на 65,4 %. Система выдачи цифровых сертификатов достигла 99,6 % успешности выпуска и обеспечила 100 % обнаружение попыток подделки при времени публичной верификации менее одной секунды. Данная методология, валидированная в лабораторных условиях, представляет собой практическое руководство по трансформации инновационных образовательных инструментов в отказоустойчивые системы, готовые к промышленной эксплуатации.</p>
      </abstract>
      <trans-abstract xml:lang="en">
        <p>The development of accessible and secure digital tools is critical for inclusive education. While our prior work demonstrated the pedagogical efficacy of a multilingual sign language learning game-evidenced by a 35 % improvement in sign recognition and a System Usability Scale (SUS) score of 90/100-the transition to a production-ready, internet-connected platform introduces significant security and operational risks. To address this, this paper presents a unified framework that integrates four core disciplines-web application security analysis, software lifecycle automation (CI/CD), secure digital document workflows, and security information and event management (SIEM)-to systematically harden the platform and ensure its long-term resilience. We implement an integrated approach where continuous security testing, protected data workflows, and threat-informed development work in concert to ensure platform integrity. Results demonstrate the elimination of critical vulnerabilities, an 87.5 % reduction in high-severity issues within three months, and a 65.4 % improvement in mean time to remediate (MTTR). The secure certificate system achieved a 99.6 % issuance success rate and 100 % forgery detection, with public verification in under one second. This lab-validated methodology provides a practical blueprint for transforming innovative educational tools into resilient, production-ready systems.</p>
      </trans-abstract>
      <kwd-group xml:lang="ru">
        <kwd>язык жестов</kwd>
        <kwd>образовательная игра</kwd>
        <kwd>безопасность веб-приложений</kwd>
        <kwd>автоматизация CI/CD</kwd>
        <kwd>защищенный документооборот</kwd>
        <kwd>SIEM</kwd>
        <kwd>конфиденциальность данных</kwd>
        <kwd>инклюзивные образовательные технологии</kwd>
      </kwd-group>
      <kwd-group xml:lang="en">
        <kwd>sign language</kwd>
        <kwd>educational game</kwd>
        <kwd>web application security</kwd>
        <kwd>CI/CD automation</kwd>
        <kwd>secure document flow</kwd>
        <kwd>SIEM</kwd>
        <kwd>data privacy</kwd>
        <kwd>inclusive educational technologies</kwd>
      </kwd-group>
      <funding-group>
        <funding-statement xml:lang="ru">Исследование выполнено без спонсорской поддержки.</funding-statement>
        <funding-statement xml:lang="en">The study was performed without external funding.</funding-statement>
      </funding-group>
    </article-meta>
  </front>
  <back>
    <ref-list>
      <title>References</title>
      <ref id="cit1">
        <label>1</label>
        <mixed-citation xml:lang="ru">Ashrafi A., Philippovich Y.N., Mokhnachev V., et al. Development of the Multilingual Sign Language Learning Game for Interactive Education. International Journal of Open Information Technologies. 2026;14(2):128–133.</mixed-citation>
      </ref>
      <ref id="cit2">
        <label>2</label>
        <mixed-citation xml:lang="ru">Ашрафи А., Мохначев В.С., Махмуд А.А. и др. Разработка политики информационной безопасности для образовательной игры. В сборнике: III Международный конгресс «Русский инженер». Искусственный интеллект в автоматизированных системах управления и обработки данных (ИИАСУ'25): Сборник статей IV Всероссийской научной конференции, 29–30 октября 2025 года, Москва, Россия. Москва: Издательство МГТУ им. Н.Э. Баумана; 2026. С. 483–491.</mixed-citation>
      </ref>
      <ref id="cit3">
        <label>3</label>
        <mixed-citation xml:lang="ru">Ашрафи А., Мохначев В.С. Информационно-теоретическая метрика для автоматического лексикографического отбора в бенгальском жестовом языке. Моделирование, оптимизация и информационные технологии. 2026;14(6). (На англ.). https://doi.org/10.26102/2310-6018/2026.57.6.011</mixed-citation>
      </ref>
      <ref id="cit4">
        <label>4</label>
        <mixed-citation xml:lang="ru">Biswas J., Hasan M., Saiful M., et al. A review on mitigating security risks: Effective strategies to prevent cross-site request forgery vulnerabilities. In: Cyber Intelligence and Information Retrieval, 14–15 December 2023, Kolkata, India. Singapore: Springer; 2025. P. 309–317. https://doi.org/10.1007/978-981-97-7603-0_27</mixed-citation>
      </ref>
      <ref id="cit5">
        <label>5</label>
        <mixed-citation xml:lang="ru">De Ryck Ph., Desmet L., Joosen W., et al. Automatic and precise client-side protection against CSRF attacks. In: Computer Security – ESORICS 2011: 16th European Symposium on Research in Computer Security, 12–14 September 2011, Leuven, Belgium. Berlin, Heidelberg: Springer; 2011. P. 100–116. https://doi.org/10.1007/978-3-642-23822-2_6</mixed-citation>
      </ref>
      <ref id="cit6">
        <label>6</label>
        <mixed-citation xml:lang="ru">Simplice I., Fidel O., Kennedy Ch.G., et al. Enhancing information system security: A vulnerability assessment of a web application using OWASP top 10 list. In: Proceedings of 3rd International Conference on Smart Computing and Cyber Security: Strategic Foresight, Security Challenges and Innovation (SMARTCYBER 2023), 05–06 December 2023, South Korea. Singapore: Springer; 2024. P. 385–397. https://doi.org/10.1007/978-981-97-0573-3_31</mixed-citation>
      </ref>
      <ref id="cit7">
        <label>7</label>
        <mixed-citation xml:lang="ru">Khazal I.F., Ghaib A.A., Shareef A., et al. Cross Site Scripting Attacks (XSS): A Review. In: Software Engineering: Emerging Trends and Practices in System Development: Proceedings of 14th Computer Science On-line Conference 2025: Volume 7, 01–03 April 2025, Czech Republic. Cham: Springer; 2025. P. 342–359. https://doi.org/10.1007/978-3-032-04581-2_24</mixed-citation>
      </ref>
      <ref id="cit8">
        <label>8</label>
        <mixed-citation xml:lang="ru">Li K., Liu H., Zhang L., et al. Automatic inspection of static application security testing (SAST) reports via large language model reasoning. In: Artificial Intelligence Logic and Applications: 4th International Conference, AILA 2024, 10–11 August 2024, Lanzhou, China. Singapore: Springer; 2025. P. 128–142. https://doi.org/10.1007/978-981-96-0354-1_11</mixed-citation>
      </ref>
      <ref id="cit9">
        <label>9</label>
        <mixed-citation xml:lang="ru">Hüther L., Sohr K., Berger B.J., et al. Machine Learning for SAST: A Lightweight and Adaptable Approach. In: Computer Security – ESORICS 2023: 28th European Symposium on Research in Computer Security: Part IV, 25–29 September 2023, The Hague, The Netherlands. Cham: Springer; 2024. P. 85–104. https://doi.org/10.1007/978-3-031-51482-1_5</mixed-citation>
      </ref>
      <ref id="cit10">
        <label>10</label>
        <mixed-citation xml:lang="ru">Melis A., Giovine A., Rinieri L. Time-Sensitive Networking Digital Twin for STRIDE-based security testing. EURASIP Journal on Information Security. 2025;2025:26. https://doi.org/10.1186/s13635-025-00213-7</mixed-citation>
      </ref>
      <ref id="cit11">
        <label>11</label>
        <mixed-citation xml:lang="ru">Shahrivar P., Millar S. Detecting Web Application DAST Attacks in Large-Scale Event Data. In: Artificial Intelligence for Security: Enhancing Protection in a Changing World. Cham: Springer; 2024. P. 325–343. https://doi.org/10.1007/978-3-031-57452-8_14</mixed-citation>
      </ref>
      <ref id="cit12">
        <label>12</label>
        <mixed-citation xml:lang="ru">Machap K., Ang X.Y. Case study for implementation of host-based intrusion detection system in cyber security. In: Evolution in Signal Processing and Telecommunication Networks: Proceedings of Ninth International Conference on Microelectronics Electromagnetics and Telecommunications (ICMEET 2024): Volume 2, 19–20 December 2024, India. Singapore: Springer; 2026. P. 591–595. https://doi.org/10.1007/978-981-96-7241-7_47</mixed-citation>
      </ref>
      <ref id="cit13">
        <label>13</label>
        <mixed-citation xml:lang="ru">Carruthers A., Ahmed S. Security Monitoring. In: Maturing the Snowflake Data Cloud: A Templated Approach to Delivering and Governing Snowflake in Large Enterprises. Berkeley: Apress; 2023. P. 105–144. https://doi.org/10.1007/978-1-4842-9340-9_3</mixed-citation>
      </ref>
      <ref id="cit14">
        <label>14</label>
        <mixed-citation xml:lang="ru">Kumar U.D., Crocker J., Knezevic J., et al. Analysis of Reliability, Maintenance and Supportability Data. In: Reliability, Maintenance and Logistic Support: A Life Cycle Approach. New York: Springer; 2000. P. 423–471. https://doi.org/10.1007/978-1-4615-4655-9_12</mixed-citation>
      </ref>
    </ref-list>
    <fn-group>
      <fn fn-type="conflict">
        <p>The authors declare that there are no conflicts of interest present.</p>
      </fn>
    </fn-group>
  </back>
</article>