Cybersecurity

The laboratory is a leading research and applied science center in the fields of cybersecurity and the protection of critical infrastructure, digital services, the digital industry, and the information society. It actively develops national capabilities in cyber resilience, studies digital dependency and cyber vulnerabilities, models complex cyber-physical systems for threat detection, and participates in the development and implementation of cybersecurity standards and methodologies, including those applicable to systems using artificial intelligence.

Services provided

  • Specialized courses and practical simulations in security for web, mobile, and AI-based systems, applied cryptography, IoT/IIoT security, and more;
  • Platform (academic Cyber Range) for realistic training and exercises;
  • Courses on IT/software process management, digital service quality and resilience, information security, critical thinking, and countering disinformation and cognitive operations;
  • Consulting on risk management and resilience, incident response, and recovery;
  • Consulting on the architecture and design of cyber-resilient systems, secure programming, cryptographic protection, and integrating security into business processes and services;
  • Penetration testing (pen-testing) and cybersecurity audits of components, systems, and organizations;
  • Simulation of cyberattacks and defense analysis in complex infrastructures;
  • Development of training programs and initiatives to improve cyber hygiene and professional skills for AI usage;
  • Specialized compliance testing according to European certification schemes and standards for cybersecurity and resilience, as well as reliable AI-enabled systems.

Activities

Researching and ensuring cybersecurity and resilience of Systems of Systems (SoS) and cyber-physical systems;

Threats intelligence and risk assessment of complex interconnected systems and services, including identification and assessment of hidden risks and threats in supply chains and AI-based systems;

Development and maintenance of a technological platform (MonSys) for monitoring the availability and accessibility of web services;

AI methods for protection and resilience, including the defense of AI-based systems;

Development of simulation technologies and platforms (Cyber Ranges) for studying interconnected critical infrastructures;

Analysis and classification of cyber threats – web, mobile platforms, IoT/IIoT, ICS/SCADA, and industrial platforms;

Study and develop architectures for simulation platforms of complex systems to analyze “interconnected weaknesses and vulnerabilities” – simulating interdependent critical infrastructures with a focus on supply chains;

Development and execution of CYBRID (Cyber/Hybrid) Shockwave Exercises using European Software Institute (ESI)U methodology and technologies, based on the “The Red Ranger” cyber range.

Development of methods and tools for assessing (auditing) cyber risks in various systems (web, mobile) of third parties;

Publications

The European AI Tango: Balancing Regulation Innovation and Competitiveness. In Proceedings of the 2023 Conference on Human Centered Artificial Intelligence: Education and Practice (HCAIep ’23). Association for Computing Machinery, New York, NY, USA, 2–8;

Christina Todorova, George Sharkov, Huib Aldewereld, Stefan Leijnen, Alireza Dehghani, Stefano Marrone, Carlo Sansone, Maurice Lynch, John Pugh, Tarry Singh, Kitti Mezei, Péter Antal, Péter Hanák, Alessandro Barducci, Fernando Perez-Tellez, and Francesco Gargiulo. 2023.
https://doi.org/10.1145/3633083.3633161 [SCOPUS]

Harnessing the Power of Responsible Innovation: The Shift Towards Human-Centered Skills and Competences in AI Engineering, CEUR Workshop Proceedings ISGT’22, Vol. 3191, ISSN 1613-0073, pp. 1-17,(2022);

Sharkov, G., Todorova, C., Varbanov, P.
http://ceur-ws.org/Vol-3191/paper01.pdf [open access, SCOPUS]

“Towards a Robust and Scalable Cyber Range Federation for Sectoral Cyber/Hybrid Exercising: The Red Ranger and ECHO Collaborative Experience”, Information & Security: An International Journal 53, no. 2 (2022): 287-302;

Sharkov, G., Todorova, C., Koykov, G., Nikolov, I. (2022)
https://doi.org/10.11610/isij.5319 [open access]

Harnessing the Potential of AI Against COVID-19 Through the Lens of Cybersecurity: Challenges, Tools, and Techniques. Information & Security: An International Journal, Vol. 49 (2021):49-69.,(2021)

George Sharkov
https://isij.eu/node/22973/ [open access]

Strategies, Policies, and Standards in the EU Towards a Roadmap for Robust and Trustworthy AI Certification. Information & Security: An International Journal 50, no. 1 (2021): 11-22;

Sharkov, George, Christina Todorova, and Pavel Varbanov.
https://doi.org/10.11610/isij.5030 [open access]

Equipment

  • Modern infrastructure for applied research projects and innovations in cybersecurity and AI systems;
  • Basic computing resources and a specialized Faraday cage section for working with sensitive and classified information;
  • Advanced tools for automated cybersecurity assessment of systems, applications, and infrastructure;
  • Cyber simulation range Cyber Range “The Red Ranger” for red-blue teaming, Capture the Flag (CTF) exercises, and Cyber Shockwave exercises.

Management

Head: Dr. Georgi Sharkov

Scientific fields:

cybersecurity and cyber -resilience, artificial intelligence, knowledge graphs, reasoning models, and complex intelligent software systems.

Achievements:

Dr. Georgi Sharkov has over 30 years of experience in developing complex software systems-of-systems, managing software process quality, cybersecurity, cyber -resilience, and trustworthy AI.

He is an Associate Professor at the Institute of ICT, Bulgarian Academy of Sciences, in the department “Artificial Intelligence and Language Models”, and Director of the European Software Institute (Sofia) since 2003.
Dr. Sharkov has served as an advisor on cyber defense to the Minister of Defense and as National Cybersecurity Coordinator, leading the “Cyber Resilient Bulgaria 2020” strategy. He is a member of the EU High-Level Expert Group on Trustworthy AI and represents the European Digital SME Alliance and SBS in key technical committees and working groups under ENISA and the European Commission.