Abstract
The paper presents a method of preventive restart of components in real-time operating systems, which combines a simplified Markov chain with a hybrid dual watchdog timer and is considered as a tool for enhancing cyber-resilience. Unlike traditional reactive strategies, which are activated only after a failure, the proposed approach provides a transition to a proactive model capable of counteracting both internal faults and external impacts, including denial-of-service (DoS) attacks, fault injections, or logic bombs. The use of compact Markov models makes it possible to quickly assess the risk of approaching a critical state without a significant increase in computational costs, which creates conditions for timely localization of the problem and initiation of the restart of a specific task, driver, or module at an early stage. This reduces the probability of losing the working context, minimizes the “window of vulnerability,” and decreases the risk of a complete reboot. The combination of software and hardware levels forms a multi-level protection mechanism: the software watchdog acts as the first line of defense, while the hardware one guarantees final recovery in case of deep lock-up or targeted attack. Such integration makes it possible to reduce the frequency of global restarts, limit downtime, and increase resilience to cyberattacks in resource-constrained conditions. The method does not require complex machine learning algorithms or cumbersome formal models, it is based on minimalist stochastic schemes and can be adapted to different platforms and threat scenarios. Experimental results demonstrated a 3.1 reduction in recovery time from 2.7 s to 0.84 s, approximately a 70% decrease in total system downtime from 4.5% to 1.37% over 5 minutes, and an average CPU load increase of only 1.4%, confirming the method’s high efficiency and low computational overhead. This ensures stability, predictability, and security of embedded and cyber-physical systems, where meeting timing constraints and continuity of task execution, as well as the ability to withstand modern cyber threats, are critically important. The obtained results demonstrate the practical effectiveness of the approach in industrial automation, robotics, automotive and medical systems, and confirm the prospects of the proposed solution for the development of next-generation cyber-defense systems.
| Original language | English |
|---|---|
| Pages (from-to) | 361-376 |
| Number of pages | 16 |
| Journal | CEUR Workshop Proceedings |
| Volume | 4126 |
| Publication status | Published - 2025 |
| Event | 2025 International Workshop on Applied Intelligent Security Systems in Law Enforcement, AISSLE 2025 - Vinnytsia, Ukraine Duration: 30 Oct 2025 → 31 Oct 2025 |
Keywords
- Markov chain
- RTOS
- cyber resilience
- cyber-physical systems anomaly detection
- fault tolerance
- operating systems
- preventive restart
ASJC Scopus subject areas
- General Computer Science
Fingerprint
Dive into the research topics of 'Hybrid method for protecting RTOS from failures and cyberattacks using compact Markov models'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver