GRADIENT-VELOCITY VECTOR LYAPUNOV ANALYSIS OF APERIODIC ROBUST STABILITY IN CYBER-DEFENSE ASSET DYNAMICS
DOI:
https://doi.org/10.37943/VUTC4044Keywords:
robust stability, vector Lyapunov function, patch management, security posture, deterministic chaos, cyber resilience, dynamical systems, aperiodic stability, controller synthesis, information securityAbstract
An enterprise security posture changes over time as exploits are disclosed, patches are applied, and assets age out of vendor support. Empirical incident studies indicate that many breaches follow not from a single point of failure but from a gradual decline of the posture over weeks and months. In this paper the population of protected assets in an information-technology infrastructure is modeled as a multidimensional, continuous-time linear dynamical system and analyzed for stability by the gradient-velocity vector Lyapunov function method. Robust aperiodic stability conditions are derived as an explicit system of linear inequalities in the patching, aging and recovery rates. These conditions are sufficient rather than necessary, so the divergent regime is confirmed by a direct spectral check of the model matrix. For the configuration studied it shows a single real positive eigenvalue, and exposure diverges monotonically and aperiodically; this loss of stability is interpreted as a structural, endogenous mechanism rather than an isolated random event. The same framework yields a linear feedback patch-management controller that places the closed-loop dynamics in the aperiodic robust stability class, with closed-form gains. A numerical experiment on a five-cohort asset model and a fourth-order companion-form plant shows that this controller reduces the residual-risk norm by about four orders of magnitude over twelve weeks, whereas the uncontrolled system grows by more than five. The method turns the intuition that “patching faster helps” into a quantitative structural criterion evaluable, in principle, from an enterprise’s own asset telemetry without a statistical baseline. All coefficients were assigned rather than identified from operational data and are reported in full, so the results hold within the proposed model only; empirical validation on operational data remains essential future work.
References
Dissanayake, A., Zahedi, A., Jayatilaka, A., Babar, M.A. (2022). Software security patch management — a systematic literature review of challenges, approaches, tools and practices // Information and Software Technology. — Vol. 144. — 106771. DOI: https://doi.org/10.1016/j.infsof.2021.106771
Verizon Business. (2024). Data Breach Investigations Report. — Annual report. — URL: https://www.verizon.com/business/resources/reports/dbir/
Allodi, L., Massacci, F. (2017). Security events and vulnerability data for cybersecurity risk estimation // Risk Analysis. — Vol. 37, No. 8. — pp. 1606–1627. DOI: https://doi.org/10.1111/risa.12864
Beisenbi, M. A., Basheyeva, Zh. O. (2019). The analysis of control systems with a high potential for robust stability on the control object output // Journal of Mathematics, Mechanics and Computer Science. — Vol. 103, No. 3. — pp. 19–30. DOI: https://doi.org/10.26577/JMMCS-2019-3-23
Martín del Rey, Á. (2015). Mathematical modeling of the propagation of malware: a review // Security and Communication Networks. — Vol. 8, No. 15. — pp. 2561–2579. DOI: https://doi.org/10.1002/sec.1186
Yao, Y., Fu, Q., Yang, W., Wang, Y., Sheng, C. (2018). An epidemic model of computer worms with time delay and variable infection rate // Security and Communication Networks. — Vol. 2018. — Article 9756982. — 11 p. DOI: https://doi.org/10.1155/2018/9756982
Chernikova, A., Gozzi, N., Perra, N., Boboila, S., Eliassi-Rad, T., Oprea, A. (2023). Modeling self-propagating malware with epidemiological models // Applied Network Science. — Vol. 8. — Article 52. DOI: https://doi.org/10.1007/s41109-023-00578-z
Yang, F., Zhang, Z., Zhang, X. (2023). A malware propagation model with dual delay in the industrial control network // Complexity. — Vol. 2023. — Article 8823080. DOI: https://doi.org/10.1155/2023/8823080
Jacobs, J., Romanosky, S., Edwards, B., Adjerid, I., Roytman, M. (2021). Exploit prediction scoring system (EPSS) // Digital Threats: Research and Practice. — Vol. 2, No. 3. — pp. 1–17. DOI: https://doi.org/10.1145/3436242
Erola, A., Bitsight Technologies. (2024). A mere five percent of vulnerable enterprises fix their issues every month: a large-scale study of vulnerability remediation timeframes across 101,201 enterprises // Bitsight Technologies Research Report. — URL: https://www.bitsight.com/blog/mere-five-percent-vulnerable-enterprises-fix-their-issues-every-month-how-help-them-do-better
Koscinski, V., Nelson, M., Okutan, A., Falso, R., Mirakhorli, M. (2025). Conflicting scores, confusing signals: an empirical study of vulnerability scoring systems // Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS ’25). — Taipei, Taiwan: ACM. — 15 p. DOI: https://doi.org/10.1145/3719027.3765210
Kiennert, C., Ismail, Z., Debar, H., Leneutre, J. (2018). A survey on game-theoretic approaches for intrusion detection and response optimization // ACM Computing Surveys. — Vol. 51, No. 5. — pp. 1–31. DOI: https://doi.org/10.1145/3232848
Hausken, K., Welburn, J.W., Zhuang, J. (2024). A review of attacker–defender games and cyber security // Games. — Vol. 15, No. 4. — Article 28. DOI: https://doi.org/10.3390/g15040028
Bellman, R. (1962). Vector Lyapunov functions // SIAM Journal on Control. — Vol. 1, No. 1. — pp. 32–34. doi: https://doi.org/10.1137/0301003
Matrosov, V.M. (1962). On the theory of stability of motion // Journal of Applied Mathematics and Mechanics. — Vol. 26, No. 6. — pp. 1506–1522. DOI: https://doi.org/10.3103/S1066369X17060044
Lakshmikantham, V., Matrosov, V.M., Sivasundaram, S. (1991). Vector Lyapunov Functions and Stability Analysis of Nonlinear Systems. — Dordrecht: Kluwer Academic Publishers. — 172 p. ISBN: 0792311523
Lyapunov, A.M. (1992). The General Problem of the Stability of Motion. — London: Taylor & Francis. — Reprint of 1892 dissertation.
Michel, A.N., Hou, L., Liu, D. (2015). Stability of Dynamical Systems: On the Role of Monotonic and Non-Monotonic Lyapunov Functions. 2nd ed. — Cham: Birkhäuser. — 653 p. DOI: https://doi.org/10.1007/978-3-319-15275-2
Lakshmikantham, V., Leela, S., Martynyuk, A.A. (2015). Stability Analysis of Nonlinear Systems. 2nd ed. — Cham: Birkhäuser. — 329 p. DOI: https://doi.org/10.1007/978-3-319-27200-9
Šiljak, D.D. (1978). Large-Scale Dynamic Systems: Stability and Structure. — New York: North-Holland. — 416 p. ISBN-10:0444002464. URL: https://searchworks.stanford.edu/view/1007595
Khalil, H.K. (2015). Nonlinear Control. — Boston, MA: Pearson. — 400 p. ISBN: 978-0-13-349926-1.
Ren, W., Li, J., Xiong, J., Sun, X.-M. (2023). Vector control Lyapunov and barrier functions for safe stabilization of interconnected systems // SIAM Journal on Control and Optimization. — Vol. 61, No. 5. — pp. 3209–3233. DOI: https://doi.org/10.1137/22M1530422
Layek, G.C. (2015). An Introduction to Dynamical Systems and Chaos. — New Delhi: Springer. — 622 p. DOI: https://doi.org/10.1007/978-81-322-2556-0
González-Aguilar, H., Ugalde, E. (Eds.) (2015). Nonlinear Dynamics New Directions: Theoretical Aspects. — Cham: Springer. — 219 p. DOI: https://doi.org/10.1007/978-3-319-09867-8
Strogatz, S.H. (2018). Nonlinear Dynamics and Chaos: With Applications to Physics, Biology, Chemistry, and Engineering. 2nd ed. — Boca Raton, FL: CRC Press. — 532 p. DOI: https://doi.org/10.1201/9780429492563
Shahzad, M., Shafiq, M.Z., Liu, A.X. (2020). Large scale characterization of software vulnerability life cycles // IEEE Transactions on Dependable and Secure Computing. — Vol. 17, No. 4. — pp. 730–744. DOI: https://doi.org/10.1109/TDSC.2019.2893950
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Articles are open access under the Creative Commons License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Authors who publish a manuscript in this journal agree to the following terms:
- The authors reserve the right to authorship of their work and transfer to the journal the right of first publication under the terms of the Creative Commons Attribution License, which allows others to freely distribute the published work with a mandatory link to the the original work and the first publication of the work in this journal.
- Authors have the right to conclude independent additional agreements that relate to the non-exclusive distribution of the work in the form in which it was published by this journal (for example, to post the work in the electronic repository of the institution or publish as part of a monograph), providing the link to the first publication of the work in this journal.
- Other terms stated in the Copyright Agreement.