Arquitectura moderna de ciberseguridad para prevención de fraudes en servicios administrativos

Autores/as

DOI:

https://doi.org/10.64439/cisai.v2i2.43

Palabras clave:

Seguridad informática, gestión de riesgos, detección de amenazas, continuidad operacional, inteligencia artificial

Resumen

A medida que las organizaciones de servicios avanzan en su modernización digital, la seguridad no siempre crece al mismo ritmo, generando vulnerabilidades que los esquemas convencionales de protección no logran cubrir. Para abordar este problema, el presente trabajo propone una arquitectura de ciberseguridad orientada a la prevención de fraudes en una empresa del sector servicios de Lima, Perú, cuyo diseño se fundamenta en el análisis documental de 385 registros técnicos de incidentes. Dicho análisis evidenció que solo el 54,3% de las vulnerabilidades fueron atendidas con oscilaciones mensuales entre 44,4% y 62,5%. Mientras que el índice
de respuesta efectiva no superó el 34%, con mínimos del 19% en los períodos de mayor carga operativa. Estos resultados, junto con la concentración de incidentes no resueltos en malware, amenazas desconocidas y ransomware, revelan fallas en la priorización y el cierre de eventos de seguridad. Ante este diagnóstico, la arquitectura propuesta articula gestión de identidades y accesos, protección avanzada contra amenazas, seguridad en entornos cloud, cumplimiento normativo y analítica extendida potenciada con inteligencia artificial, conformando una defensa en profundidad capaz de reducir la exposición residual y sostener una respuesta
antifraude robusta en entornos administrativos digitalizados.

Citas

[1] F. Houghton, M. Winterburn, and K. Oakley, “Rhysida Ransomware Attack on the British Library: Prioritisation, Expertise, and Funding Issues,” Information Technology and Libraries, vol. 44, no. 1, Mar. 2025, doi: 10.5860/ital.v44i1.17112.

[2] N. Wadesango and E. Maveneka, “Cyberthreats and their impact on financial integrity: Evaluating the effectiveness of local authorities cybersecurity policies in preventing and detecting fraud,” Corporate Law and Governance Review, vol. 7, no. 2, p. 32, Apr. 2025, doi: 10.22495/clgrv7i2p3.

[3] V. H. Che Leon Antinori, “Influence of Economic Cybercrime in Peru,” SCIENDO, vol. 27, no. 4, pp. 415–418, Oct. 2024, doi: 10.17268/sciendo.2024.071.

[4] D. F. Wahid and E. Hassini, “An augmented AI-based hybrid fraud detection framework for invoicing platforms,” Applied Intelligence, vol. 54, no. 2, pp. 1297–1310, Jan. 2024, doi: 10.1007/s10489-023-05223-x.

[5] A. Abu-Khadrah, S. Al-Washmi, A. Mohd Ali, and M. Jarrah, “Cyber-fraud detection methodology by using machine learning algorithms,” International Journal of Electrical and Computer Engineering (IJECE), vol. 15, no. 4, pp. 3949–3956, Aug. 2025, doi: 10.11591/ijece.v15i4.pp3949-3956.

[6] E. Agyepong, Y. Cherdantseva, P. Reinecke, and P. Burnap, “A systematic method for measuring the performance of a cyber security operations centre analyst,” Computers & Security, vol. 124, p. 102959, Jan. 2023, doi: 10.1016/j.cose.2022.102959.

[7] H. Yaseen and A. Al-Amarneh, “Adoption of Artificial Intelligence-Driven Fraud Detection in Banking: The Role of Trust, Transparency, and Fairness Perception in Financial Institutions in the United Arab Emirates and Qatar,” Journal of Risk and Financial Management, vol. 18, no. 4, p. 217, Apr. 2025, doi: 10.3390/jrfm18040217.

[8] C. D. R. Cevallos Ramos, F. F. Navarrete Chavez, F. R. Marquez Sanay, and M. P. Andrade Romero, “Strengthening cyber resilience in universities using artificial intelligence for proactive threat detection,” Data and Metadata, vol. 4, p. 1109, Jul. 2025, doi: 10.56294/dm20251109.

[9] J. K. Afriyie, K. Tawiah, W. A. Pels, S. Addai-Henne, H. A. Dwamena, E. O. Owiredu, S. A. Ayeh, and J. Eshun, “A supervised machine learning algorithm for detecting and predicting fraud in credit card transactions,” Decision Analytics Journal, vol. 6, p. 100163, Mar. 2023, doi: 10.1016/j.dajour.2023.100163.

[10] J. Forsberg and T. Frantti, “Technical performance metrics of a security operations center,” Computers & Security, vol. 135, p. 103529, Dec. 2023, doi: 10.1016/j.cose.2023.103529.

[11] M. A. Umer, E. G. Belay, and L. B. Gouveia, “Fortifying Industry 4.0: Internet of Things Security in Cloud Manufacturing through Artificial Intelligence and Provenance Blockchain—A Thematic Literature Review,” Sci, vol. 6, no. 3, p. 51, Sep. 2024, doi: 10.3390/sci6030051.

[12] M. Nandy and A. Dubey, “Applications of artificial intelligence to strengthening cyber security for threat detection and response,” in AIP Conference Proceedings, Bangkok, Thailand, 2026, p. 020029, doi: 10.1063/5.0298670.

[13] L. Moura, A. Barcaui, and R. Payer, “AI and Financial Fraud Prevention: Mapping the Trends and Challenges Through a Bibliometric Lens,” Journal of Risk and Financial Management, vol. 18, no. 6, p. 323, Jun. 2025, doi: 10.3390/jrfm18060323.

[14] A. Raj, V. Narayan, V. Muskan, A. Sani, P. Sharma, and S. S. Sarma, “Modern ransomware: Evolution, methodology, attack model, prevention and mitigation using multitiered approach,” Security and Privacy, vol. 7, no. 6, p. e436, Nov. 2024, doi: 10.1002/spy2.436.

[15] G. Zioviris, K. Kolomvatsos, and G. Stamoulis, “An intelligent sequential fraud detection model based on deep learning,” The Journal of Supercomputing, vol. 80, no. 10, pp. 14824–14847, Jul. 2024, doi: 10.1007/s11227-024-06030-y.

[16] G. Zogaj, F. Ismaili, E. Idrizi, and A. Luma, “Statistical Analysis of Unique Web Application Vulnerabilities: A Quantitative Assessment of Scanning Tool Efficiency,” SEEU Review, vol. 20, no. 1, pp. 136–152, Jun. 2025, doi: 10.2478/seeur-2025-0021.

[17] P. Vanini, S. Rossi, E. Zvizdic, and T. Domenig, “Online payment fraud: from anomaly detection to risk management,” Financial Innovation, vol. 9, no. 1, p. 66, Mar. 2023, doi: 10.1186/s40854-023-00470-w.

[18] E. Ukwandu, M. A. Ben-Farah, H. Hindy, M. Bures, R. Atkinson, C. Tachtatzis, I. Andonovic, and X. Bellekens, “Cyber-Security Challenges in Aviation Industry: A Review of Current and Future Trends,” Information, vol. 13, no. 3, p. 146, Mar. 2022, doi: 10.3390/info13030146.

[19] N. Torres Gamarra and M. Zuniga Carnero, “Panorama actual de la ciberseguridad: amenazas, legislacion y brechas estructurales desde una revision sistematica,” Zenodo, Jun. 2025, doi: 10.5281/zenodo.15605545.

[20] E. K. Szczepaniuk and H. Szczepaniuk, “Cybersecurity of Smart Grids: Requirements, Threats, and Countermeasures,” Energies, vol. 18, no. 18, p. 5017, Sep. 2025, doi: 10.3390/en18185017.

[21] H. Santillan, J. A. Arevalo Satan, and P. Wong, “A Comprehensive Analysis of Cybersecurity Infrastructure in Academic Environments,” Ingenieria, vol. 35, no. 1, pp. 11–23, Oct. 2024, doi: 10.15517/ri.v35i1.60075.

[22] V. F. Rodrigues, L. M. Policarpo, D. E. Da Silveira, R. Da Rosa Righi, C. A. Da Costa, J. L. V. Barbosa, R. S. Antunes, R. Scorsatto, and T. Arcot, “Fraud detection and prevention in e-commerce: A systematic literature review,” Electronic Commerce Research and Applications, vol. 56, p. 101207, Nov. 2022, doi: 10.1016/j.elerap.2022.101207.

[23] P. Pittoli, P. David, and T. Noel, “Security architectures in constrained environments: A survey,” Ad Hoc Networks, vol. 79, pp. 112–132, Oct. 2018, doi: 10.1016/j.adhoc.2018.06.001.

[24] S. L. Pauta Ayabaca and J. E. Alvarez Gavilanes, “Uso y necesidad de Tecnologias Emergentes en las empresas cuencanas para el fortalecimiento academico,” Pacha. Revista de Estudios Contemporaneos del Sur Global, vol. 3, no. 9, p. e210123, Sep. 2022, doi: 10.46652/pacha.v3i9.123.

[25] J. R. Orosco-Fabian, “Ciberseguridad en educacion superior: una revision bibliometrica,” Revista Digital de Investigacion en Docencia Universitaria, vol. 18, no. 2, p. e1933, Jul. 2024, doi: 10.19083/ridu.2024.1933.

[26] K. Schroeder, H. Trinh, and V. Y. Pillitteri, Measurement Guide for Information Security Volume 1: Identifying and Selecting Measures, NIST SP 800-55v1. Gaithersburg, MD, USA: National Institute of Standards and Technology, Dec. 2024, doi: 10.6028/NIST.SP.800-55v1.

[27] A. A. George, A. O. Ogundipe, and A. B. Bello, “Cybersecurity in healthcare systems: safeguarding electronic health records (EHRs) and medical devices against emerging cyber threats,” World Journal of Advanced Research and Reviews, vol. 25, no. 2, pp. 2249–2262, Feb. 2025, doi: 10.30574/wjarr.2025.25.2.0592.

[28] W. Khan and N. Ebrahim, “ANOGAT-Sparse-TL: A hybrid framework combining sparsification and graph attention for anomaly detection in attributed networks using the optimized loss function incorporating the Twersky loss for improved robustness,” Knowledge-Based Systems, vol. 311, p. 113144, Feb. 2025, doi: 10.1016/j.knosys.2025.113144.

[29] L. Hernandez Aros, L. X. Bustamante Molano, F. Gutierrez-Portela, J. J. Moreno Hernandez, and M. S. Rodriguez Barrero, “Financial fraud detection through the application of machine learning techniques: a literature review,” Humanities and Social Sciences Communications, vol. 11, no. 1, p. 1130, Sep. 2024, doi: 10.1057/s41599-024-03606-0.

[30] E. A. Fueres Quilumbango, R. O. Andrade Paredes, and M. V. Yamba Yugsi, “Proteccion contra ataques de ingenieria social: analisis cualitativo de estrategias, tecnologias y patrones especificos,” Religacion, vol. 10, no. 44, p. e2501310, Oct. 2024, doi: 10.46652/rgn.v10i44.1310.

[31] S. Chaudhary, V. Gkioulos, and S. Katsikas, “Developing metrics to assess the effectiveness of cybersecurity awareness program,” Journal of Cybersecurity, vol. 8, no. 1, p. tyac006, Jan. 2022, doi: 10.1093/cybsec/tyac006.

[32] D. G. Rosado, L. E. Sanchez, A. J. Varela-Vaca, A. Santos-Olmo, M. T. Gomez-Lopez, R. M. Gasca, and E. Fernandez-Medina, “Enabling security risk assessment and management for business process models,” Journal of Information Security and Applications, vol. 84, p. 103829, Aug. 2024, doi: 10.1016/j.jisa.2024.103829.

[33] K. Bennouk, N. Ait Aali, Y. El Bouzekri El Idrissi, B. Sebai, A. Z. Faroukhi, and D. Mahouachi, “A Comprehensive Review and Assessment of Cybersecurity Vulnerability Detection Methodologies,” Journal of Cybersecurity and Privacy, vol. 4, no. 4, pp. 853–908, Oct. 2024, doi: 10.3390/jcp4040040.

[34] M. Alshomrani, A. Albeshri, A. A. Alsulami, and B. Alturki, “An Explainable Hybrid CNN-Transformer Architecture for Visual Malware Classification,” Sensors, vol. 25, no. 15, p. 4581, Jul. 2025, doi: 10.3390/s25154581.

Publicado

2026-07-15

Cómo citar

Castellares Cuya, E., & Rengifo Espinal, J. (2026). Arquitectura moderna de ciberseguridad para prevención de fraudes en servicios administrativos. International Journal of Computational Innovations, Intelligent Systems and AI, 2(2), 7–25. https://doi.org/10.64439/cisai.v2i2.43

Número

Sección

Artículos Originales