The article is devoted to the solution of the problem of improving computer virus recognition systems. Although the antivirus protection systems have been used for several decades, a lot of highly skilled specialists are involved in their development, and a large number of works are devoted to the creation of the appropriate scientific and methodological base, but practical experience and known cases of successful virus attacks on domestic and foreign computer systems and networks point to the presence in modern antivirus detection of serious shortcomings. It is shown that correcting a number of disadvantages is possible by improving the mathematical support of the recognition procedure due to the use of modern neural network models based on deep neural networks. The method of development of the architecture of the deep neural network intended for the recognition of viruses is proposed. In contrast to the existing method, it is possible to avoid during the development of a neural network model of longterm numerical experiments aimed at determining the appropriateness of its application and optimizing its structural parameters. By numerical experiments using Microsoft's computer virus database BIG-2015 published by Microsoft, it is shown that the method allows constructing a neural network model that provides a recognition error that is commensurate with the error of modern computer virus detection systems. It is determined that the prospects for further research are related to the adaptation of the proposed method to the application of deep neural networks in behavioral analyzers.
The development of information systems in the modern world is inextricably linked with the improvement of destructive software, which is aimed at the various resources of information systems. Among the various ways to influence the user, the most dangerous are those that masking by under the really existing software or web service and are trying to access the personal data of the user, or use its resources or software for fraudulent purposes. The activation of such attacks requires the creation of specialized means of detection and counteraction, which will be equally effective against both present and future cyber threats with unidentified or unclearly defined properties. That is, similar means can function in a fuzzy, poorly formalized environment. Modern methods, models and systems based on fuzzy sets can be used to construct and improve existing tools for detecting intrusions and anomalies in information systems that arise as a result of the implementation of cyber threats. There are a number of developments that are used when they are detected, one of which is the method of forming linguistic etalons for intrusion detection systems. In the described method, the mechanism of the process of forming parameters etalons for email spoofing attacks is not disclosed. With this in mind, a model of linguistic variables etalons was developed for detecting email spoofing attacks, which would formalize the process of obtaining parameter benchmarks. (the number of detected IP addresses in spam bases, the number of spam words in the topic, the number of spam messages in the message) for given linguistic variables of the selected environment when solving problems, in relation to detection of attacks. Similar models can be used to increase the effectiveness of information security measures aimed at countering email spoofing attacks in information systems.
Ongoing advances in information technology affect all areas of society. One of the most promising areas of rapid growth within the field of information security is cyberattack detection and intrusion prevention. Massive cyberattacks initiate the development of specific technical solutions, tools and cyber countermeasures systems. To identify network intrusions, intrusion detection and prevention systems use modern methods, models, tools and integrated technical solutions that can remain effective when new or modified types of cyberthreats occur. In practice, however, with the emergence of new threats and anomalies, these tools do not always remain effective. Thus, intrusion detection systems must be continuously researched and improved. Such systems include specialized software that is designed to detect suspicious activity or information system intrusions and take sufficient measures to prevent cyberattacks. These systems and tools tend to be rather expensive, closed source, and require periodic support from their developers for improvement and appropriate adaptation to certain organizations' environments. Taking into account the results of well-known research, the paper presents a generalized analysis of intrusion detection systems software using a defined basic set of characteristics ("Cyberattack Category", "Adaptivity", "Detection Methods", "System Management", "Scalability", "Observation Level", "Cyberattack Response", "Security" and "Operating System Support"). This will provide the developers and users with certain options when selecting the appropriate modern information systems protection software.
The methods and means of infrasound impact on critical computer hardware infrastructure. It has been shown that a significant threat to critical infrastructure computer systems is caused by the destructive effect of infrasound waves. At the same time, most of the methods of devices: a Helmholtz resonator, generation by using a pulsating sphere such as monopolies, radiator-type rotor resonating cylinder, the sub column method of paired ultrasonic transducers, propeller. The study of these devices. Revealed their characteristic features, advantages and disadvantages. Charting infrasound radiation pattern and a graph of the volume of infrasound radiation from spent power. Also, as a result of the above devices, reasonable set of basic parameters, the values of which make it possible to assess their structural - operational properties. Also, for each of the methods of generation have been calculated approximate values of these parameters, you can go to further research in order to create a system of classification tools for creating vibration exposure devices and the method of choice method of generating infrasound signal, depending on the expected conditions of use and creation.
One of the main obstacles to widespread adoption of neural network methods and models in cyber attacks and detection systems to detect vulnerabilities in the systems resources information systems is the lack of options on which to evaluatetheir effectiveness. Also, there are no methods forassessing the effectiveness and implementation of such. Tosolve this problem has been analyzed a wide range of modern neural network methods and models used in the detection systems. The list of parameters and a method of theiruse for assessing the effectiveness of the design and selectionof these methods and models in the construction of these detection systems. The obtained results allow us to determinethe shortcomings of modern neural network detectiontools and means of cyber vulnerability detection and outlinepromising ways to improve them.
Defined the most effective types of neural networks for identification an “ideal interlocutor” among users of social networks. Analyzed, the possibility of their use due to availability of educational example, which should be the expected value of the output signal. Proposed training of neural networks based on expert knowledge in the form of production rules. Considering the peculiarity of production rules of the particular class “ideal interlocutor”, proposed to modify the classical probabilistic neural network type, by introducing her intermediate filter layer. Considered use of the developed neural network on the practical example of recognition of “ideal interlocutor” among users of social network Facebook to involve distance learning system of Kyiv National University of Construction and Architecture. Conducted experimental research, showed the effectiveness of the developed model of artificial neural network.
Theory of artificial neural networks using is one of the ways to improve the efficiency of attacks detection systems in computer networks. In this paper the method of presentation of expert knowledge in neural mass detection network attacks on computer systems. The feature of the method is the use of production rules and neural network PNN. The results can improve the efficiency of recognition and expand multiple types of network attacks, characteristics of which are registered in the statistics.
The effectiveness of email security is largely dependent on the accuracy of spam detection in leaves and roots. Existing recognition methods based on statistical analysis of text information, which significantly limits their ability to detect new types of spam and leaks. To overcome this shortcoming proposed classification methodology sheets based on semantic analysis using an electronic neural networks. A used as input parameters of the neural network in the frequency of meeting the letter of informative words in canonical form. It is shown that the best type of neural network model is Kohonen map, the main advantage of which is a high-speed training and the possibility of easy visualization of classification. This allows you to quickly react to new spam and howl leaks and conduct a final classification of letters by the user. The experiments confirmed the possibility of increasing the reliability of detection of 20-30%
Розроблено методику визначення оптимальної кількості синаптичних зв’язків та схованих нейронів двошарового персептрону, призначеного для розпізнавання аномальних величин експлуатаційних параметрів комп’ютерної мережі.
Розроблена методика розпізнавання спаму, основою якої є співставлення змісту класифікуємого електронного листа з тематикою спаму та інтересами користувача електронної пошти. Методикою передбачено використання методів реферування при отриманні змістовного навантаження, а також співставлення результатів реферування за допомогою ймовірностної нейронної мережі.