期刊名称:Eastern-European Journal of Enterprise Technologies
印刷版ISSN:1729-3774
电子版ISSN:1729-4061
出版年度:2016
卷号:6
期号:9
页码:32-44
DOI:10.15587/1729-4061.2016.85600
语种:English
出版社:PC Technology Center
摘要:The paper presents results of the research aimed at the further development of models for the intelligent systems of recognition of cyber threats, anomalies and cyber attacks.A structural scheme of adaptive expert system (AES) of information security, capable of self-learning, is proposed, which takes into account potential errors of the third kind, which may arise and accumulate while training a system of intelligent detection of complex targeted cyber attacks and preliminary process of splitting a space of attributes of the objects of recognition. We developed a model for calculating information criterion of functional effectiveness, based on entropic and distance criteria of Kullback-Leibler in the course of clustering the attributes of objects of recognition in computer systems, which allows obtaining input fuzzy classification training matrix. A procedure for the operation of AES as an element of the system for intelligent recognition of cyber threats (SIRCT) was explored in the training mode by a priori classified training matrix that allowed us to build correct decisive rules for the recognition of cyber attacks.We designed AES "Threat Analyzer" and conducted its test research under conditions of real CoS performance at several enterprises. It was found that the proposed model of AES learning makes it possible to achieve results of the recognition of the standard classes of cyber attacks at the level from 76.5 % to 99.1 %, which is at the level of recognition effectiveness by the best hybrid neural networks and genetic algorithms.
关键词:recognition of cyber attacks;expert system;clustering of attributes;functional effectiveness