<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Markov Model of Unsteady Profile of Normal Behavior of Network Objects of Computer Systems</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>Al-Farabi Kazakh National University</institution>
          ,
          <addr-line>Almaty</addr-line>
          ,
          <country country="KZ">Kazakhstan</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Kyiv National University of Construction and Architecture</institution>
          ,
          <addr-line>Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Military Academy “General Mihailo Apostolski”</institution>
          ,
          <addr-line>Skopje, North</addr-line>
          <country country="MK">Macedonia</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute”</institution>
          ,
          <addr-line>Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>1946</year>
      </pub-date>
      <fpage>0000</fpage>
      <lpage>0003</lpage>
      <abstract>
        <p>The article is devoted to the ongoing scientific and applied issue on improvement of systems of detection of cyberattacks on network objects of computer systems. Detection systems are considered based on determining the tolerance of deviations of the current values of the controlled functional parameters of the computer system from the profiles of normal behavior. It is established that one of the main disadvantages of network cyberattack detection systems is the imperfection of normal behavior profiles, which are insufficiently adapted to the typical non-stationary nature of the dynamics of the controlled functional parameters. It is proposed to form non-stationary profiles of normal behavior of network objects of computer systems on the basis of multiperiodic Markov model, which allows to take into account the typical nature of the dynamics of functional parameters that reflect the state of security of network objects of computer systems. The peculiarity of the model is the modeling of each of the stationary sections of the dynamics of the functional parameter using a homogeneous Markov chain with successive transitions. It is experimentally established that the application of the developed multiperiodic model allows to increase the accuracy of forecasting the dynamics of functional parameters up to 2 times. Moreover, it is shown that the prospects for further research are associated with the development of methods for applying the solutions of the theory of spectral analysis of data to determine the significant periods of the process of changing functional parameters.</p>
      </abstract>
      <kwd-group>
        <kwd>recognition of network cyberattacks</kwd>
        <kwd>normal behavior profile</kwd>
        <kwd>Markov's model</kwd>
        <kwd>dynamics of functional parameters</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>The importance of improving the means of recognizing network cyberattacks is
increasing due to the constant danger of cybercrime, the dynamic growth of various and
diverse cyber threats, and the increase in the complexity and responsibility of
computer networks (CN) [1, 5, 11]. The basis of these tools is the data analysis module,
the main task of that is to generate a decision on the presence or absence of a
cyberattack on the object of protection at a given time [8, 10, 16]. It is generally recognized
that one of the most promising areas for improving the quality of data analysis is the
use of the anomaly detection method in recognition systems. An important advantage
of this method is the ability to recognize new types of attacks with unknown
signatures. In this case, the work of data analyzers is based on the assumption that the sign
of a network cyberattack is a deviation of the specified parameters of the CN from the
so-called normal behavior profile (NBP). Although a lot of scientific and practical
works are devoted to the development of NBP, however, successful attempts of
network attacks on a number of domestic and foreign institutions indicate the need for
their significant improvement, which explains the relevance of research in this
direction.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Literature Review and Problem Postulation</title>
      <p>As evidenced by the literature review, control cards Shuhart, EWMA, CUSUM,
simulation and neural network models mainly used for the construction of modern PNP, as
well as models based on classical methods of statistical analysis [5, 6, 18, 19]. It
should be noted that in most cases, these profiles describe the dynamics of the
functional parameters of the CN. The method and experimental system of detection of
attacks on resources of CN is developed in work [9]. The method uses the patterns of
normal behavior based on the simulation model of the functioning of network objects
of CN. It should be mentioned that the construction of this simulation model for real
CS is associated with great difficulties. The aim of the work [1] was to develop a
mathematical model of CS network behavior and a method of anomaly detection
based on the statistical study of changes in the characteristics of this system. This
paper proposes to divide the entire space of the performance on the indicators
characterizing the use of local system resources and indicators of interaction with the outside
world. The introduced mathematical model based on the assumption the use of the
sample homogeneity criterion to identify anomalies. In addition, the literature review
allows us to determine that the methods of statistical data processing can be
additionally used to clarify the obtained NBP. Thus, the article [4] describes the process of
developing templates for fixing abnormal behavior of CN on the basis of BDS-tests. It
is argued that such tests are effective methods for identifying dependencies in time
series in the framework of their nonlinear analysis and have been widely used for
analysis of financial markets. In the article the mathematical apparatus of testing is
developed, and the results of numerical experiments are shown, confirming the
possibility of using such templates to define the malicious software by heuristic analyzers.
Article [13] is devoted to the development of adaptive patterns of fixation of
abnormal behavior of CN. The fact of possibility of use for these purposes of control cards
of Shuhart is confirmed. For the development and experimental studies, a software
model has been developed that allows to obtain a database of CN state templates and
to fix abnormal behavior of network objects. The possibility of using the developed
adaptive patterns in heuristic analyzers of intrusion detection systems is stated.</p>
      <p>However, as studies have shown, these means of forming patterns are not devoid of
a number of drawbacks. SO EWMA control cards are insensitive to short
manifestations of anomalies. At the same time, CUSUM maps detect small but constant
changes with a higher probability but have low accuracy (high probability of false positives)
under dynamic changes in the computer system display [2-5]. The analyzed patterns,
which are based on classical methods of statistical analysis, are characterized by a
high level of false positives when used in local networks, where the behavior of
objects does not have a smooth, averaged character [8, 10]. Based on authors view, it is
possible to eliminate these shortcomings by using the theory of Markov processes,
which is successfully used to build statistical models of complex processes [7]. It
should be noted that the expediency of using Markov chains in the field of recognition
of cyberattacks has already been proved in the works [9, 19, 20]. Thus, the work [9] is
devoted to the use of hidden Markov chains for modeling the mental state of the CN
operator in the implementation of cyberattacks. The paper [14] describes in detail the
methodology of CN protection based on the game theory using the Markov model.
The possibility of choosing the most effective protection strategy is shown in the
precases of a certain time window. A similar problem is considered in work [15], where
the Markov model is developed to determine the strategy of protection of a moving
target. In work [17] the algorithm of step-by-step detection of attacks on a computer
network on the basis of the hidden Markov model is offered. In work [20] the
possibility of formation of templates of normal behavior of network objects of CN on the
basis of a homogeneous Markov chain with consecutive transitions is proved. It is
determined that for the formation of patterns of normal behavior it is advisable to use
a Markov chain with the number of States equal to 20. The graph of process
transitions is developed, the corresponding mathematical support allowing to calculate the
basic parameters of the Markov link underlying the specified template is formed. The
results are experimental, confirming the effectiveness of the developed Markov model
for conditionally stationary dynamics of controlled parameters of protection.
Moreover, the expediency of further studies in the field of justification of the nomenclature
of controlled parameters and adaptation of the Markov model of the typical
nonstationary nature of the functional parameters of the CN is shown. It should be noted
that the possibility of creating a Markov model of unsteady NBP is confirmed in
theoretical works devoted to the Markov approximation of multiperiodic unsteady
processes [7, 19].</p>
      <p>Thus, as a result of the analysis of scientific and practical works [2-4, 7-17, 19, 20],
the prospects of using Markov chains for the formation of NBP are determined. In
addition, it is shown that the known mathematical models of NBP do not fully
consider the typical non-stationary nature of the dynamics of the functional parameters of
network CN.
3</p>
    </sec>
    <sec id="sec-3">
      <title>Purposes and Objectives of the Study</title>
      <p>The main purpose of this study is to develop a Markov model of the non-stationary
profile of the normal behavior of network objects of computer systems, which is
adapted to the typical non-stationary nature of the dynamics of the auxiliary
parameters of such objects.
4</p>
    </sec>
    <sec id="sec-4">
      <title>Development of the Markov model</title>
      <p>In the construction of the Markov model, the position of the theory of dynamic data
series is used, according to which the multiperiodic NBP can be represented as a sum
of single-period profiles. The graph of single-period NBP is shown in Fig. 1, and the
graph of multiperiodic PNP is shown in Fig. 2.</p>
      <p>The actual NBP corresponds to the function X=f(t). In Fig. 1, the letters A and B
denote the transition (extreme) points of the function X=f (t)., the maxima of the
function are denoted as A2, A4, ... AD, and the minima as B1, B2, ... BD-1. Indices 1,2, ... D
correspond to the numbers of transition points. At intervals of type Bd Ad 1 and
Ad 1Bd 2 single-period NBP has a stationary character. On intervals of type Bd Ad 1
the function X=f (t) increases, and on intervals of type Ad 1Bd 2 the function X=f (t)
decreases.</p>
      <p>
        According to theoretical studies in the field of the theory of Markov processes, the
basis of NBP on a stationary interval of the dynamics of operational parameters of CN
is a homogeneous Markov chain described by a system of Kolmogorov-Chapman
equations and a normalization condition that can be written using expressions:
P1(t)  P1(t 1)  P1(t 1) p1,i ...  P1(t 1) p1,N  Pi (t 1) pi,1...  PN (t 1) pN ,1
 

Pi (t)  Pi (t 1)  Pi (t 1) pi,1...  Pi (t 1) pi,N  P1(t 1) p1,i ...  PN (t 1) pN ,i
 
PN (t)  PN (t 1)  PN (t 1) pN ,1...  PN (t 1) pN ,i  P1(t 1) p1,N ...  Pi (t 1) pi,N
N
 Pi (t)  1
i1
, (
        <xref ref-type="bibr" rid="ref1">1</xref>
        )
(
        <xref ref-type="bibr" rid="ref2">2</xref>
        )
where Pi(t) is the probability of finding the functional parameter in the i-th state at
time t[0, tmax], pi,j - is the probability of transition from state i to state j in one step
of the process, N is the number of States of the Markov chain.
      </p>
      <p>If we accept the postulate that at the initial moment of time the simulated
parameter is in the first state of the Markov chain, then the initial conditions of modeling can
be written as follows:</p>
      <p>
        P1(0)  1
(
        <xref ref-type="bibr" rid="ref3">3</xref>
        )
      </p>
      <p>The disadvantages of the described Markov chain is the complexity of the
calculation of transition probabilities, which is determined primarily by the fully connected
character of possible transitions of the process by states.</p>
      <p>
        Therefore, based on the results of [7, 8, 19], the assumption is made about the
possibility of using a Markov chain in which only successive transitions are possible
between states, the number of which is equal to 10. At the same time, the accuracy of
the model remains sufficient for the task of forming the NBP. Due to the accepted
simplification, expression (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) is modified as follows:
P1(t)  P1(t 1)  P1(t 1) p1,2  P2 (t 1) p2,1
 

Pi (t)  Pi (t 1)  Pi (t 1) pi,i1  Pi1(t 1) pi1,i
 
PN (t)  PN (t 1)  PN (t 1) pN ,N 1  PN 1(t 1) pN 1,N
where N =10 is the number of states of the Markov chain.
      </p>
      <p>
        In case of approximation of dynamics of operational parameters of computer
networks it is recommended that the states with numbers from 1 to (N-1) correspond
to such values of parameters at which the software and hardware of a network will be
in a working state, and the N-th state corresponds to a non-working state 7. In a
one-sided region of operability, the first (N-1) states will be defined by the lower and
upper bounds, and the last N state by the lower bound only. Using the procedure of
uniform quantization of the region of operability, the state boundaries are defined as
follows:
(
        <xref ref-type="bibr" rid="ref5">5</xref>
        )
(
        <xref ref-type="bibr" rid="ref6">6</xref>
        )
(7)
(8)
(9)
      </p>
      <p>Lbi    i ,
Lei    (i 1) ,
  L N  1,
L  Lb  L ,
e
where , Lbi , Lei is the upper and lower bound of the i-th state,  –is the width of the
state, L –- width of the region of operability, Lb , Le - upper and lower limit of the
region of operability.</p>
      <p>An illustration of the described quantization procedure is Fig. 3, which shows
graphs of the dynamics of some operational parameter X for the same type of
controlled objects. In Fig. 3, the following notations are accepted: tk – moments of
registration; 1...N – numbers of states of a Markov chain; ni – borders of states; O1, O2,
O3, O4, O5 -realizations of X. The calculation of the probabilities of transition of the
controlled parameter from state i to state j in one step of the process is implemented
as follows:
p(tk )i1,i  R(tk )i / R(tk )r ,</p>
      <p>I
pi1,i   p(tk )i1,i / I , (10)</p>
      <p>i1
where p(tk)i-1,i – is the probability of transition between (i-1)-th and i-th state in one
step of calculation of Markov chains R(tk)i – the number of controlled objects that are
moved from (i-1)-th to i-th state for the time interval tk, which corresponds to one step
of the Markov chain. R(tk)r –– the total number of operable objects at the time tk, pi-1,i
-the probability of transition between (i-1)-th and i-th state, I-the number of
registrations of the parameter.</p>
      <p>Fig. 3. The graphs of dynamics of values of operational parameter for controlled
objects</p>
      <p>
        In the simplest case, to simulate one period of a single-period process of changing
the operational parameter X, the graph of which is shown in Fig. 3, the model will
consist of two homogeneous Markov chains given by expressions (
        <xref ref-type="bibr" rid="ref2 ref3 ref4">2, 3, 4</xref>
        ). The first
circuit is designed to simulate the AB section, the second-for the BC section. In this
case, the probabilities of the first Markov chain at time B are the initial distribution of
the form (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) for the second Markov chain.
      </p>
      <p>For a two-period process, the graph of which is shown in Fig. 4, the Mars model
will be more complex. In such a model, it is necessary to consider that the BF section
is non-stationary only in the CE section. In this case, the half-periods CD and DE are
nested in the half-period BF.</p>
      <p>Fig. 3. The half-life graph of a single-period process
To construct a multiperiodic Markov model, the authors developed an approach based
on the Markov model described in [19, 20] of a one-periodic nonstationary NBP
process X  f t , which increases sequentially at stationary intervals of
type Bd Ad 1 and decreases at stationary intervals of type Ad 1Bd 2 , where d is the
number of the transition point (see Fig. 1). The Markov model of one-period NBP
M BAB</p>
      <p>consists of two homogeneous Markov chains M BA and M AB , designed to
simulate the dynamics of functional parameters at stationary intervals of type Bd Ad 1
and Ad 1Bd 2 . By analogy with [2, 3] in the model of multiperiodic NBP, it is also
assumed that each of the stationary sites is modeled by its own homogeneous Markov
chain. For example, the NBP of a two-period process, the graph of which is shown in
fragments in Fig. 4, a sequential simulation of each of the stationary intervals AB,
BC, CD, DE, and EF is provided by a proper homogeneous Markov chain. As for the
case of a one-period NBP, the finite probability distribution of the stay of the previous
Markov chain is the initial conditions for the subsequent chain.. Thus, the Markov
model of multiperiodic NBP M BAB , the structure of which is shown in Fig. 5,
consists of modules M B1AB , M B2AB ,..., M BKAB designed to simulate K significant periods
of the dynamics of the functional parameter under study. In this case, an arbitrary
Kth module M BkAB is a Markov model of a one-period NBP developed in [19, 20],
designed for modeling the k-th periodic component. In turn M BkAB , it consists of two
LM- M BkA and M AkB , designed to model the k-th periodic component of the NBP..
The output of the k-th module</p>
      <sec id="sec-4-1">
        <title>M BkAB at the τ -th step of the calculation is</title>
        <p>
          Pk  the probability distribution vector for the k-th periodic component of the
NBP. The number of states and state boundaries of the Markov chain of each of the
modules should be calculated individually using the expressions (
          <xref ref-type="bibr" rid="ref5 ref6">5-8</xref>
          ). Also, the
values of transition probabilities should be calculated separately for each Markov chain.
For this purpose, it is possible to use expressions (9, 10), having modified them a little
for processing of statistics on the corresponding interval of functioning (half-life):
pz (tk )i1,i  Rz (tk )i /Rz (tk )r  tk ,
        </p>
        <p>I z
pz,i1,i   pz (tk )i1,i / I z ,</p>
        <p>i1
where z is the half-period in question.</p>
        <p>Other symbols (11, 12) correspond to expressions (9, 10).
where Pik   is the probability of the functional parameter staying in the i-th
state of the K-th Markov chain at the τ-th calculation step.</p>
        <p>Using the proposed Markov model, the software package MarkPr was developed,
which allows to simulate Markov processes of various types. So, in Fig.6 shows the
simulation results of a two-period Markov process with 10 states. The graph shown in
Fig. 6. corresponds to the mathematical expectation of the controlled parameter.
The output of the model M BAB at the τ t-th step of calculation is the probability
distribution vector of the form:</p>
        <p>P </p>
        <p>P, P2,..., P ,
1 N
where P  is the integral probability of finding the parameter in the i-th state
i
of the Markov chain at the τ -th step of the calculation.</p>
      </sec>
      <sec id="sec-4-2">
        <title>P  it is calculated as follows:</title>
        <p>i
(13)
(14)</p>
        <p>
          On the basis of the described Markov model, given by the expressions (
          <xref ref-type="bibr" rid="ref2 ref3 ref4 ref5 ref6">2-14</xref>
          ), a
two-period NBP of a Web server is developed. Statistical data were used to construct
the model [19, 20]. The simulation was carried out using the mentioned MarkPr
program. As a security parameter, the number of web server accesses per 1 minute is
used. The simulation results are partially presented in Fig.7, on which 1 denotes a
graph based on statistical data, 2 If based on a one-period model [20], and 3 based on
the proposed two-period model.
        </p>
        <p>Fig. 7. The graphs of the dynamics of the mathematical expectation of the number of
requests</p>
        <p>It is important to mention that for a one-period model, the average modeling error
is 0.09 [19-22], for a two - period (author's) model-0.04, and for common polynomial
models [1, 4] - 0,140,18. Therefore, the application of the proposed two-period
model allowed to reduce the error of modeling with respect to the one-period model
by about 2 times, and with respect to common polynomial models-by about 4 times.
Consequently, the results of the experiments confirm the effectiveness of the
proposed two-period Markov model of NBP. At the same time, the issue of determining
the number of significant periods that need to be taken into account in the NBP
remains unresolved. Based on the results [12], it can be assumed that this deficiency can
be corrected by using the theory of spectral analysis of data.
5</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>Conclusion</title>
      <p>As a result of the conducted researches, it is justified expediency forming of
multiperiodic profiles of normal behavior of network objects of computer systems on the
basis of a Markov chain with consecutive transitions is proved. The developed
Markov model of the non-stationary profile of normal behavior allows to consider the
typical multi periodic nature of the dynamics of functional parameters, which reflect
the state of security of network objects of computer systems. As a result of
experimental studies, it was found that the application of the developed multiperiodic model
allowed to increase the accuracy of forecasting the dynamics of functional parameters
up to 2 times relative to the best known models of similar purpose. It is shown that the
prospects for further research are associated with the development of methods for
applying solutions of the theory of spectral analysis of data to determine the
significant periods of the process of change of functional parameters.
ence for Engineering and Education II. ICCSEEA 2019. Advances in Intelligent
Systems and Computing, vol 938. Springer, Cham. Pages 3-12.
7. Ignatov V.A., Manshin G.G., Traynev V.A. Statistical optimization of the quality
of functioning of electronic systems. M .: Energy, 1974, 264 p. (In Russian).
8. Gavrilenko S.Yu., Gornostal A.A. Development of adaptive patterns for fixing
abnormal behavior of a computer system. Information Processing Systems, 2016,
issue 3. p. 11-14.
9. Gamayunov D. Falsifiability of network security research: The good, the bad, and
the ugly. In Proceedings of the 1st ACM SIGPLAN Workshop on Reproducible
Research Methodologies and New Publication Models in Computer Engineering,
TRUST ’14, pages 4:1–4:3. ACM New York, NY, USA, 2014.
10. Gnatyuk S. Critical Aviation Information Systems Cybersecurity, Meeting
Security Challenges Through Data Analytics and Decision Support, NATO Science
for Peace and Security Series, D: Information and Communication Security.
IOS Press Ebooks, Vol.47, №3, рр. 308-316, 2016.
11. Gnatyuk S., Sydorenko V., Aleksander M. Unified data model for defining state
critical information infrastructure in civil aviation, Proceedings of the 2018 IEEE
9th International Conference on Dependable Systems, Services and Technologies
(DESSERT), Kyiv, Ukraine, May 24-27, 2018, pp. 37-42.
12. Hu, Z., Tereikovskyi, I., Tereikovska, L., Tsiutsiura, M., Radchenko, K. Applying
Wavelet Transforms for Web Server Load Forecasting. Advances in Computer
Science for Engineering and Education II. ICCSEEA 2019. Advances in
Intelligent Systems and Computing, vol 938. Springer, Cham. Pages 13-22.
13. Kuznetsov G.V., Ivanov A.M. Data analysis methods for detecting attacks in
computer systems and networks of banking structures. - K .: Inf. security. Sat.</p>
      <p>
        NAU, 2004, S. 45-50.
14. Liu, S.-Z., Liao, Z.-F., Hu, J., Fan, X.-P. (2014) Classified time homogeneous
Markov model for recommendation based on implicit feedback Tien Tzu Hsueh
Pao/Acta Electronica Sinica 42(
        <xref ref-type="bibr" rid="ref4">4</xref>
        ), pp. 703-710.
15. Mustafayev AG (2016) Neyrosetevaya sistema obnaruzheniya komp'yuternykh
atak na osnove analiza setevogo trafika. Voprosy bezopasnosti, 2:1-7. Access
mode: URL: http://nbpublish.com/library_read_article.php?id=18834 (reference
date: August 22, 17).
16. Pavlov D., Chertov O. (2019) How Click-Fraud Shapes Traffic: A Case Study. In:
Chertov O., Mylovanov T., Kondratenko Y., Kacprzyk J., Kreinovich V.,
Stefanuk V. (eds) Recent Developments in Data Science and Intelligent Analysis of
Information. ICDSIAI 2018. Advances in Intelligent Systems and Computing, vol
836. Springer, Cham
17. Penagarikano, M., Bordel, G. (2004) Layered Markov models: A New
architectural approach to automatic speech recognition. Machine Learning for Signal
Processing XIV - Proceedings of the 2004 IEEE Signal Processing Society
Workshop pp. 305-314.
18. Taran, V., Gordienko, N., Kochura, Y., Gordienko, Y., Rokovyi, A., Alienin, O.,
Stirenko, S.: Performance evaluation of deep learning networks for semantic
segmentation of traffic stereo-pair images. In: Proceedings of the 19th
International Conference on Computer Systems and Technologies, pp. 73–80. ACM,
September 2018.
19. Yu. Danik, R. Hryschuk, S. Gnatyuk, Synergistic effects of information and
cybernetic interaction in civil aviation, Aviation, Vol. 20, №3, рр. 137-144, 2016.
20. Tereikovskiy, I., Parkhomenko, I., Toliupa, S., Tereikovska, L. Markov model of
normal conduct template of computer systems network objects // 14th
International Conference on Advanced Trends in Radioelectronics, Telecommunications
and Computer Engineering, TCSET 2018 – Proceedings. pp. 498 – 501.
21. A. Tikhomirov, N. Kinash, S. Gnatyuk, A. Trufanov, O. Berestneva et al,
Network Society: Aggregate Topological Models, Communications in Computer and
Information Science. Verlag: Springer International Publ, Vol. 487, рр. 415-421,
2014.
22. Toliupa, S., Tereikovska, L., Toliupa, S., Tereikovska, L., Korystin, O.,
Nakonechnyi, V. One-periodic template marks model of normal behavior of the
safety parameters of information systems networking resources // 2019
International Scientific-Practical Conference Problems of Infocommunications. Science
and Technology, PIC S&amp;T′2019. 08-11 October 2019 Kyiv, Ukraine, pp. 774 –
779.
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Baranov</surname>
            <given-names>P. A.</given-names>
          </string-name>
          <article-title>Detection of anomalies based on an analysis of the uniformity of parameters of computer systems: the dissertation</article-title>
          ...
          <source>Candidate of Technical Sciences: 05.13.19 St. Petersburg</source>
          ,
          <year>2007</year>
          155 p.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Choudhury</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mandal</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Prasanna</surname>
            ,
            <given-names>S.R.M.</given-names>
          </string-name>
          <article-title>Comparative study of Markov Model based synthesis and recognition systems</article-title>
          . (
          <year>2017</year>
          ). IEEE Region 10 Annual International Conference, Proceedings/TENCON pp.
          <fpage>272</fpage>
          -
          <lpage>276</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Choudhury</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mandal</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Prasanna</surname>
            ,
            <given-names>S.R.M.</given-names>
          </string-name>
          <article-title>Comparative study of Markov Model based synthesis and recognition systems</article-title>
          . (
          <year>2017</year>
          ). IEEE Region 10 Annual International Conference, Proceedings/TENCON pp.
          <fpage>272</fpage>
          -
          <lpage>276</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <article-title>Design templates for identification state of computer systems are based on BDStest / Semenov S</article-title>
          .G,
          <string-name>
            <given-names>S.</given-names>
            <surname>Yu. Gavrilenko</surname>
          </string-name>
          ,
          <string-name>
            <surname>V.</surname>
          </string-name>
          <article-title>V Chelak // Herald of the National Technical University "KhPI"</article-title>
          .
          <source>Subject issue: Information Science and Modelling. - Kharkov: NTU "KhPI"</source>
          . -
          <fpage>2016</fpage>
          . - No
          <volume>21</volume>
          (
          <issue>1193</issue>
          ).
          <source>- Р</source>
          .
          <fpage>118</fpage>
          -
          <lpage>127</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Dychka</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tereikovskyi</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tereikovska</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pogorelov</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mussiraliyeva</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          (
          <year>2018</year>
          ),
          <article-title>Deobfuscation of computer virus malware code with value state dependence graph</article-title>
          ,
          <source>Advances in Intelligent Systems and Computing</source>
          , pp
          <fpage>370</fpage>
          -
          <lpage>379</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Dychka</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chernyshev</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tereikovskyi</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tereikovska</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pogorelov</surname>
          </string-name>
          , V.
          <source>Malware Detection Using Artificial Neural Networks Advances in Computer Sci-</source>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>