<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Application of Multifactor Analysis for the Purpose of Detecting Malicious Software Implants of the Software in Local Computer Networks</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Vadym Paiuk</string-name>
          <email>vadympaiuk@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Olena Geidarova</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Kosenkov</string-name>
          <email>vladimirkosenkov@ukr.net</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Savenko</string-name>
          <email>savenko_oleg_st@ukr.net</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andrii</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Nicheporuk</string-name>
          <email>andrey.nicheporuk@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Khmelnytskyi National University</institution>
          ,
          <addr-line>Instytutska str., 11, Khmelnytskyi, 29016</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>A study of the detection of harmful implants in software. They can be of two types. In particular, in the first case, malicious implants in the software may be independent entities, and in the second case, they may be part of certain malicious software. Other cases are not considered in the work. The selected information systems of the network type, which operate in local computer networks, were selected for the study. Accordingly, the presence of harmful implants in the software is considered in local computer networks. The difficulty of detecting such harmful implants in the software lies in its ability to be in a latent state. Such a secretly included in the form of a module in the software under certain conditions can provide unauthorized access to attackers. Functionally and physically as such an object can be part of a software package. He performs the task. In addition, it can completely replace certain parts of the software. Or it can replace a certain program completely. The difficulty in detecting such malicious implants in software is that, for the most part, they make it possible to maintain the functions of useful software even when available. These functions were in the terms of reference for the project and they were required by the manufacturer. As a result, important software features are included in the system, but they are only part of it, not all. To solve such a scientific problem, it is proposed to use the methods of multifactor analysis. Their use will indicate the presence of more important factors. This allows you to apply the results to malware implants and they may be part of some malware. The implementation of multifactor analysis methods is carried out in a network distributed malware detection system. This implementation allows you to use a ready-made system, which is tested, and add to it several methods aimed at detecting software implants. In general, this increases the reliability of detection by this system. On the other hand, it provides an opportunity to focus only on the added detection methods, as the distributed system has already been tested using other methods. In the considered scientific problem we will use a taxonomic indicator for comparison of objects in which there is a large number of signs. That is, it can be an indicator of the presence of software implants in the software on the local network. To identify it, the application of the taxonomic method of processing statistical data of observations will allow to detect it with a certain degree of reliability. As objects of analysis, software that operates on local computer networks. To confirm the proposed solutions, an experiment was performed with a distributed detection system, which implemented methods of multifactor analysis. The result of an experiment to identify software implants in software confirmed the viability of research and proposed solutions.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Software implant</kwd>
        <kwd>multifactor analysis</kwd>
        <kwd>malicious software</kwd>
        <kwd>local computer network</kwd>
        <kwd>distributed detection system</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>The use of modern information technologies in various fields is growing. This use of information
technology greatly simplifies many processes that required significant human resources. At the
expense of such technologies automation of many links of technological processes of information
processing is carried out. In addition, the new paradigm in the industry, which is based on the
development of Industry 4.0 and the active involvement of information technology in all possible
areas of human life and production, affects the positive dynamics of development. But in parallel with
these processes, there are many attackers who, using weak links in the protection of such
technologies, try to benefit. Therefore, the use of information technology, which does not address the
protection of information flows and information, encourages malicious activity. Of particular interest
to attackers are the banking sector, various financial institutions and industries. Therefore, the focus
on the organization of detection of malicious actions requires primarily organizations (enterprises)
that use information technology. Because they are important objects of profit from the point of view
of malefactors.</p>
      <p>Intruders access to corporate computer network resources can be software implants that are
embodied in the software and hardware of computers and peripherals. They allow you to hide
unauthorized access to resources. This can be done mainly through a local computer network.</p>
      <p>The object of detection will be considered a software implant [1]. Its location will be considered
local computer networks of enterprises. Software implants may not show up for a long time. This
significantly complicates their detection. At the initial stage of commissioning by the software
developer, checking it for the presence of software implants may be unsuccessful. That is, software
implants may not be detected. This will create a problem in the future when using such software. But
even if the software implant is not detected, it still has to manifest itself in a certain way, because it
must communicate with certain network resources to maintain its activity and receive commands from
them. If he did not communicate, then the attackers would not know where he is physically, at what
addresses and so on. This activity of the software implant will lead to certain signs of its
manifestation, which will change certain factors.</p>
      <p>Software implants can store functions that are declared by the manufacturer, and they are
implemented as part of the functions that are part of the software package. That is, the functions of the
implant can also use the functions of a specific purpose of the software that is put into operation. This
indicates the possibility of dual use of functions, which complicates the search for program implants.</p>
      <p>Such a scientific problem is really relevant. To solve it, it is necessary to develop a mathematical
apparatus and implement it in the methods of detecting software implants in software in computer
networks.</p>
      <p>Such an object can be part of a software package that performs tasks, replace completely certain
parts of the software package, replace a certain required program.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Related works</title>
      <p>Detection of software implants in local computer networks is carried out by various methods and
means. They depend on the specific types of malware. When software implants are detected, there is a
discrepancy between the results of software testing and the processes that may actually be caused by it
[1]. To hide software implants, attackers have developed many approaches, algorithms, techniques
and methods.</p>
      <p>Malware-related security breaches damage users by at least $ 500 billion annually [1].</p>
      <p>The number of malicious programs and their varieties is growing every year [2]. Attackers direct
their funds to organizations and enterprises that work with information technology in local computer
networks, because the financial and economic spheres motivate them the most.</p>
      <p>There are many ways to penetrate the local networks of organizations and enterprises, some of
which are described in [3-7]. The paper analyzes the strategy of an attacker to use a software implant,
which is based on the use of software implants in computer software and peripherals.</p>
      <p>The purpose of their strategy is for attackers to gain unauthorized access to system resources
through the local network. The software implant in the work is considered as a secretly implemented
program or software module. It is embodied in the software and as a result poses a threat to the
information contained in the computer [8].</p>
      <p>The paper considers as the object of study software implants that use the capabilities of software in
local computer networks of enterprises that are malicious. There is a difficulty in identifying such a
secretly operating software implant, because it does not appear during testing. Software developers
embody them in useful software applications, mixing functions. But under certain conditions, such
software implants can provide unauthorized access to the resources of entrepreneurs. In addition,
software implants can be inactive for a long time, which makes them difficult to detect. Such software
implants retain software functions. They can be implemented by some other functions that are part of
the software package [9-12]. Such strategies are also implemented by well-known Trojan programs.
But the object of study is such programs or program modules that are used in organizations, which are
introduced by software developers when creating them for malicious use. Their hiding in the
programs was carried out when handing over the finished software to the customer. Part of such a
software implant in programs may be related to malicious programs such as Backdoor [9-12], and part
provides other, than malicious programs such as Backdoor implementation mechanisms.</p>
      <p>The analysis of hidden possibilities of modules in the developed software is paid attention in
works [13-18].</p>
      <p>Malicious software is a malicious tool that launches a secret sharing feature. The structure and
internal algorithms of such a hidden function are given in [16]. To solve this problem, an algorithm
for detecting a hidden function was developed in [17].</p>
      <p>Models of hidden schemes of exchange of functions are developed in scientific article [18]. They
are designed with a secure distributed data protocol.</p>
      <p>In [19], the authors proposed a new method of detecting malware such as Backdoor. Artificial
neural networks and object classification were used for this purpose.</p>
      <p>The main disadvantage of this solution is a small set of proven and reliable data sets [19]. This
may affect its adequacy and viability.</p>
      <p>The model used by attackers is presented in a scientific paper [20]. It is used to hide the ways of
invasion. The authors explored the possibility of using this approach to detect other types of malware,
including Backdoor.</p>
      <p>In [21], one of the methods of encoding code fragments with the help of specially designed
interrupts is analyzed and substantiated, which manipulate the state of execution time when triggered
and under certain conditions can continuously perform arbitrary calculations.</p>
      <p>Problems of formalizing a terminal machine by modeling a program or system using a so-called
machine with a marked final state are proposed in a scientific paper in [22]. This allows you to
consider the software product as an emulator.</p>
      <p>The complexity of this problem is analyzed using many tools in [23, 24]. For example, you can
consider a hardware component, a special program, or malware. And this is a pre-necessary method of
developing methods for their detection.</p>
      <p>In works [25-27] special narrowly specialized approaches to detection of hidden software are
considered. The considered methods are focused on information protection.</p>
      <p>An active type of malware that can implant software implants are botnets [28-32]. In [28-31] the
technique of detection of botnets on the basis of DNS-traffic is presented. Detect botnets based on a
bot group activity property in DNS traffic that appears after a short period of time in host group DNS
queries when trying to access C&amp;C servers, migrate, run commands, or download malware updates.
In [28], a method of protection against DNS evasion for detecting botnets in corporate networks is
proposed.</p>
      <p>One of the main elements that can be used to detect program implants are the functions of the
application programming interface. These functions can be analyzed dynamically, as presented in
[3334]. Attackers often use the obfuscation function to mask malicious code. One of the most difficult to
detect is the function of metamorphic transformation [35]. In [35] it is shown how the use of
metamorphic transformations makes it possible to hide the program codes of functions.</p>
      <p>In [36-38] the use of baits to detect abnormal and malignant manifestations was analyzed. The
obtained results have shown their effectiveness and can be used in the detection of software implants.</p>
      <p>The use of known mathematical methods for processing various events that are associated with the
operation of software is presented in scientific papers in [39-47]. The considered methods can be used
to identify software implants. The method of multifactor analysis for the detection of software
implants in a local computer network is presented in [43]. The basis of this method is a taxonomic
method of processing statistical data of observations, which is used in studies of various subject areas
[44, 45].</p>
      <p>The various methods used for the detection process require the initial stages of data preparation for
processing, the purpose of which is to develop a comprehensive approach to the detection of software
implants. The scientific task of detecting software implants in local networks is relevant and
promising. One of the tasks that needs to be solved is to develop appropriate methods for creating
effective system components for detecting software implants in local networks based on the search for
abnormal manifestations, taking into account multifactor analysis.</p>
    </sec>
    <sec id="sec-3">
      <title>3. The Approach to Application of Multifactor Analysis for the Purpose of</title>
    </sec>
    <sec id="sec-4">
      <title>Detecting Malicious Software Implants in Local Computer Networks</title>
      <p>In our case, the objects are computer networks, and the signs may be [30, 31]: the presence of
software modules that do not meet the purpose of the process; the presence of files related to
operating systems, and which form open processes that do not meet the purpose of the process; there
is a high intensity for I / O operations from a certain process, and so on. (11 signs are given, although
their number may be higher).</p>
      <p>The basis for research is a matrix of observations X:</p>
      <p> ...</p>
      <p>X = 
 xi1
 x11

 x21
 ...

xω1
where xik is the number of manifestations of the k-th feature in the i-th object during the observation
period; n is the number of features; ω is the number of objects.</p>
      <p>How isotonic and isomorphic (structural) ordering of objects, Chekanovsky's method for research of
subsets on homogeneity is resulted.</p>
      <p>In economic research, a taxonomic indicator of the level of development is used to compare
objects that are characterized by a large number of features [43]. In our case, this may be an indicator
of the presence of software implants in the local network. And this will be a further development of
research, which is presented in [1].</p>
      <p>
        The first stage is the standardization of features in the matrix (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) and its transformation into a
matrix Z.
      </p>
      <p>- the expert constructs a square matrix of n×n pairwise comparisons of features, which has the
property of inverse symmetry a ji = 1aij ;</p>
      <p>- eigenvectors of priorities are calculated, for which all elements of a row are multiplied and
the root of the n-th degree is taken from result, and then the received number is divided by the sum of
such numbers of a column and estimates of a vector of priorities ( x1, x2 ,, xn ) are received;
- the matrix n×n is multiplied by the column of the priority vector and a column with (
y1, y2 ,, yn ) is obtained, which shows the degree of importance of each feature.</p>
      <p>
        Then, before the transition from the matrix X to the matrix Z, the results of observations in the
matrix (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) must be multiplied by the coefficients yk , respectively.
      </p>
      <p>In [42], the transition to the matrix Z is proposed in the following sequence:
k = 1,2, n the value of the sign k for the unit i; X
k is the arithmetic mean of the sign k; S
k
standard deviation of the sign k; Zik is the standardized value of the characteristic k for the unit i.</p>
      <p>Next, the so-called
development standard is formed,
which represents a point
with
Z 01, Z 02 ,, Z 0n coordinates. These coordinates represent the standards or valid values of the features.</p>
      <p>Then the distance between the points-units of the matrix Z and the point is determined by the
formula:</p>
      <p>At these distances, the indicator of the presence of software implants is calculated:</p>
      <p>,
  ,
  =
( 
−   )</p>
      <p>2
where</p>
      <p>=1
where</p>
      <p>,
 0 =  0̅ + 2 0,

1

 =1
.</p>
      <p>
        (
        <xref ref-type="bibr" rid="ref2">2</xref>
        )
(
        <xref ref-type="bibr" rid="ref3">3</xref>
        )
(
        <xref ref-type="bibr" rid="ref4">4</xref>
        )
(
        <xref ref-type="bibr" rid="ref5">5</xref>
        )
(
        <xref ref-type="bibr" rid="ref6">6</xref>
        )
(
        <xref ref-type="bibr" rid="ref7">7</xref>
        )
(
        <xref ref-type="bibr" rid="ref8">8</xref>
        )
(
        <xref ref-type="bibr" rid="ref9">9</xref>
        )
(
        <xref ref-type="bibr" rid="ref10">10</xref>
        )
      </p>
      <p>The indicator di* can be in the range 0… .1. The closer this value is to zero, the more likely it
is that there will be no software implants in the facility.</p>
      <p>The indicator is used to statically characterize a set of objects. For a more in-depth analysis,
you need to consider the dynamic characteristics of a single object and then a set of objects.</p>
      <p>Then, based on the results of observations for several periods of time, a matrix of
observations X is formed for one object:</p>
      <p>X = </p>
      <p>X 0 = [X1, Z 2 ,, Zωn ] ,</p>
      <p>where xik - the value of the sign k in the period i.</p>
      <p>
        Then, as shown above, there is a process of standardization (matrix Z), the standard is built
The taxonomic index di* is determined by formula (
        <xref ref-type="bibr" rid="ref6">6</xref>
        ), where
 =1


(
        <xref ref-type="bibr" rid="ref11">11</xref>
        )
(
        <xref ref-type="bibr" rid="ref12">12</xref>
        )
(
        <xref ref-type="bibr" rid="ref13">13</xref>
        )
(
        <xref ref-type="bibr" rid="ref14">14</xref>
        )
(15)
(16)
(17)
      </p>
      <p>Then the dependence (16) for the square of the distance for the aggregate indicator and the square
of the distance for the individual indicators can be written as:</p>
      <p>So, now the indicator di* describes the dynamics of changes in the sets under study, but for
one object.
block matrix:</p>
      <p>You can now proceed to the dynamic characterization of a set of objects. If you denote the
observation matrix of an object j by a symbol X j , the aggregate matrix for objects will remain as a</p>
      <p>Given that all objects in the network are of the same type - they are computers, the standard
P0 may remain from the previous analysis.</p>
      <p>
        The generalized index di* is determined by formula (
        <xref ref-type="bibr" rid="ref6">6</xref>
        ), where:
C0, S0 are defined by formulas (
        <xref ref-type="bibr" rid="ref12">12</xref>
        ), (
        <xref ref-type="bibr" rid="ref13">13</xref>
        ), (
        <xref ref-type="bibr" rid="ref14">14</xref>
        ).
      </p>
      <p>Consider the variable n as the number of features; ω - number of objects; Zik - standardized
value of the sign k in the period t.</p>
      <p>The calculated value di* describes the process with the dynamic characteristics of all objects.
But according to [44-46], the directions of changes of individual components by the total value of the
indicator are not taken into account here. Therefore, in [42] it is proposed to replace the distance Ci0
with C(i0, j):</p>
      <p>=1
С 0, =
  −  0 ,
.</p>
      <p>(18)
(19)</p>
      <p>Taking into account Сi0 = С0 ∙ di* and С(i0, j) = С(0, j) ∙ dij the dependence between aggregate and
individual indicators will remain:</p>
      <p>The obtained formula allows to estimate the influence of individual taxonomic indicators of
objects d</p>
      <p>
        i*j on the general taxonomic indicator of the set of objects di* . Here, as before, this figure is
in the range (
        <xref ref-type="bibr" rid="ref1">0, 1</xref>
        ).
      </p>
      <p>The result of the indicator refers to one of the five intervals that allow us to assess the level of
possible presence of software implants.</p>
    </sec>
    <sec id="sec-5">
      <title>4. Experiments and evaluation</title>
      <p>For experiments, a distributed system [4, 30, 48-52] was used to detect malware, which will
include the ability to detect software implants based on implemented methods. An appropriate method
was implemented to check the efficiency of the classifier in the structure of the distributed system.
The result of the determination was the dependence of the percentage of detected botnets containing
software implants. Experimental studies were performed for the classifier without adding copies of
the created botnets, ie the test was performed without training the classifier on the created samples.
Botnets that use a strategy to gain complete control by activating their components were selected for
the experiment. That is, software implants were present at every computer station. The results of the
calculation of various indicators are presented in table 1. The experiments involved determining the
following metrics for the detection of bot nodes:  1
– percentage of harmful vectors belonging to a
incorrectly assigned bot nodes to one of the botnet classes.
certain class;  2 – the percentage of vectors of harmful actions belonging to this subclass of the class
in relation to all test vectors;  3 – the percentage of correctly detected botnet nodes;  4 – the
percentage of incorrectly classified botnet nodes as benign applications;  5 – the percentage of
software implants is much lower than the typical manifestations of botnets. Thus, software implants
used by botnets can be detected by distributed systems [30].</p>
    </sec>
    <sec id="sec-6">
      <title>5. Discussion and Future Work</title>
      <p>Thus, software implants create problems for software users. This is especially true for
organizations and businesses. The advantage of attackers who use software implants is that they use
hidden software functions. The difficulty in detecting such program a implants is that the processes
occur in local networks. Attackers develop and use such tools in various malicious models.</p>
    </sec>
    <sec id="sec-7">
      <title>6. Conclusions</title>
    </sec>
    <sec id="sec-8">
      <title>7. References</title>
      <p>On-premises software implants in software create problems for PC users. The proposed method for
detecting software implants allows you to assess the degree of availability in the software. The
application of the proposed solution in a distributed malware detection system has increased the
efficiency of software implant detection by 4% through the use of multidimensional analysis to detect
software implants in software on a local computer network.</p>
      <p>The direction of further research will be the development of methods for detecting software
implants based on their behavioral signatures.
[15] S. L. Thomas, T. Chothia, F. D. Garcia, Measuring the Importance of Static Data Comparisons to
Detect Backdoors and Undocumented Functionality, in: Proceedings of 22nd European
Symposium on Research in Computer Security. Oslo, Norway, 2017, pp. 513-531
[16] A. Schönegge, The Hidden Function Question Revisited, in: Proceedings of Algebraic
Methodology and Software Technology: 6th International Conference, AMAST '97. Sydney,
Australia, 1997, pp. 451-464
[17] The Secret Code of Software Validation….In 5 Easy Steps. URL:
https://www.cebos.com/blog/the-secret-code-of-software-validation-in-5-easy-steps/
[18] Y. Kawamoto, H. Yamamoto, Secret function sharing schernes and their applications to the
oblivious transfer, in: Proceedings of IEEE International Symposium on Information Theory,
2003, pp. 281-295
[19] B. Chen, W. Carvalho, N. Baracaldo, H. Ludwig, B. Edwards, et al, Detecting Backdoor Attacks
on Deep Neural Networks by Activation Clustering, CEUR Workshop 2301 (2019).
[20] J. Tarhio, E. Ukkonen, Approximate Boyer Moore String Matching. SIAM Journal on</p>
      <p>Computing 22 2, (1993) 243-260
[21] Y. Kondratenko, N. Kondratenko, Soft Computing Analytic Models for Increasing Efficiency of
Fuzzy Information Processing in Decision Support Systems. Chapter in book: Decision Making:
Processes, Behavioral Influences and Role in Business Management, R. Hudson (Ed.), Nova
Science Publishers, New York, 2015, 41-78
[22] V. Proskurin, Software malicious implant in secure systems. URL:
http://www.crimeresearch.ru/library/progwir98.htm [in Ukrainian].
[23] O. V. Kaarin, Program protection theory and practice. MGUL, 2004 [in Russian].
[24] O. V. Kaarin, Computer system software security. MGUL, 2003 [in Russian].
[25] V. F. Shanugin, Protection of computer information. Effective methods and tools: a textbook.</p>
      <p>DMK Press, 2008 [in Russian].
[26] V. F. Shanugin, Protection of information in computer systems and networks. DMK Press,
(2012) [in Russian].
[27] G. Balakrishnan, T. Reps, WYSINWYX: What You See Is Not What You eXecute. in:
Proceedings of ACM Transactions on Programming Languages and Systems, Vol. 32, Issue 6,
2010.
[28] S. Lysenko, K. Bobrovnikova, O. Savenko. A Botnet Detection Approach Based on The Clonal
Selection Algorithm, in: Proceedings of 2018 IEEE 9th International Conference on Dependable
Systems, Services and Technologies, DeSSerT-2018, Kyiv, Ukraine, 2018, pp. 424-428.
[29] S. Lysenko, O. Pomorova, O. Savenko, A. Kryshchuk and K. Bobrovnikova DNS-based
Antievasion Technique for Botnets Detection, in: Proceedings of the 8-th IEEE International
Conference on Intelligent Data Acquisition and Advanced Computing Systems: Technology and
Applications, Warsaw, 2015, pp. 453–458.
[30] S. Lysenko, K. Bobrovnikova, O. Savenko and A. Kryshchuk, BotGRABBER: SVM-Based
SelfAdaptive System for the Network Resilience Against the Botnets’ Cyberattacks,
Communications in Computer and Information Science, 1039 (2019) 127-143. doi:
10.1007/9783-030-21952-9_10
[31] O. Savenko, S. Lysenko, A. Kryschuk, Multi-agent based approach of botnet detection in
computer systems Communications in Computer and Information Science, 291 (2012) 171-180
[32] S. Taheri, A.M. Bagirov, I. Gondal, S. Brown. Cyberattack triage using incremental clustering
for intrusion detection system Internation Journal of Information Security, 19 (2020) 597–607.
doi: https://doi.org/10.1007/s10207-019-00478-3.
[33] O. Savenko, A. Nicheporuk, I. Hurman, S. Lysenko, Dynamic signature-based malware detection
technique based on API call tracing CEUR-WS 2393 (2019) 633-643
[34] A. Drozd, J. Drozd, S. Antoshchuk, V. Nikul, M. Al-dhabi, Objects and Methods of On-Line
Testing: Main Requirements and Perspectives of Development, in: Proceedings of IEEE
EastWest Design &amp; Test Symposium, Yerevan, Armenia, 2016, pp. 72 – 76. doi:
10.1109/EWDTS.2016.7807750
[35] O. Pomorova, O. Savenko, S. Lysenko, A. Nicheporuk Metamorphic Viruses Detection</p>
      <p>Technique based on the Modified Emulators, CEUR-WS 1614 (2016) 375-383
[36] T. Sochor, M. Zuzcak, Study of Internet Threats and Attach Methods Using Honeypots and</p>
      <p>Honeynets, Computer Network 431 (2014 118–127
[37] T. Sochor, M. Zuzcak, Attractiveness Study of Honeypots and Honeynets in Internet Threat</p>
      <p>
        Detection, Computer Networks 522 (2015) 69-81. doi: 10.1007/978-3-319-19419-6 7.
[38] P. Owezarski, A near real-time algorithm for autonomous identification and characterization of
honeypot attacks, in: Proceedings of the 10th ACM Symposium on Information, Computer and
Communications Security, ser. ASIA CCS ’15. New York, NY, USA: ACM, 2015, pp. 531–542.
[39] J. Mazel, P. Casas, P. Owezarski. Sub-Space Clustering and Evidence Accumulation for
Unsupervised Network Anomaly Detection, in: Proceedings of the Third International
Conference on Traffic Monitoring and Analysis, ser. TMA’11. Berlin: Springer-Verlag, 2011,
pp. 15–28.
[40] N. A. Rosli, W. Yassin, M.F. Faizal, S.R. Selamat Clustering Analysis for Malware Behavior
Detection using Registry Data. (IJACSA) International Journal of Advanced Computer Science
and Applications 10 12 (2019) 93-102.
[41] S. Bezobrazov, A. Sachenko, M. Komar, V. Rubanau, The method of artificial intelligence for
malicious applications detection in android OS, International Journal of Computing, 15(
        <xref ref-type="bibr" rid="ref3">3</xref>
        ) (2016)
184-190
[42] M. Kolisnyk, V. Kharchenko, I. Piskachova, Research of the attacks spread model on the smart
office’s router, International Journal of Computing, 19(
        <xref ref-type="bibr" rid="ref4">4</xref>
        ) (2020) 629-637.
[43] V. Pluta Comparative multidimensional analysis in economic research: methods of taxonomy
and factor analysis, Statistics, 1980 [in Russian]
[44] B. N. Igumnov, T. P. Zavgorodnyaya, Cybernetic bases of construction of economic systems for
the enterprises, TUP, 2000 [in Russian]
[45] G. Saat, K. Kerno, Analytical planning. Organization of systems: Translated from English, Radio
and communication, 1991 [in Russian]
[46] A. V. Andreychikov, O. N. Andreychikova Analysis, synthesis, planning solutions in economics,
      </p>
      <p>Finance and Statistics, 2001 [in Russian]
[47] A. Melnyk, V. Melnyk, Remote Synthesis of Computer Devices for FPGA-Based IoT Nodes, in:
Proceedings of 2020 10th International Conference on Advanced Computer Information
Technologies, ACIT 2020, pp. 254-259
[48] A. Drozd, M. Lobachev, J. Drozd, “The problem of on-line testing methods in approximate data
processing,” Proc. 12th IEEE International On-Line Testing Symposium, Como, Italy, pp. 251–
256, 2006. DOI: 10.1109/IOLTS.2006.61.\
[49] J. Drozd, A. Drozd, M. Al-dhabi, “A resource approach to on-line testing of computing circuits,”
Proc. IEEE East-West Design &amp; Test Symposium, Batumi, Georgia, 2015, pp. 276 – 281. DOI:
10.1109/EWDTS.2015.7493122
[50] Lysenko, S., Savenko, O., Bobrovnikova, K., Kryshchuk, A., Savenko, B.: Information
Technology for Botnets Detection Based on Their Behaviour in the Corporate Area Network. In:
International Conference on Computer Networks, 2017, pp. 166-181. Springer, Cham.
[51] Lysenko, S., Savenko, O., Bobrovnikova, K., Kryshchuk, A.: Self-adaptive System for the
Corporate Area Network Resilience in the Presence of Botnet Cyberattacks. In: International
Conference on Computer Networks, pp. 385-401. Springer, Cham (2018).
[52] Savenko O., Lysenko S., Nicheporuk A., Savenko B. Approach for the Unknown Metamorphic
Virus Detection. The 9-th IEEE International Conference on Intelligent Data Acquisition and
Advanced Computing Systems: Technology and Applications : Proceedings (Bucharest,
Romania, September 21–23, 2017). Bucharest, 2017. Vol. 1. Pp. 453–458.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>G.</given-names>
            <surname>Sanjam</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Gentr</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Halevi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Raykova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Sahai</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Waters</surname>
          </string-name>
          ,
          <article-title>Hiding Secrets in Software: A Cryptographic Approach to Program Obfuscation</article-title>
          .
          <source>Communications of the ACM, 59</source>
          <volume>5</volume>
          (
          <year>2016</year>
          )
          <fpage>113</fpage>
          -
          <lpage>120</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>McAfee</given-names>
            <surname>Mobile Threat Report Q1</surname>
          </string-name>
          ,
          <year>2019</year>
          . URL: https://www.mcafee.com/enterprise/enus/assets/reports/rp-mobile
          <source>-threat-report-2019</source>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>K.</given-names>
            <surname>Drozd</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Zashcholkin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Martynyuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Ivanova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Drozd</surname>
          </string-name>
          ,
          <article-title>Development of Checkability in FPGA Components of Safety-Related Systems</article-title>
          ,
          <source>CEUR WS 2762</source>
          (
          <year>2020</year>
          )
          <fpage>30</fpage>
          -
          <lpage>42</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>S.</given-names>
            <surname>Lysenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Bobrovnikova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Matiukh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I.</given-names>
            <surname>Hurman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Savenko</surname>
          </string-name>
          ,
          <article-title>Detection of the botnets' low-rate DDoS attacks based on self-similarity</article-title>
          ,
          <source>International Journal of Electrical and Computer Engineering 10</source>
          <volume>4</volume>
          (
          <year>2020</year>
          )
          <fpage>3651</fpage>
          -
          <lpage>3659</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>B.</given-names>
            <surname>Anderson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Quist</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Neil</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Storlie</surname>
          </string-name>
          , T. Lane,
          <article-title>Graph-based malware detection using dynamic analysis</article-title>
          .
          <source>Journal in Computer Virology</source>
          ,
          <volume>7</volume>
          (
          <year>2011</year>
          )
          <fpage>247</fpage>
          -
          <lpage>258</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>N.</given-names>
            <surname>Runwal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. M.</given-names>
            <surname>Low</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Stamp</surname>
          </string-name>
          ,
          <article-title>Opcode Graph Similarity and Metamorphic Detection</article-title>
          .
          <source>Journal in Computer Virology</source>
          ,
          <volume>8</volume>
          (
          <year>2012</year>
          )
          <fpage>37</fpage>
          -
          <lpage>52</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>A.</given-names>
            <surname>Nagaraju</surname>
          </string-name>
          <article-title>Metamorphic malware detection using base malware identification approach</article-title>
          .
          <source>Journal Security and Communication Networks</source>
          ,
          <volume>7</volume>
          (
          <year>2014</year>
          )
          <fpage>1719</fpage>
          -
          <lpage>1733</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <source>[8] DSTU 3396.2-97 Protection of information. Technical protection of information. Terms and definitions. State Committee of Ukraine</source>
          , Kyiv (
          <year>1997</year>
          ) [in Ukrainian].
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>B.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Carvalho</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Baracaldo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Ludwig</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Edwards</surname>
          </string-name>
          , et al,
          <article-title>Detecting Backdoor Attacks on Deep Neural Networks by Activation Clustering</article-title>
          .
          <source>CEUR WS 2301</source>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>Adups</given-names>
            <surname>Backdoor</surname>
          </string-name>
          . URL: https://www.kryptowire.com/adups_security_analysis.
          <source>html.</source>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>K.</given-names>
            <surname>Alminshid</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. N.</given-names>
            <surname>Omar</surname>
          </string-name>
          ,
          <article-title>Detecting backdoor using stepping stone detection approach</article-title>
          , in: Proceedings of 2013 Second International Conference on Informatics &amp;
          <article-title>Applications (ICIA), Lodz</article-title>
          , Poland,
          <year>2013</year>
          , pp.
          <fpage>87</fpage>
          -
          <lpage>92</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>J.</given-names>
            <surname>Zaddach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Kurmus</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Balzarotti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.-O.</given-names>
            <surname>Blass</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Francillon</surname>
          </string-name>
          , et al.,
          <article-title>Implementation and Implications of a Stealth Hard-drive Backdoor, in</article-title>
          .
          <source>Proceedings. of 29th Annual Computer Security Applications Conference</source>
          , New Orleans, Louisiana,
          <string-name>
            <surname>US</surname>
          </string-name>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>T. F.</given-names>
            <surname>Dullien</surname>
          </string-name>
          ,
          <article-title>Weird machines, exploitability, and provable unexploitability</article-title>
          ,
          <source>IEEE Transactions on Emerging Topics in Computing</source>
          ,
          <volume>99</volume>
          (
          <year>2017</year>
          )
          <fpage>1</fpage>
          -
          <lpage>15</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>S. L.</given-names>
            <surname>Thomas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Chothia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F. D.</given-names>
            <surname>Garcia</surname>
          </string-name>
          ,
          <article-title>HumIDIFy: A Tool for Hidden Functionality Detection in Firmware</article-title>
          ,
          <source>in: Proceedings of 14th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment</source>
          , Bonn, Germany,
          <year>2017</year>
          , pp.
          <fpage>279</fpage>
          -
          <lpage>300</lpage>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>