<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Model of Operation System's Incidents Forecasting</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Valeri Lakhno</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andii Sahun</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Vladyslav Khaidurov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Dmitro Kasatkin</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Serhii Liubytskyi</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Institute of Engineering Thermophysics of NAS of Ukraine</institution>
          ,
          <addr-line>2а Mariyi Kapnist str., Kyiv, 03057</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute</institution>
          ,”
          <addr-line>37 Peremohy ave., Kyiv, 03056</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>National University of Life and Environmental Sciences of Ukraine</institution>
          ,
          <addr-line>15 Heroyiv Oborony str., Kyiv, 03041</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>11</fpage>
      <lpage>13</lpage>
      <abstract>
        <p>Modeling the operating system incident forecasting subsystem allows obtaining accurate and reliable forecasts. For this purpose, elements of the theory of heuristic self-organization and concrete realization of this theory-GMDH are applied. The data of the system log of OS hardware errors incidents were used as input data of the model. As a result of testing the proposed model based on test samples at different settings of the machine learning system and parameters (the degree of reference polynomial, the number of variables in the model of the characteristic polynomial, the number of selection series) obtained a much more accurate forecast. Thus, in comparison with classical regression methods or the method of exponential smoothing, GMDH gives not more than 4% of erroneous calculations using GMDH.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Time series</kwd>
        <kwd>forecasting subsystem</kwd>
        <kwd>machine learning</kwd>
        <kwd>polynomial subsystem</kwd>
        <kwd>GMDH</kwd>
        <kwd>Windows incident log</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        One of the most problematic areas when planning measures to prevent the consequences of
hardware failures of the operating system is to obtain an effective model for predicting incidents of
the operating system. Most authors do not raise the issue of classifying methods and models for
predicting the operation of operating systems (OS). As a review of the literature shows, currently the
most popular are classical incidents forecasting models (trending, regression), forecasting using
neural networks, and Markov models [
        <xref ref-type="bibr" rid="ref1 ref2 ref3 ref4 ref5">1–5</xref>
        ]. Scientists make a special contribution to the theory and
practice of creating algorithms, methods, and forecasting systems in [
        <xref ref-type="bibr" rid="ref6 ref7 ref8">6–8</xref>
        ]. Therefore, it is relevant to
analyze critical operating modes of operating systems using modern methods of forecasting time
series, as well as developing new effective machine learning methods based on GMDH for use in
incident forecasting subsystems. Thus, the object of research is the subsystem for forecasting
incidents of the Windows family operating system using time series forecasting and machine learning
methods.
      </p>
      <p>
        Among examples of the actions of the hardware, errors are logs registered by the operating system
[
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. As was shown in [
        <xref ref-type="bibr" rid="ref10 ref3 ref4">3, 4, 10</xref>
        ] for the time series for the subsystem for predicting incidents of OS
operation, the sampling of critical events in the OS using the “Exponential Smoothing” forecast
method cannot be considered satisfactory [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ].
      </p>
      <p>
        To prove the correctness of this trend, it is possible to go in two ways: empirical and experimental.
It is possible to use the predictive trend model using regression analysis [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. An alternative way to
improve the quality of the forecast is to use neural networks and a deep machine learning algorithm
for the models [
        <xref ref-type="bibr" rid="ref11 ref12">11, 12</xref>
        ]. This is not always necessary for cybersecurity experts [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ].
      </p>
    </sec>
    <sec id="sec-2">
      <title>2. Main Part</title>
      <p>
        But, to obtain accurate and reliable forecasts in the study of complex objects, such as an incident
registration system, the theory of heuristic self-organization, and the concrete implementation of the
theory—GMDH [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] are used. It makes sense to use GMDH is a basic method for forecasting
incidents, since the data sampling (Windows system event log) contains several elements [
        <xref ref-type="bibr" rid="ref10 ref9">9,10</xref>
        ].
      </p>
      <p>
        The algorithm for finding the optimal structure model for the incident forecasting subsystem can
be represented in the form of the following steps [
        <xref ref-type="bibr" rid="ref10 ref15">10,15</xref>
        ]:
2. Let  ,
      </p>
      <p>partitioning sets
1. There is a sample in the form of the time series (TS) system: log 
= {(  ,  
)}
 =1, where
 ∈ ℜ</p>
      <p>. Since for the GMDH operation, it is necessary to conduct learning and testing, the
samples are divided into learning and test ones. In the practical GMDH implementation, the
percentage of these samples is manually selected.</p>
      <p>be set from the range {1, . . ,  } =  . These sets satisfy the conditions for
 ∪ 
= 
1
 ∩ 
= 0.
elements   for which the index  ∈  . The partition of the sample is written as follows:
The matrix   consists of row vectors   for which the index  ∈  . Vector  1 consists of those
 
∈ ℜ
 
 1
= (</p>
      <p>,  
) ,  
∈ ℜ
3. Let’s define the base model. This model describes the relationship between a dependent
variable</p>
      <p>and free variables  . For the forecasting algorithm being created, let’s use the
Voltaire functional series (the so-called Kolmogorov-Gabor polynomial):

 =1</p>
      <p>=1  =1</p>
      <p>=1  =1  =1
=  0 + ∑     + ∑
∑      + ∑

∑
∑  
  
   + ⋯.
4. In the model (1),  = {  | = 1, . . ,  } – set of free variables and
-set of weights:

= ⟨  ,   ,</p>
      <p>| ,  ,  , … = 1, . . ,  ⟩.
5. Based on the set objectives, the objective function is selected – an external criterion that
describes the quality of the model. A few commonly used external criteria are described below.
6. Inductively generated candidate models. In this case, restrictions are introduced on the length of
the polynomial of the base model. For example, the degree of a polynomial of the base model
should not exceed a specific natural value. Then the basic model is written as a linear
combination of a given number  0 of products of free variables as follows:</p>
      <p>=  ( 1,  2, . . ,  12,  1 2,  22, . . ,   ),
where f is the linear combination function. Arguments (2) are redefined as follows:
(1)
(2)

 1 2 →   ,  22 →   , . . ,  
 1 →  1,  2 →  2, . . ,  21 →   ,
→   0,
order: 
form:</p>
      <p>=  ( 1,  2, . . ,   0).</p>
      <p>For coefficients linearly included in the model, one-index numbering is specified in the following
=  1, . . ,   0. In this case, the model can be represented as a linear combination of the
Each model of the generated form (3) is defined by a linear combination of elements
{(  , . . ,   )} in which the set of indices { } =  is subset {1, . . ,  0}.</p>
      <p>7. To configure these parameters, internal criteria are used; it is calculated using the training
sample. To each element of a vector</p>
      <p>−  selection element  , a vector is mapped   . Next, a
view matrix is constructed   , which represents a set of column vectors   .The matrix   is
divided into sub-matrixes   and   . The smallest remainder of the form | −  |, where  =
^
^</p>
      <p>
        ^
[
        <xref ref-type="bibr" rid="ref10 ref15">10,15</xref>
        ], respectively, of the expression:
      </p>
      <p>returns the value of the parameter vector  , which is calculated by the least-squares method
where 
∈ { ,  , 
}. The internal criterion for the model applies the standard error of the form:

=  0 +
∑     .</p>
      <p>(3)
 2 = |  −     | .</p>
      <p>^
2
In accordance with the criterion  2 → 
, parameters 
are selected and errors are calculated
on the test sample  , where</p>
      <p>=  . When the model is complicated, the internal criterion does not
give the minimum models of optimal complexity; therefore, it is not suitable for choosing a model.
8. To select the best models, let’s calculate their quality. For this, a control sample and an external
criterion are used. The error in the sample  is indicated as follows:
 2
( ) =  2
( | ) = | 
−   0  | ,
^
2
where 
∈ { ,  }, 
∩ 
= 0. This means that the error is calculated on the sample 
with the
model parameters obtained on the sample  .</p>
      <p>A model that provides a minimum of external criteria is considered optimal. With an increase in
the number of variables in the model and the degree of the reference polynomial, obtaining the best
forecasting model can increase significantly.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Application of the Developed Forecasting Model</title>
      <p>An application of a developed forecasting model in the C# language based on GHMD has been
implemented. As a result of the program</p>
      <p>module realization, the mathematical model of training
selects the best models, and as a result of the selection of the best models get the best model, which
will be used to predict security incidents of the investigated OS (Fig. 1). All data taken for forecasting
in the developed model are average statistics from the Windows incident log. In principle, you can
take such a time series based on the probability of meeting or on the basis of average data (averaging
is performed for a fixed period).</p>
      <p>On the graph of the input and processed data of the forecasting model based on GMDH, it is
possible to estimate the discrepancy between the data of the real sample and the data (shown in black)
obtained on the basis of the best forecasting GMDH model (shown in red) (Fig. 2). Prediction results
are obtained with various system settings and various parameters (degree of the reference polynomial,
number of variables of the characteristic polynomial model, number of selection series).</p>
      <p>
        In order to predict the time series obtained from the incident log of the Windows family’s OS
based on GMDH, it is necessary to select the best models at each iteration of the method. This
approach reduces the total number of calculations (processor time) and also reduces the amount of
memory needed for the work of the method itself. Comparing the forecasting results, generated by the
GMDH model and by the autoregression, it is possible to use the created software product in practice.
Among examples of hardware actions, errors are ones registered by operating system logs. This
information in the logs of system events of the Windows OS, for example, there are following:
 Problems in the file system structure; device controller error.
 Error on the device.
 Damage to the disk resource cluster and numbers of other similar errors [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
      <p>
        As was shown in [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ] for the time series for the subsystem for predicting incidents of OS
operation, the sampling of critical events in the OS using the “Exponential Smoothing” forecast
method can be considered satisfactory.
      </p>
      <p>By changing the input parameters of the model (shown in Fig. 1) for the same input data of the TS,
the parameters of the time series data sampling test part, and the ones of the real TS, it is possible to
reject the results of the selection of changes in the model except for the best ones. Real data of TS are
taken from the logs without preserving the pre-juvenile OS.</p>
      <p>On the graph of the input and refined data of the forecast model based on the GMDH, it is possible
to estimate the distribution of the real sample data and data (shown by the new color), which were
taken on the basis of the short model to the forecast of the GMDH (shown by the black color) (Fig. 2).</p>
      <p>
        When calculating the parameters of the GMDH model, we obtain the corresponding intermediate
data of the stages of calculation of the GMDH-based models:
 Regularity criteria for the obtained models on optimization steps: S[
        <xref ref-type="bibr" rid="ref1">1</xref>
        ], S[
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], S[
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], S[
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
 Global criterion at level 1 selection.
      </p>
      <p> The module of a deviation estimation of the received forecasting models on all samples.</p>
      <p>Some prediction results are obtained with various system settings and various parameters (degree
of the reference polynomial, number of variables of the characteristic polynomial model, number of
selection series) are shown in Fig. 3.</p>
      <p>After testing the obtained forecasting subsystem and the generated test samples, it is found that the
results of the model incidents forecasting model to predict OS incidents are taken with various system
settings and parameters may differ slightly (not more than 4%).</p>
    </sec>
    <sec id="sec-4">
      <title>4. Conclusions</title>
      <p>The accuracy of predicting incidents of the same type over a given time series (computer system
hardware incidents) can be assessed positively. Of course, if there is a lot of such data and they cover
large numbers of sources with as many behaviors as possible, then the forecast will be more accurate.</p>
      <p>The peculiarity of this model is the fairly accurate past results (if such points were not filmed in
the time series before). The value of such a model may be manifested when the intervals for taking
data to the incident log were high, but there is a need to determine the significance of this type of
event in the past (incident investigation).</p>
      <p>The use of a large number of polynomial models, such as those used in GMDH, allows one to
obtain a much more accurate forecast for the task of forecasting OS incidents than classical regression
methods, as well as the method of exponential smoothing.</p>
      <p>An important aspect of the resulting model is that it can be used to obtain a retrospective forecast.
This is especially useful when, as a result of the investigation, it is necessary to know the exact value
of the TS. But, at the same time, there is no real value due to the large interval of bound values.</p>
    </sec>
    <sec id="sec-5">
      <title>5. References</title>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>R. H.</given-names>
            <surname>Shumway</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. S.</given-names>
            <surname>Stoffer</surname>
          </string-name>
          ,
          <source>Time Series Analysis and Its Applications</source>
          , 4nd. ed., Springer International Publishing,
          <year>2017</year>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -52452-8.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Krause</surname>
          </string-name>
          ,
          <article-title>Evaluating the Performance of Adapting Trading Strategies with Different Memory Lengths</article-title>
          ,
          <source>in: Intelligent Data Engineering and Automated Learning - IDEAL</source>
          , Berlin, Heidelberg,
          <year>2009</year>
          , pp.
          <fpage>711</fpage>
          -
          <lpage>718</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>S.</given-names>
            <surname>Geisser</surname>
          </string-name>
          ,
          <article-title>Predictive inference: an introduction</article-title>
          , Chapman &amp; Hall, London,
          <year>1993</year>
          , doi:10.1007/978-1-
          <fpage>4899</fpage>
          -4467-2.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>N.</given-names>
            <surname>Sun</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Zhang</surname>
          </string-name>
          , P. Rimba,
          <string-name>
            <given-names>S.</given-names>
            <surname>Gao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. Y.</given-names>
            <surname>Zhang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Xiang</surname>
          </string-name>
          ,
          <article-title>Data-driven cybersecurity incident prediction: A survey</article-title>
          ,
          <source>IEEE Communications Surveys &amp; Tutorials</source>
          <volume>21</volume>
          (
          <year>2019</year>
          )
          <fpage>1744</fpage>
          -
          <lpage>1772</lpage>
          . doi:
          <volume>10</volume>
          .1109/COMST.
          <year>2018</year>
          .
          <volume>2885561</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>S. A.</given-names>
            <surname>Billings</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Hong</surname>
          </string-name>
          ,
          <article-title>Dual-orthogonal radial basis function networks for nonlinear time series prediction</article-title>
          ,
          <source>Neural Networks: the official journal of the International Neural Network Society</source>
          <volume>11</volume>
          (
          <year>1998</year>
          )
          <fpage>479</fpage>
          -
          <lpage>493</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>E.</given-names>
            <surname>Pontes</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. E.</given-names>
            <surname>Guelfi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. T.</given-names>
            <surname>Kofuji</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. A. A.</given-names>
            <surname>Silva</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. E.</given-names>
            <surname>Guelfi</surname>
          </string-name>
          ,
          <article-title>Applying multi-correlation for improving forecasting in cyber security</article-title>
          ,
          <source>in: 2011 Sixth International Conference on Digital Information Management</source>
          ,
          <year>2011</year>
          , pp.
          <fpage>179</fpage>
          -
          <lpage>186</lpage>
          . doi:
          <volume>10</volume>
          .1109/ICDIM.
          <year>2011</year>
          .
          <volume>6093323</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Zhang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Sarabi</surname>
          </string-name>
          , M. Liu,
          <string-name>
            <given-names>M.</given-names>
            <surname>Karir</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Bailey</surname>
          </string-name>
          ,
          <article-title>Predicting cyber security incidents using feature-based characterization of network-level malicious activities</article-title>
          ,
          <source>in: Proceedings of the 2015 ACM International Workshop on International Workshop on Security and Privacy Analytics</source>
          ,
          <year>2015</year>
          , pp.
          <fpage>3</fpage>
          -
          <lpage>9</lpage>
          . doi:
          <volume>10</volume>
          .1145/2713579.2713582.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>J.</given-names>
            <surname>Yang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. S.</given-names>
            <surname>Power System Short-term Load</surname>
          </string-name>
          <string-name>
            <surname>Forecasting</surname>
          </string-name>
          ,
          <source>Ph.D. thesis</source>
          , Elektrotechnik und Informationstechnik der Technischen Universitat, Darmstadt,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Windows</given-names>
            <surname>Hardware Error Architecture Overview</surname>
          </string-name>
          , Microsoft,
          <year>2020</year>
          . URL: https://docs.microsoft.com/en-us/windows-hardware/drivers/whea/windows-hardware
          <article-title>-errorarchitecture-overview</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>V.</given-names>
            <surname>Lakhno</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Sagun</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Khaidurov</surname>
          </string-name>
          , E. Panasko,
          <article-title>Development of an Intelligent Subsystem for Operating System Incidents Forecasting</article-title>
          ,
          <source>Technology Audit and Production Reserves</source>
          <volume>2</volume>
          (
          <year>2020</year>
          )
          <fpage>35</fpage>
          -
          <lpage>39</lpage>
          . doi:
          <volume>10</volume>
          .15587/
          <fpage>2706</fpage>
          -
          <lpage>5448</lpage>
          .
          <year>2020</year>
          .
          <volume>202498</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>C.</given-names>
            <surname>Bishop</surname>
          </string-name>
          ,
          <source>Pattern Recognition and Machine Learning</source>
          , Springer-Verlag, New York,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>D. J.C. MacKay</surname>
            , Information Theory, Inference and
            <given-names>Learning</given-names>
          </string-name>
          <string-name>
            <surname>Algorithms</surname>
          </string-name>
          , Cambridge University Press,
          <year>2003</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>J.</given-names>
            <surname>Schmidhuber</surname>
          </string-name>
          ,
          <article-title>Deep learning in neural networks: An overview</article-title>
          ,
          <source>Neural Networks</source>
          <volume>61</volume>
          (
          <year>2015</year>
          )
          <fpage>85</fpage>
          -
          <lpage>117</lpage>
          . doi:
          <volume>10</volume>
          .1016/j.neunet.
          <year>2014</year>
          .
          <volume>09</volume>
          .003.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>B.</given-names>
            <surname>Akhmetov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Lakhno</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Akhmetov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Alimseitova</surname>
          </string-name>
          ,
          <article-title>Development of sectoral intellectualized expert systems and decision making support systems in cybersecurity</article-title>
          ,
          <source>in: Proceedings of the Computational Methods in Systems and Software</source>
          , Springer, Cham,
          <year>2018</year>
          , pp.
          <fpage>162</fpage>
          -
          <lpage>171</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>030</fpage>
          -00184-1_
          <fpage>15</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>O. G.</given-names>
            <surname>Ivakhnenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. A.</given-names>
            <surname>Ivakhnenko</surname>
          </string-name>
          ,
          <article-title>The Review of Problems Solvable by Algorithms of the Group Method of Data Handling (GMDH), Pattern Recognition and Image Analysis 5 (</article-title>
          <year>2007</year>
          )
          <fpage>527</fpage>
          -
          <lpage>535</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>