<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Distributed System of Intelligent Content Monitoring Agents </article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Artem Soboliev</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Dmytro Lande</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute”</institution>
          ,
          <addr-line>Peremohy Avenue, 37, Kyiv, 03056</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>205</fpage>
      <lpage>214</lpage>
      <abstract>
        <p>   The coverage and generalization of large dynamic information flows constantly generated in the space of the Internet requires qualitatively new methods and approaches to the implementation of measures to ensure the completeness, accessibility and reliability of the target information. In the process of content monitoring of the Internet it is important to use tools of distributed global network content monitoring and creation of multiple interfaces between agents who control collection of information from different Internet segments. This paper proposes methods and tools for monitoring the distributed content of social networks, taking into account the constant changes in the availability of certain segments of the Internet. The proposed solutions are used to populate the content monitoring databases of InfoStream and CyberAggregator web resources and social networks. A system of intelligent content monitoring agents based on several servers located in different data centers is offered. The intelligent system of agents interacts with the management and control system, which ensures an appropriate level of fault tolerance, completeness and reliability of the received information.</p>
      </abstract>
      <kwd-group>
        <kwd> 1  Information resources</kwd>
        <kwd>social networks</kwd>
        <kwd>intelligent agent information gathering</kwd>
        <kwd>distributed content monitoring</kwd>
        <kwd>intelligent agent system</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction </title>
      <p>
        Currently, the level of tasks solved by Internet content monitoring systems is constantly growing
from traditional information retrieval tasks to management, design, modeling and forecasting of various
processes/events. It is worth noting that the amount of accumulated information is becoming gigantic
(Big Data). Consequently, when creating content monitoring systems, it is advisable to take into account
the peculiarities of access to certain segments of the Internet. There is a need to find unconventional
approaches to the use of information technology and mathematical methods of collecting, processing
and analyzing information [
        <xref ref-type="bibr" rid="ref1 ref3">1, 3</xref>
        ].
      </p>
      <p>
        Internet resources and social networks have become a convenient and effective means of
communication. They provide a huge freedom of action in the information space, which is mostly open
and accessible. When used effectively, Internet resources become a powerful source of information for
analytical work, open source intelligence (Open-Source Intelligence, OSINT) [
        <xref ref-type="bibr" rid="ref3 ref4">3, 4</xref>
        ] and at the same
time provide an opportunity to obtain strategically important, expert and at the same time publicly
available information, in particular security issues that allow to assess the mood of society in a particular
information field. Consideration of information from open sources is of great importance for
determining the directions of economic, scientific and technical development, as well as for solving
problems in the spheres of security and defense [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>In the global information and technological environment, rapid response and early warning systems
for challenges and threats based on monitoring information via the Internet, OSINT systems are being
actively improved. Analysis of technological and information problems and functional needs of such
systems shows that the use of distributed content monitoring tools (in particular, creation of networks
of information proxies) and a set of interfaces between intelligent information gathering agents
(scanning) is important in the process of analyzing information via the Internet. This is due to the
following factors:
1. Rapidly growing need for reliable information for management decision-making;
2. The need to take into account the level of accessibility of Internet segments and their features
in the formation of content;</p>
      <p>3. Different approaches to the possibility of providing information in different segments of global
networks, the constant expansion of software interfaces;</p>
      <p>4. The need to reduce the load on computing resources when using software agent systems
operating in separate segments of global networks;</p>
      <p>5. The need for automated management, design, modeling and forecasting, taking into account
the distribution of content in the segments of global networks</p>
      <p>Popular social networks contain a huge amount of data about people's daily lives and social
interactions, so they carefully check every request for information and do not always allow third-party
services to use this information. When these information services notice unusual behavior of a client
(in particular, a software client, a data collection agent) that makes a request for their data, they
immediately block its access and additionally check requests coming from the IP addresses of this client.
This requires that the clients, intelligent software agents that collect information for content monitoring
systems, provide certain standard behavior in relation to information services inherent in the average
user. This achieves the availability of both individual services and entire segments of the Internet.</p>
      <p>The number of such agents can be quite large, and information interaction should be provided
between them. This will reduce the load on the target information services in global networks, which
will also increase their availability.</p>
      <p>The purpose of the article is to describe the features of building a system of distributed monitoring
of the content of global information networks, taking into account belonging to different segments with
the help of intelligent information gathering agents.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Presentation of the basic material of the research </title>
      <p>Coverage and generalization of large dynamic information flows continuously generated in the
Internet space requires qualitatively new methods and approaches to the implementation of measures
to ensure monitoring of their content. Specialized content monitoring systems are used for prompt
coverage of the information space. Such systems provide:</p>
      <p>1. Responsiveness, which cannot be obtained from traditional search engines, where the time of
indexing online content can vary from a day to several weeks;</p>
      <p>2. Completeness, both in terms of covering sources and providing materials from those sources
that are not provided by news aggregators;</p>
      <p>3. Application of analytical tools for automated design, modeling and forecasting of
processes/events.</p>
      <p>
        A large number of multilingual information resources complicates their use in information and
analytical work. When analyzing or collecting such data, there are problems of processing extremely
large amounts of data, searching and navigating in dynamic information flows. To solve these problems,
such technological concepts as Big Data, Complex Networks, Cloud Computing, Data/Text Mining are
used. [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>Problems in the dynamics and dimensionality of multilingual information resources of global
networks require fundamental research in the field of pattern recognition, discrete mathematics,
linguistics, digital signal processing, wavelet and fractal analysis. Although in some cases modern
development of technology allows us to find the necessary information in networks, there are still
unresolved problems of further analytical processing of this information, the allocation of the necessary
factual data, determination of trends in the development of certain subject areas, the relationship of
objects, events, recognition of significant anomalies, forecasting, etc. Many of the obtained problems
are actual issues of semantic processing of ultra-large dynamic text arrays of information.</p>
      <p>
        Today, some attempts to solve these problems in practice determine the success of such projects as
search engines Baidu, Yandex, social network monitoring systems Google Keyhole, Brandwatch,
CyberAlert, analytical systems Palantir, Centrifuge. One of the suggested approaches to solving of such
problems is based on the system of content monitoring of web resources InfoStream [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] and social
networks Cyber Aggregator [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. Modernization and scaling (formation of multilingual full-text
databases, modeling of information flows in huge computer networks) in these systems takes into
account the software and hardware placement of the "essence" of the segments of the information space,
that is, the deployment of a network of information, proxy servers built on the basis of distributed
content monitoring, the use of a system of intelligent agents for collecting information.
      </p>
      <p>
        Let us consider the need for distributed content monitoring tools. It would seem that at the primary
level we can use the data available through traditional network search engines hosted on the servers of
well-known news integrators. But in this case, there are a number of problems that prevent further
serious use of network resources to perform analytical work [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]:
      </p>
      <p>Not all resources are available in the national segment, in particular, there is no access to some
foreign sites and some social networks.</p>
      <p>Traditional search engines do not always index news posted on deep levels of websites, news is not
always indexed by them in time, social networks and special databases posted on the Internet are poorly
covered, there is a problem of the Deep Web. In some cases, when the access is not anonymous,
websites or social networks involved in information wars can provide distorted information, fakes, to
the mainstream users. In some cases, access to information may be denied even if the information has
the status of open to all. In addition, requests that satisfy the information needs of analysts, transmitted
in an unprotected form, can disclose these needs to an interested party - an information adversary.</p>
      <p>To solve these OSINT tasks, it is necessary to use modern integrated systems that are characterized
by the following features:</p>
      <p>
        In order to ensure the simultaneous process of obtaining information from social networks without
the use of third-party paid services and to control and manage such a system from a single place, it is
proposed to introduce teams of agents that allow downloading and exchanging such information with
each other and ensure the integrity of the received data and distribute the load among themselves. This
will overcome the complexity of distributed content monitoring of information resources on the Internet
[
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>Distributed collection of information from websites and social networks using ensembles of
intelligent collection agents distributed in a cloud environment that geographically spans different
countries. These agents must interact, exchange information, and pass this information to the analytical
part of the OSINT system. Information retrieval agents should execute pre-programmed and customized
information gathering scenarios, interact with websites, social networks, deep web databases, news
aggregators, preferably (if possible) in an anonymous mode. The use of information retrieval agents as
the basis of the system of information proxy servers should ensure the completeness of information in
case of blocking of individual agents, prevent distortion and duplication of information transmitted to
the OSINT system databases. To prevent information leakage, OSINT analysts should use
anonymization, masking, VPN, etc. during data extraction and processing.</p>
      <p>
        According to the source [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], OSINT principles are based on the continuous collection of information
from public available sources, then analyzed, preparation and timely delivery of the final result to the
customer. In order to solve tasks of timely intelligence based on the information received from OSINT
is used the result of systematic collection and processing of analyzed publicly available Information.
The basis of cybersecurity using the OSINT principle is determined by a number of aspects, including
the speed and cost of information obtaining, its volume, quality, reliability, convenience of further use
etc. The process of planning and preparation for OSINT management depends on the following factors
[
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]:
      </p>
      <p>1. Efficiency in information support is achieved by using the method of collecting information
from the Internet, user-generated content, hashtags, geo-tags, etc;</p>
      <p>2. The relevance, depth, availability and volume of publicly available information makes it
possible to find the information necessary for intelligence without the involvement of other specialized
intelligence tools;
3. Simplification of data collection processes. OSINT provides the necessary information,
eliminating the need to attract unnecessary technical and human resources;</p>
      <p>4. Depth of data analysis. As part of the intelligence process, OSINT enables in-depth analysis of
publicly available information to make appropriate decisions;</p>
      <p>5. Efficiency. Dramatic reduction of time to access information on the Internet. Fast receipt of
valuable operational information. The situation that changes rapidly during crises is most fully reflected
in the current news;</p>
      <p>6. Volumes. The possibility of mass monitoring of certain information sources in order to find
targeted content, people and events;</p>
      <p>7. Quality. Compared to the reports of special forces, information from open sources is devoid of
subjectivity;
8. Reliability;
9. Ease of use. OSINT-data can be easily transferred to any interested authorities, they are open;
10. Cost. Obtaining data on the price in OSINT is minimal.</p>
      <p>
        There is a problem associated with the large amount of information received from social networks
and the analysis of this data, assessing the dynamics and susceptibility to constant change. This problem
and ways to overcome it today are called Big Data. In this case, it is problematic to implement the
functions of collecting, cleaning, storing, searching, accessing, transmitting, analyzing and visualizing
such sets as a complete integrity, rather than local fragments. The defining characteristics of big data
are the "three V's": Volume (physical volume), velocity (the rate of growth in data transmission and
retrieval and the need for high speed of processing and retrieval of results), variety (diversity, the ability
to handle different types of structured data). and weak data, structured data at the same time). [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]
2.1.
      </p>
    </sec>
    <sec id="sec-3">
      <title>System Functionality </title>
      <p>
        There are problems with processing large volumes of circulating information necessary to search
and navigate in dynamic data streams during the collection and analysis of open data from the Internet.
Large number of multilingual dynamic information resources, as well as dominance of information
noise complicate the search for the necessary information in the operational analysis, and hence the use
of open sources in information and analytical work in general. Most of the above problems are topical
issues of semantic processing of large dynamic text arrays of information. Nowadays such technological
concepts as Big Data, Complex Networks, Cloud Computing, Data/Text Mining are used to solve these
problems. In cybersecurity, the Ontology approach is increasingly used to build models of subject areas.
[
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]
      </p>
      <p>
        The actual solution to the problem of creating such a corporate system is the simultaneous use of
methods and tools for searching, analyzing and aggregating data from information flows. A system of
monitoring and analysis of social media, automatic processing of full texts from social networks for a
certain period on the topic of "cybersecurity" has been created. Information is scraped from social
networks (blogs, various social networks, websites, messengers, etc.) in search mode. Queries (search
key phrases in the relevant social network, otherwise an account is required) are read by the software
from special configuration tables. Next comes the search and display of records that match the
corresponding queries. After that, unique records are written to the server database. Analysis of existing
approaches to the aggregation of thematic news has led to the need and possibility of creating a set of
tools for monitoring the content of social networks on specific issues, in particular, cybersecurity. The
described system includes personalization tools that provide online access to databases, including from
mobile devices, for which the possibilities of RSS formats are widely used. The choice of
"off-theshelf" software modules is substantiated, the development tools (scrapers for social networks, tools for
generating dynamic RSS-feeds) are described and the results of their integration into the system are
presented. [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]
      </p>
      <p>The intelligent agent system interacts with the management and control system, which ensures an
appropriate level of fault tolerance, completeness and reliability of the information received. As a basis
for control, management, load synchronization and interaction of the intelligent system of data
collection agents developed by the authors, the document-oriented database management system
MongoDB is used, which allows storing information about agents, lists of their corresponding network
sources, and algorithms of agent behavior. The MongoDB NoSQL database can be easily deployed in
most popular operating systems, is undemanding to resources and can withstand heavy loads.</p>
      <p>To provide interaction between a group of agents to obtain information, it is necessary to use a
database that will allow synchronizing and launching agents according to certain settings of the
intelligent system. This database will be used to continuously write and read data. Since in dynamically
growing systems, data volumes tend to increase rapidly, you may encounter a problem when the current
resources of the machine will not be enough for normal operation.</p>
      <p>To solve this problem, scaling is used. Scaling is of two types - horizontal and vertical. Vertical
scaling - increasing the power of one machine - adding CPU, RAM, HDD. Horizontal scaling - adding
new machines to existing ones and distributing data between them. The first case is the simplest because
it does not require additional program settings and any additional database configuration, but its
disadvantage is that it is not suitable for distributed intelligent agents, because each server must run a
replica of the database and it is easy to connect additional servers if necessary. Therefore, in our case,
horizontal scaling will be used, which has the following advantages:
almost infinite scaling (you can include as many machines as you want);
better data security (only if replication is used) - machines can be located in different data centers
(if one of them fails, the others will remain).</p>
      <p>In this scheme, in addition to sharing, there is segment replication. Let us say a few words about it.
All write, delete and update operations go to the primary (primary), and then are written to a special
collection oplog, from where they are asynchronously transferred to replicas - repl.1 and repl.2
(secondary). Thus, data duplication occurs. Why is it necessary?</p>
      <p>1. Redundancy provides data security - if the master fails, a vote is taken between the replicas and
one of them becomes the master.</p>
      <p>2. Master and replicas can be located in different data centers - this can be useful if the server is
physically damaged (fire in the data center).</p>
      <p>3. Replicas can be used to read data more efficiently. For example, there is an application that has
a clientele in Europe and the USA. One replica can be placed in the United States and configured so
that American clients read data from it. It should be noted that documents to replicas are received with
a delay and it is not always possible to immediately find a document re-recorded to a replica. Therefore,
this item is an advantage only if the program logic allows reading on replicas.</p>
      <p>4. The replica set scheme is often used in serious production applications where data security is
important or there is a large number of reads, and the application logic allows reading from replicas.</p>
      <p>We will not dwell on this scheme in detail, because it can be a subject of a separate paper.</p>
      <p>In order to ensure the simultaneous process of obtaining information from social networks without
the use of third-party paid services, as well as to control and manage such a system from a single place,
it is proposed to introduce agent teams that allow you to download and exchange data with each other
and ensure the integrity of the data received and distribute the load among themselves.</p>
      <p>Access control systems in popular social networks are focused on detecting unusual user behavior.
In order to avoid such "non-standard behavior", special algorithms for agents' access to such networks
were created, which took into account the amount of time spent in these networks, the amount of
information collected per request, and the amount of information provided by such a social network
agent. It should also be noted that certain attention in such services is paid to the behavior of clients at
night (from the region from which the request is made), since during this period the number of requests
from clients should be minimized, otherwise such clients are already an object for research.</p>
      <p>In the pilot model of the system of intelligent agents for collecting information for distributed
interaction ("Nabla" system, ∇), the authors used 3 servers that were geographically located in different
data centers, at a great distance from each other (Fig.1):
1. Netherlands;
2. Ukraine;
3. United States of America.</p>
      <sec id="sec-3-1">
        <title>Figure 1: Scheme of distributed information retrieval based on 3 servers </title>
        <p>MongoDB database cluster, intelligent management system and agent commands for information
retrieval are deployed on these servers. For management and interaction between agents, the HTTPS
protocol is used, as it is the most popular protocol on the global Internet, which allows you to quickly
optimize commands for network agents and has an appropriate level of security.</p>
        <p>Also use RESTful service architecture as the basis for these agent commands, which allows you to
configure and monitor their operation efficiently. They also use system messages like Heartbeat as the
basis of their interaction, which allows them to efficiently explore the lifecycle of agents and, if any of
them fails, quickly identify the problem without losing the data received.</p>
        <p>The proposed ∇ teams of agents represent a high availability cluster in which, if one agent fails, its
functions are taken over by another available agent. Thus, the process of obtaining information from
social networks continues continuously due to the intelligent management and control of these agents.
In order to build a fault-tolerant structure, at least two physical servers with storage systems are
required, so an auxiliary third server is used to provide fault tolerance on two servers, which allows
efficient use of resources and even load balancing between the two servers. Also, the intelligent system
of management and control of network agents operates on the following principle: when one agent fails,
the other one is automatically included in the work with a message about the agent failure.</p>
        <p>A separate agent in the system normally operates in the following scenario (Fig. 2): The agent has a
local registry of collected documents, which is constantly synchronized with the general registry stored
in the MongoDB DBMS environment. According to the time schedule, the agent selects the task of
checking the information resource or part of it, accesses the registers to avoid repeated scanning. Then,
if necessary, the information is collected and loaded into the information proxy. Meta-information is
written to the local and general registers. The agent then selects a new task again and so on. The process
can only end at the command of the system administrator.</p>
      </sec>
      <sec id="sec-3-2">
        <title>Figure 2: Scheme of the information collection agent functioning </title>
        <p>The general logic of the agent cluster is created at the level of software protocols and allows users
to:
1. Manage all network agents with a single intelligent module;
2. Add and update software and hardware resources without system shutdown or major architecture
changes;
3. Ensure uninterrupted system operation in case of failure of one or two agents;
4. synchronize data between clusters of agents;
5. Efficiently distribute requests to agent clusters;
6. Use a common database of agents.</p>
        <p>One of the servers in the cluster is the central server of the cluster. The central server, in addition to
serving client connections, manages the entire cluster and maintains a cluster registry for this purpose.</p>
        <p>When a connection is established, the agent communicates with the cluster’s central server. The
central server, based on the analysis of the agent's workload statistics, directs it to the specific workflow
it should perform.</p>
        <p>So, the main task of the agent cluster is to eliminate system downtime and report how much the
agents collected themselves and how much they took from other agents. Ideally, any incident related to
external interference or failure of an internal resource should allow the system to continue working.</p>
        <p>In the distributed system under consideration, shared memory, through which different agents can
exchange data, is almost never used. Thus, traditional synchronization and communication methods can
be considered excluded. It is a set of autonomous agents that are logically combined in communication
networks to perform the task of collecting and exchanging data and information about them. With the
help of individual agents and MongoDB-based control and management tools, distributed actions are
coordinated and information is exchanged.</p>
        <p>The considered system of intelligent agents for collecting information, which monitors distributed
content, is currently used in the InfoStream and CyberAggregator systems, which distribute monitoring
by language (Ukrainian, English, German, Italian, Spanish, French, etc.), by segments of the Internet
(web resources, social networks: Youtube, Twitter, Telegram, Facebook, etc.). In this case, information
proxies, covering information collected by their respective teams of intelligent agents, process
individual segments of the Internet. This approach reduces the load on computing resources by
distributing the power of processor modules and global network segments.</p>
        <p>Models built using data mining algorithms can be used to make decisions about connecting an
additional source. For example, when outliers appear in the time series of the main data stream, a model
that identifies such outliers can be used to determine whether it is an error. The model can be built from
previously collected data and emergent situations resolved by experts. In addition, if there is feedback
from an analyst while receiving data, it can learn, thus adapting to current conditions.</p>
        <p>To make a decision on connecting a new source, it is proposed to use methods of intelligent analysis.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>3. Intelligent collection of information for analysis </title>
      <p>Raw data analysis can be an alternative to collecting all data before performing the analysis. This
approach includes the following key steps:
1. Selecting the main data sources;
2. The primary analysis is performed based on information from these data sources;
3. Prioritizing the query for each data source;
4. Can be done based on different criteria;
5. Requesting other data sources, depending on requirements, if information from the basic data
sources is not sufficient for the preliminary analysis and/or the probability that the results are correct is
low (e.g. outliers and/or jumps are detected in the data);</p>
      <p>6. Data processing and evaluation of results performed separately from the main task, if possible
close to the data source (preferably at the node where the data are located or in its local network).</p>
      <p>
        Internet solution systems use cloud computing technologies to analyze data and solve problems with
computing resources [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. The cloud provides scalable computing resources and other tools for creating
analytical services. However, this approach retains the listed disadvantages. To solve them, Cisco
proposed the concept of fog computing [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ].
      </p>
      <p>It extends cloud computing closer to the sources. Fog computing completely solves or reduces the
impact of a number of common problems of distributed systems:
1. High network latency;
2. Scalability of information sources;
3. Difficulties associated with endpoint mobility;
4. High cost of bandwidth;
5. Large geographical distribution of systems.</p>
      <p>
        Despite the advantages and popularity of the fog computing concept, there are no ready-made
solutions for its implementation. This is explained by both the youth of the concept and the high level
of abstraction. One of the solutions that corresponds to the concept of fog computing is distributed data
analysis based on intelligent agents (actors) [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
      </p>
      <p>It can be used for both cloud and fog computing. The proposed approach allows splitting data mining
algorithms into "pure" functions and executing them on distributed sources.</p>
      <p>
        The data mining algorithm is represented as a sequence of function calls. For their parallel execution,
a function is added that allows parallelizing algorithms. For execution in a distributed environment, the
data mining algorithm decomposed into functions was compared with the model of intelligent agents
(actors). Thus, the distributed data analysis algorithm is represented as a set of agents that exchange
messages with the main agent. Intelligent agents (actors) transfer part of the computation to the sources,
which improves the analysis performance and reduces the network traffic between the sources and the
cloud. However, this approach has some limitations: it does not allow prioritizing data sources and
querying data according to their priorities. In addition, the cost of queries from data sources is not taken
into account [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
      </p>
      <p>Consider a simpler system of two agents (Agent 1 and Agent 2), shown in Figure 3, which collect
information from an information resource on behalf of two users (User 1 and User 2). The collected
information is placed on proxy servers (Proxy 1 and Proxy 2). The information needs of users are
represented by query packages (Query 1 and Query 2). If agents make these requests to an information
resource (for example, social networks YouTube or Twitter), they may receive several documents R1
and R2, which may coincide - the same documents may satisfy the conditions of different requests.</p>
      <p>The rational application of the dual-agent system is to avoid double collection of the same
documents due to the interaction of agents. For both request packages, documents already collected by
one agent are collected by the second agent not from an external information resource, but from the
corresponding information proxy. In this case, the benefit (K) from the application of this scheme of
information collection can be calculated as a coefficient:

|1 ∨ 2
|1 ∪ 2
|
|
,
where R1 is resource 1, R2 is resource 2.</p>
    </sec>
    <sec id="sec-5">
      <title>4. Conclusions </title>
      <p>This paper presents an algorithm for distributed content search agents based on OSINT fundamentals
and demonstrates the main possibilities of its use. At the same time, it becomes obvious how diverse
and powerful information retrieval processes can be optimized through their interaction. In addition, a
mechanism for building a cluster of distributed agents has been presented. It ensures the correct
extraction of information. It becomes obvious that the OSINT algorithm is constantly changing and
improving, as the owners of open information try to provide a minimum level of access to their
resources to other systems.</p>
      <p>Based on the testing and evaluation of these network agents, which extract content from the web and
social networks and consist of 3 servers, it can be concluded that the proposed interaction is effective.
The proposed architecture provided the pilot system with an appropriate level of fault tolerance and
reliability of the information received and ensured uniform loading of agent clusters.</p>
      <p>In addition, the presented system performs the security tasks of the monitoring service, which allows
it to ensure the integrity of the received data, bypassing the limitations in the collection of information,
the availability of data for monitoring and the completeness of the received information. If the
(1) 
information for any country is changed, distorted, agents in interaction with each other will reflect these
changes and save all copies of the received data.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>D. V.</given-names>
            <surname>Lande</surname>
          </string-name>
          ,
          <article-title>Analysis of information flows in global computer networks</article-title>
          ,
          <source>Bulletin of the National Academy of Sciences of Ukraine- No</source>
          <volume>3</volume>
          (
          <year>2017</year>
          ), pp.
          <fpage>46</fpage>
          -
          <lpage>54</lpage>
          . doi:
          <volume>10</volume>
          .15407/visn2017.
          <fpage>03</fpage>
          .045.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>H.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Gegov</surname>
          </string-name>
          , and М. Cocea,
          <article-title>Rule Based Systems for Big Data. A Machine Learning Approach</article-title>
          . Heidelberg, Germany: Springer,
          <year>2016</year>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -23696-4.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>M.</given-names>
            <surname>Glassman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. J.</given-names>
            <surname>Kang</surname>
          </string-name>
          ,
          <article-title>Intelligence in the internet age: The emergence and evolution of Open Source Intelligence (OSINT)</article-title>
          ,
          <source>Computers in Human Behavior</source>
          ,
          <year>2012</year>
          , volume
          <volume>28</volume>
          ,
          <source>No. 2</source>
          , pp.
          <fpage>673</fpage>
          -
          <lpage>682</lpage>
          . doi:
          <volume>10</volume>
          .1016/j.chb.
          <year>2011</year>
          .
          <volume>11</volume>
          .014.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <source>[4] Army Techniques Publication No. 2-22.9 (FMI 2-22.9)</source>
          ,
          <source>Headquarters Department of the Army, ATP 2-22</source>
          .9 (Washington, DC, 10
          <year>July 2012</year>
          ), URL: https://fas.org/irp/doddir/army/atp2-22-9.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>A. N.</given-names>
            <surname>Grigoryev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. V.</given-names>
            <surname>Lande</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. A.</given-names>
            <surname>Borodenkov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. V.</given-names>
            <surname>Mazurkevich</surname>
          </string-name>
          , and
          <string-name>
            <given-names>V. N.</given-names>
            <surname>Poter</surname>
          </string-name>
          , InfoStream.
          <article-title>Monitoring News from the Internet: Technology, System, and Service</article-title>
          . Kyiv, Ukraine: Start-
          <volume>98</volume>
          ,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>S.</given-names>
            <surname>Choi</surname>
          </string-name>
          ,
          <string-name>
            <surname>B. Bae,</surname>
          </string-name>
          <article-title>The real-time monitoring system of social big data for disaster management</article-title>
          ,
          <source>Computer science and its applications</source>
          . - Springer, Berlin, Heidelberg,
          <year>2015</year>
          , pp.
          <fpage>809</fpage>
          -
          <lpage>815</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>662</fpage>
          -45402-2_
          <fpage>115</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>A.</given-names>
            <surname>Hannemann</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Liiva</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Klamma</surname>
          </string-name>
          ,
          <article-title>Navigation Support in Evolving Open-Source Communities by a Web-Based Dashboard</article-title>
          ,
          <source>IFIP International Conference on Open Source Systems</source>
          . - Springer, Berlin, Heidelberg,
          <year>2014</year>
          , pp.
          <fpage>11</fpage>
          -
          <lpage>20</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>642</fpage>
          -55128-
          <issue>4</issue>
          _
          <fpage>2</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>A. M.</given-names>
            <surname>Sobolev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. V.</given-names>
            <surname>Lande</surname>
          </string-name>
          ,
          <article-title>Distributed Intelligent Content Extraction Agents from Social Networks"</article-title>
          .
          <source>Proceedings of the Scientific and Practical Conference "Information and Telecommunication Systems and Technologies and Cybersecurity: New Challenges, New Tasks". - Kyiv: Igor Sikorsky Institute of Cybernetics</source>
          ,
          <year>2021</year>
          , pp.
          <fpage>274</fpage>
          -
          <lpage>275</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>J.</given-names>
            <surname>Gubbi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Buyya</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Marusic</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Palaniswami</surname>
          </string-name>
          ,
          <article-title>Internet of Things (IoT): A vision, architectural elements, and future directions</article-title>
          .
          <source>Future Generation Computer Systems</source>
          ,
          <year>2013</year>
          , No 29, pp.
          <fpage>1645</fpage>
          -
          <lpage>1660</lpage>
          . doi:
          <volume>10</volume>
          .1016/j.future.
          <year>2013</year>
          .
          <volume>01</volume>
          .010.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>F.</given-names>
            <surname>Bonomi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Milito</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Zhu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Addepalli</surname>
          </string-name>
          ,
          <article-title>Fog computing and its role in the internet of things</article-title>
          .
          <source>Proc. MCC</source>
          , Helsinki, Finland,
          <year>2012</year>
          , pp.
          <fpage>13</fpage>
          -
          <lpage>15</lpage>
          . URL:https://conferences.sigcomm.org/sigcomm/2012/paper/mcc/p13.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>I.</given-names>
            <surname>Kholod</surname>
          </string-name>
          , I. Petuhov,
          <string-name>
            <given-names>N.</given-names>
            <surname>Kapustin</surname>
          </string-name>
          ,
          <article-title>Creation of data mining cloud service on the actor model</article-title>
          .
          <source>Internet of Things, Smart Spaces, and Next Generation Networks and Systems</source>
          . Springer,
          <year>2015</year>
          , pp.
          <fpage>585</fpage>
          -
          <lpage>598</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -23126-6_
          <fpage>52</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>M. S. Efimova</surname>
          </string-name>
          <article-title>Smart data collection from distributed data sources</article-title>
          <source>Software &amp; Systems Received</source>
          ,
          <year>2019</year>
          , vol.
          <volume>32</volume>
          , no.
          <issue>4</issue>
          , pp.
          <fpage>565</fpage>
          -
          <lpage>572</lpage>
          . doi:
          <volume>10</volume>
          .15827/
          <fpage>0236</fpage>
          -
          <lpage>235X</lpage>
          .
          <fpage>128</fpage>
          .
          <fpage>565</fpage>
          -
          <lpage>572</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>D.</given-names>
            <surname>Lande</surname>
          </string-name>
          ; I.
          <article-title>Subach; A. Puchkov System of Analysis of Big Data from Social Media Information</article-title>
          &amp; Security: An
          <source>International Journal</source>
          <volume>47</volume>
          , no.
          <issue>1</issue>
          (
          <year>2020</year>
          ):
          <fpage>44</fpage>
          -
          <lpage>61</lpage>
          . doi:
          <volume>10</volume>
          .11610/isij.4703.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>R.</given-names>
            <surname>Layton</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Watters</surname>
          </string-name>
          ,
          <article-title>Automating open source intelligence: algorithms for OSINT (Rockland</article-title>
          , MA: Syngress Media,
          <year>2016</year>
          ),
          <article-title>URL: www.bookdepository.com/Automating-Open-</article-title>
          <string-name>
            <surname>SourceIntelligence-</surname>
          </string-name>
          Robert-Layton/9780128029169.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>B.</given-names>
            <surname>Akhgar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Saskia Bayerl</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Sampson</surname>
          </string-name>
          , Open Source Intelligence Investigation: From Strategy to Implementation (Springer International Publishing AG,
          <year>2016</year>
          ), doi:10.1007/978-3-
          <fpage>319</fpage>
          -47671- 1.D.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>U. K. Wiil</surname>
            , Counterterrorism and
            <given-names>Open</given-names>
          </string-name>
          <string-name>
            <surname>Source Intelligence (Wien: SpringerVerlag</surname>
          </string-name>
          ,
          <year>2011</year>
          ), doi:10.1007/978-3-
          <fpage>7091</fpage>
          -0388-3.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>B. J.</given-names>
            <surname>Jansen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. L.</given-names>
            <surname>Booth</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Spink</surname>
          </string-name>
          ,
          <article-title>Determining the informational, navigational, and transactional intent of Web queries</article-title>
          ,
          <source>Information Processing &amp; Management</source>
          ,
          <year>2008</year>
          , volume
          <volume>44</volume>
          , No 3.
          <string-name>
            <surname>- С</surname>
          </string-name>
          .
          <fpage>1251</fpage>
          -
          <lpage>1266</lpage>
          . doi:
          <volume>10</volume>
          .1016/j.ipm.
          <year>2007</year>
          .
          <volume>07</volume>
          .015
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>G.</given-names>
            <surname>Gutin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Mansour</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Severini</surname>
          </string-name>
          ,
          <article-title>A characterization of horizontal visibility graphs and combinatorics on words</article-title>
          ,
          <source>Physica A: Statistical Mechanics and its Applications</source>
          ,
          <year>2011</year>
          , volume
          <volume>390</volume>
          , No.
          <volume>12</volume>
          , pp.
          <fpage>2421</fpage>
          -
          <lpage>2428</lpage>
          . doi:
          <volume>10</volume>
          .1016/j.physa.
          <year>2011</year>
          .
          <volume>02</volume>
          .031.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>