<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Simulation Model of a Fuzzy Cyber Attack Detection System </article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Ihor Subach</string-name>
          <email>igor_subach@ukr.net</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Vitalii Fesokha</string-name>
          <email>vitaliifesokha@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Artem Mykytiuk</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Volodymyr Kubrak</string-name>
          <email>volodymir.kubrak@ukr.net</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Stanislav Korotayev</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Military Institute of Telecommunications and Information Technologies named after Heroes of Kruty</institution>
          ,
          <addr-line>st. Moscow, 45/1, Kyiv, 01011</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>National Technical University of Ukraine "Igor Sikorsky Kyiv Polytechnic Institute"</institution>
          ,
          <addr-line>st.Verkhnoklyuchova, 4, Kyiv, 03056</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>92</fpage>
      <lpage>101</lpage>
      <abstract>
        <p>   The method of applying a simulation model of a fuzzy cyberattack detection system is considered. The functional diagram of the simulation model is given. The block diagram of the simulation model is considered and the purpose of its elements is described. The main steps of using a simulation model for conducting an experimental study of evaluating the effectiveness of models and methods for detecting cyber attacks based on the theory of fuzzy sets and fuzzy inference are described. The procedure for generating initial data is given, the classes of cyberattacks to be detected are defined, the vectors of cyberattack features are identified, the parameters of the studied traffic are described, the types of membership functions are defined to formalize expert knowledge and represent it in the knowledge base in the form of fuzzy production rules. The issue of parametric adaptation of membership functions to clarify the subjective judgments of experts are considered. To implement the possibility of detecting polymorphic cyberattacks, the procedure for determining the required number of the most important features for each known class of cyberattacks, represented by fuzzy sets and linguistic variables that characterize them quite fully, is described. A comparative analysis of the results of modeling the process of detecting cyber attacks based on the proposed approach with existing methods for detecting cyber attacks was carried out, based on the theory of fuzzy sets and fuzzy logic, artificial immune systems and neural networks in terms of accuracy.</p>
      </abstract>
      <kwd-group>
        <kwd>1  Cybersecurity</kwd>
        <kwd>cyber attack</kwd>
        <kwd>IDS</kwd>
        <kwd>simulation model</kwd>
        <kwd>fuzzy set theory</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction </title>
      <p>statistical database - statistics of telemetry of network traffic for a certain period for its further use
in order to improve the system to adapt the parameters of the mechanism of detection of cyber attacks
to existing changes;</p>
      <p>
        scheduler - plans further actions of the system after processing by the analyzer (in case it detects a
cyberattack, the scheduler gives control to the response module to take measures to stop malicious
activity; otherwise, the scheduler gives control to the data analysis module detection cyber attacks
second tier, built on the basis of the developed model of cyberattack detection [
        <xref ref-type="bibr" rid="ref10 ref11 ref8 ref9">8-11</xref>
        ];
fasificationblock - clear values of the studied parameters are turned into fuzzy (the degree of their
belonging to the term sets of linguistic variables specified by experts is determined). Fuzzy network
activity is taken into account based on the application of the model proposed in [
        <xref ref-type="bibr" rid="ref10 ref11 ref8 ref9">8-11</xref>
        ];
fuzzy rule base: contains fuzzy production rules built by experts at the stage of preparing the system
for operation;
      </p>
      <p>adaptation module: performs primary parametric adjustment of membership functions by means of
genetic algorithms on the basis of a certain training sample and further training of the system if
necessary on the basis of statistical data to clarify the values of cyber attack detection mechanism;
fuzzy inference block - a module for making decisions about the state of the network based on
determining the relationship between input data (telemetry of network traffic) and expert opinions by
means of fuzzy logic;
 
Figure 1. Architecture of a promising fuzzy intelligent system for detecting cyber attacks 
response module - generates requests and notifications to the console, takes protective measures to
block detected cyberattacks, as well as fills the database of statistical decisions on their decisions for
further use by the adaptation module;
management console: module for configuring the cybersecurity officer of the system parameters.</p>
      <p>The application of the proposed IDS architecture allows to increase the efficiency of detecting
cyberattacks in near real time, based on the application of a multi-tiered approach to their detection. In
addition, it becomes possible to adapt the system to the detection of unknown types of cyber attacks
(zero day), as well as increase the efficiency of the cybersecurity officer on such indicators as efficiency
and soundness of decision-making.</p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref10 ref11 ref8 ref9">8-11</xref>
        ] – models and methods for detecting known and polymorphic cyber attacks based on the
theory of fuzzy sets and fuzzy inference. Formally, the task of fuzzy identification of a cyber attack is
to find a solution to analytical expression that connects a set of parameters of the state of the system,
on the basis of which its anomalous behavior is determined and an expert solution that meets them,
taking into account the weighting coefficients for fuzzy rules (Figure 2):
      </p>
      <p>X *  x1*, x2* ,, xn*   y  a1jk j , a2jk j ,, anjk j  D  d1, d 2 ,d n ,i  1, n, j  1, m,
(1)
where X  x1, x2 ,, xn  is a set of parameters of the information and communication system (ICS)
which are analyzed;
y is a linguistic description of the expert decision (opinion) d j  D on the state of ICS;
jk j is a numbers of combinations of values of xi of the parameters of ICS state description,
corresponding to the value of d j .</p>
      <p>Input Parameters
(Signs of Cyber Attacks)
x1
x2
y*D.

xn</p>
      <sec id="sec-1-1">
        <title>Fuzzy</title>
        <p>knowledge
base
(fuzzy
rules)</p>
      </sec>
      <sec id="sec-1-2">
        <title>Logic output unit</title>
        <p>Solution:
Cyber Attack Class
d1
d2
y*D.

dm
d
Figure 2. Graphical interpretation of the problem of cyber attack identification </p>
        <p>
          To evaluate the effectiveness of the proposed solutions, a system simulation model (FIDM – Fuzzy
Intrusion Detection Model) was developed using the Fuzzy Logic Toolbox™ package,which provides
MATLAB® functions and the Simulink® block [
          <xref ref-type="bibr" rid="ref13 ref14 ref15">13, 14, 15</xref>
          ] for designing and modeling systems based
on fuzzy logic.
2. Functional and structural diagram of the simulation model 
        </p>
        <p>The functional diagram of the simulation model is shown in Figure 3, where x1..xn are input
parameters and y is an output variable.</p>
        <p>
          The basis of the proposed simulation model is a modular diagram for organizing sequential iterative
interaction between its components: a data input module for analysis, a fuzzification module, a
knowledge base (KB), a fuzzy inference and defuzzification module [
          <xref ref-type="bibr" rid="ref13 ref14 ref15">13, 14, 15</xref>
          ]. The structure diagram
of the developed simulation model is shown in Figure 4.
        </p>
        <p>
          For the operation of the test data input module [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ], is a set of statistical data on cyberattacks KDD
        </p>
      </sec>
      <sec id="sec-1-3">
        <title>Cup 1999 Data (xlsx files) was used.</title>
        <p>The purpose of the fuzzification module is to represent the quantitative and qualitative values of the
studied parameters using term sets and linguistic variables. Incomplete and uncertain data on network
activity were taken into account by applying the developed model of cyber attack detection.</p>
        <p>Additional rules generation module was used to create new fuzzy production rules in the knowledge
base by intersecting fuzzy sets of linguistic variables of previously existing rules and the most
significant linguistic variables predefined by an expert for each class of cyberattacks.</p>
      </sec>
      <sec id="sec-1-4">
        <title>The knowledge base is a set of fuzzy production rules built by an expert. 94</title>
        <p>Figure 3. Functional diagram of the FIDM simulation model 
Figure 4. Structure diagram of the developed simulation model </p>
        <p>The purpose of the fuzzy inference module is to generate a decision about the state of the information
and communications network based on determining the relationship between input data and expert
conclusions using fuzzy logic.</p>
        <p>The defuzzification module was used to convert the obtained values of the fuzzy inference into crisp
ones.
3. Methodology of applying the simulation model </p>
      </sec>
      <sec id="sec-1-5">
        <title>Step 1: Defining is a set of cyber attackstatistics: KDD Cup 1999 Data [16].</title>
        <p>
          Step 2. Defining the classes of cyberattacks to be detected [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ]: Denial of Service, Remote to Local,
        </p>
      </sec>
      <sec id="sec-1-6">
        <title>User to Root, Probe and normal states of the ICS. Step 3. The input of the simulation model was fed with vectors of cyber attacks of the KDD Cup 1999 Data set in the number of: known – Denial of Service – 4264, Remote to Local – 1020, User to 95</title>
        <p>Root – 52, Probe – 3231; normal states of the information system – 1000; polymorphic cyberattacks
built on the basis of known ones – 100. Thus, the total number of attribute vectors was 9667.</p>
        <p>For the study, 38 parameters of network traffic telemetry were selected based on the classification
proposed in the chosen data set on cyberattacks (Table 1).
 
Table 1 
The studied parameters of network traffic </p>
        <p>Code  Parameter 
x1  duration  
x2  src_bytes 
x3 
x4 
x5 
x6 
x7 
x8 
x9 
x10 
x11 
x12 
x13 
x14 
x15 
x16 
x17 
x18 
x19 
x20 
x21 
x22 
x23 
x24 
x25 
x26 
x27 
x28 
x29 
dst_bytes 
land   
wrong_fragment 
urgent  
hot  
num_failed_logins 
logged_in 
num_compromised 
root_shell 
su_attempted 
num_root 
num_file_creations 
num_shells 
num_access_files 
num_outbound_cmds 
is_host_login 
is_guest_login 
count  
srv_count 
serror_rate 
srv_serror_rate 
rerror_rate 
srv_rerror_rate 
same_srv_rate 
diff_srv_rate 
srv_diff_host_rate 
dst_host_count </p>
        <p>Description 
Connection time in seconds 
Number  of  bytes  from  source  to 
destination 
Number  of  bytes  in  the  response  to  the 
client 
1  if  the  connection  is  from/to  the  same 
host/port 
Number of false fragments 
Number of urgent packages 
Number of hot indicators 
Number of failed registration attempts 
1 if successful login; 0 unsuccessful 
Number of compromising conditions 
1 if a root shell is obtained; otherwise 0 
1 if su root was executed; otherwise 0 
Number of root accesses 
Number of file creation operations 
Number of shell requests  
Number  of  operations  to  access  file 
control  
Number  of  FTP  session  output 
commands 
1 if the login belonged to the hot list 
1 if guest login 
Number  of  connections  in  the  current 
session in the last 2 sec. 
Number  of  connections  to  the  same 
service in the last 2 sec. 
% of connections that had SYN errors 
%  of  connection  with  an  error  in  SYN 
packet 
% of connections that had REJ errors 
% of connections with REJ errors 
% of connections having the same service 
% of connections to different services 
% connections from other hosts 
Number  of  connections  to  the  host 
established by the remote party 
dst_host_srv_count 
dst_host_same_srv_rate 
dst_host_diff_srv_rate 
dst_host_same_src_port_rate 
dst_host_srv_diff_host_rate 
dst_host_serror_rate 
dst_host_srv_serror_rate 
dst_host_rerror_rate 
dst_host_srv_rerror_rate </p>
        <p>Number  of  connections  to  the  host 
established by the remote party that use 
one service 
%  of  connections  to  the  local  host 
established  by  the  remote  party  using 
one service 
%  of  connections  to  the  local  host 
established  by  the  remote  party  using 
different services 
%  of  connections  to  the  host  at  the 
current source port number 
%  of  connections  to  the  service  of 
different hosts 
% of connections with SYN error for the 
destination host 
% of connections with SYN error for the 
receiver service 
%  of  connections  with  REJ  error  for  the 
destination host 
%  of  connections  with  REJ  error  for  the 
receiver service 
 </p>
        <p>
          Step 4. Defining the type of membership functions to describe the ranges of values of the studied
parameters and the power of term sets for input and output linguistic variables: triangular membership
functions (2) due to the ability to undergo parametric adaptation (refinement) while maintaining an
acceptable level of computational complexity [
          <xref ref-type="bibr" rid="ref17 ref18 ref19 ref20 ref21 ref22">17-22</xref>
          ], term set power – 7 (number: VS is acronym for
“very small”, S is acronym for “small”, BA is acronym for “below average”, A is acronym for
“average”, AA is acronym for “above average”, L is acronym for “large”, VL is acronym for “very
large”).
 0, x  a 
 x  a 
f x, a,b, c  bc  ax ,,ba  xx  cb , (2)
 c  b 
 0, x  c 
where a, b, c is a some numeric parameters that take arbitrary real values and are ordered by relations:
a  b  c .
        </p>
        <p>Step 5. Defining input and output linguistic variables: 38 input linguistic variables that correspond
to the number of studied parameters of network traffic and one output – an indicator of the state of the
information and communications system. Each input value ( ) corresponds to the network traffic
parameter according to the KDD Cup 1999 Data, and the membership functions configured by the
expert are represented by term sets.</p>
        <p>x1 – {VS – very small [0, 250, 510], S –small [500, 1000, 1500], BA – below average [1400, 2000,
2500], A – average [4000, 5250, 6500], AA – above average [6400, 8500, 10500], L – large [10400,
15500, 20500], VL – very large [20000, 31000, 42500]} on the universe [0, 42500];
x2 – {VS – very small [0, 250, 550], S –small [520, 1000, 1500], BA – below average [1400, 5500,
10500], A – average [10000, 12500, 25500], AA – above average [25000, 40000, 54550], L – large
[2500000, 77000000, 150000000], VL – very large [120000000, 350000000, 700000000]} on the
universe [0, 700000000];
x3 – {S –small [0, 500, 1000], BA – below average [1000, 5000, 9999], A – average [10000, 60000,
100000], AA – above average [125000, 600000, 1000000], L – large [1100000, 1800000, 2500000],
VL – very large [2400000, 3500000, 5250000]} on the universe [0, 5250000];</p>
        <p>
          x4 , x9 , x11, x12, x17 , x18 , x19 , x24 , x25 – {S –small [0, 0.25, 0.5], L – large [0.5, 1, 1.5]} on the universe
x7 – {S –small [
          <xref ref-type="bibr" rid="ref10 ref5">0, 5, 10</xref>
          ], A – average [
          <xref ref-type="bibr" rid="ref21 ref25">21, 25, 30</xref>
          ], L – large [
          <xref ref-type="bibr" rid="ref10 ref15 ref22">10, 15, 22</xref>
          ]} on the universe [0, 30];
x8 – {S –small [0, 0.25, 0.5], A – average [0.5, 1, 1.5], L – large [
          <xref ref-type="bibr" rid="ref4 ref5 ref6">4, 5, 6</xref>
          ]} on the universe [
          <xref ref-type="bibr" rid="ref6">0, 6</xref>
          ];
x10 – {S –small [
          <xref ref-type="bibr" rid="ref10 ref5">0, 5, 10</xref>
          ], L – large [15, 27.5, 40]} on the universe [0, 40];
x13 – {S –small [
          <xref ref-type="bibr" rid="ref10 ref5">0, 5, 10</xref>
          ], A – average [
          <xref ref-type="bibr" rid="ref10 ref15 ref20">10, 15, 20</xref>
          ], L – large [30, 42.5, 55]} on the universe [0, 55];
x14 – {S –small [
          <xref ref-type="bibr" rid="ref2 ref5">0,2,5</xref>
          ], L – large [20,22.5,25]} on the universe [
          <xref ref-type="bibr" rid="ref25">0,25</xref>
          ];
Figure 5.Graphical representation of the described linguistic terms of membership function 
x15 , x16 – {S –small [0, 50, 101], A – average [99, 200, 305], L – large [300, 400, 515]} on the
universe [0, 515];
x22 , x23, x26 , x27 , x28 – {S –small [0, 0.25, 0.6], L – large [0.5, 0.8, 1.2]} on the universe [0, 1.2];
x29 , x30 – {S –small [0, 50, 105], A – average [100, 150, 205], L – large [200, 230, 260]} on the
universe [0, 260];
        </p>
        <p>x31, x32 , x33, x34 , x35 , x36 , x37 , x38 – {S –small [0, 0.25, 0.6], L – large [0.5, 0.8, 1.2]} on the universe
[0, 1.2].</p>
        <p>Step 6. Preparing test data format of KDD Cup 1999 Data for the Fuzzy Logic Toolbox™ software.</p>
        <p>
          Step 7. Creating fuzzy production rules for the KB based on the KDD Cup 1999 Data set using
association rule search algorithms (Fig. 6) [
          <xref ref-type="bibr" rid="ref23 ref24">23, 24</xref>
          ].
        </p>
        <p>Step 8. Obtaining expert conclusions about the state of IP according to the classification of cyber
attacks presented in the KDD Cup 1999 Data: Denial of Service, Remote to Local, User to Root, Probe
and normal state: total number of rules: 335, of which Denial of Service – 68; Remote to Local – 55;
User to Root – 18; Probe – 107; Normal – 87.</p>
        <p>
          Step 9. Parametric adaptation of constructed membership functions [
          <xref ref-type="bibr" rid="ref25 ref26 ref27">25, 26, 27</xref>
          ] in order to clarify
the subjective point of view of the expert by means of the Optimization Tool package of MATLAB®
software [
          <xref ref-type="bibr" rid="ref13 ref14 ref15">13, 14, 15</xref>
          ]: on the basis of the frequent data sets found at the previous stage, parametric
optimization of membership functions was performed for the above terms of each studied variable
(search for the optimum of the parameter vector of the system of equations of the analytical model of
the triangular membership function).
        </p>
        <p>Step 10. Determining the required number of the most important (informative) parameters (features)
for each known class of cyberattacks, represented as fuzzy sets of linguistic variables that characterize
them quite fully in order to be able to identify polymorphic modifications of known cyberattacks:</p>
        <p>X dos  x1, x3 , x5 , x20 , x21, x22 , x23 , x26 , x28 , x29 , x30 , x31, x32 , x33;
 </p>
        <p>X r2l  x1, x2 , x3 , x7 , x9 , x20 , x21, x26 , x28 , x29 , x30 , x31, x32 , x33 , x34 , x35 , x36 ;
X u2r   x2 , x3 , x9 , x26 , x27 , x29 , x31, x32 , x33 , x37 , x38 ;</p>
        <p>X probe   x20 , x21 , x24 , x25 , x26 , x27 , x29 , x30 , x32 , x37 , x38 .</p>
        <p>Figure 6. Associative rules search box in Open‐Source Data Mining Library SPMF 
 </p>
        <p>Step 11. Obtaining additional fuzzy production rules for KB based on the actions taken in the
previous step and removing duplicate rules. As a result, new rules were obtained in the following
quantity: Denial of Service – 48; Remote to Local – 14; User to Root – 13; Probe – 16. The total number
of rules in the KB – 426.</p>
        <p>Step 12. Application of the developed program code for the correct input of data from the cyberattack
data set for further analysis by the Fuzzy Logic Toolbox™ library.
 
Table 2. 
Comparative analysis of simulation results </p>
        <p>Immune  Neural  Fuzzy  Suggested 
Cyber attack class </p>
        <p>systems  networks  logic  method 
DoS  0,98  1,0  0,94  1,0 
 
R2L 
U2L 
Probe </p>
        <p>Normal 
Polymorphic (DoS) 
Polymorphic (R2l) </p>
        <p>Polymorphic (U2r) 
Polymorphic (Probe) 
0,90 
0,97 
0,96 
0,97 
‐ 
‐ 
‐ 
‐ </p>
        <p>Step 13. Conducting experimental studies on cyber attack detection by a developed simulation
model, the functioning of which is based on the application of models and methods and comparative
analysis of the results of modeling the process of detecting cyber attacks based on the proposed
approach with existing methods for detecting cyber attacks: based on the theory of fuzzy sets and fuzzy
logic, artificial immune systems and neural networks in terms of accuracy.</p>
        <p>Accuracy  TD , (3)</p>
        <p>TD  FN
where TD (True Detection) is the number of correctly detected cyber attacks;</p>
      </sec>
      <sec id="sec-1-7">
        <title>FN (False Negative) is a type II errors (classifying a cyber attack as a normal state).</title>
        <p>A comparative analysis of the results of modeling the process of cyber attack detection based on the
approach proposed in the study and existing solutions in terms of accuracy are presented in Table 2.</p>
        <p>
          The results of the study were included in the methodology of rational choice of security incident
management system for building operational security center [
          <xref ref-type="bibr" rid="ref28">28</xref>
          ].
        </p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>4. Conclusion </title>
    </sec>
    <sec id="sec-3">
      <title>References </title>
      <p>The practical application of the developed simulation model of a fuzzy cyber attack detection system
showed the expediency of using it to evaluate models and methods of cyber attack detection based on
the theory of fuzzy sets and fuzzy inference. Thus, the comparison of the developed scientific and
methodological apparatus with the already available ones shows that its use makes it possible to increase
the effectiveness of information systems cyber protection in terms of the accuracy of detecting known
cyber attacks by an average of 10%, as well as to ensure the detection of polymorphic cyber attacks in
terms of accuracy of at least 98 %.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kubrak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Mykytiuk</surname>
          </string-name>
          ,
          <article-title>Architecture and functional model of a promising proactive intelligent system SIEM-system for cyber protection of critical infrastructure</article-title>
          ,
          <source>Information Technology and Security</source>
          Vol.
          <volume>7</volume>
          Iss. 2 (
          <year>2019</year>
          )
          <fpage>208</fpage>
          -
          <lpage>215</lpage>
          . doi:
          <volume>10</volume>
          .20535/
          <fpage>2411</fpage>
          -
          <lpage>1031</lpage>
          .
          <year>2019</year>
          .
          <volume>7</volume>
          .2.190570.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Fesokha</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Fesokha</surname>
          </string-name>
          ,
          <article-title>Analysis of existing intrusion prevention solutions in information and telecommunication networks, opened on the basis of publicly available licenses</article-title>
          ,
          <source>Information Technology and Security</source>
          Vol.
          <volume>5</volume>
          Iss. 1 (
          <year>2017</year>
          )
          <fpage>29</fpage>
          -
          <lpage>41</lpage>
          . doi:
          <volume>10</volume>
          .20535/
          <fpage>2411</fpage>
          -
          <lpage>1031</lpage>
          .
          <year>2017</year>
          .
          <volume>5</volume>
          .1.120554.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <source>[3] IDS architecture</source>
          ,
          <year>2015</year>
          . URL: https://studfile.net/preview/1665659/page:28.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <source>[4] Intrusion detection system architecture</source>
          ,
          <year>2020</year>
          URL: https://studref.com/521846/informatika/arhitektura_sistem_obnaruzheniya_vtorzheniy.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>D.</given-names>
            <surname>Levonevsky</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Fatkieva</surname>
          </string-name>
          ,
          <article-title>Development of a system for detecting network traffic anomalies</article-title>
          ,
          <source>Scientific Bulletin of NGTU</source>
          Vol.
          <volume>56</volume>
          Iss.
          <volume>3</volume>
          (
          <year>2014</year>
          )
          <fpage>108</fpage>
          -
          <lpage>114</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>J.</given-names>
            <surname>Rabatel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Bringay</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Poncelet</surname>
          </string-name>
          ,
          <article-title>Fuzzy anomaly detection in monitoring sensor data</article-title>
          :
          <source>IEEE International Conference on Fuzzy Systems</source>
          , Inc.,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>M.</given-names>
            <surname>Dodonov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Dodonova</surname>
          </string-name>
          ,
          <article-title>Automated detection system of insider attacks using fuzzy logic: Information Technology and Nanotechnology (ITNT-</article-title>
          <year>2015</year>
          ), Inc.,
          <year>2015</year>
          , pp.
          <fpage>376</fpage>
          -
          <lpage>380</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kubrak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Mykytiuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Korotaiev</surname>
          </string-name>
          ,
          <article-title>Zero-day polymorphic cyberattacks detection using fuzzy inference system</article-title>
          ,
          <source>Austrian Journal of Technical and Natural</source>
          Sciences Vol.
          <volume>5</volume>
          -
          <issue>6</issue>
          , (
          <year>2020</year>
          )
          <fpage>8</fpage>
          -
          <lpage>13</lpage>
          . doi:
          <volume>10</volume>
          .29013/AJT-20-
          <issue>5</issue>
          .
          <fpage>6</fpage>
          -8-13.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Zdorenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Fesokha</surname>
          </string-name>
          .
          <article-title>Methods of detecting JS(HTML)/Scrinjectcyber attacks based on the application of the mathematical apparatus of fuzzy set theory</article-title>
          ,
          <source>Proceedings of the Heroes of Kruty Military Institute of Telecommunications and Informatization Iss</source>
          .
          <volume>4</volume>
          (
          <year>2018</year>
          )
          <fpage>125</fpage>
          -
          <lpage>131</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Fesokha</surname>
          </string-name>
          .,
          <article-title>A model for detecting cyber attacks on information and telecommunication systems based on the description of anomalies in their operation by weighted fuzzy rules</article-title>
          ,
          <source>Information Technology and Security</source>
          Vol.
          <volume>5</volume>
          . Iss.
          <volume>2</volume>
          (
          <year>2017</year>
          )
          <fpage>145</fpage>
          -
          <lpage>152</lpage>
          . doi:
          <volume>10</volume>
          .20535/
          <fpage>2411</fpage>
          -
          <lpage>1031</lpage>
          .
          <year>2017</year>
          .
          <volume>5</volume>
          .2.136984.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kubrak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Mykytiuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Korotaev</surname>
          </string-name>
          ,
          <article-title>Rule-oriented method of cyber incidents detection by SIEM based on fuzzy logical inference</article-title>
          :
          <source>CEUR Workshop Proceedings (CEURWS.org)</source>
          , Vol.
          <volume>2859</volume>
          ,
          <year>2021</year>
          , pp.
          <fpage>210</fpage>
          -
          <lpage>219</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>M.</given-names>
            <surname>Beshley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Toliupa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Pashkevych</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Kolodiy</surname>
          </string-name>
          ,
          <article-title>Development of software system for network traffic analysis and intrusion detection:</article-title>
          <source>International Conference on Information and Telecommunication Technologies and Radio Electronics</source>
          , UkrMiCo, Inc.,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <article-title>Matlab documentation</article-title>
          .
          <source>Exponent</source>
          ,
          <year>2020</year>
          URL: https://docs.exponenta.ru/matlab.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>S.</given-names>
            <surname>Sivanandam</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Sumathi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Deepa</surname>
          </string-name>
          , Introduction to Fuzzy Logic using MATLAB: SpringerVerlag Berlin Heidelberg, Inc.,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>A.V.</given-names>
            <surname>Leonenkov</surname>
          </string-name>
          ,
          <article-title>Fuzzy modeling in MATLAB and fuzzyTECH, St</article-title>
          . Petersburg, BHVPetersburg,
          <year>2003</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>UCI</given-names>
            <surname>Knowledge</surname>
          </string-name>
          <article-title>Discovery in Databases Archive</article-title>
          . University of California, Irvine, CA 92697-
          <fpage>3425</fpage>
          . KDD Archive,
          <year>2020</year>
          URL: http://kdd.ics.uci.edu/databases/kddcup99/task.html.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>A.</given-names>
            <surname>Rothstein</surname>
          </string-name>
          ,
          <article-title>Intelligent identification technologies: fuzzy sets, genetic algorithms, neural networks</article-title>
          ,
          <source>Vinnytsia: UNIVERSUM</source>
          ,
          <year>1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>S.</given-names>
            <surname>Shtovba</surname>
          </string-name>
          ,
          <article-title>Fuzzy model tuning based on a training set with fuzzy model output values</article-title>
          ,
          <source>Cybernetics and Systems</source>
          Analysis Vol.
          <volume>43</volume>
          (
          <year>2007</year>
          )
          <fpage>334</fpage>
          -
          <lpage>340</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>A.</given-names>
            <surname>Rothstein</surname>
          </string-name>
          ,
          <article-title>Medical diagnostics on fuzzy logic</article-title>
          ,
          <source>Vinnytsia: Continent-PRIM</source>
          ,
          <year>1996</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Mityushkin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Mokin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Rothstein</surname>
          </string-name>
          , Soft Computing:
          <article-title>identification of patterns of fuzzy knowledge bases: a monograph</article-title>
          .
          <source>Vinnytsia: UNIVERSUM-Vinnytsia</source>
          ,
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>O.</given-names>
            <surname>Rothstein</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Chernovolyk</surname>
          </string-name>
          , E. Laryushkin,
          <article-title>Method of constructing membership functions of fuzzy sets</article-title>
          .
          <source>Bulletin of VPI</source>
          , Vol.
          <volume>3</volume>
          (
          <year>1996</year>
          )
          <fpage>72</fpage>
          -
          <lpage>75</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>A.</given-names>
            <surname>Piegat</surname>
          </string-name>
          , Fuzzy Modeling and Control, Physica-Verlag, Heidelberg.
          <year>2001</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>SPMF</surname>
          </string-name>
          ,
          <year>2022</year>
          URL: http://www.philippe
          <article-title>-fournier-viger</article-title>
          .com/spmf/index.php.
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>P.</given-names>
            <surname>Fournier-Viger</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Gomariz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Gueniche</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Soltani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Wu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V. S.</given-names>
            <surname>Tseng</surname>
          </string-name>
          ,
          <article-title>SPMF: a Java Open-Source Pattern Mining Library</article-title>
          ,
          <source>Journal of Machine Learning Research</source>
          Vol.
          <volume>1</volume>
          (
          <issue>2014</issue>
          )
          <fpage>1</fpage>
          -
          <lpage>5</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Zaichenko</surname>
          </string-name>
          , Operations Research: Fuzzy Optimization: Kiev, High school,
          <year>1991</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>D.</given-names>
            <surname>Goldberg</surname>
          </string-name>
          , Genetic Algorithms in Search,
          <source>Optimization and Machine Learning</source>
          .
          <year>1989</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>F.</given-names>
            <surname>Herrera</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Lozano</surname>
          </string-name>
          ,
          <article-title>Adaptation of genetic algorithm parameters based on fuzzy logic controllers</article-title>
          .
          <source>Genetic Algorithms and Soft Computing: Physica-Verlag, Heidelberg</source>
          .
          <year>1996</year>
          . pp.
          <fpage>95</fpage>
          -
          <lpage>124</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>I.</given-names>
            <surname>Subach</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kubrak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Mykytiuk</surname>
          </string-name>
          ,
          <article-title>Methodology of rational choice of security incident management system for building operational security center:</article-title>
          <source>CEUR Workshop Proceedings (CEUR-WS.org)</source>
          , Vol.
          <volume>2577</volume>
          ,
          <year>2019</year>
          , pp.
          <fpage>11</fpage>
          -
          <lpage>20</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>