<?xml version="1.0" encoding="UTF-8"?>
<TEI xml:space="preserve" xmlns="http://www.tei-c.org/ns/1.0" 
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
xsi:schemaLocation="http://www.tei-c.org/ns/1.0 https://raw.githubusercontent.com/kermitt2/grobid/master/grobid-home/schemas/xsd/Grobid.xsd"
 xmlns:xlink="http://www.w3.org/1999/xlink">
	<teiHeader xml:lang="en">
		<fileDesc>
			<titleStmt>
				<title level="a" type="main">Simulation Model of a Fuzzy Cyber Attack Detection System</title>
			</titleStmt>
			<publicationStmt>
				<publisher/>
				<availability status="unknown"><licence/></availability>
			</publicationStmt>
			<sourceDesc>
				<biblStruct>
					<analytic>
						<author>
							<persName><forename type="first">Ihor</forename><surname>Subach</surname></persName>
							<email>igor_subach@ukr.net</email>
							<affiliation key="aff0">
								<orgName type="institution">National Technical University of Ukraine &quot;Igor Sikorsky Kyiv Polytechnic Institute&quot;</orgName>
								<address>
									<addrLine>st.Verkhnoklyuchova, 4</addrLine>
									<postCode>03056</postCode>
									<settlement>Kyiv</settlement>
									<country key="UA">Ukraine</country>
								</address>
							</affiliation>
							<affiliation key="aff1">
								<orgName type="department">Military Institute of Telecommunications and Information Technologies named after Heroes of Kruty</orgName>
								<address>
									<addrLine>st. Moscow, 45/1</addrLine>
									<postCode>01011</postCode>
									<settlement>Kyiv</settlement>
									<country key="UA">Ukraine</country>
								</address>
							</affiliation>
						</author>
						<author>
							<persName><forename type="first">Vitalii</forename><surname>Fesokha</surname></persName>
							<email>vitaliifesokha@gmail.com</email>
							<affiliation key="aff1">
								<orgName type="department">Military Institute of Telecommunications and Information Technologies named after Heroes of Kruty</orgName>
								<address>
									<addrLine>st. Moscow, 45/1</addrLine>
									<postCode>01011</postCode>
									<settlement>Kyiv</settlement>
									<country key="UA">Ukraine</country>
								</address>
							</affiliation>
						</author>
						<author>
							<persName><forename type="first">Artem</forename><surname>Mykytiuk</surname></persName>
							<affiliation key="aff0">
								<orgName type="institution">National Technical University of Ukraine &quot;Igor Sikorsky Kyiv Polytechnic Institute&quot;</orgName>
								<address>
									<addrLine>st.Verkhnoklyuchova, 4</addrLine>
									<postCode>03056</postCode>
									<settlement>Kyiv</settlement>
									<country key="UA">Ukraine</country>
								</address>
							</affiliation>
						</author>
						<author>
							<persName><forename type="first">Volodymyr</forename><surname>Kubrak</surname></persName>
							<email>volodymir.kubrak@ukr.net</email>
							<affiliation key="aff0">
								<orgName type="institution">National Technical University of Ukraine &quot;Igor Sikorsky Kyiv Polytechnic Institute&quot;</orgName>
								<address>
									<addrLine>st.Verkhnoklyuchova, 4</addrLine>
									<postCode>03056</postCode>
									<settlement>Kyiv</settlement>
									<country key="UA">Ukraine</country>
								</address>
							</affiliation>
						</author>
						<author>
							<persName><forename type="first">Stanislav</forename><surname>Korotayev</surname></persName>
							<affiliation key="aff0">
								<orgName type="institution">National Technical University of Ukraine &quot;Igor Sikorsky Kyiv Polytechnic Institute&quot;</orgName>
								<address>
									<addrLine>st.Verkhnoklyuchova, 4</addrLine>
									<postCode>03056</postCode>
									<settlement>Kyiv</settlement>
									<country key="UA">Ukraine</country>
								</address>
							</affiliation>
						</author>
						<author>
							<affiliation key="aff2">
								<orgName type="department">XXI International Scientific and Practical Conference &quot;Information Technologies and Security&quot; (ITS</orgName>
								<address>
									<addrLine>2021), December 9</addrLine>
									<postCode>2021</postCode>
									<settlement>Kyiv</settlement>
									<country key="UA">Ukraine</country>
								</address>
							</affiliation>
						</author>
						<title level="a" type="main">Simulation Model of a Fuzzy Cyber Attack Detection System</title>
					</analytic>
					<monogr>
						<imprint>
							<date/>
						</imprint>
					</monogr>
					<idno type="MD5">39C1ADAA0A316E7173D4589EDF8E2DD9</idno>
				</biblStruct>
			</sourceDesc>
		</fileDesc>
		<encodingDesc>
			<appInfo>
				<application version="0.7.2" ident="GROBID" when="2023-03-25T04:07+0000">
					<desc>GROBID - A machine learning software for extracting information from scholarly documents</desc>
					<ref target="https://github.com/kermitt2/grobid"/>
				</application>
			</appInfo>
		</encodingDesc>
		<profileDesc>
			<textClass>
				<keywords>
					<term>Cybersecurity, cyber attack, IDS, simulation model, fuzzy set theory 0000-0002-9344-713X (I. Subach)</term>
					<term>0000-0001-6612-1970 (V. Fesokha)</term>
					<term>0000-0002-8307-9978 (A. Mykytiuk)</term>
					<term>0000-0001-8877-5289 (V. Kubrak)</term>
					<term>0000-0003-3823-8375 (S. Korotayev)</term>
				</keywords>
			</textClass>
			<abstract>
<div xmlns="http://www.tei-c.org/ns/1.0"><p>The method of applying a simulation model of a fuzzy cyberattack detection system is considered. The functional diagram of the simulation model is given. The block diagram of the simulation model is considered and the purpose of its elements is described. The main steps of using a simulation model for conducting an experimental study of evaluating the effectiveness of models and methods for detecting cyber attacks based on the theory of fuzzy sets and fuzzy inference are described. The procedure for generating initial data is given, the classes of cyberattacks to be detected are defined, the vectors of cyberattack features are identified, the parameters of the studied traffic are described, the types of membership functions are defined to formalize expert knowledge and represent it in the knowledge base in the form of fuzzy production rules. The issue of parametric adaptation of membership functions to clarify the subjective judgments of experts are considered. To implement the possibility of detecting polymorphic cyberattacks, the procedure for determining the required number of the most important features for each known class of cyberattacks, represented by fuzzy sets and linguistic variables that characterize them quite fully, is described. A comparative analysis of the results of modeling the process of detecting cyber attacks based on the proposed approach with existing methods for detecting cyber attacks was carried out, based on the theory of fuzzy sets and fuzzy logic, artificial immune systems and neural networks in terms of accuracy.</p></div>
			</abstract>
		</profileDesc>
	</teiHeader>
	<text xml:lang="en">
		<body>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="1.">Introduction</head><p>In <ref type="bibr" target="#b0">[1,</ref><ref type="bibr" target="#b1">2]</ref> the architecture of a promising fuzzy intelligent system for detecting cyber attacks was proposed. It allows the security operations centers (SOC) operational personnel to make decisions on their detection promptly and reasonably. It is based on the technologies of data mining, machine learning, big data processing and artificial intelligence (Figure <ref type="figure">1</ref>).</p><p>The proposed architecture consists of the following components <ref type="bibr" target="#b1">[2]</ref><ref type="bibr">[3]</ref><ref type="bibr" target="#b2">[4]</ref><ref type="bibr" target="#b3">[5]</ref><ref type="bibr" target="#b4">[6]</ref><ref type="bibr" target="#b5">[7]</ref><ref type="bibr" target="#b6">[8]</ref><ref type="bibr" target="#b7">[9]</ref><ref type="bibr" target="#b8">[10]</ref>: information collection subsystem -a set of sensors on network nodes that collect and process primary data on network activity; analyzer -the module of the first echelon of cyber attack detection -analyzes security events (incidents) and on the basis of signature analysis classifies harmful activity as cyber attack; signature database -a dictionary of signatures of classified cyberattacks used by the componentanalyzer; statistical database -statistics of telemetry of network traffic for a certain period for its further use in order to improve the system to adapt the parameters of the mechanism of detection of cyber attacks to existing changes; scheduler -plans further actions of the system after processing by the analyzer (in case it detects a cyberattack, the scheduler gives control to the response module to take measures to stop malicious activity; otherwise, the scheduler gives control to the data analysis module detection cyber attacks second tier, built on the basis of the developed model of cyberattack detection <ref type="bibr" target="#b6">[8]</ref><ref type="bibr" target="#b7">[9]</ref><ref type="bibr" target="#b8">[10]</ref><ref type="bibr" target="#b9">[11]</ref>;</p><p>fasificationblock -clear values of the studied parameters are turned into fuzzy (the degree of their belonging to the term sets of linguistic variables specified by experts is determined). Fuzzy network activity is taken into account based on the application of the model proposed in <ref type="bibr" target="#b6">[8]</ref><ref type="bibr" target="#b7">[9]</ref><ref type="bibr" target="#b8">[10]</ref><ref type="bibr" target="#b9">[11]</ref>; fuzzy rule base: contains fuzzy production rules built by experts at the stage of preparing the system for operation; adaptation module: performs primary parametric adjustment of membership functions by means of genetic algorithms on the basis of a certain training sample and further training of the system if necessary on the basis of statistical data to clarify the values of cyber attack detection mechanism; fuzzy inference block -a module for making decisions about the state of the network based on determining the relationship between input data (telemetry of network traffic) and expert opinions by means of fuzzy logic; Figure <ref type="figure">1</ref>. Architecture of a promising fuzzy intelligent system for detecting cyber attacks response module -generates requests and notifications to the console, takes protective measures to block detected cyberattacks, as well as fills the database of statistical decisions on their decisions for further use by the adaptation module; management console: module for configuring the cybersecurity officer of the system parameters.</p><p>The application of the proposed IDS architecture allows to increase the efficiency of detecting cyberattacks in near real time, based on the application of a multi-tiered approach to their detection. In addition, it becomes possible to adapt the system to the detection of unknown types of cyber attacks (zero day), as well as increase the efficiency of the cybersecurity officer on such indicators as efficiency and soundness of decision-making.</p><p>In <ref type="bibr" target="#b6">[8]</ref><ref type="bibr" target="#b7">[9]</ref><ref type="bibr" target="#b8">[10]</ref><ref type="bibr" target="#b9">[11]</ref> -models and methods for detecting known and polymorphic cyber attacks based on the theory of fuzzy sets and fuzzy inference. Formally, the task of fuzzy identification of a cyber attack is to find a solution to analytical expression that connects a set of parameters of the state of the system, on the basis of which its anomalous behavior is determined and an expert solution that meets them, taking into account the weighting coefficients for fuzzy rules (Figure <ref type="figure" target="#fig_0">2</ref>):  To evaluate the effectiveness of the proposed solutions, a system simulation model (FIDM -Fuzzy Intrusion Detection Model) was developed using the Fuzzy Logic Toolbox™ package,which provides MATLAB® functions and the Simulink® block <ref type="bibr" target="#b11">[13,</ref><ref type="bibr" target="#b12">14,</ref><ref type="bibr" target="#b13">15]</ref> for designing and modeling systems based on fuzzy logic.</p><formula xml:id="formula_0">      , ,<label>1 , , 1 , , , , , , , , , 2 1 2 1</label></formula></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="2.">Functional and structural diagram of the simulation model</head><p>The functional diagram of the simulation model is shown in Figure <ref type="figure" target="#fig_1">3</ref>, where x1..xn are input parameters and y is an output variable.</p><p>The basis of the proposed simulation model is a modular diagram for organizing sequential iterative interaction between its components: a data input module for analysis, a fuzzification module, a knowledge base (KB), a fuzzy inference and defuzzification module <ref type="bibr" target="#b11">[13,</ref><ref type="bibr" target="#b12">14,</ref><ref type="bibr" target="#b13">15]</ref>. The structure diagram of the developed simulation model is shown in Figure <ref type="figure" target="#fig_2">4</ref>.</p><p>For the operation of the test data input module <ref type="bibr" target="#b14">[16]</ref>, is a set of statistical data on cyberattacks KDD Cup 1999 Data (xlsx files) was used.</p><p>The purpose of the fuzzification module is to represent the quantitative and qualitative values of the studied parameters using term sets and linguistic variables. Incomplete and uncertain data on network activity were taken into account by applying the developed model of cyber attack detection.</p><p>Additional rules generation module was used to create new fuzzy production rules in the knowledge base by intersecting fuzzy sets of linguistic variables of previously existing rules and the most significant linguistic variables predefined by an expert for each class of cyberattacks.</p><p>The knowledge base is a set of fuzzy production rules built by an expert.  The purpose of the fuzzy inference module is to generate a decision about the state of the information and communications network based on determining the relationship between input data and expert conclusions using fuzzy logic.</p><p>The defuzzification module was used to convert the obtained values of the fuzzy inference into crisp ones.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="3.">Methodology of applying the simulation model</head><p>Step 1: Defining is a set of cyber attackstatistics: KDD Cup 1999 Data <ref type="bibr" target="#b14">[16]</ref>.</p><p>Step 2. Defining the classes of cyberattacks to be detected <ref type="bibr" target="#b14">[16]</ref>: Denial of Service, Remote to Local, User to Root, Probe and normal states of the ICS.</p><p>Step 3. The input of the simulation model was fed with vectors of cyber attacks of the KDD Cup 1999 Data set in the number of: known -Denial of Service -4264, Remote to Local -1020, User to Root -52, Probe -3231; normal states of the information system -1000; polymorphic cyberattacks built on the basis of known ones -100. Thus, the total number of attribute vectors was 9667.</p><p>For the study, 38 parameters of network traffic telemetry were selected based on the classification proposed in the chosen data set on cyberattacks (Table <ref type="table" target="#tab_1">1</ref>). Step 4. Defining the type of membership functions to describe the ranges of values of the studied parameters and the power of term sets for input and output linguistic variables: triangular membership functions (2) due to the ability to undergo parametric adaptation (refinement) while maintaining an acceptable level of computational complexity <ref type="bibr" target="#b15">[17]</ref><ref type="bibr" target="#b16">[18]</ref><ref type="bibr" target="#b17">[19]</ref><ref type="bibr" target="#b18">[20]</ref><ref type="bibr" target="#b19">[21]</ref><ref type="bibr" target="#b20">[22]</ref>, term set power -7 (number: VS is acronym for "very small", S is acronym for "small", BA is acronym for "below average", A is acronym for "average", AA is acronym for "above average", L is acronym for "large", VL is acronym for "very large").</p><formula xml:id="formula_1">                                c x c x b b c x c b x a a b a x a x c b a x f , 0 , , , 0 , , , ,<label>(2)</label></formula><p>where a, b, c is a some numeric parameters that take arbitrary real values and are ordered by relations:</p><formula xml:id="formula_2">c b a   .</formula><p>Step 5. Defining input and output linguistic variables: 38 input linguistic variables that correspond to the number of studied parameters of network traffic and one output -an indicator of the state of the information and communications system. Each input value (𝑥 ) corresponds to the network traffic parameter according to the KDD Cup 1999 Data, and the membership functions configured by the expert are represented by term sets. Step 6. Preparing test data format of KDD Cup 1999 Data for the Fuzzy Logic Toolbox™ software.</p><p>Step 7. Creating fuzzy production rules for the KB based on the KDD Cup 1999 Data set using association rule search algorithms (Fig. <ref type="figure" target="#fig_4">6</ref>) <ref type="bibr" target="#b21">[23,</ref><ref type="bibr" target="#b22">24]</ref>.</p><p>Step 8. Obtaining expert conclusions about the state of IP according to the classification of cyber attacks presented in the KDD Cup 1999 Data: Denial of Service, Remote to Local, User to Root, Probe and normal state: total number of rules: 335, of which Denial of Service -68; Remote to Local -55; User to Root -18; Probe -107; Normal -87.</p><p>Step 9. Parametric adaptation of constructed membership functions <ref type="bibr" target="#b23">[25,</ref><ref type="bibr" target="#b24">26,</ref><ref type="bibr" target="#b25">27]</ref> in order to clarify the subjective point of view of the expert by means of the Optimization Tool package of MATLAB® software <ref type="bibr" target="#b11">[13,</ref><ref type="bibr" target="#b12">14,</ref><ref type="bibr" target="#b13">15]</ref>: on the basis of the frequent data sets found at the previous stage, parametric optimization of membership functions was performed for the above terms of each studied variable (search for the optimum of the parameter vector of the system of equations of the analytical model of the triangular membership function).</p><p>Step 10. Determining the required number of the most important (informative) parameters (features) for each known class of cyberattacks, represented as fuzzy sets of linguistic variables that characterize them quite fully in order to be able to identify polymorphic modifications of known cyberattacks:  Step 12. Application of the developed program code for the correct input of data from the cyberattack data set for further analysis by the Fuzzy Logic Toolbox™ library. Step 13. Conducting experimental studies on cyber attack detection by a developed simulation model, the functioning of which is based on the application of models and methods and comparative analysis of the results of modeling the process of detecting cyber attacks based on the proposed approach with existing methods for detecting cyber attacks: based on the theory of fuzzy sets and fuzzy logic, artificial immune systems and neural networks in terms of accuracy. where TD (True Detection) is the number of correctly detected cyber attacks; FN (False Negative) is a type II errors (classifying a cyber attack as a normal state).</p><p>A comparative analysis of the results of modeling the process of cyber attack detection based on the approach proposed in the study and existing solutions in terms of accuracy are presented in Table <ref type="table" target="#tab_3">2</ref>.</p><p>The results of the study were included in the methodology of rational choice of security incident management system for building operational security center <ref type="bibr" target="#b26">[28]</ref>.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head n="4.">Conclusion</head><p>The practical application of the developed simulation model of a fuzzy cyber attack detection system showed the expediency of using it to evaluate models and methods of cyber attack detection based on the theory of fuzzy sets and fuzzy inference. Thus, the comparison of the developed scientific and methodological apparatus with the already available ones shows that its use makes it possible to increase the effectiveness of information systems cyber protection in terms of the accuracy of detecting known cyber attacks by an average of 10%, as well as to ensure the detection of polymorphic cyber attacks in terms of accuracy of at least 98 %.</p></div><figure xmlns="http://www.tei-c.org/ns/1.0" xml:id="fig_0"><head>Figure 2 .</head><label>2</label><figDesc>Figure 2. Graphical interpretation of the problem of cyber attack identification</figDesc></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0" xml:id="fig_1"><head>Figure 3 .</head><label>3</label><figDesc>Figure 3. Functional diagram of the FIDM simulation model</figDesc><graphic coords="4,111.66,72.00,385.92,201.54" type="bitmap" /></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0" xml:id="fig_2"><head>Figure 4 .</head><label>4</label><figDesc>Figure 4. Structure diagram of the developed simulation model</figDesc><graphic coords="4,96.12,312.24,417.00,245.52" type="bitmap" /></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0" xml:id="fig_3"><head>1 x 5 xFigure 5 .</head><label>155</label><figDesc>Figure 5.Graphical representation of the described linguistic terms of membership function</figDesc></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0" xml:id="fig_4"><head>Figure 6 .</head><label>6</label><figDesc>Figure 6. Associative rules search box in Open-Source Data Mining Library SPMF Step 11. Obtaining additional fuzzy production rules for KB based on the actions taken in the previous step and removing duplicate rules. As a result, new rules were obtained in the following quantity: Denial of Service -48; Remote to Local -14; User to Root -13; Probe -16. The total number of rules in the KB -426.Step 12. Application of the developed program code for the correct input of data from the cyberattack data set for further analysis by the Fuzzy Logic Toolbox™ library.</figDesc><graphic coords="8,72.00,319.98,449.28,255.72" type="bitmap" /></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0"><head></head><label></label><figDesc></figDesc><graphic coords="2,72.96,311.76,449.04,260.16" type="bitmap" /></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0"><head></head><label></label><figDesc></figDesc><graphic coords="7,72.00,306.66,450.84,231.00" type="bitmap" /></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0" type="table" xml:id="tab_1"><head>Table 1</head><label>1</label><figDesc>The studied parameters of network traffic</figDesc><table><row><cell>Code</cell><cell>Parameter</cell><cell>Description</cell></row><row><cell>x1</cell><cell>duration</cell><cell>Connection time in seconds</cell></row><row><cell>x2</cell><cell>src_bytes</cell><cell>Number of bytes from source to</cell></row><row><cell></cell><cell></cell><cell>destination</cell></row><row><cell>x3</cell><cell>dst_bytes</cell><cell>Number of bytes in the response to the</cell></row><row><cell></cell><cell></cell><cell>client</cell></row><row><cell>x4</cell><cell>land</cell><cell>1 if the connection is from/to the same</cell></row><row><cell></cell><cell></cell><cell>host/port</cell></row><row><cell>x5</cell><cell>wrong_fragment</cell><cell>Number of false fragments</cell></row><row><cell>x6</cell><cell>urgent</cell><cell>Number of urgent packages</cell></row><row><cell>x7</cell><cell>hot</cell><cell>Number of hot indicators</cell></row><row><cell>x8</cell><cell>num_failed_logins</cell><cell>Number of failed registration attempts</cell></row><row><cell>x9</cell><cell>logged_in</cell><cell>1 if successful login; 0 unsuccessful</cell></row><row><cell>x10</cell><cell>num_compromised</cell><cell>Number of compromising conditions</cell></row><row><cell>x11</cell><cell>root_shell</cell><cell>1 if a root shell is obtained; otherwise 0</cell></row><row><cell>x12</cell><cell>su_attempted</cell><cell>1 if su root was executed; otherwise 0</cell></row><row><cell>x13</cell><cell>num_root</cell><cell>Number of root accesses</cell></row><row><cell>x14</cell><cell>num_file_creations</cell><cell>Number of file creation operations</cell></row><row><cell>x15</cell><cell>num_shells</cell><cell>Number of shell requests</cell></row><row><cell>x16</cell><cell>num_access_files</cell><cell>Number of operations to access file</cell></row><row><cell></cell><cell></cell><cell>control</cell></row><row><cell>x17</cell><cell>num_outbound_cmds</cell><cell>Number of FTP session output</cell></row><row><cell></cell><cell></cell><cell>commands</cell></row><row><cell>x18</cell><cell>is_host_login</cell><cell>1 if the login belonged to the hot list</cell></row><row><cell>x19</cell><cell>is_guest_login</cell><cell>1 if guest login</cell></row><row><cell>x20</cell><cell>count</cell><cell>Number of connections in the current</cell></row><row><cell></cell><cell></cell><cell>session in the last 2 sec.</cell></row><row><cell>x21</cell><cell>srv_count</cell><cell>Number of connections to the same</cell></row><row><cell></cell><cell></cell><cell>service in the last 2 sec.</cell></row><row><cell>x22</cell><cell>serror_rate</cell><cell>% of connections that had SYN errors</cell></row><row><cell>x23</cell><cell>srv_serror_rate</cell><cell>% of connection with an error in SYN</cell></row><row><cell></cell><cell></cell><cell>packet</cell></row><row><cell>x24</cell><cell>rerror_rate</cell><cell>% of connections that had REJ errors</cell></row><row><cell>x25</cell><cell>srv_rerror_rate</cell><cell>% of connections with REJ errors</cell></row><row><cell>x26</cell><cell>same_srv_rate</cell><cell>% of connections having the same service</cell></row><row><cell>x27</cell><cell>diff_srv_rate</cell><cell>% of connections to different services</cell></row><row><cell>x28</cell><cell>srv_diff_host_rate</cell><cell>% connections from other hosts</cell></row><row><cell>x29</cell><cell>dst_host_count</cell><cell>Number of connections to the host</cell></row><row><cell></cell><cell></cell><cell>established by the remote party</cell></row></table></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0" type="table" xml:id="tab_3"><head>Table 2 .</head><label>2</label><figDesc>Comparative analysis of simulation results</figDesc><table><row><cell>Cyber attack class</cell><cell>Immune systems</cell><cell>Neural networks</cell><cell>Fuzzy logic</cell><cell>Suggested method</cell></row><row><cell>DoS</cell><cell>0,98</cell><cell>1,0</cell><cell>0,94</cell><cell>1,0</cell></row></table></figure>
		</body>
		<back>
			<div type="references">

				<listBibl>

<biblStruct xml:id="b0">
	<analytic>
		<title level="a" type="main">Architecture and functional model of a promising proactive intelligent system SIEM-system for cyber protection of critical infrastructure</title>
		<author>
			<persName><forename type="first">I</forename><surname>Subach</surname></persName>
		</author>
		<author>
			<persName><forename type="first">V</forename><surname>Kubrak</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Mykytiuk</surname></persName>
		</author>
		<idno type="DOI">10.20535/2411-1031.2019.7.2.190570</idno>
	</analytic>
	<monogr>
		<title level="j">Information Technology and Security</title>
		<imprint>
			<biblScope unit="volume">7</biblScope>
			<biblScope unit="issue">2</biblScope>
			<biblScope unit="page" from="208" to="215" />
			<date type="published" when="2019">2019</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b1">
	<analytic>
		<title level="a" type="main">Analysis of existing intrusion prevention solutions in information and telecommunication networks, opened on the basis of publicly available licenses</title>
		<author>
			<persName><forename type="first">I</forename><surname>Subach</surname></persName>
		</author>
		<author>
			<persName><forename type="first">V</forename><surname>Fesokha</surname></persName>
		</author>
		<author>
			<persName><forename type="first">N</forename><surname>Fesokha</surname></persName>
		</author>
		<idno type="DOI">10.20535/2411-1031.2017.5.1.120554</idno>
	</analytic>
	<monogr>
		<title level="j">Information Technology and Security</title>
		<imprint>
			<biblScope unit="volume">5</biblScope>
			<biblScope unit="issue">1</biblScope>
			<biblScope unit="page" from="29" to="41" />
			<date type="published" when="2017">2017</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b2">
	<monogr>
		<ptr target="https://studref.com/521846/informatika/arhitektura_sistem_obnaruzheniya_vtorzheniy" />
		<title level="m">Intrusion detection system architecture</title>
				<imprint>
			<date type="published" when="2020">2020</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b3">
	<analytic>
		<title level="a" type="main">Development of a system for detecting network traffic anomalies</title>
		<author>
			<persName><forename type="first">D</forename><surname>Levonevsky</surname></persName>
		</author>
		<author>
			<persName><forename type="first">R</forename><surname>Fatkieva</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Scientific Bulletin of NGTU</title>
		<imprint>
			<biblScope unit="volume">56</biblScope>
			<biblScope unit="issue">3</biblScope>
			<biblScope unit="page" from="108" to="114" />
			<date type="published" when="2014">2014</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b4">
	<analytic>
		<title level="a" type="main">Fuzzy anomaly detection in monitoring sensor data</title>
		<author>
			<persName><forename type="first">J</forename><surname>Rabatel</surname></persName>
		</author>
		<author>
			<persName><forename type="first">S</forename><surname>Bringay</surname></persName>
		</author>
		<author>
			<persName><forename type="first">P</forename><surname>Poncelet</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">IEEE International Conference on Fuzzy Systems</title>
				<imprint>
			<publisher>Inc</publisher>
			<date type="published" when="2010">2010</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b5">
	<monogr>
		<title level="m" type="main">Automated detection system of insider attacks using fuzzy logic: Information Technology and Nanotechnology</title>
		<author>
			<persName><forename type="first">M</forename><surname>Dodonov</surname></persName>
		</author>
		<author>
			<persName><forename type="first">N</forename><surname>Dodonova</surname></persName>
		</author>
		<imprint>
			<date type="published" when="2015">2015. 2015</date>
			<publisher>Inc</publisher>
			<biblScope unit="page" from="376" to="380" />
			<pubPlace>ITNT-</pubPlace>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b6">
	<analytic>
		<title level="a" type="main">Zero-day polymorphic cyberattacks detection using fuzzy inference system</title>
		<author>
			<persName><forename type="first">I</forename><surname>Subach</surname></persName>
		</author>
		<author>
			<persName><forename type="first">I</forename><surname>Subach</surname></persName>
		</author>
		<author>
			<persName><forename type="first">V</forename><surname>Kubrak</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Mykytiuk</surname></persName>
		</author>
		<author>
			<persName><forename type="first">S</forename><surname>Korotaiev</surname></persName>
		</author>
		<idno type="DOI">10.29013/AJT-20-5.6-8-13</idno>
	</analytic>
	<monogr>
		<title level="j">Austrian Journal of Technical and Natural Sciences</title>
		<imprint>
			<biblScope unit="volume">5</biblScope>
			<biblScope unit="issue">6</biblScope>
			<biblScope unit="page" from="8" to="13" />
			<date type="published" when="2020">2020</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b7">
	<analytic>
		<title level="a" type="main">Methods of detecting JS(HTML)/Scrinjectcyber attacks based on the application of the mathematical apparatus of fuzzy set theory</title>
		<author>
			<persName><forename type="first">I</forename><surname>Subach</surname></persName>
		</author>
		<author>
			<persName><forename type="first">Y</forename><surname>Zdorenko</surname></persName>
		</author>
		<author>
			<persName><forename type="first">V</forename><surname>Fesokha</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Proceedings of the Heroes of Kruty Military Institute of Telecommunications and Informatization Iss</title>
		<imprint>
			<biblScope unit="volume">4</biblScope>
			<biblScope unit="page" from="125" to="131" />
			<date type="published" when="2018">2018</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b8">
	<analytic>
		<title level="a" type="main">A model for detecting cyber attacks on information and telecommunication systems based on the description of anomalies in their operation by weighted fuzzy rules</title>
		<author>
			<persName><forename type="first">I</forename><surname>Subach</surname></persName>
		</author>
		<author>
			<persName><forename type="first">V</forename><surname>Fesokha</surname></persName>
		</author>
		<idno type="DOI">10.20535/2411-1031.2017.5.2.136984</idno>
	</analytic>
	<monogr>
		<title level="j">Information Technology and Security</title>
		<imprint>
			<biblScope unit="volume">5</biblScope>
			<biblScope unit="issue">2</biblScope>
			<biblScope unit="page" from="145" to="152" />
			<date type="published" when="2017">2017</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b9">
	<analytic>
		<title level="a" type="main">Rule-oriented method of cyber incidents detection by SIEM based on fuzzy logical inference</title>
		<author>
			<persName><forename type="first">I</forename><surname>Subach</surname></persName>
		</author>
		<author>
			<persName><forename type="first">V</forename><surname>Kubrak</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Mykytiuk</surname></persName>
		</author>
		<author>
			<persName><forename type="first">S</forename><surname>Korotaev</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">CEUR Workshop Proceedings</title>
				<imprint>
			<date type="published" when="2021">2021</date>
			<biblScope unit="volume">2859</biblScope>
			<biblScope unit="page" from="210" to="219" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b10">
	<analytic>
		<title level="a" type="main">Development of software system for network traffic analysis and intrusion detection</title>
		<author>
			<persName><forename type="first">M</forename><surname>Beshley</surname></persName>
		</author>
		<author>
			<persName><forename type="first">S</forename><surname>Toliupa</surname></persName>
		</author>
		<author>
			<persName><forename type="first">V</forename><surname>Pashkevych</surname></persName>
		</author>
		<author>
			<persName><forename type="first">R</forename><surname>Kolodiy</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">International Conference on Information and Telecommunication Technologies and Radio Electronics</title>
				<imprint>
			<publisher>UkrMiCo, Inc</publisher>
			<date type="published" when="2018">2018</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b11">
	<monogr>
		<ptr target="https://docs.exponenta.ru/matlab" />
		<title level="m">Matlab documentation</title>
				<imprint>
			<date type="published" when="2020">2020</date>
		</imprint>
		<respStmt>
			<orgName>Exponent</orgName>
		</respStmt>
	</monogr>
</biblStruct>

<biblStruct xml:id="b12">
	<monogr>
		<title level="m" type="main">Introduction to Fuzzy Logic using MATLAB</title>
		<author>
			<persName><forename type="first">S</forename><surname>Sivanandam</surname></persName>
		</author>
		<author>
			<persName><forename type="first">S</forename><surname>Sumathi</surname></persName>
		</author>
		<author>
			<persName><forename type="first">S</forename><surname>Deepa</surname></persName>
		</author>
		<imprint>
			<date type="published" when="2007">2007</date>
			<publisher>Inc</publisher>
			<pubPlace>Berlin Heidelberg,</pubPlace>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b13">
	<monogr>
		<title level="m" type="main">Fuzzy modeling in MATLAB and fuzzyTECH</title>
		<author>
			<persName><forename type="first">A</forename><forename type="middle">V</forename><surname>Leonenkov</surname></persName>
		</author>
		<imprint>
			<date type="published" when="2003">2003</date>
			<pubPlace>St. Petersburg; BHV-Petersburg</pubPlace>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b14">
	<monogr>
		<ptr target="http://kdd.ics.uci.edu/databases/kddcup99/task.html" />
		<title level="m">UCI Knowledge Discovery in Databases Archive</title>
				<meeting><address><addrLine>Irvine, CA 92697</addrLine></address></meeting>
		<imprint>
			<date type="published" when="2020">2020</date>
			<biblScope unit="page">3425</biblScope>
		</imprint>
		<respStmt>
			<orgName>University of California</orgName>
		</respStmt>
	</monogr>
	<note>KDD Archive</note>
</biblStruct>

<biblStruct xml:id="b15">
	<monogr>
		<title level="m" type="main">Intelligent identification technologies: fuzzy sets, genetic algorithms, neural networks</title>
		<author>
			<persName><forename type="first">A</forename><surname>Rothstein</surname></persName>
		</author>
		<imprint>
			<date type="published" when="1999">1999</date>
			<publisher>UNIVERSUM</publisher>
			<pubPlace>Vinnytsia</pubPlace>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b16">
	<analytic>
		<title level="a" type="main">Fuzzy model tuning based on a training set with fuzzy model output values</title>
		<author>
			<persName><forename type="first">S</forename><surname>Shtovba</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Cybernetics and Systems Analysis</title>
		<imprint>
			<biblScope unit="volume">43</biblScope>
			<biblScope unit="page" from="334" to="340" />
			<date type="published" when="2007">2007</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b17">
	<monogr>
		<title level="m" type="main">Medical diagnostics on fuzzy logic</title>
		<author>
			<persName><forename type="first">A</forename><surname>Rothstein</surname></persName>
		</author>
		<imprint>
			<date type="published" when="1996">1996</date>
			<publisher>Continent-PRIM</publisher>
			<pubPlace>Vinnytsia</pubPlace>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b18">
	<monogr>
		<author>
			<persName><forename type="first">Y</forename><surname>Mityushkin</surname></persName>
		</author>
		<author>
			<persName><forename type="first">B</forename><surname>Mokin</surname></persName>
		</author>
		<author>
			<persName><forename type="first">O</forename><surname>Rothstein</surname></persName>
		</author>
		<title level="m">Soft Computing: identification of patterns of fuzzy knowledge bases: a monograph</title>
				<meeting><address><addrLine>Vinnytsia</addrLine></address></meeting>
		<imprint>
			<publisher>UNIVERSUM-Vinnytsia</publisher>
			<date type="published" when="2002">2002</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b19">
	<analytic>
		<title level="a" type="main">Method of constructing membership functions of fuzzy sets</title>
		<author>
			<persName><forename type="first">O</forename><surname>Rothstein</surname></persName>
		</author>
		<author>
			<persName><forename type="first">G</forename><surname>Chernovolyk</surname></persName>
		</author>
		<author>
			<persName><forename type="first">E</forename><surname>Laryushkin</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Bulletin of VPI</title>
		<imprint>
			<biblScope unit="volume">3</biblScope>
			<biblScope unit="page" from="72" to="75" />
			<date type="published" when="1996">1996</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b20">
	<monogr>
		<title level="m" type="main">Fuzzy Modeling and Control</title>
		<author>
			<persName><forename type="first">A</forename><surname>Piegat</surname></persName>
		</author>
		<imprint>
			<date type="published" when="2001">2001</date>
			<publisher>Physica-Verlag</publisher>
			<pubPlace>Heidelberg</pubPlace>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b21">
	<monogr>
		<title/>
		<author>
			<persName><surname>Spmf</surname></persName>
		</author>
		<ptr target="http://www.philippe-fournier-viger.com/spmf/index.php" />
		<imprint>
			<date type="published" when="2022">2022</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b22">
	<analytic>
		<title level="a" type="main">SPMF: a Java Open-Source Pattern Mining Library</title>
		<author>
			<persName><forename type="first">P</forename><surname>Fournier-Viger</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Gomariz</surname></persName>
		</author>
		<author>
			<persName><forename type="first">T</forename><surname>Gueniche</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Soltani</surname></persName>
		</author>
		<author>
			<persName><forename type="first">C</forename><surname>Wu</surname></persName>
		</author>
		<author>
			<persName><forename type="first">V</forename><forename type="middle">S</forename><surname>Tseng</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Journal of Machine Learning Research</title>
		<imprint>
			<biblScope unit="volume">1</biblScope>
			<biblScope unit="page" from="1" to="5" />
			<date type="published" when="2014">2014</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b23">
	<monogr>
		<author>
			<persName><forename type="first">Y</forename><surname>Zaichenko</surname></persName>
		</author>
		<title level="m">Operations Research: Fuzzy Optimization</title>
				<meeting><address><addrLine>Kiev, High school</addrLine></address></meeting>
		<imprint>
			<date type="published" when="1991">1991</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b24">
	<monogr>
		<title level="m" type="main">Genetic Algorithms in Search, Optimization and Machine Learning</title>
		<author>
			<persName><forename type="first">D</forename><surname>Goldberg</surname></persName>
		</author>
		<imprint>
			<date type="published" when="1989">1989</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b25">
	<analytic>
		<title level="a" type="main">Adaptation of genetic algorithm parameters based on fuzzy logic controllers</title>
		<author>
			<persName><forename type="first">F</forename><surname>Herrera</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><surname>Lozano</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Genetic Algorithms and Soft Computing</title>
				<meeting><address><addrLine>Heidelberg</addrLine></address></meeting>
		<imprint>
			<publisher>Physica-Verlag</publisher>
			<date type="published" when="1996">1996</date>
			<biblScope unit="page" from="95" to="124" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b26">
	<analytic>
		<title level="a" type="main">Methodology of rational choice of security incident management system for building operational security center</title>
		<author>
			<persName><forename type="first">I</forename><surname>Subach</surname></persName>
		</author>
		<author>
			<persName><forename type="first">V</forename><surname>Kubrak</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Mykytiuk</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">CEUR Workshop Proceedings</title>
				<imprint>
			<date type="published" when="2019">2019</date>
			<biblScope unit="volume">2577</biblScope>
			<biblScope unit="page" from="11" to="20" />
		</imprint>
	</monogr>
</biblStruct>

				</listBibl>
			</div>
		</back>
	</text>
</TEI>
