<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>model for classification of network cybersecurity events</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Tetiana Babenko</string-name>
          <email>babenkot@ua.fm</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Grygorii Hnatiienko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Vira Vialkova</string-name>
          <email>veravialkova@mail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andrii Bigdan</string-name>
          <email>abigdan@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Cybersecurity, Security System</institution>
          ,
          <addr-line>Neural Network, Prediction, Network Security</addr-line>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Taras Shevchenko National University</institution>
          ,
          <addr-line>Volodymyrska St. 60, Kyiv, 01103</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Security experts are required to detect and determine appropriate countermeasures against modern computer attacks. Despite the increasing detection of exploits and vulnerabilities, methods of defense remain notably slower. However, this is still an open research issue. Our paper discusses our research in a specific field of network attack identification, leveraging neural networks, in particular a multilayer perceptron, to identify and predict future network security events based on previous observations. To ensure the quality of the learning process and to obtain the desired generalization of the model, 4 million records accumulated within 7 days by the Canadian Institute of Cybersecurity were used. Our result suggests that neural network models based on multilayer perceptron can be used, after refinement, to identify and predict network security events.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Each year, 111 trillion lines are added to the total number of software code, with each line potentially
likely to be a new vulnerability and, therefore, a zero-day attack can be implemented. At the same time,
technologies used by attackers to attack computer systems and networks become more and more
complex and advanced [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Several ways for solving this issue are being explored, including
technologies that allow the creation of secure software [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. For this purpose, for the automation of
processes of controlling security events in info systems, traditionally Intrusion Detection or Protection
System (IDS / IPS) are used, the main task of which is to automate the process of identifying attacks
[
        <xref ref-type="bibr" rid="ref3 ref4 ref5">3-5</xref>
        ] or improper uses [6; 7]. These systems, depending on the technology used to detect attacks, are
usually divided into two main groups: malicious user behavior detection systems; and systems for
detecting abnormal behavior of a computer system. In the first case, comparing the attack pattern with
the flow of events, the second one compares the pattern of the normal behavior of the system with the
flow of events. In this case, it is generally believed that the task of detecting intrusions in TCP/IP
networks is reduced to recognition tasks [
        <xref ref-type="bibr" rid="ref10 ref8 ref9">8-10</xref>
        ]:



structural signs (signatures) of known types of attacks;
invariant signs of the structure of correct computational processes;
correlation signs of the normal functioning of distributed computing systems. In the case of an
issue with the recognition of network anomalies, there are some complexities that are mainly related
to the increasing demand for identifying previously unknown attacks and destructive influences,
which in its turn requires:
in conditions of uncertainty of environmental influences;
      </p>
      <p>2022 Copyright for this paper by its authors.
2. definition of necessary and sufficient informative features;
3. construction of rules for determining anomalies.</p>
      <p>
        As a rule, the detection of network anomalies is carried out according to the scheme in which the
following functional blocks are [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]:
 analysis of the information contained in the headings of IP datagrams;
 construction of the prognosticating;
 search and estimation of anomalies;
 response to anomaly;
 filling and / or editing the IDS / IPS rules base.
      </p>
      <p>The collected statistical information is used for the construction of a mathematical model for
forecasting traffic based on cyclic analysis of time series. This model allows you to predict the network
load based on the frequency search in network traffic.</p>
      <p>In all cases, IDS might not be able to detect an intrusion, since they will not be able to distinguish it
from the background white noise, which exists in any system due to weaknesses in the packet analysis
tool or lack of signature of the corresponding attack, etc.</p>
      <p>
        Consequently, most of the typical ways of identifying attacks and countering them have low
accuracy and speed and do not allow effective counteracting of both known attacks and zero-day
attacks. Therefore, many different technologies are being developed to protect computer systems [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]
and networks based on data mining technologies and neural networks [
        <xref ref-type="bibr" rid="ref13 ref14 ref15 ref16 ref17">13-17</xref>
        ]. This is due to the neural
network structure's ability to solve tasks that are difficult to formalize, as well as its ability to learn,
self-organize, and generalize. This approach allows us to obtain models that can quickly adapt to the
environment and allow us to predict the development of the process based on the property of
generalization [18; 19].
      </p>
      <p>Artificial intelligence is a broad term based on the imitation of human abilities by computers: to feel,
understand, and react.</p>
      <p>
        In the field of computer science known as machine learning, statistical techniques are frequently
used to help computers "learn" (i.e., gradually improve their performance at a given job) [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ].
      </p>
      <p>Data Sciences – to apply (use) machine learning algorithms, it is necessary to define data sets, choose
pertinent variables and metrics, and carry out a variety of information engineering tasks, such as looking
for hidden dependencies, gathering data, training it, integrating it, visualizing it, and evaluating
algorithm performance, among others.</p>
      <p>Each learning model should be based on a certain algorithm. These include classification, clustering,
associative rules, in-depth learning, regression, and pattern matching. The choice of algorithm depends
on the ultimate goal, which is set as a goal to achieve. The model of cybersecurity event identification,
considered in this research, is based on supervised training and on classification algorithms of neural
networks.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Material and methods</title>
      <p>While solving the task of classifying events that occur in the process of network interaction, some
issues arise, mostly associated with a need to account for unknown attacks and destructive influences,
which in turn needs: building benchmark sets of normal (semantically correct) profile behaviors of the
system in conditions of uncertainty of environmental influences, defining the necessary and sufficient
informative signs and building rules for identifying anomalies [21; 22].</p>
      <p>
        A similar and less complex task was performed for SQL (Structured Query Language) injection
attacks [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ]. An attack known as SQL injection involves changing database queries by taking advantage
of weaknesses in online applications. A successful attack enables the attacker to collect, alter, or even
delete sensitive information.
      </p>
      <p>To synthesize and analyze the SQL injection identification model, we prepared preliminary training,
control, and test datasets. The training dataset contained the parameters of the training object, and the
parameters were selected heuristically based on the analysis of significant attack features that may
contain a URL.</p>
      <p>
        Artificial neural networks are mathematical models and their software or hardware implementations.
The term was coined in the study of processes in the brain and attempts to model these processes.
Interpreting sensory data using a kind of machine perception by labeling or grouping input data is the
basic principle of building neural networks. Any data is translated into vectors containing recognized
patterns, which are numerical [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ].
      </p>
      <p>In a neural network, each node has inputs and an output. A neuron has two modes: training and use.
During training, the neuron learns to respond to specific input patterns. In use mode, the neuron
responds to input and generates an output. If the input is unusual, the neuron uses its activation function
to decide whether to activate itself or not.</p>
      <p>The relevant weight of each input signal is calculated based on the input data. If this value exceeds
the threshold, the neuron is triggered.</p>
      <p>Neural models work exclusively with numerical data presented in a certain numerical range, so at
the first stage of the study, a numerical URL classifier was developed. This subroutine converts the
URL into a binary value and sets 1 (the logical value "true") if the parameter in the URL is related to
the attack, and 0 (the logical value "false") otherwise. Thus, an input vector was generated for each
URL, and the output vector can be represented as:
,
where n is the number of query parameters used in the SQL pattern of the URL.</p>
      <p>Thus, the neural network model will have n neurons as input. Each vector is defined by a value:
Benign (0) means no attack, while Injection (1) means an attack. To divide the input vectors into two
classes with values of 0 and 1, it is enough to have only one neuron at the output.</p>
      <p>As a result, we obtained a relative error of the simulated model of no more than 5% for both the
control and test samples. So, we may apply such an approach to a wider range of security events and
attacks.</p>
      <p>The purpose of this research is to study opportunities for using artificial neural networks, in
particular, the perceptron of Rumelhart (a separate case of the perceptron of Rosenblatt) for the
identification of network attacks and predicting events connected with network security [25; 26]. To
ensure the quality of the training process and to obtain the desired generalization of the model's
properties, it is necessary to have a significant number of implementation examples of the relevant
attacks. For experimental purposes, 4 million records were collected that were accumulated within 7
days by the Canadian Institute of Cybersecurity. The networking infrastructure of the attacker consisted
of 50 machines. The victim organization consisted of 5 departments, and each of them used 420 user
nodes and 30 servers. The dataset contains information about the intercepted network traffic and system
logs of each machine of the victim organization. The data processing scheme is presented in Figure 1.</p>
      <p>During the dataset mining, profile concepts were used: B-profile and M-profile.</p>
      <p>B-profile (Benign) – encapsulation of user behavior using various methods of machine learning and
statistical analysis (such as K-Means, SVM, Random Forest, and J48).</p>
      <p>Encapsulated functions are the size distributions of protocol packets, the number of packets per
thread, certain payload structures, the payload size, and the time-division request for the protocol.</p>
      <p>The model consists of the following stages:
1. Collecting the network activity data, system logs, and event logs.
2. Processing the preliminary data and bringing them to the required form.
3. Training and testing of the neural network.
4. Analyzing results.</p>
      <p>
        During the simulation, the following protocols were used: HTTP, HTTPS, SMTP, POP3, IMAP,
SSH, and FTP. According to the results of the frequency analysis of the data, it was concluded that the
bulk of the traffic is represented by HTTP and HTTPS packets. M-profile (Malignant) – an attempt to
describe the attack scenario unambiguously. In the simplest case, people can interpret these profiles and
then execute them. Ideally, stand-alone agents, together with compilers, will be used to interpret and
execute these scenarios. Six different scenarios of attack implementation were considered:
● In the case of network infiltration, a harmful file was sent through email to the target. Once the
vulnerability on the target's computer was exploited, the backdoor was activated. This allowed
the attacker to scan the internal network using the target's computer and search for any potential
new mailboxes.
● In this scenario, an attack known as denial of service HTTP was implemented using Slowloris
and LOIC. These tools are capable of making web servers completely inaccessible through one
attack system. Slowloris initiates a full TCP connection with a remote server and keeps the
connection open by sending valid, incomplete HTTP requests at specific intervals. This is done
to avoid closing sockets. As web servers have a limited capacity to serve connections, it becomes
a matter of time before all sockets are utilized, and no further connections can be accepted.
● In this scenario, the Damn Vulnerable Web App (DVWA) was utilized to test security analysis
skills. DVWA is designed specifically for security professionals. The initial step involves
crawling the website using a web application vulnerability scanner, followed by executing
different types of web-based attacks, which may include SQL injection, system command
injections, and unprotected file upload capability. To detect software vulnerabilities against SQL
injections, there are multiple methods such as functional testing (black/white box), phasing,
static, dynamic, and manual analysis of the source code. In addition, WAF (web application
firewall) is commonly used alongside vulnerability scanning in software applications. WAF
offers two security models: signature-based and rule-based, each with its own advantages and
disadvantages. However, both models are unable to detect zero-day threats, which means that
the attack vector cannot be fully covered [
        <xref ref-type="bibr" rid="ref27">27-30</xref>
        ]. Therefore, typical approaches to protect
against SQL injection attacks may not provide a sufficient level of security due to low
identification accuracy and speed. To counteract known and zero-day attacks, many
technologies are being developed based on data mining techniques and the use of neural
networks to protect computer systems and networks effectively.
● One common type of cyber attack is a brute-force attack. In this type of attack, hackers try out
various combinations of usernames and passwords in order to break into a user's account. There
are many tools available for conducting a brute-force attack, including Hydra, Medusa, Ncrack,
Metasploit, and Nmap NSE modules. Additionally, there are tools for cracking password hashes,
such as hashcat and hashpump. One particularly effective tool is the Python program Patator,
which is both flexible and multi-threaded. Patator is able to save the results of each attack in a
separate log file, making it easy to review and process later on. In our own testing, we used a
password list with 90 million different words.
● Recent attacks have exploited known vulnerabilities, which are severe flaws that can affect
millions of servers or victims. These vulnerabilities can be repeatedly exploited and often takes
several months to patch all the vulnerable software code. One of the most well-known
vulnerabilities in recent years is Heartbleed.
      </p>
      <p>Details of the attacks which were identified, and the means used to implement them are presented
in Table 1.</p>
    </sec>
    <sec id="sec-3">
      <title>3. The main results of the research</title>
      <p>There are two approaches to analyzing network attacks: one is based on analyzing network activity,
and the other is based on analyzing packet content. In this study, we have focused on an approach based
on the analysis of network activity. The analysis of network activity was performed using the
specialized software CICFlowMeter. CICFlowMeter generates bi-directional streams, where sending
the first packet determines the path to the destination source and back to the source system and allows
you to get over 80 statistical network traffic attributes. For modeling goals, 67 parameters of network
traffic in each thread were identified.</p>
      <p>While preparing the data, a new Label attribute was included to distinguish whether a thread
represents a specific attack or the regular functioning of information services. As a result, all data was
categorized with the following values: Benign, FTP-BruteForce, SSH-Bruteforce, DoS-GoldenEye,
DoS-Slowloris, DoS-SlowHTTPTest, DoS-Hulk, DDoS attacks – LOIC-HTTP, DDoS-LOIC-UDP,
DDOS-HOIC, Brute Force –Web, Brute Force –XSS, Infiltration, and Bot.</p>
      <p>We synthesized the neural network model based on a multilayer Rumelhart perceptron, which is a
special case of Rosenblatt perceptron, where weights of neurons are adjusted by back-propagating error
correction. The use of more than one layer (usually two or three) is a feature of the approach [24: 31].</p>
      <p>The multilayer perceptron developed by Rumelhart served as the foundation for the synthesis of the
neural network model. Rumelhart's multilayer perceptron is a particular instance of the Rosenblatt
perceptron in which the error-reversing algorithm modifies the weight coefficients of the neurons. The
existence of many layers (often two or three layers) is uncommon [24; 31]. The Rosenblatt
perceptronbased neural network divides input vectors into the classes 0 and 1, respectively. The input array X and
the target array Y, which designate each of the input vectors to one of the two classes, are the two arrays
that make up the training sequence.</p>
      <p>Input, output, and hidden layers were used in the investigation. The two stages of neural network
back-propagation activities are forward and back-propagation. The input pattern is applied to the input
layer during the forward propagation stage, and its impact spreads across the network layer by layer
until the output value is attained. The error signal for each of the output nodes is calculated after the
actual and predicted output values of the network have been compared. The output errors are sent back
from the output layer to each node in the hidden (inner) layer, which influences the output layer, as all
hidden nodes have more or less contributed to the discovered mistakes in the output layer. The error
signal is used to determine the relative contribution of each node to the overall error. This process is
repeated layer by layer until all nodes receive an error signal.</p>
      <p>The weighting values for each connection are updated using the error data after we have identified
the error signal for each node, and this process continues until the network reaches a point where all
training schemes can be encoded. Using a method known as the delta rule or gradient descent, the
backpropagation algorithm looks for the least value of the error function in the weight space. For the
training task, weights that reduce the error function are thought to be the best option [13; 14].</p>
      <p>When training, if a certain pattern is fed into the input layer, the weighted sum of the inputs to the
jth node in the hidden layer is determined using the following formula:</p>
      <p>(1) determines a neuron's total input. θ_j, a weighted shift node with a constant output value of 1, is
one example. For each neuron in the hidden and output layers, the shift node functions as a
"pseudoinput" and is used to address issues when the value of the input pattern is zero. Without a shift node,
the neural network may be trained if any input pattern contains zero values.</p>
      <p>The action   potential value is supplied to the appropriate activation function, which uses it to
determine whether or not to activate a neuron. The output of the neuron is determined by the value of
the activation function, which also serves as the input for the corresponding neurons in the subsequent
layers.</p>
      <p>For the back-propagation algorithm to work, the activation function must be differentiable. Thus, a
commonly used function is the sigmoid equation.
(1)
(2)</p>
      <p>There could be applied other types of functions for example hyperbolic. (1) and (2) are used to
determine the initial value of the node k in the output layer.</p>
      <p>The synthesis of the model was based on the creation of its software that implements training and
testing of the model. The basic mathematical algorithms used to normalize the data and the training of
the model were performed using the Weka API (Application Programming Interface). Weka is
opensource software released under the GNU General Public License and contains a set of machine-learning
algorithms for data mining tasks. It contains tools for data preparation, classification, regression,
clustering, association extraction rules, and visualization. Weka contains API, which is written in Java
and implements existing algorithms for training with minimal settings. The final training and validation
module was written in the Java programming language.</p>
      <p>To identify the event with a given accuracy, it is required that the relative error does not exceed 4%.
Due to a large amount of training data, it was divided into several blocks according to the type of attack
and it was decided to synthesize a separate neural network model to identify each type of attack.</p>
      <p>If transmitted data to the classifier contains match patterns, then you can calculate the relative error
of the network.</p>
      <p>To ensure accuracy in endpoint identification, our training, validation, and test data must come from
separate machines. Our model undergoes 100 epochs of training, with regular validation to assess its
performance. We select the model that shows the best performance for validation data. Detailed
information on assessing the adequacy of the resulting model when presented with a test subset of data
is presented in Table. 2. This sample reflects the different types of attacks and their relative error of
identification when applied to a synthesized model.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Conclusions</title>
      <p>Analysis of the received results shows that relative identification error when test samples are
presented to the synthesized model varies significantly for different types of network attacks. As Table
2 shows, such types of DoS attacks as GoldenEye, Slowloris, LOIC-UDP, Infiltration, and the HTTP
Benign cannot be identified by the model. However, in general, further research of the opportunity to
use this type of neural network for solving network attack identification issues are rather promising.
Upon reaching acceptable results, the accuracy of the identification model will allow not only to identify
network attacks but also to perform a network security event forecast based on retrospective data
accumulated in the information system over a period and given to the neural network model for training.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Reference</title>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>P.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Desmet</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Huygens</surname>
          </string-name>
          ,
          <article-title>A study on advanced persistent threats</article-title>
          ,
          <source>in: IFIP International Conference on Communications and Multimedia Security</source>
          , Portugal,
          <year>2014</year>
          , pp
          <fpage>63</fpage>
          -
          <lpage>72</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>G.</given-names>
            <surname>Stringhini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Thonnard</surname>
          </string-name>
          ,
          <article-title>That ain't you: Blocking spearphishing through behavioural modelling</article-title>
          .
          <source>In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA)</source>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>The</given-names>
            <surname>White-Hat Hacking</surname>
          </string-name>
          Machine:
          <article-title>Meet Mayhem, winner of the DARPA contest to find and repair software vulnerabilities</article-title>
          , pp.
          <fpage>30</fpage>
          -
          <lpage>35</lpage>
          . https://doi.org/10.1109/MSPEC.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>R.</given-names>
            <surname>Mercy</surname>
          </string-name>
          , G. Padmavathi,
          <article-title>Self-healing AIS with Entropy Based SVM and Bayesian Aggregate Model for the Prediction and Isolation of Malicious Nodes Triggering DoS Attacks in</article-title>
          VANET,
          <source>International Journal of Computer Network and Information Security</source>
          <volume>15</volume>
          (
          <issue>3</issue>
          ) (
          <year>2023</year>
          )
          <fpage>90</fpage>
          -
          <lpage>105</lpage>
          . doi:
          <volume>10</volume>
          .5815/ijcnis.
          <year>2023</year>
          .
          <volume>03</volume>
          .07
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>D. E.</given-names>
            <surname>Denning</surname>
          </string-name>
          ,
          <article-title>An Intrusion Detection Model</article-title>
          ,
          <source>in: Proceedings of the Seventh IEEE Symposium on Security and Privacy</source>
          ,
          <year>1986</year>
          , pp.
          <fpage>119</fpage>
          -
          <lpage>131</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>I.</given-names>
            <surname>Korobiichuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Fedushko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Juś</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Syerov</surname>
          </string-name>
          ,
          <article-title>Methods of Determining Information Support of Web Community User Personal Data Verification System</article-title>
          ,
          <source>Advances in Intelligent Systems and Computing</source>
          <volume>550</volume>
          (
          <year>2017</year>
          )
          <fpage>144</fpage>
          -
          <lpage>150</lpage>
          . doi: https://doi.org/10.1007/978-3-
          <fpage>319</fpage>
          -54042-9_
          <fpage>13</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>K.</given-names>
            <surname>Scarfone</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Mell</surname>
          </string-name>
          ,
          <article-title>Guide to Intrusion Detection and Prevention Systems (IDPS), NIST Special Publication on Computer security (</article-title>
          <year>2007</year>
          )
          <fpage>58</fpage>
          -
          <lpage>69</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>S. M.</given-names>
            <surname>Bellovin</surname>
          </string-name>
          , AT&amp;T Lab Res.,
          <article-title>USA a look back at security problems in the TCP/IP protocol suite</article-title>
          ,
          <source>in: 20th Annual Computer Security Applications Conference</source>
          , USA,
          <year>2004</year>
          , pp.
          <fpage>268</fpage>
          -
          <lpage>286</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>A.</given-names>
            <surname>Borkar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Donode</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Kumari</surname>
          </string-name>
          ,
          <article-title>A survey on Intrusion Detection System (IDS) and Internal Intrusion Detection and protection system (IIDPS)</article-title>
          ,
          <source>in: International Conference on Inventive Computing and Informatics (ICICI)</source>
          , Coimbatore, India,
          <year>2017</year>
          , pp
          <fpage>878</fpage>
          -
          <lpage>880</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>M.</given-names>
            <surname>Azhagiri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Rajesh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Karthik</surname>
          </string-name>
          ,
          <article-title>Intrusion detection and prevention system: technologies and challenges</article-title>
          ,
          <source>International Journal of Applied Engineering Research</source>
          <volume>10</volume>
          (
          <issue>87</issue>
          ) (
          <year>2015</year>
          )
          <fpage>1</fpage>
          -
          <lpage>11</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>R.</given-names>
            <surname>Daş</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Baykara</surname>
          </string-name>
          .
          <article-title>A Survey on Potential Applications of Honeypot Technology in Intrusion Detection Systems</article-title>
          ,
          <source>International Journal of Computer Networks and Applications</source>
          <volume>2</volume>
          (
          <issue>5</issue>
          ) (
          <year>2015</year>
          )
          <fpage>203</fpage>
          -
          <lpage>208</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Hu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Gnatyuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Okhrimenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kinzeryavyy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Iavich</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Yubuzova</surname>
          </string-name>
          ,
          <article-title>High-Speed Privaсy Amplification Method for Deterministic Quantum Cryptography Protocols Using Pairs of Entangled Qutrits</article-title>
          ,
          <source>CEUR Workshop Proceedings</source>
          <volume>2393</volume>
          (
          <year>2019</year>
          ). https://ceur-ws.org/Vol2393/paper_430.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>V. M.</given-names>
            <surname>Linh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Q. N.</given-names>
            <surname>Van</surname>
          </string-name>
          ,
          <string-name>
            <surname>K.</surname>
          </string-name>
          <article-title>Jin-young, K</article-title>
          . Kwangki,
          <string-name>
            <given-names>K.</given-names>
            <surname>Jinsul</surname>
          </string-name>
          ,
          <article-title>Applications of Anomaly Detection Using Deep Learning on Time Series Data</article-title>
          ,
          <source>in: 16th Int. Conf. on Dependable, Autonomic and Secure Computing</source>
          ,
          <year>2018</year>
          , pp.
          <fpage>393</fpage>
          -
          <lpage>396</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>P.</given-names>
            <surname>Chaudhary</surname>
          </string-name>
          ,
          <source>Usage of Machine Learning for Intrusion Detection in a Network</source>
          ,
          <source>International Journal of Computer Networks and Applications</source>
          <volume>3</volume>
          (
          <issue>6</issue>
          ) (
          <year>2016</year>
          )
          <fpage>139</fpage>
          -
          <lpage>145</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Shen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Mariconti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. A.</given-names>
            <surname>Vervier</surname>
          </string-name>
          , G. Stringhini, Tiresias, in: GSAC Conference on Computer and Communications Security,
          <source>CCS '18</source>
          ,
          <year>2018</year>
          , pp.
          <fpage>592</fpage>
          -
          <lpage>605</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Zh</surname>
          </string-name>
          . Lianbing,
          <article-title>Study on Applying the Neural Network</article-title>
          , in: Computer Network Security Assessment 2016 Eighth International Conference on
          <source>Measuring Technology and Mechatronics Automation (ICMTMA)</source>
          ,
          <year>2016</year>
          , pp
          <fpage>639</fpage>
          -
          <lpage>642</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>J.</given-names>
            <surname>Li</surname>
          </string-name>
          , Ch. Dong,
          <article-title>Research on Network Security Situation Prediction-Oriented Adaptive Learning Neuron</article-title>
          , in: Second International Conference on Networks Security,
          <source>Wireless Communications and Trusted Computing</source>
          ,
          <year>2010</year>
          , Vol.
          <volume>2</volume>
          , pp
          <fpage>483</fpage>
          -
          <lpage>485</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>E.</given-names>
            <surname>Chul</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Shin</surname>
          </string-name>
          , Da. Song,
          <string-name>
            <given-names>R.</given-names>
            <surname>Moazzezi</surname>
          </string-name>
          ,
          <article-title>Recognizing Functions in Binaries with Neural Networks</article-title>
          , in: USENIX Security Symposium Washington,
          <year>2015</year>
          , pp.
          <fpage>611</fpage>
          -
          <lpage>626</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>A. A.</given-names>
            <surname>Kuznetsov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. A.</given-names>
            <surname>Smirnov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. A.</given-names>
            <surname>Danilenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Berezovsky</surname>
          </string-name>
          ,
          <article-title>The statistical analysis of network traffic for the intrusion detection and prevention systems</article-title>
          ,
          <source>Telecommunications and Radio Engineering</source>
          <volume>74</volume>
          (
          <issue>1</issue>
          ) (
          <year>2015</year>
          )
          <fpage>61</fpage>
          -
          <lpage>78</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>A.</given-names>
            <surname>Menshawy</surname>
          </string-name>
          ,
          <article-title>Deep Learning By Example. A hands-on guide to implementing advanced machine learning algorithms and neural networks</article-title>
          ,
          <source>Pact Publishing Ltd., Birmingham</source>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>N. I. Naumenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Yu. V.</given-names>
            <surname>Stasev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. A.</given-names>
            <surname>Kuznetsov</surname>
          </string-name>
          ,
          <article-title>Methods of synthesis of signals with prescribed properties</article-title>
          ,
          <source>Cybernetics and Systems Analysis</source>
          <volume>43</volume>
          (
          <issue>3</issue>
          ) (
          <year>2007</year>
          )
          <fpage>321</fpage>
          -
          <lpage>326</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>S.</given-names>
            <surname>Duman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Kalkan-Cakmakci</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Egele</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W. K.</given-names>
            <surname>Robertson</surname>
          </string-name>
          , E. Kirda,
          <article-title>EmailProfiler: Spearphishing Filtering with Header and Stylometric Features of Emails, in: IEEE 40th Annual Computer Software</article-title>
          and Applications Conference (COMPSAC), USA,
          <year>2016</year>
          , pp.
          <fpage>121</fpage>
          -
          <lpage>126</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>O.</given-names>
            <surname>Hubskyi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Babenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Myrutenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Oksiiuk</surname>
          </string-name>
          ,
          <article-title>Detection of sql injection attack using neural networks</article-title>
          .
          <source>Advances in Intelligent Systems and Computing</source>
          ,
          <volume>1265</volume>
          AISC,
          <year>2021</year>
          , pp.
          <fpage>277</fpage>
          -
          <lpage>286</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>S.</given-names>
            <surname>Haykin</surname>
          </string-name>
          ,
          <source>Neural networks and Learning Machines</source>
          , 2nd ed.,
          <string-name>
            <surname>Prentice</surname>
            <given-names>Hall</given-names>
          </string-name>
          , Harlow,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>G.</given-names>
            <surname>Stringhini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Holz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Stone-Gross</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Kruegel</surname>
          </string-name>
          , G. Vigna,
          <article-title>BotMagnifier: Locating Spambots on the Internet</article-title>
          ,
          <source>in: Proceedings of the 2011 USENIX Security Symposium</source>
          , San Francisco, CA,
          <year>2011</year>
          , pp.
          <fpage>427</fpage>
          -
          <lpage>443</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>S.</given-names>
            <surname>Toliupa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Babenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Trush</surname>
          </string-name>
          ,
          <article-title>The building of a security strategy based on the model of game management</article-title>
          , in: 4th International Scientific-Practical Conference Problems of Infocommunications. Science and
          <string-name>
            <surname>Technology (PIC S&amp;T)</surname>
          </string-name>
          , Kharkiv, Ukraine,
          <year>2017</year>
          , pp.
          <fpage>103</fpage>
          -
          <lpage>108</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <article-title>Multiple Buffer Format String Vulnerabilities in SQL Server</article-title>
          . http://www.microsoft.com/technet/security/bulletin/MS01-060.asp.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>