Russian Journal of Cybernetics
RUS  ENG    JOURNALS   PEOPLE   ORGANISATIONS   CONFERENCES   SEMINARS   VIDEO LIBRARY   PACKAGE AMSBIB  
General information
Latest issue
Archive

Search papers
Search references

RSS
Latest issue
Current issues
Archive issues
What is RSS



Russian Journal of Cybernetics:
Year:
Volume:
Issue:
Page:
Find






Personal entry:
Login:
Password:
Save password
Enter
Forgotten password?
Register


Russian Journal of Cybernetics, 2022, Volume 3, Issue 4, Pages 41–45
DOI: https://doi.org/10.51790/2712-9942-2022-3-4-05
(Mi uk26)
 

Indirect monitoring of suspicious activity on computer systems

K. I. Bushmeleva, A. V. Gavrilenko, A. V. Nikiforov

Surgut State University, Surgut, Russian Federation
References:
Abstract: This study conspires the drawbacks of the existing fraud detection tools and offers a solution: indirect monitoring of suspicious activity on computer systems. We applied the expected value, variance, and standard deviation concepts to estimate the thresholds of indirect indicators of compromise and derived a solution based on the selective mean, selective variance, and selective standard deviation. The paper also describes a sample size estimation procedure from the computer system's indirect indicator sampling rate and runtime. The thresholds of the indirect indicators, the estimated sample size, and other proposed indicators describe the normal operation of the computer system. With this set of indicators, we can define a piecewise function used to check the indirect indicators against the normal operation conditions. Consequently, the computer system can be represented as a predicate. The predicate and the set of indicators are a template describing the computer system. The resulting template and its application scenarios provide a foundation for developing the architecture of an indirect suspicious activity monitoring tool.
Keywords: methodology, monitoring, suspicious activity, computer systems, indirect indicators of compromise.
Document Type: Article
Language: Russian
Citation: K. I. Bushmeleva, A. V. Gavrilenko, A. V. Nikiforov, “Indirect monitoring of suspicious activity on computer systems”, Russian Journal of Cybernetics, 3:4 (2022), 41–45
Citation in format AMSBIB
\Bibitem{BusGavNik22}
\by K.~I.~Bushmeleva, A.~V.~Gavrilenko, A.~V.~Nikiforov
\paper Indirect monitoring of suspicious activity on computer systems
\jour Russian Journal of Cybernetics
\yr 2022
\vol 3
\issue 4
\pages 41--45
\mathnet{http://mi.mathnet.ru/uk26}
\crossref{https://doi.org/10.51790/2712-9942-2022-3-4-05}
Linking options:
  • https://www.mathnet.ru/eng/uk26
  • https://www.mathnet.ru/eng/uk/v3/i4/p41
  • Citing articles in Google Scholar: Russian citations, English citations
    Related articles in Google Scholar: Russian articles, English articles
    Russian Journal of Cybernetics
    Statistics & downloads:
    Abstract page:22
    Full-text PDF :33
    References:3
     
      Contact us:
     Terms of Use  Registration to the website  Logotypes © Steklov Mathematical Institute RAS, 2024