<?xml version="1.0" encoding="UTF-8"?>
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="JATS-archive-oasis-article1-4.xsd" article-type="research-article" dtd-version="1.4" xml:lang="ru">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>Журнал Современные наукоемкие технологии</journal-title>
      </journal-title-group>
      <issn>1812-7320</issn>
      <publisher>
        <publisher-name>Общество с ограниченной ответственностью &amp;quot;Издательский Дом &amp;quot;Академия Естествознания&amp;quot;</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.17513/snt.39501</article-id>
      <article-id pub-id-type="publisher-id">ART-39501</article-id>
      <title-group>
        <article-title>ИСПОЛЬЗОВАНИЕ МЕТОДОВ МАШИННОГО ОБУЧЕНИЯ ДЛЯ ГЕНЕРАЦИИ ПРАВИЛ ОБНАРУЖЕНИЯ ВРЕДОНОСНОГО ТРАФИКА В АВТОНОМНОМ ПРОГРАММНО-АППАРАТНОМ КОМПЛЕКСЕ</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name-alternatives>
            <name xml:lang="ru">
              <surname>Шнайдер</surname>
              <given-names>А.В.</given-names>
            </name>
          </name-alternatives>
          <name-alternatives>
            <name xml:lang="en">
              <surname>Shnayyder</surname>
              <given-names>A.V.</given-names>
            </name>
          </name-alternatives>
          <email>shnaider_andrey@mail.ru</email>
          <xref ref-type="aff" rid="aff1"/>
        </contrib>
        <contrib contrib-type="author">
          <name-alternatives>
            <name xml:lang="ru">
              <surname>Казаков</surname>
              <given-names>Ф.А.</given-names>
            </name>
          </name-alternatives>
          <name-alternatives>
            <name xml:lang="en">
              <surname>Kazakov</surname>
              <given-names>F.A.</given-names>
            </name>
          </name-alternatives>
          <email>fkazakov@sfu-kras.ru</email>
          <xref ref-type="aff" rid="aff1"/>
        </contrib>
      </contrib-group>
      <aff id="aff1">
        <institution xml:lang="ru">ФГАОУ ВО «Сибирский федеральный университет»</institution>
        <institution xml:lang="en">Siberian Federal University</institution>
      </aff>
      <pub-date date-type="pub" iso-8601-date="2023-01-02">
        <day>02</day>
        <month>01</month>
        <year>2023</year>
      </pub-date>
      <issue>1</issue>
      <fpage>83</fpage>
      <lpage>88</lpage>
      <permissions>
        <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
          <license-p>This is an open-access article distributed under the terms of the CC BY 4.0 license.</license-p>
        </license>
      </permissions>
      <self-uri content-type="url" hreflang="ru">https://top-technologies.ru/article/view?id=39501</self-uri>
      <abstract xml:lang="ru" lang-variant="original" lang-source="author">
        <p>В данной работе, в рамках создания автономного программно-аппаратного комплекса по выявлению вредоносных сетевых воздействий, рассматривается возможность применения методов обработки естественного языка (NLP) для генерации правил системы Snort. Оценивается возможность создания автоматического модуля генерации правил, что позволит говорить о возможности создания полностью автономного программно-аппаратного комплекса. Предлагается техника NLP для упрощения процесса составления правил и, таким образом, повышения скорости реакции на возникновение новых сетевых угроз. С помощью методов обработки естественного языка и методов машинного обучения новые правила генерируются на основе выделенного обучающего набора сетевого трафика (сетевых пакетов), который может формироваться как на основе уже известных сетевых угроз, так и на основе только что выделенных вредоносных пакетов. Для создания модуля генерации трафика выбран новый класс нейросетей – трансформеров, используемый для решения задач обработки естественного языка, учитывающий сильные зависимости. Выполнено сравнение стационарного типового набора правил выделения сетевых угроз с динамически сформированным набором с точки зрения обнаружения существующих типов вредоносного трафика и количества «ложноположительных» срабатываний, показано достаточно высокое качество полученного набора и минимальные показатели ошибок.</p>
      </abstract>
      <abstract xml:lang="en" lang-variant="translation" lang-source="translator">
        <p>In this paper, within the framework of creating an autonomous hardware-software complex for detecting malicious network influences, the possibility of applying natural language processing (NLP) methods for generating Snort system rules is considered. The possibility of creating an automatic module for rule generation is assessed, which will allow talking about the possibility of creating a fully autonomous hardware and software complex. We propose an NLP technique to simplify the rule generation process and thus increase the speed of response to the emergence of new network threats. Using natural language processing and machine learning techniques, new rules are generated from a dedicated training set of network traffic (network packets), which can be generated from both already known network threats and newly identified malicious packets. To create a traffic generation module, a new class of neural networks – transformers – is selected, which is used to solve natural language processing problems, taking into account strong dependencies. The comparison of the stationary typical set of rules for detection of network threats and dynamically generated set-in terms of detection of existing types of malicious traffic and number of “false positives” is performed, it is shown that the obtained set is of high enough quality and minimal error rates.</p>
      </abstract>
      <kwd-group xml:lang="ru">
        <kwd>анализ сетевого трафика</kwd>
        <kwd>машинное обучение</kwd>
        <kwd>генерация правил</kwd>
        <kwd>искусственная нейронная сеть</kwd>
        <kwd>сигнатура</kwd>
      </kwd-group>
      <kwd-group xml:lang="en">
        <kwd>network traffic analysis</kwd>
        <kwd>machine learning</kwd>
        <kwd>rule generation</kwd>
        <kwd>artificial neural network</kwd>
        <kwd>signature</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <back>
    <ref-list>
      <ref>
        <note>
          <p>1. Гафаров Ф.М., Галимянов А.Ф. Искусственные нейронные сети и приложения: учебное пособие. Казань: Издательство Казанского университета, 2018. 121 с.</p>
        </note>
      </ref>
      <ref>
        <note>
          <p>2. Kashyap N. Providing Cyber Security using Artificial Intelligence. A survey, in 2019 3rd International Conference on Computing Methodologies and Communication (ICCMC). Mar. 2019. P. 717–720. DOI: 10.1109/ICCMC.2019.8819719.</p>
        </note>
      </ref>
      <ref>
        <note>
          <p>3. Scarfone K.A., Mell P.M. Guide to Intrusion Detection and Prevention Systems (IDPS). National Institute of Standards and Technology, 2007. P. 28. P. 800-894. DOI: 10.6028/NIST.S.</p>
        </note>
      </ref>
      <ref>
        <note>
          <p>4. Understanding and Configuring Snort Rules. Rapid7 Blog, Rapid7, Dec. 09. 2019. [Электронный ресурс]. URL: https://www.rapid7.com/blog/post/2016/12/09/understanding-and-configuring- snort-rules/ (дата обращения: 15.11.2022).</p>
        </note>
      </ref>
      <ref>
        <note>
          <p>5. Peter J.B., Richard A.D. Introduction to Time Series and Forecasting – 2nd ed. Springer-Verlag New York, Inc. 2020. 449 с.</p>
        </note>
      </ref>
      <ref>
        <note>
          <p>6. Abanda A., Mori U., Lozano J. A review on distance-based time series classification. Data Mining and Knowledge Discovery. 2019. Vol. 33. No. 2. P. 378–412.</p>
        </note>
      </ref>
      <ref>
        <note>
          <p>7. Top NLP-Based Personal Assistant Apps Used In 2019. [Электронный ресурс]. URL: https://analyticsindiamag.com/top-nlp-based-personal-assistant-apps-used-in-2019/ (дата обращения: 19.11.2022).</p>
        </note>
      </ref>
      <ref>
        <note>
          <p>8. Natural Language Processing (NLP): What Is It &amp; How Does it Work? MonkeyLearn. [Электронный ресурс]. URL: https://monkeylearn.com/natural-language-processing/ (дата обращения: 16.11.2022).</p>
        </note>
      </ref>
      <ref>
        <note>
          <p>9. Range Dependency – an overview // ScienceDirect Topics. [Электронный ресурс]. URL: https://www.sciencedirect.com/topics/computer-science/range-dependency (дата обращения: 16.11.2022).</p>
        </note>
      </ref>
      <ref>
        <note>
          <p>10. Attention Is All You Need // Vaswani A. Dec. 2017. [Электронный ресурс]. URL: http://arxiv.org/abs/1706.03762 (дата обращения: 16.11.2022).</p>
        </note>
      </ref>
      <ref>
        <note>
          <p>11. Sathyanarayan V.S., Kohli P., Bruhadeshwar B. Signature Generation and Detection of Malware Families. in Information Security and Privacy, Berlin, Heidelberg, 2008. P. 336–349. DOI: 10.1007/978-3-540-70500-0_25.</p>
        </note>
      </ref>
    </ref-list>
  </back>
</article>
