<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">7</article-id>
      <title-group>
        <article-title>Detection of network attacks in software-defined networks using isolating forest algorithm</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Обнаружение сетевых атак в программно-конфигурируемых сетях с использованием алгоритма изолирующего леса</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name>
            <surname>Stepanov</surname>
            <given-names>M.</given-names>
          </name>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-1345-1874</contrib-id>
          <name>
            <surname>Pavlenko</surname>
            <given-names>Evgeny</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>pavlenko_eyu@spbstu.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-2849-4682</contrib-id>
          <name>
            <surname>Lavrova</surname>
            <given-names>Daria</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>lavrova_ds@spbstu.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Peter the Great St. Petersburg Polytechnic University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2021-03-30">
        <day>30</day>
        <month>03</month>
        <year>2021</year>
      </pub-date>
      <issue>1</issue>
      <fpage>62</fpage>
      <lpage>78</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2021_1-5-6.pdf"/>
      <abstract xml:lang="en">
        <p>This paper proposes an approach for detecting network attacks in software-defined networks. The specifics of such networks in terms of security are taken into account, and a modified isolating forest algorithm is taken as the basis for the developed approach. The results of experimental studies where the optimal parameters of the isolating forest algorithm and the extended algorithm of the isolating forest are chosen are presented. Based on the results of the studies, a conclusion is made about the effectiveness of the isolating forest for network attack detection in software-defined networks</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>software-defined network</kwd>
        <kwd>network attacks</kwd>
        <kwd>isolation forest algorithm</kwd>
        <kwd>extended isolation forest algorithm</kwd>
        <kwd>networks attack detection</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
