<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">3</article-id>
      <title-group>
        <article-title>Approach to detecting malicious actions of attacker based on autoregression model in investigation of cyber incident</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Подход к обнаружению вредоносных действий злоумышленника на основе модели авторегрессии при расследовании киберинцидента</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name>
            <surname>Smirnov</surname>
            <given-names>S.</given-names>
          </name>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-5511-4000</contrib-id>
          <name>
            <surname>Eremeev</surname>
            <given-names>Mihail</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Pribylov</surname>
            <given-names>I.</given-names>
          </name>
        </contrib>
      </contrib-group>
      <aff id="aff1">MIREA – Russian Technological University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2021-06-03">
        <day>03</day>
        <month>06</month>
        <year>2021</year>
      </pub-date>
      <issue>2</issue>
      <fpage>41</fpage>
      <lpage>47</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2021_2-5-6.pdf"/>
      <abstract xml:lang="en">
        <p>The paper presents an approach to detecting malicious actions of an attacker based on the analysis of the Security.evtx event logs of the Windows operating system when investigating an information security incident. The authors experimentally tested the use of the autoregression model (the Change Finder algorithm), on the basis of which malicious activity of domain users in the corporate network was detected</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>information security incident</kwd>
        <kwd>APT attack</kwd>
        <kwd>lateral movement</kwd>
        <kwd>security log security.evtx</kwd>
        <kwd>change finder algorithm</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
