<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">2</article-id>
      <title-group>
        <article-title>Encrypted files detection algorithm</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Алгоритм обнаружения зашифрованных файлов</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-6501-2008</contrib-id>
          <name>
            <surname>Kozachok</surname>
            <given-names>Alexander</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>totrin@mail.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Kozachok</surname>
            <given-names>Vasily</given-names>
          </name>
          <xref ref-type="aff" rid="aff2"/>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-7231-5728</contrib-id>
          <name>
            <surname>Spirin</surname>
            <given-names>Andrey</given-names>
          </name>
          <xref ref-type="aff" rid="aff3"/>
          <email>spirin_aa@mirea.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">The Academy of Federal Security Guard Service of the Russian Federation</aff>
      <aff id="aff2">Academy of the FSO of Russia</aff>
      <aff id="aff3">MIREA – Russian Technological University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2021-11-12">
        <day>12</day>
        <month>11</month>
        <year>2021</year>
      </pub-date>
      <issue>3</issue>
      <fpage>16</fpage>
      <lpage>26</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/2021_3_5-6.pdf"/>
      <abstract xml:lang="en">
        <p>Since 2010 there is an increase in leaks of confidential information due to the fault of an internal violator, despite the availability of a wide range of means for detecting and preventing information leaks. One of the possible channels leakage is transmission of information in encrypted form, since existing leak detection tools use signature methods of data classification. The article presents an algorithm for detecting encrypted data based on a statistical model of pseudorandom sequences. The proposed algorithm allows classifying encrypted and compressed data with an accuracy of 0.97.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Statistical Data Analysis</kwd>
        <kwd>Classification of Encrypted and Compressed Data</kwd>
        <kwd>Machine Learning</kwd>
        <kwd>Binary Data Analysis</kwd>
        <kwd>Pseudorandom Sequences</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
