<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">1</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/ukdu-5bxg-fz27</article-id>
      <title-group>
        <article-title>Analysis of methods for attaching malware at the level of security rings of x86_64 processors</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Анализ методов закрепления вредоносного программного обеспечения на уровне колец безопасности процессоров х86_64</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-0623-9891</contrib-id>
          <name>
            <surname>Gololobov</surname>
            <given-names>Nikita</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>gololobov_nv@spbstu.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-1345-1874</contrib-id>
          <name>
            <surname>Pavlenko</surname>
            <given-names>Evgeny</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>pavlenko_eyu@spbstu.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Peter the Great St. Petersburg Polytechnic University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2024-12-20">
        <day>20</day>
        <month>12</month>
        <year>2024</year>
      </pub-date>
      <issue>4</issue>
      <fpage>9</fpage>
      <lpage>21</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2024_4-5-6.pdf"/>
      <abstract xml:lang="en">
        <p>This paper examines methods for persistence establishment of malicious software (malware) to various levels of security rings of modern processors based on the x86_64 architecture. The article discusses all levels of rings from 3 (user) to -3 (level of the control engine). In addition, for each level, the capabilities of malware are defined, which is attached to the corresponding ring. Correlating the capabilities and levels of rings makes it possible in the future to develop criteria according to which it will be possible to identify malicious software operating on a personal computer. As a result of the analysis, it was established that the methods of attachment for different rings differ, and malicious activity can only be detected from levels lower than the malware located, which imposes a number of requirements on a unified method for its detection</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>cybersecurity</kwd>
        <kwd>malware analysis</kwd>
        <kwd>security rings</kwd>
        <kwd>methods of attaching malware</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
