<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">1</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/t99x-zeux-75er</article-id>
      <title-group>
        <article-title>Optimization of indicator of compromise utilization in information security tasks</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Оптимизация использования индикаторов компрометации в задачах информационной безопасности</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0007-7981-1146</contrib-id>
          <name>
            <surname>Chizhevsky</surname>
            <given-names>Maxim</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>ch.inc@yandex.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-5583-4972</contrib-id>
          <name>
            <surname>Serpeninov</surname>
            <given-names>Oleg</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>serpeninov53@mail.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-2273-725X</contrib-id>
          <name>
            <surname>Lapsar</surname>
            <given-names>Aleksey</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>lapsar1958@mail.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Rostov State University of Economics</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2025-03-25">
        <day>25</day>
        <month>03</month>
        <year>2025</year>
      </pub-date>
      <issue>1</issue>
      <fpage>9</fpage>
      <lpage>20</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/2025_1-5-6.pdf"/>
      <abstract xml:lang="en">
        <p>The article deals with the problem of updating indicators of compromise in the field of information security. One of the key difficulties is the growing number of false positives, which slows down the process of incident investigation. To solve this problem, we propose a model for assessing the relevance of indicators of compromise, the purpose of which is to optimise their use. The developed model takes into account various parameters, such as the indicator obsolescence rate, the level of trust in the source, the frequency of detection, the proportion of false positives, the consideration of information from open sources, and the type of malicious activity. The model reduces the number of false positives and improves the efficiency of incident monitoring.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Indicator of compromise</kwd>
        <kwd>relevance</kwd>
        <kwd>assessment model</kwd>
        <kwd>relevance dynamics</kwd>
        <kwd>information security</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
