<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">4</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/78up-h9mu-rmxt</article-id>
      <title-group>
        <article-title>Using entropy metrics to detect data integrity attacks in real-time</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Использование энтропийных метрик для выявления атак на целостность данных в режиме реального времени</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0008-8810-6307</contrib-id>
          <name>
            <surname>Bondarenko</surname>
            <given-names>Timur</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>bondarenko.ta@edu.spbstu.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-2009-5460</contrib-id>
          <name>
            <surname>Ovasapyan</surname>
            <given-names>Tigran</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>otd@ibks.spbstu.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0009-5163-9975</contrib-id>
          <name>
            <surname>Piskov</surname>
            <given-names>Aleksandr</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>brontosd2@gmail.com</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Peter the Great St. Petersburg Polytechnic University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2025-08-25">
        <day>25</day>
        <month>08</month>
        <year>2025</year>
      </pub-date>
      <issue>Спецвыпуск</issue>
      <fpage>48</fpage>
      <lpage>57</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2025_spetsvipusk-5-6.pdf"/>
      <abstract xml:lang="en">
        <p>Existing methods of detecting attacks on data integrity on file systems are investigated. A method of detecting such attacks based on the use of several entropy metrics is proposed. The efficiency of the proposed method is evaluated on the example of detection of existing ransomware.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Data integrity</kwd>
        <kwd>entropy</kwd>
        <kwd>dynamic analysis</kwd>
        <kwd>ransomware</kwd>
        <kwd>encryptor</kwd>
        <kwd>driver filter</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
