Approach to detecting malicious actions of attacker based on autoregression model in investigation of cyber incident
Authors:
Abstract:
The paper presents an approach to detecting malicious actions of an attacker based on the analysis of the Security. evtx event logs of the Windows operating system when investigating an information security incident. The authors experimentally tested the use of the autoregression model (the Change Finder algorithm), on the basis of which malicious activity of domain users in the corporate network was detected