<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="en">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">1</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/422m-udhg-dg48</article-id>
      <title-group>
        <article-title>Identification of malicious executable files based on static-dynamic analysis using machine learning</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Выявление вредоносных исполняемых файлов на основе статико-динамического анализа с использованием машинного обучения</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0004-1271-709X</contrib-id>
          <name>
            <surname>Ognev</surname>
            <given-names>Roman</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>ognev_ra@spbstu.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0002-7321-7430</contrib-id>
          <name>
            <surname>Zhukovskii</surname>
            <given-names>Evgeniy</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>bugaev.va@edu.spbstu.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-0232-7248</contrib-id>
          <contrib-id contrib-id-type="scopus">13103571000</contrib-id>
          <name>
            <surname>Zegzhda</surname>
            <given-names>Dmitry</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>zegzhda_dp@spbstu.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Kiselev</surname>
            <given-names>Alexey</given-names>
          </name>
        </contrib>
      </contrib-group>
      <aff id="aff1">Peter the Great St. Petersburg Polytechnic University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2021-12-24">
        <day>24</day>
        <month>12</month>
        <year>2021</year>
      </pub-date>
      <issue>4</issue>
      <fpage>9</fpage>
      <lpage>25</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2021_4-7-8.pdf"/>
      <abstract xml:lang="en">
        <p>The article is devoted to the study of methods for detecting malicious software (malware) using static-dynamic analysis. A method for detecting malware is proposed, in which the number of parameters of the behavior of executable files is optimized using clustering of insignificant features, and also fuzzy-hashing of own functions is used when constructing a call trace. A prototype of a malware detection system based on the proposed method has been developed. Experimental studies assess the effectiveness of the proposed method. The efficiency of malware detection by the developed prototype is estimated. According to the verification results, the developed prototype was able to improve the detection efficiency of malware.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>information security systems</kwd>
        <kwd>detection of malicious software</kwd>
        <kwd>static-dynamic analysis</kwd>
        <kwd>parameter feature selection</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
