<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="en">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">14</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/uhg2-dake-6d11</article-id>
      <title-group>
        <article-title>Intelligent mechanisms for extracting features of file modification in dynamic virus analysis</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Интеллектуальные механизмы извлечения признаков модификации файлов при динамическом вирусном анализе</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-1284-0915</contrib-id>
          <name>
            <surname>Fomicheva</surname>
            <given-names>Svetlana</given-names>
          </name>
          <email>levikha@mail.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0009-9294-7261</contrib-id>
          <name>
            <surname>Gayduk</surname>
            <given-names>Oleg</given-names>
          </name>
          <email>gajduk.o@inbox.ru</email>
        </contrib>
      </contrib-group>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2024-03-25">
        <day>25</day>
        <month>03</month>
        <year>2024</year>
      </pub-date>
      <issue>1</issue>
      <fpage>153</fpage>
      <lpage>167</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2024_1_contents_en.pdf"/>
      <abstract xml:lang="en">
        <p>The paper proposes machine-learning pipelines that allow to automatically generating relevant feature spaces for virus detectors, detect the presence of viral modifications in JS-files and scripts in real time, as well as interpret and visualize the machine solution obtained automatically. 
It is shown that the best quality metrics will be demonstrated by models of an abstract syntactic tree using binary classifiers based on ensembles of decision tree. The explanation, the solution  automatically generated by the virus detector, is demonstrated.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>virus analysis</kwd>
        <kwd>machine-learning models</kwd>
        <kwd>features viral modification</kwd>
        <kwd>decision trees ensembles</kwd>
        <kwd>machine solution interpretation</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
