<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="en">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">8</article-id>
      <title-group>
        <article-title>Integration of recommender systems into UEBA architecture for behavioral anomaly detection</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Интеграция рекомендательных систем в архитектуру UEBA для обнаружения поведенческих аномалий</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name>
            <surname>Logacheva</surname>
            <given-names>Svetlana</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>logacheva_sv@edu.spbstu.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Moskalev</surname>
            <given-names>Nikita</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>moskalev.no@ibks.spbstu.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-2849-4682</contrib-id>
          <name>
            <surname>Lavrova</surname>
            <given-names>Daria</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>lavrova_ds@spbstu.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Peter the Great St. Petersburg Polytechnic University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-10-09">
        <day>09</day>
        <month>10</month>
        <year>2026</year>
      </pub-date>
      <issue>3</issue>
      <fpage>110</fpage>
      <lpage>119</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/images/oblozhki/3_2026.png"/>
      <abstract xml:lang="en">
        <p>The work is devoted to the problem of detecting behavioral anomalies in corporate information systems that are potentially related to the actions of internal intruders. During the work, an analysis of existing UEBA (User and Entity Behavior Analytics) systems was conducted. The identified shortcomings of known solutions highlight the need to create new approaches to analyzing user behavior. As a solution, an approach to integrating recommendation systems into the UEBA architecture was developed, based on rephrasing the task of anomaly detection as a task of estimating the typicality of user behavior based on collective experience. The feasibility of this approach was theoretically justified and experimentally confirmed. The obtained results demonstrate the superiority of the proposed approach over the basic methods in terms of Precision and F1-score metrics and can be used to create new protective solutions.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>UEBA</kwd>
        <kwd>recommender systems</kwd>
        <kwd>behavioral analytics</kwd>
        <kwd>collaborative filtering</kwd>
        <kwd>anomaly detection</kwd>
        <kwd>insider threats</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
