<?xml version="1.0" encoding="utf-8"?>
<journal>
  <titleid>9004</titleid>
  <issn>2071-8217</issn>
  <journalInfo lang="ENG">
    <title>Problems of information security. Computer systems</title>
  </journalInfo>
  <issue>
    <number>3</number>
    <altNumber> </altNumber>
    <dateUni>2026</dateUni>
    <pages>1-216</pages>
    <articles>
      <article>
        <artType>REV</artType>
        <langPubl>RUS</langPubl>
        <pages>9-24</pages>
        <authors>
          <author num="001">
            <authorCodes>
              <orcid>0009-0007-8669-8081</orcid>
            </authorCodes>
            <individInfo lang="ENG">
              <orgName>Peter the Great St. Petersburg Polytechnic University</orgName>
              <surname>Istomina</surname>
              <initials>Anastasiya</initials>
              <email>isto.anastasiya@gmail.com</email>
            </individInfo>
          </author>
          <author num="002">
            <authorCodes>
              <orcid>0009-0008-9678-2428</orcid>
            </authorCodes>
            <individInfo lang="ENG">
              <orgName>JSC “Positive Technologies”</orgName>
              <surname>Iakovlev</surname>
              <initials>Andrei</initials>
              <email>Andrew42ru@icloud.com</email>
            </individInfo>
          </author>
        </authors>
        <artTitles>
          <artTitle lang="ENG">Systematization of open protection mechanisms for agent systems based on large language models and analysis of threat landscape coverage</artTitle>
        </artTitles>
        <abstracts>
          <abstract lang="ENG">Protection tools for agent systems based on large language models develop in a fragmented way. They exist as separate open-source projects, commercial products, and research publications, and there is no unified view of how completely they cover current threat classes. This work systematizes the protection mechanisms of agent systems and assesses how completely they cover the threat landscape. A two-axis classification is proposed, in which each mechanism is characterized by its architectural level of application and its nature of impact. Following a unified scheme, 46 mechanisms selected from a catalog of 118 repositories are described. A quantitative coverage map of threats and mechanisms is built against the OWASP Top 10 for Agentic Applications 2026 and the OWASP Top 10 for Large Language Model Applications 2025. A defensein-depth indicator is introduced. The set of mechanisms covers all 10 classes of agentic threats, but coverage depth is distributed unevenly. “Tool misuse” is covered most fully, while “memory poisoning”, “insecure inter agent communication”, and “compromised agents” remain structural gaps without a mature preventive tool. Typical misconceptions in selecting protection tools are identified, and a minimal set of protections for designing agent systems is proposed.</abstract>
        </abstracts>
        <codes>
          <udk>004.056</udk>
        </codes>
        <keywords>
          <kwdGroup lang="ENG">
            <keyword>Agent systems</keyword>
            <keyword>large language models</keyword>
            <keyword>protection mechanisms</keyword>
            <keyword>threat landscape</keyword>
            <keyword>OWASP</keyword>
            <keyword>prompt injection</keyword>
            <keyword>threat coverage map</keyword>
          </kwdGroup>
        </keywords>
        <files>
          <furl>https://jisp.spbstu.ru/article/2026.28.1/</furl>
          <file>3_2026.png</file>
        </files>
      </article>
      <article>
        <artType>RAR</artType>
        <langPubl>RUS</langPubl>
        <pages>25-48</pages>
        <authors>
          <author num="001">
            <authorCodes>
              <orcid>0009-0000-3319-8357</orcid>
            </authorCodes>
            <individInfo lang="ENG">
              <orgName>Saint Petersburg Electrotechnical University "LETI"</orgName>
              <surname>Kasyanov</surname>
              <initials>Alexandr</initials>
              <email>kasjanov@inbox.ru</email>
            </individInfo>
          </author>
          <author num="002">
            <authorCodes>
              <orcid>0000-0003-1373-0670</orcid>
            </authorCodes>
            <individInfo lang="ENG">
              <orgName>ITMO University</orgName>
              <surname>Grishencev</surname>
              <initials>Alexey</initials>
              <email>agrishentsev@yandex.ru</email>
            </individInfo>
          </author>
        </authors>
        <artTitles>
          <artTitle lang="ENG">Method of evaluating the quality of random-number generators based on spectral entropy calculation</artTitle>
        </artTitles>
        <abstracts>
          <abstract lang="ENG">The aim of this study was to develop and mathematically substantiate a method for assessing the randomness quality of output sequences produced by random and pseudorandom number generators based on spectral entropy. To solve the individual subproblems, the following methods were used: the discrete Fourier transform for signal spectrum computation; nonparametric bootstrap for constructing empirical distributions of estimates and determining decision thresholds; and the Mahalanobis distance for quantitative comparison of the analyzed realizations with a reference region and for formalizing the criterion of membership in the class of random sequences. Using a test case based on a deterministic sequence of natural numbers, it was established that Shannon entropy may yield a false-positive conclusion of randomness, whereas spectral entropy reliably detects non-randomness. The study of random sequences generated by a physical generator under different operating modes made it possible to conclude that the spectral entropy method detects degradation of sequence randomness when the generator operating conditions are chosen incorrectly. It should be noted that, in terms of effectiveness for the problem under consideration, the proposed spectral entropy method is not inferior to the standard NIST STS tests and, in some cases, outperforms them. Within the conducted experiments, it was established that the synthesized sequences generated using the ChaCha20 stream cipher satisfy the randomness criterion obtained by the spectral entropy method, which is interpreted as compliance with the requirements imposed on cryptographic sources of randomness. The study also showed that the developed method makes it possible to detect non-randomness in sequences generated by linear feedback shift registers (LFSRs). The scientific novelty of the work lies in the fact that а method for evaluating the quality of random and pseudorandom number generators based on spectral entropy computation has been theoretically substantiated and developed to a level of readiness for practical application. It has been established that, compared with Shannon entropy, the method provides greater robustness in randomness quality assessment. The practical significance lies in improving the efficiency of assessing the quality of random and pseudorandom sequences.</abstract>
        </abstracts>
        <codes>
          <udk>519.248:004.056.5</udk>
        </codes>
        <keywords>
          <kwdGroup lang="ENG">
            <keyword>Randomness</keyword>
            <keyword>bit sequence</keyword>
            <keyword>spectral entropy</keyword>
            <keyword>power spectral density</keyword>
            <keyword>bootstrap method</keyword>
            <keyword>statistical testing</keyword>
            <keyword>Mahalanobis distance (metric)</keyword>
            <keyword>interquartile range</keyword>
            <keyword>linear feedback shift registers</keyword>
          </kwdGroup>
        </keywords>
        <files>
          <furl>https://jisp.spbstu.ru/article/2026.28.2/</furl>
          <file>3_2026.png</file>
        </files>
      </article>
      <article>
        <artType>REV</artType>
        <langPubl>RUS</langPubl>
        <pages>49-59</pages>
        <authors>
          <author num="001">
            <authorCodes>
              <orcid>0009-0009-2388-9467</orcid>
            </authorCodes>
            <individInfo lang="ENG">
              <orgName>Peter the Great St. Petersburg Polytechnic University</orgName>
              <surname>Siotanov</surname>
              <initials>Alexey</initials>
              <email>siotanov.am@edu.spbstu.ru</email>
            </individInfo>
          </author>
          <author num="002">
            <individInfo lang="ENG">
              <orgName>Peter the Great St. Petersburg Polytechnic University</orgName>
              <surname>Makarov</surname>
              <initials>Alexander</initials>
              <email>makarov_as@spbstu.ru</email>
            </individInfo>
          </author>
        </authors>
        <artTitles>
          <artTitle lang="ENG">Review of protocols for secure remote access to computer systems</artTitle>
        </artTitles>
        <abstracts>
          <abstract lang="ENG">The article discusses the problem of ensuring information security with remote access to information resources. The relevance of the work is due to the growth of distributed computer systems and the high risks of data interception during the transfer of credentials. The functions of the remote access server and the basic Point-to-Point Protocol link layer are analyzed. The main focus is on the classification and comparison of authentication protocols: direct scheme (PAP, CHAP, S/Key) and indirect (centralized) scheme (RADIUS, Kerberos). The article describes in detail the algorithms of each protocol. As a result of the research, the necessity of a combined approach to the choice of authentication protocols depending on the network architecture is substantiated, as well as the requirements for modern remote access systems are formulated.</abstract>
        </abstracts>
        <codes>
          <udk>004.056.5</udk>
        </codes>
        <keywords>
          <kwdGroup lang="ENG">
            <keyword>Information security</keyword>
            <keyword>remote access</keyword>
            <keyword>protocol</keyword>
            <keyword>authentication</keyword>
            <keyword>computer systems</keyword>
          </kwdGroup>
        </keywords>
        <files>
          <furl>https://jisp.spbstu.ru/article/2026.28.3/</furl>
          <file>3_2026.png</file>
        </files>
      </article>
      <article>
        <artType>RAR</artType>
        <langPubl>RUS</langPubl>
        <pages>60-71</pages>
        <authors>
          <author num="001">
            <authorCodes>
              <orcid>0009-0003-4569-2258</orcid>
            </authorCodes>
            <individInfo lang="ENG">
              <orgName>Peter the Great St. Petersburg Polytechnic University</orgName>
              <surname>Vedenskii</surname>
              <initials>Viktor</initials>
              <email>viktor_vedenskiy@bk.ru</email>
            </individInfo>
          </author>
        </authors>
        <artTitles>
          <artTitle lang="ENG">A model of risk-aware scheduling in container orchestrators considering the attacker’s horizontal movement</artTitle>
        </artTitles>
        <abstracts>
          <abstract lang="ENG">Common container orchestrator schedulers focus on resource metrics and distribution policies, ignoring the security risks associated with lateral movement between containers and cluster nodes. This paper presents a risk-based pod placement model that accounts for three channels of lateral movement: shared system calls on a node (risk of container escape), role-based access control mismatches, and network interactions between pods. Probabilistic estimates of container compromise are introduced as a function of node security. A greedy algorithm for sequential container assignment suitable for use in real-world schedulers is proposed. A comparative analysis with leading approaches to securing container environments is provided. The results of this study can be applied for the development of Kubernetes scheduler extensions that integrate placement-level security.</abstract>
        </abstracts>
        <codes>
          <udk>004.056</udk>
        </codes>
        <keywords>
          <kwdGroup lang="ENG">
            <keyword>Kubernetes</keyword>
            <keyword>scheduling</keyword>
            <keyword>container security</keyword>
            <keyword>lateral movement</keyword>
          </kwdGroup>
        </keywords>
        <files>
          <furl>https://jisp.spbstu.ru/article/2026.28.4/</furl>
          <file>3_2026.png</file>
        </files>
      </article>
      <article>
        <artType>RAR</artType>
        <langPubl>RUS</langPubl>
        <pages>72-83</pages>
        <authors>
          <author num="001">
            <authorCodes>
              <orcid>0000-0003-0623-9891</orcid>
            </authorCodes>
            <individInfo lang="ENG">
              <orgName>Peter the Great St. Petersburg Polytechnic University</orgName>
              <surname>Gololobov</surname>
              <initials>Nikita</initials>
              <email>gololobov_nv@spbstu.ru</email>
            </individInfo>
          </author>
        </authors>
        <artTitles>
          <artTitle lang="ENG">A formal model of executive software code based on an execution graph for solving the binary morphing problem</artTitle>
        </artTitles>
        <abstracts>
          <abstract lang="ENG">This paper addresses the problem of developing a formal model of executable software code intended to provide a rigorous mathematical description of runtime program transformation (code morphing) processes. The relevance of the study is determined by the need to develop a mathematical framework that provides a formal justification for methods of modifying the structure of executable code without violating the functional correctness of software. The aim of the study is to develop an architecture-independent formal model of executable code that enables the identification of invariant software properties during code morphing operations and establishes the conditions required to preserve the observable behavior of a program. The proposed model integrates both static and dynamic components of executable code. The static component represents a program as a collection of basic blocks connected by a control flow graph, together with a code placement configuration in the address space and a set of control references between the blocks. The dynamic component provides a formal description of the program execution trace, the sequence of computational system states, and the observable behavior defined exclusively by externally observable execution results. The practical significance of the study lies in the development of a unified formal framework suitable for proving the correctness of executable code morphing algorithms, designing methods for their formal verification, and analyzing the security of software systems. The obtained results establish a theoretical foundation for further research in the field of dynamic executable code transformation and the development of advanced software protection technologies.</abstract>
        </abstracts>
        <codes>
          <udk>004.056</udk>
        </codes>
        <keywords>
          <kwdGroup lang="ENG">
            <keyword>Сybersecurity</keyword>
            <keyword>software model</keyword>
            <keyword>execution graph</keyword>
            <keyword>graph theory</keyword>
            <keyword>security analysis</keyword>
            <keyword>code transformation</keyword>
          </kwdGroup>
        </keywords>
        <files>
          <furl>https://jisp.spbstu.ru/article/2026.28.5/</furl>
          <file>3_2026.png</file>
        </files>
      </article>
      <article>
        <artType>RAR</artType>
        <langPubl>RUS</langPubl>
        <pages>84-95</pages>
        <authors>
          <author num="001">
            <authorCodes>
              <orcid>0000-0002-4151-5908</orcid>
            </authorCodes>
            <individInfo lang="ENG">
              <orgName>Mozhaisky Military Space Academy</orgName>
              <surname>Russu</surname>
              <initials>Valery</initials>
              <email>russu_valeriy@mail.ru</email>
            </individInfo>
          </author>
          <author num="002">
            <individInfo lang="ENG">
              <orgName>Military Space Academy named after A. F. Mozhaisky</orgName>
              <surname>Kazmin</surname>
              <initials>Denis</initials>
              <email>nemaskin3112@mail.ru</email>
            </individInfo>
          </author>
          <author num="003">
            <authorCodes>
              <orcid>0000-0003-1300-2470</orcid>
            </authorCodes>
            <individInfo lang="ENG">
              <orgName>Mozhaysky Military Space Academy</orgName>
              <surname>Biryukov</surname>
              <initials>Denis</initials>
              <email>Biryukov.D.N@yandex.ru</email>
              <address>Russia, 197198, St. Petersburg, Zhdanovskaya str., 13</address>
            </individInfo>
          </author>
        </authors>
        <artTitles>
          <artTitle lang="ENG">A method for identifying hidden information leak channels due to incorrect updates of database management system kernel programs</artTitle>
        </artTitles>
        <abstracts>
          <abstract lang="ENG">This article examines the problem of vulnerabilities that arise during software updates in isolated corporate systems running Astra Linux. A possible method for implementing an attack to gain root access through a modified software update package is demonstrated. A multi-layered method for detecting update package modifications is proposed, including static, behavioral, and signature-based analysis using machine learning methods and algorithms. This method significantly improves the security of the software update process in network isolation.</abstract>
        </abstracts>
        <codes>
          <udk>004.056.53</udk>
        </codes>
        <keywords>
          <kwdGroup lang="ENG">
            <keyword>Information security</keyword>
            <keyword>automated vulnerability detection</keyword>
            <keyword>automated firmware unpacking</keyword>
            <keyword>information security</keyword>
          </kwdGroup>
        </keywords>
        <files>
          <furl>https://jisp.spbstu.ru/article/2026.28.6/</furl>
          <file>3_2026.png</file>
        </files>
      </article>
      <article>
        <artType>RAR</artType>
        <langPubl>RUS</langPubl>
        <pages>96-109</pages>
        <authors>
          <author num="001">
            <individInfo lang="ENG">
              <orgName>Peter the Great St. Petersburg Polytechnic University</orgName>
              <surname>Abitov</surname>
              <initials>Roman</initials>
              <email>abitov_roman@mail.ru</email>
            </individInfo>
          </author>
          <author num="002">
            <authorCodes>
              <orcid>0000-0001-9862-1507</orcid>
            </authorCodes>
            <individInfo lang="ENG">
              <orgName>Peter the Great St. Petersburg Polytechnic University</orgName>
              <surname>Dakhnovich</surname>
              <initials>Andrey</initials>
              <email>add@ibks.spbstu.ru</email>
            </individInfo>
          </author>
          <author num="003">
            <individInfo lang="ENG">
              <orgName>Peter the Great St. Petersburg Polytechnic University</orgName>
              <surname>Moskvin</surname>
              <initials>Dmitry</initials>
              <email>moskvin_da@spbstu.ru</email>
            </individInfo>
          </author>
        </authors>
        <artTitles>
          <artTitle lang="ENG">Research on methods for automated data extraction from web resources with dynamically changing content using AI agents</artTitle>
        </artTitles>
        <abstracts>
          <abstract lang="ENG">This paper addresses automated extraction of data from web resources with dynamically changing content using AI agents. Data collection practice remains fragmented because of heterogeneous DOM structures, interactive user actions, anti-bot controls, and the predominance of unstructured web data, which increases maintenance costs of classical parsers. We propose a two-stage method that separates an expensive large language model analysis stage from an economical deterministic mass-collection stage. The method is implemented in a software prototype based on OpenClaw multi-agent orchestration, an isolated Chromium browser contour, the Model Context Protocol, and an authentication contour. We performed comparative analysis of scraping tools and large language models, classified feed types and active actions, and experimentally assessed extraction quality. On a reference dataset the primary quality metric reached F1 = 0.89. Limitations include selector fragility, evolving anti-bot mechanisms, and the computational cost of the configuration stage.</abstract>
        </abstracts>
        <codes>
          <udk>004.89:004.738.5</udk>
        </codes>
        <keywords>
          <kwdGroup lang="ENG">
            <keyword>AI agents</keyword>
            <keyword>data extraction</keyword>
            <keyword>web scraping</keyword>
            <keyword>dynamic content</keyword>
            <keyword>large language models</keyword>
            <keyword>asynchronous processing</keyword>
            <keyword>fault tolerance</keyword>
            <keyword>data quality</keyword>
            <keyword>Model Context Protocol</keyword>
            <keyword>Chromium</keyword>
            <keyword>OpenClaw</keyword>
          </kwdGroup>
        </keywords>
        <files>
          <furl>https://jisp.spbstu.ru/article/2026.28.7/</furl>
          <file>3_2026.png</file>
        </files>
      </article>
      <article>
        <artType>RAR</artType>
        <langPubl>RUS</langPubl>
        <pages>110-119</pages>
        <authors>
          <author num="001">
            <individInfo lang="ENG">
              <orgName>Peter the Great St. Petersburg Polytechnic University</orgName>
              <surname>Logacheva</surname>
              <initials>Svetlana</initials>
              <email>logacheva_sv@edu.spbstu.ru</email>
            </individInfo>
          </author>
          <author num="002">
            <individInfo lang="ENG">
              <orgName>Peter the Great St. Petersburg Polytechnic University</orgName>
              <surname>Moskalev</surname>
              <initials>Nikita</initials>
              <email>moskalev.no@ibks.spbstu.ru</email>
            </individInfo>
          </author>
          <author num="003">
            <authorCodes>
              <orcid>0000-0003-2849-4682</orcid>
            </authorCodes>
            <individInfo lang="ENG">
              <orgName>Peter the Great St. Petersburg Polytechnic University</orgName>
              <surname>Lavrova </surname>
              <initials>Daria</initials>
              <email>lavrova_ds@spbstu.ru</email>
              <address>Russia, 195251, St. Petersburg, Polytechnicheskaya str., 29</address>
            </individInfo>
          </author>
        </authors>
        <artTitles>
          <artTitle lang="ENG">Integration of recommender systems into UEBA architecture for behavioral anomaly detection</artTitle>
        </artTitles>
        <abstracts>
          <abstract lang="ENG">The work is devoted to the problem of detecting behavioral anomalies in corporate information systems that are potentially related to the actions of internal intruders. During the work, an analysis of existing UEBA (User and Entity Behavior Analytics) systems was conducted. The identified shortcomings of known solutions highlight the need to create new approaches to analyzing user behavior. As a solution, an approach to integrating recommendation systems into the UEBA architecture was developed, based on rephrasing the task of anomaly detection as a task of estimating the typicality of user behavior based on collective experience. The feasibility of this approach was theoretically justified and experimentally confirmed. The obtained results demonstrate the superiority of the proposed approach over the basic methods in terms of Precision and F1-score metrics and can be used to create new protective solutions.</abstract>
        </abstracts>
        <codes>
          <udk>004.056</udk>
        </codes>
        <keywords>
          <kwdGroup lang="ENG">
            <keyword>UEBA</keyword>
            <keyword>recommender systems</keyword>
            <keyword>behavioral analytics</keyword>
            <keyword>collaborative filtering</keyword>
            <keyword>anomaly detection</keyword>
            <keyword>insider threats</keyword>
          </kwdGroup>
        </keywords>
        <files>
          <furl>https://jisp.spbstu.ru/article/2026.28.8/</furl>
          <file>3_2026.png</file>
        </files>
      </article>
      <article>
        <artType>RAR</artType>
        <langPubl>RUS</langPubl>
        <pages>120-130</pages>
        <authors>
          <author num="001">
            <authorCodes>
              <orcid>0000-0002-3139-0748</orcid>
            </authorCodes>
            <individInfo lang="ENG">
              <orgName>Origin Security</orgName>
              <surname>Antonov</surname>
              <initials>Roman</initials>
              <email>antonov@originsecurity.ru</email>
            </individInfo>
          </author>
        </authors>
        <artTitles>
          <artTitle lang="ENG">Methodology for selecting information security tools for an airline based on the branch-and-bound method</artTitle>
        </artTitles>
        <abstracts>
          <abstract lang="ENG">Modern requirements for the rational use of aircraft enterprise networks and their information security determine the choice of relevant information security tools. Currently, the market offers a wide range of certified information security tools, making it difficult to choose the optimal option. To address this issue, the article proposes a methodology based on the branch-and-bound method for selecting information security tools for processing personal data in aircraft enterprise information systems. This methodology allows for finding the optimal solution within the framework of a deterministic linear model of discrete optimization, eliminating inefficient options in the initial stages.</abstract>
        </abstracts>
        <codes>
          <udk>004.056.53</udk>
        </codes>
        <keywords>
          <kwdGroup lang="ENG">
            <keyword>Methodology</keyword>
            <keyword>branch and bound method</keyword>
            <keyword>information security</keyword>
            <keyword>airline</keyword>
            <keyword>threats</keyword>
            <keyword>discrete optimization</keyword>
            <keyword>information security tools</keyword>
          </kwdGroup>
        </keywords>
        <files>
          <furl>https://jisp.spbstu.ru/article/2026.28.9/</furl>
          <file>3_2026.png</file>
        </files>
      </article>
    </articles>
  </issue>
</journal>
