<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="https://aereview.ru/lib/pkp/xml/oai2.xsl" ?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/"
	xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
	xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/
		http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
	<responseDate>2026-08-11T00:01:57Z</responseDate>
	<request identifier="oai:ojs2.aereview.ru:article/108" metadataPrefix="jats" verb="GetRecord">https://aereview.ru/index.php/ae/oai</request>
	<GetRecord>
		<record>
			<header>
				<identifier>oai:ojs2.aereview.ru:article/108</identifier>
				<datestamp>2026-02-16T20:02:05Z</datestamp>
				<setSpec>ae:AER</setSpec>
			</header>
			<metadata>
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="https://jats.nlm.nih.gov/publishing/1.1/" dtd-version="1.1" xsi:noNamespaceSchemaLocation="https://jats.nlm.nih.gov/archiving/1.4/xsd/JATS-archivearticle1.xsd" xml:lang="ru" specific-use="eps-0.1">
			<front>
			<journal-meta>
				<journal-id journal-id-type="publisher">ae</journal-id><journal-id journal-id-type="ojs">ae</journal-id>
				<journal-title-group>
			<journal-title xml:lang="ru">Академический исследовательский журнал</journal-title><trans-title-group xml:lang="en"><trans-title>Academic Research Journal</trans-title></trans-title-group>
</journal-title-group>			<issn pub-type="epub">3034-6665</issn>			<publisher><publisher-name>Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.Индивидуальный предприниматель Подколзин М.М.</publisher-name></publisher>
			<self-uri xlink:href="https://aereview.ru/index.php/ae"/>
		</journal-meta>
		<article-meta>
			<article-id pub-id-type="doi">10.25726/v5560-6069-4729-z</article-id><article-id pub-id-type="publisher-id">108</article-id>
			<article-categories><subj-group subj-group-type="heading" xml:lang="en"><subject>APPLIED RESEARCH</subject></subj-group><subj-group subj-group-type="heading" xml:lang="ru"><subject>ПРИКЛАДНЫЕ ИССЛЕДОВАНИЯ</subject></subj-group></article-categories>
			<title-group><article-title xml:lang="ru">Разработка модели прогнозирования кибератак</article-title><trans-title-group xml:lang="en"><trans-title>Development of a cyberattack forecasting model</trans-title></trans-title-group></title-group>
			<contrib-group content-type="author">
				<contrib contrib-type="author">
					<name-alternatives>
						<name name-style="western" specific-use="primary" xml:lang="ru">
							<surname>Крахмальный</surname>
							<given-names>Игорь Олегович</given-names>
						</name>
						<name name-style="western" xml:lang="en">
							<surname>Krakhmalny</surname>
							<given-names>Igor O.</given-names>
						</name>
					</name-alternatives>
					<xref ref-type="aff" rid="aff-1"/>
					<email>io.kra@ya.ru</email>
				</contrib>
			</contrib-group>
			<aff-alternatives id="aff-1">
				<aff xml:lang="ru"><institution content-type="orgname">Херсонский технический университет</institution></aff>
				<aff xml:lang="en"><institution content-type="orgname">Kherson Technical University</institution></aff>
			</aff-alternatives>
			<pub-date date-type="collection"><year>2025</year></pub-date><pub-date date-type="pub" publication-format="epub"><day>30</day><month>05</month><year>2025</year></pub-date>
			<volume seq="1">33</volume>
			<issue>55</issue>
				<issue-id>7</issue-id><issue-title xml:lang="ru">Академический исследовательский журнал </issue-title><issue-title xml:lang="en">Academic Research Journal</issue-title><fpage>180</fpage>
				<lpage>184</lpage>
			<history>
				<date date-type="received" iso-8601-date="2025-07-29">
					<day>29</day>
					<month>07</month>
					<year>2025</year>
				</date>
			</history>
			<permissions>
				<copyright-statement>Copyright (c) 2025 Академический исследовательский журнал</copyright-statement>
				<copyright-year>2025</copyright-year>
				<copyright-holder>Академический исследовательский журнал</copyright-holder>
				<license xml:lang="ru" xlink:href="https://creativecommons.org/licenses/by-nc-nd/4.0">
					<license-p>Это произведение доступно по лицензии Creative Commons «Attribution-NonCommercial-NoDerivatives» («Атрибуция — Некоммерческое использование — Без производных произведений») 4.0 Всемирная.</license-p>
				</license>
				<license license-type="open-access" specific-use="metadata" xml:lang="ru" xlink:href="https://creativecommons.org/publicdomain/zero/1.0/">
					<license-p>Метаданные настоящей записи распространяются на условиях Creative Commons CC0 1.0 (передача в общественное достояние).</license-p>
				</license>
			</permissions>
			
			<self-uri xlink:href="https://aereview.ru/index.php/ae/article/view/108"/>
			<abstract><p>В статье рассматривается проблема повышения проактивности защиты информационных систем за счет прогнозирования кибератак. Основная цель исследования заключается в разработке и валидации модели прогнозирования инцидентов информационной безопасности, основанной на анализе гетерогенных данных, собираемых центром управления информационной безопасностью (Security Operation Center – SOC). Авторами предложена многоуровневая архитектура модели, интегрирующая методы предобработки больших объемов операционных данных (логи SIEM, NetFlow, алерты IDS/IPS, данные EDR), выделения значимых признаков и применения ансамблевых алгоритмов машинного обучения, включая градиентный бустинг и рекуррентные нейронные сети, для выявления прекурсоров атак. Экспериментально подтверждена эффективность модели на реальных исторических данных SOC, продемонстрировавшая снижение времени обнаружения (MTTD) угроз на 35% и повышение точности (precision) прогноза до 0.87. Результаты исследования имеют значительный практический потенциал для совершенствования процессов мониторинга и реагирования в SOC.</p></abstract><trans-abstract xml:lang="en"><p>The article discusses the problem of increasing the proactivity of information system protection by predicting cyber attacks. The main purpose of the research is to develop and validate an information security incident forecasting model based on the analysis of heterogeneous data collected by the Information Security Management Center (SOC). The authors propose a multi-level model architecture that integrates methods for preprocessing large amounts of operational data (SIEM logs, NetFlow, IDS/IPS alerts, EDR data), identifying significant features, and using ensemble machine learning algorithms, including gradient boosting and recurrent neural networks, to identify attack precursors. The effectiveness of the model based on real historical SOC data has been experimentally confirmed, demonstrating a 35% reduction in threat detection time (MTTD) and an increase in forecast accuracy to 0.87. The results of the study have significant practical potential for improving the monitoring and response processes in SOC.</p></trans-abstract><trans-abstract xml:lang="en"><p>The article discusses the problem of increasing the proactivity of information system protection by predicting cyber attacks. The main purpose of the research is to develop and validate an information security incident forecasting model based on the analysis of heterogeneous data collected by the Information Security Management Center (SOC). The authors propose a multi-level model architecture that integrates methods for preprocessing large amounts of operational data (SIEM logs, NetFlow, IDS/IPS alerts, EDR data), identifying significant features, and using ensemble machine learning algorithms, including gradient boosting and recurrent neural networks, to identify attack precursors. The effectiveness of the model based on real historical SOC data has been experimentally confirmed, demonstrating a 35% reduction in threat detection time (MTTD) and an increase in forecast accuracy to 0.87. The results of the study have significant practical potential for improving the monitoring and response processes in SOC.</p></trans-abstract>
			
			
			<kwd-group xml:lang="en"><title>Keywords</title><kwd>prediction of cyber attacks</kwd><kwd>Security Operation Center (SOC)</kwd><kwd>SIEM data</kwd><kwd>machine learning</kwd><kwd>attack precursors</kwd><kwd>proactive security</kwd><kwd>incident analysis</kwd><kwd>big data in information security</kwd><kwd>threat model</kwd><kwd>anomaly detection</kwd></kwd-group><kwd-group xml:lang="ru"><title>Ключевые слова</title><kwd>прогнозирование кибератак</kwd><kwd>Security Operation Center (SOC)</kwd><kwd>данные SIEM</kwd><kwd>машинное обучение</kwd><kwd>прекурсоры атак</kwd><kwd>проактивная безопасность</kwd><kwd>анализ инцидентов</kwd><kwd>большие данные в ИБ</kwd><kwd>модель угроз</kwd><kwd>обнаружение аномалий</kwd></kwd-group><funding-group>
				<funding-statement xml:lang="ru">Исследование выполнено без внешнего финансирования.</funding-statement>
				<funding-statement xml:lang="en">The study was conducted without external funding.</funding-statement>
			</funding-group>
			<counts><page-count count="5"/></counts>
			<custom-meta-group><custom-meta><meta-name>issue-cover</meta-name><meta-value><inline-graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://aereview.ru/public/journals/1/cover_issue_7_ru_RU.jpg"/></meta-value></custom-meta></custom-meta-group><custom-meta-group>
				<custom-meta>
					<meta-name>metadata-license</meta-name>
					<meta-value><ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/publicdomain/zero/1.0/">CC0 1.0</ext-link></meta-value>
				</custom-meta>
			</custom-meta-group>
		</article-meta>
	</front>
	<back>
		<ref-list xml:lang="ru">
			<title>Список литературы</title>
			<ref id="R1"><mixed-citation>Абрамов М.В., Теплых Д.С. Методология оценки рисков информационной безопасности на основе прогнозных моделей // Надежность и качество сложных систем. 2021. № 3(35). С. 15-28.</mixed-citation></ref>
			<ref id="R2"><mixed-citation>Белов Е.Б., Шелупанов А.А. Предобработка и обогащение данных мониторинга информационной безопасности // Прикладная информатика. 2021. Т. 16. № 4(94). С. 61-73.</mixed-citation></ref>
			<ref id="R3"><mixed-citation>Волынский А.Ф., Королев В.Ю. Прогнозирование инцидентов информационной безопасности: методы и модели // Кибернетика и программирование. 2020. № 5. С. 78-89.</mixed-citation></ref>
			<ref id="R4"><mixed-citation>Горбунов А.А., Костин К.А. Применение рекуррентных нейронных сетей для анализа временных рядов событий безопасности // Искусственный интеллект и принятие решений. 2023. № 1. С. 22-34.</mixed-citation></ref>
			<ref id="R5"><mixed-citation>Дмитриев П.А., Федоров М.И. Сравнительный анализ алгоритмов градиентного бустинга для классификации угроз информационной безопасности // Научно-технические ведомости СПбГПУ. Информатика. Телекоммуникации. Управление. 2022. Т. 15. № 3. С. 98-110.</mixed-citation></ref>
			<ref id="R6"><mixed-citation>Иванова Е.С. Анализ больших данных в задачах информационной безопасности: монография. М.: Инфра-М, 2023. 215 с.</mixed-citation></ref>
			<ref id="R7"><mixed-citation>Кузнецов Д.Л., Михайлов А.П. Использование данных SIEM систем для выявления целевых атак // Труды СПИИРАН. 2022. Т. 21. № 1. С. 120-135.</mixed-citation></ref>
			<ref id="R8"><mixed-citation>Петров А.М., Сидоров К.В. Оценка эффективности Security Operation Center: проблемы и метрики // Безопасность информационных технологий. 2021. № 4. С. 32-41.</mixed-citation></ref>
			<ref id="R9"><mixed-citation>Скляров И.А., Титов В.Н. Современные тенденции развития киберугроз и методы противодействия // Информационная безопасность. 2022. – Т. 24. № 3. С. 45-56.</mixed-citation></ref>
			<ref id="R10"><mixed-citation>Смирнов Н.Г. Алгоритмы машинного обучения для обнаружения аномалий в сетевом трафике // Известия ЮФУ. Технические науки. 2020. № 3(216). С. 145-159.</mixed-citation></ref>
		</ref-list>
	</back>
</article>			</metadata>
		</record>
	</GetRecord>
</OAI-PMH>
