<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">kaspscj</journal-id><journal-title-group><journal-title xml:lang="ru">Каспийский научный журнал</journal-title><trans-title-group xml:lang="en"><trans-title>Caspian scientific journal</trans-title></trans-title-group></journal-title-group><publisher><publisher-name>Caspian Institute of Sea and River Transport named after General-Admiral F. M. Apraksin – branch of Volga State University of Water Transport</publisher-name></publisher></journal-meta><article-meta><article-id custom-type="elpub" pub-id-type="custom">kaspscj-43</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>Информационные технологии</subject></subj-group></article-categories><title-group><article-title>Сравнение рекуррентной и сверточной нейросетей для анализа и прогнозирования угроз кибербезопасности</article-title><trans-title-group xml:lang="en"><trans-title>Comparison of recurrent and convolutional neural networks for analyzing and predicting cyber security threats</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Петров</surname><given-names>Иван Андреевич</given-names></name><name name-style="western" xml:lang="en"><surname>Petrov</surname><given-names>Ivan Andreevich</given-names></name></name-alternatives><bio xml:lang="ru"><p>аспирант и ассистент кафедры информационной безопасности</p></bio><bio xml:lang="en"><p>Postgraduate and Assistant at the Department of Information Security </p></bio><email xlink:type="simple">iapetrov@fa.ru</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Финансовый университет при Правительстве РФ</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Financial University under The Government of Russian Federation</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2024</year></pub-date><pub-date pub-type="epub"><day>30</day><month>12</month><year>2024</year></pub-date><volume>0</volume><issue>4(5)</issue><issue-title>Каспийский научный журнал №4(5) - 2024</issue-title><fpage>46</fpage><lpage>56</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Петров И.А., 2025</copyright-statement><copyright-year>2025</copyright-year><copyright-holder xml:lang="ru">Петров И.А.</copyright-holder><copyright-holder xml:lang="en">Petrov I.A.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://www.kaspianjournal.ru/jour/article/view/43">https://www.kaspianjournal.ru/jour/article/view/43</self-uri><abstract><p>Кибератаки становятся все более сложными и изощренными, что требует разработки новых методов анализа и предсказания угроз. Традиционные методы, такие как сигнатурный анализ и статистические модели, часто оказываются неэффективными против современных угроз. Рекуррентные нейронные сети (RNN) представляют собой перспективный инструмент для решения этой задачи благодаря своей способности обрабатывать временные ряды данных и выявлять сложные закономерности. В данной статье рассматриваются возможности применения рекуррентных и сверточных для анализа и прогнозирования киберугроз, а также приводятся примеры успешных реализаций этих моделей в области кибербезопасности. Для обучения модели была использована база данных, состоящая из более чем 125 тысяч кибератак. Целью данной статьи является создание и исследование возможностей применения рекуррентных и сверточных нейронных сетей в контексте анализа и прогнозирования угроз информационной безопасности. Научная новизна данной статьи заключается в сравнении результатов работы различных нейросетей с разными параметрами. Методы исследований: системный анализ существующих методов машинного обучения, теоретическая формализация, проведение эксперимента.</p></abstract><trans-abstract xml:lang="en"><p>Cyberattacks are becoming increasingly complex and sophisticated, which requires the development of new methods for analyzing and predicting threats. Traditional methods such as signature analysis and statistical models are often ineffective against advanced threats. Recurrent neural networks (RNN) represent a promising tool for this task due to their ability to process time-series data and identify complex patterns. Today's information systems face an ever-increasing number of cyber threats. These threats range from simple phishing attacks to sophisticated campaigns carried out by organized criminal groups. Securing information resources requires the development of effective methods to analyze and anticipate potential threats. Current approaches include the use of machine learning and artificial intelligence (AI). In order to use AI as part of information security challenges, particularly cybersecurity, it is necessary to understand which algorithm is best suited for analyzing, predicting and detecting cyber threats in modern and complex information systems. This paper discusses the potential applications of RNN for analyzing and predicting cyber threats and provides examples of successful implementations of these models in the cybersecurity domain. A database consisting of 40000 cyberattacks was used to train the model. The purpose of this paper is to investigate the potential applications of recurrent neural networks in the context of analyzing and predicting information security threats. The scientific novelty of this article lies in the comparison of the results of different neural networks. Research methods: system analysis of existing machine learning methods, theoretical formalization, experimentation.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>искусственный интеллект</kwd><kwd>машинное обучение</kwd><kwd>кибербезопасность</kwd><kwd>информационная безопасность</kwd><kwd>рекуррентная нейросеть</kwd><kwd>сверточная нейросеть</kwd></kwd-group><kwd-group xml:lang="en"><kwd>Artificial intelligence</kwd><kwd>machine learning</kwd><kwd>cybersecurity</kwd><kwd>information security</kwd><kwd>recurrent neural network</kwd><kwd>convolutional neural network</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Павлычев, А. В. Использование алгоритма машинного обучения Random Forest для выявления сложных компьютерных инцидентов / А. В. Павлычев, М. И. Стародубов, А. Д. Галимов // Вопросы кибербезопасности. – 2022. – № 5(51). – С. 74-81. – DOI 10.21681/2311-3456-2022-5-74-81. – EDN ZAPFHO.</mixed-citation><mixed-citation xml:lang="en">Pavlychev, A. V. Using the Random Forest machine learning algorithm to identify complex computer incidents / A. V. Pavlychev, M. I. Starodubov, A. D. Galimov // Voprosy cybersecurity. - 2022. - № 5(51). - С. 74-81. - DOI 10.21681/2311-3456-2022-5-74-81. - EDN ZAPFHO.</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Qin Y., Wei J., Yang W. Deep Learning Based Anomaly Detection Scheme in Software-Defined Networking // 20th Asia-Pacific Network Operations and Management Symposium (APNOMS), IEEE, 2019. P. 1-4</mixed-citation><mixed-citation xml:lang="en">Qin Y., Wei J., Yang W. Deep Learning Based Anomaly Detection Scheme in Software-Defined Networking // 20th Asia-Pacific Network Operations and Management Symposium (APNOMS), IEEE, 2019. P. 1-4</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Karbab E.B., Debbabi M., Derhab A., Mouheb D. MalDozer: Automatic Framework for Android Malware Detection Using Deep Learning// Digital Investigation. 2018. Vol. 24. P. S48-S59.</mixed-citation><mixed-citation xml:lang="en">Karbab E.B., Debbabi M., Derhab A., Mouheb D. MalDozer: Automatic Framework for Android Malware Detection Using Deep Learning// Digital Investigation. 2018. Vol. 24. P. S48-S59.</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Wang P., Ye F., Chen X., Qian Y. DataNet: Deep Learning Based Encrypted Network Traffic Classification in SDN Home Gateway // IEEE Access, 2018. Vol. 6. P. 55380-55391</mixed-citation><mixed-citation xml:lang="en">Wang P., Ye F., Chen X., Qian Y. DataNet: Deep Learning Based Encrypted Network Traffic Classification in SDN Home Gateway // IEEE Access, 2018. Vol. 6. P. 55380-55391</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Гайфулина, Д. А. Применение методов глубокого обучения в задачах кибербезопасности. Часть 2 / Д. А. Гайфулина, И. В. Котенко // Вопросы кибербезопасности. – 2020. – № 4(38). – С. 11-21. – DOI 10.21681/2311-3456-2020-04-11-21. – EDN MEZKLH.</mixed-citation><mixed-citation xml:lang="en">Gaifulina, D. A. Application of deep learning methods in cybersecurity tasks. Part 2 / D. A. Gaifulina, I. V. Kotenko // Voprosy cybersecurity. - 2020. - № 4(38). - С. 11-21. - DOI 10.21681/2311-3456-2020-04-11-21. - EDN MEZKLH.</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Yin C., Zhu Y., Fei J., He X. A Deep Learning Approach for Intrusion Detection Using Recurrent Neural Networks // IEEE Access, 2017. Vol. 5. P. 21954-21961.</mixed-citation><mixed-citation xml:lang="en">Yin C., Zhu Y., Fei J., He X. A Deep Learning Approach for Intrusion Detection Using Recurrent Neural Networks // IEEE Access, 2017. Vol. 5. P. 21954-21961.</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Zhu M., Ye K., Wang Y., Xu C.Z. A Deep Learning Approach for Network Anomaly Detection Based on AMF-LSTM // IFIP International Conference on Network and Parallel Computing Springer, Cham, 2018. P. 137-141.</mixed-citation><mixed-citation xml:lang="en">Zhu M., Ye K., Wang Y., Xu C.Z. A Deep Learning Approach for Network Anomaly Detection Based on AMF-LSTM // IFIP International Conference on Network and Parallel Computing Springer, Cham, 2018. P. 137-141.</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Manavi M., Zhang Y. A New Intrusion Detection System Based on Gated Recurrent Unit (GRU) and Genetic Algorithm // International Conference on Security, Privacy and Anonymity in Computation, Communication and Storage, Springer, Cham, 2019. P. 368-383.</mixed-citation><mixed-citation xml:lang="en">Manavi M., Zhang Y. A New Intrusion Detection System Based on Gated Recurrent Unit (GRU) and Genetic Algorithm // International Conference on Security, Privacy and Anonymity in Computation, Communication and Storage, Springer, Cham, 2019. P. 368-383.</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Shibahara T., Yagi T., Akiyama M., Chiba D., Hato K. Efficient Dynamic Malware Analysis for Collecting HTTP Requests using Deep Learning IEICE Transactions on Information and Systems, 2019. Vol. 102. No. 4. P. 725-736.</mixed-citation><mixed-citation xml:lang="en">Shibahara T., Yagi T., Akiyama M., Chiba D., Hato K. Efficient Dynamic Malware Analysis for Collecting HTTP Requests using Deep Learning IEICE Transactions on Information and Systems, 2019. Vol. 102. No. 4. P. 725-736.</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">VirusTotal. Available at: https://virustotal.com (accessed November 06, 2024).</mixed-citation><mixed-citation xml:lang="en">VirusTotal. Available at: https://virustotal.com (accessed November 06, 2024).</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Jain G., Sharma M., Agarwal B. Optimizing semantic LSTM for spam detection // International Journal of Information Technology. 2019. Vol. 11. No. 2. P. 239-250.</mixed-citation><mixed-citation xml:lang="en">Jain G., Sharma M., Agarwal B. Optimizing semantic LSTM for spam detection // International Journal of Information Technology. 2019. Vol. 11. No. 2. P. 239-250.</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Зуев, В. Н. Обнаружение аномалий сетевого трафика методом глубокого обучения / В. Н. Зуев // Программные продукты и системы. – 2021. – № 1. – С. 91-97. – DOI 10.15827/0236-235X.133.091-097. – EDN YCVLDE.</mixed-citation><mixed-citation xml:lang="en">Zuev, V. N. Detection of the network traffic anomalies by the deep learning method / V. N. Zuev // Software Products and Systems. - 2021. - № 1. - С. 91-97. - DOI 10.15827/0236-235X.133.091-097. - EDN YCVLDE.</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
