| dc.contributor.author | Підлісна, А. О. | uk |
| dc.contributor.author | Pidlisna, A. O. | en |
| dc.date.accessioned | 2026-09-03T10:39:58Z | |
| dc.date.available | 2026-09-03T10:39:58Z | |
| dc.date.issued | 2026 | |
| dc.identifier.citation | Підлісна А. О. Застосування методів машинного навчання для поведінкового виявлення прихованих процесів // Матеріали Міжнародної науково-практичної інтернет-конференції «Молодь в науці: дослідження, проблеми, перспективи (МН-2026)», м. Вінниця, 22-26 червня 2026 р. Електрон. текст. дані. 2026. URI: https://conferences.vntu.edu.ua/index.php/mn/mn2026/paper/view/27926. | uk |
| dc.identifier.uri | https://ir.lib.vntu.edu.ua/handle/123456789/53343 | |
| dc.description.abstract | Досліджено проблему виявлення прихованих процесів операційної системи, які можуть бути пов’язані з діяльністю шкідливого програмного забезпечення класу руткіт. Такі програми характеризуються здатністю маскувати власну присутність у системі, змінювати поведінку процесів та приховувати системні ресурси. | uk |
| dc.description.abstract | This study examines the problem of detecting hidden operating system processes that may be associated with the activity of rootkit-class malware. Such programs are characterized by their ability to mask their presence in the system, alter process behavior, and conceal system resources. Traditional signature-based protection methods are insufficiently effective for detecting new or modified malware samples. The use of a behavioral approach to anomaly detection based on the Isolation Forest algorithm is proposed. The system architecture is discussed, which includes a module for collecting operating system process telemetry, a machine learning module for assessing the abnormality of process behavior, and an analytical module for interpreting the results. It is shown that the use of the Isolation Forest algorithm allows for the effective detection of atypical process behavior without the use of signature databases. | en |
| dc.language.iso | uk_UA | uk_UA |
| dc.publisher | ВНТУ | uk |
| dc.relation.ispartof | Матеріали Міжнародної науково-практичної інтернет-конференції «Молодь в науці: дослідження, проблеми, перспективи (МН-2026)», м. Вінниця, 22-26 червня 2026 р. | uk |
| dc.relation.uri | https://conferences.vntu.edu.ua/index.php/mn/mn2026/paper/view/27926 | |
| dc.subject | інформаційна безпека | uk |
| dc.subject | руткіт | uk |
| dc.subject | машинне навчання | uk |
| dc.subject | виявлення аномалій | uk |
| dc.subject | Isolation Forest | en |
| dc.subject | поведінковий аналіз | uk |
| dc.subject | information security | en |
| dc.subject | rootkit | en |
| dc.subject | anomaly detection | en |
| dc.subject | machine learning | en |
| dc.subject | Isolation Forest | en |
| dc.subject | cybersecurity | en |
| dc.title | Застосування методів машинного навчання для поведінкового виявлення прихованих процесів | uk |
| dc.type | Thesis | |
| dc.identifier.udc | 004.056.53 | |
| dc.relation.references | Руткіт | ESET Glossary [Електронний ресурс] – Режим доступу до ресурсу: https://help.eset.com/glossary/uk-UA/rootkits.html | uk |
| dc.relation.references | Zero day: що таке вразливість нульового дня? [Електронний ресурс] – Режим доступу до ресурсу: https://itedu.center/ua/blog/articles/zero-day/ | uk |
| dc.relation.references | What is Isolation Forest [Електронний ресурс] – Режим доступу до ресурсу: https://www.geeksforgeeks.org/machine-learning/what-is-isolation-forest/ | uk |
| dc.relation.references | Що таке велика мовна модель? [Електронний ресурс] – Режим доступу до ресурсу: https://www.sap.com/ukraine/resources/what-is-large-language-model | uk |
| dc.relation.references | Інтерфейс прикладного программування (API) [Електронний ресурс] – Режим доступу до ресурсу: https://data.rada.gov.ua/open/main/api | uk |