В статье рассмотрено возможное решение задачи межклассового дисбаланса в мультиклассовых системах обнаружения компьютерных атак (IDS) на объектах критической информационной инфраструктуры Российской Федерации (КИИ РФ). Обосновано, что управляемое изменение априорных вероятностей классов позволяет корректировать вклад классов в оптимизационную задачу обнаружения компьютерных атак без разрушения статистической структуры данных. В результате это позволило разработать соответствующую методику генеративной балансировки и успешно ее апробировать на практике защиты объектов КИИ РФ.
< ... >
This article considers a possible solution to the problem of inter-class imbalance in multiclass systems for detecting computer attacks (IDS) at critical information infrastructure (CII) facilities. It is proved that a controlled change in the a priori probabilities of classes makes it possible to adjust the contribution of classes to the optimization task of detecting computer attacks without destroying the statistical data structure. As a result, this made it possible to develop an appropriate generative balancing technique and successfully test it in practice for the protection of CII facilities.
Keywords:
critical information infrastructure, information security, computer attack detection, generative attack detection models, risk management, computer attack detection systems