ORGANIZATION OF THE INTERACTION OF DISTRIBUTED MULTILEVEL COMPONENTS MALWARE DETECTION SYSTEMS BASED ON THEIR SECURITY LEVELS
Abstract
The work out the developed method of interaction of components of distributed multi-level system of detection of malicious software on the basis of decentralized and self-organized architecture in local networks. Its feature is the synthesis of its requirements of distribution, decentralization, multilevel and self-organization. This allows you to use it autonomously. The basis of the distributed distributed system is its structural components, which are represented by autonomous software modules that can be in different states. The transition between module states is based on a defined set of transitions. Interaction and communication between autonomous software modules is based on their presence in certain states during operation and is determined by the rules of the developed method. Distributed system is a responsive system that will monitor selected events. Each program module places a resident mechanism, the motive mechanisms for the transition between states, the transitions between which are given by subsets of transitions, the data for which will be formed using the technologies of artificial intelligence. In addition, the feature of the components of the system is the same organization, which allows the exchange of knowledge in the middle of the system, which, unlike the known systems, allows us to use the knowledge gained by separate parts of our system in other parts. The developed system allows to fill it with subsystems of detection of various types of malicious software in local area networks. The method of interaction of components of a distributed multilevel detection system of malicious software provides a procedure for communication between parts of the system and the exchange of knowledge between them. It will be used to organize the interaction of system components and maintain its integrity. In order to solve the problem of the direct detection of malicious software in local area networks, methods will be applied that will be applied to the lower level of the system, which will include the architectural features of the distributed system and the technology of detecting the malicious software-based software. However, the developed method of interaction includes the ability to determine the state of a distributed multi-level system, depending on the states of individual modules, and on its basis, in accordance with it will be decided on the further operation of the system as a whole and its configuration. The method regulates the actions of the part of the system that relates to the bundling software of the distributed system. The conducted experiments on the use of the developed distributed system showed the possibility of attracting to the detection of the malicious software of computing power of 78 # 24 (2018) other hosts of the local network. The obtained results of experiments show an increase in the reliability of the detection of malicious software.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.