<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">rst</journal-id>
      <journal-title-group>
        <journal-title xml:lang="ru">Информационно-экономические аспекты стандартизации и технического регулирования</journal-title>
        <trans-title-group xml:lang="en">
          <trans-title>Informatsionno-ekonomicheskiye aspekty standartizatsii i tekhnicheskogo regulirovaniya</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2311-1348</issn>
      <publisher>
        <publisher-name>ФГБУ «Институт стандартизации»</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id custom-type="edn" pub-id-type="custom">UHJPOY</article-id>
      <article-id custom-type="elibrary-id" pub-id-type="custom">82707605</article-id>
      <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Research Article</subject>
        </subj-group>
        <subj-group subj-group-type="section-heading" xml:lang="ru">
          <subject>Информационные системы и процессы</subject>
        </subj-group>
        <subj-group subj-group-type="section-heading" xml:lang="en">
          <subject>information systems and processes</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>ПРИМЕНЕНИЕ МЕТОДОВ МАШИННОГО ОБУЧЕНИЯ ДЛЯ ПРОТИВОДЕЙСТВИЯ DGA-УГРОЗАМ В СИСТЕМЕ УПРАВЛЕНИЯ КАЧЕСТВОМ ИНФОРМАЦИОННОЙ БЕЗОПАСНОСТИ ПРЕДПРИЯТИЙ</article-title>
        <trans-title-group xml:lang="en">
          <trans-title>APPLICATION OF MACHINE LEARNING METHODS TO COUNTER DGA THREATS IN THE ENTERPRISE INFORMATION SECURITY QUALITY MANAGEMENT SYSTEM</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author" corresp="yes">
          <name-alternatives>
            <name name-style="eastern" xml:lang="ru">
              <surname>Королев</surname>
              <given-names>И. А.</given-names>
            </name>
            <name name-style="western" xml:lang="en">
              <surname>Korolev</surname>
              <given-names>I. А.</given-names>
            </name>
          </name-alternatives>
          <bio xml:lang="ru">
            <p>Королев И. А.,  Финансовый университет при Правительстве РФ</p>
            <p>Москва, Россия</p>
          </bio>
          <bio xml:lang="en">
            <p>Korolev I. А., Financial University under the Government of the Russian Federation</p>
            <p>Moscow, Russia</p>
          </bio>
          <xref ref-type="aff" rid="aff-1"/>
        </contrib>
        <contrib contrib-type="author" corresp="yes">
          <name-alternatives>
            <name name-style="eastern" xml:lang="ru">
              <surname>Кобелев</surname>
              <given-names>Е. А.</given-names>
            </name>
            <name name-style="western" xml:lang="en">
              <surname>Kobelev</surname>
              <given-names>E. A.</given-names>
            </name>
          </name-alternatives>
          <bio xml:lang="ru">
            <p>Кобелев Е. А.,  Финансовый университет при Правительстве РФ</p>
            <p>Москва, Россия</p>
          </bio>
          <bio xml:lang="en">
            <p>Kobelev E. A., Financial University under the Government of the Russian Federation</p>
            <p>Moscow, Russia</p>
          </bio>
          <xref ref-type="aff" rid="aff-1"/>
        </contrib>
        <contrib contrib-type="author" corresp="yes">
          <name-alternatives>
            <name name-style="eastern" xml:lang="ru">
              <surname>Булгакова</surname>
              <given-names>Е. В.</given-names>
            </name>
            <name name-style="western" xml:lang="en">
              <surname>Bulgakova</surname>
              <given-names>E. V.</given-names>
            </name>
          </name-alternatives>
          <bio xml:lang="ru">
            <p>Булгакова Е. В., доцент Московский университет МВД России имени В.Я. Кикотя</p>
            <p>Москва, Россия</p>
          </bio>
          <bio xml:lang="en">
            <p>Bulgakova E. V., Associate Professor Moscow University of the Ministry of Internal Affairs of Russia named after V.Ya. Kikot</p>
            <p>Moscow, Russia</p>
          </bio>
          <xref ref-type="aff" rid="aff-1"/>
        </contrib>
        <contrib contrib-type="author" corresp="yes">
          <name-alternatives>
            <name name-style="eastern" xml:lang="ru">
              <surname>Кубанков</surname>
              <given-names>А. Н.</given-names>
            </name>
            <name name-style="western" xml:lang="en">
              <surname>Kubankov</surname>
              <given-names>A. N.</given-names>
            </name>
          </name-alternatives>
          <bio xml:lang="ru">
            <p>Кубанков А. Н., главный научный сотрудник Российский институт стандартизации</p>
            <p>Москва, Россия</p>
          </bio>
          <bio xml:lang="en">
            <p>Kubankov A. N., Chief Researcher Russian Standardization Institute</p>
            <p>Moscow, Russia</p>
          </bio>
          <xref ref-type="aff" rid="aff-1"/>
        </contrib>
      </contrib-group>
      <aff-alternatives id="aff-1">
        <aff xml:lang="ru">
          Финансовый университет при Правительстве РФ
          <country>Россия</country>
        </aff>
        <aff xml:lang="en">
          Financial University under the Government of the Russian Federation
          <country>Russian Federation</country>
        </aff>
      </aff-alternatives>
      <pub-date pub-type="collection">
        <year>2025</year>
      </pub-date>
      <volume>114</volume>
      <issue>85</issue>
      <fpage>46</fpage>
      <lpage>55</lpage>
      <permissions>
        <copyright-statement>Copyright © Королев И. А., Кобелев Е. А., Булгакова Е. В., Кубанков А. Н., 2026</copyright-statement>
        <copyright-year>2026</copyright-year>
        <copyright-holder xml:lang="ru">Королев И. А., Кобелев Е. А., Булгакова Е. В., Кубанков А. Н.</copyright-holder>
        <copyright-holder xml:lang="en">Korolev I. А., Kobelev E. A., Bulgakova E. V., Kubankov A. N.</copyright-holder>
        <license license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple" xml:lang="ru">
          <license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p>
        </license>
      </permissions>
      <self-uri xlink:href="https://iea.gostinfo.ru/article/view/35">https://iea.gostinfo.ru/article/view/35</self-uri>
      <abstract>
        <p>В данной статье определяется понятие технологии DGA, проводится анализ существующих решений для распознавания её применения. Формируется набор моделей машинного обучения, подходящих для определения зараженных доменов, на основе сравнения и обучения которых разрабатывается нейронная сеть для автоматической классификации данных. Описаны этапы подготовки данных, построения бинарного классификатора и оценки его эффективности. Проведено сравнение моделей Random Forest, Gradient Boosting и Logistic Regression по метрикам точности, полноты, F1-меры и ROC AUC. Результаты показали высокую эффективность при комбинировании методов машинного обучения внутри нейронной сети, особенно с использованием Gradient Boosting. Разработанный алгоритм применим в реальном времени и может быть интегрирован в информационные системы для защиты сетевой инфраструктуры.</p>
      </abstract>
      <trans-abstract xml:lang="en">
        <p>This article defines the concept of DGA technology, analyzes existing solutions for recognizing its application, and forms a set of machine learning models suitable for identifying infected domains. Based on the model comparison and training, a neural network is developed for automatic data classification. Methods used: This study focuses on the development and implementation of an algorithm for detecting DGA domains using machine learning models. It describes the binary classifier setup, including feature transformation, model training, and performance interpretation. Results of the study: Three models - Random Forest, Gradient Boosting, and Logistic Regression - were compared. Gradient Boosting showed the best performance (ROC AUC = 0.998). Practical value: The proposed solution is suitable for integration into DNS monitoring systems to enhance information security. The developed algorithm can be applied in real time and integrated into information systems to protect network infrastructure.</p>
      </trans-abstract>
      <kwd-group xml:lang="ru">
        <kwd>DGA</kwd>
        <kwd>ДОМЕН</kwd>
        <kwd>ХОСТ</kwd>
        <kwd>БОТНЕТ</kwd>
        <kwd>МАШИННОЕ ОБУЧЕНИЕ</kwd>
        <kwd>НЕЙРОННАЯ СЕТЬ</kwd>
        <kwd>БИНАРНАЯ КЛАССИФИКАЦИЯ</kwd>
      </kwd-group>
      <kwd-group xml:lang="en">
        <kwd>DGA</kwd>
        <kwd>DOMAIN</kwd>
        <kwd>HOST</kwd>
        <kwd>BOTNET</kwd>
        <kwd>MACHINE LEARNING</kwd>
        <kwd>NEURAL NETWORK</kwd>
        <kwd>BINARY CLASSIFICATION</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <back>
    <ref-list>
      <title>References</title>
      <ref id="cit1">
        <label>1</label>
        <citation-alternatives>
          <mixed-citation xml:lang="ru">Галиахметов Д.Г. Сравнение алгоритмов классификации применительно к задаче обнаружения вредоносных доменных имен // Математические методы в технике и технологиях-ММТТ. 2019. Т. 12. С. 190–194.</mixed-citation>
          <mixed-citation xml:lang="en">Galiakhmetov D.G. Sravnenie algorytmov classifikacii primenitel’no k zadache obnaruzhenya vredonosnykh domennykh
imyon. Matematicheskie metody v tekhnike i tekhnologiyah-MMTT. 2019; 12: 190–194. (In Russ.).</mixed-citation>
        </citation-alternatives>
      </ref>
      <ref id="cit2">
        <label>2</label>
        <citation-alternatives>
          <mixed-citation xml:lang="ru">Berman D.S., et al. A survey of deep learning methods for cyber security // Information. 2019. Т. 10, № 4. С. 122.</mixed-citation>
          <mixed-citation xml:lang="en">Berman D.S., et al. A survey of deep learning methods for cyber security // Information. 2019. Т. 10, № 4. С. 122.</mixed-citation>
        </citation-alternatives>
      </ref>
      <ref id="cit3">
        <label>3</label>
        <citation-alternatives>
          <mixed-citation xml:lang="ru">Бубнов Я.В., Иванов Н.Н. Обнаружение DGA доменов и предотвращение botnet средствами Q-обучения для POMDP //
Доклады Белорусского государственного университета информатики и радиоэлектроники. 2021. Т. 19, № 2. С. 91–99.</mixed-citation>
          <mixed-citation xml:lang="en">Bubnov Y.V., Ivanov N.N. Obnaruzheniye DGA domenov i predotvrascheniye botnet sredstvami Q-obucheniya dlya
POMDP. Doklady Belorusskogo gosudarstvennogo universiteta informatiki i radioelektroniki. 2021; 19(2): 91–99. (In Russ.).</mixed-citation>
        </citation-alternatives>
      </ref>
      <ref id="cit4">
        <label>4</label>
        <citation-alternatives>
          <mixed-citation xml:lang="ru">Antonakakis M., Perdisci R. From throw-away traffic to bots: detecting the rise of DGA-based malware // In Proceedings
of the 21st USENIX Security Symposium. 2012, pp. 491–506.</mixed-citation>
          <mixed-citation xml:lang="en">Antonakakis M., Perdisci R. From throw-away traffic to bots: detecting the rise of DGA-based malware // In Proceedings
of the 21st USENIX Security Symposium. 2012, pp. 491–506.</mixed-citation>
        </citation-alternatives>
      </ref>
      <ref id="cit5">
        <label>5</label>
        <citation-alternatives>
          <mixed-citation xml:lang="ru">Binkley J.R., Singh S. An algorithm for anomaly-based botnet detection // SRUTI. 2006. № 6. pp. 43–48</mixed-citation>
          <mixed-citation xml:lang="en">Binkley J.R., Singh S. An algorithm for anomaly-based botnet detection // SRUTI. 2006. № 6. pp. 43–48</mixed-citation>
        </citation-alternatives>
      </ref>
      <ref id="cit6">
        <label>6</label>
        <citation-alternatives>
          <mixed-citation xml:lang="ru">Li Y., Xiong K. Machine Learning Framework for Domain Generation Algorithm-Based Malware Detection // IEEE Access.
2019. C. 32765–32782.</mixed-citation>
          <mixed-citation xml:lang="en">Li Y., Xiong K. Machine Learning Framework for Domain Generation Algorithm-Based Malware Detection // IEEE Access.
2019. C. 32765–32782.</mixed-citation>
        </citation-alternatives>
      </ref>
      <ref id="cit7">
        <label>7</label>
        <citation-alternatives>
          <mixed-citation xml:lang="ru">Alazab M., Tang M. Deep Learning Applications for Cyber Security. Springer Nature Switzerland, 2019. 246 c.</mixed-citation>
          <mixed-citation xml:lang="en">Alazab M., Tang M. Deep Learning Applications for Cyber Security. Springer Nature Switzerland, 2019. 246 c.</mixed-citation>
        </citation-alternatives>
      </ref>
      <ref id="cit8">
        <label>8</label>
        <citation-alternatives>
          <mixed-citation xml:lang="ru">AsSadhan B., Moura J.M.F., Lapsley D., et al. Detecting botnets using command and control traffic // In 2009 8th IEEE
International Symposium on Network Computing and Applications. IEEE, 2009. С. 156–162.</mixed-citation>
          <mixed-citation xml:lang="en">AsSadhan B., Moura J.M.F., Lapsley D., et al. Detecting botnets using command and control traffic // In 2009 8th IEEE
International Symposium on Network Computing and Applications. IEEE, 2009. С. 156–162.</mixed-citation>
        </citation-alternatives>
      </ref>
      <ref id="cit9">
        <label>9</label>
        <citation-alternatives>
          <mixed-citation xml:lang="ru">Malwarebytes Labs 2019 State of Malware Report. URL: https://resources.malwarebytes.com/files/2019/01/MalwarebytesLabs-2019-State-of Malware- Report-2.pdf (дата обращения:15.05.2025).</mixed-citation>
          <mixed-citation xml:lang="en">Malwarebytes Labs 2019 State of Malware Report. URL: https://resources.malwarebytes.com/files/2019/01/MalwarebytesLabs-2019-State-of Malware- Report-2.pdf (дата обращения:15.05.2025).</mixed-citation>
        </citation-alternatives>
      </ref>
      <ref id="cit10">
        <label>10</label>
        <citation-alternatives>
          <mixed-citation xml:lang="ru">Wang Z., Jia Z., Zhang B. A detection scheme for DGA domain names, based on SVM // In 2018 International Conference
on Mathematics, Modelling, Simulation and Algorithms (MMSA 2018). 2018. C. 257–263.</mixed-citation>
          <mixed-citation xml:lang="en">Wang Z., Jia Z., Zhang B. A detection scheme for DGA domain names, based on SVM // In 2018 International Conference
on Mathematics, Modelling, Simulation and Algorithms (MMSA 2018). 2018. C. 257–263.</mixed-citation>
        </citation-alternatives>
      </ref>
      <ref id="cit11">
        <label>11</label>
        <citation-alternatives>
          <mixed-citation xml:lang="ru">Why Machine Learning Models Degrade in Production [Электронный ресурс]. URL: https://towardsdatascience.com/
why-machine-learning-models-degrade-in-production-d0f2108e9214 (дата обращения: 15.05.2025).</mixed-citation>
          <mixed-citation xml:lang="en">Why Machine Learning Models Degrade in Production. URL: https://towardsdatascience.com/
why-machine-learning-models-degrade-in-production-d0f2108e9214 (дата обращения: 15.05.2025).</mixed-citation>
        </citation-alternatives>
      </ref>
    </ref-list>
    <fn-group>
      <fn fn-type="conflict">
        <p xml:lang="ru">Конфликт интересов. Авторы заявляют об отсутствии конфликта интересов.</p>
        <p xml:lang="en">The authors declare that there are no conflicts of interest present.</p>
      </fn>
    </fn-group>
  </back>
</article>
