SELECTION OF DATA IN SYSTEMS AND TOOLS FOR COMPUTER ATTACK DEFENSE TAKING INTO ACCOUNT THE HISTORICAL ASPECT OF THEIR USE
DOI:
https://doi.org/10.31891/csit-2026-3-19Keywords:
corporate networks, computer attacks, data optimization, historical data, data selection, information redundancy, self-learning, depth of horizon for dataAbstract
The article considers the problem of data selection for systems and means of countering computer attacks in corporate networks in the context of constant growth of information volumes, high dynamism of information flows and limited computing resources. It is shown that the effectiveness of the functioning of modern systems for countering computer attacks largely depends not only on the quality of threat detection algorithms, but also on the timely provision of decision-making processes with relevant, relevant and most valuable data. It is substantiated that the use of the entire accumulated array of information leads to an increase in the time of its processing, an increase in information redundancy and a decrease in the efficiency of response to computer attacks, while an excessive reduction in data volumes can lead to the loss of important information necessary to identify complex or recurring threats.
A method of data selection for systems and means of countering computer attacks is proposed, which is based on the complex use of the depth of the analysis horizon, self-learning mechanisms and previous experience of the system functioning. A feature of the method is the integrated evaluation of data according to a set of criteria, which allows taking into account their current relevance, predicted usefulness in different time horizons, the results of previous use, and the ability to adaptively change the selection parameters in accordance with changes in the information environment. In contrast to existing approaches, the proposed method provides an intelligent choice of data, taking into account the relationship between the historical effectiveness of information, its prospective significance and the results of the system's self-learning.
To implement the proposed method, an architecture of the memory subsystem of systems and means of countering computer attacks has been developed, which provides accumulation, classification, optimization, modification and adaptive selection of data in accordance with the needs of means of different levels. The proposed architecture allows maintaining a balance between completeness, duration of storage and relevance of information, reducing information redundancy, reducing access time to critical data and increasing the efficiency of information support of decision-making processes.
The practical significance of the results obtained lies in the possibility of using the proposed method in the development of intelligent memory subsystems of systems and means of countering computer attacks in corporate networks, which provides an increase in the accuracy of data selection, acceleration of information analysis processes, improvement of the adaptability of systems to changes in operating conditions and increase in the efficiency of detection and neutralization of computer attacks.
Prospects for further research are the development of a mathematical model for adaptive adjustment of the weights of the data selection method, the improvement of self-learning mechanisms using modern methods of artificial intelligence, and the experimental assessment of the effectiveness of the proposed method in real corporate networks under various scenarios of computer attacks.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Vadym PAIUK, Antonina KASHTALIAN

This work is licensed under a Creative Commons Attribution 4.0 International License.
