Method for detecting security violations (using the example of ransomware) in the Astra Linux OS using machine learning
News
Method for detecting security violations (using the example of ransomware) in the Astra Linux OS using machine learning
Abstract
This paper proposes a method for detecting security violations in the Astra Linux OS, leveraging machine learning (ML) and accounting for the specific features of its security tools, primarily the Mandatory Integrity Control (MIC) mechanism. The method focuses on ransomware activity detection and is based on a granular analysis of system call event streams. Data collection and processing, including MIC-specific parameters, are performed by an author-developed monitoring system. The model uses a comprehensive input dataset consisting of system call types, their arguments, and MIC-specific attributes, such as integrity levels for processes, files, and directories, as well as their associated security flags. The synthesized classifier, based on a Bidirectional Gated Recurrent Unit (BiGRU) neural network, demonstrated high efficiency in identifying destructive patterns, including scenarios of security violation attempts accompanied by multiple access denials. Practical evaluation of the monitoring system confirmed its capability for rapid ransomware detection at early stages of data compromise, while maintaining a minimal false positive rate. The research results prove the potential of applying ML methods to automate monitoring processes and enhance information security in secure domestic operating systems.
Keywords
Edition
Proceedings of the Institute for System Programming, vol. 38, issue 5, 2026, pp. 51-72
ISSN 2220-6426 (Online), ISSN 2079-8156 (Print).
DOI: 10.15514/ISPRAS-2026-38(5)-4
For citation
Full text of the paper in pdf (in Russian)
Back to the contents of the volume