<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD with OASIS Tables with MathML3 v1.4 20241031//EN" "https://jats.nlm.nih.gov/archiving/1.4/JATS-archive-oasis-article1-4-mathml3.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" dtd-version="1.4" article-type="research-article" xml:lang="en"><front><journal-meta><journal-title-group><journal-title xml:lang="ru">Цифровое право</journal-title></journal-title-group><issn publication-format="print">3034-4271</issn><issn publication-format="electronic">3034-4271</issn></journal-meta><article-meta><article-id pub-id-type="doi">10.24412/3034-4271-2026-3-53-58</article-id><article-categories><subj-group><subject>Other</subject></subj-group></article-categories><title-group><article-title xml:lang="ru">ПРЕИМУЩЕСТВА РЕШЕНИЙ EDR НА БАЗЕ ИСКУССТВЕННОГО ИНТЕЛЛЕКТА В СВЕТЕ МОДЕЛИ УГРОЗ</article-title><trans-title-group xml:lang="en"><trans-title>ATT&amp;CK;;;;;. ADVANTAGES OF EDR CLASS SOLUTIONS BASED ON ARTIFICIAL INTELLIGENCE TECHNOLOGIES IN THE CONTEXT OF THE MITRE THREAT MODEL OF ATT&amp;CK</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author"><name-alternatives><name xml:lang="ru"><surname>Зуфарова</surname><given-names>Анна Сергеевна</given-names></name><name xml:lang="en"><surname>Zufarova</surname><given-names>Anna Sergeevna</given-names></name></name-alternatives><xref ref-type="aff" rid="aff1"/><xref ref-type="aff" rid="aff2"/><email>006694@togudv.ru</email></contrib><contrib contrib-type="author"><name-alternatives><name xml:lang="ru"><surname>Верхозина</surname><given-names>Анастасия Федоровна</given-names></name><name xml:lang="en"><surname>Verhozina</surname><given-names>Anastasia Fedorovna</given-names></name></name-alternatives><xref ref-type="aff" rid="aff3"/><xref ref-type="aff" rid="aff4"/><email>2018101805@togudv.ru</email></contrib><aff-alternatives id="aff1"><aff><institution xml:lang="en">Senior Lecturer, Pacific State University</institution></aff></aff-alternatives><aff-alternatives id="aff2"><aff><institution xml:lang="ru">старший преподаватель, Тихоокеанский государственный университет</institution></aff></aff-alternatives><aff-alternatives id="aff3"><aff><institution xml:lang="en">Student, Pacific State University</institution></aff></aff-alternatives><aff-alternatives id="aff4"><aff><institution xml:lang="ru">студент, Тихоокеанский государственный университет</institution></aff></aff-alternatives></contrib-group><pub-date pub-type="epub" iso-8601-date="2026-01-01"><day>01</day><month>01</month><year>2026</year></pub-date><issue>3</issue><fpage>53</fpage><lpage>58</lpage><history><date date-type="received" iso-8601-date="2026-05-28"><day>28</day><month>05</month><year>2026</year></date><date date-type="accepted" iso-8601-date="2026-06-30"><day>30</day><month>06</month><year>2026</year></date></history><abstract xml:lang="ru"><p>В современном мире атаки в сети становятся всесложнее, и важной частью защиты является не только обнаружение угроз, но и их прогнозирование. Статья посвящена исследованию преимуществ решений класса Endpoint Detection and Response (EDR), построенных на технологиях искусственного интеллекта (ИИ), применительно к модели угроз MITRE ATT&amp;CK. Сегодня современные подходы к обеспечению информационной безопасности требуют новых подходов к обнаружению и предотвращению угроз. Традиционные защитные механизмы оказываются недостаточно эффективными против продвинутых атак, направленных на критически важные ресурсы предприятий. Искусственный интеллект в составе решений EDRспособен существенно повысить уровень защиты благодаря способности выявлять нестандартные и ранее невиданные угрозы, минимизируя количество ложных срабатываний. Описаны основные преимущества решений EDR на основе ИИ, среди которых особое внимание уделено автоматизированному выявлению сложных угроз, уменьшению количества ложных тревог, проведению глубокого поведенческого анализа и улучшению прогнозирования возможных сценариев развития инцидентов. Рассматриваются ключевые компоненты модели MITRE ATT&amp;CK, позволяющие оценивать эффективность различных этапов атаки и предлагать действенные меры защиты. Примеры конкретных техник и методик отражают актуальные аспекты современных угроз, подчеркивая необходимость интеграции интеллектуальных компонентов в процесс выявления вторжений. Заключение подчеркивает важность комплексного подхода к информационной безопасности, основанного на применении передовых технологий, позволяющих своевременно выявлять и устранять любые проявления киберпреступности. Таким образом, статья демонстрирует практическую значимость внедрения решений EDR с искусственным интеллектом для устойчивого роста устойчивости бизнеса в цифровую эпоху.</p></abstract><abstract xml:lang="en" abstract-type="summary"><p>In today’s world, online attacks are becoming more complex, and an important part of protection is notonly detecting threats, butalso predicting them. № 3 ( - ) 2026. 54 The article is devoted to the study of the advantages of Endpoint Detection and Response (EDR) class solutions based on artificial intelligence (AI) technologies in relation to the MITRE ATT&amp;CKthreat model. Today, modern approaches to information security require newapproaches to threat detection and prevention. Traditional defense mechanisms are proving insufficiently effective against advanced attacks targeting critical enterprise resources. Artificial intelligence in EDRsolutions is able to significantly increase the level of protection due to the ability to identify non-standard and previously unseen threats, minimizing the number of false positives. The main advantages of AI-based EDRsolutions are described, among which special attention is paid to the automated identification of complex threats, reducing the number of false alarms, conducting in-depth behavioral analysis and improving the prediction of possible incident scenarios. The keycomponents of the MITRE ATT&amp;CKmodel are considered, which make itpossible to evaluate the effectiveness of various stages of an attack and propose effective protection measures. Examples of specific techniques and techniques reflect current aspects of modern threats, emphasizing the need to integrate intelligent components into the intrusion detection process. The conclusion underlines the importance of an integrated approach to information security based on the use of advanced technologies that allow timely detection and elimination of anymanifestations of cybercrime. Thus, the article demonstrates the practical importance of implementing EDRsolutions with artificial intelligence for the sustainable growth of business sustainability in the digital age.</p></abstract><kwd-group xml:lang="ru"><kwd>машинное обучение</kwd><kwd>искусственный интеллект (ИИ)</kwd><kwd>кибератака</kwd><kwd>угроза</kwd><kwd>защита</kwd><kwd>прогнозирование угроз</kwd></kwd-group><kwd-group xml:lang="en"><kwd>Endpoint Detection and Response (EDR)</kwd><kwd>artificial intelligence (AI)</kwd><kwd>MITRE ATT&amp;CK</kwd><kwd>cyberattack</kwd><kwd>threat</kwd><kwd>protection</kwd><kwd>machine learning</kwd><kwd>threat forecasting</kwd></kwd-group></article-meta></front><back><ref-list><ref id="ref1"><mixed-citation publication-type="other" xml:lang="en">Reiber, J. MITRE ATT&amp;CK for dummies: AttackIQ Special Edition / J. Reiber, C. Wright. — 2021. — 42 p.</mixed-citation><mixed-citation publication-type="other" xml:lang="ru">Reiber, J. MITRE ATT&amp;CK for dummies: AttackIQ Special Edition / J. Reiber, C. Wright. — 2021. — 42 p.</mixed-citation></ref><ref id="ref2"><mixed-citation publication-type="other" xml:lang="en">Pashayev, F. G. Development of software and hardware tools to protect technological processes from cyber threats / F. G. Pashayev, D. I. Zeynalov, G. T. Nadzhafov // Problems of information security. Computer systems. — 2024. — No. 2 (59). — P. 104–116.</mixed-citation><mixed-citation publication-type="other" xml:lang="ru">Пашаев Ф. Г. Разработка программно-технических средств защиты технологических процессов от киберугроз / Ф. Г. Пашаев, Д. И. Зейналов, Г. Т. Наджафов // Проблемы информационной безопасности. Компьютерные системы. — 2024. — № 2 (59). — С. 104–116.</mixed-citation></ref><ref id="ref3"><mixed-citation publication-type="other" xml:lang="en">Krivchun, N. A. Cyberattacks and methods for their prevention in information systems / N. A. Krivchun, D. V. Solodovnikov, A. K. Sokolov, et al. // Discussion. — 2024. — No. 7 (128). — P. 120–126.</mixed-citation><mixed-citation publication-type="other" xml:lang="ru">Кривчун Н. А. Кибератаки и методы их предотвращения в информационных системах / Н. А. Кривчун, Д. В. Солодовников, А. К. Соколов и др. // Дискуссия. — 2024. — № 7 (128). — С. 120–126.</mixed-citation></ref><ref id="ref4"><mixed-citation publication-type="other" xml:lang="en">Belyaeva O. N. The meaning and role of cybersecurity in the modern world / O. N. Belyaeva, K. M. Malysheva // Reports Scientific Society. - 2024. - No. 2 (46). — P. 5–8.</mixed-citation><mixed-citation publication-type="other" xml:lang="ru">Беляева О. Н. Значение и роль кибербезопасности в современном мире / О. Н. Беляева, К. М. Малышева // Reports Scientific Society. — 2024. — № 2 (46). — С. 5–8.</mixed-citation></ref><ref id="ref5"><mixed-citation publication-type="other" xml:lang="en">Gorda M. D. Model for investigating cybercrimes / M. D. Gorda, A. A. Chechulin // Informatization and communication. - 2023. - No. 3. - P. 92–97.</mixed-citation><mixed-citation publication-type="other" xml:lang="ru">Горда М. Д. Модель расследования киберпреступлений / М. Д. Горда, А. А. Чечулин // Информатизация и связь. — 2023. — № 3. — С. 92–97.</mixed-citation></ref><ref id="ref6"><mixed-citation publication-type="other" xml:lang="en">Vasiliev V.I. Artificial intelligence: history in faces / V.I. Vasiliev. — 2nd ed., add. — Moscow: Mechanical Engineering, 2015. — 111 p.</mixed-citation><mixed-citation publication-type="other" xml:lang="ru">Васильев В. И. Искусственный интеллект: история в лицах / В. И. Васильев. — 2-е изд., доп. — Москва: Машиностроение, 2015. — 111 с.</mixed-citation></ref><ref id="ref7"><mixed-citation publication-type="other" xml:lang="en">Gibadullin A. A. Myths and legends of artificial intelligence / A. A. Gibadullin // Academic journalism. — 2024. — No. 1–1. — P. 553–556.</mixed-citation><mixed-citation publication-type="other" xml:lang="ru">Гибадуллин А. А. Мифы и легенды искусственного интеллекта / А. А. Гибадуллин // Академическая публицистика. — 2024. — № 1–1. — С. 553–556.</mixed-citation></ref><ref id="ref8"><mixed-citation publication-type="other" xml:lang="en">Zufarova A. S. The Path of Artificial Intelligence: From a Computer Game to Means of ЦИФРОВОЕ ПРАВО № 3 (ИЮЛЬ - СЕНТЯБРЬ) 2026 г. 58 Cognitive Development of Students ChatGPT / A. S. Zufarova, A. V. Samoilov, M. R. Mulyavka, et al. // Education Management: Theory and Practice. — 2023. — No. 7 (65). — P. 76–90.</mixed-citation><mixed-citation publication-type="other" xml:lang="ru">Зуфарова А. С. Путь искусственного интеллекта: от компьютерной игры до средств познавательного развития учащихся ChatGPT / А. С. Зуфарова, А. В. Самойлов, М. Р. Мулявка и др. // Управление образованием: теория и практика. — 2023. — № 7 (65). — С. 76–90.</mixed-citation></ref><ref id="ref9"><mixed-citation publication-type="other" xml:lang="en">Shevchenko A. V. Protecting Artificial Intelligence and Explainable Artificial Intelligence from Adversarial Attacks / A. V. Shevchenko, A. N. Averkin // Soft Measurements and Computations. — 2024. — Vol. 85, No. 12. — P. 103–113.</mixed-citation><mixed-citation publication-type="other" xml:lang="ru">Шевченко А. В. Защита искусственного интеллекта и объяснимого искусственного интеллекта от состязательных атак / А. В. Шевченко, А. Н. Аверкин // Мягкие измерения и вычисления. — 2024. — Т. 85, № 12. — С. 103–113.</mixed-citation></ref><ref id="ref10"><mixed-citation publication-type="other" xml:lang="en">Pikalov P. A. Cyberfraud Using Artificial Intelligence / P. A. Pikalov // Current Issues in Combating Crime. - 2024. - No. 2. - Pp. 56-59.</mixed-citation><mixed-citation publication-type="other" xml:lang="ru">Пикалов П. А. Кибермошенничество с использованием искусственного интеллекта / П. А. Пикалов // Актуальные вопросы борьбы с преступлениями. — 2024. — № 2. — С. 56–59.</mixed-citation></ref><ref id="ref11"><mixed-citation publication-type="other" xml:lang="en">Alanurova O. Digital Security and Innovative Approaches to Data Protection / O. Alanurova, J. Shokhradova // Symbol of Science: International Scientific Journal. - 2024. - Vol. 2, No. 12-1. - Pp. 67-68.</mixed-citation><mixed-citation publication-type="other" xml:lang="ru">Аланурова О. Цифровая безопасность и инновационные подходы к защите данных / О. Аланурова, Дж. Шохрадова // Символ науки: международный научный журнал. — 2024. — Т. 2, № 12–1. — С. 67–68.</mixed-citation></ref><ref id="ref12"><mixed-citation publication-type="other" xml:lang="en">Malenkov M. G. Defense against AI-Using Attacks with AI / M. G. Malenkov // Innovations. Science. Education. - 2021. - Vol. 2, No. 44. - Pp. 49-53.</mixed-citation><mixed-citation publication-type="other" xml:lang="ru">Маленков М. Г. Защита от атак с использованием ИИ с помощью ИИ / М. Г. Маленков // Инновации. Наука. Образование. — 2021. — Т. 2, № 44. — С. 49–53.</mixed-citation></ref></ref-list></back></article>
