The Analysis of Firewall Policy Through Machine Learning and Data Mining

dc.authorid0000-0002-3971-2676
dc.authorscopusid36348997600
dc.authorscopusid57194265151
dc.authorwosidOZHAN, Erkan/N-8743-2016
dc.contributor.authorUçar, Erdem
dc.contributor.authorÖzhan, Erkan
dc.date.accessioned2022-05-11T14:15:51Z
dc.date.available2022-05-11T14:15:51Z
dc.date.issued2017
dc.departmentFakülteler, Çorlu Mühendislik Fakültesi, Bilgisayar Mühendisliği Bölümü
dc.description.abstractFirewalls are primary components for ensuring the network and information security. For this purpose, they are deployed in all commercial, governmental and military networks as well as other large-scale networks. The security policies in an institution are implemented as firewall rules. An anomaly in these rules may lead to serious security gaps. When the network is large and policies are complicated, manual cross-check may be insufficient to detect anomalies. In this paper, an automated model based on machine learning and high performance computing methods is proposed for the detection of anomalies in firewall rule repository. To achieve this, firewall logs are analysed and the extracted features are fed to a set of machine learning classification algorithms including Naive Bayes, kNN, Decision Table and HyperPipes. F-measure, which combines precision and recall, is used for performance evaluation. In the experiments, kNN has shown the best performance. Then, a model based on the F-measure distribution was envisaged. 93 firewall rules were analysed via this model. The model anticipated that 6 firewall rules cause anomaly. These problematic rules were checked against the security reports prepared by experts and each of them are verified to be an anomaly. This paper shows that anomalies in firewall rules can be detected by analysing large scale log files automatically with machine learning methods, which enables avoiding security breaches, saving dramatic amount of expert effort and timely intervention.
dc.identifier.doi10.1007/s11277-017-4330-0
dc.identifier.endpage2909
dc.identifier.issn0929-6212
dc.identifier.issn1572-834X
dc.identifier.issue2en_US
dc.identifier.scopus2-s2.0-85019615776
dc.identifier.scopusqualityQ2
dc.identifier.startpage2891
dc.identifier.urihttps://doi.org/10.1007/s11277-017-4330-0
dc.identifier.urihttps://hdl.handle.net/20.500.11776/6100
dc.identifier.volume96
dc.identifier.wosWOS:000408714200065
dc.identifier.wosqualityQ4
dc.indekslendigikaynakWeb of Science
dc.indekslendigikaynakScopus
dc.institutionauthorÖzhan, Erkan
dc.language.isoen
dc.publisherSpringer
dc.relation.ispartofWireless Personal Communications
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanıen_US
dc.rightsinfo:eu-repo/semantics/closedAccess
dc.subjectFirewall logs
dc.subjectMachine learning
dc.subjectFirewall rule
dc.subjectComputer security
dc.subjectClassification
dc.subjectPerformance
dc.subjectAgreement
dc.titleThe Analysis of Firewall Policy Through Machine Learning and Data Mining
dc.typeArticle

Dosyalar

Orijinal paket
Listeleniyor 1 - 1 / 1
Küçük Resim Yok
İsim:
6100.pdf
Boyut:
1.22 MB
Biçim:
Adobe Portable Document Format
Açıklama:
Tam Metin / Full Text