首页> 外文会议>Communications, Internet, and Information Technology >INTELLIGENT INFRASTRUCTURE SECURITY ARCHITECTURE, RESPONSE AND MANAGEMENT SYSTEM USING FIREWALLS AND ADAPTIVE POLICIES
【24h】

INTELLIGENT INFRASTRUCTURE SECURITY ARCHITECTURE, RESPONSE AND MANAGEMENT SYSTEM USING FIREWALLS AND ADAPTIVE POLICIES

机译:使用防火墙和自适应策略的智能基础设施安全体系结构,响应和管理系统

获取原文

摘要

Intrusion Detection Systems (IDS) have major limitations in their analysis of network and application traffic. The high percentage of alerts generated by such systems and the level of false positives among the major problems. We present intelligent strategies for reduction of false positives and infrastructure protection involving a novel approach using adaptive responses from firewall rulesets in a novel "network quarantine channels" (NQC), using firewall architectures. The focus of this paper is the combination of firewall architecture and rules to respond to suspicious hosts and Denial of access to critical segments of the network infrastructure. The firewall policies and rules provide effective intelligent responses by granting access to the normal packets and denying malicious traffic access to the network. This is performed after the identity of the connections are verified through the statistical analysis in the NQC. We discuss experiments performed on reducing the false positives of intrusion detection by IDSs. The main contribution of this paper is the design of intelligent strategies to reduce false positives and provide infrastructure protection using adaptive responses from firewall rulesets.
机译:入侵检测系统(IDS)在分析网络和应用程序流量方面有很大的局限性。此类系统生成的警报的百分比很高,而主要问题中的误报率也很高。我们提出了减少误报和基础设施保护的智能策略,其中涉及一种使用防火墙体系结构的新颖方法,该方法使用了来自防火墙规则集的自适应响应,该防火墙规则集位于新颖的“网络隔离通道”(NQC)中。本文的重点是结合防火墙体系结构和规则来响应可疑主机以及拒绝访问网络基础结构的关键部分。防火墙策略和规则通过授予对正常数据包的访问权限并拒绝对网络的恶意流量访问,提供了有效的智能响应。这是在NQC中通过统计分析验证了连接的身份之后执行的。我们讨论了为减少IDS入侵检测的误报而进行的实验。本文的主要贡献是设计了智能策略,以减少误报并使用来自防火墙规则集的自适应响应来提供基础结构保护。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号