首页> 外文会议>IEEE International Conference on Fuzzy Systems >D-FRI-CiscoFirewall: Dynamic Fuzzy Rule Interpolation for Cisco ASA Firewall
【24h】

D-FRI-CiscoFirewall: Dynamic Fuzzy Rule Interpolation for Cisco ASA Firewall

机译:D-Fri-CiscofireWall:Cisco ASA防火墙的动态模糊规则插值

获取原文

摘要

Dynamic fuzzy rule interpolation (D-FRI) enhances the accuracy of sparse rule-based fuzzy reasoning via efficiently exploiting fuzzy rule interpolation to produce dynamic rules. Owing to its adaptive nature in delivering a dynamic rule base, it is particularly useful for those systems which experience frequent changes. Network security is one such area where frequent changes are quite likely due to changing network conditions and traffic. Thus, D-FRI has the potential to offer an optimised and adaptive approach for improving network security. The popular Cisco Adaptive Security Appliance (ASA) Firewall is capable of monitoring and alerting a range of common threats, by baselining the traffic of a network and analysing the statistics of dropped packets. An ASA process yields a large volume of statistical information relating to certain security events. Yet, threat detection is a rudimentary function since additional intelligence is required to automate the extraction of meaningful information for alerting the users. This could be achieved using expensive automated tools offered by a third party, but doing so may unnecessarily expose an organisation to other security threats. This paper takes a different approach, presenting a DFRI-CiscoFirewall in support of automated threat detection for Cisco ASA Firewall. Through utilising threat detection statistics, the approach can customise the detection process according to organisational requirements. It performs the relative analysis of prioritised security events and is able to predict comprehensive security situations while no matching rules are available. In particular, the approach supports the creation of a dynamic rule base, derived from changing network conditions and traffic density. Its efficacy is demonstrated by experimental evaluations.
机译:动态模糊规则插值(D-FRI)通过有效利用模糊规则插值来提高基于稀疏规则的模糊推理的准确性,从而产生动态规则。由于其适应性在提供动态规则基础时,对于经常发生变化的系统特别有用。网络安全是一个这样的领域,频繁更改很可能是由于不断变化的网络条件和流量。因此,D-FRI具有能够提供优化和自适应方法来提高网络安全性。流行的思科自适应安全设备(ASA)防火墙通过基于网络的流量并分析丢弃数据包的统计信息,能够监视和警告一系列常见威胁。 ASA过程产生与某些安全事件有关的大量统计信息。然而,威胁检测是一种基本功能,因为需要额外的智能来自动化有意义的信息来提取用户来提醒用户。这可以使用第三方提供的昂贵自动化工具来实现,但这可能不必要地将组织暴露给其他安全威胁。本文采用了不同的方法,提出了一种DFRI-CiscoFireWALL,支持Cisco ASA防火墙的自动威胁检测。通过利用威胁检测统计,该方法可以根据组织要求自定义检测过程。它执行优先顺序安全事件的相对分析,并且能够预测全面的安全情况,同时不可用匹配规则。特别地,该方法支持创建从改变网络条件和流量密度的动态规则库。通过实验评估证明了其疗效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号