首页> 外文会议>IEEE International Conference on Fuzzy Systems >Fuzzy Logic Aided Intelligent Threat Detection in Cisco Adaptive Security Appliance 5500 Series Firewalls
【24h】

Fuzzy Logic Aided Intelligent Threat Detection in Cisco Adaptive Security Appliance 5500 Series Firewalls

机译:思科自适应安全设备5500系列防火墙中的模糊逻辑辅助智能威胁检测

获取原文

摘要

Cisco Adaptive Security Appliance (ASA) 5500 Series Firewall is amongst the most popular and technically advanced for securing organisational networks and systems. One of its most valuable features is its threat detection function which is available on every version of the firewall running a software version of 8.0(2) or higher. Threat detection operates at layers 3 and 4 to determine a baseline for network traffic, analysing packet drop statistics and generating threat reports based on traffic patterns. Despite producing a large volume of statistical information relating to several security events, further effort is required to mine and visually report more significant information and conclude the security status of the network. There are several commercial off-the-shelf tools available to undertake this task, however, they are expensive and may require a cloud subscription. Furthermore, if the information transmitted over the network is sensitive or requires confidentiality, the involvement of a third party or a third-party tool may place organisational security at risk. Therefore, this paper presents a fuzzy logic aided intelligent threat detection solution, which is a cost-free, intuitive and comprehensible solution, enhancing and simplifying the threat detection process for all. In particular, it employs a fuzzy reasoning system based on the threat detection statistics, and presents results/threats through a developed dashboard user interface, for ease of understanding for administrators and users. The paper further demonstrates the successful utilisation of a fuzzy reasoning system for selected and prioritised security events in basic threat detection, although it can be extended to encompass more complex situations, such as complete basic threat detection, advanced threat detection, scanning threat detection, and customised feature based threat detection.
机译:思科自适应安全设备(ASA)5500系列防火墙是用于保护组织网络和系统的最流行且技术最先进的防火墙之一。它最有价值的功能之一是其威胁检测功能,该功能可在运行8.0(2)或更高版本软件的每个防火墙版本上使用。威胁检测在第3层和第4层进行操作,以确定网络流量的基准,分析数据包丢弃统计信息并基于流量模式生成威胁报告。尽管产生了大量与若干安全事件有关的统计信息,但仍需要进一步努力来挖掘和直观地报告更重要的信息,并得出网络的安全状态。有几种商用的现成工具可以执行此任务,但是它们价格昂贵,并且可能需要云订阅。此外,如果通过网络传输的信息敏感或需要保密,则第三方或第三方工具的介入可能会使组织安全性受到威胁。因此,本文提出了一种模糊逻辑辅助的智能威胁检测解决方案,该解决方案是一种免费,直观且易于理解的解决方案,可增强和简化所有人的威胁检测过程。特别是,它采用基于威胁检测统计信息的模糊推理系统,并通过开发的仪表板用户界面显示结果/威胁,以方便管理员和用户理解。本文进一步展示了模糊推理系统在基本威胁检测中对选定安全事件和优先安全事件的成功利用,尽管它可以扩展到涵盖更复杂的情况,例如完整的基本威胁检测,高级威胁检测,扫描威胁检测以及基于定制功能的威胁检测。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号