首页> 外文会议>IEEE International Conference on Fuzzy Systems >D-FRI-CiscoFirewall: Dynamic Fuzzy Rule Interpolation for Cisco ASA Firewall
【24h】

D-FRI-CiscoFirewall: Dynamic Fuzzy Rule Interpolation for Cisco ASA Firewall

机译:D-FRI-CiscoFirewall:适用于Cisco ASA防火墙的动态模糊规则插值

获取原文

摘要

Dynamic fuzzy rule interpolation (D-FRI) enhances the accuracy of sparse rule-based fuzzy reasoning via efficiently exploiting fuzzy rule interpolation to produce dynamic rules. Owing to its adaptive nature in delivering a dynamic rule base, it is particularly useful for those systems which experience frequent changes. Network security is one such area where frequent changes are quite likely due to changing network conditions and traffic. Thus, D-FRI has the potential to offer an optimised and adaptive approach for improving network security. The popular Cisco Adaptive Security Appliance (ASA) Firewall is capable of monitoring and alerting a range of common threats, by baselining the traffic of a network and analysing the statistics of dropped packets. An ASA process yields a large volume of statistical information relating to certain security events. Yet, threat detection is a rudimentary function since additional intelligence is required to automate the extraction of meaningful information for alerting the users. This could be achieved using expensive automated tools offered by a third party, but doing so may unnecessarily expose an organisation to other security threats. This paper takes a different approach, presenting a DFRI-CiscoFirewall in support of automated threat detection for Cisco ASA Firewall. Through utilising threat detection statistics, the approach can customise the detection process according to organisational requirements. It performs the relative analysis of prioritised security events and is able to predict comprehensive security situations while no matching rules are available. In particular, the approach supports the creation of a dynamic rule base, derived from changing network conditions and traffic density. Its efficacy is demonstrated by experimental evaluations.
机译:动态模糊规则插值(D-FRI)通过有效利用模糊规则插值来生成动态规则,从而提高了基于稀疏规则的模糊推理的准确性。由于它在提供动态规则库方面具有自适应性,因此对于那些经常更改的系统特别有用。网络安全就是其中之一,由于网络条件和流量的变化,很可能会经常进行更改。因此,D-FRI有潜力提供一种优化的自适应方法来提高网络安全性。流行的思科自适应安全设备(ASA)防火墙能够通过对网络流量进行基线分析并分析丢弃数据包的统计信息,来监视和警告一系列常见威胁。 ASA流程会产生大量与某些安全事件有关的统计信息。然而,威胁检测是一项基本功能,因为需要额外的情报来自动提取有意义的信息以提醒用户。这可以使用第三方提供的昂贵的自动化工具来实现,但这样做可能会使组织不必要地面临其他安全威胁。本文采用了一种不同的方法,提出了一种支持Cisco ASA防火墙自动威胁检测的DFRI-CiscoFirewall。通过利用威胁检测统计信息,该方法可以根据组织要求自定义检测过程。它执行优先安全事件的相关分析,并能够在没有匹配规则可用的情况下预测全面的安全情况。特别是,该方法支持创建动态规则库,该规则库是从不断变化的网络条件和流量密度中得出的。通过实验评估证明了其功效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号