Publication: A firewall policy anomaly detection framework for reliable network security
dc.contributor.author | Kaşif, Ahmet | |
dc.contributor.author | Çatal, Çağatay | |
dc.contributor.author | Tekinerdoğan, Bedir | |
dc.contributor.buuauthor | Togay, Cengiz | |
dc.contributor.department | Mühendislik Fakültesi | |
dc.contributor.department | Bilgisayar Mühendisliği Bölümü | |
dc.contributor.researcherid | AAG-9038-2020 | |
dc.contributor.scopusid | 15065979500 | |
dc.date.accessioned | 2024-01-30T07:39:47Z | |
dc.date.available | 2024-01-30T07:39:47Z | |
dc.date.issued | 2021-06-11 | |
dc.description.abstract | One of the key challenges in computer networks is network security. For securing the network, various solutions have been proposed, including network security protocols and firewalls. In the case of so-called packet-filtering firewalls, policy rules are implemented to monitor changes to the network and preserve the required security level. Due to the dramatic increase of devices, however, and herewith the rapid increase of the size of the policy rules, firewall policy anomalies occur more frequently. This requires careful implementation of the policy rules to ensure cost-efficient solutions for anomaly detection to support network security. In this study, we present an anomaly detection framework for detecting intrafirewall policy anomaly rules. The framework supports the simulation of packets through the firewall ruleset for validating and enhancing the security level of the network. The framework is validated using four different types of firewall policy anomalies. Experimental results demonstrate that the framework is effective and efficient in detecting firewall policy anomalies. | |
dc.identifier.citation | Togay, C. vd. (2022). "A firewall policy anomaly detection framework for reliable network security". IEEE Transactions on Reliability, 71(1), 339-347. | |
dc.identifier.doi | https://doi.org/10.1109/TR.2021.3089511 | |
dc.identifier.eissn | 1558-1721 | |
dc.identifier.endpage | 347 | |
dc.identifier.issn | 0018-9529 | |
dc.identifier.issue | 1 | |
dc.identifier.scopus | 2-s2.0-85112707923 | |
dc.identifier.startpage | 339 | |
dc.identifier.uri | https://ieeexplore.ieee.org/document/9478072 | |
dc.identifier.uri | https://hdl.handle.net/11452/39378 | |
dc.identifier.volume | 71 | |
dc.identifier.wos | 000733755300001 | |
dc.indexed.wos | SCIE | |
dc.language.iso | en | |
dc.publisher | IEEE | |
dc.relation.collaboration | Yurt içi | |
dc.relation.collaboration | Yurt dışı | |
dc.relation.journal | IEEE Transactions on Reliability | |
dc.relation.publicationcategory | Makale - Uluslararası Hakemli Dergi | |
dc.rights | info:eu-repo/semantics/closedAccess | |
dc.subject | Anomaly detection | |
dc.subject | Computer system firewalls | |
dc.subject | Logic programming | |
dc.subject | Network protocols | |
dc.subject | Packet networks | |
dc.subject | Anomaly detection frameworks | |
dc.subject | Firewall policies | |
dc.subject | Logic-programming | |
dc.subject | Networks security | |
dc.subject | Packet filtering | |
dc.subject | Policy rules | |
dc.subject | Reliable networks | |
dc.subject | Security | |
dc.subject | Security level | |
dc.subject | Network security | |
dc.subject | Ip networks | |
dc.subject | Firewalls (computing) | |
dc.subject | Shadow mapping | |
dc.subject | Redundancy | |
dc.subject | Correlation | |
dc.subject | Classification | |
dc.subject | Computer science | |
dc.subject | Engineering | |
dc.subject | Anomaly detection | |
dc.subject | Computer system firewalls | |
dc.subject | Logic programming | |
dc.subject | Network protocols | |
dc.subject | Packet networks | |
dc.subject | Anomaly detection | |
dc.subject | Anomaly detection frameworks | |
dc.subject | Firewall policies | |
dc.subject | Logic-programming | |
dc.subject | Networks security | |
dc.subject | Packet filtering | |
dc.subject | Reliable networks | |
dc.subject | Network security | |
dc.subject.scopus | Firewall; Network Security; Access Control | |
dc.subject.wos | Computer science, hardware & architecture | |
dc.subject.wos | Computer science, software engineering | |
dc.subject.wos | Engineering, electrical & electronic | |
dc.title | A firewall policy anomaly detection framework for reliable network security | |
dc.type | Article | |
dc.wos.quartile | Q1 | |
dspace.entity.type | Publication | |
local.contributor.department | Mühendislik Fakültesi/Bilgisayar Mühendisliği Bölümü | |
local.indexed.at | WOS | |
local.indexed.at | Scopus |
Files
License bundle
1 - 1 of 1
- Name:
- license.txt
- Size:
- 1.71 KB
- Format:
- Item-specific license agreed upon to submission
- Description: