Classification of Firewall Log Data Using Multiclass Machine Learning Models

被引:11
|
作者
Aljabri, Malak [1 ,2 ]
Alahmadi, Amal A. [3 ]
Mohammad, Rami Mustafa A. [4 ]
Aboulnour, Menna [2 ]
Alomari, Dorieh M. [5 ]
Almotiri, Sultan H. [1 ]
机构
[1] Umm Al Qura Univ, Coll Comp & Informat Syst, Dept Comp Sci, Mecca 21955, Saudi Arabia
[2] Imam Abdulrahman Bin Faisal Univ, Coll Comp Sci & Informat Technol, Dept Comp Sci, SAUDI ARAMCO Cybersecur Chair, POB 1982, Dammam 31441, Saudi Arabia
[3] Imam Abdulrahman Bin Faisal Univ, Coll Comp Sci & Informat Technol, Dept Networks & Commun, POB 1982, Dammam 31441, Saudi Arabia
[4] Imam Abdulrahman Bin Faisal Univ, Coll Comp Sci & Informat Technol, Dept Comp Informat Syst, POB 1982, Dammam 31441, Saudi Arabia
[5] Imam Abdulrahman Bin Faisal Univ, Coll Comp Sci & Informat Technol, Dept Comp Engn, SAUDI ARAMCO Cybersecur Chair, POB 1982, Dammam 31441, Saudi Arabia
关键词
machine learning; deep learning; network security; firewalls; random forest;
D O I
10.3390/electronics11121851
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
These days, we are witnessing unprecedented challenges to network security. This indeed confirms that network security has become increasingly important. Firewall logs are important sources of evidence, but they are still difficult to analyze. Artificial Intelligence (AI), Machine Learning (ML), and Deep Learning (DL) have emerged as effective in developing robust security measures due to the fact that they have the capability to deal with complex cyberattacks in a timely manner. This work aims to tackle the difficulty of analyzing firewall logs using ML and DL by building multiclass ML and DL models that can analyze firewall logs and classify the actions to be taken in response to received sessions as "Allow", "Drop", "Deny", or "Reset-both". Two sets of empirical evaluations were conducted in order to assess the performance of the produced models. Different features set were used in each set of the empirical evaluation. Further, two extra features, namely, application and category, were proposed to enhance the performance of the proposed models. Several ML and DL algorithms were used for the evaluation purposes, namely, K-Nearest Neighbor (KNN), Naive Bayas (NB), J48, Random Forest (RF) and Artificial Neural Network (ANN). One interesting reading in the experimental results is that the RF produced the highest accuracy of 99.11% and 99.64% in the first and the second experiments respectively. Yet, all other algorithms have also produced high accuracy rates which confirm that the proposed features played a significant role in improving the firewall classification rate.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Classification of Firewall Log Files with Multiclass Support Vector Machine
    Ertam, Fatih
    Kaya, Mustafa
    2018 6TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSIC AND SECURITY (ISDFS), 2018, : 363 - 366
  • [2] Multiclass Classification of Cancer Based on Microarray Data Using Extreme Learning Machine
    Khadijah
    Rismiyati
    Mantau, Aprinaldi Jasa
    2017 1ST INTERNATIONAL CONFERENCE ON INFORMATICS AND COMPUTATIONAL SCIENCES (ICICOS), 2017, : 159 - 164
  • [3] An Approach for the Classification of Rock Types Using Machine Learning of Core and Log Data
    Xing, Yihan
    Yang, Huiting
    Yu, Wei
    SUSTAINABILITY, 2023, 15 (11)
  • [4] Multiclass covert speech classification using extreme learning machine
    Dipti Pawar
    Sudhir Dhage
    Biomedical Engineering Letters, 2020, 10 : 217 - 226
  • [5] Multiclass covert speech classification using extreme learning machine
    Pawar, Dipti
    Dhage, Sudhir
    BIOMEDICAL ENGINEERING LETTERS, 2020, 10 (02) : 217 - 226
  • [6] Classification of a-thalassemia data using machine learning models
    Christensen, Frederik
    Kilic, Deniz Kenan
    Nielsen, Izabela Ewa
    El-Galaly, Tarec Christoffer
    Glenthoj, Andreas
    Helby, Jens
    Frederiksen, Henrik
    Moller, Soren
    Fuglkjaer, Alexander Djupnes
    COMPUTER METHODS AND PROGRAMS IN BIOMEDICINE, 2025, 260
  • [7] Comparison between Statistical Models and Machine Learning Methods on Classification for Highly Imbalanced Multiclass Kidney Data
    Jeong, Bomi
    Cho, Hyunjeong
    Kim, Jieun
    Kwon, Soon Kil
    Hong, SeungWoo
    Lee, ChangSik
    Kim, TaeYeon
    Park, Man Sik
    Hong, Seoksu
    Heo, Tae-Young
    DIAGNOSTICS, 2020, 10 (06)
  • [8] Machine learning decision tree models for multiclass classification of common malignant brain tumors using perfusion and spectroscopy MRI data
    Vallee, Rodolphe
    Vallee, Jean-Noel
    Guillevin, Carole
    Lallouette, Athena
    Thomas, Clement
    Rittano, Guillaume
    Wager, Michel
    Guillevin, Remy
    Vallee, Alexandre
    FRONTIERS IN ONCOLOGY, 2023, 13
  • [9] Prediction of TCP Firewall Action Using Different Machine Learning Models
    Bairwa, Amit Kumar
    Kamboj, Akshit
    Joshi, Sandeep
    Pavlovich, Pljonkin Anton
    Hiranwal, Saroj
    CLOUD COMPUTING, BIG DATA AND EMERGING TOPICS, JCC-BD&ET 2024, 2025, 2189 : 161 - 174
  • [10] Comparative Analysis of Multiclass Classification Machine Learning Models for Cybersecurity Intrusion Detection
    Loughmari, Mohamed
    El Affar, Anass
    DIGITAL TECHNOLOGIES AND APPLICATIONS, ICDTA 2024, VOL 2, 2024, 1099 : 97 - 108