An Intelligence Defense System with SNORT Rules

2023 25th International Conference on Advanced Communication Technology (ICACT)(2023)

引用 0|浏览1
暂无评分
摘要
Misconfiguration of firewall rules has always been considered a serious issue. The handwritten rule is messy and buggy under the increasingly complex firewall architecture. To avoid being attacked behind an insecure firewall. This study defines an intelligence defense system. Combined with data analysis, feature extraction, optimization, and firewall technology. Its main purpose is to replace handwritten firewall rules and provide immediate and reliable protection against diversified attacks. In the verification, 68,936,206 packets collected by Cowrie honeypot were used as the test data. The accuracy rate of classifying different attack behaviors reached 99.5%, and the packet coverage of Snort rules also achieved 98%. This thesis proposes a system that can effectively identify and defend from diverse attacks.
更多
查看译文
关键词
MITRE ATT&CK,K-means,PCRE Regular Expression,Snort Rule
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要