Visible to the public An MEBN framework as a dynamic firewall's knowledge flow architecture

TitleAn MEBN framework as a dynamic firewall's knowledge flow architecture
Publication TypeConference Paper
Year of Publication2014
AuthorsBoruah, A., Hazarika, S.M.
Conference NameSignal Processing and Integrated Networks (SPIN), 2014 International Conference on
Date PublishedFeb
KeywordsBayes methods, Bayesian networks, belief networks, data flow architecture, data flow computing, dynamic firewalls, explicit rule inclusion, feature extraction, firewalls, first order theory, futuristic threat prevention technique, graphical models, knowledge flow architecture, MEBN, MEBN framework, MEBN logic, multi entity Bayesian networks, Ontologies, ontologies (artificial intelligence), Probabilistic logic, probabilistic ontology, Probability distribution, security features, semantic threat graph, Semantics, Signal processing algorithms, stateful inspection, stateless traditional static filters, statistical distributions
Abstract

Dynamic firewalls with stateful inspection have added a lot of security features over the stateless traditional static filters. Dynamic firewalls need to be adaptive. In this paper, we have designed a framework for dynamic firewalls based on probabilistic ontology using Multi Entity Bayesian Networks (MEBN) logic. MEBN extends ordinary Bayesian networks to allow representation of graphical models with repeated substructures and can express a probability distribution over models of any consistent first order theory. The motivation of our proposed work is about preventing novel attacks (i.e. those attacks for which no signatures have been generated yet). The proposed framework is in two important parts: first part is the data flow architecture which extracts important connection based features with the prime goal of an explicit rule inclusion into the rule base of the firewall; second part is the knowledge flow architecture which uses semantic threat graph as well as reasoning under uncertainty to fulfill the required objective of providing futuristic threat prevention technique in dynamic firewalls.

DOI10.1109/SPIN.2014.6776957
Citation Key6776957