• DocumentCode
    117707
  • Title

    An MEBN framework as a dynamic firewall´s knowledge flow architecture

  • Author

    Boruah, Abhijit ; Hazarika, S.M.

  • Author_Institution
    Dept. of CSE, DUIET Dibrugarh Univ., Dibrugarh, India
  • fYear
    2014
  • fDate
    20-21 Feb. 2014
  • Firstpage
    249
  • Lastpage
    254
  • Abstract
    Dynamic firewalls with stateful inspection have added a lot of security features over the stateless traditional static filters. Dynamic firewalls need to be adaptive. In this paper, we have designed a framework for dynamic firewalls based on probabilistic ontology using Multi Entity Bayesian Networks (MEBN) logic. MEBN extends ordinary Bayesian networks to allow representation of graphical models with repeated substructures and can express a probability distribution over models of any consistent first order theory. The motivation of our proposed work is about preventing novel attacks (i.e. those attacks for which no signatures have been generated yet). The proposed framework is in two important parts: first part is the data flow architecture which extracts important connection based features with the prime goal of an explicit rule inclusion into the rule base of the firewall; second part is the knowledge flow architecture which uses semantic threat graph as well as reasoning under uncertainty to fulfill the required objective of providing futuristic threat prevention technique in dynamic firewalls.
  • Keywords
    belief networks; data flow computing; firewalls; ontologies (artificial intelligence); statistical distributions; MEBN framework; MEBN logic; data flow architecture; dynamic firewalls; first order theory; futuristic threat prevention technique; graphical models; knowledge flow architecture; multi entity Bayesian networks; probabilistic ontology; probability distribution; security features; stateful inspection; stateless traditional static filters; Bayes methods; Feature extraction; Ontologies; Probabilistic logic; Semantics; Signal processing algorithms; Bayesian networks; MEBN; Probabilistic Ontology; explicit rule inclusion; semantic threat graph;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Signal Processing and Integrated Networks (SPIN), 2014 International Conference on
  • Conference_Location
    Noida
  • Print_ISBN
    978-1-4799-2865-1
  • Type

    conf

  • DOI
    10.1109/SPIN.2014.6776957
  • Filename
    6776957