Synthetic security policy generation via network traffic clustering

  • Authors:
  • Taghrid Samak;Ehab Al-Shaer

  • Affiliations:
  • DePaul University, Chicago, IL, USA;University of North Carolina, Charlotte, NC, USA

  • Venue:
  • Proceedings of the 3rd ACM workshop on Artificial intelligence and security
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security policies are an essential part in the operations of any networking system. Test policies are always needed for conducting research and development. Such policies are required in various phases of research related to many problems as performance optimization, device testing, and configuration analysis. In this paper, we introduce a novel technique that utilizes trace repositories to generate traffic-driven firewall policies. An online clustering mechanism is designed and developed to infer rule criteria and policy structure from the traffic. The approach generates policies relevant to the environment while satisfying structural features specified by testing requirements. Clustering parameters are tuned to fit the need of the testing domain. High level structural features (policy size, distinct rules, rule specificity, etc) are mapped to algorithm input parameters. The technique evaluation shows the flexibility as well as the accuracy of the generated policies compared to actual administrator-defined policies.