Concepedia

Publication | Closed Access

Kavach: A Machine Learning based approach for enhancing the attack detection capability of firewalls

11

Citations

5

References

2021

Year

Abstract

Firewalls were created with the objective of allowing or restricting outside access to particular network resources for an organization. Firewalls are currently capable of enforcing network security policies, logging internet activity, and securing an organization's exposure to outside threats. With the meteoric rise of artificial intelligence, the attack vectors are being modified to bypass traditional firewalls. Hence, a poorly configured firewall can easily be brought down and expose the very resources it has been designed to protect. With the adaptations of the attack vectors, firewalls too must be enhanced to counter these attacks dynamically. This can be done with the help of extensive analysis of various payloads and network traffic. Machine learning algorithms are used to classify the payloads as malicious or not and proceed accordingly. Based on this classification, the rule sets are updated in the firewall to block the next generation of payloads. Thus our proof of concept proved that the incorporation of machine and deep learning algorithms to dynamically analyze the network traffic by detecting attack vectors and updating the firewall rules increases the detection capabilltles of the firewall.

References

YearCitations

Page 1