An automated closed-loop framework to enforce security policies from anomaly detection

被引:2
|
作者
Henriques, Joao [1 ,2 ,3 ]
Caldeira, Filipe [1 ,2 ,3 ]
Cruz, Tiago [1 ]
Simoes, Paulo [1 ]
机构
[1] Univ Coimbra, Dept Informat Engn, CISUC, P-3030290 Coimbra, Portugal
[2] Polytech Viseu, Informat Dept, P-3504510 Viseu, Portugal
[3] Polytech Viseu, CISeD Res Ctr Digital Serv, Viseu, Portugal
关键词
Automation; Policy as code; Decision trees; Machine learning; Zero -touch network and service; management (ZSM);
D O I
10.1016/j.cose.2022.102949
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Due to the growing complexity and scale of IT systems, there is an increasing need to automate and streamline routine maintenance and security management procedures, to reduce costs and improve pro-ductivity. In the case of security incidents, the implementation and application of response actions re-quire significant effort s from operators and developers in translating policies to code. Even if Machine Learning (ML) models are used to find anomalies, they need to be regularly trained/updated to avoid be-coming outdated. In an evolving environment, a ML model with outdated training might put at risk the organization it was supposed to defend.To overcome those issues, in this paper we propose an automated closed-loop process with three stages. The first stage focuses on obtaining the Decision Trees (DT) that classify anomalies. In the second stage, DTs are translated into security Policies as Code based on languages recognized by the Policy Engine (PE). In the last stage, the translated security policies feed the Policy Engines that enforce them by converting them into specific instruction sets. We also demonstrate the feasibility of the proposed framework, by presenting an example that encompasses the three stages of the closed-loop process.The proposed framework may integrate a broad spectrum of domains and use cases, being able for in-stance to support the decide and the act stages of the ETSI Zero-touch Network & Service Management (ZSM) framework.(c) 2022 The Author(s). Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND license ( http://creativecommons.org/licenses/by-nc-nd/4.0/ )
引用
收藏
页数:7
相关论文
共 50 条
  • [1] A CLOSED-LOOP AUTOMATED SEATING SYSTEM
    KWIATKOWSKI, RJ
    INIGO, RM
    JOURNAL OF REHABILITATION RESEARCH AND DEVELOPMENT, 1993, 30 (04): : 393 - 404
  • [2] Closed-loop, ultraprecise, automated craniotomies
    Pak, Nikita
    Siegle, Joshua H.
    Kinney, Justin P.
    Denman, Daniel J.
    Blanche, Timothy J.
    Boyden, Edward S.
    JOURNAL OF NEUROPHYSIOLOGY, 2015, 113 (10) : 3943 - 3953
  • [3] Double closed-loop NCSs modeling for security control and a defense framework design
    Ge, Hui
    Yue, Dong
    Xie, Xiang-peng
    Deng, Song
    Yang, Yang
    Yang, Ji-quan
    PROCEEDINGS OF THE 36TH CHINESE CONTROL CONFERENCE (CCC 2017), 2017, : 7777 - 7782
  • [4] AI-assisted Workflow Management Framework for Automated Closed-loop Operation
    Miyamoto, Tatsuji
    Kuroki, Keisuke
    Miyazawa, Masanori
    Hayashi, Michiaki
    NOMS 2018 - 2018 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2018,
  • [5] Closed-loop learning of visual control policies
    Jodogne, Sébastien
    Piater, Justus H.
    Journal of Artificial Intelligence Research, 1600, 28 : 349 - 391
  • [6] Closed-loop learning of visual control policies
    Jodogne, Sebastien
    Piater, Justus H.
    JOURNAL OF ARTIFICIAL INTELLIGENCE RESEARCH, 2007, 28 : 349 - 391
  • [7] Concurrent Fault Detection and Anomaly Location in Closed-Loop Dynamic Systems With Measured Disturbances
    Wang, Kai
    Chen, Junghui
    Song, Zhihuan
    IEEE TRANSACTIONS ON AUTOMATION SCIENCE AND ENGINEERING, 2019, 16 (03) : 1033 - 1045
  • [8] Closed-loop person tracking and detection
    Kettnaker, V
    Gahm, JK
    1ST CANADIAN CONFERENCE ON COMPUTER AND ROBOT VISION, PROCEEDINGS, 2004, : 314 - 319
  • [9] A structural framework for closed-loop supply chains
    Wikner, Joakim
    Tang, Ou
    INTERNATIONAL JOURNAL OF LOGISTICS MANAGEMENT, 2008, 19 (03) : 344 - 366
  • [10] A closed-loop renewable energy evaluation framework
    Kealy, Tony
    JOURNAL OF CLEANER PRODUCTION, 2020, 251