An automated closed-loop framework to enforce security policies from anomaly detection

被引:2
|
作者
Henriques, Joao [1 ,2 ,3 ]
Caldeira, Filipe [1 ,2 ,3 ]
Cruz, Tiago [1 ]
Simoes, Paulo [1 ]
机构
[1] Univ Coimbra, Dept Informat Engn, CISUC, P-3030290 Coimbra, Portugal
[2] Polytech Viseu, Informat Dept, P-3504510 Viseu, Portugal
[3] Polytech Viseu, CISeD Res Ctr Digital Serv, Viseu, Portugal
关键词
Automation; Policy as code; Decision trees; Machine learning; Zero -touch network and service; management (ZSM);
D O I
10.1016/j.cose.2022.102949
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Due to the growing complexity and scale of IT systems, there is an increasing need to automate and streamline routine maintenance and security management procedures, to reduce costs and improve pro-ductivity. In the case of security incidents, the implementation and application of response actions re-quire significant effort s from operators and developers in translating policies to code. Even if Machine Learning (ML) models are used to find anomalies, they need to be regularly trained/updated to avoid be-coming outdated. In an evolving environment, a ML model with outdated training might put at risk the organization it was supposed to defend.To overcome those issues, in this paper we propose an automated closed-loop process with three stages. The first stage focuses on obtaining the Decision Trees (DT) that classify anomalies. In the second stage, DTs are translated into security Policies as Code based on languages recognized by the Policy Engine (PE). In the last stage, the translated security policies feed the Policy Engines that enforce them by converting them into specific instruction sets. We also demonstrate the feasibility of the proposed framework, by presenting an example that encompasses the three stages of the closed-loop process.The proposed framework may integrate a broad spectrum of domains and use cases, being able for in-stance to support the decide and the act stages of the ETSI Zero-touch Network & Service Management (ZSM) framework.(c) 2022 The Author(s). Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND license ( http://creativecommons.org/licenses/by-nc-nd/4.0/ )
引用
收藏
页数:7
相关论文
共 50 条
  • [21] A Closed-Loop Shared Control Framework for Legged Robots
    Xu, Peng
    Wang, Zhikai
    Ding, Liang
    Li, Zhengyang
    Shi, Junyi
    Gao, Haibo
    Liu, Guangjun
    Huang, Yanlong
    IEEE-ASME TRANSACTIONS ON MECHATRONICS, 2024, 29 (01) : 190 - 201
  • [22] Study on differential pricing policies in closed-loop supply chain
    Jiang, Hongwei
    INFORMATION SCIENCE AND MANAGEMENT ENGINEERING, VOLS 1-3, 2014, 46 : 2499 - 2504
  • [23] Optimal operating policies for closed-loop recycling HPLC processes
    Teoh, HK
    Sorensen, E
    Titchener-Hooker, N
    CHEMICAL ENGINEERING SCIENCE, 2003, 58 (18) : 4145 - 4158
  • [24] A Simple Framework for Identifying Dynamical Systems in Closed-Loop
    Maruta, Ichiro
    Sugie, Toshiharu
    IEEE ACCESS, 2021, 9 : 31441 - 31453
  • [25] A Closed-loop Based Framework for Design Requirement Management
    Zhang, Zhinan
    Li, Xuemeng
    Liu, Zelin
    MOVING INTEGRATED PRODUCT DEVELOPMENT TO SERVICE CLOUDS IN THE GLOBAL ECONOMY, 2014, 1 : 444 - 453
  • [26] Closed-loop automated drug infusion regulator: A clinically translatable, closed-loop drug delivery system for personalized drug dosing
    DeRidder, Louis B.
    Hare, Kyle A.
    Lopes, Aaron
    Jenkins, Josh
    Fitzgerald, Nina
    MacPherson, Emmeline
    Fabian, Niora
    Morimoto, Josh
    Chu, Jacqueline N.
    Kirtane, Ameya R.
    Madani, Wiam
    Ishida, Keiko
    Kuosmanen, Johannes L. P.
    Zecharias, Naomi
    Colangelo, Christopher M.
    Huang, Hen-Wei
    Chilekwa, Makaya
    Lal, Nikhil B.
    Srinivasan, Shriya S.
    Hayward, Alison M.
    Wolpin, Brian M.
    Trumper, David
    Quast, Troy
    Rubinson, Douglas A.
    Langer, Robert
    Traverso, Giovanni
    MED, 2024, 5 (07): : 780 - 796
  • [27] Closed-loop Test Systems for highly automated Driving Functions
    Schiefenhoevel, Martin
    ATP MAGAZINE, 2021, (08): : 46 - 48
  • [28] Automated closed-loop stimulation to inhibit neurogenic bladder overactivity
    Majerus, Steve
    Nguyen, Carvell
    Brose, Steven
    Nemunaitis, Gregory
    Damaser, Margot
    Bourbeau, Dennis J.
    PROCEEDINGS OF THE INSTITUTION OF MECHANICAL ENGINEERS PART H-JOURNAL OF ENGINEERING IN MEDICINE, 2024, 238 (06) : 619 - 627
  • [29] Automated closed-loop stimulation to inhibit neurogenic bladder overactivity
    Majerus, S. J. A.
    Nguyen, C. T.
    Brose, S. W.
    Nemunaitis, G. A.
    Damaser, M. S.
    Bourbeau, D. J.
    NEUROUROLOGY AND URODYNAMICS, 2019, 38 : S67 - S68
  • [30] Security Challenges and Solutions for Closed-Loop Artificial Pancreas Systems
    Lazaro, Caterina
    Oruklu, Erdal
    Cinar, Ali
    2017 IEEE 60TH INTERNATIONAL MIDWEST SYMPOSIUM ON CIRCUITS AND SYSTEMS (MWSCAS), 2017, : 1097 - 1100