An automated closed-loop framework to enforce security policies from anomaly detection

被引:2
|
作者
Henriques, Joao [1 ,2 ,3 ]
Caldeira, Filipe [1 ,2 ,3 ]
Cruz, Tiago [1 ]
Simoes, Paulo [1 ]
机构
[1] Univ Coimbra, Dept Informat Engn, CISUC, P-3030290 Coimbra, Portugal
[2] Polytech Viseu, Informat Dept, P-3504510 Viseu, Portugal
[3] Polytech Viseu, CISeD Res Ctr Digital Serv, Viseu, Portugal
关键词
Automation; Policy as code; Decision trees; Machine learning; Zero -touch network and service; management (ZSM);
D O I
10.1016/j.cose.2022.102949
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Due to the growing complexity and scale of IT systems, there is an increasing need to automate and streamline routine maintenance and security management procedures, to reduce costs and improve pro-ductivity. In the case of security incidents, the implementation and application of response actions re-quire significant effort s from operators and developers in translating policies to code. Even if Machine Learning (ML) models are used to find anomalies, they need to be regularly trained/updated to avoid be-coming outdated. In an evolving environment, a ML model with outdated training might put at risk the organization it was supposed to defend.To overcome those issues, in this paper we propose an automated closed-loop process with three stages. The first stage focuses on obtaining the Decision Trees (DT) that classify anomalies. In the second stage, DTs are translated into security Policies as Code based on languages recognized by the Policy Engine (PE). In the last stage, the translated security policies feed the Policy Engines that enforce them by converting them into specific instruction sets. We also demonstrate the feasibility of the proposed framework, by presenting an example that encompasses the three stages of the closed-loop process.The proposed framework may integrate a broad spectrum of domains and use cases, being able for in-stance to support the decide and the act stages of the ETSI Zero-touch Network & Service Management (ZSM) framework.(c) 2022 The Author(s). Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND license ( http://creativecommons.org/licenses/by-nc-nd/4.0/ )
引用
收藏
页数:7
相关论文
共 50 条
  • [31] Automated Kinematic Analysis of Closed-Loop Planar Link Mechanisms
    Yamamoto, Tatsuya
    Iwatsuki, Nobuyuki
    Ikeda, Ikuma
    MACHINES, 2020, 8 (03)
  • [32] A REAL-TIME CLOSED-LOOP CONTROLLER FOR SECURITY DISPATCH
    KUMAR, DV
    RAJU, VV
    KUPPURAJULU, A
    INTERNATIONAL JOURNAL OF ELECTRICAL POWER & ENERGY SYSTEMS, 1993, 15 (05) : 307 - 313
  • [33] All digital closed-loop FOG detection system
    Zhu, LX
    Wang, JF
    Yang, SZ
    2002 6TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING PROCEEDINGS, VOLS I AND II, 2002, : 1715 - 1718
  • [34] Closed-loop fault detection using the local approach
    Cheng, LL
    Kwok, KE
    Huang, B
    CANADIAN JOURNAL OF CHEMICAL ENGINEERING, 2003, 81 (05): : 1101 - 1108
  • [35] Closed-loop design of access control policies based on risk analyses
    Gao, Zhimin
    Wang, Shengyuan
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2010, 50 (SUPPL. 1): : 1590 - 1596
  • [36] Closed-Loop Control Systems in a Platform for Fouling Detection
    Melo, T. R.
    Silva, J. J.
    Rocha Neto, J. S.
    2014 IEEE INTERNATIONAL INSTRUMENTATION AND MEASUREMENT TECHNOLOGY CONFERENCE (I2MTC) PROCEEDINGS, 2014, : 392 - 396
  • [37] Closed-loop fiber optic gyroscope with homodyne detection
    Zhu, Y
    Qin, BK
    Chen, SF
    FIBER OPTIC SENSORS V, 1996, 2895 : 505 - 512
  • [38] CLOSED-LOOP DETECTION ALGORITHM USING VISUAL WORDS
    Liang, Zhiwei
    Chen, Yanyan
    INTERNATIONAL JOURNAL OF ROBOTICS & AUTOMATION, 2014, 29 (02): : 155 - 161
  • [39] Spatio-Temporal Closed-Loop Object Detection
    Galteri, Leonardo
    Seidenari, Lorenzo
    Bertini, Marco
    Del Bimbo, Alberto
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2017, 26 (03) : 1253 - 1263
  • [40] The Impact of Carbon Policies on Closed-Loop Supply Chain Network Design
    Fareeduddin, M.
    Hassan, Adnan
    Syed, M. N.
    Selim, S. Z.
    12TH GLOBAL CONFERENCE ON SUSTAINABLE MANUFACTURING - EMERGING POTENTIALS, 2015, 26 : 335 - +