An automated closed-loop framework to enforce security policies from anomaly detection

被引:2
|
作者
Henriques, Joao [1 ,2 ,3 ]
Caldeira, Filipe [1 ,2 ,3 ]
Cruz, Tiago [1 ]
Simoes, Paulo [1 ]
机构
[1] Univ Coimbra, Dept Informat Engn, CISUC, P-3030290 Coimbra, Portugal
[2] Polytech Viseu, Informat Dept, P-3504510 Viseu, Portugal
[3] Polytech Viseu, CISeD Res Ctr Digital Serv, Viseu, Portugal
关键词
Automation; Policy as code; Decision trees; Machine learning; Zero -touch network and service; management (ZSM);
D O I
10.1016/j.cose.2022.102949
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Due to the growing complexity and scale of IT systems, there is an increasing need to automate and streamline routine maintenance and security management procedures, to reduce costs and improve pro-ductivity. In the case of security incidents, the implementation and application of response actions re-quire significant effort s from operators and developers in translating policies to code. Even if Machine Learning (ML) models are used to find anomalies, they need to be regularly trained/updated to avoid be-coming outdated. In an evolving environment, a ML model with outdated training might put at risk the organization it was supposed to defend.To overcome those issues, in this paper we propose an automated closed-loop process with three stages. The first stage focuses on obtaining the Decision Trees (DT) that classify anomalies. In the second stage, DTs are translated into security Policies as Code based on languages recognized by the Policy Engine (PE). In the last stage, the translated security policies feed the Policy Engines that enforce them by converting them into specific instruction sets. We also demonstrate the feasibility of the proposed framework, by presenting an example that encompasses the three stages of the closed-loop process.The proposed framework may integrate a broad spectrum of domains and use cases, being able for in-stance to support the decide and the act stages of the ETSI Zero-touch Network & Service Management (ZSM) framework.(c) 2022 The Author(s). Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND license ( http://creativecommons.org/licenses/by-nc-nd/4.0/ )
引用
收藏
页数:7
相关论文
共 50 条
  • [41] Closed-Loop Policies for Operational Tests of Safety-Critical Systems
    Morton, Jeremy
    Wheeler, Tim A.
    Kochenderfer, Mykel J.
    IEEE TRANSACTIONS ON INTELLIGENT VEHICLES, 2018, 3 (03): : 317 - 328
  • [42] Dual-axis microgyroscope with closed-loop detection
    An, S
    Oh, YS
    Park, KY
    Lee, SS
    Song, CM
    SENSORS AND ACTUATORS A-PHYSICAL, 1999, 73 (1-2) : 1 - 6
  • [43] Dual-axis microgyroscope with closed-loop detection
    An, S
    Oh, YS
    Lee, BL
    Park, KY
    Kang, SJ
    Choi, SO
    Go, YI
    Song, CM
    MICRO ELECTRO MECHANICAL SYSTEMS - IEEE ELEVENTH ANNUAL INTERNATIONAL WORKSHOP PROCEEDINGS, 1998, : 328 - 333
  • [44] Robust optimal dynamic production/pricing policies in a closed-loop system
    Mahmoudzadeh, Mahdi
    Sadjadi, Seyed Jafar
    Mansour, Saeed
    APPLIED MATHEMATICAL MODELLING, 2013, 37 (16-17) : 8141 - 8161
  • [45] Automatic oscillation detection and characterization in closed-loop systems
    Srinivasan, B.
    Rengaswamy, R.
    CONTROL ENGINEERING PRACTICE, 2012, 20 (08) : 733 - 746
  • [46] CLONES : a closed-loop simulation framework for body, muscles and neurons
    Thomas Voegtlin
    BMC Neuroscience, 12 (Suppl 1)
  • [47] The End is the Beginning is the End: The closed-loop learning analytics framework
    Sailer, Michael
    Ninaus, Manuel
    Huber, Stefan E.
    Bauer, Elisabeth
    Greiff, Samuel
    COMPUTERS IN HUMAN BEHAVIOR, 2024, 158
  • [48] Closed-loop model set validation under a stochastic framework
    Zhou, T
    Wang, L
    Sun, ZS
    AUTOMATICA, 2002, 38 (09) : 1449 - 1461
  • [49] Development of closed-loop modelling framework for adaptive respiratory pacemakers
    Ai, Weiwei
    Suresh, Vinod
    Roop, Partha S.
    COMPUTERS IN BIOLOGY AND MEDICINE, 2022, 141
  • [50] A Flexible Algorithm Framework for Closed-Loop Neuromodulation Research Systems
    Carlson, Dave
    Linde, Dave
    Isaacson, Ben
    Afshar, Pedram
    Bourget, Duane
    Stanslaski, Scott
    Stypulkowski, Paul
    Denison, Tim
    2013 35TH ANNUAL INTERNATIONAL CONFERENCE OF THE IEEE ENGINEERING IN MEDICINE AND BIOLOGY SOCIETY (EMBC), 2013, : 6146 - 6150