Classification of Firewall Log Files withDifferent Algorithms and PerformanceAnalysis of These Algorithms

被引:0
|
作者
Efeoglu, Ebru [1 ]
Tuna, Gurkan [2 ]
机构
[1] Kutahya Dumlupinar Univ, Software Dept, Kutahya, Turkiye
[2] Trakya Univ, Dept Comp Programming, Edirne, Turkiye
来源
JOURNAL OF WEB ENGINEERING | 2024年 / 23卷 / 04期
关键词
Firewalls; log files; classification; performance metrics; the Simple Cart algorithm;
D O I
10.13052/jwe1540-9589.2344
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Classifying firewall log files allows analysing potential threats and decidingon appropriate rules to prevent them. Therefore, in this study, firewall log filesare classified using different classification algorithms and the performanceof the algorithms are evaluated using performance metrics. The dataset wasprepared using the log files of a firewall. It was filtered to make it free fromany personal data and consisted of 12 attributes in total and from theseattributes the action attribute was selected as the class. In the performanceevaluation, Simple Cart and NB tree algorithms made the best predictions,achieving an accuracy rate of 99.84%. Decision Stump had the worst predic-tion performance, achieving an accuracy rate of 79.68%. As the total numberof instances belonging to each of the classes in the dataset was not equal, theMatthews correlation coefficient was also used as a performance metric in theevaluations. The Simple Cart, BF tree, FT tree, J48 and NB Tree algorithmsachieved the highest average values. However, although the reset-both classwas not predicted successfully by the others, the Simple Cart algorithm madethe best predictions for it. The values of other performance metrics used inthis study also support this conclusion. Therefore, the Simple Cart algorithm is recommended for use in classifying firewall log files. However, there is aneed to develop a prefiltering and parsing approach to process different logfiles as each firewall brand creates and maintains log files in its own format.Therefore, in this study, a novel prefiltering and parsing approach has beenproposed to process log files with different structures and create structureddatasets using them.
引用
收藏
页码:561 / 594
页数:34
相关论文
共 50 条
  • [1] Classification of Firewall Log Files with Multiclass Support Vector Machine
    Ertam, Fatih
    Kaya, Mustafa
    2018 6TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSIC AND SECURITY (ISDFS), 2018, : 363 - 366
  • [2] Data Mining Algorithms for Knowledge Extraction from Web Log Files
    El Alami, Anass Abdelhamid
    Ezzikouri, Hanane
    Erritali, Mohammed
    ADVANCED INTELLIGENT SYSTEMS FOR SUSTAINABLE DEVELOPMENT (AI2SD'2019): VOL 1 - ADVANCED INTELLIGENT SYSTEMS FOR EDUCATION AND INTELLIGENT LEARNING SYSTEM, 2020, 1102 : 118 - 128
  • [3] Recommendation of Process Discovery Algorithms Through Event Log Classification
    Perez-Alfonso, Damian
    Fundora-Ramirez, Osiel
    Lazo-Cortes, Manuel S.
    Roche-Escobar, Raciel
    PATTERN RECOGNITION (MCPR 2015), 2015, 9116 : 3 - 12
  • [4] Classification and exploration of TSM log file based on datamining Algorithms
    El Abdelkhalki, Jamal
    Ben Ahmed, Mohamed
    Anouar, Boudhir Hakim
    ICCWCS'17: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON COMPUTING AND WIRELESS COMMUNICATION SYSTEMS, 2017,
  • [5] The Method of Elf-Files Identification Based on the Metric Classification Algorithms
    Zikratov, Igor
    Pantiukhin, Igor
    Krivtsova, Irina
    Druzhinin, Nikita
    2016 18TH CONFERENCE OF OPEN INNOVATIONS ASSOCIATION AND SEMINAR ON INFORMATION SECURITY AND PROTECTION OF INFORMATION TECHNOLOGY (FRUCT-ISPIT), 2016, : 397 - 403
  • [6] Algorithms for verifying firewall and router access lists
    Hassan, AA
    PROCEEDINGS OF THE 46TH IEEE INTERNATIONAL MIDWEST SYMPOSIUM ON CIRCUITS & SYSTEMS, VOLS 1-3, 2003, : 512 - 515
  • [7] Development of New Algorithms for Early Detection of Pump Thrombosis by Analysis of HeartWare LVAD Log Files
    Reiss, N.
    Mueller-von Aschwege, F.
    Schmidt, T.
    Feldmann, C.
    Schmitto, J.
    Hein, A.
    Glitza, J.
    JOURNAL OF HEART AND LUNG TRANSPLANTATION, 2018, 37 (04): : S12 - S12
  • [8] Left ventricular assist device diagnostics using controller log files: The potential for predictive algorithms?
    Hayward, Christopher S.
    JOURNAL OF HEART AND LUNG TRANSPLANTATION, 2019, 38 (10): : 1087 - 1088
  • [9] Three steganography algorithms for midi files
    Adli, A
    Nakao, Z
    Proceedings of 2005 International Conference on Machine Learning and Cybernetics, Vols 1-9, 2005, : 2401 - 2404
  • [10] Algorithms for loading parallel grid files
    Li, Jianzhong
    Rotem, Doron
    Srivastava, Jaideep
    SIGMOD Record, 1993, 22 (02) : 347 - 356