The Experts below are selected from a list of 633 Experts worldwide ranked by ideXlab platform

Alessandro Provetti - One of the best experts on this subject based on the ideXlab platform.

  • Firewall Configuration Policies for the Specification and Implementation of Private Zones
    2012 IEEE International Symposium on Policies for Distributed Systems and Networks, 2012
    Co-Authors: Jorge Lobo, Massimo De Marchi, Alessandro Provetti
    Abstract:

    We introduce and discuss two case studies where a complex network is modeled as a set of zones interconnected by routers or Firewalls. To address the problem in full abstraction, we defined PDLz, an extension of the PDL event-condition-action language that supports the specification of Firewall routing policies. PDLz allows the modelling of computer networks based on the concept of zone, i.e., a TCP/IP subnet where internal traffic remains unconstrained. PDLz policies are enforceable thanks to a direct translation to the IPtables Firewall Configuration language. At the same time, PDLz has a declarative semantics thanks to translation to logic programs. The logic programming translation also supports, by adding extra rules, the formal verification of properties of the network, viz. off-line reachability testing across Firewalls. We describe the application of PDLz to the case studies.

  • POLICY - Firewall Configuration Policies for the Specification and Implementation of Private Zones
    2012 IEEE International Symposium on Policies for Distributed Systems and Networks, 2012
    Co-Authors: Jorge Lobo, Massimo De Marchi, Alessandro Provetti
    Abstract:

    We introduce and discuss two case studies where a complex network is modeled as a set of zones interconnected by routers or Firewalls. To address the problem in full abstraction, we defined PDLz, an extension of the PDL event-condition-action language that supports the specification of Firewall routing policies. PDLz allows the modelling of computer networks based on the concept of zone, i.e., a TCP/IP subnet where internal traffic remains unconstrained. PDLz policies are enforceable thanks to a direct translation to the IPtables Firewall Configuration language. At the same time, PDLz has a declarative semantics thanks to translation to logic programs. The logic programming translation also supports, by adding extra rules, the formal verification of properties of the network, viz. off-line reachability testing across Firewalls. We describe the application of PDLz to the case studies.

  • POLICY - Policy-Based Parametric Firewall Configuration: A Real-Case Application
    Eighth IEEE International Workshop on Policies for Distributed Systems and Networks (POLICY'07), 2007
    Co-Authors: M. Marchi, R. Penzo, Alessandro Provetti
    Abstract:

    We describe a simple policy language for setting up and running Firewalls (FW). The language allows to describe sophisticated policies for controlling network connections. Composition is done at set-up time, when a parser, starting from a given policy, generates the relative Configuration file for one or more Firewalls operating the industry-standard Linux Iptables kernel extension. The policy captures the essence of the desired requirements and constrains upon connections between zones. The language has been designed and it is currently on testing in the context of a large intra/extranet with more than 10,000 assigned IP addresses.

  • policy based parametric Firewall Configuration a real case application
    IEEE International Workshop on Policies for Distributed Systems and Networks, 2007
    Co-Authors: M. Marchi, R. Penzo, Alessandro Provetti
    Abstract:

    We describe a simple policy language for setting up and running Firewalls (FW). The language allows to describe sophisticated policies for controlling network connections. Composition is done at set-up time, when a parser, starting from a given policy, generates the relative Configuration file for one or more Firewalls operating the industry-standard Linux Iptables kernel extension. The policy captures the essence of the desired requirements and constrains upon connections between zones. The language has been designed and it is currently on testing in the context of a large intra/extranet with more than 10,000 assigned IP addresses.

C.-c. Lo - One of the best experts on this subject based on the ideXlab platform.

  • An Efficient Flow Control Approach for SDN-Based Network Threat Detection and Migration Using Support Vector Machine
    2016 IEEE 13th International Conference on e-Business Engineering (ICEBE), 2016
    Co-Authors: Peng Wang, W. H. Lin, K.-m. Chao, H C Lin, C.-c. Lo
    Abstract:

    Most existing approaches for solving the network threat problems focus on the specific security mechanisms, for example, network intrusion detection system (NIDS) detection, Firewall Configuration, rather than on flow management approaches to defend network threats with an SDN (Software Defined Networking) architecture. Accordingly, this study proposes an improved behaviour-based SVM (support vector machine) with learning algorithm for use in the security monitoring system (SMS) to categorize network threats for network intrusion detection system. The model also adopted the ID3 decision tree theory to outrank raw features and determine the most qualified features to train support vector classifier (SVC) considering the overall detection precision rate of experiments which speeds up the learning of normal and intrusive patterns and and increases the accuracy of detecting intrusion. By using sFlow collector and analyzer associated with sFlow-RT toolset, the experimental results proved that the SMS enables a defender to classify the network threats with defence strategies and defend network threats.

Peng Wang - One of the best experts on this subject based on the ideXlab platform.

  • An Efficient Flow Control Approach for SDN-Based Network Threat Detection and Migration Using Support Vector Machine
    2016 IEEE 13th International Conference on e-Business Engineering (ICEBE), 2016
    Co-Authors: Peng Wang, W. H. Lin, K.-m. Chao, H C Lin, C.-c. Lo
    Abstract:

    Most existing approaches for solving the network threat problems focus on the specific security mechanisms, for example, network intrusion detection system (NIDS) detection, Firewall Configuration, rather than on flow management approaches to defend network threats with an SDN (Software Defined Networking) architecture. Accordingly, this study proposes an improved behaviour-based SVM (support vector machine) with learning algorithm for use in the security monitoring system (SMS) to categorize network threats for network intrusion detection system. The model also adopted the ID3 decision tree theory to outrank raw features and determine the most qualified features to train support vector classifier (SVC) considering the overall detection precision rate of experiments which speeds up the learning of normal and intrusive patterns and and increases the accuracy of detecting intrusion. By using sFlow collector and analyzer associated with sFlow-RT toolset, the experimental results proved that the SMS enables a defender to classify the network threats with defence strategies and defend network threats.

W. H. Lin - One of the best experts on this subject based on the ideXlab platform.

  • ICEBE - An Efficient Flow Control Approach for SDN-Based Network Threat Detection and Migration Using Support Vector Machine
    2016
    Co-Authors: Ping Wang, H C Lin, K.-m. Chao, W. H. Lin
    Abstract:

    Most existing approaches for solving the network threat problems focus on the specific security mechanisms, for example, network intrusion detection system (NIDS) detection, Firewall Configuration, rather than on flow management approaches to defend network threats with an SDN (Software Defined Networking) architecture. Accordingly, this study proposes an improved behaviour-based SVM (support vector machine) with learning algorithm for use in the security monitoring system (SMS) to categorize network threats for network intrusion detection system. The model also adopted the ID3 decision tree theory to outrank raw features and determine the most qualified features to train support vector classifier (SVC) considering the overall detection precision rate of experiments which speeds up the learning of normal and intrusive patterns and and increases the accuracy of detecting intrusion. By using sFlow collector and analyzer associated with sFlow-RT toolset, the experimental results proved that the SMS enables a defender to classify the network threats with defence strategies and defend network threats.

  • An Efficient Flow Control Approach for SDN-Based Network Threat Detection and Migration Using Support Vector Machine
    2016 IEEE 13th International Conference on e-Business Engineering (ICEBE), 2016
    Co-Authors: Peng Wang, W. H. Lin, K.-m. Chao, H C Lin, C.-c. Lo
    Abstract:

    Most existing approaches for solving the network threat problems focus on the specific security mechanisms, for example, network intrusion detection system (NIDS) detection, Firewall Configuration, rather than on flow management approaches to defend network threats with an SDN (Software Defined Networking) architecture. Accordingly, this study proposes an improved behaviour-based SVM (support vector machine) with learning algorithm for use in the security monitoring system (SMS) to categorize network threats for network intrusion detection system. The model also adopted the ID3 decision tree theory to outrank raw features and determine the most qualified features to train support vector classifier (SVC) considering the overall detection precision rate of experiments which speeds up the learning of normal and intrusive patterns and and increases the accuracy of detecting intrusion. By using sFlow collector and analyzer associated with sFlow-RT toolset, the experimental results proved that the SMS enables a defender to classify the network threats with defence strategies and defend network threats.

K.-m. Chao - One of the best experts on this subject based on the ideXlab platform.

  • ICEBE - An Efficient Flow Control Approach for SDN-Based Network Threat Detection and Migration Using Support Vector Machine
    2016
    Co-Authors: Ping Wang, H C Lin, K.-m. Chao, W. H. Lin
    Abstract:

    Most existing approaches for solving the network threat problems focus on the specific security mechanisms, for example, network intrusion detection system (NIDS) detection, Firewall Configuration, rather than on flow management approaches to defend network threats with an SDN (Software Defined Networking) architecture. Accordingly, this study proposes an improved behaviour-based SVM (support vector machine) with learning algorithm for use in the security monitoring system (SMS) to categorize network threats for network intrusion detection system. The model also adopted the ID3 decision tree theory to outrank raw features and determine the most qualified features to train support vector classifier (SVC) considering the overall detection precision rate of experiments which speeds up the learning of normal and intrusive patterns and and increases the accuracy of detecting intrusion. By using sFlow collector and analyzer associated with sFlow-RT toolset, the experimental results proved that the SMS enables a defender to classify the network threats with defence strategies and defend network threats.

  • An Efficient Flow Control Approach for SDN-Based Network Threat Detection and Migration Using Support Vector Machine
    2016 IEEE 13th International Conference on e-Business Engineering (ICEBE), 2016
    Co-Authors: Peng Wang, W. H. Lin, K.-m. Chao, H C Lin, C.-c. Lo
    Abstract:

    Most existing approaches for solving the network threat problems focus on the specific security mechanisms, for example, network intrusion detection system (NIDS) detection, Firewall Configuration, rather than on flow management approaches to defend network threats with an SDN (Software Defined Networking) architecture. Accordingly, this study proposes an improved behaviour-based SVM (support vector machine) with learning algorithm for use in the security monitoring system (SMS) to categorize network threats for network intrusion detection system. The model also adopted the ID3 decision tree theory to outrank raw features and determine the most qualified features to train support vector classifier (SVC) considering the overall detection precision rate of experiments which speeds up the learning of normal and intrusive patterns and and increases the accuracy of detecting intrusion. By using sFlow collector and analyzer associated with sFlow-RT toolset, the experimental results proved that the SMS enables a defender to classify the network threats with defence strategies and defend network threats.