{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/learning-to-customize-network-security-rules","title":"Learning to Customize Network Security Rules","arxiv_id":"1712.09795","date":"2017-12-28","proceeding":null,"authors":["Michael Bargury","Roy Levin","Royi Ronen"],"abstract":"Security is a major concern for organizations who wish to leverage cloud\ncomputing. In order to reduce security vulnerabilities, public cloud providers\noffer firewall functionalities. When properly configured, a firewall protects\ncloud networks from cyber-attacks. However, proper firewall configuration\nrequires intimate knowledge of the protected system, high expertise and\non-going maintenance.\n  As a result, many organizations do not use firewalls effectively, leaving\ntheir cloud resources vulnerable. In this paper, we present a novel supervised\nlearning method, and prototype, which compute recommendations for firewall\nrules. Recommendations are based on sampled network traffic meta-data (NetFlow)\ncollected from a public cloud provider. Labels are extracted from firewall\nconfigurations deemed to be authored by experts. NetFlow is collected from\nnetwork routers, avoiding expensive collection from cloud VMs, as well as\nrelieving privacy concerns.\n  The proposed method captures network routines and dependencies between\nresources and firewall configuration. The method predicts IPs to be allowed by\nthe firewall. A grouping algorithm is subsequently used to generate a\nmanageable number of IP ranges. Each range is a parameter for a firewall rule.\n  We present results of experiments on real data, showing ROC AUC of 0.92,\ncompared to 0.58 for an unsupervised baseline. The results prove the hypothesis\nthat firewall rules can be automatically generated based on router data, and\nthat an automated method can be effective in blocking a high percentage of\nmalicious traffic.","url_abs":"http://arxiv.org/abs/1712.09795v1","url_pdf":"http://arxiv.org/pdf/1712.09795v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"learning-to-customize-network-security-rules","repo_url":"https://github.com/mibarg/IP-Grouping","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":null}],"tasks":[{"task_slug":"blocking","task_name":"Blocking"},{"task_slug":"cloud-computing","task_name":"Cloud Computing"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}