DOI: 10.3390/app15062979 ISSN: 2076-3417

Development of an Anomaly Classification Model and a Decision Support Tool for Firewall Policy Configuration

Jinyong Park, Byeongjo Park, Tae-Sung Kim

A firewall is a device that is used generally to prevent cyberattacks and protect internal assets by blocking unauthorized access. Information security managers have many difficulties in managing firewall policies due to errors or anomalies in the policy that are caused by frequent internal and external requests. This paper intends to develop an anomaly classification model to detect anomalies and measure the priority of resolution in firewall policy as well as a visualized tool that supports information security managers to manage their firewall policy efficiently. This model and tool help information security managers resolve anomalies in firewall policy, enable efficient firewall policy management, and protect internal assets effectively.

More from our Archive