A Framework for Security Components Anomalies Severity Evaluation and Classification
Karim Karoui, Fakher Ben Ftima, Henda Ben Ghézala · International Journal of Network Security & Its Applications · 2013
Security components such as firewalls, IDS and IPS, are the most widely adopted security devices for network protection.These components are often implemented with several errors (or anomalies) that are sometimes critical.To ensure the security of their networks, administrators should detect these anomalies and correct them.Before correcting the detected anomalies, the administrator should evaluate and classify these latter to determine the best strategy to correct them.In this work, we propose a framework to assess and classify the detected anomalies using a three evaluation criteria: a quantitative evaluation, a semantic evaluation and multi-anomalies evaluation.The proposed process, convenient in an audit process, will be detailed by a case study to demonstrate its usefulness.