A Comprehensive Protection Method for Securing the Organization's Network Against Cyberattacks
Ghassan Kbar, Ammar Alazab · 2019
Firewalls, and intrusion detection that are based on rule or anomaly detection can be used to protect the system against cyberattacks. This would help in detecting known attacks as well as unknown or zero type of attacks. However, the accuracy of such system depends on the list of known attacks, and the type of algorithms been implemented for the anomaly detection, as well as the attributes being analyzed by the algorithms. Different researches have been proposed to minimize the false report generated by the Anomaly Intrusion Detection (AID). But they couldn't adjust the behavior of AID in real time to reduce the faulty results. In this paper a comprehensive protection method is used to secure organizations against cyberattacks. This method used a Honeypot Intrusion Detection (HID) along with Anomaly Detection Controller (ADC), and prevention firewall to test the attacks at different level when accessing the network. The results from HID and ADC are used to update a Prevention Firewall (PF). The PF verifies these results to detect the false positive and false negative as well to detecting real at-tacks. This will help in controlling the traffic by blocking the detected attacks and updating the ADC to correct its behavior in order to reduce the false positive and false negative. This will lead to a better performance when dealing with future traffic coming from the reported faulty sources that were blocked by the ADC.