Software Architecture for an Intelligent Firewall Based on Linux Netfilter
Sergey Mikhailovich Staroletov · 2022
A firewall is a tool for filtering network traffic passing through a given router or network endpoint. Initially, such systems used to have only static rules that allowed or denied traffic according to specified addresses, ports or protocols. Today, with the complication of information systems and the construction of decentralized IoT systems containing a large number of embedded controllers, there is a need to detect potential anomalies in the transmitted network traffic. Such detection should be performed quickly enough and not require serious hardware resources. After the detection, rules for the firewall should be automatically mined and applied immediately, and they can later be potentially canceled after some new data arrives. In this paper, we discuss the software architecture of a network anomaly detection system. We install a Linux Netfilter hook, in which we capture the traffic and send it to a ring buffer shared with analysis pipelines in the userspace. It allows the system to make reactions in the form of information to the user as well as to mine firewall rules, that are transmitted back to kernel space using Netlink sockets. As for the detectors, we currently use variable-order Markov chains to reveal anomalies in TCP traffic, as wellass elf-organizing K ohonen maps for classifying traffic flows and determining whether it is normal or abnormal. Thus, we briefly describe all software solutions to handle passing traffic frames and analyze them using fast processing techniques.