Network Policy Enforcement: An Intrusion Prevention Approach for Critical Infrastructures
Mike Nkongolo, Jacobus Philippus Van Deventer, Sydney Mambwe Kasongo, Werner van der Walt, Roland Kalonji, Michael Pungwe · 2022 6th International Conference on Electronics, Communication and Aerospace Technology · 2022
The recent years have witnessed the growth of network attacks in the Intrusion Detection System (IDS) domain, and zero-day exploits are also increasing at an alarming speed. Generally, the attack aims to weaken the system by using different types of intrusion despite the implementation of various preventive measures. In addition, the prevention scheme faces two problems in terms of unknown traffic detection and false alarm generation. This research study proposes a novel methodology by utilizing the existing IDS configuration with the abnormal properties of an anomaly detection dataset to block the malicious network concerns. The IDS configuration includes abnormal patterns that are used to enforce two network policies named Block URLs and infected sites. These policies incorporate Uniform Resource Locators (URLs), ports, flags, protocols, and Internet addresses. This study found over 60.6 Gbps of Ethernet traffic rejected due to malicious URLs and presents a cybersecurity approach designed to block abnormal concerns using the UGRansome dataset.