Analysis of Classification Models of Firewall Log Data Attacked by Data Poisoning and Evasion Attacks

Nayotsakorn Permpoon, Titichaya Thanamitsomboon, Kanticha Kittipeerachon · 2024

This research explores vulnerabilities in machine learning classification models applied to firewall log data, specifically examining susceptibility to data poisoning and evasion attacks. The main objective is to evaluate the robustness of different algorithms when classifying firewall logs under adversarial conditions. The study assesses each model's accuracy in classifying log actions and introduces deliberate data poisoning and evasion attacks. The results highlight significant variations in model resilience. Notably, the Artificial Neural Network (ANN) demonstrates exceptional performance, maintaining a comparatively accuracy even after being subjected to data poisoning. In contrast, the rest model experiences a substantial drop in accuracy, indicating its vulnerability to such attacks. Additionally, evasion attacks impact model performance differently. Despite the evasion attack, the ANN consistently maintains the same accuracy, showcasing its steadfast nature. Conversely, the rest model witnesses a notable decrease in accuracy after evasion attack especially the decision tree model. These findings provide valuable insights into the comparative resilience of machine learning models against data poisoning and evasion attacks in the context of firewall log classification. The research underscores the importance of selecting robust algorithms to enhance the security of network systems amidst evolving cyber threats.

Read the paper · More papers on PaperTik