An Ensemble Approach for Firewall Log Classification using Stacked Machine Learning Models
Clicks: 3
ID: 312785
2025
Article Quality & Performance Metrics
Overall Quality
Not rated
Combines reader engagement with the AI quality analysis. This
article has not been analysed, so there is no overall score —
reader engagement is measured and shown alongside.
Reader Engagement
Emerging Content
0.6
/100
3 views
2 readers
AI Quality Assessment
Not analyzed
Readership in this journal
EmergingRanked #31 of 705 articles by views in Journal of Computing & Biomedical Informatics
Most read
Least read
Bar heights use a square-root scale. Only the 120 most-read articles are drawn; the journal has 705 in total.
Mint this article as an NFT
Not yet mintedCreate a permanent, verifiable on-chain record of this article on the Scimatic Network. The NFT is held in your Journament account, and you can withdraw it to your own wallet at any time.
5
SUSD
one-off · no wallet required
Abstract
Firewall logs are still challenging to evaluate, while being important data sources. Machine Learning has become a popular technology for creating strong security measures because of their ability to react quickly to complicated attacks. Firewall logs generate high-volume, complex, and often imbalanced data, where malicious activities are rare compared to normal traffic. The challenge is further compounded by the dynamic nature of cyber threats and the presence of noise or redundant information in the logs. In this research, a stacking classifier called Decision Tree Classifier + Bagging Classifier (DB) for Firewall logs is proposed using the ensemble machine learning models. A comparison is performed to evaluate the classifier's overall performance based on F1-score, accuracy, precision, and recall. A firewall that was set up with Snort and TWIDS had its logs taken. The 65532 occurrences of the receiving log record include a total of 12 attributes. Creating multi-class machine learning models that can analyze the firewall logs dataset and classify the necessary actions in response to learned classes as "Reset-both," "Allow," "Deny," or "Drop". For assessment, a variety of machine learning methods have been used, such as Random Forest, K-Nearest Neighbor, Logistic Regression, and AdaBoost Classifier. The experiment's 99.89% accuracy rate for the proposed model using stacking classifier DB is an interesting interpretation of the findings. However, the high accuracy rates produced as compared to other algorithms show that the recommended points were crucial in increasing the firewall classification rate.
| Reference Key |
imported_1777056815_69ebbc2f91465
Use this key to autocite in the manuscript while using
SciMatic Manuscript Manager or Thesis Manager
|
|---|---|
| Authors | Mudasir Ali, Muhammad Faheem Mushtaq, Urooj Akram, Shabana Ramzan, Saba Tahir, Muhammad Ahsan |
| Journal | Journal of Computing & Biomedical Informatics |
| Year | 2025 |
| DOI |
DOI not found
|
| URL | |
| Keywords | Keywords not found |
Citations
No citations found. To add a citation, contact the admin at info@scimatic.org
Comments
No comments yet. Be the first to comment on this article.