Return
Explainable Logic-Driven Firewall Anomaly Detection with Knowledge Graph Visualization and Machine Learning Validation
DOI:10.3390/electronics15081714.png)
Abstract
En 中文
Firewall policy misconfigurations remain a major source of security vulnerabilities in modern networks, particularly as firewall rule sets grow in size and complexity. Such misconfigurations, commonly referred to as firewall anomalies, can lead to unintended access control behavior and undermine network security. In this paper, we propose a formal logic rule-based framework for the systematic detection and investigation of firewall anomalies, supported by knowledge graph-based visualization. First-order logic (FOL) is employed to precisely model firewall rules and to define major anomaly types, including shadowing, redundancy, correlation, generalization, and irrelevance, in both single and distributed firewall environments. The proposed framework introduces explicit and comprehensive logical definitions for each anomaly type, enabling deterministic, interpretable, and complete detection of rule conflicts and overlaps. Complex anomalies, particularly correlation and generalization, are systematically decomposed into well-defined logical cases to facilitate the accurate identification of subtle, order-dependent interactions among firewall rules. To enhance usability and analysis, firewall rules and detected anomalies are represented using Neo4j knowledge graphs, providing intuitive visual insights into rule relationships and anomaly causes. The effectiveness of the proposed approach is validated using a real operational backbone network dataset collected from Stanford University’s campus network. Experimental results demonstrate the framework’s ability to accurately detect both simple and complex firewall anomalies under realistic network conditions. To further validate the proposed logic rules, a machine learning-based evaluation was conducted. The findings confirm their effectiveness in accurately characterizing firewall anomalies. Unlike machine learning or heuristic-based methods, the proposed approach does not require training data and guarantees formal correctness and explainability. These features make it a robust and practical solution for firewall policy verification and network security management.
Keywords:
firewall anomaly detection
knowledge graph
firewall policy verification
explainable network security
logistic regression validation
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

