黑名单
限制
黑名单
计算机科学
计算机安全
工程类
机械工程
作者
Samuel Šuľan,Martin Husák
标识
DOI:10.1145/3538969.3539007
摘要
Blacklists (blocklists, denylists) of network entities (e.g., IP addresses, domain names) are popular approaches to preventing cyber attacks. However, the limited capacity of active network defense devices may not hold all the entries on a blacklist. In this paper, we evaluated two strategies to limit the size of a blacklist and their impact on the blacklist's accuracy. The first strategy is setting the maximal size of a blacklist; the second is setting an expiration time to blacklist items. Short-term attack predictions are typically more precise, and, thus, the recent blacklist entries should be more valuable than older ones. Our experiment shows that the blacklists reduced to half of the size via either strategy achieve only a 25 % drop in accuracy.
科研通智能强力驱动
Strongly Powered by AbleSci AI