Classification of Firewall Log Files with Multiclass Support Vector Machine
| dc.contributor.author | Ertam, Fatih | |
| dc.contributor.author | Kaya, Mustafa | |
| dc.date.accessioned | 2026-08-12T16:41:28Z | |
| dc.date.issued | 2018 | |
| dc.department | Fırat Üniversitesi | |
| dc.description | 6th International Symposium on Digital Forensic and Security (ISDFS) -- MAR 22-25, 2018 -- Antalya, TURKEY | |
| dc.description.abstract | It is very important to analyze the logs on the Firewall devices and control the internet traffic according to these analysis results. In this study, some logs obtained with the Firewall Device used at Firat University are classified using multiclass support vector machine (SVM) classifier. Linear, polynomial, sigmoid and Radial Basis Function (RBF) functions are used as the activation function for SVM classification. In order to measure the performance of the classifier, the comparison was made by finding the measurement values of sensitivity, recall and their harmonic mean F-1 Score. In this study, 65532 instances have been examined using 11 features. The feature that characterizes any personal data in the selected data has not been used. The Action attribute is selected as the class from these attributes. The allow, deny, drop and reset-both parameters have been implemented for the Action class. Activation functions have been tried and the SVM responses have been evaluated so as to obtain the maximum recall and precision values in the SVM classifier. It was tried to obtain the best activation function for F-1 score value. Receiver Operating Characteristic (ROC) curves were also created for each of the classes. At the end of the study, the activation functions from which the desired SVM responses are obtained are given by comparison. | |
| dc.description.sponsorship | IEEE Turkey Sect,Firat Univ,Sam Houston State Univ,Gazi Univ,Univ Arkanas Little Rock,Polytechn Inst Cavado & Ave,Havelsan,Balikesir Univ,Hacettepe Univ,Youngstown State Univ,Baskent Univ,Petru Maior Univ | |
| dc.identifier.endpage | 366 | |
| dc.identifier.isbn | 978-1-5386-3449-3 | |
| dc.identifier.orcid | 0000-0002-9736-8068 | |
| dc.identifier.scopus | 2-s2.0-85050959729 | |
| dc.identifier.scopusquality | N/A | |
| dc.identifier.startpage | 363 | |
| dc.identifier.uri | https://hdl.handle.net/11508/45847 | |
| dc.identifier.wos | WOS:000434247400069 | |
| dc.identifier.wosquality | N/A | |
| dc.indekslendigikaynak | Web of Science | |
| dc.indekslendigikaynak | Scopus | |
| dc.language.iso | en | |
| dc.publisher | Ieee | |
| dc.relation.ispartof | 2018 6Th International Symposium on Digital Forensic and Security (Isdfs) | |
| dc.relation.publicationcategory | Konferans Öğesi - Uluslararası - Kurum Öğretim Elemanı | |
| dc.rights | info:eu-repo/semantics/closedAccess | |
| dc.snmz | KA_WoS_20260511 | |
| dc.subject | Classification | |
| dc.subject | network forensics | |
| dc.subject | log analysis | |
| dc.subject | firewall | |
| dc.subject | network security | |
| dc.title | Classification of Firewall Log Files with Multiclass Support Vector Machine | |
| dc.type | Conference Object |







