Optimizing Real-Time Performance in ML-Based Application Layer Firewalls
摘要
The integration of machine learning (ML) into web application firewalls (WAFs) presents a promising avenue for bolstering security frameworks in the context of ever-evolving cyber-threats, yet faces significant hurdles in scalability and latency, particularly for web-scale applications. This study embarks on a performance evaluation of ML-based firewall systems, with an emphasis on comparing inference latency characteristics of models based on a number of popular algorithms. The endeavor seeks to unravel the complexities associated with latency and scalability issues endemic to these models through comprehensive analysis in simulated large-scale scenarios. The core objective was to unearth effective methodologies that harmonize the dichotomy between accuracy and operational efficiency within ML-based firewall systems. A comparative analysis of a diverse set of algorithms yields insights that are pivotal for the developments of advanced adaptive systems that are practical and economical at scale. Among the findings, the expedited latency capabilities of support vector machines (SVM) were brought to light, positioning them as vital components for the enhancement of real-world security applications. The SVM-based model trained in the study yielded a latency of 7.3 \(\times 10^{-7}\) sec per inference, outperforming the closest model in terms of accuracy by a factor of 3. Such observations not only highlight the adeptness of the SVM in mitigating latency issues but also accentuate the significance of algorithmic selection in the crafting of ML-based firewall systems that cater to the exigencies of high-traffic scenarios. Consequently, this research advances the comprehension of ML-driven strategies in cybersecurity and underscores the imperative for crafting scaleable and efficient mechanisms to robustly protect web applications.