Araştırma Makalesi

A Machine Learning-Driven System for Automated Threat Detection and Firewall Rule Management Using Dark Web Intelligence

Cilt: 8 Sayı: 2 24 Aralık 2025
PDF İndir
TR EN

A Machine Learning-Driven System for Automated Threat Detection and Firewall Rule Management Using Dark Web Intelligence

Öz

This paper presents a revolutionary cybersecurity framework that autonomously integrates Dark Web threat intelligence with real-time firewall rule management and machine learning-driven network anomaly detection. The proposed system employs Large Language Models (LLMs) for sophisticated threat intelligence extraction from Dark Web communications, seamlessly integrates with Check Point firewall infrastructures for automated rule validation and generation, and utilizes advanced machine learning algorithms for FortiGate network traffic analysis. Our innovative hybrid approach demonstrates significant performance improvements, achieving 94.7% threat detection accuracy alongside a 68% reduction in false positive rates compared to conventional signature-based detection systems. The framework leverages Google’s Gemini LLM for natural language processing of Dark Web content, automatically cross-references identified threats against existing firewall rule-bases, and generates adaptive security policies in real time. The system implements a multi-layer anomaly detection mechanism using K-Means clustering to establish baseline traffic patterns, and Long Short-Term Memory (LSTM) neural networks for temporal sequence analysis and zero-day threat identification. Comprehensive performance evaluations reveal the system's ability to process over 15,000 network flows per second while maintaining sub-100 millisecond response times for critical threat alerts. Over a 6-month evaluation period, the framework successfully identified 342 unique security threats, including 127 previously unknown attack patterns, 89 zero-day exploit attempts, and 126 advanced persistent threat (APT) indicators. The automated firewall rule generation engine produced 1,847 security policies with 92.3% effectiveness in production environments. The system’s modular architecture enables seamless integration with existing enterprise security infrastructures, delivering enhanced threat visibility, proactive threat mitigation, and fully automated security response coordination across heterogeneous network environments.

Anahtar Kelimeler

Kaynakça

  1. MITRE Corporation, “MITRE ATT&CK® Framework,” tech. rep., MITRE Corporation, 2024.
  2. NIST, “Cybersecurity Framework 2.0,” Tech. Rep. NIST CSF 2.0, National Institute of Standards and Technology, 2023.
  3. IBM Security, “Cost of a Data Breach Report 2024,” tech. rep., IBM Corporation, 2024.
  4. Schafer, M., Fuchs, M., Strohmeier, M., Engel, M., Liechti, M., Lenders, V. , “BlackWidow: Monitoring the Dark Web for Cyber Security Information,” 2023.
  5. D. Bringhenti, G. Marchetto, R. Sisto, F. Valenza, and J. Yusupov, “Automatic Allocation and Configuration of Packet Filters in Virtual Networks,” IEEE Transactions on Dependable and Secure Computing, vol. 20, no. 2, pp. 1559–1572, 2023.
  6. J. Cannady and J. Harrell, “A comparative analysis of current intrusion detection technologies,” in Proceedings of the Fourth Technology for Information Security Conference, vol. 96, May 1996.
  7. G. Gonza´lez-Granadillo, S. Gonza´lez-Zarzosa, and R. Diaz, “Security information and event management (SIEM): analysis, trends, and usage in critical infrastructures,” Sensors, vol. 21, no. 14, p. 4759, 2021.
  8. J. Wang, L. Yang, J. Wu, and J. H. Abawajy, “Clustering analysis for malicious network traffic,” in 2017 IEEE International Conference on Communications (ICC), pp. 1–6, IEEE, May 2017.

Ayrıntılar

Birincil Dil

İngilizce

Konular

Makine Öğrenme (Diğer)

Bölüm

Araştırma Makalesi

Yayımlanma Tarihi

24 Aralık 2025

Gönderilme Tarihi

4 Ağustos 2025

Kabul Tarihi

7 Kasım 2025

Yayımlandığı Sayı

Yıl 2025 Cilt: 8 Sayı: 2

Kaynak Göster

APA
Çarkçı, Y., Sayar, A., Ertuğrul, S., Demircan, G., & Ertuğrul, B. (2025). A Machine Learning-Driven System for Automated Threat Detection and Firewall Rule Management Using Dark Web Intelligence. Veri Bilimi, 8(2), 49-69. https://izlik.org/JA93FD68SR
AMA
1.Çarkçı Y, Sayar A, Ertuğrul S, Demircan G, Ertuğrul B. A Machine Learning-Driven System for Automated Threat Detection and Firewall Rule Management Using Dark Web Intelligence. Veri Bilim Derg. 2025;8(2):49-69. https://izlik.org/JA93FD68SR
Chicago
Çarkçı, Yasin, Alperen Sayar, Seyit Ertuğrul, Gorkem Demircan, ve Boran Ertuğrul. 2025. “A Machine Learning-Driven System for Automated Threat Detection and Firewall Rule Management Using Dark Web Intelligence”. Veri Bilimi 8 (2): 49-69. https://izlik.org/JA93FD68SR.
EndNote
Çarkçı Y, Sayar A, Ertuğrul S, Demircan G, Ertuğrul B (01 Aralık 2025) A Machine Learning-Driven System for Automated Threat Detection and Firewall Rule Management Using Dark Web Intelligence. Veri Bilimi 8 2 49–69.
IEEE
[1]Y. Çarkçı, A. Sayar, S. Ertuğrul, G. Demircan, ve B. Ertuğrul, “A Machine Learning-Driven System for Automated Threat Detection and Firewall Rule Management Using Dark Web Intelligence”, Veri Bilim Derg, c. 8, sy 2, ss. 49–69, Ara. 2025, [çevrimiçi]. Erişim adresi: https://izlik.org/JA93FD68SR
ISNAD
Çarkçı, Yasin - Sayar, Alperen - Ertuğrul, Seyit - Demircan, Gorkem - Ertuğrul, Boran. “A Machine Learning-Driven System for Automated Threat Detection and Firewall Rule Management Using Dark Web Intelligence”. Veri Bilimi 8/2 (01 Aralık 2025): 49-69. https://izlik.org/JA93FD68SR.
JAMA
1.Çarkçı Y, Sayar A, Ertuğrul S, Demircan G, Ertuğrul B. A Machine Learning-Driven System for Automated Threat Detection and Firewall Rule Management Using Dark Web Intelligence. Veri Bilim Derg. 2025;8:49–69.
MLA
Çarkçı, Yasin, vd. “A Machine Learning-Driven System for Automated Threat Detection and Firewall Rule Management Using Dark Web Intelligence”. Veri Bilimi, c. 8, sy 2, Aralık 2025, ss. 49-69, https://izlik.org/JA93FD68SR.
Vancouver
1.Yasin Çarkçı, Alperen Sayar, Seyit Ertuğrul, Gorkem Demircan, Boran Ertuğrul. A Machine Learning-Driven System for Automated Threat Detection and Firewall Rule Management Using Dark Web Intelligence. Veri Bilim Derg [Internet]. 01 Aralık 2025;8(2):49-6. Erişim adresi: https://izlik.org/JA93FD68SR