• DocumentCode
    3085713
  • Title

    Event-Based Alert Correlation System to Detect SQLI Activities

  • Author

    Alserhani, Faeiz ; Akhlaq, Monis ; Awan, Irfan U. ; Cullen, Andrea J.

  • Author_Institution
    Inf. Res. Inst., Univ. of Bradford, Bradford, UK
  • fYear
    2011
  • fDate
    22-25 March 2011
  • Firstpage
    175
  • Lastpage
    182
  • Abstract
    Alerts correlation techniques have been widely used to provide intelligent and stateful detection methodologies. This is to understand attack steps and predict the expected sequence of events. However, most of the proposed systems are based on rule - based mechanisms which are tedious and error prone. Other methods are based on statistical modeling, these are unable to identify causal relationships between the events. In this paper, we have identified the limitations of the current techniques and propose a model for alert correlation that overcomes the shortcomings. An improved "require/provide" model is presented which established a cooperation between statistical and knowledge-based model, to achieve higher detection rate with the minimal false positives. A knowledge-based model with vulnerability and extensional conditions provide manageable and meaningful attack graphs. The proposed model has been implemented in real-time and has successfully generated security events on establishing a correlation between attack signatures. The system has been evaluated to detect one of the most serious multi-stage attacks in cyber crime -- SQLIA (SQL Injection Attack). Typical SQLIA steps are analyzed within the realm of simulated malicious activities normally used by cyber criminals. The system has efficiently established a correlation in attack behaviors and has generated an attack map. The map can be used to discretely analyze the correlated attack activities which in other case may go undetected thus facilitating the multi-stage attack recognition process.
  • Keywords
    SQL; security of data; statistical analysis; SQL injection attack; SQLI activities; attack signatures; cyber crime; event based alert correlation system; knowledge based model; rule based mechanisms; statistical modeling; Correlation; Databases; Knowledge based systems; Mars; Probabilistic logic; Real time systems; Security; Alerts correlation; Network intrusion detection systems; SQL Injection; multi-stage attac;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications (AINA), 2011 IEEE International Conference on
  • Conference_Location
    Biopolis
  • ISSN
    1550-445X
  • Print_ISBN
    978-1-61284-313-1
  • Electronic_ISBN
    1550-445X
  • Type

    conf

  • DOI
    10.1109/AINA.2011.102
  • Filename
    5763386