Event Based Alert Correlation System to Detect SQLI Activities and Prevention Using Stored Procedure Mechanism |
Author(s): |
Nilesh Kasurde , Bharti Vidyapeeth College of Engineering, Kharghar, Navi Mumbai - 400614; Rahul Patil, Bharti Vidyapeeth College of Engineering, Kharghar, Navi Mumbai - 400614; Aniket Deshpande, Bharti Vidyapeeth College of Engineering, Kharghar, Navi Mumbai - 400614 |
Keywords: |
Network intrusion detection systems, Alerts correlation, multi-stage attack, SQL Injection, stored procedures |
Abstract |
Alerts correlation techniques have been widely used to provide intelligent and stateful detection methodologies. This is to understand attack steps and predict the expected sequence of events. However, most of the proposed systems are based on rule –based mechanisms which are tedious and error prone. Other methods are based on statistical modeling, These are unable to identify causal relationships between the events. In this paper, we have identified the limitations of the current techniques and propose a model for alert correlation that overcomes the shortcomings. The proposed model has been implemented in real-time and has successfully generated security events on establishing a correlation between attack signatures. The system has been evaluated to detect one of the most serious multi-stage attacks in Cyber-Crime – SQLIA (SQL Injection Attack). Typical SQLIA steps are analyzed within the realm of simulated malicious activities normally used by cyber criminals. SQL Injection attacks target databases that are accessible through a web front-end, and take advantage of flaws in the input validation logic of Web components such as CGI scripts. SQL Injection attacks can be easily prevented by more secure authentication schemes in login phase itself. |
Other Details |
Paper ID: IJSRDV2I1315 Published in: Volume : 2, Issue : 1 Publication Date: 01/04/2014 Page(s): 752-754 |
Article Preview |
|
|