Attack Analytics Module for Web Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current web application layer attack detectors generate a high volume of security alerts, making it difficult to identify and classify community attacks efficiently, which are often masked among targeted and other types of attacks, posing a risk to web application security.

Innovation Solution

Implementing an attack analytics module that uses machine learning and clustering/rule-based algorithms to correlate and classify security alerts across multiple enterprise networks, identifying community attacks by grouping similar incidents and determining their industry or spray-and-pray nature.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If web application layer attack detectors scan all requests for potential attacks, then security detection coverage is improved, but the volume of security alerts generated increases making analysis difficult

Engineering Contradiction:
Improvesecurity detection coverageVSAvoidvolume of security alerts
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines security alerts from multiple enterprise networks into unified groups based on similarity analysis. By merging related alerts that share common characteristics (attack patterns, sources, targets), the system reduces the total number of individual alerts analysts must examine while maintaining comprehensive security coverage across the enterprise network.

Inventive Principle:
Principle #5Merging (Combining)

2Productivity

If machine learning techniques are used to correlate security alerts, then the speed of alert analysis is improved, but the complexity of the analysis system increases

Engineering Contradiction:
Improvespeed of alert analysisVSAvoidcomplexity of analysis system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an attack analytics module as an intermediary layer between the web application layer attack detectors and the analysts. This module automatically performs machine learning-based correlation and grouping of security alerts, translating raw alert data into organized attack groups that are easier to analyze, thereby speeding up analysis without requiring analysts to directly manage the complex machine learning system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If community attacks are identified and classified, then prioritization of security threats is improved, but the difficulty of detecting and measuring community attacks among other attacks increases

Engineering Contradiction:
Improveprioritization of security threatsVSAvoiddifficulty of detecting community attacks
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies different analysis criteria and grouping rules to different types of security alerts based on their local characteristics. By analyzing specific features of each alert (such as source IP patterns, target vulnerabilities, attack methodologies) and applying appropriate classification rules, the system can identify and prioritize community attacks that exhibit distinctive patterns different from targeted attacks, making detection more manageable despite the diversity of attack types.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11470110B2Identifying and classifying community attacks
Publication Date: 2022.10.11 IMPERVA INC
  • US11470110B2 patent drawing
  • US11470110B2 patent drawing
  • US11470110B2 patent drawing

AI summary

A method by one or more electronic devices for identifying and classifying community attacks. The method includes determining, for each of a plurality of enterprise networks, one or more incidents occurring in that enterprise network based on analyzing security alerts generated by a web application layer attack detector used to protect a web application hosted in that enterprise network, where each incident represents a group of security alerts that have been determined as being associated with the same security event, grouping incidents occurring across the plurality of enterprise networks into groups of incidents, where incidents that are determined as having similar features are grouped into the same group of incidents, and classifying each of one or more of the groups of incidents as being an industry-based attack or a spray-and-pray attack based on industry classifications of incidents within that group of incidents.