Attack Analytics Module for Web Application Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current web application layer attack detectors generate a high volume of security alerts, making it difficult to identify and classify community attacks efficiently, which are often masked among targeted and other types of attacks, posing a risk to web application security.
Innovation Solution
Implementing an attack analytics module that uses machine learning and clustering/rule-based algorithms to correlate and classify security alerts across multiple enterprise networks, identifying community attacks by grouping similar incidents and determining their industry or spray-and-pray nature.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If web application layer attack detectors scan all requests for potential attacks, then security detection coverage is improved, but the volume of security alerts generated increases making analysis difficult
Solution Approach 1:
The patent combines security alerts from multiple enterprise networks into unified groups based on similarity analysis. By merging related alerts that share common characteristics (attack patterns, sources, targets), the system reduces the total number of individual alerts analysts must examine while maintaining comprehensive security coverage across the enterprise network.
2Productivity
If machine learning techniques are used to correlate security alerts, then the speed of alert analysis is improved, but the complexity of the analysis system increases
Solution Approach 1:
The patent introduces an attack analytics module as an intermediary layer between the web application layer attack detectors and the analysts. This module automatically performs machine learning-based correlation and grouping of security alerts, translating raw alert data into organized attack groups that are easier to analyze, thereby speeding up analysis without requiring analysts to directly manage the complex machine learning system.
3Ease of operation
If community attacks are identified and classified, then prioritization of security threats is improved, but the difficulty of detecting and measuring community attacks among other attacks increases
Solution Approach 1:
The patent applies different analysis criteria and grouping rules to different types of security alerts based on their local characteristics. By analyzing specific features of each alert (such as source IP patterns, target vulnerabilities, attack methodologies) and applying appropriate classification rules, the system can identify and prioritize community attacks that exhibit distinctive patterns different from targeted attacks, making detection more manageable despite the diversity of attack types.
Data Source
AI summary
A method by one or more electronic devices for identifying and classifying community attacks. The method includes determining, for each of a plurality of enterprise networks, one or more incidents occurring in that enterprise network based on analyzing security alerts generated by a web application layer attack detector used to protect a web application hosted in that enterprise network, where each incident represents a group of security alerts that have been determined as being associated with the same security event, grouping incidents occurring across the plurality of enterprise networks into groups of incidents, where incidents that are determined as having similar features are grouped into the same group of incidents, and classifying each of one or more of the groups of incidents as being an industry-based attack or a spray-and-pray attack based on industry classifications of incidents within that group of incidents.


