An event correlation model for real-time attack detection comprising real-time data collection, hierarchical event correlation, and correlation-based intrusion detection

Maosa, Herbert (2023) An event correlation model for real-time attack detection comprising real-time data collection, hierarchical event correlation, and correlation-based intrusion detection. Doctoral thesis, London Metropolitan University.

Abstract

The world is getting more and more interconnected at a rapid pace. This is being facilitated and accelerated by emerging technologies, such as mobile, cloud-based services and Internet of Things. The price of transmission capacity is getting cheaper, with the typical household today connected to the internet through fast links in Europe. With this level of connectedness comes an increased surface for the bad actors to attack, making it vital that efficient mechanisms be put in place to protect users of net-based services.

While Intrusion prevention systems aim at preventing security breaches from occurring in the first place, breaches are still ,occurring at an alarming rate. The recent survey by the UK Government Department for Science, Innovation and technology estimated that in the twelve months leading to April 2023, there were approximately 2.39 million instances of cybercrime and approximately 49,000 instances of fraud as a result of cybercrime in the United Kingdom alone. This makes the case for effective and efficient detection systems more compelling, as clearly not all intrusions can be prevented.

Worse is even the situation that there are 211,939 records in the Common Vulnerabilities and Exposure (CVE) database. This should be a worrying record of vulnerabilities in deployed hardware and software across different operating systems and platforms. Even more concerning is the 45,767 readymade exploits in the publicly accessible exploits database, which make it easy even for actors with little technical know-how to attack systems that exhibit the vulnerabilities recorded in the CVE database.

This research looked at how Intrusion Detection Systems can improve so that threats can be detected and responded to quickly. As a possible solution, the research has developed a conceptual event correlation model for real time attack detection. The uniqueness of the model is that firstly it performs correlations on the events themselves. This is unlike the current approaches where detection systems first raise a high volume of alerts, and then correlation is performed by third party systems on those alerts outside of the IDS. Secondly, the model puts together real time concepts in all the major components of an IDS. The model's key concepts are (1) Real time data collection, (2) Hierarchical Correlation, and (3) Correlation Based Detection. Real Time data collection encompasses additional concepts such as direct data acquisition, event streaming and stream processing. Hierarchical Correlation assembles the best of features of similarity and graph-based correlation techniques to provide an ensemble capability not possible by each one of them individually, while enabling real time analytics. Correlation Based Detection analyses clusters and graph data structures from the correlated events to detect intrusions.

Implementations of each of the model components has been developed as proof of concept and an integrated prototype was developed to test and validate the model. The experiments were based on a case study of the DARPA'99 Intrusion Detection Dataset. The results have successfully validated and affirmed the research hypothesis as the developed Network Probe Detector was able to detect all network probe attacks available in the data set based on the correlated events.

Details
Record
View Item View Item