Detection of Botnet Multi-Stage Attack By Using Alert Correlation Model

Mohammed Alnas, Abdalla M. Hanashi, Elmabruk Laias · 2013

Network Intrusion Detection Systems (NIDS) are considered as one of the essential mechanisms to ensure reliable security. Intrusive model is used in signature-based NIDS by defining attack patterns and applying signature-matching on incoming packets. However, detection of novel and multi-stage attacks are not efficiently achieved by the signature-based systems. This is due to lack of mechanism to perform sophisticated analysis to identify relationship between attack events. Hence, the systematic analysis of attack initiation has become a stressing demand in current research. Alerts correlation techniques have been widely used to provide intelligent and stateful detection methodologies. This is to understand attack steps and predict the expected sequence of events. However, most of the proposed systems are based on rule –based mechanisms which are tedious and error prone. Other methods are based on statistical modeling; these are unable to identify causal relationships between the events.In this paper, we have identified the limitations of the current techniques and propose a model for alert correlation that overcomes the shortcomings. An improved “require/provide ” model is presented which established a cooperation between statistical and knowledge-based model, to achieve higher detection rate with the minimal false positives. A knowledge-based model with vulnerability and extensional conditions provide manageable and meaningful attack graphs. The proposed model has been implemented in real-time and has successfully generated security events on establishing a correlation between attack

Read the paper · More papers on PaperTik