Detection of DoS attack and zero day threat with SIEM
K. Sornalakshmi · 2017
SIEM (Security Information and Event Management) aims at collecting log information from multiple sources and correlate the events to filter malicious activity or attacks. The proposed SIEM tool is a combination of 2 different sub-modules which are used to monitor network as well as physical systems. In this work, we propose a SIEM tool to detect one of the most dangerous network attack - Denial of Service (DoS) by using only log monitoring. There are few methods available to detect and traverse back to the source of DoS attack, but here we propose the tool that can detect the possible DoS attack by monitoring the web server logs and alert as soon as possible with a lowest false negative. We specify different predefined combinations of rules for the log analysis based on which the alert can be generated for DoS attack. Another module using SIEM is used to detect the zero-day threat in the system. Here, we propose a solution which says that monitoring the modification in few of the common system parameters which may be the result of the some malicious application running in the system. So, we propose a module that will monitor the change in those parameters and will generate alerts based on the specified rules.