Understanding Statistical Correlation of Application Security Vulnerability Data from Detection and Monitoring Tools

Santanam Kasturi, Xiaolong Li, John Pickard, Peng Li · 2023

Vulnerability data gathered from multiple detection and monitoring capabilities at different layers of an application using a time-series analysis will provide value and insights by doing a statistical correlation with attack requests observed using a Web Application Firewall (WAF) monitoring solution. Static Analysis Security Testing, Software Composition Analysis, Dynamic Analysis Security Testing (DAST), Application Ethical Hack, Application Programming Interface (API) testing are the tests / scans that have been used to gather vulnerability data for this study. Correlations can further help track abnormal transaction paths if we follow specific ones pointed out by the statistical analysis for those requests that are not blocked by the rules and are allowed as valid transactions to pass through. This provides a narrowed down focus on the convergence of observability and security, critical to realizing a near-real time rapid action. Observations must continue for many days as a time series ensuring consistency and reliability in data collections and analysis. Multiple applications must be observed in a similar manner for ensuring validity of the process for analysis. Also, gathering sufficient data that is large enough to represent a reasonable population of web applications within an organization is a significant factor in achieving reliable correlation. Applying Pearson Correlation (or Spearman Correlation for distributions that are not normal) technique provides insight into Significance (two-tailed) as to whether a correlation is present over large number of data points. Results of analysis show evidence of correlations among specific attack requests monitored by the WAF and corresponding vulnerabilities in applications, detected using one or more methods. This is significant to looking for more insights into how these correlations can further explored into predicting attack patterns based on existing vulnerabilities.

Read the paper · More papers on PaperTik