Options
Prototype application to detect malicious network traffic with case-based reasoning and SEASALT
Abstract
The amount of criminal online activities rises. Protective measures such as firewalls and intrusion detection systems are being actively developed. We accompany this development by offering a case-based reasoning prototype to detect similar attacks based on previous cases. The instantiation of the SEASALT framework allows us to distinguish between two different views on network traffic: the request itself, and the traffic overall. Here, the focus has been set on SQL-injections and cross site scripting - two of the most commonly used attack vectors in the last decade 1 . As we store cases containing these attacks, we are able to detect slightly similar attacks, which would be difficult to detect, for example, by a set of rules. Depending on the use-case, we identified up to 16 relevant attributes, predominantly text attributes. However, the similarity assessment needs improvement to reduce the rate of false-positives.
Publication Type
ConferencePaper
Editor • • •
Borck, Hayley
Eisenstadt, Viktor
Sánchez-Ruiz, Antonio
Floyd, Michael
Date Issued
2021
Faculty
Institute / Institution
Published in
ICCBR-WS 2021: ICCBR 2021 Workshop Proceedings
Conference
29th International Conference on Case-Based Reasoning, online, 13.09.-16.09.2021
Publisher
CEUR-WS
Page Start
92
Page End
93
Series Name
CEUR Workshop Proceedings
Issue Number
3017
Link to the original publication
HilPub short link