Enhancing community SQL injection rule in intrusion detection system using snort with email notifications / Nur Athirah Noor Mohamad, Noor Ashitah Abu Othman and Mohd Hafifi Mohd Supir

Noor Mohamad, Nur Athirah and Abu Othman, Noor Ashitah and Mohd Supir, Mohd Hafifi (2024) Enhancing community SQL injection rule in intrusion detection system using snort with email notifications / Nur Athirah Noor Mohamad, Noor Ashitah Abu Othman and Mohd Hafifi Mohd Supir. Progress in Computer and Mathematics Journal (PCMJ), 1. pp. 124-137. ISSN 3030-6728 (Submitted)

Abstract

This project focuses on enhancing the precision and recall rates of community-based intrusion detection systems, specifically targeting SQL injection attacks within the context of Snort. The study involves the integration of modified rules employing PCRE (Perl Compatible Regular Expressions) and fast pattern matching to improve the accuracy and performance of the intrusion detection system. Experimental results demonstrate a notable reduction in false positives and a perfect recall rate, showcasing the efficacy of the enhanced rules. The virtualized testing environment, comprising a Snort-protected server, a simulated attacker using Kali Linux and Metasploitable 2, and a vulnerable system facilitates a thorough evaluation of Snort's response to cyber threats. While acknowledging limitations and the controlled nature of the testing, this research emphasizes the importance of leveraging advanced technologies to fortify intrusion detection systems against evolving cybersecurity challenges. The incorporation of PCRE and fast pattern matching stands as a significant contribution to improving rule matching accuracy and overall system efficiency in the dynamic landscape of cybersecurity.

Metadata

Item Type: Article
Creators:
Creators
Email / ID Num.
Noor Mohamad, Nur Athirah
athrhmohd@gmail.com
Abu Othman, Noor Ashitah
noor2106@uitm.edu.my
Mohd Supir, Mohd Hafifi
hafifisupir@uitm.edu.my
Contributors:
Contribution
Name
Email / ID Num.
Editor
Ahmad Fadzil, Ahmad Firdaus
UNSPECIFIED
Editor
Abu Samah, Khyrina Airin Fariza
UNSPECIFIED
Editor
Md Saidi, Raihana
UNSPECIFIED
Editor
Saad, Shahadan
UNSPECIFIED
Editor
Jamil Azhar, Sheik Badrul Hisham
UNSPECIFIED
Editor
Zamzuri, Zainal Fikri
UNSPECIFIED
Editor
Ahmad Fesol, Siti Feirusz
UNSPECIFIED
Editor
Hamzah, Salehah
UNSPECIFIED
Editor
Hamzah, Raseeda
UNSPECIFIED
Editor
Arshad, Mohamad Asrol
UNSPECIFIED
Editor
Mohd Supir, Mohd Hafifi
UNSPECIFIED
Editor
Mat Zain, Nurul Hidayah
UNSPECIFIED
Subjects: T Technology > T Technology (General) > Integer programming
Divisions: Universiti Teknologi MARA, Melaka > Jasin Campus > Faculty of Computer and Mathematical Sciences
Journal or Publication Title: Progress in Computer and Mathematics Journal (PCMJ)
ISSN: 3030-6728
Volume: 1
Page Range: pp. 124-137
Keywords: Snort; SQL injection; PCRE; Fast pattern; Precision rate; Recall rate
Date: October 2024
URI: https://ir.uitm.edu.my/id/eprint/105867
Edit Item
Edit Item

Download

[thumbnail of 105867.pdf] Text
105867.pdf

Download (973kB)

ID Number

105867

Indexing

Statistic

Statistic details