Inventors:
Carey Nachenberg - Northridge CA, US
Abu Wawda - Los Angeles CA, US
Adam Bromwich - Santa Monica CA, US
On Lee - Redmond WA, US
Darren Sanders - Santa Clarita CA, US
Assignee:
Symantec Corporation - Cupertino CA
International Classification:
G06F 7/00
Abstract:
An incident managing module aggregates related database intrusion incidents and presents them in a manageable manner. A receiving module receives an anomalous query requesting data from a database and a type-identification module identifies anomaly type for the query received. A conversion module converts the anomalous query into a characteristic representation. In some embodiments, this is done by replacing literal field values in the query with representative values. In other embodiments, this is done by creating a tuple describing anomaly parameters for the anomalous query. In still other embodiments, the query is converted into a characteristic representation that distinguishes between injected and non-injected portions of the query. An aggregation module then aggregates into a group the anomalous queries with substantially similar characteristic representations according to anomaly type and a generation module generates a database intrusion incident report describing the group of anomalous queries.