>
Fa   |   Ar   |   En
   A Hybrid Approach For Database Intrusion Detection At Transaction and Inter-Transaction Levels  
   
نویسنده Doroudian Mostafa ,Shahriari Hamid Reza
منبع The Isc International Journal Of Information Security - 2014 - دوره : 6 - شماره : 2 - صفحه:155 -167
چکیده    Nowadays, information plays an important role in organizations. sensitive information is often stored in databases. traditional mechanisms such as encryption, access control, and authentication cannot provide a high level of confidence. therefore, the existence of intrusion detection systems in databases are necessary. in this paper, we propose an intrusion detection system for detecting attacks in both database transaction level and inter-transaction level (user task level). for this purpose, we propose a detection method at transaction level, which is based on describing the expected transactions within the database applications. then at inter-transaction level, we propose a detection method that is based on anomaly detection and uses data mining to find dependency and sequence rules. the main advantage of this system, in comparison with the previous database intrusion detection systems, is that it can detect malicious behaviors in both transaction and inter-transaction levels. also, it gains advantages of a hybrid method, including specification-based detection and anomaly detection, to minimize both false positive and false negative alarms. in order to evaluate the accuracy of the proposed system, some experiments have been done. the experiment results demonstrate that the true positive rate (recall metric) is higher than 80%, and the false positive rate is lower than 10% per different data sets and choosing appropriate ranges for support and confidence thresholds. the experimental evaluation results show high accuracy and effectiveness of the proposed system.
کلیدواژه Intrusion Detection ,Database Security ,State Machine ,Inter-Transaction Dependency ,Inter-Transaction Sequence.
آدرس Amirkabir University Of Technology, Computer Engineering And Information Technology Department, ایران, Amirkabir University Of Technology, Computer Engineering And Information Technology Department, ایران
پست الکترونیکی shahriari@aut.ac.ir
 
     
   
Authors
  
 
 

Copyright 2023
Islamic World Science Citation Center
All Rights Reserved