DocumentCode :
1688936
Title :
Identification of malicious transactions in database systems
Author :
Hu, Yi ; Panda, Brajendra
Author_Institution :
Comput. Sci. & Comput. Eng. Dept., Univ. of Arkansas, Fayetteville, AR, USA
fYear :
2003
Firstpage :
329
Lastpage :
335
Abstract :
Existing host-based intrusion detection systems (IDSs) use the operating system log or the application log to detect misuse or anomaly activities. These methods are not sufficient for detecting intrusion in database systems. In this paper, we describe a method for database intrusion detection by using data dependency relationships. Typically before a data item is updated in the database some other data items are read or written. And after the update other data items may also be written. These data items read or written in the course of updating one data item construct the read set, pre-write set, and the post-write set for this data item. The proposed method identifies malicious transactions by comparing these sets with data items read or written in user transactions. We have provided mechanisms for finding data dependency relationships among transactions and use Petri nets to model normal data update patterns at user task level. Using this method we ascertain more hidden anomalies in the database log.
Keywords :
Petri nets; database management systems; security of data; transaction processing; DBMS; IDS system; Petri nets; anomaly activity detection; data dependency relationship; data item update; data update pattern modeling; database intrusion detection; database log; database management system; database system; information system; intrusion detection system; malicious transaction identification; misuse detection; post-write set; prewrite set; read set; system security; user transaction; Artificial intelligence; Computer science; Data engineering; Database systems; Information systems; Intrusion detection; Operating systems; Spatial databases; Transaction databases; USA Councils;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Database Engineering and Applications Symposium, 2003. Proceedings. Seventh International
ISSN :
1098-8068
Print_ISBN :
0-7695-1981-4
Type :
conf
DOI :
10.1109/IDEAS.2003.1214946
Filename :
1214946
Link To Document :
بازگشت