首页> 外文期刊>Journal of Theoretical and Applied Information Technology >FALSE ALARM REDUCTION SCHEME FOR DATABASE INTRUSION DETECTION SYSTEM
【24h】

FALSE ALARM REDUCTION SCHEME FOR DATABASE INTRUSION DETECTION SYSTEM

机译:数据库入侵检测系统的虚假警报减少方案

获取原文
获取外文期刊封面目录资料

摘要

Database intrusion detection system is considered a mandatory security layer in recent database applications. The detection of intrusions in database applications is mostly based on anomaly methods like access patterns, association rule mining and mining data dependencies between data items. These countermeasures achieve good results in traditional applications but new forms of attacks on computer systems lead to the depreciation of intrusion detection systems due to the high rates of false positive alarms. The goal of this paper is to improve the accuracy of intrusion detection system by reducing false alarms using alert clustering mechanism and system hibernation capabilities. In this paper, a three-stage access control framework is developed for detecting malicious users in database. This framework is embedded with an alert clustering mechanism for reducing false alarms by correlating low-level alerts into one cluster. A post security countermeasure is developed by merging system hibernation capabilities into the developed application. The hibernation mechanism is used for maintaining the availability of data in case of intrusion detection. The experimental results of the proposed algorithm achieve high detection rate with low false positive and low false negative alarms when compared to recent researches in intrusion detection systems.
机译:数据库入侵检测系统被认为是最近数据库应用程序中的强制性安全层。对数据库应用程序中入侵的检测主要基于异常方法,例如访问模式,关联规则挖掘和挖掘数据项之间的数据依存关系。这些对策在传统应用中取得了良好的效果,但是由于误报率很高,对计算机系统的新型攻击导致入侵检测系统的贬值。本文的目的是通过使用警报群集机制和系统休眠功能减少误报,从而提高入侵检测系统的准确性。本文提出了一种三阶段访问控制框架,用于检测数据库中的恶意用户。该框架嵌入了警报群集机制,用于通过将低级别警报关联到一个群集来减少错误警报。通过将系统休眠功能合并到已开发的应用程序中,可以开发出一种安全后对策。休眠机制用于在入侵检测的情况下保持数据的可用性。与入侵检测系统的最新研究相比,该算法的实验结果实现了较高的检测率,同时具有较低的误报率和较低的误报率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号