TY - GEN
T1 - A data-centric approach to insider attack detection in database systems
AU - Mathew, Sunu
AU - Petropoulos, Michalis
AU - Ngo, Hung Q.
AU - Upadhyaya, Shambhu
PY - 2010
Y1 - 2010
N2 - The insider threat against database management systems is a dangerous security problem. Authorized users may abuse legitimate privileges to masquerade as other users or to maliciously harvest data. We propose a new direction to address this problem. We model users' access patterns by profiling the data points that users access, in contrast to analyzing the query expressions in prior approaches. Our data-centric approach is based on the key observation that query syntax alone is a poor discriminator of user intent, which is much better rendered by what is accessed. We present a feature-extraction method to model users' access patterns. Statistical learning algorithms are trained and tested using data from a real Graduate Admission database. Experimental results indicate that the technique is very effective, accurate, and is promising in complementing existing database security solutions. Practical performance issues are also addressed.
AB - The insider threat against database management systems is a dangerous security problem. Authorized users may abuse legitimate privileges to masquerade as other users or to maliciously harvest data. We propose a new direction to address this problem. We model users' access patterns by profiling the data points that users access, in contrast to analyzing the query expressions in prior approaches. Our data-centric approach is based on the key observation that query syntax alone is a poor discriminator of user intent, which is much better rendered by what is accessed. We present a feature-extraction method to model users' access patterns. Statistical learning algorithms are trained and tested using data from a real Graduate Admission database. Experimental results indicate that the technique is very effective, accurate, and is promising in complementing existing database security solutions. Practical performance issues are also addressed.
UR - https://www.scopus.com/pages/publications/78249276495
U2 - 10.1007/978-3-642-15512-3_20
DO - 10.1007/978-3-642-15512-3_20
M3 - Conference contribution
AN - SCOPUS:78249276495
SN - 3642155111
SN - 9783642155116
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 382
EP - 401
BT - Recent Advances in Intrusion Detection - 13th International Symposium, RAID 2010, Proceedings
PB - Springer Verlag
T2 - 13th International Symposium on Recent Advances in Intrusion Detection Systems, RAID 2010
Y2 - 15 September 2010 through 17 September 2010
ER -