Detection of Insiders Misuse in Database Systems
Nahla Shatnawi, Qutaibah Althebyan, Wail E. Mardini · 2011
Abstract — Almost all systems all over the world suffer from outsider and insider attacks. Outsider attacks are those that come from outside the system, however, insider attacks are those that are launched from insiders of the system. In this paper we concentrate on insider attacks detection on the application level; database is our focus. Insider attacks differ from outsider attacks in many ways; most importantly, insiders have more knowledge about the underlying systems. Because of their knowledge and their privileges of the system resources; their risk can be greater and more severe. In fact, insiders can find vulnerabilities in the system easily. Several techniques have been proposed that tackled the insider threat problem, but most of them concentrate on insider threat detection in computer system level. We describe a method for insider threat detection in database systems that handle entrants on the role of insiders for such attacks. Our simulation results show resistance against such attacks. Also, our results show good performance in terms of reducing false alarms to the minimum. Index Terms—About four key words or phrases in alphabetical order, separated by commas, for example, visualservoing, tracking, biomimetic, redundancy, degrees-offreedom I I.