Detecting intrusion transactions in databases using data item dependencies and anomaly analysis
Sattar Hashemi, Ying Yang, Davoud Zabihzadeh, Mohammad Reza Kangavari · Expert Systems · 2008
Abstract: The purpose of the intrusion detection system (IDS) database is to detect transactions that access data without permission. This paper proposes a novel approach to identifying malicious transactions. The approach concentrates on two aspects of database transactions: (1) dependencies among data items and (2) variations of each individual data item which can be considered as time‐series data. The advantages are threefold. First, dependency rules among data items are extended to detect transactions that read or write data without permission. Second, a novel behaviour similarity criterion is introduced to reduce the false positive rate of the detection. Third, time‐series anomaly analysis is conducted to pinpoint intrusion transactions that update data items with unexpected pattern. As a result, the proposed approach is able to track normal transactions and detect malicious ones more effectively than existing approaches.