Intrusion Detection and Forensic Analysis on Database using Log Mining Approach
Agrata Jain, Sneha Saswade, Yogesh Phalke, Chaitanya Gholap · 2014
The demand for secure storage of data has become necessity of our time. Financial records, medical records and legal information are all in need of secure storage.In the dynamic world economies and the era of globalization, data outsourc- ing is unavoidable. Security is the leading concern in data outsourcing environment, since data is under the custody of third party web servers.In current scenario, third party can access and view data even though they are not authorized to do so and allowing the employee of the organization to update the database. This may lead to serious data tampering, data theft or data leakages causing severe business loss to data owner. An important element of any strong security solution is represented by intrusion detection (ID) systems, which detects anomalous behavior by applications and users. In our project, we have pro- posed a novel solution to detect database intrusion using Log Mining technique. Log files are unalterable files at runtime, auto- matically created by Web servers. Main use of log file is to keep trace of transactions performed on any web applications. We consider purchaser database at server-side and compare this with the transactions traced from the log files, with the help of which database tampering can be determined for any indifference found. Finally, with the help of forensic analysis algorithm, we will figure out who did the tampering. Hence the system administrator and the data owner will have a secured system with our model.