Anomaly Detection Techniques for Database Protection Against Insider Threats (Invited Paper)

Asmaa Sallam, Qian Xiao, Elisa Bertino, Daren Fadolalkarim · 2016

In this paper, we propose techniques for detecting anomalies in user accesses by learning profiles of normal access patterns of users based on both the syntactic and semantic features of past users queries stored in database logs. New accesses are checked upon these profiles and deviations are considered anomalous accesses which may be indications of potential insider attacks. We consider two scenarios. The first scenario is when the monitored database employs role-based access control (RBAC). In this scenario, we build profiles of roles rather than individual users, this makes our approach usable for databases which have a large user population. In this case, we use the naive Bayesian classification to detect anomalies. We also employ multilabeling classification to account for the case when roles have common access patterns. The second scenario is when RBAC is not used. In this case, we detect anomalies using the COBWEB clustering algorithm. We provide extensive evaluation for our techniques. Results show that our techniques are effective.

Read the paper · More papers on PaperTik