Earticle

현재 위치 Home

Monitoring Insider Attack in Database Systems Using Multiple-Criteria Query Statement Probabilities

첫 페이지 보기
  • 발행기관
    한국EA학회 바로가기
  • 간행물
    정보화연구 KCI 등재 바로가기
  • 통권
    제12권 3호 (2015.09)바로가기
  • 페이지
    pp.375-390
  • 저자
    Sky Cheolmin Moon, Sam Chung, Barbara Endicott-Popovsky
  • 언어
    영어(ENG)
  • URL
    https://www.earticle.net/Article/A346102

※ 기관로그인 시 무료 이용이 가능합니다.

4,900원

원문정보

초록

영어
Any malicious attack on the database systems performed by an entrusted group of people having authorized access is called database insider attack. Even though the insider attack has been lively researched, it is still far from the practical application. We propose a new approach to improve the limitations in the previous researches. This approach has four objectives: (1) Multi-Preprocessing Algorithms to observe a query in multiple perspectives (2) Query Probabilities Based Database Insider Monitoring Methodology based upon Markov Mathematical Model to record insider’s behavioral patterns with query and query transition probabilities (3) Query Probabilities Time Series Graph to create metrics to monitor the insider’s behavior in order to predict insider attack, and (4) Multi-Criteria Query Probabilities Based Insider Attack Monitoring System containing the (1)–(3). The results from the evaluation show that the proposed system overcomes the limitations and is also capable to monitor insider’s behavioral data while the database is being updated.

목차

Abstract
1. Introduction
2. Background
2.1 General Query Log in a Data Base Management System (DBMS) – MySQL
2.2 Syntax-Centric and Data-Centric Approaches
2.3 Log Analysis in the Cloud
3. Previous Work
4. Problem Statement and Objectives
4.1 Monitoring the insider’s behavioral patterns
4.2 Query preprocessing algorithms with multiple perspectives
4.3 Dynamic Data, no static data for a training set
5. Architecture of A Database Insider Attack Monitoring System
6. DB Log sender node
7. Preprocessor node
7.1 Approach
8. Logger node
8.1 NoSQL DB - Cassandra DB
9. Query Probability Calculator node
9.1 Approach
9.2 Invariant Property of Markov Chain
9.3 Query Probability Calculation using the Invariant Property of Markov Chain
9.4 Example
10. Monitor node
10.1 Approach
10.2 Calculation of the Total-Mean and the Lastk-Mean Based Insider Attack Monitoring
10.3 Presentation and Interpretation
11. MONITORING Anomalous QUERY and Behavior with Query Probabilities Time Series Graphs
11.1 Detecting Anomalous Query
11.2 Detecting Anomalous Behavior
12. Conclusion
References

저자

  • Sky Cheolmin Moon [ Computer Science & Systems, Institute of Technology, University of Washington, Tacoma, WA ]
  • Sam Chung [ School of Information Systems and Applied Technologies, College of Applied Sciences and Arts, Southern Illinois University, Carbondale, IL ]
  • Barbara Endicott-Popovsky [ Institute of Technology & Center for Information Assurance and Cybersecurity, University of Washington, Tacoma, WA ]

참고문헌

자료제공 : 네이버학술정보

간행물 정보

발행기관

  • 발행기관명
    한국EA학회 [한국엔터프라이즈아키텍처학회]
  • 설립연도
    2002
  • 분야
    복합학>과학기술학
  • 소개
    한국EA학회는 전사적 관점의 아키텍처 개념 및 원칙을 국내 민간기업 및 정부기관에 적용 확산시키고, EA 및 관련 분야의 연구, 전문인력의 양성 및 정책적 건의 등을 통해 기업 및 정부기관의 경쟁력 및 생산성을 향상시키고, 우리나라 지식 기반 산업 등의 고도화를 도모하는 것을 목적으로 합니다.

간행물

  • 간행물명
    정보화연구 [정보화연구(구 정보기술아키텍처연구)]
  • 간기
    계간
  • pISSN
    1738-382X
  • 수록기간
    2004~2026
  • 등재여부
    KCI 등재
  • 십진분류
    KDC 325 DDC 658

이 권호 내 다른 논문 / 정보화연구 제12권 3호

    피인용수 : 0(자료제공 : 네이버학술정보)

    함께 이용한 논문 이 논문을 다운로드한 분들이 이용한 다른 논문입니다.

      페이지 저장