Detection of Database Intrusion Using a Two-Stage Fuzzy System

  • Authors:
  • Suvasini Panigrahi;Shamik Sural

  • Affiliations:
  • School of Information Technology, Indian Institute of Technology, Kharagpur, India;School of Information Technology, Indian Institute of Technology, Kharagpur, India

  • Venue:
  • ISC '09 Proceedings of the 12th International Conference on Information Security
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents a novel approach for detecting intrusions in databases based on fuzzy logic, which combines evidences from user's current as well as past behavior. A first-order Sugeno fuzzy model is used to compute an initial belief for each transaction. Whether the current transaction is genuine, suspicious or intrusive is first decided based on this belief. If a transaction is found to be suspicious, its posterior belief is computed using the previous suspicion score and the fuzzy evidences obtained from the history databases by applying fuzzy-Bayesian inferencing. Final decision is made about a transaction according to its current suspicion score. Evaluation of the proposed method clearly shows that the application of fuzzy logic significantly reduces the number of false alarms, which is one of the core problems of existing database intrusion detection systems.