Architecture for data collection in database intrusion detection systems

  • Authors:
  • Xin Jin;Sylvia L. Osborn

  • Affiliations:
  • Dept. of Computer Science, The University of Western Ontario, London, Ontario, Canada;Dept. of Computer Science, The University of Western Ontario, London, Ontario, Canada

  • Venue:
  • SDM'07 Proceedings of the 4th VLDB conference on Secure data management
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

A database intrusion detection system(IDS) is a new database security mechanism to guard data, the most valuable assets of an organization. To provide the intrusion detection module with relevant audit data for further analysis, an effective data collection method is essential. Currently, very little work has been done on the data acquisition mechanisms tailored to the needs of database IDSs. Most researchers use the native database auditing functionality, which excludes privileged users such as database administrators (DBAs) from being monitored. In this paper, we present a new approach to data collection for database IDSs by situating data collecting sensors on the database server and having the data transmitted to the audit server on a physically different site for further processing. This approach can guarantee that behavior of both average users and privileged users are monitored for signs of intrusion.