A Novel Intrusion Detection System Model for Securing Web-based Database Systems

  • Authors:
  • Shu Wenhui;Daniel Tan

  • Affiliations:
  • -;-

  • Venue:
  • COMPSAC '01 Proceedings of the 25th International Computer Software and Applications Conference on Invigorating Software Development
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

Intrusion Detection (ID) has become an important technology for protecting information resources and databases from malicious attacks and information leakage. This paper proposes a novel two-layer mechanism to detect intrusions against a web-based database service. Layer one built historical profiles based on audit trails and other log data provided by the web server and database server. Pre-alarms would be triggered if anomalies occurred. Layer two made further analysis on the pre-alarms generated from layer one. Such methods integrated the alarm context with the alarms themselves rather than a simple "analysis in isolation". This would reduce error rates, especially false positives and greatly improve the accuracy of intrusion detection, alarm notification and hence more effective incident handling.