A Novel Clustering Algorithm for Database Anomaly Detection.

Jinkun Geng,Daren Ye,Ping Luo,Pin Lv
DOI: https://doi.org/10.1007/978-3-319-28865-9_45
2015-01-01
Abstract:As a main method in database intrusion detection, database anomaly detection should be able to detect users’ operational behaviours for timely prevention of possible attacks and for guarantee of database security. Aiming at this, we apply cluster analysis techniques to anomaly detection and propose a novel density-based clustering algorithm called DBCAPSIC, which is adopted to clustering database users according to their behavior types and behavior frequencies. Privilege patterns are extracted from the clusters and serve as a reference in anomaly detection. The simulation experiment proves that the algorithm can recognize the anomalous operations with few mistakes.
What problem does this paper attempt to address?