Research on Multi-Dimensional Database Activity Monitor

陈旦,杨非,叶晓俊
DOI: https://doi.org/10.3969/j.issn.1001-0548.2015.02.018
2015-01-01
Abstract:According to known and unknown database attacking, we propose an architecture of multi-dimensional attack-aware database activity monitor based on captured SQLs, in which the user database behavior schema set can be constructed in the beginning by monitoring their requests and detect potential attacks by analyzing SQL queries/statements during database running. Based on the SQL’s syntactic structure and semantic feature, we present different user behavior models on SQL schematic and semantic level, session level, and structure for libraries of user behavior patterns. Malicious transactions are detected by means of calculating the structure distance of user database requests with SQLs or SQL sequences in schema matching set of the detection engine.
What problem does this paper attempt to address?