An architectural design for a hybrid intrusion detection system for database

In today's business world, information is the most valuable asset of organizations and thus requires appropriate management and protection. Amongst all types of data repositories, database is said to play the role of the heart in the body of IT infrastructure. On the other hand, nowadays, a gro...

Full description

Bibliographic Details
Main Author: Haratian, Mohammad Hossein
Format: Thesis
Language:English
Published: 2009
Subjects:
Online Access:http://eprints.utm.my/10053/
http://eprints.utm.my/10053/1/MohammadHosseinHaratianMFSKSM2009.pdf
_version_ 1848892000337657856
author Haratian, Mohammad Hossein
author_facet Haratian, Mohammad Hossein
author_sort Haratian, Mohammad Hossein
building UTeM Institutional Repository
collection Online Access
description In today's business world, information is the most valuable asset of organizations and thus requires appropriate management and protection. Amongst all types of data repositories, database is said to play the role of the heart in the body of IT infrastructure. On the other hand, nowadays, a growing number of efforts have concentrated on handling the vast variety of security attacks. The characteristic of such handling method depends on when we want it to be occurred and how we intent to deal with attack attempts. Generally there are two ways to handle subversion attempts. One way is to equip our systems by security controls. However in reality this is not feasible due to many reasons. Hence, we are interested in detecting the security attacks. Amongst different types of intrusion detection systems (like network-based, host-based and application-based IDS), database intrusion detection systems which are considered as a type of application-based IDS has become a matter of increasing concern. In this paper we proposed the architecture for a hybrid database intrusion detection system (DB-IDS). This architecture consists of several component and sub-components. It encompasses Anomaly Detection and Misuse Detection subcomponents as Detector component. Anomaly detection component works based on the Profiles constructed by Profiler. Suspicious sequence of events which are considered as potential attacks would be detected by Misuse Detector. Data Collector components is responsible for capturing necessary data for profiling. Moreover, the Transformer component is in place to convert the raw log files into an understandable format for Profiler. Finally, Anomaly Detector and Misuse Detector components send alert to Responder component in case of detection any suspicious activity.
first_indexed 2025-11-15T21:06:54Z
format Thesis
id utm-10053
institution Universiti Teknologi Malaysia
institution_category Local University
language English
last_indexed 2025-11-15T21:06:54Z
publishDate 2009
recordtype eprints
repository_type Digital Repository
spelling utm-100532018-06-13T07:08:06Z http://eprints.utm.my/10053/ An architectural design for a hybrid intrusion detection system for database Haratian, Mohammad Hossein NA Architecture QA76 Computer software In today's business world, information is the most valuable asset of organizations and thus requires appropriate management and protection. Amongst all types of data repositories, database is said to play the role of the heart in the body of IT infrastructure. On the other hand, nowadays, a growing number of efforts have concentrated on handling the vast variety of security attacks. The characteristic of such handling method depends on when we want it to be occurred and how we intent to deal with attack attempts. Generally there are two ways to handle subversion attempts. One way is to equip our systems by security controls. However in reality this is not feasible due to many reasons. Hence, we are interested in detecting the security attacks. Amongst different types of intrusion detection systems (like network-based, host-based and application-based IDS), database intrusion detection systems which are considered as a type of application-based IDS has become a matter of increasing concern. In this paper we proposed the architecture for a hybrid database intrusion detection system (DB-IDS). This architecture consists of several component and sub-components. It encompasses Anomaly Detection and Misuse Detection subcomponents as Detector component. Anomaly detection component works based on the Profiles constructed by Profiler. Suspicious sequence of events which are considered as potential attacks would be detected by Misuse Detector. Data Collector components is responsible for capturing necessary data for profiling. Moreover, the Transformer component is in place to convert the raw log files into an understandable format for Profiler. Finally, Anomaly Detector and Misuse Detector components send alert to Responder component in case of detection any suspicious activity. 2009-04 Thesis NonPeerReviewed application/pdf en http://eprints.utm.my/10053/1/MohammadHosseinHaratianMFSKSM2009.pdf Haratian, Mohammad Hossein (2009) An architectural design for a hybrid intrusion detection system for database. Masters thesis, Universiti Teknologi Malaysia, Faculty of Computer Science and Information System.
spellingShingle NA Architecture
QA76 Computer software
Haratian, Mohammad Hossein
An architectural design for a hybrid intrusion detection system for database
title An architectural design for a hybrid intrusion detection system for database
title_full An architectural design for a hybrid intrusion detection system for database
title_fullStr An architectural design for a hybrid intrusion detection system for database
title_full_unstemmed An architectural design for a hybrid intrusion detection system for database
title_short An architectural design for a hybrid intrusion detection system for database
title_sort architectural design for a hybrid intrusion detection system for database
topic NA Architecture
QA76 Computer software
url http://eprints.utm.my/10053/
http://eprints.utm.my/10053/1/MohammadHosseinHaratianMFSKSM2009.pdf