期刊文献+

基于用户行为编码的数据库入侵检测模型 被引量:1

DATABASE INTRUSION DETECTION MODEL BASED ON ENCODING OF USER'S BEHAVIOR
下载PDF
导出
摘要 鉴于数据库入侵检测系统中模板的数量不断增加,导致入侵检测效率也随着降低。提出基于用户行为编码的数据库入侵检测模型,该模型通过对提交的SQL进行编码,再利用挖掘方法得出语句中属性内部关系的规则,最后形成用户正常行为规则库,从而取代了模板库,提高了检测的效率。该方法不仅能够有效地防止SQL注入,而且也能检测出合法权限滥用。 Increasing number of templates in database intrusion detection system leads to the detection efficiency goes down. In view of this, in the paper we present a database intrusion detection model based on encoding of user's behaviour. The model encodes SQL statements submitted, attains the rules of inner relationship of attributes in sentences with mining algorithm, and eventually forms the rule base of users' normal behaviours, through these procedures it replaces the temples and improves the detection efficiency. The method can prevent database from SQL injection effectively, and can also detect the abuse of users' privileges.
出处 《计算机应用与软件》 CSCD 2010年第2期97-99,147,共4页 Computer Applications and Software
基金 上海市教委科技发展基金(05AZ68) 上海市重点学科建设项目(J50103)
关键词 数据库入侵检测 SQL语句 编码 Database intrusion detection SQL statements Encoding
  • 相关文献

参考文献7

二级参考文献17

  • 1Han J,Proc 2000 ACMSIGMOD Int Conf Management of Data(SIGMOD 2000),2000年
  • 2Han Jiawei,Issuer for On-line Analytical Mining of Data Warehouses
  • 3Anley C.Advanced SQL Injection In SQL Server Applications.Next Generation Security Software Ltd.Available at:URL http://www.nextgenss.com/papers/advanced sql injection.pdf(2002).
  • 4Litchfield D.Web Application Disassembly with ODBC Error Messages.http://www.nextgenss.com/papers/webappdis.doc.
  • 5Zhong Yong,Qin Xiaolin.Adaptive Data Protection Mechanism in Intrusion Tolerant Multilevel Secure Database.In:the Proceedings of the Second Asian Workshop on Foundations of Software.Naniing,China,Dec.2003.21-24.
  • 6O'NeillM 著 冉晓旻 郭文伟译.Web服务安全技术与原理[M].北京:清华大学出版社,2003.168-169.
  • 7Scott D, Sharp R. Abstracting Application-Level Web Security.In:Proc llth Int'l World Wide Web Conf, May 2002. 396-407
  • 8SNORT:The open source network ids. Web page at http://www. snort. org
  • 9PHP Group. PHP Hypertext Preprocessor. Web page at http://www. php. net (2001-2005)
  • 10Boyd S, Keromytis A. SQLrand: Preventing SQL injection attacks. In: Jakobsson M, Yung M, Zhou J. eds. Proceedings of the 2nd Applied Cryptography and Network Security (ACNS)Conference. Volume 3089 of Lecture Notes in Computer Science, Springer-Verlag,2004. 292-304

共引文献177

同被引文献10

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部