SlideShare a Scribd company logo
###-### title - PI - area###-### title - PI - area
DDatabaseatabase IIntrusionntrusion DDetection andetection and RResponseesponse**
Ashish Kamra and Elisa Bertino
akamra@purdue.edu, bertino@cs.purdue.edu
1. Create profiles that succinctly represent user/application behaviorinteracting with a DBMS.
2. Develop efficient algorithms fordetection of anomalous DBuser/application behavior.
3. Develop novel strategies/mechanisms forresponding to intrusions in context of a DBMS.
4. Implement ourmethods in the PostgreSQL DBMS and highlight implementation issues.
* Supported by NSF under Grant No. 0430274
System
Architecture
Query
User
Features Assessment
Profile Creator
Alarm
Drop Query
No Action
Audit
Log
Training Queries
TRAINING PHASE
Detection Engine Response Engine
Response Policy Base
(Extended ECA Policies)
Feature Selector
Profiles
Consult
Contributions
ON ---------{EVENT}
IF-----------{CONDITIONS}
THEN-------{ACTION}
CONFIRM---{CONFIRMATION ACTION}
ELSE--------{ALTERNATE ACTION}
Supervised Learning:
Roles as Classes
Naïve Bayes Classifier
Supervised Learning:
Roles as Classes
Naïve Bayes Classifier
Un-supervised Learning:
Clustering methods
Outlier Detection Test
Un-supervised Learning:
Clustering methods
Outlier Detection Test
SQL QUERIES STORED AS
ASSOCIATION RULES
SQL QUERIES STORED AS
ASSOCIATION RULES
QUERY RULES
query projection attributes =>
query selection attributes
PREDICATE RULES
LHS attributes => RHS attributes
QUERY RULES
query projection attributes =>
query selection attributes
PREDICATE RULES
LHS attributes => RHS attributes
Future
Work
Detection Tasks

More Related Content

PPSX
2016 Domingo ll de cuaresma
PDF
portfolio_susantran
PPTX
Avoiding the Top Mistakes in Social Media Marketing including your website.
PDF
Presidente do Sintese avalia política estadual de educação na Alese
PDF
Ley 27806
PPTX
Decalogo lisnely
PDF
Ley 29060
PPTX
Trabajo grupal:Participación de los padres
2016 Domingo ll de cuaresma
portfolio_susantran
Avoiding the Top Mistakes in Social Media Marketing including your website.
Presidente do Sintese avalia política estadual de educação na Alese
Ley 27806
Decalogo lisnely
Ley 29060
Trabajo grupal:Participación de los padres

Similar to Raid08 dbir (20)

DOC
Senior Systems Engineering ( Microsoft) .
PDF
IRJET- Automatic Database Schema Generator
DOCX
Part 1 Major Events DocumentationScenario You visit a retail.docx
PDF
Database Engine Control though Web Portal Monitoring Configuration
DOCX
Mca5033 open source db systems
PPT
Enterprise Architecture - IT Blueprinting
PDF
IAPP PSR 2022: How do you engineer DSAR for Complexity?
PDF
Metadata Modeling Best Practices with IBM Cognos Framework Manager
PPT
統計在半導體產業的應用 -- EDA
PDF
PPTX
Sturts 2 in EHI
PPTX
Dynamic Data Masking - Breakthrough Innovation in Application Security
PDF
Hands-On Lab: Improve large network visibility and operational efficiency wit...
PPTX
Database Management Systems Lecture # 2 Inter
DOCX
Nishant_Patnaik
PDF
GuideIT High Level Consulting Framework
DOCX
BoardSprintUser Story ScenarioDesignDevelopmentTestUAT Release1U .docx
DOC
Senior Systems Engineering ( Microsoft) .
IRJET- Automatic Database Schema Generator
Part 1 Major Events DocumentationScenario You visit a retail.docx
Database Engine Control though Web Portal Monitoring Configuration
Mca5033 open source db systems
Enterprise Architecture - IT Blueprinting
IAPP PSR 2022: How do you engineer DSAR for Complexity?
Metadata Modeling Best Practices with IBM Cognos Framework Manager
統計在半導體產業的應用 -- EDA
Sturts 2 in EHI
Dynamic Data Masking - Breakthrough Innovation in Application Security
Hands-On Lab: Improve large network visibility and operational efficiency wit...
Database Management Systems Lecture # 2 Inter
Nishant_Patnaik
GuideIT High Level Consulting Framework
BoardSprintUser Story ScenarioDesignDevelopmentTestUAT Release1U .docx
Ad

Recently uploaded (20)

PDF
cuic standard and advanced reporting.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Machine learning based COVID-19 study performance prediction
PPTX
Spectroscopy.pptx food analysis technology
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPT
Teaching material agriculture food technology
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
MYSQL Presentation for SQL database connectivity
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
cuic standard and advanced reporting.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
Machine learning based COVID-19 study performance prediction
Spectroscopy.pptx food analysis technology
Mobile App Security Testing_ A Comprehensive Guide.pdf
Assigned Numbers - 2025 - Bluetooth® Document
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
“AI and Expert System Decision Support & Business Intelligence Systems”
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Spectral efficient network and resource selection model in 5G networks
Per capita expenditure prediction using model stacking based on satellite ima...
Teaching material agriculture food technology
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
20250228 LYD VKU AI Blended-Learning.pptx
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Encapsulation_ Review paper, used for researhc scholars
MYSQL Presentation for SQL database connectivity
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Ad

Raid08 dbir

  • 1. ###-### title - PI - area###-### title - PI - area DDatabaseatabase IIntrusionntrusion DDetection andetection and RResponseesponse** Ashish Kamra and Elisa Bertino akamra@purdue.edu, bertino@cs.purdue.edu 1. Create profiles that succinctly represent user/application behaviorinteracting with a DBMS. 2. Develop efficient algorithms fordetection of anomalous DBuser/application behavior. 3. Develop novel strategies/mechanisms forresponding to intrusions in context of a DBMS. 4. Implement ourmethods in the PostgreSQL DBMS and highlight implementation issues. * Supported by NSF under Grant No. 0430274 System Architecture Query User Features Assessment Profile Creator Alarm Drop Query No Action Audit Log Training Queries TRAINING PHASE Detection Engine Response Engine Response Policy Base (Extended ECA Policies) Feature Selector Profiles Consult Contributions ON ---------{EVENT} IF-----------{CONDITIONS} THEN-------{ACTION} CONFIRM---{CONFIRMATION ACTION} ELSE--------{ALTERNATE ACTION} Supervised Learning: Roles as Classes Naïve Bayes Classifier Supervised Learning: Roles as Classes Naïve Bayes Classifier Un-supervised Learning: Clustering methods Outlier Detection Test Un-supervised Learning: Clustering methods Outlier Detection Test SQL QUERIES STORED AS ASSOCIATION RULES SQL QUERIES STORED AS ASSOCIATION RULES QUERY RULES query projection attributes => query selection attributes PREDICATE RULES LHS attributes => RHS attributes QUERY RULES query projection attributes => query selection attributes PREDICATE RULES LHS attributes => RHS attributes Future Work Detection Tasks