|
With the combination of database and computer network technology , more and more agencies and departments of government , commercial, financial , and other database connected to the Internet , more and more database by the attack , while traditional database protection technology has not the need to adapt to this situation . In order to further improve the security of the database system , database intrusion detection technologies , including database intrusion detection architecture , the definition of the rules of conduct and its extraction algorithm , a database intrusion detection based on the rules of conduct . Database intrusion detection system architecture as a whole is divided into four modules and two libraries Profiler module, data analysis module , rules module and intrusion detection module , and audit databases and rules of conduct library . The system is running normal rules of behavior in the learning stage and working stage , the learning stage , the working stages intrusion detection . Rules of conduct in the database application system , combined with the stability of the system behavior semantics of database applications and can be extracted , given the definition of the rules of conduct , rules of conduct library rules of conduct and behavior of database application system semantics linked . Divided behavior rules proposed in the audit data , given on the basis of the rules of conduct algorithms . In addition, to achieve a simplification of the rules of conduct , delete redundant rules in the rule base , simplify the rules of conduct to maintain a small number of rules in the rule base , will help speed up the process of intrusion detection . Design and Implementation of intrusion detection , combined with the proposed concept of rules of conduct , the generation of the rules of conduct into intrusion detection , clear abuse as intrusion detection and anomaly detection process , while achieving the invasion of static and dynamic detection. Intrusion detection intrusion historical audit data analysis found static , dynamic intrusion detection analysis of real-time audit data , the introduction of the increment data analysis method in dynamic intrusion detection , the performance of the system reaches a certain real-time while a smaller loss .
|