信息网络安全 ›› 2020, Vol. 20 ›› Issue (2): 83-90.doi: 10.3969/j.issn.1671-1122.2020.02.011

• • 上一篇    下一篇

RBAC模式下数据库内部入侵检测方法研究

喻露, 罗森林()   

  1. 北京理工大学信息系统及安全对抗实验中心,北京 100081
  • 收稿日期:2019-10-21 出版日期:2020-02-10 发布日期:2020-05-11
  • 作者简介:

    作者简介:喻露(1994—),女,甘肃,硕士研究生,主要研究方向为信息安全;罗森林(1968—),男,河北,教授,博士,主要研究方向为信息安全、数据挖掘、文本安全等。

  • 基金资助:
    国家242信息安全专项[2019A021]

A Method of Internal Intrusion Detection of Database in RBAC Mode

YU Lu, LUO Senlin()   

  1. Information System & Security and Countermeasures Experiments Center, Beijing Institute of Technology, Beijing 100081, China
  • Received:2019-10-21 Online:2020-02-10 Published:2020-05-11

摘要:

针对目前RBAC模式下数据库内部入侵检测方法存在用户行为表示不充分、缺乏对用户角色标签信息的利用、具体环境中检测模型判定能力不足导致该模式下数据库内部入侵检测方法效果差等问题,文章提出一种融合优化用户行为表示方法s-triplet、LDA降维方法和加权随机森林算法的RBAC模式下数据库内部入侵检测方法——IID_WRF。该方法首先对已有用户行为表示方法进行优化,细化数值特征,充分表示用户行为;然后采用能够利用用户角色标签信息的LDA方法进行降维;最后通过加权随机森林进行分类检测。实验结果表明,与其他方法相比IID_WRF在XY两个数据集上误报率、漏报率最低,有效提升了数据库内部入侵检测效果。

关键词: 数据库安全, 内部入侵, 访问控制, RBAC

Abstract:

In view of the current intrusion detection method of RBAC mode database, the user behavior is not sufficient, the use of user role tag information is lacking, and the detection ability of the detection model in the specific environment is insufficient, these lead to the problem that the internal intrusion detection method of the database is not effective. An integrated intrusion detection method IID_WRF based on s-triplet, LDA dimension reduction method and weighted random forest algorithm is proposed. The method first optimizes the existing user behavior representation method, refines the numerical features, and fully represents the user behavior; then uses the LDA method that can use the user role label information to reduce the dimension; finally, the weighted random forest is used for classification detection. The experimental results show that IID_WRF has the lowest false positive rate and false negative rate on X and Y data sets, can effectively improve the internal intrusion detection effect of the database.

Key words: database security, internal intrusion, access control, RBAC

中图分类号: