Netinfo Security ›› 2020, Vol. 20 ›› Issue (2): 83-90.doi: 10.3969/j.issn.1671-1122.2020.02.011

• 技术研究 • Previous Articles     Next Articles

A Method of Internal Intrusion Detection of Database in RBAC Mode

YU Lu, LUO Senlin()   

  1. Information System & Security and Countermeasures Experiments Center, Beijing Institute of Technology, Beijing 100081, China
  • Received:2019-10-21 Online:2020-02-10 Published:2020-05-11

Abstract:

In view of the current intrusion detection method of RBAC mode database, the user behavior is not sufficient, the use of user role tag information is lacking, and the detection ability of the detection model in the specific environment is insufficient, these lead to the problem that the internal intrusion detection method of the database is not effective. An integrated intrusion detection method IID_WRF based on s-triplet, LDA dimension reduction method and weighted random forest algorithm is proposed. The method first optimizes the existing user behavior representation method, refines the numerical features, and fully represents the user behavior; then uses the LDA method that can use the user role label information to reduce the dimension; finally, the weighted random forest is used for classification detection. The experimental results show that IID_WRF has the lowest false positive rate and false negative rate on X and Y data sets, can effectively improve the internal intrusion detection effect of the database.

Key words: database security, internal intrusion, access control, RBAC

CLC Number: