Title :
Detection of malicious transactions in DBMS
Author :
Vieira, Marco ; Madeira, Henrique
Author_Institution :
CISUC, Coimbra Univ., Portugal
Abstract :
A major difficulty faced by organizations is the protection of data against malicious access or corruption. Database management systems (DBMS) are a key component in the information infrastructure of most organizations and represent the ultimate layer in preventing unauthorized data accesses. Several mechanisms needed to protect data, such as authentication, user privileges, encryption, and auditing, have been implemented in commercial DBMS. However, typical database security mechanisms are not able to detect and handle many data security attacks. In fact, malicious transactions executed by unauthorized users that may gain access to the database by exploring system vulnerabilities and unauthorized database transactions executed by authorized users cannot be detected and stopped by typical security mechanisms. In this paper we propose a new mechanism for the detection of malicious transactions in DBMS. The paper presents a practical example of the implementation of the proposed mechanism in the Oracle 10g DBMS and evaluates the mechanism using the TPC-C benchmark.
Keywords :
database management systems; security of data; transaction processing; DBMS; database management systems; database security; malicious transaction detection; Authentication; Availability; Cryptography; Data security; Database systems; Face detection; Information security; Intrusion detection; Protection; Transaction databases;
Conference_Titel :
Dependable Computing, 2005. Proceedings. 11th Pacific Rim International Symposium on
Print_ISBN :
0-7695-2492-3
DOI :
10.1109/PRDC.2005.31