检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]华中科技大学计算机科学与技术学院,湖北武汉430074
出 处:《计算机集成制造系统》2008年第6期1230-1235,共6页Computer Integrated Manufacturing Systems
基 金:国家预研基金资助项目(513150601)。~~
摘 要:为了提高对数据库恶意事务的检测粒度和检测范围,在基于事务时序图的数据库管理系统恶意事务入侵检测机制的基础上,通过增加记录条件短语,扩展了审计表内容,增加节点属性,改进了合法事务时序图,提出了一种基于合法事务时序图的恶意事务检测算法。该算法可以使检测粒度细到查询语句条件级,而且能检测单语句事务等一些特殊事务。实验表明,该算法具有更强的检测能力、更广的适用范围及较好的性能,并能方便地应用于实际的数据库管理系统中。To enhance the detection granularity and detection scope on database malicious transaction, a detecting mechanism of malicious transactions based on transaction-profile chart for DataBase Management System (DBMS) was proposed. It expanded the content of audit table through recording the conditional command, and improved the legal transaction-profile chart by adding node attributes. A detection algorithm of malicious transactions based on transaction-profile chart was proposed. This algorithm was endowed with better detection ability on condition phrase of Structured Query Language (SOL) command, which could detect some special malicious transactions such as the one-command transaction, etc. Experimental results indicated that this algorithm had good detection ability, performance and more extensive detection scopes. This algorithm could be applied in practical DBMS.
关 键 词:信息安全 数据库管理系统 审计表 事务时序 恶意事务检测
分 类 号:TP309.2[自动化与计算机技术—计算机系统结构]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.166