A Cloud and In-Memory Based Two-Tier Architecture of a Database Protection System from Insider Attacks

被引:0
|
作者
Moon, Cheolmin Sky [1 ]
Chung, Sam [1 ,2 ]
Endicott-Popovsky, Barbara [2 ]
机构
[1] Univ Washington, Inst Technol, Comp Sci & Syst, Tacoma, WA USA
[2] Univ Washington, Ctr Informat Assurance & Cybersecur, Seattle, WA 98195 USA
关键词
Insider attacks; Database audit logs; File system audit logs; Monitoring; Cloud computing; In-memory database;
D O I
10.1007/978-3-319-05149-9_17
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As a response of emerging insider attacks targeting on database, we are proposing architecture of database protection system from insider attacks. Existing pattern matching approach to detect insider attacks cannot provide perfect solution because of false positive and true negative ratios. Accordingly, we still need reasoning by a human at the last decision to declare that the insider is malicious or not using analysis on history of transaction logs performed by the insider. To construct a system with the consideration above, the system needs to satisfy following requirements: (1) effective monitoring and analysis on large amount of log data (2) scalable system depending on increase or decrease of the log data, and (3) prompt analysis even though the amount of the log data is large enough. We propose a two-tier, distributed, cloud, and in-memory computing based architecture. The proposed architecture brings several benefits such as managing a large amount of log data, distributing analysis workload over multiple nodes, being scalable on big log data, and supporting real-time analysis of big log data.
引用
收藏
页码:260 / 271
页数:12
相关论文
共 50 条
  • [21] Network-based Malware Detection with a Two-tier Architecture for Online Incremental Update
    Yan, Anli
    Chen, Zhenxiang
    Spolaor, Riccardo
    Tan, Shuaishuai
    Zhao, Chuan
    Peng, Lizhi
    Yang, Bo
    2020 IEEE/ACM 28TH INTERNATIONAL SYMPOSIUM ON QUALITY OF SERVICE (IWQOS), 2020,
  • [22] Extending Coverage and Capacity From High Altitude Platforms With a Two-Tier Cellular Architecture
    Arum, Steve Chukwuebuka
    Grace, David
    Mitchell, Paul Daniel
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2024, 23 (02) : 1942 - 1953
  • [23] Implementation of Next-generation Traffic Sign Recognition System with Two-tier Classifier Architecture
    Balasundaram, Keerthi
    Srinivasan, Madhan Kumar
    Sarukesi, K.
    Rodrigues, Paul
    PROCEEDINGS OF THE 2012 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI'12), 2012, : 481 - 487
  • [24] Improved ZF-like Intra-Tier Precoder for A VFDM Based Two-Tier System
    Yao, Rugui
    Jiang, Pengfei
    Yao, Lukun
    Gao, Yan
    Zhang, Yuxin
    Zuo, Xiaoya
    2018 25TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS (ICT), 2018, : 47 - 51
  • [25] Two-tier anomaly detection based on traffic profiling of the home automation system
    Gajewski, Mariusz
    Batalla, Jordi Mongay
    Levi, Albert
    Togay, Cengiz
    Mavromoustakis, Constandinos X.
    Mastorakis, George
    COMPUTER NETWORKS, 2019, 158 : 46 - 60
  • [26] Design and implementation of a self-guided indoor robot based on a two-tier localization architecture
    Yeh, Lun-Wu
    Hsu, Ming-Hsiu
    Huang, Hong-Ying
    Tseng, Yu-Chee
    PERVASIVE AND MOBILE COMPUTING, 2012, 8 (02) : 271 - 281
  • [27] Efficient Content-Based Image Retrieval System with Two-Tier Hybrid Frameworks
    Shaheen, Fatima
    Raibagkar, R. L.
    APPLIED COMPUTER SYSTEMS, 2022, 27 (02) : 166 - 182
  • [28] Research on a new power system development planning model based on two-tier planning
    Fang, Liu
    Ke, Xu
    Yang, Liu
    Weiding, Xu
    Ruiguang, Ma
    Tiannan, Ma
    Yunche, Su
    Chang, Liu
    Wei, Chen
    FRONTIERS IN ENERGY RESEARCH, 2024, 11
  • [29] Management and Analytic of Biomedical Big Data with Cloud-based In-Memory Database and Dynamic Querying
    Feng, Mengling
    Ghassemi, Mohammad
    Brennan, Thomas
    Ellenberger, John
    Hussain, Ishrar
    Mark, Roger
    PROCEEDINGS OF THE 20TH ACM SIGKDD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING (KDD'14), 2014, : 1970 - 1970
  • [30] The two-tier system as a structural problem: A workshop report from the University of Mainz Library
    Jantz, M
    ZEITSCHRIFT FUR BIBLIOTHEKSWESEN UND BIBLIOGRAPHIE, 2002, 49 (5-6): : 306 - 311