应用科学学报 ›› 2005, Vol. 23 ›› Issue (5): 506-512.

• 论文 • 上一篇    下一篇


钟勇, 秦小麟, 包磊   

  1. 南京航空航天大学信息科学与技术学院, 江苏南京 210016
  • 收稿日期:2004-06-03 修回日期:2004-10-08 出版日期:2005-09-30 发布日期:2005-09-30
  • 作者简介:钟勇(1970-),男,江西峡江人,讲师,博士,E-mail:zhongyong@fosu.edu.cn;秦小麟(1953-),男,江苏苏州人,教授,博导.
  • 基金资助:

Mining Algorithm Based on User Query and Its Application in Intrusion Detection

ZHONG Yong, QIN Xiao-lin, BAO Lei   

  1. Institute of Information Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 210016, China
  • Received:2004-06-03 Revised:2004-10-08 Online:2005-09-30 Published:2005-09-30

摘要: 利用用户查询结构和属性结构的稳定性特征提出了一个事务级用户查询模式挖掘算法,该方法应用在数据库入侵检测系统中,可以有效地防止SQL注入、合法用户权限滥用等非法行为,并对该算法的实现、复杂度、应用作了阐述,最后对算法的查询性能影响作了分析.

关键词: 数据库安全, 数据挖掘, 入侵检测

Abstract: As traditional user identification and access control of database security mechanism have limitations such as inability of resisting illegal SQL injection and abuse of authorization, a transaction-level user query profiles mining algorithm is presented by using characteristics of structure stabilization of user queries and attributes.The method can be used for database intrusion detection to effectively prevent these illegal actions. Implementation, complexity and application of the algorithm are discussed, and influence of the algorithm on the database query analyzed.

Key words: intrusion detection, database security, data mining
