{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,7,26]],"date-time":"2024-07-26T23:44:55Z","timestamp":1722037495716},"reference-count":34,"publisher":"Oxford University Press (OUP)","issue":"4","license":[{"start":{"date-parts":[[2019,12,9]],"date-time":"2019-12-09T00:00:00Z","timestamp":1575849600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/journals\/pages\/open_access\/funder_policies\/chorus\/standard_publication_model"}],"funder":[{"name":"Defense Acquisition Program Administration and Agency for Defense Development","award":["UD160066BD"],"award-info":[{"award-number":["UD160066BD"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,7,24]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Relational database management system (RDBMS) is the most popular database system. It is important to maintain data security from information leakage and data corruption. RDBMS can be attacked by an outsider or an insider. It is difficult to detect an insider attack because its patterns are constantly changing and evolving. In this paper, we propose an adaptive database intrusion detection system that can be resistant to potential insider misuse using evolutionary reinforcement learning, which combines reinforcement learning and evolutionary learning. The model consists of two neural networks, an evaluation network and an action network. The action network detects the intrusion, and the evaluation network provides feedback to the detection of the action network. Evolutionary learning is effective for dynamic patterns and atypical patterns, and reinforcement learning enables online learning. Experimental results show that the performance for detecting abnormal queries improves as the proposed model learns the intrusion adaptively using Transaction Processing performance Council-E scenario-based virtual query data. The proposed method achieves the highest performance at 94.86%, and we demonstrate the usefulness of the proposed method by performing 5-fold cross-validation.<\/jats:p>","DOI":"10.1093\/jigpal\/jzz053","type":"journal-article","created":{"date-parts":[[2019,11,10]],"date-time":"2019-11-10T12:07:16Z","timestamp":1573387636000},"page":"449-460","source":"Crossref","is-referenced-by-count":5,"title":["Evolutionary Reinforcement Learning for Adaptively Detecting Database Intrusions"],"prefix":"10.1093","volume":"28","author":[{"given":"Seul-Gi","family":"Choi","sequence":"first","affiliation":[{"name":"Department of Computer Science, Yonsei University, Seoul 03722, South Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sung-Bae","family":"Cho","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Yonsei University, Seoul 03722, South Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2019,12,9]]},"reference":[{"key":"2020080108270590600_ref1","first-page":"487","article-title":"Interactions between learning and evolution","volume":"10","author":"Ackley","year":"1991","journal-title":"Artificial Life II"},{"key":"2020080108270590600_ref2","first-page":"173","volume-title":"Computer Security Applications Conference","author":"Bertino","year":"2005"},{"key":"2020080108270590600_ref3","first-page":"449","article-title":"Profiling database application to detect SQL injection attacks","author":"Bertino","year":"2007","journal-title":"Performance, Computing, and Communications Conference"},{"key":"2020080108270590600_ref4","doi-asserted-by":"crossref","first-page":"361","DOI":"10.1162\/evco.1996.4.4.361","article-title":"A comparison of selection schemes used in evolutionary algorithms","volume":"4","author":"Blickle","year":"1996","journal-title":"Evolutionary Computation"},{"key":"2020080108270590600_ref5","first-page":"196","article-title":"Learning SQL for database intrusion detection using context-sensitive modeling","author":"Bockermann","year":"2009","journal-title":"International Conference on Detect Intrusions Malware Vulnerability"},{"key":"2020080108270590600_ref6","first-page":"8","article-title":"Health information system role-based access control current security trends and challenges","volume":"2018","author":"de Carvalho","year":"2018","journal-title":"Journal of Healthcare Engineering"},{"key":"2020080108270590600_ref7","first-page":"1616","article-title":"Insider threat in database systems: preventing malicious users\u2019 activities in databases","author":"Chagarlamudi","year":"2009","journal-title":"Information Technology: New Generations"},{"key":"2020080108270590600_ref8","doi-asserted-by":"crossref","first-page":"12240","DOI":"10.1109\/ACCESS.2018.2812844","article-title":"RBAC-SC: role-based access control using smart contract","volume":"6","author":"Cruz","year":"2018","journal-title":"IEEE Access"},{"key":"2020080108270590600_ref9","first-page":"199","article-title":"Minds-Minnesota intrusion detection system","author":"Ertoz","year":"2004","journal-title":"Next Generation Data Mining"},{"key":"2020080108270590600_ref10","first-page":"554","article-title":"Role-based access control","author":"Ferraiolo","year":"1992","journal-title":"The National Computer Security Conference"},{"key":"2020080108270590600_ref11","first-page":"25","article-title":"Detanom: detecting anomalous database transactions by insiders","author":"Hussain","year":"2015","journal-title":"ACM Conference on Data and Application Security and Privacy"},{"key":"2020080108270590600_ref12","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1007\/978-3-642-17604-3_10","article-title":"Intrusion detection in database systems","author":"Javidi","year":"2010","journal-title":"Communication and Networking"},{"key":"2020080108270590600_ref13","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1145\/1410308.1410318","volume-title":"Proceedings of the 2nd SIGMOD PhD Workshop on Innovative Database Re-Search","author":"Kamra","year":"2008"},{"key":"2020080108270590600_ref14","first-page":"461","article-title":"Designing neural networks using genetic algorithms with graph generation system","volume":"4","author":"Kitano","year":"1990","journal-title":"Complex Systems"},{"key":"2020080108270590600_ref15","volume-title":"A pattern matching model for misuse intrusion detection","author":"Kumar","year":"1994"},{"key":"2020080108270590600_ref16","doi-asserted-by":"crossref","first-page":"179","DOI":"10.1007\/s10207-010-0102-5","article-title":"Database intrusion detection using sequence alignment","volume":"9","author":"Kundu","year":"2010","journal-title":"International Journal of Information Security"},{"key":"2020080108270590600_ref17","first-page":"25","article-title":"A comparative study of anomaly detection schemes in network intrusion detection","author":"Lazarevic","year":"2003","journal-title":"SIAM International Conference on Data Mining Society for Industrial and Applied Mathematics"},{"key":"2020080108270590600_ref18","first-page":"35","article-title":"Improving web application firewalls to detect advanced SQL injection attacks","author":"Makiou","year":"2014","journal-title":"International Conference on Information Assurance and Security"},{"key":"2020080108270590600_ref19","first-page":"382","article-title":"A data-centric approach to insider attack detection in database systems","author":"Mathew","year":"2010","journal-title":"International Symposium on Research in Attacks, Intrusions and Defenses"},{"key":"2020080108270590600_ref20","first-page":"1140","article-title":"Anomaly detection in large databases using behavioral patterning","author":"Mazzawi","year":"2017","journal-title":"IEEE International Conference on Data Engineering"},{"key":"2020080108270590600_ref21","first-page":"1","article-title":"Complex event processing based hybrid intrusion detection system","author":"Mohan","year":"2015","journal-title":"IEEE International Conference on Signal Processing, Communication and Networking"},{"key":"2020080108270590600_ref22","first-page":"762","article-title":"Training feedforward neural networks using genetic algorithms","volume":"89","author":"Montana","year":"1989","journal-title":"International Joint Conference on Artificial Intelligence"},{"key":"2020080108270590600_ref23","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1007\/s10796-010-9252-2","article-title":"Two-stage database intrusion detection by combining multiple evidence and belief update","volume":"15","author":"Panigrahi","year":"2013","journal-title":"Information Systems Frontiers"},{"key":"2020080108270590600_ref24","first-page":"1","article-title":"A classification based approach to create database policy for intrusion detection and respond anomaly requests","author":"Parmar","year":"2014","journal-title":"IEEE Conference on IT in Business, Industry and Government"},{"key":"2020080108270590600_ref25","first-page":"510","article-title":"CBRid4SQL: a cbr intrusion detector for SQL injection attacks","volume":"6077","author":"Pinzon","year":"2010","journal-title":"Hybrid Artificial Intelligent Systems"},{"key":"2020080108270590600_ref26","first-page":"1","article-title":"Database intrusion detection by transaction signature","author":"Rathod","year":"2012","journal-title":"IEEE International Conference on Computing Communication & Networking Technologies"},{"key":"2020080108270590600_ref27","doi-asserted-by":"crossref","first-page":"238","DOI":"10.1016\/j.ins.2016.06.038","article-title":"Anomalous query access detection in RBAC-administered databases with random forest and PCA","volume":"369","author":"Ronao","year":"2016","journal-title":"Information Sciences"},{"key":"2020080108270590600_ref28","first-page":"123","article-title":"Web anomaly misuse intrusion detection framework for SQL injection detection","volume":"3","author":"Salama","year":"2012","journal-title":"International Journal of Advanced Computer Science and Applications"},{"key":"2020080108270590600_ref29","first-page":"36","article-title":"Approaches and challenges in database intrusion detection","volume":"43","author":"Santos","year":"2014","journal-title":"ACM Conference on Special Interest Group on Management of Data Record"},{"key":"2020080108270590600_ref30","first-page":"318","article-title":"Employing neural networks for the detection of SQL injection attack","author":"Sheykhkanloo","year":"2014","journal-title":"International Conference on Security of Information and Networks"},{"key":"2020080108270590600_ref31","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1007\/978-3-642-12145-6_4","article-title":"Soft computing techniques for intrusion detection of SQL-based attacks","author":"Skarus","year":"2010","journal-title":"Asian Conference on Intelligent Information and Database Systems"},{"key":"2020080108270590600_ref32","first-page":"2","article-title":"Uniform crossover in genetic algorithms","author":"Syswerda","year":"1989","journal-title":"International Conference of Genetic Algorithms"},{"key":"2020080108270590600_ref33","first-page":"0","article-title":"Standard specification","volume":"1","author":"Transaction Processing Performance Council (TPC), TPC benchmark E","year":"2014","journal-title":"Version"},{"key":"2020080108270590600_ref34","doi-asserted-by":"crossref","first-page":"123","DOI":"10.1007\/11506881_8","article-title":"A learning-based approach to the detection of SQL at-tacks","author":"Valeur","year":"2005","journal-title":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment"}],"container-title":["Logic Journal of the IGPL"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/academic.oup.com\/jigpal\/article-pdf\/28\/4\/449\/33554777\/jzz053.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"http:\/\/academic.oup.com\/jigpal\/article-pdf\/28\/4\/449\/33554777\/jzz053.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,8,1]],"date-time":"2020-08-01T12:27:39Z","timestamp":1596284859000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/jigpal\/article\/28\/4\/449\/5670474"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,12,9]]},"references-count":34,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2019,12,9]]},"published-print":{"date-parts":[[2020,7,24]]}},"URL":"https:\/\/doi.org\/10.1093\/jigpal\/jzz053","relation":{},"ISSN":["1367-0751","1368-9894"],"issn-type":[{"value":"1367-0751","type":"print"},{"value":"1368-9894","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2020,8]]},"published":{"date-parts":[[2019,12,9]]}}}