Towards an Open Format for Scalable System Telemetry
Teryl Taylor, Frederico Araujo, et al.
Big Data 2020
The article describes a practical method for detecting outlier database connections in real-time. Outlier connections are detected with a specified level of confidence. The method is based on generalized security rules and a simple but effective real-time machine learning mechanism. The described method is non-intrusive to the database and does not depend on the type of database. The method is used to proactively control access even before database connection is established, minimize false positives, and maintain the required response speed to detected database connection outliers. The capabilities of the system are demonstrated with several examples of outliers in real-world scenarios.
Teryl Taylor, Frederico Araujo, et al.
Big Data 2020
Julia Hesse, Nitin Singh, et al.
USENIX Security 2023
Naoise Holohan, Stefano Braghin, et al.
CCS 2024
Francesca Falzon, Kaoutar El Khiyaoui, et al.
CCS 2023