METHOD OF DETECTING VULNERABILITIES AND AUTOMATED RESPONSE IN CORPORATE DATABASE PROTECTION SYSTEMS
DOI: 10.31673/2409-7292.2025.029259
DOI:
https://doi.org/10.31673/2409-7292.2025.029259Abstract
The article proposes a scientifically based method for detecting vulnerabilities and automated response in corporate
database protection systems operating in modern network infrastructure. The relevance of the study is due to the increasing
complexity of cyberattacks, the increase in data volumes, and the spread of cloud technologies, which significantly complicate
access control and make it impossible to use only traditional approaches to ensuring the security of database management
systems. A multi-level architecture is proposed, which is based on a combination of user behavior analysis models and
mathematical risk assessment of database queries. Each SQL query is described by a vector of features that are analyzed using
the Isolation Forest model. The determined threat level allows for the formation of a combined risk assessment that integrates
behavioral anomaly and query criticality. Based on this assessment, a real-time automatic response mechanism is implemented
- in particular, access blocking, SOC notification, and possible launch of scripts via a plug-in for the SIEM system. A feature of
the method is the possibility of its adaptation to real IT infrastructures, which is ensured by the modularity of the system and
compatibility with existing monitoring tools. The proposed method is an innovative combination of behavioral analysis, adaptive
machine learning and automated response in a single architecture for protecting corporate databases. Its distinctive features are
proactivity, flexibility of response, preventive action before executing a request and the possibility of integration with existing
SOC solutions. The effectiveness of the method is confirmed by the results of modeling, in particular by comparison with other
approaches using completeness metrics and ROC curves. The proposed solution has practical significance for increasing the
resilience of corporate database management systems to internal and external threats.
Keywords: information security, database protection, detection of access anomalies, response automation.
References
1. Omotunde, H., & Ahmed, M. (2023). A Comprehensive Review of Security Measures in Database Systems:
Assessing Authentication, Access Control, and Beyond. Mesopotamian Journal of Cyber Security, 115–133.
https://doi.org/10.58496/mjcsc/2023/016.
2. Touil, H., El Akkad, N., Satori, K., Soliman, N. F., & El-Shafai, W. (2024). Efficient Braille Transformation
for Secure Password Hashing. IEEE Access, 1. https://doi.org/10.1109/access.2024.3349487.
3. Pan, X., Obahiaghon, A., Makar, B., Wilson, S., & Beard, C. (2024). Analysis of Database Security. OALib,
11(04), 1–19. https://doi.org/10.4236/oalib.1111366.
4. Wang, Y., Xi, J., & Cheng, T. (2021). The Overview of Database Security Threats’ Solutions: Traditional and
Machine Learning. Journal of Information Security, 12(01), 34–55. https://doi.org/10.4236/jis.2021.121002.
5. Almaiah, M. A., Saqr, L. M., Al-Rawwash, L. A., Altellawi, L. A., Al-Ali, R., & Almomani, O. (2024).
Classification of Cybersecurity Threats, Vulnerabilities and Countermeasures in Database Systems. Computers, Materials
& Continua, 1–10. https://doi.org/10.32604/cmc.2024.057673.
6. Ilyenko, A., Ilyenko, S., Diana, K., & Mazur, Y. (2023). Практичні підходи щодо виявлення вразливостей
в інформаційно-телекомунікаційних мережах. Електронне фахове наукове видання «Кібербезпека: освіта, наука,
техніка», 3(19), 96–108. https://doi.org/10.28925/2663-4023.2023.19.96108.
7. Mosope Williams & Tina Charles Mbakwe-Obi. (2024). Integrated strategies for database protection:
Leveraging anomaly detection and predictive modelling to prevent data breaches. World Journal of Advanced Research
and Reviews, 24(3), 1098–1115. https://doi.org/10.30574/wjarr.2024.24.3.3795.
8. Щавінський, Ю., & Будзинський, О. (2025). Аналіз актуальних проблем безпеки корпоративних баз
даних в умовах сучасної інфраструктури та шляхи їх вирішення . Електронне фахове наукове видання
«Кібербезпека: освіта, наука, техніка», 3(27), 390–405. https://doi.org/10.28925/2663-4023.2025.27.726.
9. Савченко,В. А., Смолєв,Є. С., & Гамза,Д. Є.(2023). Методика виявлення аномалій взаємодії
користувачів з інформаційними ресурсами організації. Сучасний захист інформації, 4(56), 6–12. https://doi.org/
10.31673/2409-7292.2023.030101.
10. Xu, H., Pang, G., Wang, Y., Wang, Y. (2023). Deep Isolation Forest for Anomaly Detection. IEEE Trans. on
Knowl. and Data Eng. 35(12), 12591–12604. (2023). https://doi.org/10.1109/TKDE.2023.3270293.