Article in Press
This article is currently in the Just Accepted phase. The final published version may have formatting changes or additional corrections.
Abstract
Modern enterprise data repositories are increasingly subjected to sophisticated cyber-attacks, ranging from advanced SQL injection (SQLi) variants to insider data exfiltration. Traditional signature-based Intrusion Detection Systems (IDS) and static database auditing tools frequently fail against zero-day exploits and polymorphic threat vectors. This paper presents a comprehensive framework for database security threat detection utilizing hybrid Machine Learning (ML) methodologies. By combining supervised classification models for known attack signatures with unsupervised anomaly detection for behavioural drift, the proposed system analyses real-time Database Management System (DBMS) access logs, query structures, and session telemetry. The framework demonstrates a notable reduction in false-positive rates while maintaining high classification accuracy, bridging the gap between automated threat mitigation and database administration.
