Anomaly Detection in MariaDB/MySQL Database Activity Using Isolation Forest Based on Binary Log Extraction and Temporal Aggregation
Abstract
This study proposes a behavior-based framework for detecting anomalous activity in MariaDB/MySQL databases using unsupervised machine learning. Database activity was extracted from ROW-format binary logs using the pymysqlreplication library, then transformed through One-Hot Encoding and one-minute temporal aggregation into a 23-feature representation covering 82 active time slots. Isolation Forest was implemented with PyCaret using a contamination value of 0.08. The model achieved a ROC AUC of 0.9679 and 100% recall, detecting all four anomalous intervals with three false positives among 78 normal observations. Feature analysis identified transaction payload size as the strongest anomaly indicator.
A controlled resampling experiment reduced anomaly prevalence from 4.9% to 0.07% while preserving the original empirical characteristics. Under this condition, precision fell to 0.87%, whereas recall remained at 100% and ROC AUC reached 0.9759. Recurring benign structural events, particularly schema initialization, could receive higher anomaly scores than genuine transaction spikes under extreme class imbalance. These findings show that the framework is effective for short-window detection but requires adaptive contamination tuning, dynamic thresholding, or explicit handling of recurring benign events for long-term deployment. An interactive Streamlit dashboard was also developed for operational monitoring.Keywords
Full Text:
PDFReferences
Al Farizi, W. S., Hidayah, I., & Rizal, M. N. (2021). Isolation Forest Based Anomaly Detection: A Systematic Literature Review. 2021 8th International Conference on Information Technology, Computer and Electrical Engineering, ICITACEE 2021, 118–122. https://doi.org/10.1109/ICITACEE53184.2021.9617498
Alzaabi, F. R., & Mehmood, A. (2024). A Review of Recent Advances, Challenges, and Opportunities in Malicious Insider Threat Detection Using Machine Learning Methods. IEEE Access, 12, 30907–30927. https://doi.org/10.1109/ACCESS.2024.3369906
Breiman, L. (2001). Random Forests. Machine Learning, 45(1), 5–32. https://doi.org/10.1023/A:1010933404324
Buczak, A. L., & Guven, E. (2016). A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection. IEEE Communications Surveys and Tutorials, 18(2), 1153–1176. https://doi.org/10.1109/COMST.2015.2494502
Cao, Y., Xiang, H., Zhang, H., Zhu, Y., & Ting, K. M. (2025). Anomaly Detection Based on Isolation Mechanisms: A Survey. Machine Intelligence Research 2025 22:5, 22(5), 849–865. https://doi.org/10.1007/S11633-025-1554-4
Chandola, V., Banerjee, A., & Kumar, V. (2009). Anomaly detection. ACM Computing Surveys, 41(3), 1–58. https://doi.org/10.1145/1541880.1541882
Chourasiya, L., Khatri, S., Lilhore, U. K., Simaiya, S., Alroobaea, R., Baqasah, A. M., Alsafyani, M., & Khan, M. (2025). Advanced system log analyzer for anomaly detection and cyber forensic investigations using LSTM and transformer networks. Journal of Cloud Computing, 14(1). https://doi.org/10.1186/S13677-025-00789-Y
Ferrag, M. A., Maglaras, L., Moschoyiannis, S., & Janicke, H. (2020). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications, 50, 102419. https://doi.org/10.1016/J.JISA.2019.102419
Hariri, S., Kind, M. C., & Brunner, R. J. (2021). Extended Isolation Forest. IEEE Transactions on Knowledge and Data Engineering, 33(4), 1479–1489. https://doi.org/10.1109/TKDE.2019.2947676
Li, Z., Shi, J., & van Leeuwen, M. (2026). Graph Neural Networks Based Log Anomaly Detection and Explanation. Data Mining and Knowledge Discovery. https://doi.org/10.1007/s10618-026-01235-6
Liu, F. T., Ting, K. M., & Zhou, Z. H. (2008). Isolation forest. Proceedings - IEEE International Conference on Data Mining, ICDM, 413–422. https://doi.org/10.1109/ICDM.2008.17
Liu, F. T., Ting, K. M., & Zhou, Z.-H. (2012). Isolation-Based Anomaly Detection. ACM Transactions on Knowledge Discovery from Data, 6(1), 1–39. https://doi.org/10.1145/2133360.2133363
Mahbooba, B., Timilsina, M., Sahal, R., & Serrano, M. (2021). Explainable Artificial Intelligence (XAI) to Enhance Trust Management in Intrusion Detection Systems Using Decision Tree Model. Complexity, 2021. https://doi.org/10.1155/2021/6634811
MariaDB Foundation. (2026). Binary Log Formats. https://mariadb.com/docs/server/server-management/server-monitoring-logs/binary-log/binary-log-formats
Momand, A., Jan, S. U., & Ramzan, N. (2023). A Systematic and Comprehensive Survey of Recent Advances in Intrusion Detection Systems Using Machine Learning: Deep Learning, Datasets, and Attack Taxonomy. Journal of Sensors, 2023(1), 6048087. https://doi.org/10.1155/2023/6048087
Pedregosa, F., Varoquaux, G., Gramfort, A., Michel, V., Thirion, B., Grisel, O., Blondel, M., Prettenhofer, P., Weiss, R., Dubourg, V., Vanderplas, J., Passos, A., Cournapeau, D., Brucher, M., Perrot, M., & Duchesnay, É. (2011). Scikit-learn: Machine Learning in Python. Journal of Machine Learning Research, 12, 2825–2830.
PyCaret. (2026). PyCaret: Low-Code Machine Learning for Python. https://pycaret.org/
Rachwal, A., Karczmarek, P., Rachwal, A., & Stegierski, R. (2024). Isolation Forest With Exclusion of Attributes Based on Shapley Index. IEEE Access, 12, 101797–101813. https://doi.org/10.1109/ACCESS.2024.3432174
Sallam, A., & Bertino, E. (2019). Techniques and Systems for Anomaly Detection in Database Systems. Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 11550 LNCS, 113–133. https://doi.org/10.1007/978-3-030-17277-0_7
Sussan, O., Matthias, D., & Anireh, V. (2023). A Model for Intrusion Detection and Prevention in a Database System Using Deep Learning. Journal of Web Engineering & Technology, 10(2), 1–9.
Tengku, T. D. F., Buaton, R., & Syahputra, S. (2025). Implementation of the Isolation Forest Algorithm for MySQL Query Performance Anomaly Detection Based on Data Performance Schema. Journal of Artificial Intelligence and Engineering Applications, 5(1), 592–597.
Uchenna Jeremiah, N., Bernice Stephen, B., Oluwatobi, O., Victor Ayomide, A., Abiodun John, O., Samuel, N., & Oluwaseyi Segun, A. (n.d.). Machine Learning-Driven Anomaly Detection in a Large-Scale Database Systems: A Systematic Literature Review. https://doi.org/10.51244/IJRSI
Uchenna Jeremiah, N., Stephen, B. B., Oluwatobi, O., Ayomide, A. V, John, O. A., Samuel, N., & Segun, A. O. (2026). Machine Learning-Driven Anomaly Detection in a Large-Scale Database Systems: A Systematic Literature Review. International Journal of Research and Scientific Innovation, 13(4). https://doi.org/10.51244/IJRSI.2026.1304000140
Xu, H., Pang, G., Wang, Y., & Wang, Y. (2023). Deep Isolation Forest for Anomaly Detection. IEEE Transactions on Knowledge and Data Engineering, 35(12), 12591–12604. https://doi.org/10.1109/TKDE.2023.3270293
Zhang, L., Jia, T., Tan, X., Huang, X., Jia, M., Liu, H., Wu, Z., & Li, Y. (2025). E-Log: Fine-Grained Elastic Log-Based Anomaly Detection and Diagnosis for Databases. IEEE Transactions on Services Computing, 18(5), 2808–2821. https://doi.org/10.1109/TSC.2025.3594870
DOI: https://doi.org/10.30596/jcositte.v7i2.31998
Refbacks
- There are currently no refbacks.




.png)

