Traditional database security mechanisms are very limited in defending against data attacks. Authorized but malicious transactions can make a database useless by impairing its integrity and availability. This paper presents the design of a real-time data attack isolation system, denoted DAIS. DAIS isolates likely suspicious actions before a definite determination of intrusion is reported. In this way, the database can be immunized from many malicious transactions. DAIS is a COTS-DBMSspecific implementation of a general isolation algorithm that we developed [Liu P, Jajodia S, McCollum CD. Intrusion confinement by isolation in information systems. Journal of Computer Security, 2000;8(4):243