Internet services and applications have become an inextricable part of daily life, enabling communication and the management of personal information from anywhere. To accommodate this increase in application and data complexity, web services have moved to a multi tiered design wherein the web server runs the application front-end logic and data are outsourced to a database or file server. Presenting Double Guard, an Intrusion Detection System that models the network behavior of user sessions across both the front-end web server and the back-end database. By monitoring both web and subsequent database requests, it is possible to ferret out attacks that independent IDS would not be able to identify.