Enforcing Access Control to Web Databases
Ahlem Bouchahda, Nhan Le Thanh, Adel Bouhoula, Faten Labbene · 2010
The insider threat against database management systems is a very dangerous and common security problem. Authorized users may compromise database security by abusing legitimate privileges to masquerade as another user or to gather data for malicious purposes. This problem is aggravated for databases made available over the web through web applications since the DBMS recognizes only the database user and ignores end users. It is important for the DBMS to have an idea of who exactly has access to data. Much research on mitigating insider threats focuses on detection. In this paper, we consider the prevention of attacks using access control and we propose (RBAC+), an extension of the NIST RBAC (Role-Based Access Control) standard with the notions of application, application profile and sub-application session. The importance of our solution is that, on the one hand, it enforces access control to the web database, and, on the other hand, it is able to identify malicious activities carried out by legitimate users of the system and prevent insider attacks.