A rule-based approach to database security

Annette Lerine Steenkamp, I.V. Kopaliani · 2011

According to the National Institute of Standards and Technology (NIST) (2011), which tracks software vulnerabilities, the number of software vulnerabilities has grown from 75 instances in 1996 to over 6,600 in 2006. Though the number of vulnerabilities has reduced, by the end of 2010 they were still at 4,600. Amateur and professional hackers regularly exploit these vulnerabilities causing tremendous damage. Protecting the core database schema and data with a rule-based approach is the focus of this research study. The key contribution of this research is a conceptual solution supported by a functional prototype, dbRuleSecurity, which successfully protects the database schema and data from unscrupulous alterations for Legacy, ERP, and RDBMS systems. The solution introduces a new way of implementing security patterns into the database-level protection by allowing users to define and configure specific rules for each database, and monitor and log activities for regulatory purposes. The dbRuleSecurity is comprised of three modules: Data Schema Protection (DSP) that monitors and protects database schema integrity; Server Side Data Protection (SDP) that ensures integrity of the data stored within the database on the server; and, Client Side Data Protection (CDP) that monitors and protects data on the client machine. In order to verify and validate the dbRuleSecurity, the Software Validation and Verification Plan (SVVP) was created to comply with the IEEE-1012:2004 standard. In order to evaluate the functionality of the dbRuleSecurity, 257 illustrative tests have been conducted across the three modules: DSP, SDP, and CDP. The test results have demonstrated that dbRuleSecurity is able to monitor, protect, and report the database schema and data successfully.

Read the paper · More papers on PaperTik