Hardening web applications using a least privilege DBMS access model

Stuart Steiner, Daniel Conte de Leon, Ananth A. Jillepalli · 2018

Within the last three years hundreds of millions of private data records have been compromised in high-profile data breaches, resulting in billions of dollars in economic losses and unrecoverable loss of privacy. One commonality is that attackers obtained administrative-level access to records on a central database. We argue that the widespread practice of highest privilege design and configuration is a significant contributor, where users and applications are given the highest level of privilege needed to execute the union of all needed tasks. One problematic common practice is, in a web-based application, for front-end and middleware processes to have root privileges to the complete DBMS back-end database. This practice is in stark opposition to the well-known secure design principle of least privilege introduced 40 years ago. Enforcing least privilege at all levels of a web application would help prevent future all-lost cyber-compromises. Here we introduce Hierarchical Policy (HPol), a formal access control modeling tool used in modeling web application database security.

Read the paper · More papers on PaperTik