THREAT MODELLING FOR SQL SERVERS
E. Bertino, D. Bruschi, S. Franzoni, I. Nai-Fovino, S. ValtoIina · Kluwer Academic Publishers eBooks · 2005
In this paper we present the results from an analysis focusing on security threats that can arise against an SQL server when included in Web application environments. The approach used is based on the STRIDE classification methodology. The results presented provide also some general guidelines and countermeasures against the different attacks that can exploit the identified vulnerabilities.