首页> 外文会议>IEEE International Symposium on Technologies for Homeland Security >Establishing Independent Audit Mechanisms for Database Management Systems
【24h】

Establishing Independent Audit Mechanisms for Database Management Systems

机译:建立数据库管理系统的独立审计机制

获取原文

摘要

The pervasive use of databases for the storage of critical and sensitive information in many organizations has led to an increase in the rate at which databases are exploited in computer crimes. While there are several techniques and tools available for database forensic analysis, such tools usually assume an apriori database preparation, such as relying on tamper-detection software to already be in place and the use of detailed logging. Further, such tools are built-in and thus can be compromised or corrupted along with the database itself. In practice, investigators need forensic and security audit tools that work on poorlyconfigured systems and make no assumptions about the extent of damage or malicious hacking in a database.In this paper, we present our database forensics methods, which are capable of examining database content from a storage (disk or RAM) image without using any log or file system metadata. We describe how these methods can be used to detect security breaches in an untrusted environment where the security threat arose from a privileged user (or someone who has obtained such privileges). Finally, we argue that a comprehensive and independent audit framework is necessary in order to detect and counteract threats in an environment where the security breach originates from an administrator (either at database or operating system level).
机译:对于关键和敏感信息在许多组织中贮存普遍使用的数据库已导致增加在该数据库在计算机犯罪利用的速度。虽然有多种技术和适用于数据库取证分析工具,这些工具通常假设一个先验数据库的准备,如依靠篡改检测软件已经到位,并使用详细记录的。此外,这些工具是内置的,因此可以被破坏或与数据库本身一起损坏。在实践中,调查人员需要法医和安全审计工具,对poorlyconfigured系统工作,并没有关于在database.In损坏或恶意黑客攻击的程度假设本文中,我们提出我们的数据库取证的方法,这是能够从检查数据库内容存储(磁盘或RAM)图像,而无需使用任何日志或文件系统的元数据。我们描述这些方法如何可以用来检测在安全威胁来自(谁取得这样的特权或某人)特权用户产生一个不可信的环境安全隐患。最后,我们认为,一个全面和独立审计框架是必要的,以便及时发现和打击威胁的环境下从管理员的安全漏洞起源(无论是在数据库或操作系统级别)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号