首页> 外文会议>IEEE International Conference on Trust, Security and Privacy in Computing and Communications >Automated Enforcement of the Principle of Least Privilege over Data Source Access
【24h】

Automated Enforcement of the Principle of Least Privilege over Data Source Access

机译:自动执行最少特权的原则,通过数据源访问权限

获取原文
获取外文期刊封面目录资料

摘要

The state-of-the-art database-backed web applications usually assign full privileges to connections between applications and data sources. This phenomenon, which would enable a malicious attacker to easily compromise the applications through arbitrarily manipulating the data sources without the restriction of privileges, seriously breaks the principle of least privilege (PLP), a fundamental law of system security. Motivated to counter this problem, we propose a framework PDA (PLP over Data source Access) to automatically enforce this principle over data source access based on application-driven privilege separation. Our proposed PDA contributes from the following aspects: i) PDA achieves the privilege separation by intercepting database queries and enforcing privileged connections to database for each database query; ii) PDA can effectively defend against SQL-based vulnerabilities including buggy queries and SQL injection attacks. Lastly, we evaluate PDA on a widely used application platform, JForum, to demonstrate the effectiveness of PDA with a promising performance overhead of 8.13%.
机译:最先进的数据库备份的Web应用程序通常为应用程序和数据源之间的连接分配完全权限。这种现象,这将使恶意攻击者能够通过在没有限制特权的情况下任意操纵数据来源来容易地损害应用程序,严重打破最少特权(PLP)的原理,系统安全的基本规律。有动力解决这个问题,我们提出了一个框架PDA(PLP通过数据源访问),以基于应用程序驱动的权限分离自动强制执行此原则。我们提出的PDA从以下几个方面贡献:i)PDA通过拦截数据库查询并强制对数据库查询的特权连接来实现特权分离; ii)PDA可以有效地防止基于SQL的漏洞,包括错误查询和SQL注入攻击。最后,我们在广泛使用的应用平台,JForum上评估PDA,以证明PDA的有效性,具有8.13%的高度表现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号