首页> 外文学位 >VIEW-less value-based security.
【24h】

VIEW-less value-based security.

机译:基于VIEW的基于价值的安全性。

获取原文
获取原文并翻译 | 示例

摘要

This dissertation presents a new database security policy with broad business applicability, called Value Based Security (VBS). VBS rules create subsets of sensitive objects that depend only on the subject (user) and query type using expressions that specify values of VBS attributes. The rules are independent of: (I) Query language, object, complexity and order; (II) the DBMS; (III) Domains of VBS attributes.; The main research question is how to enforce VBS rules effectively and efficiently for dynamic SQL queries--the mainstay of client-server and data warehouse applications.; Static, DBMS-dependent facilities such as views or rules can enforce VBS effectively for static SQL queries. However they are infeasible for securing dynamic SQL queries due to: (1) High administrative complexity and coordination costs; (2) Limited Audit trail; (3) Dependence on DBMS; (4) Query scope and type restrictions; (5) Inflexible design; (6) Mandatory schema denormalization to support updates.; The dissertation presents new data driven solutions that essentially reduce the research problem to one of dynamically intercepting and modifying a dynamic SQL query to enforce VBS rules. These techniques can create generalized 'dynamic views' for SQL query access.; The described field implementation enforces VBS policy for thousands of dynamic SQL SELECT queries in a client-server data warehouse of a Fortune 50 corporation. This confirms the following advantages for the new solution: (1) Effective, consistent, efficient and transparent VBS enforcement; (2) Simple, flexible, scaleable, low cost, robust design; (3) Constant, dynamic enforcement performance independent of query scope, type and VBS rule complexity; (4) Secures SQL Update queries without denormalization; (5) No hidden side effects, independent of DBMS and location; (6) Easy, low cost administration; (7) Effective security audit.; The main research contributions of this work are: (I) Formal specification of a new Value Based database security policy. (II) A new, comprehensive, effective solution to enforce VBS policy for dynamic SQL SELECT queries. (III) A new, general technique to create "dynamic views" by dynamically modifying SQL SELECT, UPDATE, INSERT and DELETE queries.
机译:本文提出了一种新的具有广泛业务适用性的数据库安全策略,称为基于价值的安全性(VBS)。 VBS规则使用指定VBS属性值的表达式创建仅取决于主题(用户)和查询类型的敏感对象子集。规则独立于:(I)查询语言,对象,复杂性和顺序; (II)DBMS; (III)VBS属性的域。主要研究问题是如何针对动态SQL查询有效而有效地执行VBS规则,这是客户端服务器和数据仓库应用程序的主体。静态的,依赖于DBMS的工具(例如视图或规则)可以有效地对静态SQL查询实施VBS。但是,由于以下原因,它们对于保护动态SQL查询是不可行的:(1)高管理复杂性和协调成本; (2)有限的审计追踪; (3)依赖DBMS; (4)查询范围和类型限制; (5)不灵活的设计; (6)强制模式非规范化以支持更新。本文提出了一种新的数据驱动解决方案,从本质上将研究问题减少为动态拦截和修改动态SQL查询以实施VBS规则之一。这些技术可以为SQL查询访问创建通用的“动态视图”。所描述的字段实现对财富50强公司的客户端-服务器数据仓库中的数千个动态SQL SELECT查询实施VBS策略。这证实了新解决方案的以下优势:(1)有效,一致,高效和透明的VBS实施; (2)简单,灵活,可扩展,低成本,坚固的设计; (3)恒定的动态执行性能,与查询范围,类型和VBS规则复杂性无关; (4)保护SQL Update查询而不进行非规范化; (5)没有隐藏的副作用,独立于DBMS和位置; (6)简便,低成本的管理; (7)有效的安全审核。这项工作的主要研究贡献是:(I)新的基于价值的数据库安全策略的正式规范。 (II)一种新的,全面,有效的解决方案,可对动态SQL SELECT查询实施VBS策略。 (III)一种新的通用技术,可通过动态修改SQL SELECT,UPDATE,INSERT和DELETE查询来创建“动态视图”。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号