首页> 外文期刊>Information Systems >Preventing database schema extraction by error message handling
【24h】

Preventing database schema extraction by error message handling

机译:通过错误消息处理防止数据库模式提取

获取原文
获取原文并翻译 | 示例
       

摘要

Nowadays, a large volume of an organization's sensitive data is stored in databases making them attractive to attackers. The useful information attackers try to obtain in the preliminary steps, is the database structure or schema. One of the popular approaches to infer and extract the schema of a database is to analyze the returned error messages from its DBMS. In this paper, we propose a framework to handle and modify the error messages automatically in order to prevent schema revealing. To this aim, after identifying and introducing an appropriate set of categories of error messages, each error message that is returned from a DBMS is placed in a proper category. According to the policy specified for each category, corresponding rules are applied for removing/modifying/obfuscating the sensitive data in the error messages of that category before submitting them to the application. The general way proposed to determine the category of an error message is employing the keyword based categorization approach, which is 95% accurate for Microsoft SQL Server 2012. (C) 2015 Elsevier Ltd. All rights reserved.
机译:如今,组织中的大量敏感数据存储在数据库中,使它们对攻击者有吸引力。攻击者试图在初步步骤中获得的有用信息是数据库结构或架构。推断和提取数据库模式的一种流行方法是分析其DBMS返回的错误消息。在本文中,我们提出了一个框架来自动处理和修改错误消息,以防止架构泄露。为此,在标识并引入了一组适当的错误消息类别之后,将从DBMS返回的每个错误消息都放在适当的类别中。根据为每个类别指定的策略,在将其提交给应用程序之前,将应用相应的规则来删除/修改/混淆该类别的错误消息中的敏感数据。建议的确定错误消息类别的一般方法是采用基于关键字的分类方法,该方法对于Microsoft SQL Server 2012而言准确率为95%。(C)2015 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号