...
首页> 外文期刊>The international arab journal of information technology >Advanced Analysis of the Integrity of Access Control Policies: the Specific Case of Databases
【24h】

Advanced Analysis of the Integrity of Access Control Policies: the Specific Case of Databases

机译:高级分析访问控制策略的完整性:数据库的具体情况

获取原文
获取原文并翻译 | 示例

摘要

Databases are considered as one of the most compromised assets according to 2014-2016 Verizon Data Breach Reports. The reason is that databases are at the heart of Information Systems (IS) and store confidential business or private records. Ensuring the integrity of sensitive records is highly required and even vital in critical systems (e-health, clouds, e-government, big data, e-commerce, etc.,). The access control is a key mechanism for ensuring the integrity and preserving the privacy in large scale and critical infrastructures. Nonetheless, excessive, unused and abused access privileges are identified as most critical threats in the top ten database security threats according to 2013-2015 Imperva Application Defense Center reports. To address this issue, we focus in this paper on the analysis of the integrity of access control policies within relational databases. We propose a rigorous and complete solution to help security architects verifying the correspondence between the security planning and its concrete implementation. We define a formal framework for detecting non-compliance anomalies in concrete Role Based Access Control (RBAC) policies. We rely on an example to illustrate the relevance of our contribution.
机译:数据库被视为根据2014-2016 verizon数据泄露报告的最严重资产之一。原因是数据库位于信息系统(IS)的核心并存储机密业务或私人记录。确保敏感记录的完整性是非常需要的,甚至在关键系统中至关重要(电子健康,云,电子政务,大数据,电子商务等)。访问控制是确保完整性和维护大规模和关键基础架构的隐私的关键机制。尽管如此,根据2013-2015 imperva应用防务中心报告,仍然将过度,未使用和滥用的访问权限被确定为十大数据库安全威胁中的最关键威胁。为了解决这个问题,我们专注于本文对关系数据库中的访问控制策略完整性的分析。我们提出了一个严格和完整的解决方案,帮助安全架构师验证安全规划与其具体实施之间的对应关系。我们定义了一个正式的框架,用于检测基于混凝土角色的访问控制(RBAC)政策中的非合规性异常。我们依靠一个例子来说明我们的贡献的相关性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号