...
首页> 外文期刊>International journal of secure software engineering >Security Gaps in Databases: A Comparison of Alternative Software Products for Web Applications Support
【24h】

Security Gaps in Databases: A Comparison of Alternative Software Products for Web Applications Support

机译:数据库中的安全漏洞:支持Web应用程序的替代软件产品的比较

获取原文
获取原文并翻译 | 示例
           

摘要

When deploying database-centric web applications, administrators should pay special attention to database security requirements. Acknowledging this, Database Management Systems (DBMS) implement several security mechanisms that help Database Administrators (DBAs) making their installations secure. However, different software products offer different sets of mechanisms, making the task of selecting the adequate package for a given installation quite hard. This paper proposes a methodology for detecting database security gaps. This methodology is based on a comprehensive list of security mechanisms (derived from widely accepted security best practices), which was used to perform a gap analysis of the security features of seven software packages composed by widely used products, including four DBMS engines and two Operating Systems (OS). The goal is to understand how much each software package helps developers and administrators to actually accomplish the security tasks that are expected from them. Results show that while there is a common set of security mechanisms that is implemented by most packages, there is another set of security tasks that have no support at all in any of the packages.
机译:部署以数据库为中心的Web应用程序时,管理员应特别注意数据库安全性要求。认识到这一点,数据库管理系统(DBMS)实现了多种安全机制,可帮助数据库管理员(DBA)使安装安全。但是,不同的软件产品提供了不同的机制集,这使得为给定安装选择适当的软件包的任务变得非常困难。本文提出了一种检测数据库安全漏洞的方法。该方法基于完整的安全机制列表(来自广泛接受的安全最佳实践),该列表用于对由广泛使用的产品组成的七个软件包的安全功能进行差距分析,其中包括四个DBMS引擎和两个系统(OS)。目的是了解每个软件包在很大程度上帮助开发人员和管理员实际完成他们期望的安全任务。结果表明,尽管大多数软件包都实现了一套通用的安全机制,但是在所有软件包中根本没有任何支持的另一组安全任务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号