首页> 外文期刊>International journal of web information systems >Using the structure of B+-trees for enhancing logging mechanisms of databases
【24h】

Using the structure of B+-trees for enhancing logging mechanisms of databases

机译:使用B +树的结构来增强数据库的日志记录机制

获取原文
获取原文并翻译 | 示例
       

摘要

Purpose - Today's database management systems implement sophisticated access control mechanisms to prevent unauthorized access and modifications. For instance, this is an important basic requirement for SOX (Sarbanes-Oxley Act) compliance, whereby every past transaction has to be traceable at any time. However, malicious database administrators may still be able to bypass the security mechanisms in order to make hidden modifications to the database. This paper aims to address these issues. Design/methodology/approach - In this paper the authors define a novel signature of a B+-tree, a widely-used storage structure in database management systems, and propose its utilization for supporting the logging in databases. This additional logging mechanism is especially useful in conjunction with forensic techniques that directly target the underlying tree-structure of an index. Several techniques for applying this signature in the context of digital forensics on B+-trees are proposed in the course of this paper. Furthermore, the authors' signature can be used to generate exact copies of an index for backup purposes, thereby enabling the owner to completely restore data, even on the structural level. Findings - For database systems in enterprise environments, compliance to regulatory standards such as SOX (Sarbanes-Oxley Act), whereby every past transaction has to be traceable at any time, is a fundamental requirement. Today's database management systems usually implement sophisticated access control mechanisms to prevent unauthorized access and modifications. Nonetheless malicious database administrators would be able to bypass the security mechanisms in order to make modifications to the database, while covering their tracks. Originality/value - In this paper, the authors demonstrate how the tree structure of the underlying store engine can be used to enhance forensic logging mechanisms of the database. They define a novel signature for B+-trees, which are used by the InnoDB storage engine. This signature stores the structure of database storage files and can help in reconstructing previous versions of the file for forensic purposes. Furthermore, the authors' signature can be used to generate exact copies of an index for backup purposes, thus enabling the owner to completely restore data, even on the structural level. The authors applied their concept to four real-life scenarios in order to evaluate its effectiveness.
机译:目的-当今的数据库管理系统实现了复杂的访问控制机制,以防止未经授权的访问和修改。例如,这是遵守SOX(萨班斯-奥克斯利法案)的重要基本要求,因此过去的每笔交易都必须随时可追溯。但是,恶意数据库管理员仍然可以绕过安全机制,以便对数据库进行隐藏修改。本文旨在解决这些问题。设计/方法/方法-在本文中,作者定义了B +树的新颖签名,B +树是数据库管理系统中广泛使用的存储结构,并提出了将其用于支持数据库登录的方法。这种附加的日志记录机制与直接针对索引的基础树结构的取证技术结合使用时特别有用。在本文的过程中,提出了几种在B +树上进行数字取证的情况下应用此签名的技术。此外,作者的签名可用于生成索引的精确副本以用于备份,从而使所有者即使在结构级别上也可以完全还原数据。发现-对于企业环境中的数据库系统,基本要求是必须遵守SOX(萨班斯-奥克斯利法案)之类的监管标准,根据该标准,每笔过去的交易都必须随时可追溯。当今的数据库管理系统通常实现复杂的访问控制机制,以防止未经授权的访问和修改。但是,恶意数据库管理员将能够绕过安全机制,以便在对数据库进行修改的同时对其进行修改。原创性/价值-在本文中,作者演示了如何使用底层存储引擎的树结构来增强数据库的取证日志记录机制。他们为B +树定义了一个新颖的签名,供InnoDB存储引擎使用。此签名存储数据库存储文件的结构,并且可以帮助出于司法目的重建文件的先前版本。此外,作者的签名可用于生成索引的精确副本以用于备份,从而使所有者即使在结构级别上也可以完全还原数据。作者将其概念应用于四个现实生活场景,以评估其有效性。

著录项

  • 来源
  • 作者单位

    Technical Mathematics in Computer Science at the Vienna University of Technology, specializing in cryptography and numerics;

    Vienna University of Technology and a researcher at SBA Research;

    MMath Masters (1st class) from the University of St Andrews, Scotland;

    MSc degree in computer and data security from the Vienna University of Technology, Vienna, Austria;

    B.Sc. degree in business informatics from the University of Vienna, Vienna, Austria, and the MSc degree in information and communication security systems from the Royal Institute of Technology, Stockholm, Sweden;

    PhD degree from the Vienna University of Technology, Vienna, Austria.;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    database forensics; b+-tree; database log; databases; database management systems;

    机译:数据库取证;b +树数据库日志;数据库;数据库管理系统;
  • 入库时间 2022-08-17 13:47:05

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号