基于数据库安全保障的审计系统的设计与实现
Design and implementation of audit system based on database security control
-
摘要: 针对目前大多数据库内部操作不透明,易造成机密信息泄漏、资源滥用等问题,设计了一套数据库审计系统.该系统采取旁路监听的方式,对同一局域网中服务器的指定端口进行流量抓取,获得监听网络数据,通过分析抓取到的网络数据包,将审计信息及时备份到安全的数据库中,以备查找与分析.系统通过监控外界用户对数据库的访问操作,记录操作行为,并及时反馈给审计人员,从而使审计人员能够实时掌握数据库系统的安全状态,有效保障数据库的安全.测试结果表明,系统的有效性和实时性良好.
-
关键词:
- 数据库安全 /
- 审计系统 /
- MySQL /
- SQL Server
Abstract: In view of the drawbacks that internal operations of present database are mostly opaque,which likely causes confidential information leakage and resource abuse,a set of database audit system was proposed.The bypass to monitor was adopted in the system,through traffic grab to the specified port number on the server in the same LAN,network packets could be obtained.And then these captured network packets were analyzed,finally the analyzed audit information would backup to the secure database in a timely manner for search and analysis.The system could effectively ensure the security of database by monitoring the external users access to the database operation,recording operation behavior,and timely feeding back to the auditor controlling the database system security status in real time.The test results showed that the system had good character of effectiveness and real-time.-
Key words:
- database security /
- audit system /
- MySQL /
- SQL Server
-
-
[1]
索炜.浅谈IT技术在数据库审计领域的应用[N].中国审计报,2013-01-09(8).
-
[2]
钱正麟,高航,李曙强.基于网络侦听的数据库审计方法[J].计算机系统应用,2014,23(4):97.
-
[3]
徐国智.基于Web 2.0技术的数据库审计管理系统的设计与实现[D].北京:清华大学,2012.
-
[4]
余本德,陈永义.对数据库审计的思考[J].华南金融电脑,2008(1):21.
-
[5]
Bishop M.Computer Security:Art and Science[M].New York:Addison Wesley,2002.
-
[6]
李亿红,徐韧,程祥圣.基于XML和Web Service的数据库审计系统[J].计算机应用与软件,2010,27(1):198.
-
[7]
王渊,马骏.一种基于入侵检测的数据库安全审计[J].计算机仿真,2007,24(2):33.
-
[8]
李晶媛,韩慧莲.一个基于误用检测的数据库安全审计系统[J].计算机与数字工程,2009,37(10):116.
-
[9]
李丽萍,杨寅春,何守才,等.数据库安全中审计的设计与实现[J].计算机科学,2005,32(S7):83.
-
[10]
Liu P.Architectures for intrusion tolerant database systems[C]//Proceedings of 200218th Annual Conference on Computer Security Applications,Piscatway:IEEE,2003:311.
-
[11]
冯玉东,冯明卿,余宁.ASP常见安全隐患及防范措施[J].郑州轻工业学院学报:自然科学版,2005,20(3):102.
-
[12]
胡滨.基于Windows平台的底层网络数据包捕获技术[J].计算机工程与设计,2005,26(11):3037.
-
[13]
刘斌,代素环.基于Libpcap的数据包捕获机制的实现[J].农业网络信息,2008(9):62.
-
[1]
计量
- PDF下载量: 32
- 文章访问数: 896
- 引证文献数: 0