Title | Vulnerabilities and Threat Management in Relational Database Management Systems |
Publication Type | Conference Paper |
Year of Publication | 2022 |
Authors | Gharpure, Nisha, Rai, Aradhana |
Conference Name | 2022 5th International Conference on Advances in Science and Technology (ICAST) |
Date Published | dec |
Keywords | Access Control, authentication, composability, computer security, cryptography, Database systems, Encryption, Heart, Human Behavior, Metrics, pubcrawl, relational database management systems, relational database security, relational databases, resilience, Resiliency, Safety, SQL, SQL Injection |
Abstract | Databases are at the heart of modern applications and any threats to them can seriously endanger the safety and functionality of applications relying on the services offered by a DBMS. It is therefore pertinent to identify key risks to the secure operation of a database system. This paper identifies the key risks, namely, SQL injection, weak audit trails, access management issues and issues with encryption. A malicious actor can get help from any of these issues. It can compromise integrity, availability and confidentiality of the data present in database systems. The paper also identifies various means and ways to defend against these issues and remedy them. This paper then proceeds to identify from the literature, the potential solutions to these ameliorate the threat from these vulnerabilities. It proposes the usage of encryption to protect the data from being breached and leveraging encrypted databases such as CryptoDB. Better access control norms are suggested to prevent unauthorized access, modification and deletion of the data. The paper also recommends ways to prevent SQL injection attacks through techniques such as prepared statements. |
DOI | 10.1109/ICAST55766.2022.10039599 |
Citation Key | gharpure_vulnerabilities_2022 |