본문

서브메뉴

Techniques to Secure and Monitor Client Database Applications
Techniques to Secure and Monitor Client Database Applications
Techniques to Secure and Monitor Client Database Applications

상세정보

자료유형  
 학위논문 서양
최종처리일시  
20250211152946
ISBN  
9798342140942
DDC  
005.74
저자명  
Fadolalkarim, Daren.
서명/저자  
Techniques to Secure and Monitor Client Database Applications
발행사항  
[Sl] : Purdue University, 2024
발행사항  
Ann Arbor : ProQuest Dissertations & Theses, 2024
형태사항  
153 p
주기사항  
Source: Dissertations Abstracts International, Volume: 86-04, Section: A.
주기사항  
Advisor: Bertino, Elisa;Bingham, Clifton;Li, Ninghui;Aref, Walid.
학위논문주기  
Thesis (Ph.D.)--Purdue University, 2024.
초록/해제  
요약Application programs are a possible source of attacks to databases as attackers might exploit vulnerabilities in a privileged database application to perpetrate different attacks, e.g., SQL injection, Denial of Service, etc. Following secure code practices to avoid vulnerabilities is one of the best ways to prevent attacks. However, developers usually make mistakes either due to a lack of knowledge or due to bad code practices like copying code segments, which reproduce bugs and vulnerabilities in the code. Detecting and fixing such vulnerabilities manually is expensive and time-consuming. It is thus clear that in order to systematically find and fix vulnerabilities we need automatic tools. Attackers can also perform different attacks on secure code under certain circumstances. For example, a malicious insider with access privileges to the application or its binaries could make changes to the application at run time. Such attacks very often result in changes in the program's behavior, program monitoring techniques represent an effective defense to detect ongoing attacks. It is hence crucial to utilize monitoring techniques while using the applications.Therefor, comprehensive solutions for securing database client applications require combining authentication of users, access control, and encryption with automated repair techniques to patch vulnerable applications source code and anomaly detection techniques to detect changes in applications behavior while running. In this thesis, we propose AD-PROM, an Anomaly Detection system that aims at protecting relational database systems against malicious/compromised applications PROgraMs aiming at stealing data. Both systems succeeded in achieving their objectives. We also develop the Database Client Applications Fixer (DCAFixer)tool, which automatically detects and repairs three types of common vulnerabilities in SQL application programs, namely unsanitized user inputs, insecure credentials handling, and unencrypted connections.
일반주제명  
Relational data bases
일반주제명  
Software
일반주제명  
Data base management systems
일반주제명  
Data integrity
일반주제명  
Art techniques
일반주제명  
Large language models
일반주제명  
Access control
일반주제명  
Information science
기타저자  
Purdue University.
기본자료저록  
Dissertations Abstracts International. 86-04A.
전자적 위치 및 접속  
로그인 후 원문을 볼 수 있습니다.

MARC

 008250123s2024        us                              c    eng  d
■001000017164306
■00520250211152946
■006m          o    d                
■007cr#unu||||||||
■020    ▼a9798342140942
■035    ▼a(MiAaPQ)AAI31606885
■035    ▼a(MiAaPQ)Purdue26359810
■040    ▼aMiAaPQ▼cMiAaPQ
■0820  ▼a005.74
■1001  ▼aFadolalkarim,  Daren.
■24510▼aTechniques  to  Secure  and  Monitor  Client  Database  Applications
■260    ▼a[Sl]▼bPurdue  University▼c2024
■260  1▼aAnn  Arbor▼bProQuest  Dissertations  &  Theses▼c2024
■300    ▼a153  p
■500    ▼aSource:  Dissertations  Abstracts  International,  Volume:  86-04,  Section:  A.
■500    ▼aAdvisor:  Bertino,  Elisa;Bingham,  Clifton;Li,  Ninghui;Aref,  Walid.
■5021  ▼aThesis  (Ph.D.)--Purdue  University,  2024.
■520    ▼aApplication  programs  are  a  possible  source  of  attacks  to  databases  as  attackers  might  exploit  vulnerabilities  in  a  privileged  database  application  to  perpetrate  different  attacks,  e.g.,  SQL  injection,  Denial  of  Service,  etc.  Following  secure  code  practices  to  avoid  vulnerabilities  is  one  of  the  best  ways  to  prevent  attacks.  However,  developers  usually  make  mistakes  either  due  to  a  lack  of  knowledge  or  due  to  bad  code  practices  like  copying  code  segments,  which  reproduce  bugs  and  vulnerabilities  in  the  code.  Detecting  and  fixing  such  vulnerabilities  manually  is  expensive  and  time-consuming.  It  is  thus  clear  that  in  order  to  systematically  find  and  fix  vulnerabilities  we  need  automatic  tools.  Attackers  can  also  perform  different  attacks  on  secure  code  under  certain  circumstances.  For  example,  a  malicious  insider  with  access  privileges  to  the  application  or  its  binaries  could  make  changes  to  the  application  at  run  time.  Such  attacks  very  often  result  in  changes  in  the  program's  behavior,  program  monitoring  techniques  represent  an  effective  defense  to  detect  ongoing  attacks.  It  is  hence  crucial  to  utilize  monitoring  techniques  while  using  the  applications.Therefor,  comprehensive  solutions  for  securing  database  client  applications  require  combining  authentication  of  users,  access  control,  and  encryption  with  automated  repair  techniques  to  patch  vulnerable  applications  source  code  and  anomaly  detection  techniques  to  detect  changes  in  applications  behavior  while  running.  In  this  thesis,  we  propose  AD-PROM,  an  Anomaly  Detection  system  that  aims  at  protecting  relational  database  systems  against  malicious/compromised  applications  PROgraMs  aiming  at  stealing  data.  Both  systems  succeeded  in  achieving  their  objectives.  We  also  develop  the  Database  Client  Applications  Fixer  (DCAFixer)tool,  which  automatically  detects  and  repairs  three  types  of  common  vulnerabilities  in  SQL  application  programs,  namely  unsanitized  user  inputs,  insecure  credentials  handling,  and  unencrypted  connections.
■590    ▼aSchool  code:  0183.
■650  4▼aRelational  data  bases
■650  4▼aSoftware
■650  4▼aData  base  management  systems
■650  4▼aData  integrity
■650  4▼aArt  techniques
■650  4▼aLarge  language  models
■650  4▼aAccess  control
■650  4▼aInformation  science
■690    ▼a0800
■690    ▼a0723
■690    ▼a0454
■71020▼aPurdue  University.
■7730  ▼tDissertations  Abstracts  International▼g86-04A.
■790    ▼a0183
■791    ▼aPh.D.
■792    ▼a2024
■793    ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17164306▼nKERIS▼z이  자료의  원문은  한국교육학술정보원에서  제공합니다.

미리보기

내보내기

chatGPT토론

Ai 추천 관련 도서


    신착도서 더보기
    최근 3년간 통계입니다.

    소장정보

    • 예약
    • 소재불명신고
    • 나의폴더
    • 우선정리요청
    • 비도서대출신청
    • 야간 도서대출신청
    소장자료
    등록번호 청구기호 소장처 대출가능여부 대출정보
    TF10581 전자도서 대출가능 마이폴더 부재도서신고 비도서대출신청 야간 도서대출신청

    * 대출중인 자료에 한하여 예약이 가능합니다. 예약을 원하시면 예약버튼을 클릭하십시오.

    해당 도서를 다른 이용자가 함께 대출한 도서

    관련 인기도서

    로그인 후 이용 가능합니다.