首页> 外文会议>National information systems security conference >A BRIEF DATABASE SECURITY TUTORIAL: OR THE LESS THAN CIVIL WAR BETWEEN EASE-OF-USE AND SECURITY, THE BATTLE BETWEEN GRANT AND LEE'S PRIVILEGE, ROLES AND ROLLBACKS, MAC DAC AND FACT, EVEN DISTRIBUTION AND REPLICATION MAYBE
【24h】

A BRIEF DATABASE SECURITY TUTORIAL: OR THE LESS THAN CIVIL WAR BETWEEN EASE-OF-USE AND SECURITY, THE BATTLE BETWEEN GRANT AND LEE'S PRIVILEGE, ROLES AND ROLLBACKS, MAC DAC AND FACT, EVEN DISTRIBUTION AND REPLICATION MAYBE

机译:简短的数据库安全教程:易用性和安全性之间的战争,以及GRANT和LEE的特权,角色和回滚,MAC DAC和事实,甚至分发和复制之间的冲突

获取原文

摘要

Database security is a young interdisciplinary science. Several NCSC-rated C and B1-level operating systems are being produced and are being used. Two vendors are attempting to build B2-level systems. Many vendors are maintaining the security in their most recent database system version, a good idea because users should not have to needlessly give up performance and utility for security. The Trusted Database Interpretations has been published and is assisting architects in the layering of products. The promise and the terrors of the Internet have spurred some vendors into considering security problems that could occur when users are working with client/server and distributed applications. Some problems remain. How do we know that the code is doing exactly what it should and no more? The question is similar to that for critical code or for code that must be highly reliable. As we become more and more dependent on information systems, the results caused by some software/firmware/hardware bug will be disastrous and can not be acceptable. Legal liability, under possible negligence or even strict liability theories may be the force that causes the more reliable systems. Future database will tend to be larger, sometimes very large. To handle these larger databases, parallel and massively parallel hardware will be used. Many users will want access to their data at any time and therefore fault tolerant and replicated systems will be used. Interconnectivity will be a goal. Firewalls will be used on the Internet and many other networks. Federated database systems, hypertext, web servers, web servers with connections to other database servers, and multimedia servers will be in demand. Database systems will be largely client/server or distributed with heterogeneous nodes. Some database systems will be smart, where rules, and derived knowledge are stored and used to make further queries for the user. Operating systems may have some database management system functionality. Security research and development is needed in all of these areas. I hope that we have the appropriate fire extinguisher before the fire starts.
机译:数据库安全是一门年轻的跨学科科学。正在生产和使用几种NCSC等级的C和B1级别的操作系统。两家供应商正在尝试构建B2级系统。许多供应商都在其最新数据库系统版本中维护安全性,这是一个好主意,因为用户不必为安全性而不必要地放弃性能和实用程序。可信数据库解释已经发布,正在协助架构师进行产品分层。 Internet的前景和恐怖刺激促使一些供应商考虑在用户使用客户端/服务器和分布式应用程序时可能发生的安全问题。仍然存在一些问题。我们怎么知道代码完全按照其应有的方式工作?问题类似于关键代码或必须高度可靠的代码。随着我们越来越依赖信息系统,由某些软件/固件/硬件错误引起的结果将是灾难性的,无法接受。在可能的过失甚至严格的责任理论下,法律责任可能是导致建立更可靠系统的力量。未来的数据库将趋于更大,有时甚至很大。为了处理这些较大的数据库,将使用并行和大规模并行硬件。许多用户将随时希望访问其数据,因此将使用容错和复制的系统。互连性将是一个目标。防火墙将用于Internet和许多其他网络。将需要联合数据库系统,超文本,Web服务器,与其他数据库服务器连接的Web服务器以及多媒体服务器。数据库系统将主要是客户端/服务器或分布有异构节点。某些数据库系统将很智能,在其中存储规则和派生的知识,并用于对用户进行进一步的查询。操作系统可能具有某些数据库管理系统功能。所有这些领域都需要进行安全性研究和开发。我希望在火灾发生前我们有适当的灭火器。

著录项

相似文献

  • 外文文献
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号