Utilize este identificador para referenciar este registo: http://hdl.handle.net/10773/18233
Título: SPDC: Secure Proxied Database Connectivity
Autor: Regateiro, Diogo Domingues
Pereira, Óscar Mortágua
Aguiar, Rui L.
Palavras-chave: Access Control
Software Architecture
Security and Privacy Protection
Network Communications
Database Connectivity
Data: 2017
Editora: SCITEPRESS
Resumo: In the business world, database applications are a predominant tool where data is generally the most important asset of a company. Companies use database applications to access, explore and modify their data in order to provide a wide variety of services. When these applications run in semi-public locations and connect directly to the database, such as a reception area of a company or are connected to the internet, they can become the target of attacks by malicious users and have the hard-coded database credentials stolen. To prevent unauthorized access to a database, solutions such as virtual private networks (VPNs) are used. However, VPNs can be bypassed using internal attacks, and the stolen credentials used to gain access to the database. In this paper the Secure Proxied Database Connectivity (SPDC) is proposed, which is a new methodology to enhance the protection of the database access. It pushes the credentials to a proxy server and separates the information required to access the database between a proxy server and an authentication server. This solution is compared to a VPN using various attack scenarios and we show, with a proof-of concept, that this proposal can also be completely transparent to the user.
Peer review: yes
URI: http://hdl.handle.net/10773/18233
DOI: 10.5220/0006424500560066
ISBN: 978-989-758-255-4
Aparece nas coleções: DETI - Comunicações

Ficheiros deste registo:
Ficheiro Descrição TamanhoFormato 
(CP) - 2017-07-24 (DATA - Madrid -Spain) SPDC - Secure Proxied Database Connectivity.pdfDocumento principal302.82 kBAdobe PDFrestrictedAccess


FacebookTwitterLinkedIn
Formato BibTex MendeleyEndnote Degois 

Todos os registos no repositório estão protegidos por leis de copyright, com todos os direitos reservados.