Please use this identifier to cite or link to this item: http://hdl.handle.net/10773/16166
Full metadata record
DC FieldValueLanguage
dc.contributor.authorPereira, Óscar Mortáguapt
dc.contributor.authorRegateiro, Diogo Dominguespt
dc.contributor.authorAguiar, Rui L.pt
dc.date.accessioned2016-09-27T13:59:56Z-
dc.date.issued2015-12-
dc.identifier.issn0218-1940pt
dc.identifier.urihttp://hdl.handle.net/10773/16166-
dc.description.abstractIn database applications, access control security layers are mostly developed from tools provided by vendors of database management systems and deployed in the same servers containing the data to be protected. This solution conveys several drawbacks. Among them we emphasize: (1) if policies are complex, their enforcement can lead to performance decay of database servers; (2) when modifications in the established policies implies modifications in the business logic (usually deployed at the client-side), there is no other possibility than modify the business logic in advance and, finally, 3) malicious users can issue CRUD expressions systematically against the DBMS expecting to identify any security gap. In order to overcome these drawbacks, in this paper we propose an access control stack characterized by: most of the mechanisms are deployed at the client-side; whenever security policies evolve, the security mechanisms are automatically updated at runtime and, finally, client-side applications do not handle CRUD expressions directly. We also present an implementation of the proposed stack to prove its feasibility. This paper presents a new approach to enforce access control in database applications, this way expecting to contribute positively to the state of the art in the field.pt
dc.language.isoengpt
dc.publisherWorld Scientific Publishingpt
dc.relationFCT - UID/EEA/50008/2013pt
dc.rightsrestrictedAccesspor
dc.subjectInformation securitypt
dc.subjectAccess controlpt
dc.subjectDatabasept
dc.subjectSQLpt
dc.subjectSoftware architecturept
dc.titleSecure, dynamic and distributed access control stack for database applicationspt
dc.typearticlept
dc.peerreviewedyespt
ua.distributioninternationalpt
degois.publication.firstPage1703pt
degois.publication.issue9-10pt
degois.publication.lastPage1708pt
degois.publication.titleInternational Journal of Software Engineering and Knowledge Engineeringpt
degois.publication.volume25pt
dc.date.embargo10000-01-01-
dc.identifier.doi10.1142/S0218194015710035pt
Appears in Collections:DETI - Artigos

Files in This Item:
File Description SizeFormat 
(JA) - 2015-12-01 (IJSEKE - Journal) Secure, Dynamic and Distributed Access Control Stack for Database Applications.pdfDocumento principal147.2 kBAdobe PDFrestrictedAccess


FacebookTwitterLinkedIn
Formato BibTex MendeleyEndnote Degois 

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.