Information security of corporate databases.

Authors

  • Lysetskyi Yu.M. https://orcid.org/0000-0002-5080-1856 , ДП «ЕС ЕНД ТІ УКРАЇНА», м. Київ, Україна
  • Kalbazov D.Y. https://orcid.org/0000-0003-3370-4584 , ТОВ «Інформаційні спеціалізовані системи», м. Київ, Україна

DOI:

https://doi.org/10.34121/1028-9763-2023-3-31-37

Keywords:

databases, access rights, threats, attacks, data protection, countermeasures, бази даних, права доступу, загрози, атаки, захист даних, методи протидії

Abstract

Every day, companies all over the world collect and generate a large amount of data. Now information is digital and is stored in automated digital databases, the use of which allows for processing large amounts of data that previously were difficult to process. Protecting corporate databases and the information within them is essential for economic security. It includes their physical protection, productivity assurance and monitoring, data protection from destruction or damage, access control, and recording of new databases appearing in the infrastructure. However, since users of different types and levels of access (internal users, system administrators, contractors, partners, and M2M communications) have access to databases, they can abuse their access rights in several ways. These may be an abuse of excessive, objectively necessary, or non-used rights. As a rule, an inefficiently controlled process of granting access rights creates excessive access rights which in turn may cause new information security risks. Security measures include implementing an access management process, granting minimally necessary access rights, and implementing a mechanism to control and block the given access rights. This article discusses such threats to databases as SQL Injections and NoSQL injection attacks, insufficient detailing of events in databases, backup leaks, vulnerabilities and configurations, DDoS attacks, and methods to counter these threats. The most effective way to protect databases is to implement specialized software and hardware complexes such as Imperva DBS and Imperva WAF developed for database protection. The use of Imperva DBS will help to solve all the key tasks of database protection and provide complete visibility and control over their usage in the enterprise infrastructure.

References

1. Total data volume worldwide 2010–2025 – Statista. URL: https://www.statista.com/statistics/871513/worldwide-data-created/ (дата звернення: 17.02.2023).

2. Лисецький Ю.М., Козаченко С.В. Програмно-визначені системи зберігання даних. Переваги і особливості. Математичні машини і системи. 2021. № 1. C. 17–23.

3. Что такое SQL-инъекции и как им противостоять? URL: https://highload.today/sql-inektsii/ (дата звернення: 18.02. 2023).

4. What is a Stored Procedure? – Definition from WhatIs.com. URL: https://www.techtarget.com/searchoracle/definition/stored-procedure#:~:text=A%20stored%20procedure%20is%20a,and%20shared%20by%20multiple%20programs (дата звернення: 18.02.2023).

5. The Model View Controller Pattern – MVC Architecture and Frameworks Explained. URL: https://www.freecodecamp.org/news/the-model-view-controller-pattern-mvc-architecture-and-frameworks-explained/ (дата звернення: 19.02.2023).

6. Imperva Database Security. URL: https://www.imperva.com/resources/datasheets/Imperva-Database-Security-Datasheet-2020.pdf (дата звернення: 19.02.2023).

7. Лисецкий Ю.М. Информационная безопасность: защита от DDoS-атак. Системный анализ и информационные технологии: сб. тезисов междунар. научн.-практ. конф. (Киев, 26–30 июня 2014 г.). К.: НТУ «КПИ», 2014. С. 405–406.

8. Intrusion Detection Systems: A Modern Investigation. URL: https://www.academia.edu/13787335/Intrusion_Detection_Systems_A_Modern_Investigation (дата звернення: 20.02.2023).

9. Imperva Web Application Firewall (WAF) | App & API Protection. URL: https://www.imperva.com/products/web-application-firewall-waf/ (дата звернення: 20.02. 2023).

Downloads

Views: 86
Downloads: 37

Published

2023-09-01

Issue

Section

INFORMATION AND TELECOMMUNICATION TECHNOLOGY

How to Cite

Information security of corporate databases. (2023). Mathematical Machines and Systems, 3, 31–37. https://doi.org/10.34121/1028-9763-2023-3-31-37