Font Size: a A A

Design And Implementation Of Automatic Detection Tools For Database Security Baselines

Posted on:2018-10-30Degree:MasterType:Thesis
Country:ChinaCandidate:Y H MaFull Text:PDF
GTID:2348330536981541Subject:Computer technology
Abstract/Summary:PDF Full Text Request
The rapid development and popularization of Internet makes information ubiquitous.In the era of information explosion,enterprise and individuals can't live without database.However,since the database often stores important and sensitive data,and the data storage is relatively centralized,which has the characteristics of easy attack and striking effect.Therefore,how to detect database security quickly and effectively has become an urgent problem in the field of database security.Aiming at this problem,this paper studies the database security baseline that can guarantee the minimum requirements of database security and puts forward the security baseline of Mongo DB and the tool set of the detection method.The automatic detection tool for database security baseline is designed and implemented in this paper to detect and discover the security problems so as to improve the security of the database.Firstly,this paper introduces relevant key technologies and theories,including active host detection technology,task scheduling algorithm and security baseline.In this paper,the automatic detection tool for database security baselines is designed and implemented.Before the detection,the basis and reference for database security baseline detection has to be setted up.By consulting the security baseline of MySQL and Oracle security and incorporating the related content of Mongo DB database security,the security baseline of Mongo DB database is putted forward.After the criteria is setted up,the security baseline of the database can be detected.Through the technology of active host detection,the type and version of the database installed on the remote host are gained.According to the result and the tool set of detection method,the corresponding scripts are generated and copied to remote host to execute for obtaining the detected results.At the same time,in order to ensure the good execution efficiency of the tool in the complex environment,the priority task scheduleing function is designed and implemented.Then,the evaluation method based on the security baseline weight value is used to calcula te the compliance of the database to evaluate the database security.Finally,all of the modules of the database security baseline automatic detection tool are tested by functional test.In conclusion,this paper implements the database security baseline automation detection tool.The system test result show that the tool meets the design goal.
Keywords/Search Tags:database security, security baseline, task scheduling, detection
PDF Full Text Request
Related items