• DocumentCode
    2900748
  • Title

    A Trust-Based Benchmark for DBMS Configurations

  • Author

    Neto, Afonso Araújo ; Vieira, Marco

  • Author_Institution
    Dept. of Inf. Eng., Univ. of Coimbra, Coimbra, Portugal
  • fYear
    2009
  • fDate
    16-18 Nov. 2009
  • Firstpage
    143
  • Lastpage
    150
  • Abstract
    Database management systems (DBMS), the central component of many computers applications, are typically immersed in very complex environments. Protecting the DBMS from security attacks requires evaluating a long list of complex configuration characteristics that may impact, in a variety of ways, the applications and people that interact with the database system. Effectively, understanding the impact of different configuration alternatives in terms of security is one of the most difficult problems faced by database administrators nowadays (DBA). In this paper we propose a benchmark that allows DBAs to assess and compare database configurations. The benchmark provides a trust-based security metric, named minimum untrustworthiness, that expresses the minimum level of distrust the DBA should have in a given configuration regarding its ability to prevent attacks. The practical application of the benchmark in four real large database installations shows that it is quite easy to use and is, in fact, a powerful tool for DBAs to make informed security decisions, by taking into account the specifics needs of the environment being managed.
  • Keywords
    database management systems; security of data; software metrics; user interfaces; DBMS configurations; computers applications; database administrators; database configurations; database management systems; trust-based benchmark; trust-based security metric; Charge measurement; Computer hacking; Current measurement; Data engineering; Data security; Database systems; Environmental management; Informatics; Information security; Protection; DBMS; Security; benchmarking; configurations; trust-based metrics; trustworthiness;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Computing, 2009. PRDC '09. 15th IEEE Pacific Rim International Symposium on
  • Conference_Location
    Shanghai
  • Print_ISBN
    978-0-7695-3849-5
  • Type

    conf

  • DOI
    10.1109/PRDC.2009.31
  • Filename
    5368487