Unlock instant, AI-driven research and patent intelligence for your innovation.

Method for enhancing safety of Oracle database server by utilizing progress infusion and TNS protocol analysis

A server security and protocol analysis technology, applied in the field of external security enhancement for Oracle database servers, can solve problems such as danger, large impact on original system performance, and difficulty in making up for the impact of security enhancement on database performance, etc., to achieve the effect of security feature enhancement

Inactive Publication Date: 2012-10-03
中国人民解放军理工大学指挥自动化学院
View PDF5 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0007] (2) Performance impact analysis: After receiving the processing results of the database, the two security enhancement methods need to copy the results and return them to the client, so they have a great impact on the performance of the original system
When the amount of data accessed reaches a certain scale, the security enhancement brought by it will be difficult to compensate for its impact on database performance
[0008] (3) Anti-attack ability: The anti-attack ability of the data access interface proxy method is poor, and it cannot prevent attacks from client software such as SQL*PLUS and DBA Studio.
The third method does not require additional DLL files compared to the other two methods, so it is more flexible but also more complicated and dangerous
Once there is a bug in the injected code, the remote thread will crash immediately

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method for enhancing safety of Oracle database server by utilizing progress infusion and TNS protocol analysis
  • Method for enhancing safety of Oracle database server by utilizing progress infusion and TNS protocol analysis
  • Method for enhancing safety of Oracle database server by utilizing progress infusion and TNS protocol analysis

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0035] The present invention belongs to the method of compiling code into DLL and mapping it to remote process by using CreateRemoteThread and LoadLibrary in the optional implementation scheme of process injection.

[0036] The implementation object of the method for enhancing the security of the Oracle database server by using process injection and TNS protocol analysis in the present invention is the Oracle database server series, and the operating system platform is the Microsoft Windows series. The architecture of the method includes server-side and client-side. The client is an ordinary commercial Oracle client, and no additional software needs to be installed, and the server includes an Oracle database server and a security enhancement module. The security enhancement module includes a TNS protocol analysis module and a security feature enhancement function module. First, the TNS protocol analysis module and security feature enhancement function module are injected into ...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a method for enhancing the safety of an Oracle database server from the outside by utilizing progress infusion and TNS protocol analysis, comprising the following steps: firstly, TNS protocol analysis and safety characteristic enhancing functional modules are compiled into DLL; a create remote thread and a load library are used for mapping the DLL to a remote Oracle servo progress; and when the Oracle servo progress receives the communication information of an Oracle client terminal and a server terminal, the TNS protocol analysis module and the safety characteristic enhancing functional module begin to work. The invention can support all data access interfaces and has very good versatility; the invention can directly run at the server terminal, can protect attack from a long range and can also protect attack from the local machine; and for a result returned by the database server to the client terminal, the invention only records the successful or unsuccessful operation information of the database server, avoids duplicating a result set and lowers the influence on the performance of the database.

Description

technical field [0001] The invention belongs to the technology of externally enhancing the security of an Oracle database server, in particular to a method for enhancing the security of an Oracle database server by utilizing process injection and TNS protocol analysis. Background technique [0002] Oracle database server is one of the most widely used commercial database servers in the world. The security protection function provided by itself cannot meet the needs of fields with high requirements for information security, such as government confidential departments, public security departments, military departments, etc. Therefore, It is necessary to perform security enhancement on the Oracle database server externally. Traditional security enhancement methods such as figure 1 As shown, the principle is to add an isolation layer between the Oracle client and the Oracle server, that is, the security enhancement system, and all communication messages from the client to the s...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): G06F21/00G06F9/44H04L29/06G06F21/55
Inventor 张涛赵成赵敏汤凯王金双袁志坚宋磊
Owner 中国人民解放军理工大学指挥自动化学院