Automatic testing and evaluation method for database security in classified protection testing and evaluation and system thereof

An evaluation system and database technology, applied in the direction of electrical digital data processing, computer security devices, special data processing applications, etc., can solve problems such as evaluation errors, inspection methods are too simple, not standardized enough, etc., to ensure evaluation, reduce risk and time-consuming Short, effective work efficiency

Inactive Publication Date: 2012-07-11
ELECTRIC POWER RES INST OF GUANGDONG POWER GRID
View PDF1 Cites 13 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] 1) The inspection method is too simple, resulting in incomplete evaluation results;
[0005] 2) It takes too long and the evaluation efficiency is low;
[0006] 3) Man-made evaluation errors are likely to bring the risk of evaluation errors;
[0007] 4) When checking and evaluating the security configuration checkpoints of different database hosts, it is not standardized enough due to human factors

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Automatic testing and evaluation method for database security in classified protection testing and evaluation and system thereof
  • Automatic testing and evaluation method for database security in classified protection testing and evaluation and system thereof

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0027] The present invention will be further elaborated below in conjunction with specific embodiments.

[0028] Such as figure 1 The shown automatic evaluation method for database security in equal protection evaluation includes the following steps:

[0029] (1) For different types of databases in the equal protection evaluation, establish an evaluation script library that can check each security configuration checkpoint of each database;

[0030] (2) According to the information system security level protection evaluation requirements, for each evaluation index of the database security requirements, establish an evaluation index reference value list library;

[0031] (3) Identify the type of the database to be tested, select the corresponding evaluation script from the evaluation script library according to the established security level of the database to be tested, and execute the evaluation script on the host computer of the database to be tested, and obtain the data ret...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses an automatic testing and evaluation method for database security in classified protection testing and evaluation. The method comprises the steps of establishing testing and evaluation script library which can check various security configuration check points of each database, identifying types of the databases to be tested through a testing and evaluation script execution module, selecting an appropriate testing and evaluation script from the testing and evaluation script library, executing the testing and evaluation script, analyzing testing and evaluation script evaluation return results through a script return data analysis module to form a testing and evaluation result, storing the result into a database, and automatically generating a testing and evaluation report of the security database through a testing and evaluation report generation module. The invention also discloses an automatic testing and evaluation system of the database security in classified protection testing and evaluation, which comprises a testing and evaluation script library module, the testing and evaluation script evaluation module, the script return data analysis module and the testing and evaluation report generation module which are connected in sequence. The method and the system can perform automatic testing and evaluation on database security, so as to obtain a classified protection testing and evaluation result.

Description

technical field [0001] The present invention relates to information system security level protection evaluation (referred to as equal protection evaluation) technology, more specifically, to an automatic evaluation method for database security in equal protection evaluation. An automated evaluation system for database security. Background technique [0002] Information security involves national interests, security and sovereignty. In 2007, the Ministry of Public Security of the People's Republic of China, the State Secrets Bureau, the State Cryptography Administration, and the State Council Informatization Office jointly issued the "Notice on Carrying out the Classification of National Important Information System Security Level Protection", requiring all industries, provinces and cities to Organized and carried out the grading work for the security level protection of important information systems. According to the "Information Security Level Protection Management Measur...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): G06F21/00G06F17/30G06F21/57
Inventor 梁智强江泽鑫陈炯聪余南华梁志宏苏扬周强峰胡朝辉石炜君梁毅成
Owner ELECTRIC POWER RES INST OF GUANGDONG POWER GRID
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products