Database Metadata Shell for SQL Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large enterprises face challenges in securing their database management systems due to sophisticated cybersecurity attacks, which are difficult to detect and trace, leading to potential data exfiltration and privilege escalation.
Innovation Solution
A computer-implemented method that populates a metadata shell database with hash values corresponding to verified database system installations, monitors metadata information, and alerts administrators if discrepancies are found, utilizing a locked-down environment with firewalls and whitelisting to maintain integrity and detect unauthorized changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If database systems are deployed on enterprise networks to enable data access and operations, then productivity and business functionality are improved, but the systems become vulnerable to cybersecurity attacks and compromises
Solution Approach 1:
The patent creates a metadata shell database in advance that contains hash values of verified database system metadata. This baseline is established before deployment, allowing future comparisons to detect any unauthorized modifications or attacks on the database system.
Solution Approach 2:
The patent introduces a metadata shell database as an intermediary layer between the enterprise network and the actual database systems. This shell database stores reference hash values and serves as a secure comparison mechanism to detect compromises without exposing the actual database systems directly.
2Ease of operation
If traditional security monitoring methods are used to detect attacks, then ease of operation is maintained, but detection precision and reliability are insufficient due to sophisticated attack techniques
Solution Approach 1:
The patent replaces traditional mechanical security monitoring methods with a cryptographic hash-based detection system. By computing hash values of database metadata and comparing them against the metadata shell database, the system achieves high precision in detecting unauthorized changes without complex monitoring mechanisms.
Solution Approach 2:
The patent changes the detection parameter from monitoring user actions or network traffic to comparing cryptographic hash values of database metadata. This parameter transformation enables precise detection of even minor unauthorized modifications while maintaining operational simplicity.
3Reliability
If hash values are computed and stored for all database systems to enable compromise detection, then reliability of security detection is improved, but device complexity and computational resources increase
Solution Approach 1:
The patent extracts only the essential metadata from database systems and computes hash values of this extracted information, rather than monitoring entire database contents. This extraction approach reduces computational complexity while maintaining reliable compromise detection capability.
Solution Approach 2:
The patent creates a simplified copy of database system characteristics in the form of metadata hash values, stored in the metadata shell database. This copying mechanism enables reliable comparison and compromise detection without requiring access to or processing of the actual database systems.
4Stability of the object's composition
If continuous monitoring of database metadata is implemented to detect unauthorized changes, then data integrity is improved, but loss of time and computational overhead increase
Solution Approach 1:
The patent implements periodic monitoring where hash values are computed and compared at scheduled intervals rather than continuously. This periodic action maintains data integrity monitoring while significantly reducing time loss and computational overhead compared to continuous monitoring approaches.
Data Source
AI summary
The present disclosure describes a computer-implemented method that includes: populating a metadata shell database with one or more hash values, wherein: each hash value corresponds to a verified installation of a database system, and the metadata shell database is maintained within a locked-down environment on an enterprise network; and monitoring metadata information of one or more database systems on the enterprise network based on periodically accessing metadata information of one or more database systems; and determining whether a database system on the enterprise network has been compromised based on a hash value of the metadata information of the database system and the one or more hash values from the metadata shell database.


