Database Security Overlay for Intrusion Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional database security methods focus on user-based access control, which can be inadequate for modern security standards, particularly failing to scrutinize privileged local database accesses and outsourced DBA activities, leading to potential breaches and compliance issues.
Innovation Solution
A two-stage security overlay approach that performs a lightweight check on local database accesses and forwards suspect connections to a network appliance for further scrutiny, ensuring comprehensive monitoring and blocking of unauthorized access attempts without burdening the database server, and allowing for redaction of sensitive data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a network appliance is replicated via a local agent or processing on the database server, then security monitoring coverage is improved, but server performance is degraded due to the burden of security processing
Solution Approach 1:
The patent extracts the full security processing burden from the database server by implementing a two-stage approach: a lightweight first stage on the server that only performs initial screening, and a second stage on a remote network appliance that handles comprehensive security analysis. This separation removes the performance burden from the server while maintaining complete security monitoring coverage.
Solution Approach 2:
The security processing is segmented into two distinct stages: (1) a lightweight first stage implemented on the database server that performs initial connection screening using minimal resources, and (2) a comprehensive second stage implemented on a remote network appliance that performs full security analysis. This segmentation allows the server to maintain high performance while the remote appliance provides thorough security monitoring.
2Measurement precision
If data-based security methods are implemented with high granularity access control, then access control precision is improved, but complexity of security processing is increased
Solution Approach 1:
The complex data-based security processing is segmented into two stages: a lightweight first stage that performs basic connection attribute checking with simple rules, and a comprehensive second stage on a remote appliance that handles the complex rule-based access control decisions. This segmentation reduces the complexity burden on the database server while maintaining high granularity access control precision through the remote appliance's full rule evaluation capabilities.
Data Source
AI summary
A database security overlay that identifies each network and local access gateway to a database, and monitors each access path from the identified gateways to analyze each connection to the database and block any connections determined to transport unauthorized or undesirable content. Access gateways that establish connections are identifiable by interprocess communication (IPC) mechanisms employed in accessing the database. An evaluator monitors access attempts, while a tapping mechanism on IPC mechanisms that provide the connections captures access attempts from the access gateways. The tapping mechanism intercepts and forwards access attempts to the evaluator to centralize and focus DB paths amid multiple local and external connections on the DB server. A lightweight check for each local access quickly determines if the access attempt warrants further scrutiny.


