Virtual Database Security Testing via Object Catalog Import

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current database security testing methods can cause damage to online services and are challenging to set up for production environments, as they require equivalent production database systems for data integrity assurance, which is difficult to replicate.

Innovation Solution

A computer-implemented method that imports a real database object catalog into a virtual database, organizes objects by levels, applies predefined data security policies to test query message traffic, and generates a data security risk report without affecting the real production database.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data security attacks are applied to test real production database systems, then data security risk assessment can be performed, but damage may be caused to online services and data integrity may be compromised

Engineering Contradiction:
Improvedata security risk assessment capabilityVSAvoiddamage to online services
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a virtual database that replicates the structure, objects, and data of the real production database. This virtual copy serves as a safe testing environment where security attacks can be performed without affecting the actual production system. The virtual database includes virtual objects that mirror real database objects, allowing comprehensive security testing while preserving the integrity of the live system.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent separates the testing function from the production database by creating a distinct virtual database environment. This segmentation allows security testing to be performed in isolation, preventing any harmful effects from reaching the production system while maintaining the ability to assess security risks effectively.

Inventive Principle:
Principle #1Segmentation

2Reliability

If equivalent production database systems are set up for data security testing, then data integrity assurance is improved, but system complexity and setup difficulty increase significantly

Engineering Contradiction:
Improvedata integrity assuranceVSAvoidtesting system setup complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of requiring a fully replicated production environment, the patent creates a virtual database that copies only the essential structural elements, objects, and data from the production database. This virtual representation maintains data integrity for testing purposes while dramatically reducing the complexity of setup and maintenance compared to a complete production replica.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The virtual database serves multiple functions: it provides a testing environment, assesses security risks, and validates security policies, all without requiring a separate equivalent production system. This multi-functionality reduces overall system complexity while maintaining testing effectiveness.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If a virtual database is created for security testing, then damage to production systems is prevented, but setup complexity may increase due to virtualization requirements

Engineering Contradiction:
Improveprotection from security testing damageVSAvoidvirtual database setup complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements virtualization by creating a virtual database that mirrors the production database's structure and objects. This approach protects the production system from security testing damage while managing setup complexity through automated virtual object creation and mapping mechanisms that replicate only necessary elements.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The virtual database acts as an intermediary between security testing tools and the production database. It absorbs the complexity of virtualization and testing infrastructure, providing a protective layer that isolates the production system from direct testing impacts while enabling comprehensive security assessment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10362052B2Generating a virtual database to test data security of a real database
Publication Date: 2019.07.23 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10362052B2 patent drawing
  • US10362052B2 patent drawing
  • US10362052B2 patent drawing

AI summary

Determining a data security risk level of a virtual database is provided. An object catalog corresponding to a real database is imported into the virtual database. Objects in the object catalog are organized by levels. It is determined whether one or more data security policy definitions corresponding to a set of objects referenced by test query message traffic performed an action in response to determining that one or more test query messages in the test query message traffic run on the virtual database did not satisfy respective parameters of the one or more data security policy definitions. In response to determining that one or more of the data security policy definitions corresponding to the set of objects referenced by the test query message traffic did not perform the action, a test failure result is returned. A data security risk level for the virtual database is determined based on the result.