Security Assessment Model for Database Relational Designs

Author:

Alshammari Bandar M.

Abstract

The increasing number of data breaches has led many organizations to focus on securing their IT infrastructures and application architectures. However, the main causes of many of the latest attacks are not associated with these two architectures. The damage caused by most of the recent attacks could have been minimized if more attention was given to enhancing the security of all components of the database architecture. The existing enterprise database architecture frameworks do not consider this issue a priority; hence, it has received minimal attention. The enterprise database architecture is the most important architecture because it is responsible for defining how all types of data, whether security-critical or not, are stored and accessed. This paper focuses on addressing the lack of a complete solution to help enterprise system architects to address the security of their organizations from early stages. The novelty of this approach is that it specifies how to modify the required artifacts by the enterprise database architecture to address security-critical data. The approach also defines a number of security measurements that help enterprise architects in measuring the security of the organization database based on those artifacts. These metrics are developed based on the results of a cybersecurity experiment conducted on 100 randomly selected open-source websites. The paper's contributions also consist of the definition of a number of security refactoring rules that specify how to modify current enterprise databases to make them more secure. This paper uses an existing relational diagram for a health clinic database to illustrate the application of the model to an existing database. The validity and applicability of these metrics and refactoring rules are proved using an experiment conducted on a number of security-related databases.

Publisher

American Scientific Publishers

Subject

Health Informatics,Radiology Nuclear Medicine and imaging

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3