A Security Model for Access Control in Graph-Oriented Databases

A Security Model for Access Control in Graph-Oriented Databases
复制标题

DOI:
10.1109/qrs.2018.00027
复制
发表时间:
2018-07
期刊:
2018 IEEE International Conference on Software Quality, Reliability and Security (QRS)
影响因子:
--
通讯作者:
Claudia Morgado;Gisele Busichia Baioco;Tânia Basso;Regina L. O. Moraes
Claudia Morgado;Gisele Busichia Baioco;Tânia Basso;Regina L. O. Moraes
中科院分区:
其他
文献类型:
--
作者:
Claudia Morgado;Gisele Busichia Baioco;Tânia Basso;Regina L. O. Moraes

文献摘要

被引文献

相似文献

如今,组织收集大量数据用于未来分析。在Web2.0的数据量和需求的推动下,近年来出现了大量的非关系数据库(NoSQL)。然而,关系数据库中的几个安全特性(例如,访问控制)被留在非关系管理系统中由应用程序开发,这可能会引起安全漏洞。本文提出了一种基于元数据的安全模型,为面向图的NoSQL数据库管理系统提供访问控制。目标是支持使用面向图的数据库的应用程序的开发,以保持存储数据的完整性,并保护它们免受未经授权的访问。作为概念验证,进行了案例研究,其中模型被实例化并为Neo4j数据库实现。结果表明,访问限制得到正确应用,避免了未经授权的访问。提供了Neo4j的模式,一旦它没有本地模式。
Nowadays, organizations collect vast amounts of data for future analysis. Motivated by this amount of data and requirements of Web2.0, a plethora of non-relational databases (NoSQL) emerged in recent years. However, several security features in relational databases (e.g., access control) have been left in non-relational management systems to be developed by the application, which can raise security breaches. This paper proposes a security model, based on the use of metadata, to provide access control for NoSQL graph-oriented database management system. The goal is to support the development of applications that use graph-oriented database in preserving the integrity of stored data and protect them from non-authorized access. A case study was performed as proof of concept, where the model was instantiated and implemented for Neo4j database. Results showed that access restrictions were applied correctly, avoiding unauthorized access. A schema for Neo4j was provided, once it does not have a native one.