On the Difficulty of Securing Web Applications Using CryptDB

On the Difficulty of Securing Web Applications Using CryptDB
复制标题

关于使用 CryptDB 保护 Web 应用程序安全的困难

DOI:
--
复制
发表时间:
2014
期刊:
2014 IEEE Fourth International Conference on Big Data and Cloud Computing
影响因子:
--
通讯作者:
B. Sunar
B. Sunar
中科院分区:
--
文献类型:
--
作者:
Ihsan Haluk Akin;B. Sunar

文献摘要

被引文献

相似文献

Crypt DB已经被提出作为一种实用和安全的中间件来保护部署在半诚实云服务器上的数据库。虽然CD在Threat-1下提供了足够的保护,但我们在这里演示了当CD被部署为保护实际Web应用程序的云托管数据库时,数据库攻击者或恶意数据库管理员(mDBA)可以轻松窃取信息,甚至升级他的权限成为Web应用程序的管理员。我们的攻击属于受限制的威胁-2形式,我们只假设攻击者或mDBA篡改CD保护的数据库,并通过Web应用程序打开普通用户帐户。我们的攻击是在假设代理和应用服务器完全安全的情况下进行的。因此,攻击无需恢复驻留在代理服务器上的主密钥即可工作。攻击的根源在于缺乏对CD数据库中数据的完整性检查。我们提出了一些实用的对策,以减轻针对CD数据库的完整性的攻击。我们还证明了数据完整性是不足以保护数据库,当考虑查询完整性和频率攻击。
Crypt DB has been proposed as a practical and secure middleware to protect databases deployed on semi-honest cloud servers. While CD provides sufficient protection under Threat-1, here we demonstrate that when CD is deployed to secure the cloud hosted database of a realistic Web application, an attacker to database or a Malicious Database Administrator (mDBA) can easily steal information, and even escalate his privilege to become the administrator of the Web application. Our attacks, fall under a restricted form of Threat-2 where we only assume that the attackers or the mDBA tampers with the CD protected database and is opens an ordinary user account through the Web application. Our attacks, are carried out assuming perfectly secure proxy and application servers. Therefore, the attacks work without recovering the master key residing on the proxy server. At the root of the attack lies the lack of any integrity checks for the data in the CD database. We propose a number of practical countermeasures to mitigate attacks targeting the integrity of the CD database. We also demonstrate that the data integrity is not sufficient to protect the databases, when query integrity and frequency attacks are considered.