节点文献

基于拟态防御的数据库系统设计与实现

Design and Implementation of Database System Based on Mimic Defense

【作者】 董俊杰

【导师】 邬江兴;

【作者基本信息】 东南大学 , 计算机技术(专业学位), 2022, 硕士

【摘要】 数据库系统作为承载数据存储和分析功能的专用软件,经过半个多世纪的发展演进,已成为当今各类信息系统的核心组成部分。数据库系统在为社会的进步和发展带来便利的同时,也带来了许多安全隐患。近年来,随着数据库软件安全漏洞的频繁爆出,数据库系统面临的安全问题也愈发严重。然而现有的数据库防御技术主要基于已知的攻击方法或已知漏洞信息进行防御,在面对未知漏洞和后门威胁时难以应对。网络空间拟态防御是国内提出的一种主动防御理论,针对当前信息系统普遍存在的静态、相似、单一“基因缺陷”,通过引入动态、异构、冗余机制对其进行“拟态化”改造,使新的系统对未知漏洞和后门具备内生的抵御能力。因此,将拟态防御的相关思想和机制引入到数据库系统中,为其提供对未知漏洞后门的防御能力,能够弥补现有防御方法的局限和不足,从而改善当前数据库安全的严峻现状。基于上述考虑,本文借鉴拟态防御思想和动态异构冗余架构模型,对数据库系统的体系结构和运行策略等方面进行了拟态构建的关键技术研究,设计并实现了兼容My SQL通信协议的拟态数据库系统。论文的主要贡献如下:1.针对当前数据库系统无法有效应对未知漏洞和后门的问题,提出了一种基于动态异构冗余架构模型的数据库体系结构,从构造上增强系统对未知漏洞和后门的防御能力。2.针对异构数据库采用的通信协议不一致的问题,通过引入自定义消息包和Java数据库通信接口,将My SQL请求转换成其它异构数据库支持的通信协议格式。3.针对如何构建功能等价的异构数据库执行体的问题,通过引入执行体应用、元数据库和后端数据库,将异构数据库系统封装为表征一致的执行体。4.针对如何对异构数据库执行体输出的SQL结果集进行有效裁决的问题,设计并实现了基于多数一致性裁决策略的裁决器。通过对拟态数据库系统进行功能测试、性能测试和安全性测试,验证了系统的功能完整性和应对未知威胁的能力,为解决数据库安全问题提供了一种新思路。

【Abstract】 As a special software carrying data storage and analysis functions,the database system has become the core component of today’s various information systems after more than half a century of development and evolution.While the database system brings convenience to the progress and development of society,it also brings many hidden dangers to security.In recent years,with the frequent explosion of database software security vulnerabilities,the security problems faced by database systems have become more and more serious.However,the existing database defense technologies are mainly based on known attack methods or known vulnerability information,which are difficult to deal with in the face of unknown vulnerabilities and backdoor threats.Cyberspace mimic defense is an active defense theory put forward in China.Aiming at the static,similar,and single ”gene defects” that are common in current information systems,it is ”mimic” transformation by introducing dynamic,heterogeneous,and redundant mechanisms.Make new systems endogenously resistant to unknown vulnerabilities and backdoors.Therefore,the related ideas and mechanisms of mimic defense are introduced into the database system to provide them with defense capabilities against unknown vulnerability backdoors,which can make up for the limitations and deficiencies of existing defense methods,thereby improving the current severe situation of database security.Based on the above considerations,this paper draws on the idea of mimetic defense and the dynamic heterogeneous redundant architecture model,and studies the key technologies of mimetic construction in terms of database system architecture and operation strategy,and designs and implements a mimetic database system compatible with My SQL communication protocol..The main contributions of the paper are as follows:1.Aiming at the problem that the current database system cannot effectively deal with unknown vulnerabilities and backdoors,a database architecture based on the dynamic heterogeneous redundant architecture model is proposed to enhance the system’s defense ability against unknown vulnerabilities and backdoors.2.Aiming at the problem of inconsistent communication protocols adopted by heterogeneous databases,the My SQL request is converted into the communication protocol format supported by other heterogeneous databases by introducing custom message packets and Java database communication interfaces.3.For the problem of how to construct functionally equivalent heterogeneous database executives,by introducing executive applications,metadata databases and back-end databases,the heterogeneous database system is encapsulated into executives with consistent representations.4.Aiming at the problem of how to effectively adjudicate the SQL result set output by the heterogeneous database executives,an arbiter based on the majority consensus adjudication strategy is designed and implemented.The functional integrity of the system and the ability to deal with unknown threats are verified by functional testing,performance testing and security testing of the mimic database system,which provides a new idea for solving database security problems.

  • 【网络出版投稿人】 东南大学
  • 【网络出版年期】2024年 02期
  • 【分类号】TP311.13;TP309
节点文献中: 

本文链接的文献网络图示:

本文的引文网络