RUS  ENG
Full version
JOURNALS // Prikladnaya Diskretnaya Matematika. Supplement // Archive

Prikl. Diskr. Mat. Suppl., 2015 Issue 8, Pages 89–92 (Mi pdma221)

This article is cited in 2 papers

Mathematical Foundations of Computer Security

Non-invasive method of mandatory access control implementaion on DBMS layer in web applications

D. N. Kolegova, N. O. Tkachenkob

a Tomsk State University, Tomsk
b Tomsk State University, Tomsk

Abstract: We propose non-invasive method of mandatory access control implementation on DBMS MySQL layer in web applications. This method is based on formal DP-models for DBMS MySQL and proxy-based reference monitor for SQL queries. The main idea of the method is identification of users in account-based web applications and SQL query rewriting. Users' identities are added by applicaion's module (Django middleware) and transmitted in comments of SQL queries to MySQL-proxy. After identification of users has been completed, we simulate DBMS's entities identification and row level security by SQL rewriting.

Keywords: access control, web applications, DBMS security.

UDC: 004.94

DOI: 10.17223/2226308X/8/33



© Steklov Math. Inst. of RAS, 2024