

Research of Least Privilege for Database Administrators



Traditional database administrator (DBA) privileges are too high, which causes insider security threat problem. To solve this problem, an extended Role Based Access Control (RBAC) rights management model for DBA was brought out in this paper. Combined with the principle of least privilege security, this paper proposes a scheme which contains three management roles separation and dynamic constraints. It solved the problem that system administrator's privileges are too high and avoided the insider threats. Practice proves that this model has versatility, flexibility, and high security.


 1. Introduction
 2. Relate Research
  2.1. Problems of DBA Role
  2.2. RBAC Model
  2.3. Least Priviledge
 3. The Extended RBAC Model For DBA
 4. The Design of GF-RBAC Model For DBA
  4.1. A Method to Separate Privileges of DBA into Groups
  4.2. Database Operations Classification
  4.3. System Privileges Classification
  4.4. Access Privilege of Database Resource
  4.5. Factor Constraints
 6. Type-style and Fonts
 7. Footnotes


  • Mou Shen Beijing Key Laboratory of Network Technology School of Computer Science and Engineering Beihang University, Beijing, 100191 China
  • Mengdong Chen Beijing Key Laboratory of Network Technology School of Computer Science and Engineering Beihang University, Beijing, 100191 China
  • Min Li Beijing Key Laboratory of Network Technology School of Computer Science and Engineering Beihang University, Beijing, 100191 China
  • Lianzhong Liu Beijing Key Laboratory of Network Technology School of Computer Science and Engineering Beihang University, Beijing, 100191 China


자료제공 : 네이버학술정보

    ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

    0개의 논문이 장바구니에 담겼습니다.