IRMA-International.org: Creator of Knowledge
Information Resources Management Association
Advancing the Concepts & Practices of Information Resources Management in Modern Organizations

Security Gaps in Databases: A Comparison of Alternative Software Products for Web Applications Support

Security Gaps in Databases: A Comparison of Alternative Software Products for Web Applications Support
View Sample PDF
Author(s): Afonso Araújo Neto (University of Coimbra, Portugal)and Marco Vieira (University of Coimbra, Portugal)
Copyright: 2011
Volume: 2
Issue: 3
Pages: 21
Source title: International Journal of Secure Software Engineering (IJSSE)
Editor(s)-in-Chief: Martin Gilje Jaatun (SINTEF Digital, Norway)
DOI: 10.4018/jsse.2011070103

Purchase

View Security Gaps in Databases: A Comparison of Alternative Software Products for Web Applications Support on the publisher's website for pricing and purchasing information.

Abstract

When deploying database-centric web applications, administrators should pay special attention to database security requirements. Acknowledging this, Database Management Systems (DBMS) implement several security mechanisms that help Database Administrators (DBAs) making their installations secure. However, different software products offer different sets of mechanisms, making the task of selecting the adequate package for a given installation quite hard. This paper proposes a methodology for detecting database security gaps. This methodology is based on a comprehensive list of security mechanisms (derived from widely accepted security best practices), which was used to perform a gap analysis of the security features of seven software packages composed by widely used products, including four DBMS engines and two Operating Systems (OS). The goal is to understand how much each software package helps developers and administrators to actually accomplish the security tasks that are expected from them. Results show that while there is a common set of security mechanisms that is implemented by most packages, there is another set of security tasks that have no support at all in any of the packages.

Related Content

Nan Jiang. © 2026. 18 pages.
Fang Zhou, Jianheng Ji, Shuping Wang, Wei Zhao. © 2026. 28 pages.
Dhivya Guru, Baskar Chinnaiah, Senthilraj Subramaniam. © 2026. 29 pages.
Jisheng Shi, Yunying He. © 2026. 17 pages.
Yizihe Lang, Chunchao Chen, Qiancheng Cai, Shuangzhu Tao, Xiao Zhang, Baoxing Ju. © 2026. 19 pages.
Yingdong Lai, Suijiang Mo, Zixin Li, Baoguo Li, Hongbing Wen. © 2026. 16 pages.
Masafumi Nakano. © 2026. 14 pages.
Body Bottom