Invention Grant
- Patent Title: Mitigation of injection security attacks against non-relational databases
-
Application No.: US15882043Application Date: 2018-01-29
-
Publication No.: US10657280B2Publication Date: 2020-05-19
- Inventor: Patrick Spiegel , Martin Johns
- Applicant: SAP SE
- Applicant Address: DE Walldorf
- Assignee: SAP SE
- Current Assignee: SAP SE
- Current Assignee Address: DE Walldorf
- Agency: Fish & Richardson P.C.
- Main IPC: G06F16/00
- IPC: G06F16/00 ; G06F21/62 ; G06F16/25 ; G06F16/245 ; G06F16/242 ; G06F21/55

Abstract:
For mitigation of injection security attacks against non-relational databases, a database driver layer is integrated with a security layer. A trigger associated with the security layer is set to implement a learning phase of the security layer. In response to enabling the trigger, queries and query parameters associated with the respective queries are received. For the queries, a previously-stored security pattern is identified based on the query and the associated query parameters. The trigger associated with the security layer is reset to implement an execution of the security patterns. In response to resetting the trigger, an additional query and additional query parameters associated with the additional query is received. A particular security pattern is identified that is associated with the additional query and the additional query parameters. At least one of the additional query parameters is determined to not match a corresponding query parameter of the particular security pattern.
Public/Granted literature
- US20190236301A1 MITIGATION OF INJECTION SECURITY ATTACKS AGAINST NON-RELATIONAL DATABASES Public/Granted day:2019-08-01
Information query