skip to main content
10.1145/1940941.1940958acmotherconferencesArticle/Chapter ViewAbstractPublication PagesinfoseccdConference Proceedingsconference-collections
research-article

Database forensics

Published:01 October 2010Publication History

ABSTRACT

At the user or surface level, most Database Management System (DBMS) are similar. Most databases contain multiple tables, a standardized query language, primary key, foreign key, referential integrity, and metadata. With regard to physical file structures, concurrency mechanisms, security mechanisms, query optimization and datawarehouse techniques, databases may be radically different from each other. Most Forensic tools are too time consuming to be applied to large databases. Meanwhile, database tools such as oracle logminer and auditing features can assist in forensics, but were not created for that purpose. Many of these tools alter the database in ways that may complicate the use of their results in a legal proceeding. This paper analyzes the challenges of digital forensics, related literature, topics involved, current options for performing forensics on databases as well as considerations in teaching database forensics.

References

  1. Betjlich, Richard, Proactive vs Reactive Security, TaoSecurity, Retrieved on August 1, 2010 from http://taosecurity.blogspot.com/2007/03/proactive-vs-reactive-security.htmlGoogle ScholarGoogle Scholar
  2. Kroenke, David M., Database Concepts 4th edition, ISBN 0136086535, Prentice Hall, 2009.Google ScholarGoogle Scholar
  3. Litchfield, David (2008) - Oracle Forensics Analysis Using the Forensic Examiners Database Scalpel (FEDS) Tool, ISBN:9780470191187, Wiley, 2008.Google ScholarGoogle Scholar
  4. Pete Finnigan (2004) -- Oracle Forensics module -- SANS training, Retrieved on July 1, 2010 from http://www.petefinnigan.com/Oracle_Forensics.pdfGoogle ScholarGoogle Scholar
  5. Wright, Paul, Oracle Forensics: -- ISBN-10-0977671526., Rampant Techpress, 2010.Google ScholarGoogle Scholar
  6. Litchfield, David, Oracle Security, Retrieved on July 1, 2010 from http://www.databasesecurity.com/oracle-forensics.htmGoogle ScholarGoogle Scholar
  7. Litchfield, David, MS SQL Server Security, Retrieved on July 1, 2010 from http://www.databasesecurity.com/sql-server-forensics.htm Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. Litchfield, David, Oracle Security, DB2 Security, Retrieved on July 1, 2010 from http://www.databasesecurity.com/db2.htmGoogle ScholarGoogle Scholar
  9. Litchfield, David, Oracle Security, Informix Security, Retrieved on July 1, 2010 from http://www.databasesecurity.com/informix.htmGoogle ScholarGoogle Scholar
  10. Litchfield, David, Oracle Security, Postgres Security, Retrieved on July 1, 2010 from http://www.databasesecurity.com/postgresql.htmGoogle ScholarGoogle Scholar
  11. Oracle Forensics in a Nutshell, Retrieved on July 2, 2010 from http://www.oracleforensics.com/wordpress/wp-content/uploads/2007/03/OracleForensicsInANutshell.pdfGoogle ScholarGoogle Scholar
  12. Stahlberg, P., Miklau, G. and Levine, N. B., Threats to Privacy in the Forensic Analysis of Database Systems, ACM-SIGMOD, 07, June 12--14, 2007, Beijing, China Google ScholarGoogle ScholarDigital LibraryDigital Library
  13. Pavlou, K. E. and Snodgrass, R. T. 2008. Forensic analysis of database tampering. ACM Trans. Datab. Syst. 33, 4, Article 30 (November 2008), 47 pages. DOI = 10.1145/1412331.1412342 http://doi.acm.org/10.1145/1412331.1412342 Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. Database forensics

          Recommendations

          Comments

          Login options

          Check if you have access through your login credentials or your institution to get full access on this article.

          Sign in
          • Published in

            cover image ACM Other conferences
            InfoSecCD '10: 2010 Information Security Curriculum Development Conference
            October 2010
            187 pages
            ISBN:9781450302029
            DOI:10.1145/1940941

            Copyright © 2010 ACM

            Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

            Publisher

            Association for Computing Machinery

            New York, NY, United States

            Publication History

            • Published: 1 October 2010

            Permissions

            Request permissions about this article.

            Request Permissions

            Check for updates

            Qualifiers

            • research-article

            Acceptance Rates

            Overall Acceptance Rate18of23submissions,78%

          PDF Format

          View or Download as a PDF file.

          PDF

          eReader

          View online with eReader.

          eReader