IP Library Granted Patent US 8,683,220
Granted Patent B2
US 8,683,220 · App. 13/248,121 · Granted Mar 25, 2014

System and method for securing database activity

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,683,220
App. No.
13/248,121
Granted
Mar 25, 2014
Kind
B2
Abstract

A method is provided in one example embodiment that includes detecting database activity associated with a statement having a signature, validating the signature; and evaluating the statement as a signed statement if the signature is valid. In more particular embodiments, the signature may include a unique script identifier and a hash function of a shared key. In yet other embodiments, validating the signature may include checking a session variable and comparing the statement to a list of signed statements.

Claims (32)

1. A method, comprising:

detecting database activity by a database activity monitor (DAM) that is collocated with a database server for which it performs monitoring, wherein the database activity includes an attempt to execute a statement in a script, and wherein the statement includes a plurality of instructions for executing the database activity;

validating a signature by parsing the statement to determine whether the statement includes the signature, wherein an association is generated between the signature and the statement in order to distinguish authorized database activity from unauthorized database activity, and wherein different rules are defined for handling the authorized database activity and the unauthorized database activity; and

evaluating the statement as a signed statement if the signature is valid, wherein the signed statement is indicative of a planned, preapproved database activity that has been authorized.

2. The method of claim 1 , wherein the signature comprises a unique script identifier.

3. The method of claim 1 , wherein the signature comprises a hash function of a shared key.

4. The method of claim 1 , wherein the signature is embedded in a comment portion of the statement.

5. The method of claim 1 , wherein validating the signature comprises extracting a first signature hash from the signature, calculating a second signature hash based on the signature, and comparing the first signature hash to the second signature hash.

6. The method of claim 1 , wherein the signature comprises a unique script identifier and validating the signature comprises comparing the statement to valid statements associated with the unique script identifier.

7. The method of claim 1 , wherein validating the signature comprises extracting a script identifier from a session variable and comparing the statement to a list of valid statements associated with the script identifier.

8. Logic encoded in one or more non-transitory media that includes code for execution and when executed by one or more processors is operable to perform operations comprising:

detecting database activity by a database activity monitor (DAM) that is collocated with a database server for which it performs monitoring, wherein the database activity includes an attempt to execute a statement in a script, and wherein the statement includes a plurality of instructions for executing the database activity;

validating a signature by parsing the statement to determine whether the statement includes the signature, wherein an association is generated between the signature and the statement in order to distinguish authorized database activity from unauthorized database activity, and wherein different rules are defined for handling the authorized database activity and the unauthorized database activity; and

evaluating the statement as a signed statement if the signature is valid, wherein the signed statement is indicative of a planned, preapproved database activity that has been authorized.

9. The encoded logic of claim 8 , wherein the signature comprises a unique script identifier.

10. The encoded logic of claim 8 , wherein the signature comprises a hash function of a shared key.

11. The encoded logic of claim 8 , wherein the signature is embedded in a comment portion of the statement.

12. The encoded logic of claim 8 , wherein validating the signature comprises extracting a first signature hash from the signature, calculating a second signature hash based on the signature, and comparing the first signature hash to the second signature hash.

13. The encoded logic of claim 8 , wherein the signature comprises a unique script identifier and validating the signature comprises comparing the statement to valid statements associated with the unique script identifier.

14. The encoded logic of claim 8 , wherein validating the signature comprises extracting a script identifier from a session variable and comparing the statement to a list of valid statements associated with the script identifier.

15. An apparatus, comprising:

a database activity monitor agent;

a signature module; and

one or more processors operable to execute instructions associated with the database activity monitor agent and the signature module such that the apparatus is configured for:

detecting database activity by the database activity monitor agent that is collocated with the apparatus for which it performs monitoring, wherein the database activity includes an attempt to execute a statement in a script, and wherein the statement includes a plurality of instructions for executing the database activity;

validating a signature by parsing the statement to determine whether the statement includes the signature, wherein an association is generated between the signature and the statement in order to distinguish authorized database activity from unauthorized database activity, and wherein different rules are defined for handling the authorized database activity and the unauthorized database activity; and

evaluating the statement as a signed statement if the signature is valid, wherein the signed statement is indicative of a planned, preapproved database activity that has been authorized.

16. The apparatus of claim 15 , wherein the signature comprises a unique script identifier.

17. The apparatus of claim 15 , wherein the signature comprises a hash function of a shared key.

18. The apparatus of claim 15 , wherein the signature is embedded in a comment portion of the statement.

19. The apparatus of claim 15 , wherein validating the signature comprises extracting a first signature hash from the signature, calculating a second signature hash based on the signature, and comparing the first signature hash to the second signature hash.

20. The apparatus of claim 15 , wherein the signature comprises a unique script identifier and validating the signature comprises comparing the statement to valid statements associated with the unique script identifier.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →