IP Library Granted Patent US 11,601,446
Granted Patent B2
US 11,601,446 · App. 16/998,846 · Granted Mar 7, 2023

Method to detect database management system SQL code anomalies

Inventor: Emad Mohammad Al-Mousa (Dammam, SA)
Assignee: Saudi Arabian Oil Company
H04L63/1416G06F16/2255G06F16/2379G06F16/24558H04L63/02H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,601,446
App. No.
16/998,846
Granted
Mar 7, 2023
Kind
B2
Abstract

The present disclosure describes a computer-implemented method that includes: populating a metadata shell database with one or more hash values, wherein: each hash value corresponds to a verified installation of a database system, and the metadata shell database is maintained within a locked-down environment on an enterprise network; and monitoring metadata information of one or more database systems on the enterprise network based on periodically accessing metadata information of one or more database systems; and determining whether a database system on the enterprise network has been compromised based on a hash value of the metadata information of the database system and the one or more hash values from the metadata shell database.

Claims (58)

1. A computer-implemented method comprising:

scanning an enterprise network for a plurality of database systems thereon;

populating a metadata shell database for the plurality of database systems with hash values, wherein:

each hash value corresponds to a database system from the plurality of database systems and comprises a metadata hash of a verified installation of the corresponding database system, and

the metadata shell database is maintained for the plurality of database systems within a locked-down environment on the enterprise network; and

monitoring metadata information of the plurality of database systems on the enterprise network based on periodically accessing metadata information of the plurality of database systems; and

determining whether a database system on the enterprise network has been compromised based on a hash value of the periodically accessed metadata information of the database system and hash values from the metadata shell database.

2. The computer-implemented method of claim 1 , further comprising:

computing a respective hash value of the metadata information of each of the plurality of database systems; and

comparing the respective hash value with a hash value from the metadata shell database.

3. The computer-implemented method of claim 2 , further comprising:

determining whether the respective hash value matches the hash value from the metadata shell database that comprises the metadata hash of the verified installation of the corresponding database system.

4. The computer-implemented method of claim 3 , further comprising:

in response to determining that the respective hash value does not match the hash value from the metadata shell database that comprises the metadata hash of the verified installation of the corresponding database system, determining that the database system on the enterprise network has been compromised.

5. The computer-implemented method of claim 4 , further comprising:

in response to determining that the database system on the enterprise network has been compromised, alerting a system administrator of the enterprise network.

6. The computer-implemented method of claim 1 , wherein populating a metadata shell database with hash values comprises:

accessing the metadata information of the plurality of database systems on the enterprise network;

computing a respective hash value of the metadata information for each database system on the enterprise network; and

populating the metadata shell database with the respective hash value for each database system on the enterprise network.

7. The computer-implemented method of claim 1 , wherein populating a metadata shell database with hash values comprises:

accessing a vendor repository for a list of hash values for the plurality of database systems; and

populating the metadata shell database with the list of hash values for each database systems.

8. The computer-implemented method of claim 1 , wherein populating a metadata shell database with hash values comprises:

accessing metadata of a group of shell database systems that correspond to the plurality of database systems, wherein a group of shell database systems are maintained within the locked-down environment on the enterprise network;

computing a respective hash value of the metadata information for each database system from the group of shell database systems; and

populating the metadata shell database with the respective hash value for each database system on the enterprise network.

9. The computer-implemented method of claim 8 , wherein the group of shell database systems are provisioned as container images, and wherein the container images are patched periodically to synchronize with verified installations.

10. The computer-implemented method of claim 1 , wherein the locked-down environment on the enterprise network is enforced by a firewall or a whitelist.

11. A computer system comprising one or more processors, wherein the one or more processors are configured to perform operations of:

scanning an enterprise network for a plurality of database systems thereon:

populating a metadata shell database for the plurality of database systems with one or more hash values, wherein:

each hash value corresponds to a database system from the plurality of database systems and comprises a metadata hash of a verified installation of the corresponding database system, and

the metadata shell database for the plurality of database systems within a locked-down environment on the enterprise network; and

monitoring metadata information of the plurality of database systems on the enterprise network based on periodically accessing metadata information of the plurality of database systems; and

determining whether a database system on the enterprise network has been compromised based on a hash value of the periodically accessed metadata information of the database system and hash values from the metadata shell database.

12. The computer system of claim 11 , wherein the operations further comprise:

computing a respective hash value of the metadata information of each of the plurality of database systems; and

comparing the respective hash value with a hash value from the metadata shell database.

13. The computer system of claim 12 , wherein the operations further comprise:

determining whether the respective hash value matches the hash value from the metadata shell database that comprises the metadata hash of the verified installation of the corresponding database system.

14. The computer system of claim 13 , wherein the operations further comprise:

in response to determining that the respective hash value does not match the hash value from the metadata shell database that comprises the metadata hash of the verified installation of the corresponding database system, determining that the database system on the enterprise network has been compromised.

15. The computer system of claim 14 , wherein the operations further comprise:

in response to determining that the database system on the enterprise network has been compromised, alerting a system administrator of the enterprise network.

16. The computer system of claim 11 , wherein populating a metadata shell database with one or more hash values comprises:

accessing the metadata information of the plurality of database systems on the enterprise network;

computing a respective hash value of the metadata information for each database system on the enterprise network; and

populating the metadata shell database with the respective hash value for each database system on the enterprise network.

17. The computer system of claim 11 , wherein populating a metadata shell database with hash values comprises:

accessing a vendor repository for a list of hash values for the plurality of database systems; and

populating the metadata shell database with the list of hash values for each database systems.

18. The computer system of claim 11 , wherein populating a metadata shell database with hash values comprises:

accessing metadata of a group of shell database systems that correspond to the plurality of database systems, wherein a group of shell database systems are maintained within the locked-down environment on the enterprise network;

computing a respective hash value of the metadata information for each database system from the group of shell database systems; and

populating the metadata shell database with the respective hash value for each database system on the enterprise network.

19. The computer system of claim 18 , wherein the group of shell database systems are provisioned as container images, and wherein the container images are patched periodically to synchronize with verified installations.

20. The computer system of claim 11 , wherein the locked-down environment on the enterprise network is enforced by a firewall or a whitelist.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2020
From: AL-MOUSA, EMAD MOHAMMAD
To: SAUDI ARABIAN OIL COMPANY
Reel/Frame 053558/0724 →
Continuity (1)
Related Publication 20220060486A1 · Feb 24, 2022