Security&privacy issues and challenges in NoSQL databases

被引:11
|
作者
Sicari, Sabrina [1 ]
Rizzardi, Alessandra [1 ]
Coen-Porisini, Alberto [1 ]
机构
[1] Univ Insubria, Dipartimento Sci Teor & Applicate, Via O Rossi 9, I-21100 Varese, Italy
关键词
NoSQL databases; Internet of Things; Access control; Authentication; Authorization; Security; Privacy; GRAINED ACCESS-CONTROL; POLICY ENFORCEMENT; BIG DATA; INTERNET; ENCRYPTION; QUERIES; THINGS; CLOUD;
D O I
10.1016/j.comnet.2022.108828
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Organizing the storing of information and data retrieval from databases is a crucial issue, which has become more critical with the spreading of cloud and Internet of Things (IoT) based applications. In fact, not only the network's traffic has increased, but also the amount of memory and the mechanisms needed to manage the so-called Big Data efficiently. Relational databases, based on SQL, are giving way to the NoSQL ones due to their efficiency in managing the heterogeneous information gathered from IoT environments. Such data can be stored, in a distributed manner, within the IoT network's devices or in the cloud. Hence, security and privacy concerns naturally emerge regarding access control, authentication, and authorization requirements. This paper analyzes the current state of the art of security and privacy solutions tailored to NoSQL databases, particularly Redis, Cassandra, MongoDB, and Neo4j stores. The paper also aims to shed light on current challenges and future research directions in the field databases' security in the IoT scenario.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Security Issues in NoSQL Databases
    Okman, Lior
    Gal-Oz, Nurit
    Gonen, Yaron
    Gudes, Ehud
    Abramov, Jenny
    TRUSTCOM 2011: 2011 INTERNATIONAL JOINT CONFERENCE OF IEEE TRUSTCOM-11/IEEE ICESS-11/FCST-11, 2011, : 541 - 547
  • [2] DATABASES SECURITY ISSUES - A SHORT ANALYSIS ON THE EMERGENT SECURITY PROBLEMS GENERATED BY NoSQL DATABASES
    Nica, Elvira
    Tudorica, Bogdan George
    Dusmanescu, Dorel-Mihail
    Popescu, Gheorghe
    Breaz, Alina Maria
    ECONOMIC COMPUTATION AND ECONOMIC CYBERNETICS STUDIES AND RESEARCH, 2019, 53 (03): : 113 - 129
  • [3] Security and privacy issues for sensor databases
    Thuraisingham, B
    SENSOR LETTERS, 2004, 2 (01) : 37 - 47
  • [4] HbbTV Security and Privacy: Issues and Challenges
    Ghiglieri, Marco
    Waidner, Michael
    IEEE SECURITY & PRIVACY, 2016, 14 (03) : 61 - 67
  • [5] Privacy-Breaching Patterns in NoSQL Databases
    Goel, Kanika
    Ter Hofstede, Arthur H. M.
    IEEE ACCESS, 2021, 9 : 35229 - 35239
  • [6] Security and Privacy of Smart Cities: Issues and Challenges
    Sookhak, Mehdi
    Tang, Helen
    Yu, F. Richard
    IEEE 20TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS / IEEE 16TH INTERNATIONAL CONFERENCE ON SMART CITY / IEEE 4TH INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2018, : 1350 - 1357
  • [7] An Insightful View on Security and Performance of NoSQL Databases
    Saxena, Upaang
    Sachdeva, Shelly
    DATA SCIENCE AND ANALYTICS, 2018, 799 : 643 - 653
  • [8] Security of Sharded NoSQL Databases: A Comparative Analysis
    Zahid, Anam
    Masood, Rahat
    Shibli, Muhammad Awais
    2014 CONFERENCE ON INFORMATION ASSURANCE AND CYBER SECURITY (CIACS), 2014, : 1 - 8
  • [9] Security policies by design in NoSQL document databases
    Blanco, Carlos
    Garcia-Saiz, Diego
    Rosado, David G.
    Santos-Olmo, Antonio
    Peral, Jesus
    Mate, Alejandro
    Trujillo, Juan
    Fernandez-Medina, Eduardo
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 65
  • [10] A Practical Framework for Privacy-Preserving NoSQL Databases
    Macedo, Ricardo
    Paulo, Joao
    Pontes, Rogerio
    Portela, Bernardo
    Oliveira, Tiago
    Matos, Miguel
    Oliveira, Rui
    2017 IEEE 36TH INTERNATIONAL SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS (SRDS), 2017, : 11 - 20