Invention Grant
- Patent Title: Database firewall for use by an application using a database connection pool
-
Application No.: US16185736Application Date: 2018-11-09
-
Publication No.: US10904215B2Publication Date: 2021-01-26
- Inventor: Leonid Rodniansky , Tania Butovsky
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. LaBaw; David H. Judson
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/62

Abstract:
An application server environment that uses connection pooling is augmented to include a database access control system having a database firewall. When the database firewall detects a security violation with respect to a request received via a pooled connection, the firewall skips over (i.e. do not forward) the violating request and instead creates an artificial error database protocol packet corresponding to the application request. The database firewall then sends the error database protocol packet as a response back to the application, using the pool connection. The application receives the database error as a response to the security violating request, and it responds by releasing the connection of the policy violation database user. By releasing the pool connection is this manner, the performance of other applications (or other clients) using the connection pool is not impacted. Preferably, the error packets include no sensitive information.
Public/Granted literature
- US20200153794A1 Database firewall for use by an application using a database connection pool Public/Granted day:2020-05-14
Information query