A Cyber Secure Framework for Modern Database Systems
DOI:
https://doi.org/10.37256/ccds.72202610054Keywords:
database security, cyber-secure architecture, zero trust, privileged access management, encryption and key management, audit logging, anomaly detectionAbstract
Database servers remain prime targets for cyberattacks due to their critical role in storing sensitive organizational data and supporting missioncritical applications; however, database security is often implemented through isolated controls, such as access management, encryption, logging, and backup, leading to fragmented protection and exploitable gaps across applications, identity, configuration, monitoring, and governance layers. This study proposes a comprehensive cybersecurity framework for modern database systems based on a layered architecture that integrates prevention, detection, and governance across the database lifecycle. The framework comprises seven coordinated layers: network and perimeter segmentation with mutual Transport Layer Security (mTLS), host and operating system hardening, identity and privileged access management, secure database configuration controls, data protection mechanisms, centralized key management, and continuous monitoring with correlation and anomaly-based detection. Using design science research methodology, a prototype reference deployment was evaluated against a baseline system under realistic workloads and simulated attack scenarios, including credential compromise, privilege escalation, Structures Query Language (SQL) injection via application pathways, data exfiltration attempts, destructive ransomware-like queries, and insider-style bulk data exports. The results indicate that the proposed framework reduces attack surface exposure, limits potential damage, enhances detection readiness, and strengthens containment and recovery capabilities. Although additional controls introduced measurable overhead in latency, throughput, and telemetry volume, these trade-offs remained operationally acceptable with appropriate tuning. The study contributes a validated reference architecture and evaluation framework for secure database deployment across cloud, hybrid, and onpremises environments.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Hafiz Malik Usman Shehzad, Altaf Hussain

This work is licensed under a Creative Commons Attribution 4.0 International License.
