Forensic Investigation in SQL Server Database Using Temporal Tables & Extended Events Artifacts

  • Zakarneh S
N/ACitations
Citations of this article
15Readers
Mendeley users who have this article in their library.

Abstract

Different Database management systems (DBMS) were developed and introduced to store and manipulate data. Microsoft SQL (MSSQL) Server one of the most popular relational DBMS used for large databases. With the increasing use of databases, intentional and unintentional accidents on databases are increasing dramatically. Therefore, there is a great need to develop database forensic investigation (DBFI) tools and models. The temporal table is a new feature introduced with MSSQL server 2012 for track changes, database audit, data loss protection, and data recovery. In addition, the extended events another new feature introduced with MSSQL server 2008 for database performance troubleshooting. This study focused on DBFI in the MSSQL server using temporal tables and extended events artifacts. The experiment is conducted and the results have presented the use of the temporal tables and extended events artifacts in analyzing and determining the internal unauthorized modification on the database.

Cite

CITATION STYLE

APA

Zakarneh, S. K. A. (2023). Forensic Investigation in SQL Server Database Using Temporal Tables & Extended Events Artifacts. International Journal of Applied Sciences and Smart Technologies, 5(1), 1–16. https://doi.org/10.24071/ijasst.v5i1.4611

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free