Detailed steps to enhance SQL Server database system security

Source: Internet
Author: User

You can take the following steps:

Query the latest service package
Make sure that you always have the latest service package. For SQL Server2000, this is SQL/downloads/2000/SP3.asp "> SP3a. Remember that there are multiple service packages. If you use SP3a, you do not have to use the previous service packages, such as SP3, SP2, or SP1. SP3 is a special service package. Once installed, it will no longer use any of the previous upgrade programs, but it must have been installed with SP1 or SP2.

Register Security Alerts
Although the service package helps your SQL Server database avoid many threats, they are not able to cope with security issues such as attackers and worms. You need to register Microsoft's free security notification service, which will notify you via email about what has penetrated your security system and how to solve them.

Run Microsoft Baseline Security Analyzer (MBSA)

This tool targets SQL Server and MSDE2000 desktop engines. It can be used locally or online. It uses password, access permission, access control list, registration, and other methods to find problems, and it finds the lost security package or service package. You can find related information on TechNet.

Delete SA and old password
A common security error is that you do not change the system management password. You will easily ignore the installation files and remaining configuration information, without well-protected authentication information and other sensitive data, which may be attacked. You must delete the old installation files. Similarly, use the KILLPWD tool to find out the old passwords and delete them.

Monitoring connection
The connection tells you who is attempting to access SQL Server. Therefore, monitoring connection is a good way to ensure database security. For a large running SQL Server, too many link data may need to be monitored. However, it is necessary to monitor the failed links because they may represent some attempts. You can log on to the enterprise manager with the failed links.

1. Right-click the server and select Properties ).
2. Click the Security tab and select Failure under Audit Level.
3. Stop and restart the server to get the start of the check.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.