Network Access Restriction
The MariaDB TCP service is restricted to the network or hosts that require database access.
Prevent unauthorized systems from reaching the MariaDB service.
MariaDB is an open-source relational database server that can accept local and remote client connections depending on its network configuration and database-account permissions.
Remote database access introduces a security risk when the database service is reachable from networks that are not required for legitimate application operations or when database accounts permit connections from broader hosts than necessary.
MariaDB provides multiple controls that can be used to restrict remote access. The bind-address setting determines which network addresses the server listens on, while MariaDB account definitions use the form 'username'@'host', allowing access to be restricted according to the connecting host. MariaDB also supports host patterns and network ranges for account matching.
In this use case, a controlled MariaDB database server is deployed on Ubuntu Linux inside an isolated VirtualBox laboratory. Kali Linux is used as the authorized security-testing platform.
The assessment evaluates whether unauthorized remote systems can reach the MariaDB service and whether database accounts are correctly restricted to their approved source hosts.
The security validation combines network-level access restriction, MariaDB account-host validation, least-privilege database accounts, and connection auditing.
A controlled remote-access test is performed from Kali Linux using the MariaDB client and network-connectivity testing. The assessment verifies both cases where the network connection should be blocked and cases where the network connection reaches MariaDB but the database account should reject the source host.
MariaDB's Audit Plugin can record connection activity, including connection and failed-connection events, providing useful evidence for security monitoring and compliance-oriented investigation.
Wazuh monitors the Ubuntu and MariaDB environment, while OpenSearch provides centralized investigation of connection attempts, authentication failures, and access-control events.
Complete Risk Assessment & Compliance Workflow: MariaDB Database Server → Network Exposure Assessment → Remote Access Identification → Firewall / Network Restriction → Account-Host Validation → Unauthorized Remote Access Attempt → Connection / Authentication Result → Audit Logging → Wazuh Monitoring → OpenSearch Investigation → Risk Evaluation → Remediation → Post-Remediation Validation
The MariaDB server provides database services to authorized applications and users. Remote connectivity can be configured through the server's network binding and firewall rules, while database accounts determine which users can authenticate from which hosts. MariaDB documentation describes remote access configuration through bind-address, firewall rules, and account host restrictions.
A MariaDB server may become unnecessarily exposed when the database port is reachable from unauthorized network segments or when database accounts use overly broad host definitions such as '%'.MariaDB documents that an accounts host component controls which client hosts can match the account. Exact host matches take precedence over wildcard matches, and a host of '%' represents a broad wildcard.
The security problem is therefore:
The proposed security architecture introduces network restriction and account-host validation so that a connection must satisfy both the required network-access policy and the appropriate MariaDB account restrictions.
The controlled attack scenario attempts to connect to the MariaDB database service from an unauthorized laboratory host. The assessment first identifies whether the MariaDB TCP service is reachable from the testing network. The tester then evaluates whether the database account permits connections from the testing host. A controlled database account is configured for an approved source host or laboratory network, and Kali Linux is used to attempt access from a source outside the permitted host definition. The assessment determines whether the request is blocked at the network layer or rejected during MariaDB account authentication. The objective is to identify an access-control gap where an unauthorized host can establish a database session despite the intended network and account-host restrictions.
The primary security concept is defense-in-depth for database remote access.
Network controls determine whether a remote host can reach the MariaDB service, while MariaDB account-host definitions determine whether a particular database account can authenticate from that source host. The bind-address setting controls the addresses on which the server listens, while remote access also requires appropriate database-account permissions and firewall configuration. The account definition provides an additional access-control boundary because MariaDB accounts contain both a username and host component.
The secure processing flow is:
The MariaDB TCP service is restricted to the network or hosts that require database access.
Prevent unauthorized systems from reaching the MariaDB service.
MariaDB is configured to listen only on the required network interface rather than unnecessarily exposing the database service on all interfaces.
Reduce the network exposure of the MariaDB server.
The firewall permits MariaDB traffic only from the approved laboratory source network or application host.
Block unauthorized remote connections before they reach MariaDB.
MariaDB accounts are configured with explicit host restrictions.
Prevent a valid database username from being used from an unauthorized source host.
Overly broad host definitions such as '%' are identified and replaced with narrower host definitions where remote access is genuinely required.
Reduce unnecessary database-account exposure.
Application-specific accounts receive only the privileges required for their intended database operations.
Limit the impact of an unauthorized or compromised database account.
Administrative accounts are restricted to appropriate local or explicitly approved management sources.
Reduce exposure of privileged database accounts.
MariaDB auditing is configured to record connection-related activity, including failed connections where supported by the selected audit configuration.
Provide evidence of remote-access attempts and authentication activity.
Wazuh monitors MariaDB and Ubuntu security activity.
Detect suspicious remote connection and authentication activity.
OpenSearch stores and correlates security events from the MariaDB environment.
Support investigation of unauthorized access attempts and access-control violations.
The configured network and account-host restrictions are repeatedly tested from authorized and unauthorized laboratory sources.
Verify that database access controls remain effective after configuration changes.
MariaDB provides the controlled relational database environment.
The MariaDB command-line client is used from authorized and unauthorized laboratory sources to validate database connectivity and authentication behavior.
UFW is used as the host firewall on Ubuntu where appropriate.
Nmap is used from Kali Linux to identify the controlled MariaDB service exposure.
The MariaDB Audit Plugin provides connection and database-activity auditing. It documents CONNECT, QUERY, and TABLE event categories and supports output to a local file or syslog depending on configuration.
Kali Linux provides the authorized remote-access testing environment.
Wireshark is used to inspect controlled database-network traffic.
Wazuh monitors Ubuntu and MariaDB security activity.
OpenSearch provides centralized investigation of MariaDB security telemetry.
Ubuntu provides the controlled MariaDB server environment.
VirtualBox provides the isolated laboratory environment.