Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, June 23, 2011

Database security

Translate Request has too much data
Parameter name: request
Translate Request has too much data
Parameter name: request

Database Security is one of the broader topics that Securosis covers. Database servers are highly complex systems – storing, organizing, and managing data for a wide array of applications. Most mid-sized firms have dozens of them, some embedded in desktop applications, while others serve core systems such as web commerce, financials, manufacturing, and inventory management. A Fortune 100 company may have thousands. To address the wide range of offerings and uses, we will cover database security from two different angles. The first is the security of the application itself, and the second is the use and security of the data within the database.

Database Vulnerability Assessment (VA), access control & user management, and patch management are all areas where preventative security measures can be applied to a database system. For securing the data itself, we include such topics as Database Activity Monitoring (DAM), auditing, data obfuscation/masking, and database encryption. Technologies like database auditing can be used for either, but we include them in the later category because they provide a transactional view of database usage. We also include some of the database programming guidelines that can help protect databases from SQL injection and other attacks against application logic.

Papers and Posts

If you are just getting started, we recommend you read the following blog posts and papers in order. (In keeping with our Totally Transparent Research policy, for sponsored papers we also link to the original blog posts so you can see how the content was developed, and comments).

  1. Database Activity Monitoring research paper remains a reader favorite and can be downloaded here: “Understanding and Selecting a Database Activity Monitoring Solution” white paper.
  2. Understanding and Selecting a Database Assessment Solution is now available. We are very happy with this paper. We have even been told by database assessment vendors their product teams learned some tips from this paper, and we think you will too.
  3. Our Understanding and Selecting a Database Encryption or Tokenization Solution paper is available.
  4. Database Audit Events is a comprehensive list of database events available through native database auditing techniques.
  5. Many supporting posts on Database Encryption: Application vs. Database Encryption and Database Encryption: Fact vs. Fiction, Format and Datatype Preserving Encryption, An Introduction to Database Encryption, Database Encryption Misconceptions, Media encryption options for databases,and threat vectors to consider when encrypting data.
  6. The 5 laws of Data Masking.

Database Security Patch Coverage

  1. Oracle Critical Patch Update, July 2009.

General Coverage

  1. SQL Injection Prevention
  2. Database Audit Performance in this Friday Summary introduction
  3. Database Encryption Benchmarking
  4. Three Database Roles: Programmer, DBA, Architect
  5. Database Security: The Other First Steps
  6. Sentrigo and MS SQL Server Vulnerability.
  7. Amazon’s SimpleDB.
  8. Information on Weak Database Password Checkers.
  9. Database Connections and Trust, and databases are not typically set up to validate incoming connections against SQL injection and misused credentials, and this post on recommending Stored Procedures to address SQL Injection attacks
  10. Separation of Duties and Functions through roles and programmatic elements, and putting some of the web application code back into the database.
  11. Native database primary key generation to avoid data leakage and inference problems, and additional comments on Inference Attacks.
  12. Your Top 5 Database Security Resolutions.
  13. Posts on separation of duties: Who “Owns” Database Security, and the follow-up: DBAs should NOT own DAM & Database Security.
  14. A look at general threats around using External Database Procedures and variants in relational databases.
  15. Database Audit Events.
  16. Database Security Mass-Market Update and Friday Summary - May 29, 2009
  17. Database Patches, Ad Nauseum
  18. Acquisitions and Strategy
  19. Comments on Oracle’s Acquisition of Sun
  20. Oracle CPU for April 2009
  21. Netezza buys Tizor
  22. More Configuration and Assessment Options. Discusses recent Oracle and Tenable advancements.
  23. Policies and Security Products applies to database security as well as other product lines.
  24. Oracle Security Update for January 2009.
  25. Responding to the SQL Server Zero Day: Security Advisory 961040 includes some recommendations and workarounds.
  26. Will Database Security Vendors Disappear? and Rich’s follow-on Database Security Market Challenges considerations for this market segment.
  27. Behavioral Monitoring for database security.
  28. NitroSecurity acquired RippleTech.
  29. Database Monitoring is as big or bigger than DLP.

Presentations

Podcasts, Webcasts and Multimedia

None at this time

Vendors/Tools

The following is just an alphabetized and categorized list of vendors and products in this area (including any free tools we are aware of). It does not imply endorsement, and is meant to assist you should you start looking for tools. Please email info@securosis.com if you have any additions or corrections.

Database Activity Monitoring

Database Vulnerability Assessment

Database Encryption

Note that some of the vendors listed provide transparent disk encryption or application layer encryption that can be applied to database files or content.

Database Auditing

Database Masking

Note that there are several vendors who offer format preserving encryption and tokenization, such as NuBridges, Prime Factors, Protegrity and Voltage, which also provides some masking capabilities.

Database Vendors

There are dozens of vendors, both big and small, who offer databases – many with specific competitive advantages. We aren’t even attempting to comprehensive, and specifically ignored any without widespread mainstream adoption. There are also dozens more open source databases with small numbers of deployments, perhaps primarily embedded in applications or backending non-commercial web applications.

More aboutDatabase security

Wednesday, June 22, 2011

New white paper: comparative analysis of security: beyond the parameters

Since I wrote the CSO pragmatic life there (OK, 4 years, but it feels like life), I've been evangelizing better quantify security programs. Even without context, quantification is valuable, but they are much more useful as a whole. If I was intensely to find against a set of similar societies to compare your settings, which provide needed context. Unfortunately, with the number of fires, that we must fight every day, people of more accurate security are not time to adopt measures.

This article focuses on why you should. Keep us account security measures at a high level of the Foundation, and then spend most of the article explaining what benchmarking offers to your security program and how to do it. A brief extract Executive Summary explains well:

A key aspect of maturation of our safety programs must be the collection of parameters of security and their use to improve business processes. Even those with broad security measures programs still have difficulty in communicating the relative effectiveness of their efforts - in large part because they have no point of comparison. When speaking of success/failure of any safety program, without Management main objective reference point has therefore no idea if your results are good. Or a bad thing.

Enter the reference for the security, which involves comparing your security settings to a group of peers from similar businesses. If you can get a whole broad enough consistent data (both qualitative and quantitative), then compare your numbers with this data set, you can get a feeling of relative performance. Obviously, it is the care must be exercised when sharing, but the ability to transcend "yellow" (not bad) identifying current and arbitrary issues as 'red' (bad), or "green" (a little better) allows us to finally have some clarity on the effectiveness of our sensitive data security programs. In addition, metric and reference data can be exploited internally to provide goals and illuminate the trends to improve key security operations.

Those of you who espouse quantification acquire an objective method to make decisions regarding your security program. No more black magic, Voodoo or hypnosis for your approved budget, OK?

The paper has a landing page, or you can download the document directly: Security Benchmarking: Going Beyond Metrics (PDF).

While you enjoy the paper, please send a thank you to nCircle for her licence.

-Rothman (0) Mike comments
More aboutNew white paper: comparative analysis of security: beyond the parameters

Mobile security for oblivion

Are you interested in security of mobile applications? Max Veytsman, consultant in security at security Compass, to speak on this hot topic at the next meeting of the OWASP Toronto Chapter. Come and check it out! Date/time: May 11th, 2011 5: 00 - 6: 00 PM place: Auditorium C, 315 Front Street West, Toronto, ON M5V 2 d 6 length: 60 minutes [...]
More aboutMobile security for oblivion

N-Stalker is winning 2009′s the web application, database security security software, said!

SECURITY-database, one of the entities of more accredited in the world dedicated to identify and evaluate web security threats (and the best tools available on the market to combat them) named N-STALKER as winner of the 2009's in the assessment tools web application security. It is the result of 10 years, entirely dedicated to the creation, design and development [...]
More aboutN-Stalker is winning 2009′s the web application, database security security software, said!

Tuesday, June 21, 2011

The chronic SDL - how a change in Culture of engineering driven by the needs of security paid

Error in deserializing body of reply message for operation 'Translate'. The maximum string content length quota (8192) has been exceeded while reading XML data. This quota may be increased by changing the MaxStringContentLength property on the XmlDictionaryReaderQuotas object used when creating the XML reader. Line 1, position 9737.
Error in deserializing body of reply message for operation 'Translate'. The maximum string content length quota (8192) has been exceeded while reading XML data. This quota may be increased by changing the MaxStringContentLength property on the XmlDictionaryReaderQuotas object used when creating the XML reader. Line 1, position 9842.

Hi All – Doug here…

We recently had the opportunity to get an inside look into a large company’s journey addressing a web application security incident that led to a deep analysis and change in how a development organization builds security into their software development process.  

MidAmerican Energy Holdings Company is a global leader producing energy from diversified fuel sources for the U.S. and U.K. consumer markets with approximately 6.9 million electricity and gas customers worldwide. In mid-May 2008, the MidAmerican Energy website was under attack from a botnet titled banner82. Botnets are networks of compromised computers controlled by hackers known as “bot-herders” and have become a serious problem in cyberspace.

The company has a long tradition of customer service so this was a very important issue to them. They surveyed industry best practices and chose the Microsoft Security Development Lifecycle (SDL) as their preferred process for developing secure software and changing their engineering practices.

This story is captured in a new case study that takes you through the entire story of the cyber-attack and steps to resolution. Important issues show up like the need for executive support and how to get everyone onboard as MidAmerican raised security development as a central focus for their internal development group moving forward. The case study validates the need to make deep changes when necessary within the software development culture versus performing “security around the edges”. Other important insights detail how an aggressive timeline created focus and gave everyone a clear goal. The case study reports on how the company was able to significantly reduce the number of vulnerabilities and meet their security goals while setting the company up for long term success.

What we found particularly interesting was that after they went through this experience, MidAmerican was not only creating more secure applications but they also found something they hadn’t counted on. The SDL’s process requirements and the resultant engineering culture shift had brought together the entire development organization with QA in a way they hadn’t seen previously. Together they engaged in the SDL process and as a result there were fewer security bugs that were found and needed to be fixed late in the process – when it is most expensive. MidAmerican saw a real productivity gain out of their development organization, not just better application security. These ROI results mirror the key findings from the recent Forrester Consulting thought leadership paper as well as the Aberdeen Group research report. You might also want to take a look at the SDL Progress Report as it provides much of the same information that MidAmerican used to make their decision to implement the SDL.

Check out this fascinating real life story that we often don’t get to hear.

 

More aboutThe chronic SDL - how a change in Culture of engineering driven by the needs of security paid