Archive for the ‘Database Security’ Category
Build Your Business’s Mobile Strategy Around Device Management And Security
W3C PLING Interest Group – Charter extended until June 2009
Good news. The W3C Policy Languages Interest Group (PLING - co-chairs: Renato Iannella, Marco Casassa Mont) charter has been extended until June 2009.
Please have a look at the PLING Twiki site for current outcomes of phone meetings, discussions and collection of material, about the following policy-related topics: use cases, policy languages review, related initiatives, interesting cases, open issues and scientific resources. Feel free to contribute and ensure that your positions and views are covered.
The PLING Twiki site also provides up-to-date information about coming PLING phone meetings. These meetings are open to anybody interested in the policy topic.
We are looking for speakers that are willing to provide a short presentation (30 min), during our phone conferences, illustrating their work in the space of policy/policy management, open/new issues, interesting use cases and their vision in this space.
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
High Touch Trumps High Tech When Switching Online Bill Payments
Global Banking Platform Deals 2007: Regions And Functionality
Market Update: Open Source Databases
Survey: Only Eight Percent of American are “Very Confident” their Personal Data is Properly Managed
This is the outcome of a recent survey by The Strategic Counsel, at least based on the overview provided by this article (called "Only Eight Percent of Americans are 'Very Confident' Their Personal Data is Safe With Retailers, Banks and Governments"):
"Only an average of eight percent of Americans say they are very confident in the ability of U.S. retailers, government and banks to protect their personal information, according to a national survey commissioned by CA, Inc., and conducted by The Strategic Counsel. The CA 2008 Security and Privacy Survey was done as in follow-up to the 2006 survey. Additionally, the consumer survey indicated that an average of 79 percent of American consumers cite loss of trust and confidence, damage to reputation, and reduced customer satisfaction as consequences of major security and privacy breaches suffered by the business or government organizations that they deal with."
Even more interesting is this statement, mentioned by the above article:
"Businesses used to worry about the hackers and thieves launching denial of service attacks from outside the firewall, now they recognize that their greatest danger lurks within the organization. The good news is that increasingly businesses are turning to identify and access management solutions to ensure that confidential data is safeguarded and available only to the people within the organization who genuinely need to have it."
Well, I just partially agree with the final part of this statement. Turning to identity and access management solutions is indeed important, but this is just one step towards really ensuring that personal and confidential data is managed according to legislation and users' preferences.
First of all, most of current IdM solutions are not really privacy-aware and/or do not provide privacy enhancing capabilities (e.g. privacy-aware access control) - aspects that are at the base for preventing that PII data is accessed and used beyond agreed purposes and for the wrong intents ... Secondly, IdM solutions can address the problem till at one point if accidents, social engineering, actions by traitors/insiders, and the effects of bad processes and practices can still happen ...
So, the other part of the story, for the enterprise, is putting in place proper "data governance processes" and dealing (upfront and periodically) with the necessary risk assessment and management steps. These steps (that should be carried out before deploying any "control point" in the IT infrastructure) are much, much harder to achieve and maintain than simply deploying IdM solutions ...
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
Oracle Security Advisories and CVE Identifiers
The previous Oracle proprietary numbering scheme had several issues in relationship to CVE numbering -
- Oracle provided a mapping to previously released vulnerabilities only for those vulnerabilities in core components like Apache and OpenSSL. No mapping was provided for previously publicly disclosed vulnerabilities, so there are cases when the same vulnerability has two CVE identifiers.
- A single CVE identifier was usually assigned to multiple vulnerabilities in an almost arbitrary fashion. This meant that a CVE identifier might include vulnerabilities from multiple components and in the case of the Oracle E-Business Suite across multiple patches. For Integrigy, this caused problems with our vulnerability scanning tool, AppSentry, since our reports have to handle many-to-many mappings when dealing with CVEs, patches, and vulnerabilities.
- The CVE numbers were usually assigned 1-2 days after the Oracle release.
The CVE identifiers in the Oracle advisory does use a single CVE identifier per vulnerability and maps directly to previously disclosed vulnerabilities (see CVE-2007-1359). Although it would have been nice if Oracle had included hyperlinks in the advisory to either CVE or NVD for easier access. It will be interesting to see if CVE-2007-1359 is fixed in this CPU as either CVE-2008-2589, CVE-2008-2594, or CVE-2008-2609, which would reduce the effectiveness of using the CVE identifiers and again result in duplication of vulnerabilities in CVE if CVE identifiers for previously disclosed vulnerabilities are not used.
Using the CVE Identifiers
Additional information on vulnerabilities can be found either in the CVE or the National Vulnerability Database (NVD) sponsored by the Department of Homeland Security. NVD contains the most detailed information including a break-down of the CVSS2 score and links to external references that may have more information on the vulnerability. The typical process is that a generic NVD is created with only a reference to the original Oracle advisory. When there is public disclosure with additional details on the vulnerability, the NVD entry is updated with links to those disclosures. This process should be much more timely and accurate as most public disclosures will now include the CVE identifier. Usually, about 30% of the vulnerabilities per quarter will have additional information and the database vulnerabilities typically have more information than the other products.
An example of a fully populated entry is the ModSecurity vulnerability that was previously fixed in ModSecurity 2.1.1 -
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1359
An example of an entry with additional details is the buffer overflow in the Oracle AQ package SYS.DBMS_AQELM -
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2607
Tax Risk Management: An Inconvenient Truth
Best Practices: Managing The Responsibility And Associated Risks Of Global Business Partners
Inquiry Insights: Client Security, Q3 2008
On Identity Analytics - Part II
In a previous post of mine I announced the release of a new HPL Technical Report, titled "On Identity Analytics: Setting the Context" (authors: Marco Casassa Mont, Adrian Baldwin, Simon Shiu), providing an overview of an HP Labs R&D project in the space of "Identity Analytics".
I received a few emails asking (among other things) about HP/HPL strategies in Identity Management and how Identity Analytics fits in all this. Some additional details follow, based on what I can publicly discuss.
Identity Analytics is an HP Labs project, in the context of the Security Analytics project (Systems Security Lab). The R&D goal of this project is to innovate in the space of Identity Management (in a broad sense, i.e. including also human, social and economic aspects) by moving from an approach purely based on operational Identity Management solutions to an approach that also takes into accounts the "strategic" needs and requirements of key decision makers (e.g. CIOs/CISOs).
What is the impact on an organisation (e.g. in terms of costs, risks, reputation, trust, etc.) when making strategic decisions and/or defining policies in the space of Identity Management? Are current policies adequate based on current (business, security, etc.) objectives? How technical, educational, human, social and business aspects are going to affect the (economic, security and business) outcomes, based on choices and decisions made? What are the relevant trade-offs that need to be analysed and how to evaluate them? How to provide strategic, forward-looking, "what-if" analysis to decision makers? These are some of the questions to be answered ...
This is a green field, open to innovation. In this context, technical Identity Management solutions are just one aspect of the overall equation (and sometimes not the most important ...), that also includes costs, (security and business) risks, business priorities and economic aspects.
I am confident that there are new business and market opportunities in this space, considering also the current shift (backed by key decision makers) from a pure "compliance-based" approach to a "risk-based" approach ...
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
Oracle Critical Patch Update July 2008 Pre-Release Analysis
- Overall, 45 security vulnerabilities are fixed in this CPU, which is an average number well within the range of previous CPUs (Apr-08=41, Jan-08=26, Oct-07=51, Jul-07=45, Apr-07=36, Jan-07=51, Oct-06=101, Jul-06=62, Apr-06=34, Jan-06=80).
- This is the first CPU that includes fixes for BEA WebLogic, Hyperion BI, and TimesTen Database.
- The product and vulnerability mix appears to be similar to previous CPUs. All CPU supported Oracle Database, Oracle Application Server, and Oracle E-Business Suite versions are included. The list of supported versions is getting very short and should be carefully reviewed to determine if version upgrades are required prior to applying the CPU security patches -
- Database = 9.2.0.8, 10.1.0.5, 10.2.0.3, 10.2.0.4, and 11.1.0.6 for major platforms
- Application Server = 9.0.4.3, 10.1.2, and 10.1.3
- E-Business Suite = 11.5.10.2, and 12.0.x
- Database version 10.2.0.4 is included in the list of affected versions
- Oracle E-Business Suite 11i versions 11.5.9, 11.5.10.0, and 11.5.10.1 are no longer supported for CPUs
Oracle Database
- There are 11 database vulnerabilities and none are remotely exploitable without authentication, which is consistent with previous CPUs. Usually, the vast majority of database vulnerabilities require authentication. However, a portion of these vulnerabilities can be exploited using only PUBLIC privileges accessible by all database accounts.
- The vulnerabilities of most interest are in the Core RDBMS and Authentication components, but the Database Scheduler vulnerability could be interesting.
- At least one of the database security vulnerabilities has a CVSS 2.0 metric of 6.5, which for database vulnerabilities should be considered high risk. This typically means anyone with a valid database session is able to compromise the entire database, but is unable to achieve root operating system access.
Oracle Application Server
- There are 9 new Oracle Application Server vulnerabilities, all of which are remotely exploitable without authentication. In previous CPUs, the majority of Oracle Application Server vulnerabilities have tended to be remotely exploitable without authentication. The vulnerabilities are in Hyperion BI Plus, Oracle HTTP Server, Oracle Internet Directory, and Oracle Portal.
- The Oracle HTTP Server vulnerabilities may be related to recent Apache HTTP Server and OpenSSL fixes.
- The Oracle Portal vulnerability may be related to CVE-2008-2138, which is an access restriction bypass issue in the WebDav component of Oracle Portal.
Oracle E-Business Suite 11i and R12
- There are 6 new Oracle E-Business Suite 11i and R12 vulnerabilities and none are remotely exploitable without authentication. However, since iStore allows for customer self-registration, most likely these vulnerabilities can be readily exploited by an unprivileged user.
- For the Oracle E-Business Suite 11i, only 11.5.10.2 is now supported for CPUs and requires ATG_PF.H RUP 5 or RUP 6 be installed.
Planning Impact
- As with all previous CPUs, this quarter's security patches should be deemed critical and you should adhere to the established procedures and timing used for previous CPUs.
Client Virtualization Enables Green Customer Care Centers: A Cox Communications Case Study
Topic Overview: Corporate Social Responsibility
On Identity Analytics: New HP Labs Technical Report
This community might be interested to a new HPL Technical Report, just released, titled "On Identity Analytics: Setting the Context" (authors: Marco Casassa Mont, Adrian Baldwin, Simon Shiu).
This report reflects R&D work we are doing at HP Labs, Systems Security Lab. I am very keen in getting your views and input. The abstract of this technical report follows:
"This paper aims at setting the context for "Identity Analytics" within enterprises and paving the path towards new R&D opportunities. In our vision, Identity Analytics is about explaining and predicting the impact of identity and identity management (along with other related aspects, such as users' behaviours) on key factors of relevance to decision makers (e.g. CIOs, CISOs), in complex enterprise scenarios - based on their initial assumptions and investment decisions.
Ultimately the goal is to provide rigorous techniques to help decision makers gain a better understanding of the investment trade-offs within the identity space (e.g. investing in technologies vs. changing processes vs. investing in users' education, etc.). This means providing "decision support" and "what-if analysis" capabilities to decision makers enabling them to explore these investment trade-offs, formulate new policies and/or justify existing ones. Our vision of "Identity Analytics" is introduced and discussed, along with the methodology that we intend to adopt.
There are many research opportunities and challenges in this space: we believe that a scientific approach is required, involving the usage of modelling and simulation techniques, coupled with the understanding of involved technologies and processes, human behaviours and economic aspects. To ground some of the concepts discussed in this paper, we provide an illustration of Identity Analytics focusing on emerging "web 2.0 enterprise collaborative data sharing", where unstructured information is created, stored and shared by people in collaborative contexts, within and across organisations. We demonstrate how trade-offs can be explored using the modelling approach hence allowing decision makers to explore the different impacts of policy choices."
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
Chip’s Blog - Buffer Overflow in SQL Server Convert Function
Chip’s Blog - Buffer Overflow in SQL Server Convert Function
Aligning Sourcing Processes With Corporate Sustainability
The Secret To Email Deliverability
Gartner’s Report: Top Seven Cloud-computing Security Risks
I tend to agree with the outcomes of a recent Gartner’s Report on the top seven cloud-computing security risks. A related article, by Jon Brodkin, provides a nice overview and summary of the key taking points of this report:
“Cloud computing is fraught with security risks, according to analyst firm Gartner. Smart customers will ask tough questions, and consider getting a security assessment from a neutral third party before committing to a cloud vendor, Gartner says in a June report titled “Assessing the Security Risks of Cloud Computing.” Cloud computing has “unique attributes that require risk assessment in areas such as data integrity, recovery and privacy, and an evaluation of legal issues in areas such as e-discovery, regulatory compliance and auditing,” Gartner says.” In particular I believe that the aspects related to “privileged user access”, “regulatory compliance” and “data location/data segregation/privacy management” are potential key issues that, if not properly addressed, can expose organizations (and users) to high risks.--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
FTC Planning to Conduct a Wide-Range Study on Identity Theft Victims
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
Chip’s Blog - Microsoft Releases KB Article on SQL Injection
Chip’s Blog - Microsoft Releases KB Article on SQL Injection
The Forrester Wave(tm): IT Risk And Compliance Software, Q2 2008
The Future of Identity Management? It is all about Managing Risk …
As I have been posting for a while, I believe that Identity Management will evolve, during the next few years, from a pure “control point and compliance”-based approach towards an approach that will increasingly factor in the management of Risk.
Decision makers (CIOs, CISOs, etc.) are shifting from a “compliance management” mentality to a “risk management” mentality, when making investment decisions on IT security solutions. Their investment decisions (including the ones on Identity Management) are going to be increasingly questioned, due to the shrinking of resources available. Hence the need to prioritise based on real business objectives and needs.
I am glad that Burton Group is now making some statements in the same direction, as it is possible to evince from this article:
“Identity management is evolving to include a closer recognition of risk and how to manage it rather than trying to eliminate it using technology, according to the head of the Burton Group consulting firm.
“Companies are looking at controls from a risk perspective instead of trying to control everything,” said Jamie Lewis, CEO of the Burton Group during the opening day of the firm’s annual Catalyst Conference. “It is about people managing risk and not about technology trying to make risk disappear.””
I believe there is a whole new set of research and commercial opportunities in this space (i.e. beyond compliance management and control points), whilst traditional Identity Management solutions are becoming more and more a commodity.
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---