RE: Security auditing tools
Date: Mon, 18 Jun 2012 10:12:32 -0400
Message-ID: <C3F905167E081B418BFC63B8668D52FF23C1E7112A_at_GOXEXVS03.fplu.fpl.com>
We are using Guardium (we're using the IBM stack here). Takes a long time to get running properly and I believe it integrates into the kernel of the OS it's "guarding". If any changes are required, it takes a reboot of the machine. Whenever I do anything I'm not supposed to, I get an email from infosec asking what I was doing. The reports are fairly extensive and they capture just about everything. From what we've seen, very little impact on db performance. One of the key selling points was the ability to block any types of sql that it didn't see as "normal activity".
Thanks!
Jeremy
-----Original Message-----
From: oracle-l-bounce_at_freelists.org [mailto:oracle-l-bounce_at_freelists.org] On Behalf Of Upendra N
Sent: Friday, June 15, 2012 7:30 PM
To: joel.patterson_at_crowley.com; Oracle-L
Subject: RE: Security auditing tools
Hi Joel,
I have been reviewing of tools similar that as well.. the notable ones that I have come across are Guardium (IBM purchased this some time ago) and DBProtect (A product from Application Security Inc.). Both of them provide very similar functionality.. We could audit the database binary for missing patches, known vulnerabilities, default passwords. Guardium also says that it has tools to analyze the workload characteristics of a user and identify any deviations which might be a result of SQL Injection etc.
Both of them let you configure real-time alerting based on several criteria. They both provide built-in reports which contains enough information for SOX/PCI/HiPAA compliance reporting.
BTW, for the 22 page document you are talking about.. did you build this yourself?
Have you seen the 157 page document about Oracle Database security? ;) https://benchmarks.cisecurity.org/tools2/oracle/CIS_Oracle_11g_Benchmark_v1.1.0.pdf
-Upendra
> From: Joel.Patterson_at_crowley.com
> To: Oracle-L_at_freelists.org
> Date: Fri, 15 Jun 2012 11:03:08 -0400
> Subject: Security auditing tools
>
> We are in the process of laying out a baseline of what and how the databases and software should be set - as it pertains to security.
> Of course this encompasses everything from file permissions to account locks, default passwords - and on and on as you might imagine. I have already seen a 22 page document listing.
>
> Right away, I notice there are a couple items out of date, in this case pertaining to passwords on the listeners. Or, pertaining to listeners again, creating separate listeners for everything on your server, from the agent to administration purposes. Or 'locking' the oracle account --- etc....
>
> What I would like from the list, if one is inclined to be so kind, is if there are any good 'tools' that anyone uses, that automates the process of checking/auditing security. Also, any up to date documents on issues like, but not unlike, what I just brought up with the listeners.
>
> Best Regards,
>
> Joel Patterson
> Database Administrator
> 904 727-2546
>
>
>
> --
> http://www.freelists.org/webpage/oracle-l
>
>
-- http://www.freelists.org/webpage/oracle-l -- http://www.freelists.org/webpage/oracle-lReceived on Mon Jun 18 2012 - 09:12:32 CDT