Over 158 million personal data records have been exposed since February 2005. There is no question that databases are under attack. No longer satisfied with defacing Web sites or committing other malicious acts, today’s attackers are increasingly targeting the database, where they can harvest data en mass and sell that data for financial gain.
Over 158 million personal data records have been exposed since February 2005. There is no question that databases are under attack. No longer satisfied with defacing Web sites or committing other malicious acts, today’s attackers are increasingly targeting the database, where they can harvest data en mass and sell that data for financial gain.
Attacks from insiders are also on the rise. Forrester Research estimates that over 70% of database breaches are internal. As security breaches transition from random hackers to planned, organized assaults on enterprise data, organizations are increasingly identifying such activity through the use of real-time activity monitoring focused at the database.
An important component of monitoring for suspicious activity is the correct targeting and proper identification of varied insider threats. A successful security plan requires an understanding of the varied nature of these threats. As interconnectivity and on-demand access to information have become more and more integral to the daily operation of business, the definition of insiders has been expanded to include several types of users:
Authorized users: Employees — clerks, accountants, finance, salespeople, purchasing and others. Essentially anyone who has been given access to data or systems within a given enterprise.
Privileged users: Individuals with elevated privileges, broad access and extensive database knowledge, including database administrators, developers, quality assurance, contractors and consultants.
Knowledge users: Employees with access to and knowledge of systems or security protocols such as IT operations, network operations, security personnel and audit personnel.
Outsiders with insider access and/or vulnerability knowledge: The sophisticated white-collar criminal.
Due to the varied nature of insiders, it is no longer sufficient to monitor privileged users exclusively. Security best practices mandate the monitoring of privileged activity regardless of user. By focusing activity monitoring on all relevant activity performed by all types of users, an enterprise can mitigate risk more effectively and protect database assets from breach and attack.
Addressing the threat of both internal and external database attacks requires increased and ongoing visibility of all database activity. Comprehensive database-monitoring solutions actively view, aggregate and report on database communications within the enterprise. Many solutions also incorporate business requirements such as auditing and compliance, and alert on potential security or regulatory violations.
Database security and compliance best practices dictate monitoring for known vulnerabilities. Commonly referred to as a compensating control, real-time activity monitoring ensures that databases are protected during the gap in time between discovery of a vulnerability and mitigation of that vulnerability. Organizations should proactively deploy activity monitoring to ensure the highest level of database security.
Activity monitoring assists organizations seeking to improve their security posture by:
• Identifying and alerting on anomalous activity and potential policy violations.
• Generating secure, tamper-evident audit trails on privileged activity by legitimate and unauthorized users.
• Automating key activity reporting — including violations.
• Documenting privacy controls, enhancing forensic capability and focusing the scope of investigative activity.
• Verifying that a comprehensive data-protection strategy is in place.
• Demonstrating security oversight and compliance for the purpose of minimizing liability in the event of a breach.
An effective database-monitoring solution is capable of observing all database activity. To do this, comprehensive security systems monitor database communication via network-based and host-based sensors. Network-based sensors are designed to “police the network,” examining every packet going in and out of the database(s). Unaddressed by this approach is local traffic from a client tapped directly into the database. A host-based sensor is needed to capture the activity operating directly on the database. Host-based solutions talk directly to the database asking for all requested activity — for example “What is the database sending?” and “What is being requested?” The captured data is then aggregated, analyzed and filtered by a centralized management console responsible for data correlation and reporting.
This is particularly essential in highly complex, heterogeneous, distributed enterprise environments. With millions of bits of event data cycling through, centralized management assists with identifying, alerting and reporting on important events, critical violations and potentially harmful activity. Equally vital to addressing database risks is access to a robust, up-to-date and complete knowledgebase of vulnerabilities to alert against. Without such knowledge, monitoring systems operate without the ability to correlate events with known threats such as SQL Slammer Worm, SQL injection attacks, buffer overflows and any number of holes impacting unpatched systems.
Activity monitoring is an essential part of any comprehensive database-security best practice. Monitoring and alerting enables enterprises to detect unusual database activity or policy violations and generate immediate alerts. A comprehensive approach combining database vulnerability assessment and real-time activity monitoring is necessary to proactively address security auditing and compliance requirements. By addressing these areas of concern within today’s highly complex database environments, organizations can address risk and mitigate security weaknesses within their IT infrastructure.
VanHorn is director of marketing for Application Security, Inc. He can be reached at tvanhorn@appsecinc.com.




