Practical Oracle Security: Your Unauthorized Guide to Relational Database Security

Shaul, Josh; Ingram, Aaron

In stock
Regular price 19.250 KD inc. VAT
License
Table of contents
  • Cover
  • Contentsix
  • Chapter 1 Oracle Security: The Big Picture1
  • Introduction2
  • A Brief History of Security Features in Oracle3
  • Privilege Controls4
  • Networking5
  • Oracle Advanced Networking Option5
  • The i in Oracle8i6
  • Auditing7
  • Fine Grained Auditing7
  • Password Management8
  • Profiles9
  • Data Compartmentalization11
  • Trusted Oracle711
  • Virtual Private Database13
  • Oracle Label Security13
  • Oracle10g and Beyond14
  • The Regulatory Environment Driving Database Security15
  • The Sarbanes-Oxley Act16
  • The Gramm-Leach-Bliley Act16
  • California Senate Bill 138617
  • The Health Insurance Portability and Accountability Act17
  • The Payment Card Industry Data Security Standard . .18
  • The Federal Information Security Management Act . .19
  • Major Data Theft Incidents20
  • CardSystems Solutions—June 200520
  • ChoicePoint—February 200521
  • TJX—January 200722
  • Department of Veterans Affairs—May 200624
  • A Step-by-step Approach to Securing Oracle25
  • Appropriate Security For Each Class of Database System26
  • Demonstrating Compliance28
  • Summary29
  • Solutions Fast Track29
  • Frequently Asked Questions31
  • Chapter 2 File System33
  • Introduction34
  • Getting to Know Your Files34
  • Data35
  • Tablespaces36
  • Redo Logs39
  • Backups40
  • Control Files41
  • Logs41
  • Software44
  • Reviewing Recommended Permissions46
  • Operating System Basics46
  • Software Permissions47
  • Non-software Permissions49
  • Managing Change49
  • Summary50
  • Solutions Fast Track50
  • Frequently Asked Questions52
  • Chapter 3 TNS Listener Security55
  • Introduction56
  • Introduction to the TNS Listener56
  • Listener Components57
  • tnslsnr57
  • lsnrctl57
  • sqlnet.ora57
  • listener.ora58
  • tnsnames.ora59
  • Listener Commands59
  • Oracle 10g Listener Changes61
  • Listeners Can Be a Major Source of Vulnerability to Attacks61
  • Listener Vulnerabilities “By Design”62
  • No Account Lockout62
  • Passwords Transmitted in Cleartext62
  • Authentication with Password or Password Hash63
  • Fixing Listener Vulnerabilities by Applying Oracle Patch Sets and CPUs63
  • Listener DoS Attacks64
  • Listener Buffer Overflow Attacks66
  • Securing the Listener Configuration67
  • Listener Security/Listener Password67
  • ADMIN_RESTRICTIONS68
  • Listener Logging and Tracing69
  • ExtProc71
  • Valid Node Checking75
  • Summary77
  • Solutions Fast Track77
  • Frequently Asked Questions80
  • Chapter 4 Managing Default Accounts83
  • Introduction84
  • The Role of Oracle Default Accounts From 9i to 10g86
  • Default Accounts87
  • Account:ADAMS87
  • Account:ANONYMOUS87
  • Account:AURORA$JIS$UTILITY$88
  • Account:AURORA$ORB$UNAUTHENTICATED88
  • Account: BLAKE88
  • Account: CLARK89
  • Account: CTXSYS89
  • Account: DBSNMP89
  • Account: DIP90
  • Account: DMSYS90
  • Account: EXFSYS90
  • Account: JONES91
  • Account: HR91
  • Account: LBACSYS91
  • Account: MDDATA91
  • Account: MDSYS92
  • Account:ODM92
  • Account: ODM_MTR92
  • Account: OE92
  • Account: OLAPDBA93
  • Account: OLAPSVR93
  • Account: OLAPSYS93
  • Account: ORDPLUGINS94
  • Account: ORDSYS94
  • Account: OSE$HTTP$ADMIN94
  • Account: OUTLN95
  • Account: PM95
  • Account: QS95
  • Account: RMAN95
  • Account: SCOTT96
  • Account: SH96
  • Account: SI_INFORMTN_SCHEMA96
  • Account: SYS97
  • Account: SYSMAN97
  • Account: SYSTEM97
  • Account:TSMSYS98
  • Account:WK_TEST98
  • Account:WKPROXY98
  • Account:WKSYS99
  • Account:WMSYS99
  • Account: XDB99
  • Lock Accounts and Expire Default Passwords101
  • Configure Strong Passwords101
  • Unlock Accounts and Configure Impossible Passwords103
  • Oracle’s Password Hashing Algorithm104
  • Defining Impossible Passwords105
  • Deploying Impossible Passwords106
  • Automating the Process of Identifying Default Accounts107
  • Creating Your Own Default Password Scanning Script108
  • Using a Freely Available Default Password Scanner109
  • Using a Commercial Database Vulnerability Scanner111
  • Summary114
  • Solutions Fast Track114
  • Frequently Asked Questions117
  • Chapter 5 PUBLIC Privileges121
  • Introduction122
  • The PUBLIC Group122
  • The Big Picture: Oracle Privileges and Roles124
  • Oracle Privileges124
  • Oracle Roles128
  • Roles Granted to PUBLIC130
  • Default Privileges on Sensitive Functions131
  • DBMS_RANDOM132
  • UTL_FILE132
  • UTL_HTTP136
  • UTL_SMTP137
  • UTL_TCP137
  • Privileges You Should Never Grant to PUBLIC138
  • System Privileges138
  • ANY System Privileges139
  • Individual System Privileges141
  • Object Privileges in the SYS Schema144
  • Use Common Sense144
  • Summary145
  • Solutions Fast Track145
  • Frequently Asked Questions147
  • Chapter 6 Software Updates149
  • Introduction150
  • Understanding Oracle’s Patching Philosophy150
  • Security151
  • Cost155
  • Platforms156
  • Examining a CPU156
  • Assessing the Risk Matrix157
  • The Common Vulnerability Scoring System159
  • Acting on Security Advisories161
  • Installing a Critical Patch Update164
  • Planning164
  • Testing and Deploying165
  • Evaluating Security Alerts167
  • Summary168
  • Solutions Fast Track168
  • Frequently Asked Questions170
  • Chapter 7 Passwords and Password Controls173
  • Introduction174
  • Configuring Strong Passwords174
  • What Makes a Password Weak?175
  • Who Can Remember a Strong Password?176
  • Password Management Tools177
  • Password Rule Sets177
  • Passwords For Non-production Systems178
  • Password Controls Using Oracle Profiles178
  • The Oracle Profile179
  • Failed Login Attempts180
  • Password Life Time181
  • Password Reuse Max181
  • Password Reuse Time182
  • Password Lock Time182
  • Password Grace Time183
  • Password Verify Function183
  • Assigning Profiles to Users184
  • OS Authentication187
  • Remote OS Authentication187
  • OS Authentication Prefix187
  • Creating and Identifying OS Authenticated Users189
  • Automated Scanning for Weak Passwords190
  • Freeware Password Scanners191
  • Commercial Password Scanners193
  • Summary195
  • Solutions Fast Track195
  • Frequently Asked Questions197
  • Chapter 8 Database Activity Monitoring201
  • Introduction202
  • Database Intrusion 101202
  • Injecting SQL203
  • HTTP Server204
  • Direct Database Access205
  • Detecting Known Attack Patterns209
  • Detecting Suspicious Activity213
  • Tracking the Attacker216
  • Adhering to Government and Industry Regulations218
  • The Sarbanes-Oxley Act218
  • The Gramm-Leach-Bliley Act219
  • California Senate Bill 1386219
  • The Health Insurance Portability and Accountability Act219
  • The Payment Card Industry Data Security Standard220
  • Summary221
  • Solutions Fast Track221
  • Frequently Asked Questions223
  • Chapter 9 Implementation Guide225
  • Introduction226
  • Getting Started227
  • Implementing Basic Security229
  • Implementing Best Practices231
  • Locking Down Your Database233
  • Summary236
  • Solutions Fast Track236
  • Frequently Asked Questions238
  • Index239
Book details
  • Vendor Elsevier S & T
  • SKU 9781597491983
  • ISBN-13 9780080555669
  • Author Shaul, Josh; Ingram, Aaron
  • Category Computers
  • Subject Computer Science

Do you have questions about this book?

Ask an expert!

This is the only practical, hands-on guide available to database administrators to secure their Oracle databases. This book will help the DBA to assess their current level of risk as well as their existing security posture. It will then provide practical, applicable knowledge to appropriately secure the Oracle database. The book’s companion Web site contains dozens of working scripts that DBA’s can use to secure and automate their Oracle databases.

* The only practical, hands-on guide for securing your Oracle database published by independent experts.
* Companion Web site contains dozens of scripts to help you automate security tasks.
* Your Oracle database does not exist in a vacuum, so this book shows you how to securely integrate your database into your enterprise.