![]() |
Your Enterprise Database Security Strategy 2010 an Independent Analyst Report by Forrester Research Inc. Download here |
Mar 09, 2010 | 07:27 PM
By Kelly Jackson HigginsGoogle's and Adobe's disclosure in January that they had been hit by the same wave of targeted attacks were rare voluntary revelations, the likes of which may never be seen again: Most companies won't disclose an attack unless required to by law or regulations. But security experts and forensics investigators say the best way to defend against targeted attacks and help unmask who's behind them is to gather and correlate attack information among various victims.
There's no common way today for victim firms to safely and confidentially share data about attacks they suffer, nor is there necessarily much incentive to do so. The so-called Aurora attacks out of China that hit Google, Adobe, Intel, and an unknown number of other organizations in the U.S. have reignited a debate about voluntary breach disclosure. Google's discovery of the attacks demonstrated how victims can benefit from collaboration with one another and law enforcement.
Aside from the obvious privacy concerns and worries about damage to their public images in the event of a publicly disclosed hack, many firms have reservations about sharing their breach information with law enforcement because it's often more of a one-way street than an information-sharing arrangement: They supply their attack information to the authorities and often don't hear back.
But that soon could change. FBI director Robert Mueller last week in a keynote address at the RSA Conference 2010 said while today it's the exception rather than the rule for organizations to report cyberattacks to the bureau, he promised some big changes that could allay privacy concerns. "We will minimize the disruption to your business. We will safeguard your privacy and your data. Where necessary, we will seek protective orders to preserve trade secrets and business confidentiality. And we will share with you what we can, as quickly as we can, about the means and methods of attack," Mueller told attendees.
Kevin Mandia, CEO of forensics firm Mandiant, says one approach would be for vertical markets to set up their own disclosure vehicles. They could then take that anonymized information and offer it to the FBI or other authorities. "I would send the raw information, malware, and intelligence to the government, but not through my organization," Mandia says. Doing so would provide a more confidential conduit of disclosure, plus different industries have different IT security requirements, he says.
But the reality is that unless they are bound by disclosure laws or regulations, most organizations just keep quiet about attacks on their networks. "It's a lonely life as a victim," he says. "How do they merge their data without repercussions? And [many times] they don't get any intelligence out of [sharing the information]."
Verizon Business, meanwhile, last week released to the public its framework for gathering and analyzing forensics data from a data breach that serves as the basis for its comprehensive annual data breach reports. The hope is the framework will facilitate more cooperation and data-sharing among breach victim organizations.
Half of all breaches that Verizon has investigated during the past two years have been related in some way. But in many other cases, breaches aren't correlated to look for connections, says Wade Baker, director of risk intelligence for Verizon Business. "Something I would love to see is [determining] connections among attacks," he says.
National cybersecurity coordinator Howard Schmidt said last week in an RSA town hall meeting discussion that he's looking at incident response issues. Schmidt said private industry hasn't had a central point of contact for reporting attacks, and they want to know who to call and how to protect their intellectual property.
Meanwhile, there has been plenty of speculation about Google's own business reasons for revealing the targeted attacks out of China, but all the search giant has said is it did so because of the security implications, human rights issues, and freedom of speech. Adobe also had its reasons for coming forward: "For us, it was about transparency. Our software is widely distributed," said Gary Terrell, CISO for Adobe Systems.
The CSO Council-Bay Area, of which Adobe is a founding member and Terrell the chair, also serves as an informal venue for some organizations to share breach information under nondisclosure. "We are able to share information confidentially" in the council, says Leslie Lambert, the former CISO for Sun Microsystems. Lambert notes that law enforcement typically wants "to pull from us [enterprises]" without necessarily reciprocating with any information about attacks or investigations.
Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.
You've Been Breached: Responding to a Database Compromise
Criminals are after your corporate databases, and sometimes, despite your best efforts, they get in and steal credit card numbers, personally identifiable information, proprietary business data or sensitive intellectual property. What do you do then? In this Dark Reading Tech Center report, we discuss the basics of incident response; discovering what was breached, and how; and the best way to protect your assets going forward.
Beyond the Database: Protecting Unstructured Data
Corporate databases may be the crown jewels, but unstructured data stores contain plenty of diamonds in the rough. Organizations can be burned by an exposed spreadsheet of credit card numbers, an e-mail with patient information or a file share containing reports on a pharmaceutical company's new wonder drug. In this Dark Reading Tech Center report, we show how to classify, find and protect unstructured data across the enterprise.
Protecting Databases from Web Applications
Most external hacks of databases occur because of flaws in Web applications that link to those databases. Yet, enterprises are increasingly exposing their most valuable data to these outward-facing interfaces. In this Dark Reading Tech Center report, we'll discuss how security teams, database administrators and application developers can work together to improve the defenses of both front-end Web applications and back-end databases to prevent these attacks from succeeding, and offer a look at the most frequent Web-borne database attacks.
Other reports from the Database Security Tech Center:
| Sponsored by: | ![]() |
HOWTO Secure and Audit Oracle 10g and 11g
Read the "Hardening Your Database" chapter from the 454-page book "HOWTO Secure and Audit Oracle 10g and 11g" and learn how to navigate the many security options within Oracle (authored by database security expert and Guardium CTO, Ron Ben Natan, Ph.D.)
HOWTO Monitor Database Activity
Read the "Database Activity Monitoring (DAM)" chapter from "HOWTO Secure and Audit Oracle 10g and 11g" (CRC Press, 2009) and learn how to leverage DAM to prevent cyberattacks, monitor privileged users and track access to sensitive data.
8 Steps to Holistic Database Security
Get the 8 essential best practices for a holistic approach to both safeguarding databases and achieving compliance with key regulations such as SOX, PCI-DSS, NIST 800-53 and data protection laws.
Essential Steps to Implementing Database Security and Auditing
Learn best practices and specific tips for effectively securing Oracle, SQL Server, DB2, MySQL and Sybase environments, including tracking security vulnerabilities, the anatomy of buffer overflow vulnerabilities and database auditing.
Databases at Risk: Current State of Database Security (ESG Research)
This recently published ESG report analyzes the current state of database security -- concluding it depends upon too many manual processes -- and also offers concrete steps to improve database security across the enterprise.