Many database security projects arrive DOA because database administrators and security pros aren't singing the same tune.
As more organizations act to protect data at its most fundamental state, within the database, one of the biggest challenges that they run into is a people problem. In order to truly mitigate data risks, security teams need to learn to not only play nice with their database administrators, but to make them meaningful stakeholders in securing the databases they're entrusted to manage. That takes education, respectful conversations, and a willingness from both parties to open their minds a bit, experts say.
"There's a shift going on where [as an industry] we're changing our database security practices and we're starting to focus on that lost realm of the database security," said Josh Shaul, CTO of Application Security. "The folks who 'own' that database, the database administrators (DBAs), are finding their worlds changing in a significant way, and some of the freedoms that they've had are being taken away from them in order to do the security stuff. From my experience, I've seen that dynamic really create a gap in understanding or perspective between the DBA and security team that often has led organizations to get stuck in the muck around the area of database security."
The perception gap stems largely from a divergence in technology backgrounds.
"Often the DBA's focus is on performance and tuning and often many of them haven't been trained on security. They do their best and they're trying to learn it on the fly," said Scott Laliberte, managing director at Protiviti. "On the flipside, a lot of the security professionals out there do not have good database skills. They tend to be operating system, network, and application folks, and you can get security folks providing recommendations that aren't real practical or can introduce a problem within the database. The DBAs, therefore, fight them very hard."
According to Larry Whiteside, CISO for Visiting Nurse Service of New York, the way a lot of security controls work necessarily require some form of performance overhead within the database. It is only natural for the kneejerk reaction from DBAs to be somewhat negative.
Role-based access control based on least user privilege is one of the most effective ways to prevent the compromise of corporate data. Our new report explains why proper provisioning is a growing challenging, due to the proliferation of "big data," NoSQL databases, and cloud-based data storage. Download the report now. (Free registration required.)
Published: 2015-03-30 The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_s...
Published: 2015-03-30 Untrusted search path vulnerability in the Clean Utility application in Rockwell Automation FactoryTalk Services Platform before 2.71.00 and FactoryTalk View Studio 8.00.00 and earlier allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
Published: 2015-03-30 The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote atta...
Published: 2015-03-30 readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory ...
Published: 2015-03-30 Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that trigger creation of multiple dictionaries.