Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


11:54 AM
Adrian Lane
Adrian Lane

Goldman Sachs Lawsuit Shows Need For DAM

When Goldman Sachs was hit with a lawsuit by Ipreo Networks, I got a call from Dark Reading contributor Ericka Chickowski to talk about the alleged misuse of the "BigDough" database. Specific details on this case remain scarce, but threats to Customer Relationship Management (CRM) systems and SaaS based data services are well known.

When Goldman Sachs was hit with a lawsuit by Ipreo Networks, I got a call from Dark Reading contributor Ericka Chickowski to talk about the alleged misuse of the "BigDough" database. Specific details on this case remain scarce, but threats to Customer Relationship Management (CRM) systems and SaaS based data services are well known.As is typical in these cases, the access control system validated the user. Ipreo suspects misuse because the logins were conducted via an Internet connection from and address owned by Goldman. The question is, what does Ipreo really know? If someone at Goldman was doing something wrong, why did it take Ipreo two years to detect the issue?

CRM system misuse is difficult to detect with standard security measures, but this is a textbook example of why database activity monitoring systems were invented.

I began writing homegrown activity monitoring tools in 1998, specifically to detect misuse of the brokerage CRM systems I managed. Through a combination of database triggers and network monitoring, the specific use cases I needed to address were brokers looking at a number of records that were "owned" by other brokers, or when a broker looked to be downloading a large percentage of the database. Our brokers commonly served multiple products and multiple geographic locations, so the trick was differentiating between normal behavior and suspect behavior. The commercial intrusion detection systems (IDS)lacked any of the business context to differentiate between normal and suspicious business transactions. CRM misuse is, to me, the very genesis of the database monitoring market.

Since that time, DAM platforms have undergone several generations of maturity, offering much better performance and analysis capabilities. But use of DAM products for SaaS services remains rare. Service providers still rely upon access controls, looking at the IP address in association with the users account during login in order to detect compromised credentials. And this approach remains effective at catching shared credentials used in different locations -- provided you only permit your customer to be in one location. But this is an outdated assumption with salespeople likely to be on the road, using any wireless hotspot they can connect with. That means a different IP address every day. Reliance on network-based detection is speculative at best.

The problem of sharing credentials is really common. You want to help a friend, so you give them a login to help solve a problem. But odds are that they use the account the next time they need a quick answer. Few people go to the hassle of changing their password to stop a friend from using the account again. Password rotation helps block the causal mis-user who was provided credentials and merely wants to view information to help them make business decisions. But odds are pretty good their friends and family will give them the new passwords as well.

Password policies do not address account hijacking, cases where data is altered, or detect a user downloading an entire copy of the database. Unless Ipreo was monitoring usage, their claim for damages will be sketchy at best. Their access control system saw valid credentials, their gateways see an IP address, but unless they engineered their applications to record data queries, they may not be able to prove data was actually viewed.

If a database contains valuable enough data, it's a safe bet it will attract the purely malicious attacker. Downloading credit card numbers to be sold or used in a fraudulent manner, altering accounts for financial gain, or monitoring inside information for stock trades are all malicious acts that go undetected by access controls, intrusion detection and most auditing systems. With more firms offering services over the Internet, or even in the cloud, we cannot differentiate between insiders and outsiders.

With SaaS, all of your users are outsiders. IP addresses can be faked, so the association of appropriate IP addresses in conjunction with a specific accounts is no longer a viable method to detect account hijacking. If Ipreo is serious about misuse detection for their database and doesn't want to allow shared account usage to go on for years, then they need to look at monitoring database activity.

If the database is how you generate most of your revenue, don't you think you should watch over it?

Adrian Lane is an analyst/CTO with Securosis LLC, an independent security consulting practice. Special to Dark Reading. Adrian Lane is a Security Strategist and brings over 25 years of industry experience to the Securosis team, much of it at the executive level. Adrian specializes in database security, data security, and secure software development. With experience at Ingres, Oracle, and ... View Full Bio


Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/10/2020
Researcher Finds New Office Macro Attacks for MacOS
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/7/2020
Healthcare Industry Sees Respite From Attacks in First Half of 2020
Robert Lemos, Contributing Writer,  8/13/2020
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: It's a technique known as breaking out of the sandbox kids.
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-08-13
ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka allows escalation of privileges by local users via manipulations involving files and using symbolic links.
PUBLISHED: 2020-08-13
njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c.
PUBLISHED: 2020-08-13
njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff" in the NGINX use case because there is no remote attack surface.
PUBLISHED: 2020-08-13
An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an authenticated user to escalate privileges by placing a specially crafted DLL file in the search path. This issue was fixed in version 1.0.7, which was r...
PUBLISHED: 2020-08-13
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.