Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

5/18/2010
11:54 AM
Adrian Lane
Adrian Lane
Commentary
50%
50%

Goldman Sachs Lawsuit Shows Need For DAM

When Goldman Sachs was hit with a lawsuit by Ipreo Networks, I got a call from Dark Reading contributor Ericka Chickowski to talk about the alleged misuse of the "BigDough" database. Specific details on this case remain scarce, but threats to Customer Relationship Management (CRM) systems and SaaS based data services are well known.

When Goldman Sachs was hit with a lawsuit by Ipreo Networks, I got a call from Dark Reading contributor Ericka Chickowski to talk about the alleged misuse of the "BigDough" database. Specific details on this case remain scarce, but threats to Customer Relationship Management (CRM) systems and SaaS based data services are well known.As is typical in these cases, the access control system validated the user. Ipreo suspects misuse because the logins were conducted via an Internet connection from and address owned by Goldman. The question is, what does Ipreo really know? If someone at Goldman was doing something wrong, why did it take Ipreo two years to detect the issue?

CRM system misuse is difficult to detect with standard security measures, but this is a textbook example of why database activity monitoring systems were invented.

I began writing homegrown activity monitoring tools in 1998, specifically to detect misuse of the brokerage CRM systems I managed. Through a combination of database triggers and network monitoring, the specific use cases I needed to address were brokers looking at a number of records that were "owned" by other brokers, or when a broker looked to be downloading a large percentage of the database. Our brokers commonly served multiple products and multiple geographic locations, so the trick was differentiating between normal behavior and suspect behavior. The commercial intrusion detection systems (IDS)lacked any of the business context to differentiate between normal and suspicious business transactions. CRM misuse is, to me, the very genesis of the database monitoring market.

Since that time, DAM platforms have undergone several generations of maturity, offering much better performance and analysis capabilities. But use of DAM products for SaaS services remains rare. Service providers still rely upon access controls, looking at the IP address in association with the users account during login in order to detect compromised credentials. And this approach remains effective at catching shared credentials used in different locations -- provided you only permit your customer to be in one location. But this is an outdated assumption with salespeople likely to be on the road, using any wireless hotspot they can connect with. That means a different IP address every day. Reliance on network-based detection is speculative at best.

The problem of sharing credentials is really common. You want to help a friend, so you give them a login to help solve a problem. But odds are that they use the account the next time they need a quick answer. Few people go to the hassle of changing their password to stop a friend from using the account again. Password rotation helps block the causal mis-user who was provided credentials and merely wants to view information to help them make business decisions. But odds are pretty good their friends and family will give them the new passwords as well.

Password policies do not address account hijacking, cases where data is altered, or detect a user downloading an entire copy of the database. Unless Ipreo was monitoring usage, their claim for damages will be sketchy at best. Their access control system saw valid credentials, their gateways see an IP address, but unless they engineered their applications to record data queries, they may not be able to prove data was actually viewed.

If a database contains valuable enough data, it's a safe bet it will attract the purely malicious attacker. Downloading credit card numbers to be sold or used in a fraudulent manner, altering accounts for financial gain, or monitoring inside information for stock trades are all malicious acts that go undetected by access controls, intrusion detection and most auditing systems. With more firms offering services over the Internet, or even in the cloud, we cannot differentiate between insiders and outsiders.

With SaaS, all of your users are outsiders. IP addresses can be faked, so the association of appropriate IP addresses in conjunction with a specific accounts is no longer a viable method to detect account hijacking. If Ipreo is serious about misuse detection for their database and doesn't want to allow shared account usage to go on for years, then they need to look at monitoring database activity.

If the database is how you generate most of your revenue, don't you think you should watch over it?

Adrian Lane is an analyst/CTO with Securosis LLC, an independent security consulting practice. Special to Dark Reading. Adrian Lane is a Security Strategist and brings over 25 years of industry experience to the Securosis team, much of it at the executive level. Adrian specializes in database security, data security, and secure software development. With experience at Ingres, Oracle, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Small Business Security: 5 Tips on How and Where to Start
Mike Puglia, Chief Strategy Officer at Kaseya,  2/13/2020
Architectural Analysis IDs 78 Specific Risks in Machine-Learning Systems
Jai Vijayan, Contributing Writer,  2/13/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-0055
PUBLISHED: 2020-02-19
OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.
CVE-2019-12437
PUBLISHED: 2020-02-19
In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,
CVE-2020-8441
PUBLISHED: 2020-02-19
JYaml through 1.3 allows remote code execution during deserialization of a malicious payload through the load() function. NOTE: this is a discontinued product.
CVE-2020-8824
PUBLISHED: 2020-02-19
Hitron CODA-4582U 7.1.1.30 devices allow XSS via a Managed Device name on the Wireless > Access Control > Add Managed Device screen.
CVE-2020-8959
PUBLISHED: 2020-02-19
Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.