Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

3/31/2010
01:14 PM
Adrian Lane
Adrian Lane
Commentary
50%
50%

Insiders Not The Real Database Threat

The recent incident where an HSBC employee raided a corporate database of customer information and then attempted to sell information to French tax collectors has been characterized as a user-access control issue. But I don't agree.

The recent incident where an HSBC employee raided a corporate database of customer information and then attempted to sell information to French tax collectors has been characterized as a user-access control issue. But I don't agree.A Dark Reading article covering the HSBC database hack contends that user access control settings and maintenance were the main issue. For years, we had been hearing about the "insider threat" -- every security vendor mentions it in their product literature. The Secret Service Cyber Threat study on this for the better part of the last decade was accepted because it was the best data we had concerning data breaches. We have now discovered that data theft was far more widespread - and far more subtle - external data theft present with most corporations. The Verizon Breach Report, the Albert Gonzalez trial, and other research has gone a long way to dispel the myth that the insider threat is our greatest challenge.

This is important because focusing on an insider or outsider is a red herring to database security efforts. Insider theft is a specific threat model -- but just one to be considered.

Access controls provide the front line of defense, but access and authorization can be obtained without credentials. So if we reduce permissions to a minimum and keep the settings perfectly in line with established policies, there are dozens of ways to directly or indirectly obtain access and authorization. The most common is to compromise a service that has credentials, and then the attacker reprograms the service to do the dirty work. Sure, hackers guess passwords and sniff them off the network, but in many data breaches, access controls are bypassed entirely.

But access controls don't verify usage. Phil Lieberman of Lieberman Software captured this position in the Dark Reading piece:

"Problems like using commonly known shared passwords, never changing sensitive passwords, and allowing their employees to have too much access for too long to sensitive data with no accountability is the rule rather than the exception,"

You would think that better access controls and better administration that keep settings up to date was the best way to address the threat. But accountability is the real issue. Once you have access, you can perform any function that your authorization profile allows. Which is exactly what Mr. Falciani did at HSBC. The problem is he was not caught until he tried to sell the information to someone outside the company.

The important point Mr. Lieberman makes is the lack of accountability. Taking a page from accounting practices, proper separation of duties coupled with auditing are the most basic elements of fraud detection, and absent from most database security operations. If there is no way to perform validation for activity, there is no way to detect fraud electronically, and you are reliant on external systems (the French government in this case). External parties (customers, partners, peers) have been the common element in detecting most of the major data breaches, further evidence internal controls are absent or inadequate.

If I have guessed the password for an admin account, and I queries the customer database, how can you tell if I am an insider or an outsider? Can you determine if the activity is part of my normal job function, or am I stealing data? The common modes of access into the database, queries and extraction methods are leveraged by attackers and legitimate user alike. Sometimes there is no way to tell the difference. In other cases, context and behavior offer clues to detect and even stop data theft. When the request is coming from outside the company, at odd times a day, from an unknown application or simply exhibit irrational query patterns we have a very good indication of misuse.

The insider threat will always be a problem, regardless of how good your access control scheme is, because you have to provide employees credentials to do their job, and you have to trust them at some point. If you are worried about data theft, database monitoring and auditing are essential measures for fraud detection and security. These technologies close the gap left by access control systems for many different types of threats, not just employee theft.

Adrian Lane is an analyst/CTO with Securosis LLC, an independent security consulting practice. Special to Dark Reading. Adrian Lane is a Security Strategist and brings over 25 years of industry experience to the Securosis team, much of it at the executive level. Adrian specializes in database security, data security, and secure software development. With experience at Ingres, Oracle, and ... View Full Bio

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/14/2020
Lock-Pickers Face an Uncertain Future Online
Seth Rosenblatt, Contributing Writer,  8/10/2020
Hacking It as a CISO: Advice for Security Leadership
Kelly Sheridan, Staff Editor, Dark Reading,  8/10/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 New Cybersecurity Vulnerabilities That Could Put Your Enterprise at Risk
In this Dark Reading Tech Digest, we look at the ways security researchers and ethical hackers find critical vulnerabilities and offer insights into how you can fix them before attackers can exploit them.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-17475
PUBLISHED: 2020-08-14
Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to anyone by sending packet data to UDP port 5000.
CVE-2020-0255
PUBLISHED: 2020-08-14
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-10751. Reason: This candidate is a duplicate of CVE-2020-10751. Notes: All CVE users should reference CVE-2020-10751 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta...
CVE-2020-14353
PUBLISHED: 2020-08-14
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-18270. Reason: This candidate is a duplicate of CVE-2017-18270. Notes: All CVE users should reference CVE-2017-18270 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta...
CVE-2020-17464
PUBLISHED: 2020-08-14
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2020-17473
PUBLISHED: 2020-08-14
Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server.