Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

3/31/2010
01:14 PM
Adrian Lane
Adrian Lane
Commentary
50%
50%

Insiders Not The Real Database Threat

The recent incident where an HSBC employee raided a corporate database of customer information and then attempted to sell information to French tax collectors has been characterized as a user-access control issue. But I don't agree.

The recent incident where an HSBC employee raided a corporate database of customer information and then attempted to sell information to French tax collectors has been characterized as a user-access control issue. But I don't agree.A Dark Reading article covering the HSBC database hack contends that user access control settings and maintenance were the main issue. For years, we had been hearing about the "insider threat" -- every security vendor mentions it in their product literature. The Secret Service Cyber Threat study on this for the better part of the last decade was accepted because it was the best data we had concerning data breaches. We have now discovered that data theft was far more widespread - and far more subtle - external data theft present with most corporations. The Verizon Breach Report, the Albert Gonzalez trial, and other research has gone a long way to dispel the myth that the insider threat is our greatest challenge.

This is important because focusing on an insider or outsider is a red herring to database security efforts. Insider theft is a specific threat model -- but just one to be considered.

Access controls provide the front line of defense, but access and authorization can be obtained without credentials. So if we reduce permissions to a minimum and keep the settings perfectly in line with established policies, there are dozens of ways to directly or indirectly obtain access and authorization. The most common is to compromise a service that has credentials, and then the attacker reprograms the service to do the dirty work. Sure, hackers guess passwords and sniff them off the network, but in many data breaches, access controls are bypassed entirely.

But access controls don't verify usage. Phil Lieberman of Lieberman Software captured this position in the Dark Reading piece:

"Problems like using commonly known shared passwords, never changing sensitive passwords, and allowing their employees to have too much access for too long to sensitive data with no accountability is the rule rather than the exception,"

You would think that better access controls and better administration that keep settings up to date was the best way to address the threat. But accountability is the real issue. Once you have access, you can perform any function that your authorization profile allows. Which is exactly what Mr. Falciani did at HSBC. The problem is he was not caught until he tried to sell the information to someone outside the company.

The important point Mr. Lieberman makes is the lack of accountability. Taking a page from accounting practices, proper separation of duties coupled with auditing are the most basic elements of fraud detection, and absent from most database security operations. If there is no way to perform validation for activity, there is no way to detect fraud electronically, and you are reliant on external systems (the French government in this case). External parties (customers, partners, peers) have been the common element in detecting most of the major data breaches, further evidence internal controls are absent or inadequate.

If I have guessed the password for an admin account, and I queries the customer database, how can you tell if I am an insider or an outsider? Can you determine if the activity is part of my normal job function, or am I stealing data? The common modes of access into the database, queries and extraction methods are leveraged by attackers and legitimate user alike. Sometimes there is no way to tell the difference. In other cases, context and behavior offer clues to detect and even stop data theft. When the request is coming from outside the company, at odd times a day, from an unknown application or simply exhibit irrational query patterns we have a very good indication of misuse.

The insider threat will always be a problem, regardless of how good your access control scheme is, because you have to provide employees credentials to do their job, and you have to trust them at some point. If you are worried about data theft, database monitoring and auditing are essential measures for fraud detection and security. These technologies close the gap left by access control systems for many different types of threats, not just employee theft.

Adrian Lane is an analyst/CTO with Securosis LLC, an independent security consulting practice. Special to Dark Reading. Adrian Lane is a Security Strategist and brings over 25 years of industry experience to the Securosis team, much of it at the executive level. Adrian specializes in database security, data security, and secure software development. With experience at Ingres, Oracle, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Commentary
How SolarWinds Busted Up Our Assumptions About Code Signing
Dr. Jethro Beekman, Technical Director,  3/3/2021
News
'ObliqueRAT' Now Hides Behind Images on Compromised Websites
Jai Vijayan, Contributing Writer,  3/2/2021
News
Attackers Turn Struggling Software Projects Into Trojan Horses
Robert Lemos, Contributing Writer,  2/26/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: George has not accepted that the technology age has come to an end.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-28466
PUBLISHED: 2021-03-07
This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer from the maintainers: Running a NATS service which is exposed to untrusted users presents a heightened r...
CVE-2021-27364
PUBLISHED: 2021-03-07
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
CVE-2021-27365
PUBLISHED: 2021-03-07
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length...
CVE-2021-27363
PUBLISHED: 2021-03-07
An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system...
CVE-2021-26294
PUBLISHED: 2021-03-07
An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_...