Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


01:14 PM
Adrian Lane
Adrian Lane

Insiders Not The Real Database Threat

The recent incident where an HSBC employee raided a corporate database of customer information and then attempted to sell information to French tax collectors has been characterized as a user-access control issue. But I don't agree.

The recent incident where an HSBC employee raided a corporate database of customer information and then attempted to sell information to French tax collectors has been characterized as a user-access control issue. But I don't agree.A Dark Reading article covering the HSBC database hack contends that user access control settings and maintenance were the main issue. For years, we had been hearing about the "insider threat" -- every security vendor mentions it in their product literature. The Secret Service Cyber Threat study on this for the better part of the last decade was accepted because it was the best data we had concerning data breaches. We have now discovered that data theft was far more widespread - and far more subtle - external data theft present with most corporations. The Verizon Breach Report, the Albert Gonzalez trial, and other research has gone a long way to dispel the myth that the insider threat is our greatest challenge.

This is important because focusing on an insider or outsider is a red herring to database security efforts. Insider theft is a specific threat model -- but just one to be considered.

Access controls provide the front line of defense, but access and authorization can be obtained without credentials. So if we reduce permissions to a minimum and keep the settings perfectly in line with established policies, there are dozens of ways to directly or indirectly obtain access and authorization. The most common is to compromise a service that has credentials, and then the attacker reprograms the service to do the dirty work. Sure, hackers guess passwords and sniff them off the network, but in many data breaches, access controls are bypassed entirely.

But access controls don't verify usage. Phil Lieberman of Lieberman Software captured this position in the Dark Reading piece:

"Problems like using commonly known shared passwords, never changing sensitive passwords, and allowing their employees to have too much access for too long to sensitive data with no accountability is the rule rather than the exception,"

You would think that better access controls and better administration that keep settings up to date was the best way to address the threat. But accountability is the real issue. Once you have access, you can perform any function that your authorization profile allows. Which is exactly what Mr. Falciani did at HSBC. The problem is he was not caught until he tried to sell the information to someone outside the company.

The important point Mr. Lieberman makes is the lack of accountability. Taking a page from accounting practices, proper separation of duties coupled with auditing are the most basic elements of fraud detection, and absent from most database security operations. If there is no way to perform validation for activity, there is no way to detect fraud electronically, and you are reliant on external systems (the French government in this case). External parties (customers, partners, peers) have been the common element in detecting most of the major data breaches, further evidence internal controls are absent or inadequate.

If I have guessed the password for an admin account, and I queries the customer database, how can you tell if I am an insider or an outsider? Can you determine if the activity is part of my normal job function, or am I stealing data? The common modes of access into the database, queries and extraction methods are leveraged by attackers and legitimate user alike. Sometimes there is no way to tell the difference. In other cases, context and behavior offer clues to detect and even stop data theft. When the request is coming from outside the company, at odd times a day, from an unknown application or simply exhibit irrational query patterns we have a very good indication of misuse.

The insider threat will always be a problem, regardless of how good your access control scheme is, because you have to provide employees credentials to do their job, and you have to trust them at some point. If you are worried about data theft, database monitoring and auditing are essential measures for fraud detection and security. These technologies close the gap left by access control systems for many different types of threats, not just employee theft.

Adrian Lane is an analyst/CTO with Securosis LLC, an independent security consulting practice. Special to Dark Reading. Adrian Lane is a Security Strategist and brings over 25 years of industry experience to the Securosis team, much of it at the executive level. Adrian specializes in database security, data security, and secure software development. With experience at Ingres, Oracle, and ... View Full Bio


Recommended Reading:

Comment  | 
Print  | 
More Insights
Oldest First  |  Newest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/10/2020
Researcher Finds New Office Macro Attacks for MacOS
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/7/2020
Lock-Pickers Face an Uncertain Future Online
Seth Rosenblatt, Contributing Writer,  8/10/2020
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: They said you could use Zoom anywhere.......
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-08-13
A timeout during a TLS handshake can result in the connection failing to terminate. This can result in a Niagara thread hanging and requires a manual restart of Niagara (Versions,,, and Niagara Enterprise Security (Versions 2.4.31, 2.4.45, to corr...
PUBLISHED: 2020-08-13
An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metacharacters. The attacker can then, for example, read sensitive files such as appliance admin configura...
PUBLISHED: 2020-08-13
For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature
PUBLISHED: 2020-08-13
For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.
PUBLISHED: 2020-08-13
A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.10.21 allows remote authenticated attackers to execute arbitrary SQL commands via the TPF_XPAR1 parameter.