Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

8/10/2012
01:59 PM
Adrian Lane
Adrian Lane
Quick Hits
50%
50%

Strategies For Protecting Web-Facing Databases

The Web is the cybercriminal's favorite medium for attacking your database. But some databases must face the Web. Here are some tips for protecting that exposed data

[Excerpted from "Strategies For Protecting Web-Facing Databases," a new report published this month in Dark Reading's Database Security Tech Center.]

What do recent database attacks have in common?Answer: in moste cases, the criminals used the Web as an attack vector. Web applications, by their very nature, expose your infrastructure to the public. And we have plenty of evidence that demonstrates that people will, for fun or profit, hack your databases.

So how do you keep Web-facing databases secure? Removing them from the Web would be the easy answer, but a system that does not serve a business function is worthless to the company. Companies push more features and functions to the Web to better serve their customers and, in turn, generate more revenue. That is the focus of their efforts.

There is no doubt that once an application is serving customers and making money, no one is willing to pull it out of service in the name of security. Revenue trumps database security, so it’s the job of security professionals to figure out how to secure databases with limited resources while keeping the business systems operational.

In practical terms, all applications and databases created today are designed to communicate over Web protocols -- as an option, if not the primary communications channel. And every Web application has a database that manages data and application "state." In essence, databases hold the record of all activity that has occurred up to now.

Some of you may be asking at this point, "Doesn’t the application protect the database?" or "Isn’t the database shielded behind the application?" The answer to both of these questions is "no."

Many IT administrators have considered databases safe, or at least less accessible to attack, because they sit "behind" the Web application that directly serves users. In reality, many attacks are passed directly to the database from the calling application. Unless the application was designed and built to cleanse user data before it reaches the database, it’s merely a gateway used by a remote attacker to hack into a database.

Applications only shield databases from specific -- or specific classes -- of attack if they were programmed to do so. Most applications are not coded to protect a database by default, so assume your databases are as exposed to bad actors as any other Web application.

For a detailed list of attacks and threats to Web-facing databases -- as well as a list of strategies for defending against those threats -- download the free report on protecting Web-facing databases.

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Adrian Lane is a Security Strategist and brings over 25 years of industry experience to the Securosis team, much of it at the executive level. Adrian specializes in database security, data security, and secure software development. With experience at Ingres, Oracle, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
Breaches Are Inevitable, So Embrace the Chaos
Ariel Zeitlin, Chief Technology Officer & Co-Founder, Guardicore,  11/13/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13581
PUBLISHED: 2019-11-15
An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A heap-based buffer overflow allows remote attackers to cause a denial of service or execute arbitrary ...
CVE-2019-13582
PUBLISHED: 2019-11-15
An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A stack overflow could lead to denial of service or arbitrary code execution.
CVE-2019-6659
PUBLISHED: 2019-11-15
On version 14.0.0-14.1.0.1, BIG-IP virtual servers with TLSv1.3 enabled may experience a denial of service due to undisclosed incoming messages.
CVE-2019-6660
PUBLISHED: 2019-11-15
On BIG-IP 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.1, undisclosed HTTP requests may consume excessive amounts of systems resources which may lead to a denial of service.
CVE-2019-6661
PUBLISHED: 2019-11-15
When the BIG-IP APM 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.4.1, or 11.5.1-11.6.5 system processes certain requests, the APD/APMD daemon may consume excessive resources.