SQLProNews This is an iEntry Publication

Advertising, Headlines, Signup
SQLProNews
SecurityProNews
ITmanagement








Oracle Adding Firewall To Their Database

By John Vinson
Expert Author
Article Date: 2011-02-18

For Oracle users who are continually worrying about security, this news will seem like a breath of fresh air.It was announced earlier this week that Oracle would be adding a database firewall to their system. This will provide monitoring services, enforce normal behavior, and defend against unauthorized access or injection attacks.

Oracle is using what is called "SQL grammar analysis technology". This will help to analyze SQL queries that can access all sorts of important informational. The technology came from a May 2010 acquisition; the firewall vendor Secerno.

So if you want to add this firewall to your system, will any changes need to be met?

According to Oracle, no. Existing databases can be left as is, along with applications and infrastructure. Compatibility is a key issue as well, and the firewall supposedly works with any Intel-based hardware.

Vipin Samar, VP of database security for Oracle, states why Oracle users should look into this firewall, "Customers are not taking sufficient measures to prevent attacks from reaching their databases."

"This is confirmed by industry reports like the 2010 (and 2009) Verizon Data Breach Investigations Report that found that compromised database servers were responsible for 89% of breached data. This isn't surprising since sensitive and regulated data in most organizations resides in their databases."

A question brought up by some users is why provide the firewall as an add-on? There are a couple of key reasons. First, database firewalls are easy to get off the ground. They also can provide protection across multiple databases, instead of worrying about security for each one specifically.

Another major factor is cost control. Using a firewall requires simple updates from time to time, unlike complete databases. Considering security is something continually updated, this could require database restarts on a regular basis.

Attacks to SQL are continuing to grow, and security becomes more important with each passing year. While a firewall doesn't guarantee complete security, it's definitely a good place to start.


About the Author:
John is a staff writer for WebProNews.




SQLProNews is an iEntry, Inc. ® publication - All Rights Reserved Privacy Policy and Legal
Oracle Adding Firewall To Their Database