Open-Source Database Security

A recent article on Dark Reading underscores a growing concern in IT: how to secure open-source databases.

Adrian Lane, Contributor

June 21, 2010

1 Min Read
Dark Reading logo in a gray background | Dark Reading

A recent article on Dark Reading underscores a growing concern in IT: how to secure open-source databases.According to the article, "Open-Source Databases Pose Unique Security Challenges," by Ericka Chickowski, Ingres and MySQL are being used for large-scale commercial applications. They support Web commerce sites and are growing in use as fast as their commercial counterparts. They are used as a replacement for Oracle, DB2, and SQL Server when cost or flexibility is an issue. The issue Ericka raises is not that these platforms are less secure by nature, but that they lack the supporting security knowledge and tools available on other platforms.

Until recently, the major database vendors did not offer a full suite of database security options. Now they do, with activity monitoring, assessment, and transparent encryption to go along with access controls and authorization schemes. Rummage around the open-source Web sites and you will discover deployment guides and basic security tips -- but these center around access controls and secure communication (i.e., SSL). Security research and tools designed to help secure these platforms is generally absent. Third-party vendors have not ported their monitoring, masking, auditing, and assessment tools because customer demand has not been high enough to justify the costs.

To get a better idea of why this is important, let's look at vulnerability assessment. There are no formalized assessment products, and beyond a smattering of policies for MySQL, no research teams perform policy development for open-source databases.

About the Author

Adrian Lane

Contributor

Adrian Lane is a Security Strategist and brings over 25 years of industry experience to the Securosis team, much of it at the executive level. Adrian specializes in database security, data security, and secure software development. With experience at Ingres, Oracle, and Unisys, he has extensive experience in the vendor community, but brings a pragmatic perspective to selecting and deploying technologies having worked on "the other side" as CIO in the finance vertical. Prior to joining Securosis, Adrian served as the CTO/VP at companies such as IPLocks, Touchpoint, CPMi and Transactor/Brodia. He has been invited to present at dozens of security conferences, contributed articles to many major publications, and is easily recognizable by his "network hair" and propensity to wear loud colors.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights