Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • Networking
    • Storage

    Oracle Beefs Up Database Firewall With SQL Injection Defenses, MySQL

    Written by

    Fahmida Y. Rashid
    Published January 9, 2012
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Oracle has updated its Oracle Database Firewall product to improve enterprise database security and help enterprises block both malicious insiders and SQL injection attacks from gaining access to the data.

      The new release of Oracle Database Firewall introduces support for MySQL Enterprise Edition and other reporting capabilities, Oracle said Jan. 9. The database firewall protects MySQL databases from data breaches without requiring the administrator to make any changes to the database infrastructure or to the underlying operating system running the database, Vipin Samar, vice president of database security at Oracle, told eWEEK. Developers also won’t have to modify existing applications to take advantage of the SQL injection defense capabilities, he said.

      With MySQL support, the database firewall now supports Oracle’s own flagship product, Database 11g and earlier versions, as well as IBM DB2, Linux, Unix, Windows, Microsoft SQL Server, Sybase Adaptive Server Enterprise and Sybase SQL Anywhere. Many enterprises use MySQL extensively for their database operations and Oracle added support for the open-source database due to customer demand, Samar said.

      “With new MySQL support, Oracle Database Firewall extends the combination of databases that organizations can secure across their enterprise,” said Samar.

      The Oracle Database Firewall establishes a “defensive perimeter” around databases, which would help administrators address threats such as SQL injection attacks, according to Samar. SQL injection attacks are commonly used by attackers exploiting a vulnerability in Web applications to access and extract data from a database. It is often used by submitting a malicious query in a form in the application, such as a comment box, which tricks the database into executing the query.

      The grammar-based analytical engine compares the SQL queries being submitted with the queries it knows are within the parameters of “normal application behavior” to identify any anomalies, Samar said. When the application sends a suspicious SQL query to the database, the firewall can block the query entirely, substitute it with a harmless query for the database to execute or just log it, depending on the severity, said Samar. The firewall can also issue alerts to administrators when necessary.

      If the application is designed to obtain records from the customer table in the database, any query trying to get data from another table is automatically suspicious and can be stopped, Roxana Bradescu, senior director of security product management at Oracle, told eWEEK. Malicious queries, such as one that orders the elimination of entire data tables can be automatically blocked, Bradescu said.

      In a recent Independent Oracle Users Group survey, only 36 percent of respondents said that they have taken steps to ensure their applications are not susceptible to SQL injection attacks, according to Bradescu.

      The firewall monitors application behavior in real time to help prevent both SQL injection attacks as well as unauthorized attempts internally to access data, Samar said.

      Oracle Database Firewall is also integrated with Oracle Advanced Security, which allows administrators to monitor all encrypted traffic going to the database for any potential threats.

      The new reporting infrastructure in the firewall will help organizations address various regulatory compliance requirements, according to Samar. The new version has 10 new out-of-the-box reports specifically addressing privacy and regulatory mandates such as the Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry (PCI) Data Security Standard (DSS) and Sarbanes Oxley. Oracle Business Intelligence Publisher customers can take advantage of all capabilities for authoring, managing and delivering highly formatted reports, the company said.

      MySQL joined Oracle’s product portfolio when the database giant closed on its $7.4 billion deal for Sun Microsystems in January 2010. Sun originally acquired MySQL AB, the development team behind the open-source database, for approximately $1 billion in 2008.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.