oracle security peoug09 - peoug - peru oracle users group · oracle security options (based on...

49
ORACLE SECURITY OPTIONS PEOUG’ 2009 2009 Lima, Peru By: Francisco Munoz Alvarez

Upload: others

Post on 23-Aug-2020

19 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

ORACLE SECURITY OPTIONSPEOUG’ 20092009 Lima, Peru

By:

Francisco Munoz Alvarez

Page 2: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

ORACLE SECURITY OPTIONS(Based on Oracle EMEA Security Workshop)

Francisco Munoz Alvarez

Oracle ACE Director

President CLOUG, LAOUC & NZOUG

8/9/10g/11g OCP, RAC OCE, AS OCA, E-Business OCP, SQL/PLSQL OCA, Oracle 7 OCM

Oracle 7 & 11GR2 Beta Tester

ITIL Certified

Blog: www.oraclenz.com - Email: [email protected] – Twitter : fcomunoz

Blog: www.oracleenespanol.com - Comunidad Oracle: www.oraclemania.ning.com

CEO at DBIS ™

Database Integrated Solutions www.dbisonline.com

www.dbis.co.nz

Page 3: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

Information Security Has Changed

Page 4: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

Hacking Steps

Page 5: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

OFFICIAL STATISTICS

from Secret Service Germany

Page 6: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

COMPUTER CRIME DEVELOPMENT

Page 7: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

SOME SHORT FACTS

Page 8: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

HIGH SCORE LIST

Page 9: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

2007/2008 SHOPPING LIST

Page 10: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

CRISIS SHOPPING LIST 2009

Page 11: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

HACKING METHODS AND TECHNIQUES

Page 12: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

INSIDER ATTACKS EXAMPLES

European Headlines 2008

Page 13: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

THE INSIDER THREAT

Page 14: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

OFFICIAL STATISTICS

EXTERNAL/INTERNAL THREAT

Page 15: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

CONCLUSION

Page 16: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

Oracle Security Solutions

Page 17: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

Oracle Security Components

Page 18: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

DB ENVIRONMENT

Page 19: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

Security Data in Rest/Access Control

Page 20: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

WHAT IS ASO?

Page 21: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

What Security Problems does ASO

solve?

Page 22: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

ASO BENEFITS

Page 23: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

TDE – Transparent Data Encryption

Page 24: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

TDE – Transparent Data Encryption

Page 25: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

TDE – Transparent Data Encryption

Page 26: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

SECURING DATA IN MOTION

Page 27: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

NETWORK ENCRYPTION

Page 28: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

SECURING BACKUP

Page 29: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

SECURING BACKUP

Examples

Page 30: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

DATAMASKING

Page 31: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

WHAT IS DATAMASKING?

Page 32: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

PREVENT MODIFICATIONS BY

UNAUTHORIZED USERS

Page 33: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

WHAT IS DATA VAULT?

Page 34: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

DATA VAULT HELP TO SOLVE:

Page 35: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

DATA VAULT Vs

VPD and OLS

Page 36: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

DATABASE VAULT Realms and Rule

Page 37: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

DATA VAULT REPORTS

Page 38: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

DATA VAULT EXAMPLES

Page 39: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

HIGHLY SECURED ENVIROMENTS

AUDIT VALT

Page 40: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

AUDIT VAULT EXAMPLES

Page 41: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

AUDIT VAULT REPORTS

Who, What, When, Where

Page 42: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

AUDIT VAULT DASHBOARD

Page 43: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

AUDIT VAULT SUMMARY

Page 44: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

PROGRAM

The Oracle ACE Program is designed to recognize and reward members of theOracle Technology and Applications communities for their contributions to thosecommunities. These individuals are technically proficient (when applicable) andwillingly share their knowledge and experiences.

The program comprises two levels: Oracle ACE and Oracle ACE Director.

The former designation is Oracle's way of saying "thank you" to communitycontributors for their efforts; we (and the community) appreciate theirenthusiasm. The latter designation is for community enthusiasts who not onlyshare their knowledge (usually in extraordinary ways), but also want to increasetheir community advocacy and work more proactively with Oracle to findopportunities for the same. In this sense, Oracle ACE is "backward looking" andOracle ACE Director is "forward looking."

Page 45: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

PROGRAM

Page 46: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

PROGRAM

Page 47: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

PROGRAM

Page 48: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

Questions?

Page 49: Oracle Security PEOUG09 - PEOUG - PERU Oracle Users Group · ORACLE SECURITY OPTIONS (Based on Oracle EMEA Security Workshop) Francisco Munoz Alvarez Oracle ACE Director President

Thank you !