Home > Security News > Black Hat 2007: New database forensics tool could aid data breach cases
Security News:
EMAIL THIS

Black Hat 2007: New database forensics tool could aid data breach cases

By Robert Westervelt, News Editor
02 Aug 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

LAS VEGAS -- A new database forensics tool being developed by database security guru David Litchfield could help data breach investigators build evidence against attackers.

There are tools that allow you to fudge your way through, but by running them you can change a system in a drastic way.
David Litchfield,
managing director, NGS Software

Litchfield, managing director at UK-based NGS (Next Generation Security) Software Ltd. plans to release the Forensic Examiners Database Scalpel. The new tool is designed for Oracle database management systems and automates the process of sifting through mountains of system metadata to discover the cause and extent of a data security breach.

In his presentation at the Black Hat USA 2007 Briefings in Las Vegas, Litchfield, called for further research in the area of database forensics. Litchfield, who has focused his research on Oracle database security, said he has been conducting forensics research on Oracle 10g database management system for about six months.

"We've seen database breaches occurring all the time and we need to see how they are occurring," he said.

Litchfield said he has a legal hurdle to overcome with Oracle Corp., since the tool uses some of Oracle's proprietary algorithms. The new tool would be the first of its kind once it is released, he said. There are no database specific forensic analysis tools on the market.

"There are tools that allow you to ascertain a compromise or not, but by running those tools, you could compromise evidence," Litchfield said. "There are tools that allow you to fudge your way through, but by running them you can change a system in a drastic way."

Litchfield said that investigators examine redo logs, data files and Apache logs to follow the patch of a hacker.

The process of examining metadata and statistics could yield evidence of the creation of foreign database objects and database row deletions. Investigators can find hidden clues that reveal the path a hacker took and build a case using the information.

Database forensics:
Digital forensics tool Helix 'does no harm' Forensics isn't just for the scientists. This month, contributor Scott Sidel recommends Helix, a digital forensics tool that can do some important detective work on your system.

Forensics: Electronic evidence makes its mark in investigations Computer forensics offers a surprising amount of help to investigators.

"An attacker may go around creating objects and then go and attempt to clean up and hide evidence," Litchfield said.

But often, hidden deep within an Oracle data block, hackers leave traces of their past presence. The header and row directory in a data block correspond to areas within a database that can yield revealing clues, Litchfield said.

Litchfield said that forensic analysis conducted by investigators should always be done in the presence of the database administrator, who should be able to recognize problems.

A database administrator who attended Litchfield's presentation, wished to remain anonymous, but said the new tool is vital to conducting forensics research on specific data blocks. Without the tool, the work is too time consuming, he said.

"A tool like this could make a difference," he said. "There are ways to conduct an analysis with other tools, but they can alter tables and possibly damage evidence."

In recent years, database-related news at Black Hat has been dominated by Litchfield. He has focused on flaws in Oracle databases, though last year he focused instead on flaws in IBM's Informix family of database products.



Tags: Database Security ManagementData Privacy and ProtectionIdentity Theft and Data Security BreachesPCI Data Security StandardIT Security AuditsInformation Security Laws, Investigations and EthicsIdentity Theft and Data Security BreachesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Database Security Management
Oracle to buy Sun Microsystems for $7.4 billion
Oracle issues 43 updates, fixes serious database flaws
Information security book excerpts and reviews
Kaspersky website hacked multiple times, expert says
Kaspersky website hacked, customer activation codes exposed
SQL injection attacks targeting Flash, JavaScript errors
Fuzzing tool helps Oracle DBAs defend against SQL injection
Oracle extends Audit Vault third-party database compatibility
When should a database application be placed in a DMZ?
Oracle patches dangerous WebLogic, Secure Backup vulnerabilities
Database Security Management Research

Data Privacy and Protection
How to write a risk methodology that blends business, security needs
PCI compliance requirement 3: Protect data
Mass. Senate seeks to amend, weaken data breach notification law
Bruce Schneier and Marcus Ranum Face-Off: Should We Have an Expectation of Online Privacy?
Kodak CISO on virtualization, compliance
Federal efforts to secure cyberinfrastrucure
Attackers cash in on fundamental data handling mistakes, Verizon finds
RSA panel to discuss surveillance, privacy concerns
Mass. officials explain new data protection regulations
HIPAA changes force healthcare to improve data flow
Data Privacy and Protection Research

Identity Theft and Data Security Breaches
How to prevent and build protection against online identity theft
Heartland breach highlights PCI limitations
FBI investigates coordinated ATM scam
Encrypt now to meet new Mass. data protection law
Recovery plans essential for preventing data loss disasters
Internal auditors and CISOs mitigate similar risks
Cybersecurity expert sees PCI DSS problems ahead for retailers
PCI is about eliminating data, not securing it, former QSA says
Data breach discovery, disclosure outpaces 2007
PCI groups to focus on wireless, pre-authorization changes
Identity Theft and Data Security Breaches Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
data encryption/decryption IC  (SearchSecurity.com)
International Data Encryption Algorithm  (SearchSecurity.com)
link encryption  (SearchSecurity.com)
MD2  (SearchSecurity.com)
MD4  (SearchSecurity.com)
MD5  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts