Home > Security News > Black Hat 2007: New database forensics tool could aid data breach cases
Security News:
EMAIL THIS

Black Hat 2007: New database forensics tool could aid data breach cases

By Robert Westervelt, News Editor
02 Aug 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

LAS VEGAS -- A new database forensics tool being developed by database security guru David Litchfield could help data breach investigators build evidence against attackers.

There are tools that allow you to fudge your way through, but by running them you can change a system in a drastic way.
David Litchfield,
managing director, NGS Software

Litchfield, managing director at UK-based NGS (Next Generation Security) Software Ltd. plans to release the Forensic Examiners Database Scalpel. The new tool is designed for Oracle database management systems and automates the process of sifting through mountains of system metadata to discover the cause and extent of a data security breach.

In his presentation at the Black Hat USA 2007 Briefings in Las Vegas, Litchfield, called for further research in the area of database forensics. Litchfield, who has focused his research on Oracle database security, said he has been conducting forensics research on Oracle 10g database management system for about six months.

"We've seen database breaches occurring all the time and we need to see how they are occurring," he said.

Litchfield said he has a legal hurdle to overcome with Oracle Corp., since the tool uses some of Oracle's proprietary algorithms. The new tool would be the first of its kind once it is released, he said. There are no database specific forensic analysis tools on the market.

"There are tools that allow you to ascertain a compromise or not, but by running those tools, you could compromise evidence," Litchfield said. "There are tools that allow you to fudge your way through, but by running them you can change a system in a drastic way."

Litchfield said that investigators examine redo logs, data files and Apache logs to follow the patch of a hacker.

The process of examining metadata and statistics could yield evidence of the creation of foreign database objects and database row deletions. Investigators can find hidden clues that reveal the path a hacker took and build a case using the information.

Database forensics:
Digital forensics tool Helix 'does no harm' Forensics isn't just for the scientists. This month, contributor Scott Sidel recommends Helix, a digital forensics tool that can do some important detective work on your system.

Forensics: Electronic evidence makes its mark in investigations Computer forensics offers a surprising amount of help to investigators.

"An attacker may go around creating objects and then go and attempt to clean up and hide evidence," Litchfield said.

But often, hidden deep within an Oracle data block, hackers leave traces of their past presence. The header and row directory in a data block correspond to areas within a database that can yield revealing clues, Litchfield said.

Litchfield said that forensic analysis conducted by investigators should always be done in the presence of the database administrator, who should be able to recognize problems.

A database administrator who attended Litchfield's presentation, wished to remain anonymous, but said the new tool is vital to conducting forensics research on specific data blocks. Without the tool, the work is too time consuming, he said.

"A tool like this could make a difference," he said. "There are ways to conduct an analysis with other tools, but they can alter tables and possibly damage evidence."

In recent years, database-related news at Black Hat has been dominated by Litchfield. He has focused on flaws in Oracle databases, though last year he focused instead on flaws in IBM's Informix family of database products.



Tags: Database Security ManagementData Privacy and ProtectionPCI Data Security StandardIT Security AuditsInformation Security Laws, Investigations and EthicsIdentity Theft and Data Security BreachesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Database Security Management
Basic Database Security: Step by Step
Database activity monitoring lacks security lift
Information security book excerpts and reviews
IBM to acquire database security firm Guardium
What is the best database patch management process?
Is credit card tokenization a better option than encryption?
Will a database anonymization implementation succeed?
Unpatched vulnerability discovered in Microsoft SQL Server
SQL injection continues to trouble firms, lead to breaches
Oracle issues quarterly patches, fixes database flaws
Database Security Management Research

Data Privacy and Protection
New data protection laws
MA 201 CMR 17 enforcement less likely with prompt reporting, cooperation
Information security book excerpts and reviews
Quiz: Compliance-driven role management
Interpreting 'risk' in the Massachusetts data protection law
Strategies for using technology to enable automated compliance
How to prepare for a FERPA audit
How to find virtual machines for greater virtualization compliance
Quiz: Virtualization and compliance
Compliance in the cloud
Data Privacy and Protection Research

PCI Data Security Standard
New data protection laws
No major PCI DSS revision expected in 2010
PCI QSAs, certifications to get new scrutiny
The future of PCI DSS encryption requirements? Tokenization for PCI
MasterCard reverses PCI compliance requirement
PCI DSS compliance help: Using frameworks, technology to aid efforts
Chip and PIN adoption
Chip and PIN adoption serves lesson for U.S. payment industry
Heartland CIO is critical of First Data's credit card tokenization plan
Heartland CIO on end-to-end encryption, credit card tokenization

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
data encryption/decryption IC  (SearchSecurity.com)
International Data Encryption Algorithm  (SearchSecurity.com)
link encryption  (SearchSecurity.com)
MD2  (SearchSecurity.com)
MD4  (SearchSecurity.com)
MD5  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts