Home > Oracle Database / Applications News > Oracle beefs up database security at Collaborate '06
Oracle Database / Applications News:
EMAIL THIS

Oracle beefs up database security at Collaborate '06

By Mark Brunelli, News Editor
27 Apr 2006 | SearchOracle.com

Oracle tips, scripts, and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

NASHVILLE – Oracle unveiled two new database security technologies at the Collaborate '06 conference this week. The company says that Oracle Database Vault and Oracle Secure Backup are designed to thwart internal threats and automate and encrypt disk-to-tape backups. SearchOracle.com sat down with Mark Townsend, Oracle's senior director of database product management, to find out more about what these technologies do and how much they cost.

What made Oracle decide to create Database Vault?

Mark Townsend: We're seeing a lot of interest from our customers around security and compliance and what they need to do to be compliant with Sarbox requirements. It's also things like HIPAA and individual countries have equivalencies. So we're seeing more and more people wanting to drive into a compliant environment for regulatory reasons. A big part of that is actually ensuring privacy of the data and a part of that is making sure you eliminate the threat of insider access to data.

Are you saying that Database Vault is designed to protect against malicious company insiders?

Townsend: I guess it [does cover malicious company insiders] but we don't really attribute a lot of maliciousness to [insiders]. But if a DBA knows what your company's [financial] results are before you announce them, that's not a good place to be.

What exactly does Database Vault do?

Townsend: Database Vault is security technology that you can add to the database that allows you to come in and create what we call security realms. Security realms are basically a way of sandboxing off a database or parts of the database so that you can specifically control who has access. You can come in and say [that these particular] DBAs can come in and back up the database, but they can't actually see the data that is stored within this database. You can also do other things such as associate rules. You can say that end users have access to this data during these hours of the days from machines with these IP addresses. But if one of those end users tries to access this data outside of their working hours or from a different machine or maybe from a machine at home, then the Database Vault technology will actually step in and stop them from accessing. So it allows us to do that separation of duty, it allows us to build in the application rules, and the useful thing about it is that it is completely transparent to existing applications.

On which platforms can DBAs run Database Vault?

Townsend: It's going to be available on Linux within the next 30 days and it will follow on the other platforms in the first half of the fiscal year 2007. It will actually come out as an option to Oracle Database 10g release 2. It will be on the same version release train as the database going forward.

How much does Database Vault cost and what other requirements do users need to know about?

Townsend: The pricing is being set at $20,000 per [central processing unit]. The basic requirement is that you have to be on 10g release 2. There is an update to 10g release 2 that will ship in a little while that will include the Database Vault option.

More from Collaborate '06:

Special Report: Oracle enterprise apps

IOUG: Linux to be top platform for Oracle by next year

What is Oracle Secure Backup?

Townsend: In Oracle Database 10g release 1, we automated disk-to-disk backup. In 10g release 2, we made that disk-to-disk backup highly secure, [and now] we're announcing Oracle Secure Backup. Out of the box Oracle Secure Backup provides disk to tape backup. It's fully integrated with the database. You use it with your existing backup tools that Oracle provides. It's available on Linux, Unix and Windows, and it talks to over 200 different tape devices and media management systems. Just in the same way as you can automate disk-to-disk, you can also automate disk-to-tape now too.

How do IT pros usually handle disk-to-tape backup?

Townsend: People are doing this already and often they'll use third party products [from Veritas, Legato and others]. We continue to work with those third party customers.

We've discussed the "Backup" portion of the new software. What about the "Secure" part?

Townsend: The secure part of that is that we also encrypt those tapes as they are created as well too. The reason that we're doing this is that typically people want to send these tapes offsite for escrow purposes or whatever. If somebody loses them or leaves them on a train, if people capture that tape they can't possibly restore it to a database of their own.

Industry analysts have said that Advanced Technology Attachment (ATA) drives are making a comeback. Do you see this happening in the marketplace?

Townsend: ATAs are definitely making a comeback. ATA drives are a fantastic target for disk backup because they are low cost. We're also seeing a lot of ATA storage starting to come into online databases because more people are keeping data around then taking it offline and archiving it in a separate environment.

How much does Oracle Secure Backup cost?

Townsend: The pricing is a little bit interesting. For customers with a single database doing a single backup, the product is actually free. When you start stepping up into the enterprise class, where you have multiple databases maybe backed up to multiple tape drives across the network, then we're charging $3,000 per tape drive.

Tags: Oracle database installation, upgrades and patchesOracle database securityOracle RAC and database clusteringOracle database performance problems and tuningOracle database export, import and migrationOracle error messagesOracle database design and architectureOracle database backup and recoveryOracle database availabilityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Oracle database installation, upgrades and patches
Oracle's Java database continues push into embedded database market
How to use the Oracle Database Upgrade Assistant (DBUA)
Oracle delivers database fixes in Critical Patch Update
How to get the most out of Toad for Oracle 10
Coca-Cola Bottling swaps out Oracle for DB2
Oracle renews push into embedded open source software market
Oracle releases new database, says 11g upgrade will cut costs
Comparing servers for Oracle database 11g upgrades
Choosing the right server hardware is all about choosing the right software
The best of the Oracle 11g-ready servers

Oracle database security
Oracle delivers database fixes in Critical Patch Update
How to use DBMS_CRYPTO package for Oracle password encryption/hashing
How to decrypt an Oracle password using John the Ripper and checkpwd
How to use the CREATE SESSION command to track Oracle database logins
How to troubleshoot Oracle critical patch updates using OPatch
Can I automate Oracle patching when installing Oracle Standard Edition?
Is it possible to automate Oracle CPUs for a DoD project?
Three steps to help improve Oracle database security
Tips for auditing and securing database backups in Oracle
How to prevent a SQL injection attack in Oracle

Oracle RAC and database clustering
Can I have a single Oracle 11g RAC instance across multiple databases?
Review: Oracle's 11g R2 database has some good and bad
Scaling an Oracle database: What is the best strategy for you?
Oracle releases new database, says 11g upgrade will cut costs
E-discovery firm swaps out Microsoft SQL for Oracle RAC
Firm dumps MySQL on Red Hat for Oracle Database on Oracle Linux
How to back up archive log files in RAC
eHarmony spurns Microsoft, finds match with Oracle 10g
How to back up RAC database with RMAN
Using connection load balancing with Oracle RAC

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
10g  (SearchOracle.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Oracle News, Oracle Training, Oracle Management
HomeNewsTopicsTipsAsk the ExpertsMultimediaWhite PapersProductsBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts