1. Trang chủ
  2. » Công Nghệ Thông Tin

Lecture Database security and auditing - Protecting data integrity and accessibility - Chapter 9: Application Data Auditing

46 76 0

Đang tải... (xem toàn văn)

Tài liệu hạn chế xem trước, để xem đầy đủ mời bạn chọn Tải xuống

THÔNG TIN TÀI LIỆU

Thông tin cơ bản

Định dạng
Số trang 46
Dung lượng 712,83 KB

Các công cụ chuyển đổi và chỉnh sửa cho tài liệu này

Nội dung

Lecture Database security and auditing - Protecting data integrity and accessibility - Chapter 9: Auditing database activities presentation of content: Audit server activities with Microsoft SQL Server 2000, audit database activities using Microsoft SQL Profiler, use SQL Server for security auditing. Mời các bạn tham khảo.

Trang 1

Database Security and Auditing: Protecting Data Integrity and Accessibility

Chapter 9 Auditing Database Activities

Trang 2

• Use Oracle database activities

• Learn how to create DLL triggers with Oracle

• Audit database activities using Oracle

Trang 4

Using Oracle Database Activities

• Several types of activities:

against application tables

maintenance and administrative purposes

specific activity occurs

Trang 5

Creating DDL Triggers with Oracle

• Audit program provides:

• Database activities statements (in addition to DML):

Trang 6

Creating DDL Triggers with Oracle

(continued)

Trang 7

Example of LOGON and LOGOFF

Database Events

• Steps:

minutes

Trang 9

Auditing Code with Oracle

• Steps:

table

Trang 10

Auditing Database Activities with

Oracle

• Oracle provides mechanisms for auditing all:

• Two types of activities based on the type of SQL command statement used:

Trang 11

Auditing DDL Activities

• Use a SQL-based AUDIT command

• Verify auditing is on:

Trang 12

Auditing DDL Activities (continued)

Trang 13

DDL Activities Example 1

• Steps:

create a table

For ALTER and DELETE

Trang 14

DDL Activities Example 1 (continued)

• Steps (continued):

DBA_AUDIT_TRAIL table

to see auditing metadata

Trang 15

DDL Activities Example 1 (continued)

Trang 16

DDL Activities Example 1 (continued)

Trang 17

DDL Activities Example 2

• Steps:

the TABLE statement; ALTER, CREATE, and

DROP TABLE statements

Trang 19

DCL Activities Example (continued)

Trang 20

Example of Auditing User Activities

• Steps:

statement

DBA_AUDIT_TRAIL

Trang 21

Audit Trail File Destination

• Steps:

set parameter AUDIT_TRAIL to the value OS

Trang 22

Oracle Alert Log

• Audits database activities:

in the Alert log

done using a Windows or UNIX script

Trang 23

Oracle Alert Log (continued)

Trang 24

Oracle Alert Log (continued)

• Database activities (continued):

database is started

checkpoint time

sequences, as well as archiving times

Trang 25

Oracle Alert Log (continued)

Trang 26

Auditing Server Activity with Microsoft

Trang 27

Implementing SQL Profiler

• User interface for auditing events

• For each event you can audit:

Trang 28

Implementing SQL Profiler (continued)

Trang 29

Security Auditing with SQL Server

• Steps for setting security auditing level:

level

Trang 30

Security Auditing with SQL Server

(continued)

Trang 31

Security Auditing with SQL Server

(continued)

• Auditable events:

Trang 32

Security Auditing with SQL Server

Trang 33

Security Auditing with SQL Server

(continued)

• Auditable events (continued):

Trang 34

Security Auditing with SQL Server

(continued)

Trang 35

Security Auditing with SQL Server

(continued)

• New trace information:

to a database table

indefinitely

Trang 36

Security Auditing with SQL Server

(continued)

Trang 37

Security Auditing with SQL Server

(continued)

Trang 38

Security Auditing with SQL Server

(continued)

• Steps to add Login Change Password event

event classes

Trang 39

Security Auditing with SQL Server

(continued)

Trang 40

Data Definition Auditing

Trang 41

Data Definition Auditing (continued)

Trang 42

Database Auditing with SQL Server

Trang 43

Database Errors Auditing with SQL

Server

Trang 45

Summary (continued)

• Oracle provides the SQL AUDIT command: initialization parameter AUDIT_TRAIL

• NOAUDIT used to stop auditing

• DBA_AUDIT_TRAIL data dictionary view

• Oracle Alert Log:

Ngày đăng: 30/01/2020, 11:19

TỪ KHÓA LIÊN QUAN