Enterprise Linux Log

Oct 28 2008   7:33PM GMT

SE-Postgres tightens SQL security



Posted by: Caroline Hunter
Security, Linux, PostGreSQL, DataManagement, Administration, interoperability and integration

This post was contributed by Joshua Kramer. For more information about Kramer, go to the EnterpriseLinuxLog About the Editors page.

In the theater of IT operations, security has moved to center stage. Attacks have become more complex, and legislative bodies have passed laws that require data protection. In just the past year, Nevada and Massachusetts introduced legislation requiring that consumer data be protected. 

 In 2006, Oracle introduced its Audit Vault, which purported to restrict access to data even from database management administrators. This kind of tool is extremely valuable in the fight against those trying to steal personal information.  

In early 2009, another player will offer a similar — and perhaps more secure — way to restrict data access As part of its yearly feature update, the PostgreSQL group plans to implement a module called SE-Postgres in the database core. This module inherits security rules and contexts from the SELinux rule set of the host OS to control access to tables, individual rows of data and even individual columns. Currently SE-Postgres is available as a patch to the Postgres 8.3 database (for those who don’t mind compiling source code). 

This inheritance of rules applies to all facets of SELinux and therefore gives you power beyond simply restricting access by role. When SE-Postgres is configured properly, a client’s SELinux context is propagated to all data it touches. For example, rows inserted by a subject with SystemHigh privileges will carry the Secret label. A query submitted by a subject with user_t privileges will not return rows that have such a label. For the most part, referential integrity is preserved; a table join will fail if one of the objects required in a table is disallowed by SELinux context. There are a few minor exceptions, but those will be closed as the project progresses.

Comment on this Post


You must be logged-in to post a comment. Log-in/Register

Outlet  |   Apr 12 2011   3:59AM GMT

The most stylish and high quality Louis Vuitton is the best seller now. If you want to buy Louis Vuitton,just come to our Louis Vuitton Outlet Store, the best Louis Vuitton and the good service we would supply you. Cheap Louis Vuitton for sale now! Back to Louis Vuitton Outlet and choose the Louis Vuitton you prefer.
Every nobby woman all hope to have a world famous brand goods.Louis Vuitton items of Louis Vuitton Outlet Online is one best choice for you. These new design Louis Vuitton that come in unique styles. It is easy to see that Louis Vuitton Online store listed in our Louis Vuitton online that you can find the luxury Louis Vuitton products.


 

Outlet  |   Apr 12 2011   4:01AM GMT

Swarovski crystals are well-known for its fine quality.Recently our Swarovski online store offers wide varieties of Swarovski crystal,expecially Swarovski beads.If you have a desire to buy any beads on sale,catch the chance and action now.


 

Coach01outlet  |   Feb 17 2012   4:52AM GMT

http://www.coachoutlets.org.uk