Monitor TCP/IP access to Informix instance
Posted in 2008
Topics: Connectivity: ODBC / JDBC / .NET, Connectivity: ESQL/C, 4GL & Embedded SQL, Security, Permissions & Auditing, Networking & sqlhosts Configuration, Platform-Specific Issues
> Is there any way to monitor the TCP/IP access to an Informix Instance? > > I am running 9.4 on HP-UX and use TCP/IP for connecting to the > Informix instance. > The application is an Informix 4gl application and the application > code handles most of the security. > All users of the application have local ids and passwords on the Unix > server. > The issue I am facing is that we also allow ODBC access to the > instance for the various web applications > that are coming from a Windows IIS server. > So the auditors have correctly determined that a user could use ODBC > and some Windows client to gain access to the > Informix instance and completely bypass the application security. > I'd like to be able to have a log of all TCP/IP connections so that I > could monitor those that do not initiate from the server itself. > > I am also toying with the idea of adding the use of Informix roles to > the application and have the security dependent upon the role. > However I believe someone could still use ODBC and set the role to the > appropriate role and I'd still have the same issue. > > Any thoughts or ideas on this would be appreciated. > Thanks....Mick > >
On Wed, Jun 11, 2008 at 5:11 PM, Putillo, Mick J <MickPutillo@chevron.com> wrote: > > Is there any way to monitor the TCP/IP access to an Informix Instance? > > > > I am running 9.4 on HP-UX and use TCP/IP for connecting to the > > Informix instance. > > The application is an Informix 4gl application and the application > > code handles most of the security. > > All users of the application have local ids and passwords on the Unix > > server. > > The issue I am facing is that we also allow ODBC access to the > > instance for the various web applications > > that are coming from a Windows IIS server. > > So the auditors have correctly determined that a user could use ODBC > > and some Windows client to gain access to the > > Informix instance and completely bypass the application security. > > I'd like to be able to have a log of all TCP/IP connections so that I > > could monitor those that do not initiate from the server itself. > > > > I am also toying with the idea of adding the use of Informix roles to > > the application and have the security dependent upon the role. > > However I believe someone could still use ODBC and set the role to the > > appropriate role and I'd still have the same issue. > > > > Any thoughts or ideas on this would be appreciated. > > Thanks....Mick > > > > > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > Some thoughts... You have to check them and consider which ones would be useful: 1- By using a simple firewall you can restrict the TCP connections only from the application servers and from your 4GL server (I didn't understand if the 4GL is running on the same host as the database) 2- You can have different ports/IP addresses for your 4GL applications and for your Web Applications 3- You can use auditing to record each session created in the instance. Auditing is considered an "evil" tool due to performance impact, but it will impact performance accordingly to what you choose to audit 4- Making security based on roles will probably not solve your problem. This is what sometimes is considered security by obscurity. If your users have enough knowledge they can discover which roles they belong and set them. In Informix, currently, you can not have a role password (this could be provided only by the application) 5- If you decided to use roles, it would be better to use IDS v10+, because IDS 10 introduced the concept of "default role" which you don't have in 9.4 6- On IDS 11.10 another nice feature was introduced: sysdbopen() procedure. This is a normal stored procedure that is run at connect time. In it, you could check the hostname and raise an error if not from an authorized host, and you could also do some logging (an alternative to the audit sub-system) 7- Theoretically you could implement some mechanism, based on PAM (plugin authentication modules). With PAM you could do virtually anything in terms of authentication, but it can be a bit complex. If your particular case I think you'd be stuck due to a "problem" with the way IDS uses PAM: To my best knowledge the client hostname/address is not transmitted to the PAM interface, so if you want to limit connections based on it you would have problems. I would love to see this limitation removed... I have written an article about PAM in http://informix-technology.blogspot.com if you're interested in it. If you want to use PAM, you should upgrade, although PAM existing since 9.40.FC3 ( So, to summarize it, it really depends on what you want to do, what tools you may want to use and if upgrading is a possibility or not. Ask yourself a few questions before considering the above (an others that may be suggested to you): - Do you want to prevent unauthorized connections, or do you just want to have evidences of them? - Can you upgrade to a newer version? It may have some pains, but you'd benefit from the large number of improvements - Can you use a firewall? Regards, Fernando Nunes