Response to Security Request for Comments
Posted in 1991
REFERENCE: >From: chan@aim1.UUCP (Neville Chamberlain) >Keywords: database security informix >Message-ID: <53@aim1.UUCP> >Date: 15 Oct 91 05:39:11 GMT >Organization: Aztec Information Management > >Here's an interesting scenario: A retail chain are installing >a number of Unix systems at their branches to handle point of >sale, ordering, etc. Among other things, the systems will >contain confidential information ...... > >THUS: How to protect the confidential information on the systems? > >The following suggestions have been made: > >a) Enforce strict security and auditing on the systems. This will > warn of unauthorised accesses, file opens, etc. Nice but always > too late. > >b) Modify all reads and writes to the relevant tables to encrypt and > decrypt the data before it is written/after it is read. Means > that the application programs (already in existence) have to > be modified. > >c) Ignore the problem. The people at the branch outlets are not > programmers or Unix experts, either of which is required to > get to the data. > >d) Encrypt/decrypt the relevant tables after and before use. This > means that while certain applications are running, the info > is "freely" available. > >e) Combinations of the above. > >Any help/suggestions appreciated! I will summarise if there is >enough interest. > >-- >............................................................. >Neville Chamberlain :Tel: +27 (21) 419-2690 >Aztec Information Management :Fax: +27 (21) 21-1040 >chan@aim1.UUCP Since security by ignorace (c) has been suggested...maybe my suggestion will not be laughed at. This gets away from informix information, but is a valid question that needs to be answered when talking about security on a UNIX system that will be "out in the field" so to speak. Suggest: If the data is separate from the application database: Create a separate partition on the system for the confidential data. Leave the partition unmounted. Your average unix user would never realize the partition existed. Your local "root" administrator may have limited knowledge and may need to know the partition is there. However they would not have to know about the unmounted partition. Programs could be supplied that would mount, access, then unmount the files and they would never know anything about it. It would be necessary to document the partition in the system administrator's documentation in case of system failure. Whenever the data is needed, either by a cron process running as root or from a login with root capability the partition could be mounted, accessed, then unmounted when the task was complete. It could also be mounted for backup. But... If the confidential data is held within the application's database instead of being on a separate partition then the UNIX permissions could be set to 000 until time to allow a valid access to the information. Thru a cron program permissions could then be changed to allow a program to access the data. (Speaking here of "Informix as we know it" at 2.10 where we can "see" the table files inside the database.dbs directory). Don't believe this is be possible under later versions. Cheryl Gross cheryl@redriverad-emh1.army.mil