Re: Auditing
Posted in 2009
Topics: Performance & Tuning, Server Administration, Security, Permissions & Auditing, Triggers, Constraints & Referential Integrity, Logging & Checkpoints
Fernandez Garcia, Domingo wrote: > Good Morning: > > > > I would like to audit some tables in my database and after reading the > "Informix Trusted Facility Guide" I understand that I can't choose the > tables I want to audit. The only way I have founded to do this is > auditing the access to all the tables. > > > > Is this correct? Is there any tool that allow us just to select the > table I want to audit? > > > > The working envirment is the following: > > OS: RHEL4 > > IBM Informix Dynamic Server Version 10.00.FC1 > > > > Thank you in advanced > > Domingo I would prefer to start this with a question: What do you want to see/check? I use the auditing facility in every instance I control. But I regularly have conversations with customers that "need" auditing and after some discussion we come to the conclusion that either they don't really need auditing or that the auditing facility cannot answer their needs. The auditing facility doesn't allow to specify the objects as you already found. You can specify the actions and the users. Triggers as Obnoxio mentioned can be a solution, but it really depends on who you want to audit, and what you want to audit. A DBA can easily get around triggers... Also, if you're trying to check SELECTs it's very easy to work around them... There are also some external auditing facilities (3rd party products) that can help you... If you audit all the tables you can easily filter them when creating auditing reports. The obvious problem in doing this is that if you activate auditing on some operations you can easily kill your database performance and at the same time generate and enormous amount of useless data... There are some functionalities that can also help you... LBAC, or Label Based Access Control, introduced in V11, can create security labels per row/column. This defines who can see which rows/columns the tables you specify... It's not auditing, but many times people want to verify that the users only see what they're allowed to see... And this permits us to configure exactly that. So it's useless to check if you simple can define it... Another option, IF you're not trying to audit SELECTs would be to use CDC (Change Data Capture, former Data Mirror). Support for it was introduced in 11.50.xC3. It allows you to define some tables and capture all the changes. It works by looking at the logical logs, so with no impact on the database (small impact on the database host). Then you can simple create audit trails or send the changes to other databases, messages queues etc. Finally, auditing is a hot topic nowadays, so I think we can hope for new functionality in future versions... This obviously won't solve your current problem, but that's what I think will happen... P.S.: Auditing facility hasn't changed between 10 and 11, but for some other options V11 could make a difference... If you can be more specific on your needs, please feel free to post again... I'll check it. Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
I want to register which users are doing changes in some of the tables (not in all of them) and what are the changes they have done. We had thought about to use triggers but we look for an easier solution. CDC (Change Data Capture) could be the solution we need. We will try to install 11.50 and to verify if CDC can be the solution. Thanks, -----Mensaje original----- De: informix-list-bounces@iiug.org [mailto:informix-list-bounces@iiug.org] En nombre de Fernando Nunes Enviado el: jueves, 23 de abril de 2009 23:35 Para: informix-list@iiug.org Asunto: Re: Auditing Fernandez Garcia, Domingo wrote: > Good Morning: > > > > I would like to audit some tables in my database and after reading the > "Informix Trusted Facility Guide" I understand that I can't choose the > tables I want to audit. The only way I have founded to do this is > auditing the access to all the tables. > > > > Is this correct? Is there any tool that allow us just to select the > table I want to audit? > > > > The working envirment is the following: > > OS: RHEL4 > > IBM Informix Dynamic Server Version 10.00.FC1 > > > > Thank you in advanced > > Domingo I would prefer to start this with a question: What do you want to see/check? I use the auditing facility in every instance I control. But I regularly have conversations with customers that "need" auditing and after some discussion we come to the conclusion that either they don't really need auditing or that the auditing facility cannot answer their needs. The auditing facility doesn't allow to specify the objects as you already found. You can specify the actions and the users. Triggers as Obnoxio mentioned can be a solution, but it really depends on who you want to audit, and what you want to audit. A DBA can easily get around triggers... Also, if you're trying to check SELECTs it's very easy to work around them... There are also some external auditing facilities (3rd party products) that can help you... If you audit all the tables you can easily filter them when creating auditing reports. The obvious problem in doing this is that if you activate auditing on some operations you can easily kill your database performance and at the same time generate and enormous amount of useless data... There are some functionalities that can also help you... LBAC, or Label Based Access Control, introduced in V11, can create security labels per row/column. This defines who can see which rows/columns the tables you specify... It's not auditing, but many times people want to verify that the users only see what they're allowed to see... And this permits us to configure exactly that. So it's useless to check if you simple can define it... Another option, IF you're not trying to audit SELECTs would be to use CDC (Change Data Capture, former Data Mirror). Support for it was introduced in 11.50.xC3. It allows you to define some tables and capture all the changes. It works by looking at the logical logs, so with no impact on the database (small impact on the database host). Then you can simple create audit trails or send the changes to other databases, messages queues etc. Finally, auditing is a hot topic nowadays, so I think we can hope for new functionality in future versions... This obviously won't solve your current problem, but that's what I think will happen... P.S.: Auditing facility hasn't changed between 10 and 11, but for some other options V11 could make a difference... If you can be more specific on your needs, please feel free to post again... I'll check it. Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... _______________________________________________ Informix-list mailing list Informix-list@iiug.org http://www.iiug.org/mailman/listinfo/informix-list
Fernandez Garcia, Domingo wrote: > I want to register which users are doing changes in some of the tables > (not in all of them) and what are the changes they have done. > > We had thought about to use triggers but we look for an easier solution. I remember Jacques Roy once wrote a very interesting article that would allow the use of the same function for implementing several triggers. The function used some extensibility functions to find out what table was involved. This could simplify the use of triggers for this purpose... Found it...: http://www.ibm.com/developerworks/data/library/techarticle/dm-0410roy > > CDC (Change Data Capture) could be the solution we need. We will try to > install 11.50 and to verify if CDC can be the solution. > It looks pretty good. I need time to play with it :) > Thanks, Regards > > > > -----Mensaje original----- > De: informix-list-bounces@iiug.org > [mailto:informix-list-bounces@iiug.org] En nombre de Fernando Nunes > Enviado el: jueves, 23 de abril de 2009 23:35 > Para: informix-list@iiug.org > Asunto: Re: Auditing > > Fernandez Garcia, Domingo wrote: >> Good Morning: >> >> >> >> I would like to audit some tables in my database and after reading the > >> "Informix Trusted Facility Guide" I understand that I can't choose the > >> tables I want to audit. The only way I have founded to do this is >> auditing the access to all the tables. >> >> >> >> Is this correct? Is there any tool that allow us just to select the >> table I want to audit? >> >> >> >> The working envirment is the following: >> >> OS: RHEL4 >> >> IBM Informix Dynamic Server Version 10.00.FC1 >> >> >> >> Thank you in advanced >> >> Domingo > > I would prefer to start this with a question: What do you want to > see/check? > I use the auditing facility in every instance I control. But I regularly > have > conversations with customers that "need" auditing and after some > discussion we > come to the conclusion that either they don't really need auditing or > that the > auditing facility cannot answer their needs. > > The auditing facility doesn't allow to specify the objects as you > already > found. You can specify the actions and the users. > > Triggers as Obnoxio mentioned can be a solution, but it really depends > on who > you want to audit, and what you want to audit. A DBA can easily get > around > triggers... Also, if you're trying to check SELECTs it's very easy to > work > around them... > > There are also some external auditing facilities (3rd party products) > that can > help you... > > If you audit all the tables you can easily filter them when creating > auditing > reports. The obvious problem in doing this is that if you activate > auditing on > some operations you can easily kill your database performance and at the > same > time generate and enormous amount of useless data... > > There are some functionalities that can also help you... LBAC, or Label > Based > Access Control, introduced in V11, can create security labels per > row/column. > This defines who can see which rows/columns the tables you specify... > It's not > auditing, but many times people want to verify that the users only see > what > they're allowed to see... And this permits us to configure exactly that. > So > it's useless to check if you simple can define it... > > Another option, IF you're not trying to audit SELECTs would be to use > CDC > (Change Data Capture, former Data Mirror). Support for it was introduced > in > 11.50.xC3. It allows you to define some tables and capture all the > changes. It > works by looking at the logical logs, so with no impact on the database > (small > impact on the database host). Then you can simple create audit trails or > send > the changes to other databases, messages queues etc. > > > Finally, auditing is a hot topic nowadays, so I think we can hope for > new > functionality in future versions... This obviously won't solve your > current > problem, but that's what I think will happen... > > P.S.: Auditing facility hasn't changed between 10 and 11, but for some > other > options V11 could make a difference... > > If you can be more specific on your needs, please feel free to post > again... > I'll check it. > Regards. > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
On Apr 24, 7:09 pm, Fernando Nunes <domusonl...@gmail.com> wrote: > Fernandez Garcia, Domingo wrote: > > I want to register which users are doing changes in some of the tables > > (not in all of them) and what are the changes they have done. > > > We had thought about to use triggers but we look for an easier solution. Guardium is one appliance that supports Informix and can even monitor DBA access on a shared memory connection, if that is a requirement.