informix security
Posted in 2017
A user running Informix 11.70 asked how best to track what users do to his database — native Informix auditing (onaudit), Server Studio/Sentinel, or Guardium. Replies pointed to the IBM auditing tech note and Ben's onaudit blog post, and noted onaudit's limits: it logs connects, utility use and that a table/row was changed, but not the actual values changed, so triggers and schema snapshots may be needed. Others warned that auditing "everything" (even with Guardium) generates enormous volumes of data, and urged narrowing the requirement with the security officer. No single tool choice was settled on; 11.70's selective row auditing was suggested as a good fit.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Stored Procedures & SPL, Security, Permissions & Auditing
Hi to All i need to put in place a security mecanism to see what my users do on my database (data first but system also), i know there are the folowing means and i would like your advices, what to choose : - informix auditing (with developping a small web app to display the audit logs containt) - server studio with sentinel (sentinel can - Gardium any links and docs a welcome:) Thanks in advance
Hi Smith,You can use the Informix Auditing feature.http://www-01.ibm.com/support/docview.wss?uid=swg21067407Thanks,LloydFro m: "SMITH JOHN" <srafik0358@gmail.com>Sent: Tue, 07 Mar 2017 14:44:17To: ids@iiug.orgSubject: informix security [38715]Hi to Alli need to put in place a security mecanism to see what my users do on mydatabase (data first but system also), i know there are the folowing means andi would like your advices, what to choose : - informix auditing (with developping a small web app to display the auditlogs containt)- server studio with sentinel (sentinel can- Gardiumany links and docs a welcome:)Thanks in advance************************************************************************* ****** Forum Note: Use "Reply" to post a response in the discussion forum.
My considered opinion (and no offence intended to the developers) is that Informix auditing is like tits on a bull: you kind of know why its there, but its of no earthly use to man or beast. Unless you get aroused by a bulls nipples, of course, but then youre just weird. The granularity of Informix auditing is really of extremely limited use. As someone who has done the odd security implementation (including using Informix auditing), my first question is: Why are you trying to do this? Then: What do you want the output to look like? Who is this for? How will you know if its successful? What version of Informix are you using? And finally, for those of us who have been here for a while: Have you tried using UPDATE STATISTICS? :-) > On 7 Mar 2017, at 11:53, Lloyd S <lloyd_s@rediffmail.com> wrote: > > Hi Smith,You can use the Informix Auditing > feature.http://www-01.ibm.com/support/docview.wss?uid=swg21067407Thanks,LloydFro m: > "SMITH JOHN" <srafik0358@gmail.com>Sent: Tue, 07 Mar 2017 > 14:44:17To: ids@iiug.orgSubject: informix security [38715]Hi to Alli need to > put in place a security mecanism to see what my users do on mydatabase (data > first but system also), i know there are the folowing means andi would like > your advices, what to choose : - informix auditing (with developping a > small web app to display the auditlogs containt)- server studio with sentinel > (sentinel can- Gardiumany links and docs a welcome:)Thanks in > advance************************************************************************* ****** Forum > Note: Use "Reply" to post a response in the discussion forum. > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
Informix Auditing is simple to implement, and there's info out there on how
to do this, but there are some limitations which you should be aware of.
Here's a start: http://www-01.ibm.com/support/docview.wss?uid=swg21067407
Or Ben's blog here:
https://informixdba.wordpress.com/2015/07/21/auditing-and-onaudit/
It will not track system events, if you are talking UNIX events (at least in
newer versions of Informix), but it can record that somebody ran onparams,
onspaces, even onstat, etc. It can record database connects and
disconnects. But although it will record that a table was altered, when and
by whom, it won't tell you what was changed. It can record that a row was
updated, but it won't tell you what was updated on that row. So, Informix
auditing may need to be supplemented with other mechanisms to record more
detail on changes - regular schema outputs and triggers on important tables
to record historical data changes, etc.
Mike
-----Original Message-----
From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of SMITH
JOHN
Sent: Tuesday, March 07, 2017 2:14 AM
To: ids@iiug.org
Subject: informix security [38715]
Hi to All
i need to put in place a security mecanism to see what my users do on my
database (data first but system also), i know there are the folowing means
and i would like your advices, what to choose :
- informix auditing (with developping a small web app to display the audit
logs containt)
- server studio with sentinel (sentinel can
- Gardium
any links and docs a welcome:)
Thanks in advance
****************************************************************************
***
Forum Note: Use "Reply" to post a response in the discussion forum.
Loved your mail. But my objections are much more about the generated data then really about the granularity (from 11.70+) Regards. On Tue, Mar 7, 2017 at 12:52 PM, Spokey Wheeler <spokey.wheeler@gmail.com> wrote: > My considered opinion (and no offence intended to the developers) is that > Informix auditing is like tits on a bull: you kind of know why its there, > but > its of no earthly use to man or beast. > > Unless you get aroused by a bulls nipples, of course, but then youre just > weird. > > The granularity of Informix auditing is really of extremely limited use. > > As someone who has done the odd security implementation (including using > Informix auditing), my first question is: > > Why are you trying to do this? > > Then: > > What do you want the output to look like? > > Who is this for? > > How will you know if its successful? > > What version of Informix are you using? > > And finally, for those of us who have been here for a while: > > Have you tried using UPDATE STATISTICS? :-) > > > On 7 Mar 2017, at 11:53, Lloyd S <lloyd_s@rediffmail.com> wrote: > > > > Hi Smith,You can use the Informix Auditing > > > feature.http://www-01.ibm.com/support/docview.wss?uid= > swg21067407Thanks,LloydFrom: > > "SMITH JOHN" <srafik0358@gmail.com>Sent: Tue, 07 Mar > 2017 > > 14:44:17To: ids@iiug.orgSubject: informix security [38715]Hi to Alli > need to > > put in place a security mecanism to see what my users do on mydatabase > (data > > first but system also), i know there are the folowing means andi would > like > > your advices, what to choose : - informix auditing (with > developping a > > small web app to display the auditlogs containt)- server studio with > sentinel > > (sentinel can- Gardiumany links and docs a welcome:)Thanks in > > > advance***************************************************** > ************************** Forum > > Note: Use "Reply" to post a response in the discussion > forum. > > > > > > > ************************************************************ > ******************* > > Forum Note: Use "Reply" to post a response in the discussion forum. > > > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --94eb2c054604af4b82054a288073
Hello I liked your answer, thank you, so here are some answers Why are you trying to do this? -> I want to know did what on the database, especially the data. What do you want the output to look like? -> doesn't matter, text files will also be good :) and could be used in a script. Who is this for? -> IT Manager and IT Security officer How will you know if its successful? -> good question, i guess if it is a problem the errors will be found in log files (online.log), i think also that we cannot neither know if it successful with other tools, isn't it ? What version of Informix are you using? --> 11.70 regards
On Tue, Mar 7, 2017 at 7:46 PM, SMITH JOHN <srafik0358@gmail.com> wrote: > Hello > > I liked your answer, thank you, so here are some answers > > Why are you trying to do this? > > -> I want to know did what on the database, especially the data. > This is the typical and expected answer. The only problem is that it isn't feasible. Before I'm "attacked" let me explain: To answer that question in a generic way, you'd be generating (much) more data that your database. And this is generally not acceptable. You'll have to find a way to reduce the scope. Either by reducing the "who" or "who from", or the "what" Also keep in mind that the only person that cna change the data is the one who has privileges to do it... Guardium will be able to capture everything... but after seeing a Guardium appliance fill up around 200GB of logging on a bunch of tables from COB of day X to the morning of day X+1 I can assure you that you must be very careful on what you ask for. In this case customer asked for "all operations and values on this set of tables". > > What do you want the output to look like? > > -> doesn't matter, text files will also be good :) and could be used in a > script. > > Who is this for? > > -> IT Manager and IT Security officer > > How will you know if its successful? > > -> good question, i guess if it is a problem the errors will be found in > log > files (online.log), i think also that we cannot neither know if it > successful > with other tools, isn't it ? > > What version of Informix are you using? > > --> 11.70 > Very good for native auditing as it will allow selective row auditing. Regards > > regards > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --001a11452044920982054a29636d
Yeah, I can see a long haul ahead of us here. Why do you want to know who did what on your database, especially the data? What sort of things do you actually want to know? Do you want to know who accessed a table? Read a row? Updated a row? Added a row? What if the row has been deleted in the mean time? If someone has deleted a row, do you want to know what was deleted? Because all of these things are entirely possible but completely impractical. Also, you have to do an awful lot of digging to cobble together what was actually done. Id strongly suggest you go back to your IT Security Officer and ask for a much better definition of what he actually wants, and then Ill tell you exactly why its too difficult to do that. :-D > On 7 Mar 2017, at 19:46, SMITH JOHN <srafik0358@gmail.com> wrote: > > Hello > > I liked your answer, thank you, so here are some answers > > Why are you trying to do this? > > -> I want to know did what on the database, especially the data. > > What do you want the output to look like? > > -> doesn't matter, text files will also be good :) and could be used in a > script. > > Who is this for? > > -> IT Manager and IT Security officer > > How will you know if its successful? > > -> good question, i guess if it is a problem the errors will be found in log > files (online.log), i think also that we cannot neither know if it successful > with other tools, isn't it ? > > What version of Informix are you using? > > --> 11.70 > > regards > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >