or
Sign in to turn on 1-Click ordering.
or
Amazon Prime Free Trial required. Sign up when you check out. Learn More
Kindle Edition
Read instantly on your iPad, PC or Mac, no Kindle required
Buy Price: $49.69
Rent From: $19.27
 
 
   
Sell Back Your Copy
For a $38.40 Gift Card
Trade in
More Buying Choices
Have one to sell? Sell yours here
Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase
 
 

Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase [Paperback]

Ron Ben Natan (Author)
4.9 out of 5 stars  See all reviews (11 customer reviews)

List Price: $73.95
Price: $55.62 & this item ships for FREE with Super Saver Shipping. Details
You Save: $18.33 (25%)
  Special Offers Available
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.
Want it delivered Monday, January 30? Choose One-Day Shipping at checkout. Details
Textbook Student FREE Two-Day Shipping for Students. Learn more

Formats

Amazon Price New from Used from
Kindle Edition
Rent from
$49.69
$19.27
 
Paperback $55.62  
Sell Back Your Copy for $38.40
Whether you buy it used on Amazon for $48.95 or somewhere else, you can sell it back through our Book Trade-In Program at the current price of $38.40.
Used Price$48.95
Trade-in Price$38.40
Price after
Trade-in
$10.55

Book Description

1555583342 978-1555583347 May 2, 2005 1
This book is about database security and auditing. You will learn many methods and techniques that will be helpful in securing, monitoring and auditing database environments. It covers diverse topics that include all aspects of database security and auditing - including network security for databases, authentication and authorization issues, links and replication, database Trojans, etc. You will also learn of vulnerabilities and attacks that exist within various database environments or that have been used to attack databases (and that have since been fixed). These will often be explained to an "internals" level. There are many sections which outline the "anatomy of an attack" - before delving into the details of how to combat such an attack. Equally important, you will learn about the database auditing landscape - both from a business and regulatory requirements perspective as well as from a technical implementation perspective.

* Useful to the database administrator and/or security administrator - regardless of the precise database vendor (or vendors) that you are using within your organization.
* Has a large number of examples - examples that pertain to Oracle, SQL Server, DB2, Sybase and even MySQL..
* Many of the techniques you will see in this book will never be described in a manual or a book that is devoted to a certain database product.
* Addressing complex issues must take into account more than just the database and focusing on capabilities that are provided only by the database vendor is not always enough. This book offers a broader view of the database environment - which is not dependent on the database platform - a view that is important to ensure good database security.

Special Offers and Product Promotions

  • Buy $50 in qualifying physical textbooks, get $5 in Amazon MP3 Credit. Here's how (restrictions apply)

Frequently Bought Together

Customers buy this book with The Database Hacker's Handbook: Defending Database Servers $26.91

Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase + The Database Hacker's Handbook: Defending Database Servers
  • This item: Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • The Database Hacker's Handbook: Defending Database Servers

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details



Editorial Reviews

Review

"It's been said that everyone has their 15 minutes of fame. You certainly don't want to gain yours by allowing a security breach in your database environment or being the unfortunate victim of one. Information and Data are the currency of On Demand computing, and protecting their integrity and security has never been more important. Ron's book should be compulsory reading for managing and maintaining a secure database environment." Bob Picciano, VP Database Servers, IBM.

"Today, databases house our 'information crown jewels', but database security is one of the weakest areas of most information security programs. With this excellent book, Ben-Natan empowers you to close this database security gap and raise your database security bar!" Bruce W. Moulton. CISO/VP, Fidelity Investments (1995 - 2001)

"Let's start with a simple truth about today's world: If you have a database and you make it available to customers, employees, or whomever over a network, that database will be attacked by hackers -- probably sooner rather than later. If you are responsible for that database's security, then you need to read this book. No other single source covers all of the many disciplines and layers involved in protecting exposed databases, and it especially shines in synthesizing all of its concepts and strategies into very practical and specific checklists of things you need to do. I've been an Oracle DBA for 15 years, but I'm not embarrassed to admit that five minutes into Chapter One I was making notes on simple measures I had overlooked." -- Charles McClain, Senior Oracle DBA, North River Consulting, Inc.

"In just over 400 pages the author manages to quite thoroughly cover a wide variety of database security topics. Whether you want to learn more about encryption, authentication and password control, or access control, this book provides help." - dbazine.com, Craig Mullins

"I learned some new information that I would not have known if I hadn't been exposed to it by this book." - C.J. Kelly Computerworld

Book Description

Securing application environments and databases is the major focus of information security – this book will show you how to do it.

Product Details

  • Paperback: 432 pages
  • Publisher: Digital Press; 1 edition (May 2, 2005)
  • Language: English
  • ISBN-10: 1555583342
  • ISBN-13: 978-1555583347
  • Product Dimensions: 9.1 x 7.4 x 1.1 inches
  • Shipping Weight: 1.9 pounds (View shipping rates and policies)
  • Average Customer Review: 4.9 out of 5 stars  See all reviews (11 customer reviews)
  • Amazon Best Sellers Rank: #386,430 in Books (See Top 100 in Books)

More About the Author

Discover books, learn about writers, read author blogs, and more.

 

Customer Reviews

11 Reviews
5 star:
 (10)
4 star:
 (1)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.9 out of 5 stars (11 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

7 of 8 people found the following review helpful:
4.0 out of 5 stars How can we secure our databases?, June 17, 2005
This review is from: Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase (Paperback)
The preface clearly states that this book is a guide on implementing security and auditing for database environments Lays out who should read the book, basically administrators, auditors, security professionals, or any one involved with operational ownership of databases.

After reading the book I actually felt that there are so many vulnerabilities that effect every part of an IT shop that this book is a must read for developers, architects, and management as well. Often it is the way systems are architected and coded that bring out the vulnerabilities and allow would-be hackers in.

Ron really has hit a great balance between readability and information.

The book isnt just a text or reference book but also entertained me.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


3 of 3 people found the following review helpful:
5.0 out of 5 stars The Best Resource Available on Database and Data Access Auditing, June 10, 2009
This review is from: Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase (Paperback)
If compliance and auditing are on your agenda, then Ron Ben Natan's book on database security and auditing merits your attention. In this day-and-age of computer viruses, hacking, and governmental regulations, database security and auditing is a subject of paramount importance. And Implementing Database Security and Auditing attacks the subject with a vengenance.

In just over 400 pages the author manages to quite thoroughly cover a wide variety of database security topics. Whether you want to learn more about encryption, authentication and password control, or access control, this book provides help.

The book is useful for both DBAs and security administrators, giving each a better view of the world where the disciplines of database management and security management meet. Even better, the book offers many examples and guidelines for multiple environments. Whether you use DB2 on AIX, MySQL on Linux, Oracle on Unix, or SQL Server on Windows, Ben Natan's book provides useful guidance.

Are you curious to know more about SQL injection attacks? Learn what they are and why they are dangerous in this book. What about buffer overflows? Maybe you've read about them in the IT press, but those "newsy" pieces rarely delve into the depth required to understand and prevent attacks using these methods. This book offers that depth.

Chapter 7, "Using the Database to do Too Much," is particularly useful. In this chapter the author discusses some of the things not to do if you want to properly secure your database environment. You can save yourself a lot of trouble by reading and following these useful suggestions.

I think my favorite section of the book is the final three chapters. Here is where the author tackles the meaty topics of regulatory compliance and database auditing. New governmental rules and regulations are being introduced constantly and their impact on database administration is not clearly understood by many heads-down, techies. This book will give you a clearer understanding of laws such as GLB, Sarbanes-Oxley, and HIPAA -- and lend guidance on how to adapt your database environment in order to comply with these laws.

All-in-all Implementing Database Security and Auditing is a useful and timely publication that most DBAs would do well to read and embrace.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


2 of 3 people found the following review helpful:
5.0 out of 5 stars A Well-Rounded Textbook for DBAs, Auditors and InfoSec, March 23, 2007
By 
A. E Heald (Portland ME USA) - See all my reviews
(REAL NAME)   
This review is from: Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase (Paperback)
I'm rarely moved to write a review on a technical book, perhaps because I read so many of them. However, this text is truly outstanding, due to it's breadth of coverage, i.e., Oracle, SQL Server, DB2, UBD and Sybase AND well written descriptions of problems and solutions.

If you are seeking to secure your databases AND/OR audit them, this book contains both suggestions for scripting, triggers etc as well as where to look for vulnerabilities.

Bravo to the author, and THANKS, I'm using regularly, the best compliment of all.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews









Only search this product's reviews



Inside This Book (learn more)
First Sentence:
This book is about database security and auditing. Read the first page
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
database user model, application user model, system administration privileges, oblivious user, auditing solution, independent audit trail, granular access control, external security system, auditing architecture, cookie poisoning, replica database, auditing categories, mixed authentication, database auditing, label security, operating system authentication, application vulnerabilities, transaction replication, injection attacks, database login, password profiles, linked server, database security, overflow vulnerability, auditing information
Key Phrases - Capitalized Phrases (CAPs): (learn more)
Active Directory, Login Failec, Audit Add, Oracle Applications, Program Files, Control Center, Oracle Advanced Security, Cancel Help, Microsoft Office, Enterprise Portal, Event Class Description, Ron Bennatan, Audit Object, Command Description Command Description, Orange Book, Visual Studio, California Senate Bill, Event Occurs, Hardening Linux, Microsoft Windows, Oracle Internet Directory, Oracle Security Handbook, United States
New!
Books on Related Topics | Concordance | Text Stats
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Surprise Me!
Search Inside This Book:

Citations (learn more)
This book cites 6 books:
See all 6 books this book cites



What Other Items Do Customers Buy After Viewing This Item?


Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
 
(1)

Your tags: Add your first tag
 

Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   
Related forums



So You'd Like to...


Create a guide


Look for Similar Items by Category


Look for Similar Items by Subject