<?xml version="1.0" encoding="UTF-8"?><!-- generator="WordPress/2.5" -->
<rss version="0.92">
<channel>
	<title>Secure your most important technology asset - Database</title>
	<link>http://sahaa.net/blog</link>
	<description>Get a good night sleep</description>
	<lastBuildDate>Wed, 14 May 2008 00:01:19 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>TA08-100A: Adobe Flash updates for Multiple Vulnerabilities</title>
		<description><![CDATA[Adobe Flash updates for Multiple Vulnerabilities]]></description>
		<link>http://sahaa.net/blog/2008/05/14/ta08-100a-adobe-flash-updates-for-multiple-vulnerabilities/</link>
			</item>
	<item>
		<title>TA08-099A: Microsoft Updates for Multiple Vulnerabilities</title>
		<description><![CDATA[Microsoft Updates for Multiple Vulnerabilities]]></description>
		<link>http://sahaa.net/blog/2008/05/14/ta08-099a-microsoft-updates-for-multiple-vulnerabilities/</link>
			</item>
	<item>
		<title>TA08-094A: Apple Quicktime Updates for Multiple Vulnerabilities</title>
		<description><![CDATA[Apple Quicktime Updates for Multiple Vulnerabilities]]></description>
		<link>http://sahaa.net/blog/2008/05/14/ta08-094a-apple-quicktime-updates-for-multiple-vulnerabilities/</link>
			</item>
	<item>
		<title>TA08-066A: Sun Updates for Multiple Vulnerabilities in Java</title>
		<description><![CDATA[Sun Updates for Multiple Vulnerabilities in Java]]></description>
		<link>http://sahaa.net/blog/2008/05/14/ta08-066a-sun-updates-for-multiple-vulnerabilities-in-java/</link>
			</item>
	<item>
		<title>TA08-071A: Microsoft Updates for Multiple Vulnerabilities</title>
		<description><![CDATA[Microsoft Updates for Multiple Vulnerabilities]]></description>
		<link>http://sahaa.net/blog/2008/05/14/ta08-071a-microsoft-updates-for-multiple-vulnerabilities/</link>
			</item>
	<item>
		<title>TA08-079B: MIT Kerberos Updates for Multiple Vulnerabilities</title>
		<description><![CDATA[MIT Kerberos Updates for Multiple Vulnerabilities]]></description>
		<link>http://sahaa.net/blog/2008/05/14/ta08-079b-mit-kerberos-updates-for-multiple-vulnerabilities/</link>
			</item>
	<item>
		<title>TA08-079A: Apple Updates for Multiple Vulnerabilities</title>
		<description><![CDATA[Apple Updates for Multiple Vulnerabilities]]></description>
		<link>http://sahaa.net/blog/2008/05/14/ta08-079a-apple-updates-for-multiple-vulnerabilities/</link>
			</item>
	<item>
		<title>TA08-087B: Cisco Updates for Multiple Vulnerabilities</title>
		<description><![CDATA[Cisco Updates for Multiple Vulnerabilities]]></description>
		<link>http://sahaa.net/blog/2008/05/14/ta08-087b-cisco-updates-for-multiple-vulnerabilities/</link>
			</item>
	<item>
		<title>TA08-087A: Mozilla Updates for Multiple Vulnerabilities</title>
		<description><![CDATA[Mozilla Updates for Multiple Vulnerabilities]]></description>
		<link>http://sahaa.net/blog/2008/05/14/ta08-087a-mozilla-updates-for-multiple-vulnerabilities/</link>
			</item>
	<item>
		<title>TA08-134A: Microsoft Updates for Multiple Vulnerabilities</title>
		<description><![CDATA[Microsoft Updates for Multiple Vulnerabilities]]></description>
		<link>http://sahaa.net/blog/2008/05/14/ta08-134a-microsoft-updates-for-multiple-vulnerabilities/</link>
			</item>
	<item>
		<title>“IdM Risk Management” and “Identity Analytics”:  Anything Else Apart From “Bottom-Up” Approaches?</title>
		<description><![CDATA[<p>I was wondering if anybody in this community could share references to relevant material/links/documents/research projects illustrating the current status of: </p>
<p>(1) Risk Analysis and Management in the space of Identity Management</p>
<p>(2) Identity Analytics</p>
<p>My current search and assessment of this space has identified various technologies, solutions and work coming from a “compliance management” perspective i.e. (a) assessing events and evidence (e.g. logs) against expected processes/policies and (b) providing results that indicate the level of compliance and risk exposure. This is what I call the “bottom-up” approach where the “risk assessment” is done against predefined policies and/or well defined situations.</p>
<p>So far I have not found good examples of “top-down” solutions that help decision makers (e.g. CIOs, CISOs, etc.) to explore trade-offs in the Identity Management space (e.g. making investments in education vs IT solutions vs outsourcing vs etc.) to understand the impact on factor of relevance for an organisation (e.g. costs, reputation, losses, trust, etc.), make compelling decisions and potentially help them to define suitable policies. </p>
<p>A specific example would be decision support solutions that help understanding the trade-offs between adopting (in an organisation) the usage of strong passwords, SSO, multi-factor authentication, etc. against involved costs, the value of the assets to be protected, the kind of involved users and the actual benefits in terms of security. More in general these solutions should provide insights about potential trade-offs between various possible choices in the IdM space (in terms of authentication, authorization, provisioning, federation/SSO, privacy, etc.) against complex organisational realities and their business objectives. Modelling and simulation might be required to cope with the involved complexity …</p>
<p>Is anybody aware of specific research/work/solutions in this space?</p>
<p>CIOs/CISOs are increasingly asked to justify the reasons behind their security investments and/or have to make investment choices that must “maximise” their “expected outcomes” based on ever-shrinking budgets. I see the opportunity for “top-down” decision support, modelling and simulation solutions that can effectively help these decision makers, specifically in the Identity Management space …</p>
<p></p>
<p><font size="2">--- NOTE: use this </font><a href="http://research-on-identitymanagement.blogspot.com/"><u><font size="2">mirror blog</font></u></a><font size="2"> to post anonymous (un-authenticated) comments ---</font></p><img src="http://h20325.www2.hp.com/blogs/mcm/aggbug/6345.html" width="1" height="1" />]]></description>
		<link>http://sahaa.net/blog/2008/05/13/%e2%80%9cidm-risk-management%e2%80%9d-and-%e2%80%9cidentity-analytics%e2%80%9d-anything-else-apart-from-%e2%80%9cbottom-up%e2%80%9d-approaches/</link>
			</item>
	<item>
		<title>TA08-043C: Microsoft Updates for Multiple Vulnerabilities</title>
		<description><![CDATA[Microsoft Updates for Multiple Vulnerabilities]]></description>
		<link>http://sahaa.net/blog/2008/05/13/ta08-043c-microsoft-updates-for-multiple-vulnerabilities/</link>
			</item>
	<item>
		<title>License plate SQL Injection</title>
		<description><![CDATA[  <p> Wow, its been a while since I posted, I have been travelling all over the world over the last month or so, teaching my Oracle security class and also speaking at conferences and performing Oracle security audits. It's been a....<a href="http://www.petefinnigan.com/weblog/archives/00001169.htm">[Read More]</a> </p>  <p>Posted by Pete On 13/05/08 At 07:38 PM</p>]]></description>
		<link>http://sahaa.net/blog/2008/05/13/license-plate-sql-injection/</link>
			</item>
	<item>
		<title>Slides from OUG Scotland DBA SIG on Oracle Forensics available</title>
		<description><![CDATA[  <p> I have posted the slides to my talk from yesterday at the OUG Scotland SIG to my Oracle Security white papers page . They are the first entries in the page. The talk was 45 minutes about Oracle Forensics. This....<a href="http://www.petefinnigan.com/weblog/archives/00001168.htm">[Read More]</a> </p>  <p>Posted by Pete On 01/05/08 At 02:23 PM</p>]]></description>
		<link>http://sahaa.net/blog/2008/05/13/slides-from-oug-scotland-dba-sig-on-oracle-forensics-available/</link>
			</item>
	<item>
		<title>Conditionally firing triggers</title>
		<description><![CDATA[  <p> I saw a post on the BAR Solutions blog today titled " Triggers… " that was very interesting as I have had the same issue in the past for different reasons. The blog post was around an issue where triggers....<a href="http://www.petefinnigan.com/weblog/archives/00001167.htm">[Read More]</a> </p>  <p>Posted by Pete On 01/05/08 At 01:22 PM</p>]]></description>
		<link>http://sahaa.net/blog/2008/05/13/conditionally-firing-triggers/</link>
			</item>
	<item>
		<title>Lateral SQL Injection and Conferences and security training</title>
		<description><![CDATA[  <p> I am writing this whilst sat on a train travelling at around 120mph between York and Darlington, this is probably my first blog entry written at speed! I saw that David had released his paper " Lateral SQL Injection: A....<a href="http://www.petefinnigan.com/weblog/archives/00001166.htm">[Read More]</a> </p>  <p>Posted by Pete On 30/04/08 At 08:26 AM</p>]]></description>
		<link>http://sahaa.net/blog/2008/05/13/lateral-sql-injection-and-conferences-and-security-training/</link>
			</item>
	<item>
		<title>Slides from OUGN Norway and RISK 2008 Norway available</title>
		<description><![CDATA[  <p> I was over in Norway this week and the Oracle User Group Norway (OUGN) asked me to speak at an evening user group meeting of theirs. This was a eally friendly group and it was a pleasure to speak there....<a href="http://www.petefinnigan.com/weblog/archives/00001165.htm">[Read More]</a> </p>  <p>Posted by Pete On 25/04/08 At 05:58 PM</p>]]></description>
		<link>http://sahaa.net/blog/2008/05/13/slides-from-ougn-norway-and-risk-2008-norway-available/</link>
			</item>
	<item>
		<title>Two remotely exploitable without authentication bugs to be fixed</title>
		<description><![CDATA[  <p> Oracle's pre-patch advisory note for the next Critical Patch Update (CPU) due this Tuesday (15th) states that there are 17 new security fixes for the database, two for Apex and two of which are remotely exploitable without authentication. The advisory....<a href="http://www.petefinnigan.com/weblog/archives/00001164.htm">[Read More]</a> </p>  <p>Posted by Pete On 14/04/08 At 10:17 AM</p>]]></description>
		<link>http://sahaa.net/blog/2008/05/13/two-remotely-exploitable-without-authentication-bugs-to-be-fixed/</link>
			</item>
	<item>
		<title>Fine Grained network Access Control in 11g</title>
		<description><![CDATA[  <p> I saw a post by Tim Hall on his blog recently that referenced a new article he had written about the new fine grained network access controls added in 11g. As this is an area I have also looked at....<a href="http://www.petefinnigan.com/weblog/archives/00001163.htm">[Read More]</a> </p>  <p>Posted by Pete On 08/04/08 At 10:25 AM</p>]]></description>
		<link>http://sahaa.net/blog/2008/05/13/fine-grained-network-access-control-in-11g/</link>
			</item>
	<item>
		<title>C code API to encapsulate OCI</title>
		<description><![CDATA[  <p> If like me you code in C and use OCI instead of Pro*C then you will be interested in a library written by Vincent Rogier. I have looked at most C++ OCI libraries, and C libraries that encapsulate OCI in....<a href="http://www.petefinnigan.com/weblog/archives/00001162.htm">[Read More]</a> </p>  <p>Posted by Pete On 07/04/08 At 11:52 AM</p>]]></description>
		<link>http://sahaa.net/blog/2008/05/13/c-code-api-to-encapsulate-oci/</link>
			</item>
	<item>
		<title>Semi-finalist in the 2008 Ernst &#38; Young New Jersey entrepreneur</title>
		<description><![CDATA[Great news today!  We have been selected as a semi-finalist Entrepreneur of the Year Program. This would be the third year in a row that we are part of this program.  We&#8217;ll be attending a reception tonight.
]]></description>
		<link>http://sahaa.net/blog/2008/05/13/semi-finalist-in-the-2008-ernst-young-new-jersey-entrepreneur/</link>
			</item>
	<item>
		<title>Learn Oracle: Triggers</title>
		<description><![CDATA[
<p>LewisC's <a href="http://blogs.ittoolbox.com/oracle/guide">An Expert's Guide To Oracle Technology</a></p>
<p>Today I will be writing about triggers. One of the questions I get fairly often is "what is the difference between a function, a procedure and a trigger?" I already wrote about functions and procedures in &#60;a href="http://blogs.ittoolbox.com/oracle/guide/archives/learn-plsql-procedures-and-functions-13</p>]]></description>
		<link>http://sahaa.net/blog/2008/05/13/learn-oracle-triggers/</link>
			</item>
	<item>
		<title>PLING panel at WWW 2008</title>
		<description><![CDATA[<p>A PLING panel has been held at the <a href="http://www2008.org/"><u>WWW 2008 conference</u></a> (Beijing 23-25 April), discussing policies and Policy-aware Web.</p>
<p>The list of panellists includes: Renato Iannella (Moderator), Piero Bonatti, Llana Kagal, Thomas Roessler.</p>
<p>The slides presented in this panel are now available <a href="http://www.w3.org/Policy/pling/wiki/WWW2008"><u>online</u></a>.</p>
<p></p>
<p><font size="2">--- NOTE: use this </font><a href="http://research-on-identitymanagement.blogspot.com/"><u><font size="2">mirror blog</font></u></a><font size="2"> to post anonymous (un-authenticated) comments ---</font></p><img src="http://h20325.www2.hp.com/blogs/mcm/aggbug/6340.html" width="1" height="1" />]]></description>
		<link>http://sahaa.net/blog/2008/05/13/pling-panel-at-www-2008/</link>
			</item>
	<item>
		<title>Crisis or Opportunity: leading through a down economy</title>
		<description><![CDATA[I will be speaking tomorrow at the Corporate Executive Board Conferences – Customize or Standardize?  Making the Right IT Choices with Scarce Resources.   I am particularly excited about the speaking engagement as I will be at the same conference &#8212; in fact it will be meeting with &#8212; Dr. Alan Greenspan.  As part of my [...]]]></description>
		<link>http://sahaa.net/blog/2008/05/12/crisis-or-opportunity-leading-through-a-down-economy/</link>
			</item>
	<item>
		<title>A Complete Newbie&#8217;s Guide to Choosing a Database</title>
		<description><![CDATA[<p>LewisC's <a href="http://blogs.ittoolbox.com/oracle/guide">An Expert's Guide To Oracle Technology</a></p>
<p>Welcome to newbie Monday. Today's topic is choosing your database. Choosing a database for your business has some commonalities with choosing a database as a new developer or DBA. There are also differences though. Here are a few guidelines to getting started. This is not a complete guide but it is meant as a starting place.</p>
<p>If you are already an Oracle shop, or DB2 shop, or w</p>]]></description>
		<link>http://sahaa.net/blog/2008/05/12/a-complete-newbies-guide-to-choosing-a-database/</link>
			</item>
	<item>
		<title>Biometrics: State Of The Art And Future Implications</title>
		<description><![CDATA[Biometrics has matured to the point where several technologies have been internationally standardized and incorporated into major international and national identity verification implementations across both the public and private sectors. Because these biometrics technologies are being incorporated into mainstream government to citizen (G2C) and business to consumer (B2C) identification processes, broader adoption of these technologies can be accomplished more quickly and at lower cost than was previously possible. The prospect of biometrics becoming the principle consumer and citizen identification method through incorporation into government and commercial credentials is now close enough for CISOs to begin active consideration for adopting them in their enterprise business processes.]]></description>
		<link>http://sahaa.net/blog/2008/05/12/biometrics-state-of-the-art-and-future-implications/</link>
			</item>
	<item>
		<title>A new version of the Oracle password cracker woraauthbf is available</title>
		<description><![CDATA[  <p> The Oracle password cracker woraauthbf written by Laszlo Toth has been updated and released as a new version 0.21R2 (The R2) is the new part, so even if you are running version 0.21 then please download the new release. The....<a href="http://www.petefinnigan.com/weblog/archives/00001161.htm">[Read More]</a> </p>  <p>Posted by Pete On 31/03/08 At 10:33 AM</p>]]></description>
		<link>http://sahaa.net/blog/2008/05/10/a-new-version-of-the-oracle-password-cracker-woraauthbf-is-available/</link>
			</item>
	<item>
		<title>Oracle Street Talk</title>
		<description><![CDATA[I guess there are people who don’t know about Oracle or Larry Ellison.  Shocking!  I guess life down under is just that.  

]]></description>
		<link>http://sahaa.net/blog/2008/05/10/oracle-street-talk/</link>
			</item>
	<item>
		<title>In Licensing loopholes in Microsoft Windows XP</title>
		<description><![CDATA[So Dell and HP are offering XP instead of Vista.  Even with all the tweaks Microsoft has made to desktop operating system &#8212; making it more intuitive, more secure and just generally having cool stuff &#8212; means that you need more memory and faster graphics.
Meanwhile, Windows XP users are getting a surprise.  Computer makers &#8212; [...]]]></description>
		<link>http://sahaa.net/blog/2008/05/09/in-licensing-loopholes-in-microsoft-windows-xp/</link>
			</item>
	<item>
		<title>Cloudy software licensing issues</title>
		<description><![CDATA[Cloud computing &#8212; also known as grid computing (or you just call it on-demand computing) has been making headway in the press lately.  Aside from publications that stem from security to data privacy, there is a whole host of complex licensing and compliance issues that need to be addressed.  For example, in the world of [...]]]></description>
		<link>http://sahaa.net/blog/2008/05/08/cloudy-software-licensing-issues/</link>
			</item>
</channel>
</rss>
