الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

SQL Server Security vs. Oracle Security

مغلق
بدأه Mohamed Meshref في 13 ديسمبر 2006 · 2 رد · 868 مشاهدة · في قواعد بيانات Microsoft SQL Server
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

In this article I'll list some point to show you which RDBMS is more secure, is it SQL Server or Oracle?

Let's begin with this article I read recently:

compare%201.jpg

Let's zoom-in into the graph a little bit:

compare%202.jpg

Now as you see no security flaws have been reported in SQL Server 2005 since it has been released.

Interpretation of results - some Q and A

Do Oracle’s results look so bad because it runs on multiple platforms?

No – pretty much most of the issues are cross-platform. In the 10gR2 graph every flaw affects every platform.

Do the SQL Server 2005 results have no flaws because no-one is looking at it?

No – I know of a number of good researchers are looking at it – SQL Server code is just more secure than Oracle code.

Do you have any predictions on the Oracle January 2007 Critical Patch Update?

Maybe – NGSSoftware are currently waiting for Oracle to fix 49 security flaws – these will be fixed sometime in 2007 and 2008.

Do these results contain unfixed flaws?

No – only those that have been publicly reported and fixed are in the data.

Why have there been so little bugs found in SQL Server since 2002?

Three words: Security Development Lifecycle – SDL. SDL is far and above the most important factor. A key benefit of employing SDL means that knowledge learnt after finding and fixing screw ups is not lost; instead it is ploughed back into to the cycle. This means rather than remaking the same mistakes elsewhere you can guarantee that new code, whilst not necessarily completely secure, is at least more secure than the old code.

Microsoft SQL Server

Security issues and fixes in SQL Server 7, 2000 and 2005 since December 2000 to November 2006. Five MDAC security flaws over this period of time have not been included in these results because MDAC is part of Windows and not SQL Server.

compare%203.jpg

Oracle

Security issues and fixes in Oracle 8, 9 and 10 since December 2000 to November 2006.Only security issues found in the TNS Listener and the RDBMS itself have been includedin the following graph. This means issues found in components such as the IntelligentAgent or the Oracle Application Server have not been included.

compare%204.jpg

Source:

http://www.databasesecurity.com/dbsec/comparison.pdf

More Information:

http://www.blackhat.com/presentations/bh-u...-05-cerrudo.pdf

Mohamed Meshref

Performance Engineer

SQL Server Engine Team

Microsoft Corporation

Redmond, Washington, USA

http://www.microsoft.com/sql/

Blog: http://www.mmeshref.com

#2

مرحبا

كيف صحتك سيد محمد؟

هلق إنت طرحت مشكلة فعلا موجودة و لكن ممكن نقول إنه مثل مايكروسوفت ويندوز هو نظام التشغيل الأكثر شعبية و بالتالي يتعرض لكثير من الهجمات أيضا أوراكل نظام قواعد البيانات العلائقية الأكثر شعبية

عموما ، مايكروسوفت اس كي ال سيرفر يعمل فقط على منصة ويندوز و هذه يجب أن تؤخذ بعين الإعتبار ، أما أوراكل فتعمل على ويندوز و لينوكس و أنا بأكد لك إنه لو نزل اصدار من اس كيو ال يعمل على غير منصة عمل ويندوز فإنه لازم يطلعله كثييير أخطاء ، كحال أوراكل

على فكرة أنا مثلك عملت بحث و فعلا أوراكل طلعت كثييير باتشات

So Which Database Is More Secure?

Measures of how secure a database server is should include how many security bulletins, incidents, or advisories have been registered against the database. Security bulletins show the track record of the vendor regarding security.

A look at the number of security bulletins/advisories published for each database shows that Oracle has had more advisories over time than has Microsoft SQL Server products since the release of SQL Server 2000. Here are the statistics comparing Oracle and SQL Server published by a few independent sources in the recent few years.

Computer Incident Advisory Capability

• The Computer Incident Advisory Capability lists ten Oracle incidents since 2003 at http://www.ciac.org/ciac/bulletinsByType/v..._bulletins.html, with three incidents in 2004 and seven in 2003.

• Microsoft SQL Server has had two incidents over the same period of time with one in 2004 and one in 2003 according to the same source. http://www.ciac.org/ciac/bulletinsByType/v...ins.html#ms_sql

Carnegie Mellon Software Engineering

• The Carnegie Mellon Software Engineering Institute (http://www.cert.org/) lists nine Oracle Advisories in the last two years.

• The Carnegie Mellon Software Engineering Institute lists three SQL Server advisories during the same two-year period.

National Institute of Standards and Technology

• The National Institute of Standards and Technology (http://www.nist.gov/) reported 81 Oracle incidents using Oracle. (http://icat.nist.gov/icat.cfm?vendor_command=Oracle&product_command=Oracle)

• This same organization reported only 46 SQL Server incidents for the same period. (http://icat.nist.gov/icat.cfm?vendor_command=Microsoft&product_command=SQL%20Server).

Based on a review of security incidents/advisories, SQL Server has had about 50 percent fewer security incidents than does Oracle. This is evidence that SQL Server is more secure than Oracle. When a company considers data security, it also needs to consider the process they follow regarding applying patches and updates—if there is a security incident, companies need to patch their servers.

أنا غالبا أؤيد الرأي القائل أن الخطأ من نظام التشغيل " ويندوز " :)

سلام

#3

I knew that someone will say that, so the answer is really obvious in the report, if you just read the whole post you'll find it very clear:

Do Oracle’s results look so bad because it runs on multiple platforms?

No – pretty much most of the issues are cross-platform. In the 10gR2 graph every flaw affects every platform

About Windows, I've another report comparing the number of vulnerabilities discovered in Windows and those in Linux (different distros), and windows is the least one, it's not only one report, it's many reports from many 3rd parties:

http://www.us-cert.gov/cas/bulletins/SB2005.html

http://www.blackhat.com/presentations/bh-u...6-Gutterman.pdf

http://www.blackhat.com/presentations/bh-e...eu-04-hardy.pdf

And here you are another study which is talking about comparison between Windows and Redhat Linux web servers including days of attack (time between vulnerability is discovered and the actual patch is made available):

http://www.securityinnovation.com/pdf/wind...final_study.pdf

Comparing total cost of security patch management:

http://download.microsoft.com/download/1/7...O_SPM_Wipro.pdf

Windows Users Have Less Vulnerability:

http://download.microsoft.com/download/9/c...owsSecurity.pdf

Those are the actual numbers and now just someone saying his own opinion on which system is more secure, I usually put facts only, the part you put in your post is not a fact, mine is numbers and numbers only should be considered

تم تعديل هذه المشاركة بواسطة Mohamed Meshref في 13 ديسمبر 2006 في 11:41

Mohamed Meshref

Performance Engineer

SQL Server Engine Team

Microsoft Corporation

Redmond, Washington, USA

http://www.microsoft.com/sql/

Blog: http://www.mmeshref.com

هذا الموضوع مغلق.

مواضيع مشابهة