GeekInterview.com
   Home |  Tech FAQ  |   Interview Questions |  Placement Papers |  Tech Articles |  Learn |  Freelance Projects |  Online Testing |  Geeks Talk |  Job Postings |  Knowledge Base | Site Search |  Add/Ask Question

GeekInterview.com  >  Interview Questions  >  Oracle  >  Database security
Go To First  |  Previous Question  |  Next Question 
 Database security  |  Question 24 of 30    Print  
if we have database,then how can we tell the data in the "database is secured" . 2)what is ment by "data validation"?

  
Total Answers and Comments: 1 Last Update: August 15, 2006     Asked by: suribabu 
  
 Sponsored Links

 
 Best Rated Answer

No best answer available. Please pick the good answer available or submit your answer.
August 15, 2006 04:12:10   #1  
Pooja Chaturvedi        

RE: if we have database,then how can we tell the data ...
If we want to say that our Database is secured then we must confirm first that our Data is validate.There are various methods of validating the Data:1. Accept only known valid Data.2. Reject known Bad Data.3. Sanitize Bad data. We cannot emphasize strongly enough that "Accept Only Known Valid Data" is the best strategy. We do, however, recognize that this isn't always feasible for political, financial or technical reasons, and so we describe the other strategies as well.All three methods must check: * Data Type * Syntax * Length Data type checking is extremely important. The application should check to ensure a string is being submitted and not an object, for instance.Accept Only Known Valid DataAs we mentioned, this is the preferred way to validate data. Applications should accept only input that is known to be safe and expected. As an example, let's assume a password reset system takes in usernames as input. Valid usernames would be defined as ASCII A-Z and 0-9. The application should check that the input is of type string, is comprised of A-Z and 0-9 (performing canonicalization checks as appropriate) and is of a valid length.Reject Known Bad DataThe rejecting bad data strategy relies on the application knowing about specific malicious payloads. While it is true that this strategy can limit exposure, it is very difficult for any application to maintain an up-to-date database of web application attack signatures.Sanitize All DataAttempting to make bad data harmless is certainly an effective second line of defense, especially when dealing with rejecting bad input. However, as described in the canonicalization section of this document, the task is extremely hard and should not be relied upon as a primary defense technique.
 
Is this answer useful? Yes | No

 Related Questions

 REDUCED  GRANTING  OF PRIVILEGES - Rather than explicitly granting the same set  of  privileges  to  many users a database administrator  can grant the privileges  

Each  database  user  is  assigned  a Profile that specifies limitations on various system resources available to the user. 
Latest Answer : A profile is used to restrict the reource uses, password reuses, idle time of a session etc.  We can also attach a password verify function for the database user.  A database user can be assigned a profile.  It is an optional clause.  ...

Monitoring of user access to aid in the investigation of database use. 
Latest Answer : Auditing involves in recording all the activities based on the auditing rulesSome types of auditing are Database level Auditing, Schema Level auditing, Object level Auditing and Statement level auditing. ...

 An  user  account  is not a physical structure in Database but it is having important  relationship  to  the objects in the database and will be having certain privileges. 

 DBA_FREE_SPACEDBA_SEGMENTSDBA_DATA_FILES. 

 Installing and upgrading the Oracle Server and application tools.Allocating  system storage and planning future storage requirements for the database  system.Managing primary database structures 
Latest Answer : adding to the list* involved in database design * applying patch sets * writing scripts to automate the routine DBA tasks* configuring oracle net such as listeners and tnsnames* data loading and unloading using exp/imp and sqlloader* providing help to ...

 DBA - role Contains all database system privileges. SYS  user  account  - The DBA role will be assigned to this account. All of the base tables and views for the database's 
Latest Answer : &DBSNMPSupports Oracle SNMP (Simple Network Management Protocol). The Oracle Intelligent Agent requires a database logon for each SID that it manages. By default this account is called "DBSNMP" CheersRavi Prakashhttp://ravidba-oracle.blogspot.com/ ...

 SQL * DBA - This allows DBA to monitor and control an ORACLE database. SQL  *  Loader  -  It loads data from standard operating system files (Flat files) into ORACLE database 
Latest Answer : SQL Plus, SQL Loader, EXP, IMP ...

What  are  the  minimum  parameters should exist in the parameter file (init.ora) ?
 DB  NAME  -  Must  set to a text string of no more than 8 characters and it will  be  stored inside the datafiles, redo log files and control files and control file 

 Each server and background process can write an associated trace file. When an   internal  error  is  detected  by  a  process or user process, it dumps information  


 Sponsored Links

 
Related Articles

Breaking up XML into Relational Data

Breaking up XML into Relational Data While the preceding example shows how to construct an XML representation over relational data the example in this section illustrates how you can shred XML data back into relational data This reverse operation can be useful if your application works with relation
 

Querying Data with Oracle XQuery

Querying Data with Oracle XQuery Starting with Oracle Database 10g Release 2 you can take advantage of a full featured native XQuery engine integrated with the database With Oracle XQuery you can accomplish various tasks involved in developing PHP Oracle XML applications operating on any kind of dat
 

Retrieving XML Data

Retrieving XML DataTo retrieve XML data from an XMLType table you can use a SELECT SQL statement just as you would if you had to query a relational table For example to select the employee with the id set to 100 from the employees XMLType table discussed in the preceding section you might issue the
 

Using XMLType for Handling XML Data in the Database

Using XMLType for Handling XML Data in the Database Being an object type XMLType can not only be used to store XML data in the database but also to operate on that data via its built in methods Regardless of the storage model you choose XMLType provides a set of XML specific methods to operate on XM
 

Using Oracle Database for Storing, Modifying, and Retrieving XML Data

Using Oracle Database for Storing Modifying and Retrieving XML Data With Oracle XML DB you have various XML storage and XML processing options allowing you to achieve the required level of performance and scalability One of the most interesting things about Oracle XML DB is that it allows you to per
 

Performing XSLT Transformations inside the Database

Performing XSLT Transformations inside the Database Now that you have the employees XSL stylesheet stored in the database and the xmlusr schema is permitted to access the hr employees table you can create a script that will instruct the database to build an HTML page based on the data stored in hr e
 

Moving All the XML Processing into the Database

Moving All the XML Processing into the Database In the preceding example the database server performs only a part of the XML processing while the rest is still performed by the PHP engine Specifically the database server generates an employees XML document based on the records from the hr employees
 

Performing XML Processing inside the Database

Performing XML Processing inside the Database When building XML enabled applications on top of Oracle there are many advantages to performing the XML processing inside the database when compared to performing it on the client The key advantages to perform XML processing inside the database are as fo
 

ODP.NET - Techniques to Improve Performance while Retrieving Data

ODP NET Techniques to Improve Performance while Retrieving Data Performance tuning is a great subject in Oracle Volumes of books would not be enough to cover every aspect of performance tuning in Oracle However in this section we will only discuss the fundamental performance techniques while working
 

ODP.NET - Populating a Dataset with a Single Data Table

ODP NET Populating a Dataset with a Single Data Table A dataset is simply a group of data tables These data tables can be identified with their own unique names within a dataset You can also add relations between data tables available in a dataset mosgoogle The following code gives you the details o
 





About Us  |   Privacy Policy  |   Terms and Conditions  |   Contact  |   Site Map  |   Add Question  |   Propose Category  |   RSS Feeds  |   Articles Sitemap  |   Site Updates  |   Add Resource

Copyright © 2005 - 2008 GeekInterview.com. All Rights Reserved
Page copy protected against web site content infringement by Copyscape