Skip to content

Commit

Permalink
[WMSID 11493] SQL Firewall updates (#233)
Browse files Browse the repository at this point in the history
* dbseclab_v5.3

* dbseclab_v5.3

* dbseclab_v5.3

* dbseclab_v5.3

* dbseclab_v5.3

* dbseclab_v5.3

* dbseclab_v5.3

* dbseclab_v5.3

* dbseclab_v5.3

* dbseclab-v5.3

* dbseclab_v5.3

* dbseclab_v5.3

* dbseclab-v5.3

* dbseclab_v5.3

* dbseclab_v5.3

* dbseclab_v5.3

* dbseclab_v5.3

* dbseclab_v5.4

* dbseclab_v5.4

* dbseclab_v5.4

* dbseclab_v5.4

* dbseclab_v5.4

* dbseclab-v5.4

* dbseclab_v5.4

* dbseclab-v5.5

* dbseclab-v5;5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab-v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* dbseclab_v5.5

* Squashed commit of the following:

commit 41135e2
Author: Dan Wiliams <[email protected]>
Date:   Thu Dec 21 17:09:01 2023 -0500

    WMS 11492- SQL Firewall  new Livelabs  (#157)

    * Revert "[WMSID 11492] SQL Firewall new Livelabs (#153)"

    This reverts commit b00fe40.

    * Revert "Revert "[WMSID 11492] SQL Firewall new Livelabs (#153)""

    This reverts commit 575187b.

* dbseclab_v5.5

* dbseclab_v5

* dbseclab_v5.5

* dbseclab_v5.6

* dbseclab_v5.6

* dbseclab_v5.6

* dbseclab_v6.0

* dbseclab_v6.0

* dbseclab_v6.0

* dbseclab_v6.0

* dbseclab_v6.0

* dbseclab_v6.0

* dbseclab_v6.0

* dbseclab_v6.0

* dbseclab_v6.0

* dbseclab_v6.0

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab_v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* updating dv lab - rce

* small updates - rce

* make changes - rce

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.1

* dbseclab-v6.2

* dbseclab-v6.2

* Updates for 23ai

* Updates for labs

* update dv labs

* updates to the lab

* dv lab updates

* dbseclab_v70

* dbseclab-v6.2

* lab updates

* update lab

* updates to adb dv lab

* adb dv lab updates

* adb dv lab updates

* adb dv lab updates

* dbseclab-v6.2

* dbseclab-v6.2

* adb dv lab updates

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* adb dv lab updates

* adb dbv lab updates

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* updates to adb dv lab

* adb dv lab

* adb dv labs

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dv lab updates

* adb dv lab updates

* adb dv lab updates

* adb dv lab update

* adb dv

* adb dv labs

* adb dv lab updates

* dv lab updates

* dv labs update

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dv lab updagtes

* dv lab updates

* dv lab updates

* dv lab updates

* dv lab updates

* adb dv lab

* adb dv updates

* adb dv lab update

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dv lab updates

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.2

* dbseclab-v6.3

* dbseclab_v6.3

* dbseclab_v6.3

* dbseclab_v6.3

* dbseclab_v6.3

* dbseclab_v6.3

* ocw24 dv hol

* dv hol ocw

* dv ocw hol

* dbseclab_v6.3

* dbseclab_v6.4

* dbseclab_v6.4

* dbseclab_v6.3

---------

Co-authored-by: Hakim LOUMI <[email protected]>
Co-authored-by: Dan Wiliams <[email protected]>
Co-authored-by: richardcevans <[email protected]>
Co-authored-by: Ana-Maria COMAN <[email protected]>
  • Loading branch information
5 people authored Aug 14, 2024
1 parent 5746e31 commit 3fa190f
Show file tree
Hide file tree
Showing 3 changed files with 10 additions and 1,229 deletions.
8 changes: 3 additions & 5 deletions database/advanced/key-vault/key-vault.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ This lab assumes you have:

| Task No. | Feature | Approx. Time | Details |
|--|------------------------------------------------------------|-------------|--------------------|
| 1| (Mandatory) Prerequisites | <10 minutes||
| 1| Encrypt database with TDE (Mandatory) | <10 minutes||
| 2| Add an Endpoint | <10 minutes||
| 3| View the Contents of the OKV Virtual Wallet | <5 minutes||
| 4| Upload the TDE Wallet | 5 minutes | To backup the Oracle Wallet into Oracle Key Vault |
Expand All @@ -46,11 +46,9 @@ Advanced OKV Labs for 21.7
| D| Automated Java Keystore rotation | 5 minutes ||
-->

## Task 1: (Mandatory) Prerequisites
## Task 1: Encrypt database with TDE (Mandatory)

**Before beginning this lab**, make sure you have performed steps 1 to 4 of the Transparent Data Encryption (TDE) Livelabs!

If you didn't execute them yet, do it right now by following the instructions below:
To enable you to learn about Oracle Key Vault for TDE key management, you need an encrypted database (steps 1 to 4 of the Transparent Data Encryption (TDE) Livelabs):

1. Open a Terminal session on your **DBSec-Lab** VM as OS user *oracle*

Expand Down
9 changes: 7 additions & 2 deletions database/baseline/sqlfw/sqlfw.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ This workshop introduces the functionality of Oracle SQL Firewall. It gives the
*Version tested in this lab:* Oracle Database 23ai Free

### Video Preview
Watch a preview of "*Introducing SQL Firewall – a new security capability in Oracle Database 23ai*" [](youtube:81N23MDhYXU)
Watch a preview of "*Introducing SQL Firewall – a new security capability in Oracle Database 23ai*" [DB Security - SQL Firewall](videohub:1_gbm8p6ba)

### Objectives
- Train the SQL Firewall to learn the normal activity
Expand Down Expand Up @@ -264,6 +264,7 @@ In this task you will learn how the administrator trains the system to learn the

- Associate the SQL Firewall violation policy to your target database

- Ensure that your compartment is selected, otherwise please click on "**Change Compartment**"
- Select **Selected targets only (up to 10)** and choose *`DBSeclabs_DB23ai-freepdb1`*
- Select **Selected policies only** and choose *`SQL Firewall violations`*

Expand Down Expand Up @@ -442,6 +443,8 @@ Let's assume there is a malicious insider who had access to the stolen credentia
![SQLFW](./images/sqlfw-074a.png "Violation reports sub-menu")
- Ensure that your compartment is selected, otherwise please change it accordingly
- Click on the **All violations** report
![SQLFW](./images/sqlfw-074b.png "Violation reports - All violation")
Expand Down Expand Up @@ -573,6 +576,8 @@ Here, we will enable the SQL Firewall to block on detection of unauthorized SQL
![SQLFW](./images/sqlfw-074a.png "Violation reports sub-menu")
- Ensure that your compartment is selected, otherwise please change it accordingly
- Click on the **All violations** report
![SQLFW](./images/sqlfw-074b.png "Violation reports - All violation")
Expand Down Expand Up @@ -1038,4 +1043,4 @@ Technical Documentation:
## Acknowledgements
- **Author** - Hakim Loumi, Database Security PM
- **Contributors** - Angeline Dhanarani
- **Last Updated By/Date** - Hakim Loumi, Database Security PM - July 2024
- **Last Updated By/Date** - Hakim Loumi, Database Security PM - August 2024
Loading

0 comments on commit 3fa190f

Please sign in to comment.