Oracle shifts agent controls toward data-layer security
Data-layer security is becoming more important as automated systems gain broader access to sensitive information and business processes. Controls designed for predictable applications may not be enough when agents can interact directly with enterprise data.
Artificial intelligence is also accelerating the discovery of software vulnerabilities, increasing pressure on companies to patch systems and update older products. Oracle Corp. is using multiple models to examine its own code while urging customers to keep database environments current, according to Juan Loaiza (pictured), executive vice president of Oracle Database Technologies at Oracle.
“AI is literally superhuman at finding security vulnerabilities, and it’s also superhuman at how fast it does it and how many it does,” Loaiza said. “We’ve had security teams for literally decades working on securing our product, and yet AI is finding hundreds of security issues. It’s very scary and kind of crazy, like nothing I’ve ever seen before.”
Loaiza spoke with theCUBE Research’s Dave Vellante at Oracle’s “AI Cyberattacks Are Escalating: How to Secure Your Data Now” event, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed data-layer controls, faster security updates and recovery planning for agentic systems. (* Disclosure below.)
Data-layer security puts the database in charge
Application logic has traditionally determined which information users can see and what transactions they can perform. Oracle’s data-centric security strategy moves those controls closer to the data so they apply consistently across applications and agents, Loaiza noted.
“The question is, how fast can you go without the big risk of [the AI] leaking data … or it damaging your data, which is going to get you in even bigger trouble?” he said. “You got to go fast, but you have to trust the result. Our solution to that is you have to move that trust layer as low as possible.”
That approach can also reduce the security work placed on individual developers. Oracle Deep Data Security enforces authorization at the row, column and cell level based on user identity and runtime context, limiting the data available to an agent even if an application is compromised or a prompt is manipulated, according to Loaiza.
“That’s one of the big vulnerabilities with AI: You think that you know what it’s going to do, but people are very clever about how they can phrase things in order to make AI do things that you would have basically thought you had prevented by prompting the AI,” he said. “If, at that data layer, we enforce that each end user can only see their data, then no matter what kind of prompt you put … the agent that’s acting on behalf of that user can only see that user’s data.”
Recovery planning assumes the breach gets through
Data-layer security can’t eliminate every threat, so recovery must be part of the security architecture. Organizations need to isolate trusted backups and prepare to restore operations without carrying malicious code or hidden access points into the rebuilt environment, according to Loaiza.
“I’d like to tell you that our technology is 100% perfect, that it will never be breached. I can’t tell you that,” he said. “You have to be prepared to deal with what happens the minute after you find out you’ve been breached.”
Oracle’s Zero Data Loss Recovery Appliance protects database transactions in real time, validates backup integrity and supports rapid restoration. Those capabilities reflect a broader shift from treating security as a periodic update cycle to continuously limiting exposure and preparing for disruption, Loaiza noted.
“This is not a sprint,” he said. “The pipeline of issues, it’s not over by a long shot. We’ve entered into a new world, a new reality.”
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Oracle’s “AI Cyberattacks Are Escalating: How to Secure Your Data Now” event:
(* Disclosure: TheCUBE is a paid media partner for Oracle’s “AI Cyberattacks Are Escalating: How to Secure Your Data Now” event. Neither Oracle, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
Photo: SiliconANGLE
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.