Oracle puts database security controls beneath AI agents
Database security controls are moving closer to enterprise data as artificial intelligence creates new access paths around traditional application defenses. The aim is to enforce authorization regardless of which application, user or agent reaches the database.
That shift is part of Oracle Corp.’s broader security strategy to protect data at its source, speed security updates and improve resilience. It also requires organizations to look beyond encryption, according to Vipin Samar (pictured, left), senior vice president of Database Security at Oracle.
“[Databases] are the crown jewels of your company, and you’re investing all the money surrounding it. So why not really make sure that your data itself is protected, is patched, is secured?” he said. “People also think that, ‘I’ve got encryption, am I not covered?’ I tell them security is not synonymous with encryption.”
Samar spoke alongside David Knox (right), vice president of Database Security product management at Oracle, with theCUBE Research’s Dave Vellante and co-host Krista Case at Oracle’s “AI Cyberattacks Are Escalating: How to Secure Your Data Now” event, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed database security controls, application guardrails and tools for managing security across database fleets. (* Disclosure below.)
Database security controls move below the application
Oracle’s Secure at Source approach places encryption, access controls and other protections inside the database rather than relying on individual applications to enforce them, according to Samar. Using the database as a common enforcement point allows permissions to follow the user and data across different applications and agent access paths.
“We really cannot depend upon agents to enforce their own security,” Samar said. “No matter how you get in, through any agent you want, any swarm of agents you want, we are going to limit you to only what you’re authorized to get.”
An Oracle demonstration during the discussion showed how an indirect prompt could bypass application guardrails and expose salary data. When access restrictions were enforced inside the database, the same prompt could no longer retrieve the protected information.
“I want to design something that’s consistent and constant, irrespective of why something bad happened,” Knox said. “It doesn’t really matter at the end of the day. I have a provable way I always guard the data.”
Fleet-wide visibility closes security gaps at scale
Applying database security controls consistently becomes more difficult when organizations operate hundreds or thousands of databases across cloud and on-premises environments. Oracle Data Safe provides cloud-based security assessment and monitoring. At the same time, Oracle Database Security Central gives customers a unified, self-managed view of users, sensitive data, configurations and policies across the fleet, Samar explained.
“The bigger challenge is that security has to be — not around one database, but across your fleet,” he said. “AI can move very easily and naturally from one database to the other. We have to have [a] full 360-degree view across [the] entire fleet, across your users, across your data. Only then can you really have effective security.”
Fleet-wide visibility can help organizations identify configuration drift, excessive privileges and inconsistent policies before those gaps are exploited. Oracle’s database security portfolio combines that centralized posture management with protections applied during database access, according to Knox.
“You really can’t do it from the outside. You have to be inside to really understand how these things are executing,” he said. “We sit right there every time somebody executes a query, a SQL, we intercept that and we run it through all of the security capabilities.”
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Oracle’s “AI Cyberattacks Are Escalating: How to Secure Your Data Now” event:
(* Disclosure: TheCUBE is a paid media partner for Oracle’s “AI Cyberattacks Are Escalating: How to Secure Your Data Now” event. Neither Oracle, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
Photo: SiliconANGLE
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.