SlideShare a Scribd company logo
Oracle Solaris Secure Cloud Infrastructure
Copyright	©	2015, Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Secure	Cloud	Infrastructure
Secure,	Compliant,	Highest	Performing
Scott	Lynn	&	Darren	J	Moffat
Solaris	Core	Technologies
January	2016
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
200M	
Experian
Mar	‘14
150M
eBay
May	‘14
22M
Education
July	‘14
SA	Banks
OCT	‘13
Credit	
Cards
150M	+	Code
Adobe	Oct	‘13
98M
Target
Dec‘13
20M
Credit	Bureau
12M
Telecom
Jan	‘14
56M
Home	Depot
Sep	‘14
Immigration
June’14
Personal
Records
76M
JPMC
Oct	‘14
The	Age	of	Mega	Breaches
3Copyright	©	2015,	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
53M
Sony
Dec	‘14
227M
80M
Anthem
Feb	‘15
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Social	Attacks
Command	&	
Control
Brute	Force	
Hacking
Malware
SQL	Injection	
Attack
Stolen	Credentials
Typical	Attack	Vectors
4Copyright	©	2015,	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
COMMAND
SERVER
ATTACKER
DOWNLOADED
MALWARE
PHISHING
ATTACK
XSS	OR	SQL	
INJECTION
ATTACK
Anatomy	of	an	Attack	– Starts	with	Phishing
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
ESTABLISH	MULTIPLE
BACKDOORS		
DUMPING	PASSWORDS
DOMAIN	CONTROLLER
GATHERING	
DATA
Anatomy	of	an	Attack	– Establishes	a	Foothold
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
EXFILTRATE	DATA	
VIA	STAGING	SERVER
ANYWHERE
IN	THE	WORLD
Anatomy	of	an	Attack	– Exfiltrates	Data,	Covers	Tracks.
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Risks	are	Outside;	Vulnerabilities	Within
8
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Threat	#1:Stolen	privileged	user	credentials
People
9
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
100%
Of	investigated	data	breaches	
involved	stolen	credentials
10
Source:	Mandiant	Threat	Report,	2015
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|Oracle	Corporation	- Confidential 11Oracle	Company	Confidential	– Shared	Under	Terms	of	OPN	NDA 11
How	the	Sony	Breach	Changed	Security
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Oracle	Solaris	Mitigates	Credential	Abuse/Misuse
Delegation
Activity-based	user	access
Time-Based	Control
Control	when	users	can	
perform	actions
Remote	Auditing,	
Logging	and	Alerting
Audit	entries	sent	to	secure	
server;	can’t	be	tampered
12
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Threat	#2:Unpatched	and	misconfigured	
systems
Platform
13
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
99.9%Of	the	exploited	vulnerabilities	
were	compromised	more	than	
a	year	after	the	CVE	was	
published
14
Source:	Verizon	Data	Breach	Investigations	Report,	2015
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Exploited	Vulnerabilities	Compromised
15
74%
OF	ORGANIZATIONS
TAKE	3	MONTHS+
TO	PATCH
Source:	Verizon	Data	Breach	Investigations	Report,	2015;	IIOUG	Data	Security	Survey,	2014
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
The	age	of	
“If	it	ain’t	broke,	don’t	fix	it,”	
is	over!
16
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		| 17
It’s	important	to	patch	quickly	and	often…
Patching	on	other	systems	takes	significant	time	and	money.	
Firmware
Virtualization
OS
Database
Application Other	Systems:
• Different	tools
• Different	patches
• Possible	conflicts
• Downtimes
• Manual	Rollback
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Dramatically	Simpler	Lifecycle	Management
Solving	patching	and	configuration	vulnerabilities.
1818
Firmware
Virtualization
OS
Database
Application
Oracle	Solaris:
• Secure
• Pre-tested
• Single-source	
patching.
1-Step	Security	Patching1-Step	Rollback
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Simple	Administration
Major	Financial	Customer’s	Experiences	Patching	Oracle	Solaris	vs.	Red	Hat
19
Red	Hat
Enterprise	Linux
Solaris	11
16X
Servers/Admin
MANAGE
4000300020001000
250
4000
Machines/Administrator
1-Step	Security	Patching
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Simple	&	Tailorable Compliance	Reporting
20
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Stop	Malware	Before	It	Gets	In
Immutable	Systems	and	Virtual	
Machines
– Can’t	establish	a	foothold
– Prevent	administrator	mistakes
– Update	even	though	it’s	unwritable
by	users	and	applications
Tamper	Evident	Software
– Firmware	to	Applications	
– Install	only	known,	trusted	software
– Not	signed;	won’t	install
– Verified	Boot
21
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Secure	Lifecycle	Done	Right
Secure
• Immutable	Systems	and	Virtual	
Machines
• Tamper	Evident	Software
• Verified	Boot
Simple
• 1-step	patching
• Integrated	snapshots
• 1-step	rollback
Effective
• Tested	together
• From	firmware	to	
applications
22
Firmware(
Virtualiza.on(
OS(
Database(
Applica.on(
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Large	City	in	Germany
Automatic	Patching
23
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Threat	#3:Direct	data	access
Data
24
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
$194*
The	average	cost	per	record	
stolen	in	a	data	breach.
25
Source:	Symantec	http://www.databreachcalculator.com/GetStarted.aspx
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
52%
34%
11%
4%
Database
Network	
Application
Middleware
IT	Layers	Most	Vulnerable	To	Attacks
67%
15%
15%
3%
Database
Network	
Application
Middleware
Allocation	of	Resources	To	Secure	IT	Layer
Source:	CSO	Online	MarketPulse,	2013	
Network	Security	is	Not	Enough:		Protect	the	Data!
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Only	Platform	to	Protect	Applications	in	Memory
Silicon	Secured	Memory
• First	ever	hardware	based	memory	
protection
• Stops	attackers	from	accessing	
application	memory	inappropriately
• Always	on	without	compromise	
• Improved	efficiency	&	more	secure	
and	higher	available	applications
• Compatible	with	current	applications
27
Application Memory
Pointer	“B”
GO
M7	Processor
Pointer	“A”
GO
Pointer	“Y”
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
• No	performance	loss
• Automatically accelerates	Java,	Oracle	
Database,	OpenSSL/TLS,	and	custom	
applications
• Meet	compliance	with	high	performance	
disk	encryption	
• SPARC	M7	Silicon	Secured	Memory
• Integrates	with	Oracle	Key	Manager
28
Affordably
Encrypt	Everything,	Everywhere,	All	the	Time
Applications
Java
Oracle	Database
Operating	
System	Utilities
Storage
Virtualization
Firmware
Protected	at	rest,	in	motion,	and	in	memory
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
New	Exploit	mitigation	features:	sxadm(1M)
NXSTACK
Non	Executable	Stack
Been	around	since	Solaris	2.6	but	now	controlled	via	sxadm(1M)
Now	on	by	default
Tag	at	build	time	with:	-z	nxstack=enable|disable
NXHEAP
Non	Executable	Heap
New	in	11.3,		not	enabled	by	default	since	there	are	a	small	number	of	
legitimate	uses	for	an	executable	HEAP.
Tag	at	build	time	with:	-z	nxheap=enable|disable
ASLR	
Address	Space	Layout	
Randomisation
Added	11.1
sxadm	get	-p Parsable	status	output
sxadm	delcust Go	back	to	vendor	delivered	defaults
Install	Time	Policy svccfg extract	security-extensions
29
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Modernising	Firewall	in	Oracle	Solaris	11.3
• OpenBSD PF	firewall	ported	and	integrated	into	Oracle	Solaris
• Choose	either	IPfilter or	PF	– only	one	can	be	active
– pkg:/network/firewall
– pkg:/network/firewall/ftp-proxy
– pkg:/network/firewall/pflog
• Rules	in	pf.conf(4)
• Logging	is	via	new	dladm(1M)	controlled	links
• SMF	svc:/network/firewall
• Start	Transition:	IPfilter is	now	Obsolete	&	may	be	removed	in	a	future	
release
30
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Modernising SSH
• Oracle	Solaris	9	added	first	OpenSSH version,	become	forked	SunSSH over	time.
• OpenSSH (+	some	patches)	in	Oracle	Solaris	11.3
– GSS	credential	storage
– PAM	Service	Name	per	SSH	userauth method	as	per	SunSSH (PAM	can’t	be	disabled)
– DisableBanneroption	for	ssh client
• Install	either	SunSSH or	OpenSSH or	both
– only	one	can	be	default	ssh(1)	and	sshd(1M)	,	either	or	both	can	be	installed
– Set	default	via	pkg mediator	when	both	installed
• SMF	svc:/network/openssh
• Start	Transition:	SunSSH is	now	Obsolete	&	may	be	removed	in	a	future	release
31
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Oracle	Security	Inside	and	Out
Layers	of	the	Stack
Oracle	Corporation	- Confidential 32
S EC UR I TY
S EC UR I TY
S EC UR I TY
S EC UR I TY
S EC UR I TY
S EC UR I TY
S E C U R I T Y
Governance	Risk	&	Compliance	
Access	&	Certification	Review,	Anomaly	Detection,
User	Provisioning,	Entitlements	Management		
Mobile	Security,	Privileged	Users
Directory	Services,	Identity	Governance	
Entitlements	Management,	Access	Management
Encryption,	Masking,	Redaction,	Key	Management
Privileged	User	Control,	Big	Data	Security,	Secure	Config
Application	+	User	Sandboxing,	Delegated	Admin
Anti-malware	system,	Data	+	Network	Protection
Compliance	Reporting,	Secured	App	Lifecycle	
Secure	Live	Migration
Immutable	Zones	
Independent	Control	Plane
Cryptographic	Acceleration	
Application	Data	Integrity
Verified	Boot	
Disk	Encryption,	
Secured	Backup,
Enterprise	Key	Management
SPARC/Solaris
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		| 33
BUILT-IN SECURITY INSIDE AND OUT SAVES
TIME, MONEY AND REDUCES RISK
Mitigates	credential	
abuse/misuse
Secure	lifecycle	done	right
Encrypt	everything,	everywhere,	
all	the	time
Copyright	©	2015	Oracle	and/or	its	affiliates.	All	rights	reserved.		|
Q&A
34
Copyright	©	2014	Oracle	and/or	its	affiliates.	All	rights	reserved.		| 35
Oracle Solaris Secure Cloud Infrastructure

More Related Content

PPTX
Extending Hortonworks with Oracle's Big Data Platform
PDF
Oracle Data Integration - Overview
PPTX
Expand a Data warehouse with Hadoop and Big Data
PDF
2010.03.16 Pollock.Edw2010.Modern D Ifor Warehousing
PPTX
Building a marketing data lake
PDF
Oracle Data Integration CON9737 at OpenWorld
PPTX
OData External Data Integration Strategies for SaaS
PDF
2009.10.22 S308460 Cloud Data Services
Extending Hortonworks with Oracle's Big Data Platform
Oracle Data Integration - Overview
Expand a Data warehouse with Hadoop and Big Data
2010.03.16 Pollock.Edw2010.Modern D Ifor Warehousing
Building a marketing data lake
Oracle Data Integration CON9737 at OpenWorld
OData External Data Integration Strategies for SaaS
2009.10.22 S308460 Cloud Data Services

What's hot (20)

PPTX
Oracle's BigData solutions
PDF
Unlocking Big Data Silos in the Enterprise or the Cloud (Con7877)
PDF
Data Integration for Big Data (OOW 2016, Co-Presented With Oracle)
PDF
Oracle Solaris Build and Run Applications Better on 11.3
PDF
Tapping into the Big Data Reservoir (CON7934)
PPTX
Big data and its impact on SOA
PDF
Intelligent Integration OOW2017 - Jeff Pollock
PDF
Flash session -goldengate--lht1053-lon
PDF
One Slide Overview: ORCL Big Data Integration and Governance
PDF
Oracle PL/SQL 12c and 18c New Features + RADstack + Community Sites
PPTX
Tame Big Data with Oracle Data Integration
PPTX
Journey to Marketing Data Lake [BRK1098]
PPTX
Klarna Tech Talk - Mind the Data!
PDF
Oracle Enterprise Metadata Management
PDF
Oracle Stream Analytics - Developer Introduction
PDF
Moving OBIEE to Oracle Analytics Cloud
PDF
Creando un Portal Oracle para una Empresa
PDF
"Changing Role of the DBA" Skills to Have, to Obtain & to Nurture - Updated 2...
PPTX
Biwa summit 2015 oaa oracle data miner hands on lab
PDF
Accelerate Return on Data
Oracle's BigData solutions
Unlocking Big Data Silos in the Enterprise or the Cloud (Con7877)
Data Integration for Big Data (OOW 2016, Co-Presented With Oracle)
Oracle Solaris Build and Run Applications Better on 11.3
Tapping into the Big Data Reservoir (CON7934)
Big data and its impact on SOA
Intelligent Integration OOW2017 - Jeff Pollock
Flash session -goldengate--lht1053-lon
One Slide Overview: ORCL Big Data Integration and Governance
Oracle PL/SQL 12c and 18c New Features + RADstack + Community Sites
Tame Big Data with Oracle Data Integration
Journey to Marketing Data Lake [BRK1098]
Klarna Tech Talk - Mind the Data!
Oracle Enterprise Metadata Management
Oracle Stream Analytics - Developer Introduction
Moving OBIEE to Oracle Analytics Cloud
Creando un Portal Oracle para una Empresa
"Changing Role of the DBA" Skills to Have, to Obtain & to Nurture - Updated 2...
Biwa summit 2015 oaa oracle data miner hands on lab
Accelerate Return on Data
Ad

Viewers also liked (20)

PDF
Oracle Solaris Overview
PDF
Oracle Solaris Software Integration
PDF
Oracle Solaris Cloud Management and Deployment with OpenStack
PDF
Oracle Solaris Simple, Flexible, Fast: Virtualization in 11.3
PPTX
Georgia Azure Event - Scalable cloud games using Microsoft Azure
PPTX
Accelerating Business Intelligence Solutions with Microsoft Azure pass
PDF
OpenPOWER Roadmap Toward CORAL
PDF
The State of Linux Containers
PDF
OpenPOWER Update
PDF
IBM POWER8 as an HPC platform
PDF
Presentacin webinar move_up_to_power8_with_scale_out_servers_final
PPTX
Bitcoin explained
PPTX
Blockchain
PDF
Open Innovation with Power Systems
PDF
IBM Power8 announce
PPTX
Puppet + Windows Nano Server
PPTX
Expert summit SQL Server 2016
PDF
IlOUG Tech Days 2016 - Big Data for Oracle Developers - Towards Spark, Real-T...
PDF
The Quantum Effect: HPC without FLOPS
PDF
IlOUG Tech Days 2016 - Unlock the Value in your Data Reservoir using Oracle B...
Oracle Solaris Overview
Oracle Solaris Software Integration
Oracle Solaris Cloud Management and Deployment with OpenStack
Oracle Solaris Simple, Flexible, Fast: Virtualization in 11.3
Georgia Azure Event - Scalable cloud games using Microsoft Azure
Accelerating Business Intelligence Solutions with Microsoft Azure pass
OpenPOWER Roadmap Toward CORAL
The State of Linux Containers
OpenPOWER Update
IBM POWER8 as an HPC platform
Presentacin webinar move_up_to_power8_with_scale_out_servers_final
Bitcoin explained
Blockchain
Open Innovation with Power Systems
IBM Power8 announce
Puppet + Windows Nano Server
Expert summit SQL Server 2016
IlOUG Tech Days 2016 - Big Data for Oracle Developers - Towards Spark, Real-T...
The Quantum Effect: HPC without FLOPS
IlOUG Tech Days 2016 - Unlock the Value in your Data Reservoir using Oracle B...
Ad

Similar to Oracle Solaris Secure Cloud Infrastructure (20)

PPTX
kill-chain-presentation-v3
PDF
MITRE ATT&CKcon Power Hour - November
PDF
The “Security” in Oracle’s Secure Cloud Infrastructure
PDF
Security Opening Keynote Address: Security Drives DIGITAL TRANSFORMATION in...
PPTX
How to Predict, Detect and Protect Against Mobile Cyber Attacks
PDF
Delta g ric_consulting_presentation_erpscan_2015
PDF
GenAI Risks & Security Meetup 01052024.pdf
PPTX
Mobile Security - 2015 Wrap-up and 2016 Predictions
PPTX
Web Application Security
PDF
Oracle mobile cloud service
PDF
Advanced Authentication: Past, Present, and Future
PDF
MultiValue Security
PPTX
Con8817 api management - enable your infrastructure for secure mobile and c...
PPTX
Con8896 securely enabling mobile access for business transformation - final
PPTX
Black Duck & IBM Present: Application Security in the Age of Open Source
PPTX
LSI Spring Agent Open House 2014
PPTX
DeltaGRiC_Consulting_SMAC_Digital Innovation Security Conference_Presentation...
PDF
DefCamp_2016_Chemerkin_Yury_--_publish.pdf
PPTX
Let's Talk Mobile
PDF
What You Need to Know About SaaS Application Data Protection
kill-chain-presentation-v3
MITRE ATT&CKcon Power Hour - November
The “Security” in Oracle’s Secure Cloud Infrastructure
Security Opening Keynote Address: Security Drives DIGITAL TRANSFORMATION in...
How to Predict, Detect and Protect Against Mobile Cyber Attacks
Delta g ric_consulting_presentation_erpscan_2015
GenAI Risks & Security Meetup 01052024.pdf
Mobile Security - 2015 Wrap-up and 2016 Predictions
Web Application Security
Oracle mobile cloud service
Advanced Authentication: Past, Present, and Future
MultiValue Security
Con8817 api management - enable your infrastructure for secure mobile and c...
Con8896 securely enabling mobile access for business transformation - final
Black Duck & IBM Present: Application Security in the Age of Open Source
LSI Spring Agent Open House 2014
DeltaGRiC_Consulting_SMAC_Digital Innovation Security Conference_Presentation...
DefCamp_2016_Chemerkin_Yury_--_publish.pdf
Let's Talk Mobile
What You Need to Know About SaaS Application Data Protection

More from OTN Systems Hub (10)

PDF
Oracle super cluster m7
PDF
Oracle super cluster for oracle e business suite
PDF
Oracle engineered systems executive presentation
PDF
Using oracle vm virtual box as your development platform
PDF
Rapid private cloud with oracle vm and oracle openstack for oracle linux
PDF
Oracle vm engineered for open cloud
PDF
Oracle making openstack an enterprise grade solution
PDF
Oracle develop in virtual box deploy to the cloud
PDF
Oracle business continuity for virtualization and cloud infrastructure
PDF
Oracle Solaris Application-Centric Lifecycle and DevOps
Oracle super cluster m7
Oracle super cluster for oracle e business suite
Oracle engineered systems executive presentation
Using oracle vm virtual box as your development platform
Rapid private cloud with oracle vm and oracle openstack for oracle linux
Oracle vm engineered for open cloud
Oracle making openstack an enterprise grade solution
Oracle develop in virtual box deploy to the cloud
Oracle business continuity for virtualization and cloud infrastructure
Oracle Solaris Application-Centric Lifecycle and DevOps

Recently uploaded (20)

PDF
top salesforce developer skills in 2025.pdf
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PPT
Introduction Database Management System for Course Database
PPTX
Online Work Permit System for Fast Permit Processing
PPTX
history of c programming in notes for students .pptx
PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PPTX
Operating system designcfffgfgggggggvggggggggg
PDF
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PDF
How to Choose the Right IT Partner for Your Business in Malaysia
PDF
PTS Company Brochure 2025 (1).pdf.......
PDF
How Creative Agencies Leverage Project Management Software.pdf
PDF
How to Migrate SBCGlobal Email to Yahoo Easily
PDF
Understanding Forklifts - TECH EHS Solution
PPTX
Transform Your Business with a Software ERP System
PDF
AI in Product Development-omnex systems
PPTX
ManageIQ - Sprint 268 Review - Slide Deck
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
top salesforce developer skills in 2025.pdf
Design an Analysis of Algorithms II-SECS-1021-03
Design an Analysis of Algorithms I-SECS-1021-03
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
Introduction Database Management System for Course Database
Online Work Permit System for Fast Permit Processing
history of c programming in notes for students .pptx
Which alternative to Crystal Reports is best for small or large businesses.pdf
Operating system designcfffgfgggggggvggggggggg
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
Wondershare Filmora 15 Crack With Activation Key [2025
How to Choose the Right IT Partner for Your Business in Malaysia
PTS Company Brochure 2025 (1).pdf.......
How Creative Agencies Leverage Project Management Software.pdf
How to Migrate SBCGlobal Email to Yahoo Easily
Understanding Forklifts - TECH EHS Solution
Transform Your Business with a Software ERP System
AI in Product Development-omnex systems
ManageIQ - Sprint 268 Review - Slide Deck
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025

Oracle Solaris Secure Cloud Infrastructure