hp gen10 oracle12c,Oracle 12c new feature: Unified Audit

Unified Audit is a

major architectural change: fast, easy, and impossible for the DBA

to bypass. On upgrade to Oracle 12c, you really should enable it.

The earlier method that we all use is pretty awful.

Consider the

standard audit that we all know. In particular, consider how bad

the implementation really is. First, performance. Awful. If you

configure audit for an action (UPDATE on a table, for example) when

a session does an UPDATE on that table, the session has to write

the audit record. In effect, this is an autonomous transaction: the

session has to stop what it is doing, write a row to SYS.AUD$,

generating redo and undo as it does this, and COMMIT. Then it can

return to the work it was meant to be doing. That's a pretty bad

hit on the performance of the statement. Second, think about how

secure the audit trail really is. Anything written to the SYS.AUD$

table can changed by the DBA. That isn't very secure, is it? Sure,

you can audit to the OS instead. And then the SysAdmin can remove

it, which isn't much better. Furthermore, reading those OS audit

records is an awful job. They are slow to write, too.

Unified audit solves both these problems. First, performance. It is

astronomically fast. Why? because the session doesn't write the

audit record to the table. All it does is put a message on a

buffered queue. The performance hit of writing the record to the

table and generating the undo and redo is taken by a background

process, GEN0, which creates the audit record asynchronously with

respect to the calling action. Removing the writing of audit from

the calling session solves the performance problem. Second, the

audit table really is impossible to hack. Not even SYS can bypass

the controls.

Here's how to do

it:

1. Relink the

Oracle executable.

On Windows, copy in the appropriate DLL:

cd %ORACLE_HOME%\bin

copy orauniaud12.dll.dbl orauniaud12.dll

and restart the Windows service for all instances.

On Unix,

relink:

cd $ORACLE_HOME/rdbms/lib

make -f ins_rdbms.mk uniaud_on ioracle

and restart your Oracle instances.

2. Configure

Unified Audit policies

You need a role to do this, AUDIT_ADMIN. Just a simple example: the

equivalent of AUDIT UPDATE ON SCOTT.EMP and AUDIT CREATE ANY

TRIGGER by users SYS and SYSTEM is,

orclz>

orclz> create audit policy mypol1

2 privileges create any trigger

3 actions update on scott.emp;

Audit policy created.

orclz>

orclz> audit policy mypol1 by sys,system;

Audit succeeded.

orclz>

3. Query the audit trail

The audit trail is exposed through the view UNIFIED_AUDIT_TRAIL.

You need a role to see this, AUDIT_VIEWER. Then:

orclz>

orclz> select dbusername,event_timestamp,sql_text from unified_audit_trail

2 where unified_audit_policies='MYPOL1';

DBUSERNAME EVENT_TIMESTAMP SQL_TEXT

---------- ------------------ ---------------------------------------------------

SYSTEM 10-MAY-14 11.58.45 update scott.emp set sal=1000 where ename='KING'

SYS 10-MAY-14 12.01.06 create trigger scott.trig after update on scott.emp

begin

null;

end;

orclz>

4.What about security? The audit table is in a new Oracle maintained schema, and not even

SYS can tamper with it:

orclz>

orclz> conn / as sysdba

Connected.

orclz> select table_name from dba_tables where owner='AUDSYS';

TABLE_NAME

--------------------

CLI_SWP$67b5bb1a$1$1

orclz> delete from audsys."CLI_SWP$67b5bb1a$1$1";

delete from audsys."CLI_SWP$67b5bb1a$1$1"

*

ERROR at line 1:

ORA-55941: DML and DDL operations are not allowed on table "AUDSYS"."CLI_SWP$67b5bb1a$1$1"

orclz> drop user audsys cascade;

drop user audsys cascade

*

ERROR at line 1:

ORA-28050: specified user or role cannot be dropped

orclz>

The only way to trim the audit trail is with the DBMS_AUDIT_MGMT

package, access to which can be limited with the usual

discretionary access control. And, of course, any operation against

the audit trail is itself audited.

All together,

Unified Audit is an important new feature, and a good motivator for

the 12c upgrade.

--

John Watson

Oracle Certified Master DBA

http://skillbuilders.com

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
自动控制节水灌溉技术的高低代表着农业现代化的发展状况,灌溉系统自动化水平较低是制约我国高效农业发展的主要原因。本文就此问题研究了单片机控制的滴灌节水灌溉系统,该系统可对不同土壤的湿度进行监控,并按照作物对土壤湿度的要求进行适时、适量灌水,其核心是单片机和PC机构成的控制部分,主要对土壤湿度与灌水量之间的关系、灌溉控制技术及设备系统的硬件、软件编程各个部分进行了深入的研究。 单片机控制部分采用上下位机的形式。下位机硬件部分选用AT89C51单片机为核心,主要由土壤湿度传感器,信号处理电路,显示电路,输出控制电路,故障报警电路等组成,软件选用汇编语言编程。上位机选用586型以上PC机,通过MAX232芯片实现同下位机的电平转换功能,上下位机之间通过串行通信方式进行数据的双向传输,软件选用VB高级编程语言以建立友好的人机界面。系统主要具有以下功能:可在PC机提供的人机对话界面上设置作物要求的土壤湿度相关参数;单片机可将土壤湿度传感器检测到的土壤湿度模拟量转换成数字量,显示于LED显示器上,同时单片机可采用串行通信方式将此湿度值传输到PC机上;PC机通过其内设程序计算出所需的灌水量和灌水时间,且显示于界面上,并将有关的灌水信息反馈给单片机,若需灌水,则单片机系统启动鸣音报警,发出灌水信号,并经放大驱动设备,开启电磁阀进行倒计时定时灌水,若不需灌水,即PC机上显示的灌水量和灌水时间均为0,系统不进行灌水。
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值