Presentation is loading. Please wait.

Presentation is loading. Please wait.

Security Testing of Oracle Interfaces using MFT process

Similar presentations


Presentation on theme: "Security Testing of Oracle Interfaces using MFT process"— Presentation transcript:

1 Security Testing of Oracle Interfaces using MFT process
Swikruti Mohapatra, Sowmya Narayanarao & Vinay Kammar | FAI

2 Abstract This presentation outlines the security features of MFT and how it helps in Security Testing Security testing is a testing technique to determine if an information system protects data and maintains functionality as intended.  Overview of Oracle MFT :  Oracle Managed File Transfer (MFT) is a high performance, standards-based, end-to-end managed file gateway which is designed from the bottom up to make it easy for organizations to manage, monitor and secure file transfers. It protects against inadvertent access to unsecured files at every step in the end-to-end transfer of files  This presentation outlines how we can achieve greater agility and accelerate DevOps QA strategy This presentation outlines how we can achieve greater agility and accelerate. Applications.

3 Oracle MFT and Security features:
Oracle Managed File Transfer (MFT) enables secure file exchange and management with internal departments and external partners. You can protect data in your DMZ by using the SSH/FTP reverse proxy. The MFT console includes transfer prioritization, file encryption, scheduling, and embedded FTP and sFTP servers. Security is maintained with security policies such as OWSM (Oracle Web Service Manager). KEY FEATURES:- End to End Auditability, Control and Reporting Built-in Security, Identity management, LDAP and PGP encryption Compression, Scheduling and fully extensible file handling framework Extensive endpoint support: embedded SSH, FTP, File, SOAP Very well Integrated with SOA and B2B Highly available and clustered including a DMZ reverse proxy Protects files with end to end security System consolidation, cost savings and multi-platform Enables cloud adoption for large files

4 Oracle Managed File Transfer Process
You can perform various operations, such as scheduling, file encryption, resubmitting transfers, purging data, and many more such operations by using Oracle Managed File Transfer. Oracle Managed File Transfer lets you perform the following operations during the transfer process: Scheduling Resubmitting Attaching inline or referencing Compression and decompression Encryption and decryption Archiving, renaming, and deletion Purging transfer instances and files Pausing and resuming Securing with OWSM policies

5

6 Oracle Managed File Transfer Architecture
The main components of Oracle Managed File Transfer includes configuration data, the user-interface console, embedded FTP and sFTP servers, security, and interfaces to various types of file transfer endpoints. Oracle Managed File Transfer can consist of multiple managed servers that provide high availability Figure: Oracle Managed File Transfer Architecture

7 Attributes of security testing:
Authentication: The origin of the application and its data is genuine. Authorization: Specific users should only get access to authorized functions. Confidentiality: Data/information is secure from theft. Integrity: The application and its data is not altered in course of time during transmission. Non repudiation: Guarantee that sender and receiver of information cannot deny having sent or received the data. In the end, security testing makes applications reliable and minimizes the risk of theft or misuse of confidential data.  The goal of security testing is to identify the threats in the system and measure its potential vulnerabilities. It also helps in detecting all possible security risks in the system and help developers in fixing these problems through coding.

8 We deliver several benefits through our Security Testing Service:
Testing focused on the business priorities to ensure business runs as usual Reduced spends on managing breaches and their consequences Enhanced ability to collaborate with external sources (vendors, developers, customers) Security Audit Security testing control and scope in Oracle using MFT: Oracle MFT has a build in feature of notification/alert for different kind of events which keeps the system secured and the users informed of any data transfer. It is well equipped with the system which gives us an alert in case of any failed transfer. Notifications can be tailored to notify users as a part of security business requirements.  MFT provides a huge benefit in security audit as it provides detailed information on each transfer including: file name, partner name, endpoint name, transfer status, compression or encryption. It keeps records of all actions on the servers, which can be used for troubleshooting or turned in for audits which is required to prove that a company has displayed adequate accountability for its data.  High level of security using LDAP and PGP encryption

9 Encryption and Decryption process

10 MFT Process used in FAI MFT helps to automatically send/receive the files to/from Third party without any manual intervention. It transfers the files from Oracle outbound directory to third party server or transfers file from third party server to Oracle inbound directory. It picks the file as soon as it comes to the location and transfers to third party and it can be scheduled to process the files as per business requirement. Figure: Process flow of Outbound interface

11 References & Appendix

12 Author Biography Qualification: B.Tech Total 4 years of Experience in IT Industry 2.5 years of work Experience as an Oracle apps Consultant across PTP and Financial modules. Work responsibilities included Critical Batch monitoring, working on priority Oracle SR’s to provide customer solutions, Currently working as a QA Engineer with responsibilities of writing test scenarios, Developing Automation test scripts using OATS, Involved in various end-to-end testing across Oracle Modules.

13 Q & A

14 Logo of your organization


Download ppt "Security Testing of Oracle Interfaces using MFT process"

Similar presentations


Ads by Google