![]() |
Data security and privacy: A holistic approach Download here |
Locating all databases deployed within an enterprise and accounting for all sensitive data distributed across those databases is an essential component of an effective database security process control program. Over time, enterprises can lose track of their database inventory and become populated with forgotten and unauthorized databases. Often times, these “rogue” databases are not properly configured or secured. As a result, they create a security risk by providing attackers with an easy target that can be used to gain access to other databases containing sensitive data.
“Most organizations believe that they have a firm grasp on their database inventory, but almost every time we have scanned a network using our Active Discovery technology, we have turned up far more databases than the prospect or customer believed were present,” said Josh Shaul, Chief Technology Officer, AppSecInc. “The harsh reality is that database inventories at nearly all organizations are not up to date and it is an eye-opening revelation when organizations see the results of our scans.”
We Speak Database
Powered by a proprietary scanning methodology, DbProtect Active Discovery uses database protocol-based validation, rather than relying solely on simple port-based detection. The use of vendor-specific database language is the only way to ensure a completely accurate inventory of databases on the network.
This approach enables Active Discovery to:
Find all databases – whether they are communicating over the network or not.
Find databases on any port, not just default ports.
Initiate communication in vendor-specific protocols to confirm that a database has been discovered and identify the database platform.
By employing this unique set of capabilities, Active Discovery identifies every database by hostname, IP address, port, database type and version, and eliminates the risk of any database lingering unknown and posing a potential security risk.
Be Active, Not Passive
DbProtect Active Discovery employs active scanners which probe all ports on the network, not just database ports, ensuring that they locate and identify all databases. Passive database discovery solutions work by looking for SQL commands between applications and databases at various points on the network. This approach is severely limited in scope as it fails to identify databases that are not communicating over the network. Additionally, any database traffic that is not routed across the points in the network that are being monitored will not be discovered – and it’s impossible to monitor every point on the network all the time. The end result is an incomplete database inventory and a false sense of security generated by the passive database discovery approach.
“While designed as simple to use, DbProtect Active Discovery is based on very complex intellectual property created specifically to provide the high level of accuracy necessary to properly establish and maintain a complete database inventory and corresponding data security levels,” added Shaul.
“Companies need to be fully aware of the severe limitations and security challenges introduced by taking a passive approach to finding databases. It’s the most basic of all security principles. You simply cannot secure what you don’t know you have.”
DbProtect Active Discovery is generally available and included as part of the DbProtect 6.3 platform. For further information, please contact an AppSecInc sales representative at 1-866-9APPSEC or visit: http://www.appsecinc.com/products/dbprotect/.
About Application Security, Inc. AppSecInc is a pioneer and leading provider of database security solutions for the enterprise. By providing strategic and scalable software-only solutions – AppDetectivePro for auditors and IT advisors, and DbProtect for the enterprise – AppSecInc supports the database security lifecycle for some of the most complex and demanding environments in the world across more than 1,300 active commercial and government customers.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Securing The Data Warehouse
Many enterprises are building data warehouses to centralize the ever-increasing information flowing through their organizations into useful repositories. This makes good business sense, but it opens up a slew of concerns from a security standpoint. IT professionals can apply many of the same security best practices used with databases, but there are new lessons to be learned as well.
Defend Your Data From Malicious Insiders
The biggest threat to your company?s most sensitive data may be the employee who has legitimate access to corporate databases but less-than-legitimate intentions. And while the incidence of insider data breaches has decreased, external attacks often imitate them--and do serious damage. Follow our advice to mitigate the risk.
Ensuring Secure Database Access
Role-based access control based on least user privilege is one of the most effective ways to prevent the compromise of corporate data. But proper provisioning is a growing challenging, due to the proliferation of "big data," NoSQLdatabases, and cloud-based data storage.
Other reports from the Database Security Tech Center:
| Sponsored by: |
Establishing a Strategy for Database Security is No Longer Optional
As databases continue to grow in size, complexity and importance, enterprises struggle to identify the most appropriate controls regarding their use and misuse. The report identifies best practices, including: Implementing database activity monitoring to mitigate the high levels of risk from database vulnerabilities, and address audit findings in areas such as database segregation of duties and change management; using data security measures, such as data masking and data encryption; and monitoring privileged-user access and access to critical data.
Database Activity Monitoring Is Evolving Into Database Audit and Protection
In this report, Gartner writes that "Database audit and protection (DAP) represents an evolutionary advance in database activity monitoring tools." DAP suites provide comprehensive, cross-platform support in heterogeneous database environments to protect sensitive data from inappropriate use. Organizations are increasingly concerned with optimizing database security and mitigating risks associated with database vulnerabilities.
Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
Data security presents a multi-dimensional challenge in today's complex IT environment. Multiple access paths and permission levels have resulted in a broad array of security threats and vulnerabilities. We invite you to read this new eBook: "Protecting against database attacks and insider threats" to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
Demo: Distributed Database Security with Real-time Monitoring and Audit Protection
Organizations across the globe continue to experience compromised data caused by malicious attacks, web application vulnerabilities or unauthorized changes. View this demo and learn how IBM InfoSphere Guardium? database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.
Look Beyond Native Database Auditing To Improve Security, Audit Visibility, And Real-Time Protection
Today's attacks on enterprise databases are more sophisticated than ever, and they occur so fast that it's often difficult to stop them in real time. Despite significant efforts to protect enterprise databases, the number of records breached has grown each year - due to all types of internal and external attacks and violations of corporate policy.
MORE NEWSFEED >>>