Welcome Guest. | Log In | Register | Membership Benefits

Imperva Expands SecureSphere

Adds agent-based monitoring and auditing for DB2 z/OS mainframe databases

Mar 09, 2011 | 11:43 AM | 


Redwood Shores, CA – March 8, 2011 – Imperva, the leader in data security, today announced the availability of SecureSphere 8.5, which extends protection from insider threat with enhanced SecureSphere Agent Technology for file and database activity throughout the IT infrastructure. SecureSphere 8.5 extends Imperva’s award-winning data security solution, combining network monitoring and local monitoring via agents to provide support for data platforms including Windows file servers and mainframe databases as well as optimized local agent performance and management experience.

“Network-based file activity monitoring alone cannot peer into local console-based access and may not be cost-effective for remote locations, creating blind spots for many enterprises,” explained Neil MacDonald VP and Gartner Fellow. “Comprehensive file monitoring must support both agent and network-based approaches for complete coverage.”

SecureSphere 8.5 adds Windows File Server agents as a deployment option. Agents can be used in conjunction with SecureSphere File Security appliances to optimize deployments based on network topology and business needs. Key capabilities include:

Enables privileged user monitoring and separation of duties through visibility into administrative and all other local activity;

Provides clear visibility into user identities and access activity in encrypted networks;

Supports efficient auditing of distributed file servers in multiple data centers or branch offices.

In addition, SecureSphere 8.5 will include new agent-based monitoring and auditing for DB2 z/OS mainframe databases. The mainframe agent delivers a comprehensive and efficient solution for auditing database activities and addressing regulatory requirements related to critical mainframe systems. Key capabilities include:

Complete visibility into critical operations, including: SELECTS, DML and DDL, privileged activities and DB2 utilities;

Offloads processing to zIIP processors to minimize impact on total cost of mainframe computing;

Generates real-time alerts on policy violations and security events;

Fully integrated into the SecureSphere suite for cross-platform audit management.

Finally, SecureSphere 8.5 optimizes agent-based monitoring and auditing for open systems databases. The SecureSphere database agents are designed to minimize monitoring overhead and are deployed and upgraded without the need to restart target databases. SecureSphere architecture scales to support large number of agents delivering thousands of transactions per second of audited data. Agent-based monitoring can cover local traffic or all traffic and can be combined with network based monitoring for highly optimized database security deployment.

“With this release, Imperva expands the industry’s most comprehensive data security suite,” said Imperva CTO Amichai Shulman. “With our agent technology, Imperva gives enterprises the most complete solution to protect data as it moves from database to files and applications.”

SecureSphere 8.5 is available immediately for customer deployments. Certain features are scheduled for release in Q2 2011; please contact Imperva Sales for further information. About Imperva

Imperva is the global leader in data security. With more than 1,300 direct customers and 25,000 cloud customers, Imperva's customers include leading enterprises, government organizations, and managed service providers who rely on Imperva to prevent sensitive data theft from hackers and insiders. The award-winning Imperva SecureSphere is the only solution that delivers full activity monitoring for databases, applications and file systems. For more information, visit www.imperva.com, follow us on Twitter or visit our blog.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Database Security Reports

report Securing The Data Warehouse
Many enterprises are building data warehouses to centralize the ever-increasing information flowing through their organizations into useful repositories. This makes good business sense, but it opens up a slew of concerns from a security standpoint. IT professionals can apply many of the same security best practices used with databases, but there are new lessons to be learned as well.

report Defend Your Data From Malicious Insiders
The biggest threat to your company?s most sensitive data may be the employee who has legitimate access to corporate databases but less-than-legitimate intentions. And while the incidence of insider data breaches has decreased, external attacks often imitate them--and do serious damage. Follow our advice to mitigate the risk.

report Ensuring Secure Database Access
Role-based access control based on least user privilege is one of the most effective ways to prevent the compromise of corporate data. But proper provisioning is a growing challenging, due to the proliferation of "big data," NoSQLdatabases, and cloud-based data storage.

Other reports from the Database Security Tech Center:

Related Content

Establishing a Strategy for Database Security is No Longer Optional
As databases continue to grow in size, complexity and importance, enterprises struggle to identify the most appropriate controls regarding their use and misuse. The report identifies best practices, including: Implementing database activity monitoring to mitigate the high levels of risk from database vulnerabilities, and address audit findings in areas such as database segregation of duties and change management; using data security measures, such as data masking and data encryption; and monitoring privileged-user access and access to critical data.

Database Activity Monitoring Is Evolving Into Database Audit and Protection
In this report, Gartner writes that "Database audit and protection (DAP) represents an evolutionary advance in database activity monitoring tools." DAP suites provide comprehensive, cross-platform support in heterogeneous database environments to protect sensitive data from inappropriate use. Organizations are increasingly concerned with optimizing database security and mitigating risks associated with database vulnerabilities.

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
Data security presents a multi-dimensional challenge in today's complex IT environment. Multiple access paths and permission levels have resulted in a broad array of security threats and vulnerabilities. We invite you to read this new eBook: "Protecting against database attacks and insider threats" to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Demo: Distributed Database Security with Real-time Monitoring and Audit Protection
Organizations across the globe continue to experience compromised data caused by malicious attacks, web application vulnerabilities or unauthorized changes. View this demo and learn how IBM InfoSphere Guardium? database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Look Beyond Native Database Auditing To Improve Security, Audit Visibility, And Real-Time Protection
Today's attacks on enterprise databases are more sophisticated than ever, and they occur so fast that it's often difficult to stop them in real time. Despite significant efforts to protect enterprise databases, the number of records breached has grown each year - due to all types of internal and external attacks and violations of corporate policy.




Featured Webcasts
Featured Whitepapers
Featured Reports