![]() |
Data security and privacy: A holistic approach Download here |
McAfee is in the process of acquiring database activity monitoring (DAM) vendor Sentrigo for an undisclosed sum. McAfee expects the deal to be complete in the first part of April, at which time it will provide more details on its strategic vision of how to bundle the product within the Risk and Compliance business unit. The announcement was a bit of a surprise to an industry segment that is no stranger to rumors of acquisition: It's just that Sentrigo was not part of the rumor mill.
Sentrigo was a relatively late entrant into the database security market. Unlike other firms that started out as database assessment or auditing vendors, or with some other technology like Web application firewalls, Sentrigo was one of the few that's sole focus was on database monitoring.
When Sentrigo launched, data breaches were in the media on a weekly basis. In 2004 the U.S. Secret Service "Insider Threat Report" lead most of us to believe that rogue employees were the problem we needed to address. DAM technologies of this time period were designed specifically to deal with IT admins and database administrators -- privileged users, if you will -- who were stealing data. Sentrigo focused on the ability to capture database transactions in a way that bypassed the database administrator altogether: by scanning the database memory.
What sets Sentrigo apart is the method by which its technology collects SQL queries. It does this by periodically scanning the database memory and collecting new queries the database receives. Just like other DAM products, new queries are examined and generate an alert if a policy is violated. Most competitors have an agent that collects queries at the OS layer as they are sent to the database. Most vendors offer secondary collection options, such as network data and audit trail capture, but Sentrigo does not.
Memory scanning technology is actually fairly tough to develop and get right, so there was a lot of initial investment into the core capabilities of data collection and analysis. This is why Sentrigo was known as an Oracle security tool for a number of years as it focused on monitoring select versions of Oracle. Over time, Sentrigo has developed scanning for the other major database platforms, and expanded its feature set to include assessment capabilities.
Sentrigo is one of the first vendors to offer what is called "virtual patching" -- halting queries that match known attack patterns in the event a security patch is unavailable or not yet installed. As we have learned, when hackers exploit credentials, SQL injection flaws, and insecure database features, blocking malicious queries is a core requirement regardless if it comes from an insider or outsider.
What this means for McAfee is that it closes a hole in its data center security offerings. While McAfee is known for network, endpoint, and content security, its policy and vulnerability management systems are not enough. McAfee lacked application layer protections for enterprise customers. DAM is one of the top requests enterprise customers are asking for, and Sentrigo is a good fit because it finally hit a point in product maturity that it can cover not only the minimum platform coverage needed to compete in the DAM market, but also all of the workflow, reporting, and user management requirements of enterprise customers. While Sentrigo trails several competitor products in terms of depths and breadth of coverage, McAfee can dedicate the resources to close the gaps.
All in all, this is a solid acquisition for McAfee and gives it a nice offering for data center security.
Adrian Lane is an analyst/CTO with Securosis LLC, an independent security consulting practice. Special to Dark Reading.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Securing The Data Warehouse
Many enterprises are building data warehouses to centralize the ever-increasing information flowing through their organizations into useful repositories. This makes good business sense, but it opens up a slew of concerns from a security standpoint. IT professionals can apply many of the same security best practices used with databases, but there are new lessons to be learned as well.
Defend Your Data From Malicious Insiders
The biggest threat to your company?s most sensitive data may be the employee who has legitimate access to corporate databases but less-than-legitimate intentions. And while the incidence of insider data breaches has decreased, external attacks often imitate them--and do serious damage. Follow our advice to mitigate the risk.
Ensuring Secure Database Access
Role-based access control based on least user privilege is one of the most effective ways to prevent the compromise of corporate data. But proper provisioning is a growing challenging, due to the proliferation of "big data," NoSQLdatabases, and cloud-based data storage.
Other reports from the Database Security Tech Center:
| Sponsored by: |
Establishing a Strategy for Database Security is No Longer Optional
As databases continue to grow in size, complexity and importance, enterprises struggle to identify the most appropriate controls regarding their use and misuse. The report identifies best practices, including: Implementing database activity monitoring to mitigate the high levels of risk from database vulnerabilities, and address audit findings in areas such as database segregation of duties and change management; using data security measures, such as data masking and data encryption; and monitoring privileged-user access and access to critical data.
Database Activity Monitoring Is Evolving Into Database Audit and Protection
In this report, Gartner writes that "Database audit and protection (DAP) represents an evolutionary advance in database activity monitoring tools." DAP suites provide comprehensive, cross-platform support in heterogeneous database environments to protect sensitive data from inappropriate use. Organizations are increasingly concerned with optimizing database security and mitigating risks associated with database vulnerabilities.
Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
Data security presents a multi-dimensional challenge in today's complex IT environment. Multiple access paths and permission levels have resulted in a broad array of security threats and vulnerabilities. We invite you to read this new eBook: "Protecting against database attacks and insider threats" to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
Demo: Distributed Database Security with Real-time Monitoring and Audit Protection
Organizations across the globe continue to experience compromised data caused by malicious attacks, web application vulnerabilities or unauthorized changes. View this demo and learn how IBM InfoSphere Guardium? database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.
Look Beyond Native Database Auditing To Improve Security, Audit Visibility, And Real-Time Protection
Today's attacks on enterprise databases are more sophisticated than ever, and they occur so fast that it's often difficult to stop them in real time. Despite significant efforts to protect enterprise databases, the number of records breached has grown each year - due to all types of internal and external attacks and violations of corporate policy.
MORE NEWSFEED >>>