˙Guardium 首次發表針對阻擋特權使用者存取機密敏感資料的解決方案 - 橫跨且支援所有主要的DBMS平台
May 23, 2008
˙Guardium 獲選為「Red Herring北美100強」的殊榮
May 22, 2008
˙Guardium 獲選為「American Business Awards」的決選入圍者
May 21, 2008
Read more
˙資訊安全焦點新聞
˙精選資安知識庫
 
 
 
 
Guardium / RetiShieid / Identity Management
Guardium為您所有的應用程式及資料庫結構中所需的安全防護,提供了最簡潔有力的解決方案,包括:
˙ Real-time database activity monitoring (DAM)
資料庫即監控DAM:主動積極的偵測辨示出未經授權,或可疑的資料庫存取活動
  ˙Privileged User Monitoring 特定授權使用者監控
˙Application User Monitoring 應用程式使用者監控
˙Preventing External Attacks 預防外部網路攻擊


Application User Monitoring
應用程式使用者監控
Multi-tier enterprise applications such as Oracle EBS, PeopleSoft, J.D. Edwards, SAP, Siebel, Business Intelligence, and in-house systems contain an organization’s most sensitive financial, customer, employee, and intellectual property information.

These systems are the most difficult to secure because they are highly distributed and designed to allow Web-based access from insiders and outsiders, such as customers, suppliers, and partners.

In addition, multi-tier enterprise applications mask the identity of end-users at the database transaction level using an optimization mechanism known as “connection pooling.” Using pooled connections, the application aggregates all user traffic within a few database connections that are identified only by a generic service account name.? As a result, organizations find it challenging to associate specific database transactions with particular application end-users.

The primary purpose of application-layer monitoring is to detect fraud (and other abuses of legitimate access) that occurs via enterprise applications, rather than via direct access to the database.? This level of monitoring is often required for data governance requirements such as SOX. New auditor guidance from the Public Company Accounting Oversight Board for Sarbanes-Oxley compliance has also increased the emphasis on anti-fraud controls.

Guardium’s application monitoring technology resolves application user-IDs by observing all interactions between applications and database servers at the network and OS level—from outside the database.? The information is then incorporated into all Guardium queries, reports, audit processes, alerts, and policies.

Highlights

˙ Identifies application users associated with specific database queries and transactions
˙ Meets auditor requirements to comprehensively monitor and report on all access to sensitive information, regardless of its origin
˙ Generates detailed audit logs for application user activities, including identifying information about user roles/responsibilities
˙ Supports creation of policies and real-time alerts for specific conditions (e.g., when particular user IDs access sensitive tables or privacy sets)
˙ Supports pure HTTP-based Web applications as well as applications using other presentation-layer protocols (such as Oracle EBS and SAP R/3)
˙ Supports Single Sign On (SSO) environments
˙ Uses deterministic methods to positively identify users rather than statistical or other approximate methods, which are not valid for auditing and forensic purposes

 

 
 
Opportunity 人才聘用 / Partners 合作夥伴 / Privacy Policy 隱私權條款 / Site Map 網站地圖