Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Data Detectives

Finding that network and application security isn't enough, companies are turning to software that monitors database activity and provides an audit trail.

November 14, 2005 12:00 PM ET

Computerworld - At McCarron International Airport in Las Vegas, virtually every detail of airport operations is stored in one of 14 Oracle Corp. or Microsoft Corp. database servers. Passenger data, personnel files, flight information, airport security data—all of that plus volumes of other sensitive information are housed in the databases. Any unauthorized change to or theft of that data could have severe consequences for the airport.


So naturally, when Phillip Murray, McCarron's departmental systems administrator, receives a request from airport security to look into a suspicious transaction, he takes it very seriously. Until recently, he might have devoted days, or even weeks or months, to scouring log files and SQL statements to investigate questionable activity on a database. "I'd have to carefully piece together events," he says. "It's a matter of browsing through thousands of transactions."


Today, however, Murray spends a lot less time analyzing log files thanks to a database activity auditing and monitoring tool—SQL Guard from Guardium Inc. in Waltham, Mass. The software tracks database access and transactions, sending alerts when unusual activities are spotted. If Murray needs to analyze an event more closely, SQL Guard provides an audit trail of the relevant commands and transactions.


"It's been an immense timesaver," says Murray.


While much of today's application-level security is automated with third-party tools, the databases behind these applications are often not so secure. The assumption is that attacks will occur from outside and be caught by the firewall or the log-in and authorization process of the application. Databases, it is presumed, are too far into the back office to be threatened by a direct attack.


"Traditionally, databases are deep in the organization, so it's hard for somebody to directly nail the database server," says Rich Mogull, research vice president at Gartner Inc. "But more organizations are now concerned about their own systems administrators and other employees, not just external attackers, and that's where these tools are the most valuable."


Concern about data security has been heightened by media reports of thefts of consumer data, as well as financial fraud by employees. Government regulations, such as the Sarbanes-Oxley Act, have also emphasized the need to closely audit access to sensitive data. And, of course, for organizations that serve the public—like McCarron Airport—the terrorist attacks of Sept. 11, 2001, significantly heightened security fears.


"Since 9/11, we had to start looking at our vulnerabilities. Despite the fact that we do rigorous background checks, there's a possibility that someone might come in and gather data that would make the airport easier to attack," says Murray.



Additional Resources

POLL RESULTS
Accelerate your knowledge of the IT world you inhabit by viewing the results of a series of polls taken by your IT peers. These polls of 100+ IT professionals each are available for full viewing. They cover key topics such as virtualization, processor performance, green IT, cloud computing and many others. Be a part of the buzz.
WHITE PAPER
Technology is complex. Keeping it running productively shouldn't be. To that end, you want to minimize the number of solutions needed in-house to simplify operations, maintenance, and support. Kodak offers a best-practices model. One company provides support for both scanner and software, for fast problem resolution without vendor finger-pointing. Download now!
WHITE PAPER
Utilizing demand intelligence improves the precision of pricing, product assortments, channel/store placement, and promotion, which are all essential for sustainable revenue management performance. Learn more, download this free whitepaper today.

White Papers & Webcasts

Tech Horizons: ASG's metaCMDB, The Technology That Rocks
Improved business productivity often requires more efficient IT and more efficient IT cannot be achieved without a better understanding of the way business...  

Strategic ECM Webinar
Learn what new strategic business benefits can be realized through ECM!...

An SMB's Guide to ECM Software
Learn how to choose an ECM solution that helps increase productivity, provide better customer service, and automate time-consuming, paper-based processes....  

Improving Quality of Service for Oracle Database with My Oracle Support
(Source: Oracle) Oracle's Willie Hardie and Oracle Support Expert Sean Bingham discuss how My Oracle Support optimizes the quality of support provided to...

Protecting Content During Business Disruption: Are You Covered?
Learn how ECM is helping Tulane University and the 13th Judicial Circuit Court implement disaster readiness programs....  

Managing And Protecting Your Ever Increasing Mobile Assets
Learn best practices for desktop and application virtualization, computer security, and computer life-cycle management....

Selecting a Practical ECM Solution: Critical Considerations
Learn how to put together your content management strategy from the ground up!...  

5 Architecture Issues that Impact BES performance
This Live webinar will identify critical log file errors, performance counters, and configurations to pay close attention to when optimizing BES server performance....

Creating a Complete ECM Solution - DocuShare and Sharepoint
Learn the pros and cons of using a single ECM solution versus combining the portal functionality of SharePoint....  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

 

SAS Information Management Kit

SAS is the leader in business intelligence and analytical software and services. Only SAS offers leading data integration, storage, analytics and business intelligence applications within a comprehensive enterprise intelligence platform. SAS gives 97 of the top 100 companies in the 2007 Fortune 500 THE POWER TO KNOW®.

Webcast: The Information Management Roadmap
Imagine high-quality data, cleansed, analyzed and delivered throughout your organization. Join Computerworld, IT visionary Thornton May and a panel of experts to learn how SAS® can help you make it happen.

View this webcast 
Research Report: Information Management Initiatives at Midsize and Large Organizations
See the top-line results of this Computerworld sponsored survey to see how IT and business leaders are handling information management implementation.

Download this report 
White Paper: Information Management: Better Information for Winning Decisions.
This white paper explains how the SAS Information Evolution Model aids companies in assessing how they use this information to make strategic decisions and drive business.

Download this white paper