Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Activity monitoring and database security

By Thomas VanHorn , Network World , 10/02/2007
This vendor-written tech primer has been edited by Network World to eliminate product promotion, but readers should note it will likely favor the submitter's approach.

Over 158 million personal data records have been exposed since February 2005. There is no question that databases are under attack. No longer satisfied with defacing Web sites or committing other malicious acts, today’s attackers are increasingly targeting the database, where they can harvest data en mass and sell that data for financial gain.

Attacks from insiders are also on the rise. Forrester Research estimates that over 70% of database breaches are internal. As security breaches transition from random hackers to planned, organized assaults on enterprise data, organizations are increasingly identifying such activity through the use of real-time activity monitoring focused at the database.

An important component of monitoring for suspicious activity is the correct targeting and proper identification of varied insider threats. A successful security plan requires an understanding of the varied nature of these threats. As interconnectivity and on-demand access to information have become more and more integral to the daily operation of business, the definition of insiders has been expanded to include several types of users:

Authorized users: Employees — clerks, accountants, finance, salespeople, purchasing and others. Essentially anyone who has been given access to data or systems within a given enterprise.

Privileged users: Individuals with elevated privileges, broad access and extensive database knowledge, including database administrators, developers, quality assurance, contractors and consultants.

Knowledge users: Employees with access to and knowledge of systems or security protocols such as IT operations, network operations, security personnel and audit personnel.

Outsiders with insider access and/or vulnerability knowledge: The sophisticated white-collar criminal.

Due to the varied nature of insiders, it is no longer sufficient to monitor privileged users exclusively. Security best practices mandate the monitoring of privileged activity regardless of user. By focusing activity monitoring on all relevant activity performed by all types of users, an enterprise can mitigate risk more effectively and protect database assets from breach and attack.

Addressing the threat of both internal and external database attacks requires increased and ongoing visibility of all database activity. Comprehensive database-monitoring solutions actively view, aggregate and report on database communications within the enterprise. Many solutions also incorporate business requirements such as auditing and compliance, and alert on potential security or regulatory violations.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

Dear Nurse: Putting aside your rudeness I will agree: The Museum of the American Cocktail is, as far...- Mark Gibbs

Join the Discussion