Archive

Archive for September, 2011

Data Loss Prevention VS Infosphere Guardium

September 30th, 2011

Data loss Protection (DLP) emphasis in three things:

  • Protect data in use (endpoint actions). This term is related to data theft which being used like attached on emails, Instant messaging, etc.
  • Protect data in motion. This term is related to data when it is being transferred. It means how to protect data when it’s still on the network.
  • Protect data at rest. This term is related to data when it is already stored on laptop, sharing folder, flashdisk, etc.

This DLP security technology:

  • Can’t stop data theft at the source –in the data center
  • Lacks database-focused monitoring, analytics & blocking
  • No knowledge about DBMS commands, vulnerabilities & structures

Infosphere Guardium is a leak prevention solution emphasis how to prevent the leakage right into the source itself where the data is stored—Database on Data Center. This solution supported eight database vendor and using three essential technologies:

  1. Data Extrusion Monitoring. To monitor all inbound requests to the database and all returned data to detect any transactions that violate policy or represent unusual activity
  2. Database Access Prevention. Uniquely offers a wide range of actions to prevent inappropriate transactions in real-time, ranging from automatic transaction blocking and user quarantine, to real-time alerts and extended auditing.
  3. Auto-Discovery. Automated mechanisms to find and classify sensitive data, including new instances created by developers, administrators and users.

In summary, Infosphere Guardium is part of DLP which offers more specific in database leak prevention.
For more info, please visit:

http://www-01.ibm.com/software/data/guardium/prevent-database-leaks/

http://en.wikipedia.org/wiki/Data_loss_prevention_software

Database Tools , ,

IBM Infosphere Guardium

September 28th, 2011

Sekedar sharing saja. Kemarin (27/9/2011) Saya menyempatkan diri untuk datang ke workshop IBM Guardium, dan di bawah ini adalah FAQ dari product itu sendiri.

Apa itu Guardium?
Guardium adalah Real-Time Database Activity Monitoring Appliance. Tools ini berguna untuk mencari jejak ancaman pengaksesan informasi kepada tabel-tabel yang krusial pada Data Center suatu perusahaan (Peoplesoft, ERP, DWH, dll). Guardium merupakan product IBM yang baru masuk ke Indonesia meski di Malaysia dan Singapura merupakan product yang tergolong laku keras.

Bagaimana Guardium Bekerja?
Guardium memiliki agent dan collector. Agen diinstall di setiap database server dan berfungsi untuk melakukan monitoring dan mengirimkan data kepada collector. Sedangkan Collector merupakan appliance yang berfungsi sebagai penganalisa dan menampilkan informasi ancaman dengan web-based GUI.

Fitur yang menarik?
Opini Saya, Guardium kurang lebih sama dengan tools database monitoring lainnya. Yang menarik adalah Guardium memiliki prebuild fungsi pelaporan yang comply dengan SOX dan PCI-DSS sehingga cukup menarik bagi perusahaan tbk.

IBM Infosphere Guardium

Untuk lebih jelasnya dapat sowan ke link berikut:
http://www-01.ibm.com/software/data/guardium/

Database Tools , ,