The CRM Community for Customer Relationship Management solutions. Daily News, White Papers, Events, and Software Buyer's Guides.
 
     
Sentrigo Brings End-User Accountability to Enterprise Databases with Hedgehog IDentifier PDF Print E-mail
Posted by Don Panek - CRMDirectory Editor   
Sentrigo Brings End-User Accountability to Enterprise Databases with Hedgehog IDentifier

New Hedgehog Enterprise Add-on Module Associates Database Actions with Individual Users in Pooled Connection Environments

WOBURN, Mass.--Sentrigo, Inc., an innovator in database security software, today announced Hedgehog IDentifier, a new module designed for Hedgehog Enterprise customers. Based on patent-pending technology, Hedgehog IDentifier allows security professionals and auditors to identify the individual application users who perform actions in the database in pooled-connection environments. The software takes the end-user ID and context information transparently from application servers and injects that information into the database connection, making Hedgehog IDentifier the only product of its type that is entirely accurate.

The most commonly used n-tier architectures sever the link between database actions and end-users due to the use of pooled connections between the application and the database. For example, once users sign in to applications such as financials or CRM, application servers present users to the database in aggregate, effectively sharing database connections for individuals actions. This approach precludes audits from tracing changes in the database back to specific users and makes it difficult to enforce security policies that assign privileges to people, not applications.

A recent Gartner report states: Application monitoring is complicated by the use of connection pooling in multi-tier architectures. Connection pooling implements a common connection between the application server and the DBMS, which is used by the application server for all requests to the DBMS. From the DBMS perspective, all database access appears to be from a single service account. Fraud detection requires analysis with user context.1

Hedgehog IDentifier can be installed on any of the commonly used Java application servers, including IBM WebSphere, BEA WebLogic, Oracle iAS, JBoss and Apache Tomcat. Once installed, it passes user ID information through the database connection rather than rely on error-prone correlation and heuristic methods. Furthermore, the Hedgehog Enterprise rules engine can then allow or restrict access or issue alerts based on the real identity of the user making the request.

Slavik Markovich, chief technology officer at Sentrigo, said: The ability to tie identity to behavior is critical in providing full traceability and accountability of individual users. In developing Hedgehog IDentifier, we solve a security and compliance problem raised by most customers using multi-tier applications. While it is possible to modify every application to include user ID API calls to the database, such an approach requires source code, development effort and ongoing maintenanceHedgehog IDentifier provides an elegant solution with no overhead.

Hedgehog Enterprise is a host-based software product that uses sensors that reside on the database host to monitor all activity. It is highly configurable, allowing administrators to fine-tune their security policy. Hedgehog Enterprises flexibility has allowed Sentrigo to create products such as Hedgehog IDentifier that take advantage of the highly granular visibility into database operations.

Hedgehog Enterprise, which now includes Hedgehog IDentifier, may be downloaded for a free trial from www.sentrigo.com.

About Sentrigo

Sentrigo, Inc. is an innovator in security software that monitors all database activity and protects sensitive information in real time in order to prevent both internal and external data breaches. Sentrigos Hedgehog software, including a free version, can be downloaded and easily installed to provide immediate protection against breaches, as well as virtual patching against recently discovered threatswith minimal impact on database performance. The products unparalleled level of protection, coupled with its ease of use, makes it the instant standard for database security and regulatory compliance. Sentrigo was named by Network World as one of the 10 IT security companies to watch in 2007. For additional information and to download Hedgehog, visit www.sentrigo.com.

 
< Prev   Next >

Members Login






Lost Password?
No account yet? Register

Free CRM Newsletter

New Page 1
E-mail
Name
Subscribe
Unsubscribe

Dynamics CRM Blog

Pages
    Blogroll
      Archives

      Get the News Feed!

      feed image

      Advertisement

      Creative Design Concepts