fhs
Volume 12, Number 1 -- January 10, 2012

CCSS Helps Detects Fraud with New Database Monitor

Revised: January 11, 2012

by Alex Woodie

It's a well established fact that the majority of fraud reported by companies is not perpetrated by hackers coming in over the Net, but is actually the work of employees and other insiders with access to internal systems. Combating this type of fraud requires a multi-pronged approach, including strong security configurations and powerful tools. The IBM i world just got another fraud-fighting tool last month when CCSS announced the availability of its new database monitoring solution.

The new database monitoring capabilities were delivered as part of QMessage Monitor (QMM) version 7, a major new release of CCSS' real-time message monitoring software for the IBM i server. QMM has always had coverage for QAUDJRN, where many critical IBM i messages are displayed, and which provided a degree of security protection. But with version 7, QMM now gains a new database monitoring component that notifies IT managers in real time when unauthorized activity occurs in DB2/400 (DB2 for IBM i).


Users can manage the new database monitoring capabilities in QMM verion 7 through this GUI.

While the QAUDJRN coverage shows some attempts at fraud, IBM i shops will get a much more detailed picture of fraudulent activity with the new database monitor in QMM, CCSS says. With properly configured detection rules, the new database monitoring feature will show IT managers the exact users, files, libraries, and IP addresses that are involved in fraudulent activity.

The new security capability will be useful for adding an additional layer of protection on particularly sensitive files, such as payroll and personal employee data, says CCSS product manager Paul Ratchford. "There's tremendous value in being able to pin-point the exact files, libraries, users and IP addresses they are interested in," he says in a press release. "Suspicious activity has no place to hide on the system."

The new software is configured by setting up client lists, behavior rules, and escalation lists. The client list can be a single IP address or a range of IP addresses. The behavior rules cover various activities that can be performed on an entire database file or a particular record (such as reading, writing, deleting, or updating); actions performed on file members; the setting of a library list; and using SQL to access DB2/400. Finally, the escalation lists control which IT manager gets notified when a breach is detected.

When a breach is detected, the software kicks into action. CCSS gives the example of an unauthorized user who has selected all of the records in a payroll file. Soon after the user takes this action, QMM would send the IT manager an alert message that gives him details of the activity, including the user, action, file details, and job details. Additional information available includes the parameters and rules associated with the user and their client list, including the top three programs in the call stack and the SQL command actually run when SQL access is being used, CCSS says.

All of this information is automatically generated soon after the actual breach, which makes QMM an effective tool for auditors as it reduces the time required to investigate possible breaches.

QMM 7.0 is available now. For more information, see the vendor's website at www.ccssltd.com.


RELATED STORIES

CCSS Targets Security Issues in 'Best Practices' Guide

CCSS Digs Deeper Into the Audit Journal to Yield Clues

CCSS Adds Syslog Support to QMessage Monitor/a>

Love's Likes CCSS for PCi

CCSS Addresses SOX Requirements in QMessage Monitor

CCSS Boosts Problem Resolution in QMessage Monitor

Message Monitoring Software from CCSS Gets Tighter Security



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
NEW GENERATION SOFTWARE

Interested in query and BI software but want to learn more
before you speak to a salesperson or get
your team together for a demo?

Visit NGS' FREE on demand video library
for online education ranging from short tutorials
to advanced presentations.

Discover NGS-IQ's graphical, point-click development environment;
features for Microsoft Excel, Word, and Access users;
integrated Web reporting, drill down and export options;
OLAP; mobile features for smartphone and tablet users;
email; FTP; security; and options for accessing
remote data sources like SQL Server and MySQL.

Watch our videos any time, then ask for a
FREE Proof-of-Concept or Trial.

Call 800 824-1220. Visit www.ngsi.com


Editor: Alex Woodie
Contributing Editors: Dan Burger, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

Databorough:  Get ready for modernization or upgrades with X-Analysis 9.5
Guild Companies:  The All-Everything Operating System, by Brian Kelly, Price $35
CCSS:  Achieving Lights Out Automation in an IBM i environment. Get the Best Practice guide


 

IT Jungle Store Top Book Picks

BACK IN STOCK: Easy Steps to Internet Programming for System i: List Price, $49.95

The iSeries Express Web Implementer's Guide: List Price, $49.95
The iSeries Pocket Database Guide: List Price, $59
The iSeries Pocket SQL Guide: List Price, $59
The iSeries Pocket WebFacing Primer: List Price, $39
Migrating to WebSphere Express for iSeries: List Price, $49
Getting Started with WebSphere Express for iSeries: List Price, $49
The All-Everything Operating System: List Price, $35
The Best Joomla! Tutorial Ever!: List Price, $19.95


 
The Four Hundred
The World Is Not Going To End In 2012

Rocket Software Buys iCluster HA Biz From IBM

IBM Delivers Open Source Version of EGL Tools

As I See It: Punxsutawney Blue

A Little .NET Can Go A Long Way

Four Hundred Guru
I Was Just Wondering. . .

End-of-Year Odds and Ends

Admin Alert: Hidden Parameters of the Submit Job Command

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
January 7, 2012: Volume 14, Number 1

December 31, 2011: Volume 13, Number 17

December 24, 2011: Volume 13, Number 16

December 17, 2011: Volume 13, Number 15

December 10, 2011: Volume 13, Number 14

December 3, 2011: Volume 13, Number 13

TPM at The Register
US economy hands IT a mixed bag in December

Enterprise and govt chief Bell exits Dell

Amazon cloud double fluffs in 2011

Cisco enlists NCR in Middle East, Africa server push

Gartner chops 2012 IT spending forecast

Cray's Q4 whacked by AMD's Opteron delays

New CEO Rometty tweaks IBM exec lineup

Apache lets fly Hadoop 1.0 data muncher

IBM buys Green Hat for virty dev tools

Chip sales sag says semiconductor seller survey

Big cloud Internap eats little cloud Voxel

Oracle VM whips rowdy virtual machines into submission

THIS ISSUE SPONSORED BY:

Databorough
New Generation Software
Townsend Security
IntelliChief
RJS Software Systems


Printer Friendly Version


TABLE OF CONTENTS
Zend Updates PHP Server Stack for IBM i

CCSS Helps Detects Fraud with New Database Monitor

ARCAD Adds New Testing Features to ALM Suite

Linoma Adds Enterprise Features to MFT Software

Applied Logic Gives FEU New Printing and Zip Functions

News Briefs and Product Shorts:

RJS Goes Single Sign-On with i OS App . . . RPG & DB2 Summit: Skills Fitness for Modern IT . . . Beverage Company Taps IntelliChief for Forms Software . . . Infor Touts Growth, Makes an Acquisition . . . IBM Updates Software Inventory and Usage Tool . . .

Four Hundred Stuff

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2012 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement