fhs
Volume 9, Number 43 -- December 1, 2009

User Activity Monitoring from PacketMotion to Support i OS

Published: December 1, 2009

by Alex Woodie

System i shops that are concerned about the high level of access granted to systems administrators and others, but are hesitant to put controls in place for fear of slowing down transaction times, may want to consider trying out a new agent-less user activity monitoring (UAM) solution that is coming to the platform. PacketMotion recently rolled out support for TN3270 with its appliance-based UAM solution, called PacketSentry, and is close to beginning beta tests for a similar offering that will support the IBM i OS via TN5250.

The practice of over-allocating user credentials is a universal problem. It has been well documented in the System i world, where the majority of companies run with too many privileged user profiles, such as security administrator (SECADN) or all object authority (ALLOBJ), according to security vendor PowerTech's annual security survey.

The same kind of problem affects users of Windows, Unix, and mainframe servers, and customers are looking for solutions to deal with it, says Jonathan Gohstand, PacketMotion's vice president of marketing.

"I see people really grappling with this in the mainframe, and we're starting to see it on the AS/400 as well, because if they're using an application and the application doesn't have the proper logging, you're awfully limited it what you can do," Gohstand says. "You can go to the vendor and request them to add the logging. Good luck with that. Or if it's homegrown, nobody wants to touch the software because they're afraid they'll mess something up."

PacketMotion started developing PacketSentry about five years ago for the purpose of boosting user security. Along the way, the company added regulatory compliance to its repertoire. Today, the company's approach to development and marketing leans heavily on the fact that many organizations don't have the time or expertise to modify existing systems to improve security and achieve compliance with HIPAA, PCI, SOX, etc.

The PacketSentry solution basically monitors all of the actions that users--and "superusers" with special privileges in particular--take on critical systems for signs of suspicious or unauthorized activity, and stores that data in an integrated Oracle database that generates the required reports. Customers can also activate PacketSenry's security functionality and block unauthorized activity.

While it's a pre-loaded offering (and one that doesn't require a dedicated Oracle DBA, by the way), customers can customize their PacketSenry devices to meet their specific needs. For example, the customer could instruct the software to not let anybody to sign in using the systems administrator profile if they're coming in over VPN. Or user profiles used by outside contractors can be restricted to only allow access to certain machines, which will be heavily logged.

Most of PacketMotion's early customers have been on Unix and Windows machines, so supporting UAM on mainframes required PacketMotion to get a little creative, according to Gohstand. What the company instituted was a system that basically keeps a screen-by-screen log of a user's TN3270 session. Also, by correlating the mainframe audit trails with the Windows domain ID of the computer on which the telnet session was running, PacketMotion is able to eliminate any account sharing or confusion about where the session was running.

PacketMotion will use the same approach to support UAM on the System i server via 5250. General availability is tentatively planned for January, and the company is now accepting applications to participate in the System i beta test.

While hardened appliances are gaining favor for security and compliance tasks, they are not all created equally, according to Gohstand. Traditionally, a security information and event management (SIEM) or UAM appliance would be installed inline to monitor application traffic. However, this heightens the risk of an outage, because if something happens to the UAM device, then transactions cannot get through. This necessitates a second SIEM or UAM device for failover purposes, and the complexity increases.

The company gets around this problem by plugging PacketSenry Probe appliances into the monitored or "expand" ports of a switch, which duplicates all of the production network traffic, but does not impede its flow. The Probe appliance then sends the subject traffic to the PacketSentry Manager appliance, which is where the Oracle database is loaded.

"For example, you could have eight switches in front of an AS/400 or a mainframe, and have the monitored port sent to us, so we're reporting everything going on, but we're not inline," Gohstand says. "The important thing is, if our solution blows up, traffic still goes through the switch to server. It's not going to affect anything."

PacketMotion has garnered praise from Gartner, which labeled it a "cool vendor," and other analyst groups for its PacketSentry offering, which starts at around $50,000. For more information, visit www.packetmotion.com.




                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
VISION SOLUTIONS

Do You Know Your iSCORE™?

Quickly see the health of your System i with this FREE software!

A free, no-license, self-installing System i utility, iSCORE™
from Vision Solutions quickly produces a simple, clear report that outlines
the overall operating health of either your entire System i or a selected LPAR.

Click to download now.


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

Profound Logic Software:  FREE OnDemand Webinar. Learn how to easily build and extend i apps
LANSA:  Take your apps to a new dimension with RAMP. FREE Webinar!
Manta Technologies:  Your complete source for IBM i training


 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
The iSeries Express Web Implementer's Guide: List Price, $49.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
Can the AS/400 Survive IBM?: List Price, $49.00
Chip Wars: List Price, $29.95


 
The Four Hundred
IBM Slashes Power Systems Memory Prices

A New Look for the COMMON Session Grid

SSD Performance: Be Careful Before You Buy

Mad Dog 21/21: The Fox in IBM's Storage Henhouse

How Does 800,000 CPWs in a 2U Server Grab You?

Four Hundred Guru
File Caching in RSE

Message Received, But Not Understood

More with the WDSc Tasks View

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
November 28, 2009: Volume 11, Number 48

November 21, 2009: Volume 11, Number 47

November 14, 2009: Volume 11, Number 46

November 7, 2009: Volume 11, Number 45

October 31, 2009: Volume 11, Number 44

October 24, 2009: Volume 11, Number 43

October 17, 2009: Volume 11, Number 42

TPM at The Register
Fujitsu gung-ho on eight-core 'Venus' Sparc

IBM shows off Power7 HPC monster

Super Micro primes 'Magny-Cours' Opterons

Big Blue murders Cell blade servers

How to network at a supercomputing show

HP takes one in the servers

Cray previews XT6 Opteron nodes

PC sales bounce up (and down)

IBM chases HP (and Sun) with tiny mem prices

Nvidia previews next-gen Fermi GPUs

Al Gore entertains the supercomputer troops

IBM squishes systems software into new business unit

THIS ISSUE SPONSORED BY:

Help/Systems
Bytware StandGuard Security
Vision Solutions
ARCAD Software
East Coast Computer


Printer Friendly Version


TABLE OF CONTENTS
Simply Continuous Aims to Narrow 'Recovery Gap' with DR Solution

ManageEngine Adds i OS Support to Application Performance Tool

User Activity Monitoring from PacketMotion to Support i OS

Single-Platform, Technology-Focused Security Unwise Says Ex-IBMer Botz

NGS Adds PDF and Excel Report Generation to BI Suite

News Briefs and Product Shorts:

TMW to Give EGL a Chance for i OS App Modernization . . . System i Hosting Firm Taps CCSS for Systems Management . . . Steel and Lace: Lawson Upgrades M3 for Equipment and Fashion Industries . . . Equipment Dealer Lauds Attunity for Speedy DB2/400 Replication . . . First Option Goes SaaS with iSeries Watchdog . . .

Four Hundred Stuff

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2009 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement