tfh
Volume 18, Number 44 -- December 14, 2009

IBM Beefs Up Database Security with Guardium Buy

Published: December 14, 2009

by Alex Woodie

IBM two weeks ago bought database security software vendor Guardium. The acquisition nets Big Blue a powerful suite of products that monitor transactions across all major relational database management systems (RDBMS)--including DB2/400--in real time for signs of suspicious activity, such as unauthorized use by insiders or SQL injection attacks by outside hackers.

Guardium was founded in Israel about seven years ago to address what its founders considered a sizable hole in IT security tools and best practices. While most organizations have a range of security tools in place to protect their networks, applications, and data, they typically have very few security controls in place at the database layer, say officials with the company, which was based in Waltham, Massachusetts, before IBM bought it.

"The key issue for database security is that most companies have no visibility into what's really going on with their database," Phil Neray, Guardium's vice president of marketing, told IT Jungle earlier this year. "They don't really know who's accessing those databases, and they don't have any mechanisms for identifying unauthorized or suspicious activity."

Guardium's solutions provide that visibility into database access, as well as the capability to clamp down on security policy violations in real time. In particular, the software allows organizations to protect themselves against inside threats, such as systems administrators with "super user" authorities who could easily bypass application- or network-level security control points.

Guardium's offering is also effective against SQL injection attacks, which can be difficult to spot using traditional security tools. In its February X-Force report, IBM's own Internet Security Systems subsidiary identified SQL injection attacks as an increasingly popular route of ingress for hackers seeking to infiltrate corporate computer systems over the Web.

There is a slight performance hit of 2 to 4 percent as a result of running all database transactions through Guardium's policy-based controls and anomaly detection routines, company officials have said. The product also keeps a detailed audit trail of all database activities, which is useful for regulatory compliance.

Guardium has delivered its technology--which is currently at version 7 and starts at about $75,000--as a combination of a hardened appliance deployed atop VMware, as well as a series of probes that relay data from the guarded databases. The product supports all major databases, including IBM DB2 (for Unix, Linux, and Windows), DB2/400, DB2 for z/OS, and Informix; Oracle 8i through 11g; Microsoft SQL Server 2000 through 2008; and others such as MySQL, Teradata, and Sybase. Support for DB2/400 (or DB2 for i, as iBM likes to call it) was added this April.

IBM plans to integrate Guardium's technology into its Information Management division within Software Group. "This acquisition is another significant step in our abilities to help clients govern and monitor their data, and ultimately make their information more secure throughout its lifecycle," Arvind Krishna, general manager of the Information Management division, stated in a press release. No details were provided about specific integration plans.

Guardium has been growing quickly and recently became profitable. Its software is used by about 400 customers, including at the Washington Metropolitan Area Transit Authority, which processes more than 9 million credit card transactions per year. Guardium had about 150 employees in the Boston area.

According to IBM, it's the 28th acquisition for the Information Management division for this decade. IBM did not provide financial details of the acquisition. But according to an Israeli newspaper, the value of the deal was $225 million.


RELATED STORIES

Guardium Adds DB2/400 Support to Database Security Tool

Web Site Vulnerabilities Continue Unabated, IBM X-Force Says



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
WORKSRIGHT SOFTWARE

Do you need area code information?
Do you need ZIP Code information?
Do you need ZIP+4 information?
Do you need city name information?
Do you need county information?
Do you need a nearest dealer locator system?

We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

Just call us and we'll arrange for 30 days FREE use of either
ZIP/CITY or PER/ZIP4.

WorksRight Software, Inc.
Phone: 601-856-8337
Fax: 601-856-9432
E-mail: software@worksright.com
Web site: www.worksright.com


Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik, Brian Kelly, Shannon O'Donnell,
Mary Lou Roberts, Victor Rozek, Kevin Vandever, Hesh Wiener, Alex Woodie
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

10ZiG Technology:  Ask us about our new Ethernet Terminal for only $195!
Bytware StandGuard Security:  Are you monitoring and auditing your System i security? FREE trial.
Manta Technologies:  Year-End SALE! 40% off the complete library and all combo packs. Ends Jan 15

 

 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
The iSeries Express Web Implementer's Guide: List Price, $49.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
Can the AS/400 Survive IBM?: List Price, $49.00
Chip Wars: List Price, $29.95


 
Four Hundred Stuff
Fiserv 2.0 Banks on the Reliability of Power Systems

Quadrant Eases Installation, Lowers Price on IntelliChief

TMW Systems Buys Innovative Computing, Including 300 i OS Customers

Databorough Unveils 'Lite' Version of Application Analysis Tool

10ZiG Acquires BOSaNOVA System i Connectivity Products

Four Hundred Guru
Prompting CL in Run SQL Scripts

Publish Result Sets Using Web Services and IWS

Admin Alert: The Ins and Outs of IBM Business Partners

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
November 28, 2009: Volume 11, Number 48

November 21, 2009: Volume 11, Number 47

November 14, 2009: Volume 11, Number 46

November 7, 2009: Volume 11, Number 45

October 31, 2009: Volume 11, Number 44

October 24, 2009: Volume 11, Number 43

October 17, 2009: Volume 11, Number 42

TPM at The Register
Sun brews up Java EE 6

Red Hat opens up Spice desktop virtualisation protocol

IBM punts Linux-only mainframes

Europeans spend more on servers in Q3

IBM builds Pacific ring of cloud

ParAccel flashes data warehouses

Sun-Oracle x86 server combo tops the SAP charts

Intel Larrabee letdown leaves HPC to Nvidia's Fermi

Red Hat revs real-time MRG Linux to 1.2

IBM thinks outside the box with containerized data centres

Novell to mashup management tools

Stealth: Dell's other server business

THIS ISSUE SPONSORED BY:

Infinite Software
Infor
Maximum Availability
Computer Keyes
WorksRight Software


Printer Friendly Version


TABLE OF CONTENTS
Power Systems i: Serve's Up

Abacus Offers i 6.1 Upgrade Virtual Test Drive Service

The Server Market Sees Some Stability

As I See It: What's Next?

Untested Backup and Recovery Fools Midrange Shops

But Wait, There's More:

Happy Holidays, Time to Take a Break or Two or Ten . . . Reader Feedback on Power Systems i: Thinking Inside the Box . . . Micro Focus Bolstered by Acquisitions, Real Growth . . . Disk Array Sales Hold Up Better Than Servers, Says Gartner . . . IBM Beefs Up Database Security with Guardium Buy . . .

The Four Hundred

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2009 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement