• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • QJRN/400 Sniffs Out Fraud, One Journal Receiver at a Time

    October 7, 2008 Alex Woodie

    QJRN/400 from Cilasoft is a database auditing tool for the IBM System i server that relies on the operating system’s extensive journaling function to dig up evidence of malfeasance or fraud by users. Clever System i users will be able to hide their tracks to some extent. But when every little action is tracked and recorded, it’s just a matter of piecing the puzzle together, and that’s where QJRN/400 excels.

    Cilasoft was founded 10 years ago in southern France by Guy (pronounced “Gee”) Marmorat, the company’s CEO and technical manager, and the head developer of QJRN/400. At the time, many companies that relied on the iSeries server were concerned about the possibility of fraud by internal users and subsidiaries.

    Many of the clients were private banks and other financial services firms, Marmorat says. “Some of them were African companies. Because Africa is–sorry to say–number one in the world for fraud. Big companies asked me to come in and monitor activity of all these people.”

    This created an opportunity for QJRN/400, which provides an extensive array of filters, alerts, and reporting mechanisms to automatically track and notify administrators of suspicious transactions or other events. The software enables administrators to receive an alert if QJRN/400’s filters catch anything. Common items to monitor include price lists, authorization lists, transactions greater than a given amount, or countries or users that fall onto a black list.

    The alerting function provides customers an element of real-time security, but QJRN/400 can also look into fraud after the fact. The same filters can be used to pour through many gigabytes of past transactions, providing a powerful forensic tool. However, this use of QJRN/400 must be thought out carefully, as loading too many days’ worth of journal receivers can easily fill a server’s hard disks.

    Cilasoft estimates that QJRN/400 has saved its 200 customers more than €400,000 (more than $550,000 at current exchange rates) by detecting fraud. Half of this came during one harrying episode at a major brewery in Africa several years ago. The brewery’s managers had become suspicious of certain employees, and hired Marmorat to secretly install QJRN/400 to detect what was going on with the brewery’s AS/400 accounting system.

    QJRN/400 ran for three months and uncovered evidence of about €200,000 in fraudulent transactions by a group of 10 employees. Here’s how it worked: The perpetrators would arrange to sell kegs of beer to a group of participating outsiders. Instead of charging them full price, however, the insiders would go into the AS/400 beer keg pricing file, and change the list price by a small amount. Then they would submit an invoice, which would be run against the price list, per the company’s business rules. After running the invoice, they would re-enter the original price on the list before anybody noticed, and collect their fee from the participating beer keg buyers.

    The brewery, which processed thousand of invoices every day, was blind to the fraudulent transactions, which represented less than two-tenths of a percent of the total.

    “It was impossible to check everything because of the number of transactions,” Marmorat says. “Also the price difference was not enormous, but at the end of the day, it’s big enough.”

    The volume and duration of the fraud made it very profitable for the perpetrators. An investigation ensued, and 10 people were convicted and jailed, but not before they threatened to harm Marmorat, who had helped foil their plan and land them behind bars. “Because the amount was so enormous in Africa, they even tried to kill me,” he says.

    Not every QJRN/400 installation results in such a clear-cut case of fraud. In some cases, QJRN/400 has discovered bugs and errors in ERP systems. And in recent years, regulatory compliance has provided a new role for QJRN/400. Instead of looking for fraud, the product’s fine-tooth comb can be used to provide a detailed audit trail, thereby satisfying some of the IT-related requirements of Sarbanes-Oxley, HIPAA, 21 CFR Part 11, and assorted other regulations.

    Regulatory compliance provided a challenge for QJRN/400, Marmorat says. “The auditors require monthly reports, and it’s impossible to have one month’s receivers online, so I have to extract from the receivers to keep what I want to be the new source of my reports, and then to do my reports,” he says. “This is the difficulty, and we have all this functionality incorporated into the product” to address these challenges, he says.

    Cilasoft is currently working on the next major release of QJRN/400. Version 4.11 will feature templates for specific ERP systems, such as JD Edwards and BPCS, thereby enabling customers to get the software up and running more quickly. QJRN/400 4.11 is due to ship in January.

    While the South American software market seems a little more receptive to QJRN/400, Marmorat is not giving up on the North American AS/400 market, which has been a challenge for Cilasoft, among many other software companies. The company first broke into the North American market two years ago, but didn’t have the right mix of partners, according to Marmorat. “I think we made a mistake in our strategy,” he says. “Now we have some partners that are very committed, very involved, and deliver a good quality of service in the USA and Canada too, so we are very happy now.”

    Cilasoft currently has 10 partners in the U.S. and one in Canada. Marmorat is considering opening an office in the U.S., but the current economic situation has put any plans on hold. For now, the company will likely focus on lower-cost methods of product promotion, such as the recent Webinar on QJRN/400 hosted by Marmorat that turned up some good leads.

    QJRN/400 version 4 is available. Pricing is tier-based and ranges from $7,000 for P05 box to $47,000 for a P50 box. For more information, visit www.cilasoft.com.



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    Midrange Dynamics North America

    Git up to speed with MDChange!

    Git can be lightning-fast when dealing with just a few hundred items in a repository. But when dealing with tens of thousands of items, transaction wait times can take minutes.

    MDChange offers an elegant solution that enables you to work efficiently any size Git repository while making your Git experience seamless and highly responsive.

    Learn more.

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    Computer Measurement Group:  CMG '08 International Conference, December 7-12, Las Vegas
    looksoftware:  snap the best back-end into the coolest front-end
    Vision Solutions:  A $20 gas card for completing a short i5/OS DR survey

    IT Jungle Store Top Book Picks

    Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
    Getting Started with PHP for i5/OS: List Price, $59.95
    The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
    The System i Pocket RPG & RPG IV Guide: List Price, $69.95
    The iSeries Pocket Database Guide: List Price, $59.00
    The iSeries Pocket Developers' Guide: List Price, $59.00
    The iSeries Pocket SQL Guide: List Price, $59.00
    The iSeries Pocket Query Guide: List Price, $49.00
    The iSeries Pocket WebFacing Primer: List Price, $39.00
    Migrating to WebSphere Express for iSeries: List Price, $49.00
    iSeries Express Web Implementer's Guide: List Price, $59.00
    Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
    Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
    Getting Started with WebSphere Express for iSeries: List Price, $49.00
    WebFacing Application Design and Development Guide: List Price, $55.00
    Can the AS/400 Survive IBM?: List Price, $49.00
    The All-Everything Machine: List Price, $29.95
    Chip Wars: List Price, $29.95

    The SAS Disk Spec Gets a Bandwidth Boost Want a Fast and Easy Way To Sort Subfile Data?

    Leave a Reply Cancel reply

Volume 8, Number 36 -- October 7, 2008
THIS ISSUE SPONSORED BY:

New Generation Software
Vision Solutions
Safedata
Bytware
Twin Data

Table of Contents

  • QJRN/400 Sniffs Out Fraud, One Journal Receiver at a Time
  • Databorough Beefs Up X-Analysis for Application Modernization
  • BCD’s Presto Web Enablement Software Goes GA
  • IBM Promotes the i–iPhone, That Is
  • Valid Gets IBM Certification for i OS-Based Biometric System
  • Impart Solutions Targets AS/400 Shops with SaaS-Based ERP
  • TMW Updates Document Management Software
  • Texas Company Gets Good Returns with Aldon Help Desk Solution
  • InfoPrint Goes for Printer Efficiency with ‘Productivity Tracker’
  • LogiXML Delivers New Data Visualization Tool, Called VizLytics

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Public Preview For Watson Code Assistant for i Available Soon
  • COMMON Youth Movement Continues at POWERUp 2025
  • IBM Preserves Memory Investments Across Power10 And Power11
  • Eradani Uses AI For New EDI And API Service
  • Picking Apart IBM’s $150 Billion In US Manufacturing And R&D
  • FAX/400 And CICS For i Are Dead. What Will IBM Kill Next?
  • Fresche Overhauls X-Analysis With Web UI, AI Smarts
  • Is It Time To Add The Rust Programming Language To IBM i?
  • Is IBM Going To Raise Prices On Power10 Expert Care?
  • IBM i PTF Guide, Volume 27, Number 20

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle