• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • IBM Beefs Up Database Security with Guardium Buy

    December 14, 2009 Alex Woodie

    IBM two weeks ago bought database security software vendor Guardium. The acquisition nets Big Blue a powerful suite of products that monitor transactions across all major relational database management systems (RDBMS)–including DB2/400–in real time for signs of suspicious activity, such as unauthorized use by insiders or SQL injection attacks by outside hackers.

    Guardium was founded in Israel about seven years ago to address what its founders considered a sizable hole in IT security tools and best practices. While most organizations have a range of security tools in place to protect their networks, applications, and data, they typically have very few security controls in place at the database layer, say officials with the company, which was based in Waltham, Massachusetts, before IBM bought it.

    “The key issue for database security is that most companies have no visibility into what’s really going on with their database,” Phil Neray, Guardium’s vice president of marketing, told IT Jungle earlier this year. “They don’t really know who’s accessing those databases, and they don’t have any mechanisms for identifying unauthorized or suspicious activity.”

    Guardium’s solutions provide that visibility into database access, as well as the capability to clamp down on security policy violations in real time. In particular, the software allows organizations to protect themselves against inside threats, such as systems administrators with “super user” authorities who could easily bypass application- or network-level security control points.

    Guardium’s offering is also effective against SQL injection attacks, which can be difficult to spot using traditional security tools. In its February X-Force report, IBM’s own Internet Security Systems subsidiary identified SQL injection attacks as an increasingly popular route of ingress for hackers seeking to infiltrate corporate computer systems over the Web.

    There is a slight performance hit of 2 to 4 percent as a result of running all database transactions through Guardium’s policy-based controls and anomaly detection routines, company officials have said. The product also keeps a detailed audit trail of all database activities, which is useful for regulatory compliance.

    Guardium has delivered its technology–which is currently at version 7 and starts at about $75,000–as a combination of a hardened appliance deployed atop VMware, as well as a series of probes that relay data from the guarded databases. The product supports all major databases, including IBM DB2 (for Unix, Linux, and Windows), DB2/400, DB2 for z/OS, and Informix; Oracle 8i through 11g; Microsoft SQL Server 2000 through 2008; and others such as MySQL, Teradata, and Sybase. Support for DB2/400 (or DB2 for i, as iBM likes to call it) was added this April.

    IBM plans to integrate Guardium’s technology into its Information Management division within Software Group. “This acquisition is another significant step in our abilities to help clients govern and monitor their data, and ultimately make their information more secure throughout its lifecycle,” Arvind Krishna, general manager of the Information Management division, stated in a press release. No details were provided about specific integration plans.

    Guardium has been growing quickly and recently became profitable. Its software is used by about 400 customers, including at the Washington Metropolitan Area Transit Authority, which processes more than 9 million credit card transactions per year. Guardium had about 150 employees in the Boston area.

    According to IBM, it’s the 28th acquisition for the Information Management division for this decade. IBM did not provide financial details of the acquisition. But according to an Israeli newspaper, the value of the deal was $225 million.

    RELATED STORIES

    Guardium Adds DB2/400 Support to Database Security Tool

    Web Site Vulnerabilities Continue Unabated, IBM X-Force Says



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags: Tags: mtfh_rc, Volume 18, Number 44 -- December 14, 2009

    Sponsored by
    DRV Tech

    Get More Out of Your IBM i

    With soaring costs, operational data is more critical than ever. IBM shops need faster, easier ways to distribute IBM applications-based data to users more efficiently, no matter where they are.

    The Problem:

    For Users, IBM Data Can Be Difficult to Get To

    IBM Applications generate reports as spooled files, originally designed to be printed. Often those reports are packed together with so much data it makes them difficult to read. Add to that hardcopy is a pain to distribute. User-friendly formats like Excel and PDF are better, offering sorting, searching, and easy portability but getting IBM reports into these formats can be tricky without the right tools.

    The Solution:

    IBM i Reports can easily be converted to easy to read and share formats like Excel and PDF and Delivered by Email

    Converting IBM i, iSeries, and AS400 reports into Excel and PDF is now a lot easier with SpoolFlex software by DRV Tech.  If you or your users are still doing this manually, think how much time is wasted dragging and reformatting to make a report readable. How much time would be saved if they were automatically formatted correctly and delivered to one or multiple recipients.

    SpoolFlex converts spooled files to Excel and PDF, automatically emailing them, and saving copies to network shared folders. SpoolFlex converts complex reports to Excel, removing unwanted headers, splitting large reports out for individual recipients, and delivering to users whether they are at the office or working from home.

    Watch our 2-minute video and see DRV’s powerful SpoolFlex software can solve your file conversion challenges.

    Watch Video

    DRV Tech

    www.drvtech.com

    866.378.3366

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Admin Alert: The Ins and Outs of IBM Business Partners Data Masking Tool from Camouflage Now Supports DB2/400

    Leave a Reply Cancel reply

TFH Volume: 18 Issue: 44

This Issue Sponsored By

    Table of Contents

    • Power Systems i: Serve’s Up
    • Abacus Offers i 6.1 Upgrade Virtual Test Drive Service
    • The Server Market Sees Some Stability
    • As I See It: What’s Next?
    • Untested Backup and Recovery Fools Midrange Shops
    • Happy Holidays, Time to Take a Break or Two or Ten
    • Reader Feedback on Power Systems i: Thinking Inside the Box
    • Micro Focus Bolstered by Acquisitions, Real Growth
    • Disk Array Sales Hold Up Better Than Servers, Says Gartner
    • IBM Beefs Up Database Security with Guardium Buy

    Content archive

    • The Four Hundred
    • Four Hundred Stuff
    • Four Hundred Guru

    Recent Posts

    • The Turning Point For Power Systems Is Here, And Now
    • How IBM i Users Can Compete In The Digital Era With Composable Commerce
    • IBM Streamlines Data Migration With New Partition Mirror Tech
    • Profound Logic Adds MCP To IBM i AI Tool
    • IBM i PTF Guide, Volume 27, Number 29
    • Power11 Entry Machines: The Power S1124 And Power L1124
    • BRMS Isn’t The Only Backup Product With A Security Problem
    • Guru: A Faster Way To Sign A JWT
    • Maxis Adds IBM i Support To Database Modernization Tool
    • IBM i PTF Guide, Volume 27, Number 28

    Subscribe

    To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

    Pages

    • About Us
    • Contact
    • Contributors
    • Four Hundred Monitor
    • IBM i PTF Guide
    • Media Kit
    • Subscribe

    Search

    Copyright © 2025 IT Jungle