Product review: Application Security Inc.'s DbProtect - Information Security Magazine - Page 1

Product review: Application Security Inc.'s DbProtect

DATABASE SECURITY & COMPLIANCE


DbProtect
REVIEWED BY JAMES C. FOSTER

Application Security Inc.

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.


Price: $3,000 per database per year

With most Web applications leveraging a back-end database, the importance of securing and monitoring your critical databases has never been higher. Application Security's DbProtect offers a one-two punch that scans databases for vulnerabilities and monitors them in real time for potential intrusions and compliance-related issues.

DbProtect consists of two software components. AppDetectivePro is a network-based database and application-specific vulnerability scanning tool for patch and hotfix levels, configuration, compliance and policy weaknesses. AppRadar is an application-layer intrusion detection system that can reside on or near databases to monitor for attacks.


Installation/ConfigurationB  
After DbProtect's infrastructure is designed and implemented, the configuration is relatively straightforward. Most of the configuration for the scan engines and intrusion sensors can be accomplished through the Web GUI. Sensor agents can be installed locally on the database servers or on a network server. We recommend you run tools to baseline the database performance before and after the installations. The vulnerability scanning components are agentless.

You will need to reach out to your DBAs to get the connection and user account information for a current Microsoft SQL Server 2000 database, required as DbProtect's data repository.

This was first published in February 2008

Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.