Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

Oracle Launches Integrated Audit Vault and Database Firewall Solution

Oracle on Wednesday launched Oracle Audit Vault and Database Firewall, part of the database giant’s answer to help protect Oracle and non-Oracle databases by monitoring network traffic and analyzing audit data.

The new Oracle Audit Vault and Database Firewall product essentially merges its Oracle Audit Vault and Oracle Database Firewall products into one, and expands protection to third party (non-Oracle) databases, and adds other enhancements.

Oracle on Wednesday launched Oracle Audit Vault and Database Firewall, part of the database giant’s answer to help protect Oracle and non-Oracle databases by monitoring network traffic and analyzing audit data.

The new Oracle Audit Vault and Database Firewall product essentially merges its Oracle Audit Vault and Oracle Database Firewall products into one, and expands protection to third party (non-Oracle) databases, and adds other enhancements.

Oracle Security By monitoring database traffic, Oracle Audit Vault and Database Firewall helps detect unauthorized activity including SQL injection attacks, and blocks both internal and external threats targeting enterprise databases. It also is able to audit the operating system, directories and custom sources.

Oracle Audit Vault and Database Firewall serves as a “critical detective and preventive control” to protect against the abuse of legitimate access to databases responsible for almost all data breaches and cyber attacks, the company said.

Key features in the product outlined by the company include:

Database Activity Monitoring and Firewall: SQL Traffic monitoring of all certified versions of Oracle and third party databases including Microsoft SQL Server, SAP Sybase, IBM DB2, and MySQL; SQL grammar analysis that helps to reduce millions of SQL statements into “clusters” for improved accuracy and scalability; and easy to create whitelists, blacklists and exception lists to better detect unauthorized database activity including SQL injection attacks.

Expanded Enterprise Auditing: Capabilities to collect, consolidate, and manage native audit and event logs from Oracle and third party databases; additional support for collecting and consolidating audit and event logs from Microsoft Windows, Microsoft Active Directory, Oracle Solaris and Oracle Automatic Storage Management Cluster File System, as well as XML and table-based audit sources through XML-based Audit Collection Plugins.

Consolidated Reporting and Alerting: Consolidated, centralized repository for all audit and event logs to be analyzed in real-time against pre-defined policies; unprecedented visibility into stored procedure execution, recursive SQL and operational activities; dozens of built-in reports to meet compliance requirements; and powerful alerting capabilities including multi-event alerts and alert thresholds.

Oracle Audit Vault and Database Firewall

“Oracle Audit Vault and Database Firewall is not just an integration of two existing products,” said Vipin Samar, vice president of Database Security Product Development at Oracle. “This is a new product that provides a unified monitoring and auditing platform that goes beyond databases.”

Advertisement. Scroll to continue reading.

Additionally, the company said that by offering the solution through a software appliance-based platform, customers are able to accelerate enterprise-wide deployments and simplify operations.

Oracle reminded that the product is not a one-shot solution, but complements its Oracle Advanced Security, Oracle Audit Vault and Oracle Database Vault products.

Related: Oracle Boosts Security, Availability With New MySQL Enterprise Extensions 

Written By

For more than 15 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is the Director of several leading security industry conferences around the world.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

Shaun Khalfan has joined payments giant PayPal as SVP, CISO.

UK cybersecurity agency NCSC announced Richard Horne as its new CEO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Data Protection

While quantum-based attacks are still in the future, organizations must think about how to defend data in transit when encryption no longer works.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Cybersecurity Funding

Los Gatos, Calif-based data protection and privacy firm Titaniam has raised $6 million seed funding from Refinery Ventures, with participation from Fusion Fund, Shasta...