Database Activity Monitoring: Uses, Features, and How To Choose - Satori
Database Activity Monitoring: Uses, Features, and How To Choose
What Is Database Activity Monitoring?
Database activity monitoring (DAM) is a series of tools that can identify and report on illegal, fraudulent, or undesirable data access in a database, with limited impact on user productivity and daily operations. It provides capabilities like vulnerability management, identification and classification, intrusion prevention, application-level analysis, identity and access management (IAM) integration, support for unstructured data security, and risk management support.
Database Activity Monitoring Use Cases
Database activity monitoring is flexible and can be used for multiple use cases. Database monitoring systems can:
- Ensure separation of duties (SoD) on database administrators for SOX compliance. This is done by producing SOX-specific documents that can be used to audit and oversee database administrator activity.
- In databases with payment data, alert on any abnormal access to a payment card field, in organizations complying with PCI DSS. Encryption can be used to protect the data against theft of the entire dataset, while DAM safeguards against insider threats and other types of external threat.
- Ensure that service accounts only connect to a database via a specific source IP, and that it only uses a finite set of permitted queries. This type of monitoring can prevent compromised accounts.
- Perform closed-loop integration with external change management tools, to monitor any changes to database configuration or SQL queries. This makes it possible to monitor administrator activity and produce change management documents for compliance purposes.
Common DAM Architectures
Three common architectures used to implement database activity monitoring are interception-based, memory-based, and log-based.
Interception-based
Today, most DAM systems monitor the database by intercepting communications between the database server and the database client. DAM systems locate communication streams and receive the requests and responses without needing any input from the database.
A Database Security Proxy is a non-intrusive technique for implementing DAM. The interception can be performed at several points, including:
- At the network level, via a network SPAN or TAP port, if the information is not encrypted
- At the database memory level, for example the System Global Area (SGA)
- At the operating system level
- At the database library level
Memory-based
Certain DAM systems use a lightweight sensor that connects to secure databases. The sensor continuously polls the system global area (SGA) to gather SQL statements as they are executed.
Log-based
Certain DAM systems examine and extract the data from the transaction logs—commonly the redo log. By scraping redo logs, they can obtain much valuable data.
Key Features of Database Activity Monitoring Systems
The core features that differentiate database activity monitoring tools are their capacity to:
- Audit and monitor all database activity separately, such as privileged user activities and SELECT transactions, without a loss of performance.
- Safely store database activity outside the observed database.
- Produce alerts when a policy violation is identified.
- Correlate and aggregate database activities from heterogeneous database control systems.
- Ensure separation of duties of database administrators, oversee their activity, and prevent tampering or manipulation of database logs.
- Offer insight into how information is seen and by whom.
Database Activity Monitoring: An Evaluation Checklist
All organizations need a database activity monitoring tool that has minimal effect on their databases. The following is a checklist that stakeholders and DBAs can use when considering solutions.
Here are things to seek from a database security monitoring tool:
- Should consume up to 1-3% of disk resources and CPU, using an agent-only method of collection.
- Should offer ongoing, real-time monitoring of all SQL traffic.
- Should initiate a TCP reset when blocking a session.
- Should use minimal network bandwidth when examining incoming SQL statements to the gateway.
- Should dispatch alerts over multiple channels.
Here are things to avoid in a database security monitoring tool:
- Should not require adding any new objects, scripts, or credentials to the database.
- Should not alter or require alteration of the database, database parameters, or database configuration files.
- Should not require a host reboot, except in exceptional cases.
- Should not write to the file system, except when communication with the gateway is lost.
Database Activity Monitoring with Satori
Satori provides smart context-rich audit and monitoring across your data stores. The audit logs are universally available for reporting and analytics, and include a lot of additional metadata added from the IdP and from Satori’s continuous data classification engine.