www.eweek.com/c/a/Security/Vendors-Tie-Database-Activit -
[Cached Version]
Published on: 1/14/2009
Last Visited: 1/16/2009
"The example of a pooled application comes to mind, where an application is accessing a database, but multiple users are logging into the application," said Frank Hayes, vice president of marketing at NitroSecurity.
"To the database, it's all coming from one user, but in reality it could be any number of users."
Hayes continued, "By analyzing database activity in a SIEM that also analyzes your application logs, you can bridge the gap to determine who really did what.
That's only one example ...detected events: your SIEM detects that multiple bad log-ins occurred, followed by a successful log-in, followed by an IPS alert indicating a SQL backdoor exploit occurred.
"But what really happened?
You know everything up to the database itself, but by adding the database activity to the picture as well, you can easily determine if the exploit succeeded, and if it did, what data, if any, was accessed," Hayes said.