Click here to receive your FREE subscription to Campus Technology
11/30/2007
Sentrigo has enhanced its Hedgehog database monitoring software to identify SQL injection security problems in database built-in packages. SQL injections in packages have represented the lion's share of database exploits in recent years, according to the company.
The security solution provider claims that its Hedgehog 1.2 solution can spot difficult-to-detect SQL injections, especially unknown ones, thereby helping to avoid potential "zero-day" attacks.
Sentrigo's literature explains that Hedgehog 1.2 accomplishes its SQL exploit detection via a method it calls "context-based SQL injection detection."
Rather than track the signatures of known injections, Hedgehog monitors database activity, such as actions run by packages, triggers and stored procedures. To detect unknown injections, Hedgehog examines the context from which SQL statements originate, as well as the types of commands used and the user's access privileges.
Hedgehog can detect improper commands. For instance, when a package has the definer rights of a privileged user and initiates a command that is incongruent with its intended use, Hedgehog will recognize this as a manipulation via SQL injection. Because the software monitors the database memory, it can detect these instances when they occur. The solution is capable of tracking activity from outside attackers, as well as threats from the inside.
Hedgehog 1.2 is currently available from the Sentrigo Web site.
David Kopf is a freelance technology writer and marketing consultant. He can be reached at david@dkcopy.com.
copy text (above) for proper citation
In May in San Francisco, experts from leading universities, libraries, and research institutions around the world met as part of an ongoing effort to address a pressing issue: archiving the world's history, right up to today.
The Quilt, a coalition of 28 regional network organizations, has added XO Communications Services to its authorized vendor list. The Quilt represents 200 universities and thousands of other educational institutions across the United States. With this new relationship, Quilt members can purchase XO's high-speed IP transit and network transport services at competitive rates.
At the NECC 2008 conference in Texas this week, Wimba launched a new version of Wimba Classroom, the virtual classroom component of the company's Collaboration Suite. The new 5.2 release expands options for classroom capture and adds a variety of other functional and ease of use features.
The lure of automating workflow online so human intervention is minimized is continually reinforced in the minds of higher education administrators by examples of automated campus systems such as financials, student information systems, and other enterprise systems. But what's good for management is not always good for learning.
Cognos, which IBM acquired in January, has released an update to its business intelligence software that will run on the Linux operating system on IBM System z mainframes. IBM Cognos 8 BI was being developed by the two companies prior to the acquisition, but assimilation of Cognos into IBM accelerated development.
Facebook is a way to greet a colleague as if she or he is on your own campus: a wave at a distance, a hello at the corner burrito place, a honk as you both leave the campus parking lot. Informal collegiality has been extended over the miles.