Hedgehog 1.2 Adds Context-Based SQL Injection Security

Sentrigo has enhanced its Hedgehog database monitoring software to identify SQL injection security problems in database built-in packages. SQL injections in packages have represented the lion's share of database exploits in recent years, according to the company.

The security solution provider claims that its Hedgehog 1.2 solution can spot difficult-to-detect SQL injections, especially unknown ones, thereby helping to avoid potential "zero-day" attacks.

Sentrigo's literature explains that Hedgehog 1.2 accomplishes its SQL exploit detection via a method it calls "context-based SQL injection detection."

Rather than track the signatures of known injections, Hedgehog monitors database activity, such as actions run by packages, triggers and stored procedures. To detect unknown injections, Hedgehog examines the context from which SQL statements originate, as well as the types of commands used and the user's access privileges.

Hedgehog can detect improper commands. For instance, when a package has the definer rights of a privileged user and initiates a command that is incongruent with its intended use, Hedgehog will recognize this as a manipulation via SQL injection. Because the software monitors the database memory, it can detect these instances when they occur. The solution is capable of tracking activity from outside attackers, as well as threats from the inside.

Hedgehog 1.2 is currently available from the Sentrigo Web site.

About the Author

David Kopf is a freelance technology writer and marketing consultant, and can be reached at [email protected].

Featured

  • Businessman using laptop analyzing data and growth graph chart

    AI Budgets in Education Show No Sign of Decline

    The vast majority of education organizations (98%) expect their AI infrastructure budgets to either increase or hold steady over the next year, according to a recent report from cloud storage provider Wasabi.

  • Interconnected Light Particles in Vibrant Streams

    Rubrik Agent Cloud Expands Policy Controls for Agent Prompts/Responses

    Rubrik has made Rubrik Agent Cloud generally available, adding expanded governance controls that enforce predefined and custom policies on both AI agent prompts and responses.

  • abstract cybersecurity data protection

    Rubrik Intros Google Workspace Data Protection

    Rubrik has announced the launch of Rubrik Data Protection for Google Workspace, a product the company said is designed to help enterprise customers protect data and restore operations across Google Workspace environments.

  • Silhouettes of business professionals stand against a blurred futuristic city skyline at night, with a glowing digital network data connection

    It's Time for Higher Ed to Get Serious About AI Strategy

    Without a coordinated strategy that involves multiple academic and administrative units across the entire campus, colleges risk wasting resources, duplicating efforts, and ultimately failing to deliver on the promise of deploying technology to improve learning and operations.