How it Works
Secerno.SQL in IDS mode monitors database activity at the highest level to detect known and unknown threats and ensure the continuous improvement of data security. It deploys a microperimeter approach and sits immediately next to the data asset it is protecting. Secerno.SQL monitors data access and discovers anomalies – whether they come from attacks from outside the organisation, disgruntled employees or other internal sources.
Understand
Secerno.SQL allows users to understand application-to-database behaviour, which can be used to detect any database interactions that do not conform to permitted behaviours. It does this by automatically building a model that analyses how applications interact with the database, which in turn allows organisations to quickly and accurately develop a security policy that reflects how its applications use the database.
Control
Secerno.SQL provides organisations with unprecedented control over data assets. There are no black-lists (negating the need for regular updates to protect against new threats) or white-lists (which require organisations to painstakingly create a list of acceptable commands). This allows efficient and accurate policy setting and enforcement and, uniquely, ensures there is no degradation of performance as the security policy grows more complex, which can happen with techniques that rely on black- and white-lists.
In order to satisfy current and next-generation compliance and demonstrate best practice, Secerno.SQL provides secure, aggregated, intelligent logging across multiple databases.
Secerno.SQL in IDS mode can also identify Permission creep and feature creep
Protect
Secerno.SQL protects organisations through its microperimeter approach that is positioned next to the data asset it is protecting and through delivering the highest levels of detection of known or unknown attacks, whether they originate from inside or outside an organisation. Secerno technology is the only way to detect all SQL injection attacks – the fastest growing threat to corporate databases.