"... As a result of our NitroSecurity implementation, we have not had a single [virus outbreak] and we virtually eliminated illegal file-sharing"
— Director of Network Operations & Information Security Officer, Berry College
 

    Quick Contact

    First Name:

    Last Name:

    Company:

    Email:

    Phone:

    State:

    What can we do for you?

      


    Click here for more contact options.

  •  

 
 

NitroView  Network Database Monitor



Network-based Database Monitoring for Protection and Compliance

NitroView Data base Monitor
How to Buy
Contact Us to request a demo, or
call us at 888-LOG-SIEM

Features at a Glance
Full compliance audit & reporting

Monitor and enforce database usage policies

Discover Sensitive Data

Assess vulnerabilities and risk

100% visibility into all database activity

Full session awareness from login to logoff

Policy-based and anomaly-based detection

Fully integrated with NitroView ESM to support advanced security and compliance use cases

Easy to deploy, easy to use

More Information
NitroView Database Monitoring (DBM) Datasheet
NitroSecurity Solution Brochure
Awards
Testimonials
DBM Product Specs

NitroView DBM (DBM) is a complete database protection solution that delivers non-intrusive, detailed security logging of databases and applications by monitoring all access to sensitive corporate and customer data. NitroView DBM's pre-defined rules and reports, privacy-friendly logging features and encrypted, time-stamped files make it easy to comply with regulations such as Sarbanes-Oxley, PCI, HIPAA, GLBA, FDIC, FISMA, NERC-CIP, DCID 6/3, and ISO 17799, among others.

NitroView DBM is the only database activity monitoring product that not only consolidates database activity into a central audit repository, but also provides normalization, correlation, analysis and reporting of that activity. This enables advanced, real-time security operations in addition to enterprise compliance auditing and reporting. By expanding visibility to include user information, application contents, OS activity, vulnerabilities, and even network location, NitroView DBM is able to support a broader array of relevant use cases:

  • Track user activity across applications, even when using pooled accounts
  • Examine full session activity from login to logoff
  • Detect sensitive data, and identify access policy violations
  • Discover access using spoofed identities and ghost accounts
  • Detect leakage of data obtained through authorized channels through related user and application activity
  • Correlate anomalous database activity directly to relevant security events from firewalls, IPS devices, etc

This is possible because NitroView DBM does more than provide visibility into database activity. As part of the NitroView solution, NitroView DBM is fully and seamlessly integrated into NitroView ESM — the industry's fastest and most scalable SIEM, and the industry's only content aware SIEM. Using a simple "single pane of glass" user interface, you have easy access to everything from database policy management to full enterprise-wide correlation and data leakage detection. Simple, reliable, cost-effective and efficient ... and because NitroView ADM and ESM are provided as drop-in network appliances, you get all this without impacting the performance of your databases — or the business-critical applications that rely on them.

"Database Activity Monitoring is crucial because organizations store sensitive, business-critical information in their DBMSs. Monitoring & analysis of critical data access is becoming compliance standard of due care, & this capability is also required to detect data breaches in the event of a successful targeted attack."

Gartner: Mark Nicolett, "DAM Technology Provides Monitoring & Analytics", NOV 2007

Integrated Compliance and Security Solutions

NitroView DBM integrates well with both NitroView ELM, for compliant storage and encryption of data activity logs, and NitroView ESM, for event analysis and correlation. Pre-built compliance reporting is available whether you choose LogCaster or NitroView ESM or both, assisting you in your compliance efforts regardless of your specific operational needs.

Already have SIEM or Log Management solution? Use NitroView DBM as standalone database activity monitoring tool, to detect policy violations, threats, and to generate detailed database activity logs. NitroView DBM can forward events to other SIEM or Log Management devices, or be used on its own to improve security and compliance.

For compliance audit purposes, all database activity and transactions are monitored, producing detailed database activity logs. In addition, security events are produced when policy violations or anomalies are detected. Hundreds of rules are included out-of-the-box, with a simple, GUI rule editor to create or modify new rules. Alerts are easily correlated against other security events within NitroView, and any specific alert of database transaction can be quickly traced back to a complete audit trail of the full database session, from login to logoff. When a high-risk threat is detected, NitroView takes action, allowing you to blacklist users or protocols, disable a network interface, or quarantine an end user.

"... we have centralized monitoring from the perimeter to the application layer. It is a very powerful tool from a security perspective. This is the trend for the future."

Career Education Corporation

Pre-defined rules & reports to meet your security & compliance needs for:
  • PCI
  • SOX
  • HIPAA
  • FISMA
  • FDIC
  • GLBA
  • ISO 17799
  • Basel II
  • FFIEC
  • DCID 6/3

Flexible Options

Network-based database monitoring ensures zero-impact to your core data (and the applications that access that data). Rather than using processor cycles on your database server, NitroGuard sits on the network next to your server, monitoring traffic for suspicious activity, transactions, logins, etc. However, for those companies requiring an agent-based system—such as environments where the console and database cohabit a server—NitroView DBM is available as a host-based database monitor, as well. Either way, your data is being watched: activity is logged for compliance, and alerts are sent to NitroView ESM for analysis, correlation, and forensic operations.


Part of Your Best-Practice, Tiered Security Solution

Critical assets require multiple layers of protection. A bank keeps money in a safe, but also locks its doors and monitors the lobby. The same edge-to-core protection is provided by the NitroView and NitroGuard solution: NitroGuard IPS protects the perimeter and watches what is happening in your network; NitroView DBM monitors your core applications. Alerts from both systems are managed together by NitroView ESM for correlation and analysis, providing a clear picture of everything that's happening within your infrastructure.


Specifications 

NitroView Database Monitor Specifications

Select a Model for Specifications

Model                  Description      Appliance      Supported DBs      Events/Sec     
NS-DBM-4245-R NitroView DBM 4000, Database Monitor Pack. 1U Appliance good DB2, Oracle, MS SQL, MySQL, SyBase 15,000
NS-DBM-2250-R NitroView DBM 2000, Database Monitor Pack. 1U Appliance goodDB2, Oracle, MS SQL, MySQL, SyBase 10,000
NS-DBM-2230-R NitroView DBM 2000, Database Monitor Pack. 1U Appliance goodDB2, Oracle, MS SQL, MySQL, SyBase 5,000

Related Products

NitroView Enterprise Security Manager Specifications

Select a Model for Specifications [Note: for US Army APL approved models, please visit our government site]

Model           Description                         Events/sec     Report   
speed*    
HDD**    
NS-ELM-XXXX NitroView Enterprise Log Manager (ELM) Integrated Log Management for NitroView ESM & NitroView Receiver
 NS-ESM-X5 NitroView ESM X5 "High Speed" Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions for large enterprise networks. 7TB local storage plus 500GB of in-memory storage for etremely high performance. One 3U appliance, plus one 2U Appliance. 40 Million 1 Billion events/sec 7TB +
500GB RAM
 NS-ESM-5750-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions for medium to large enterprise networks. 7TB local storage. 3U Appliance. 4 Million 100 Million events/sec 7 TB
 NS-ESM-5510-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions. 3.75TB local storage, 3U appliance 3 Million 50 Million events/sec 3.75 TB
 NS-ESM-5205-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. 2.5TB local storage. 3U appliance. 2 Million 25 Million events/sec 2.5 TB
 NS-ESMRCV-5205-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 2.5 TB local storage. 3U appliance. Rated for 5,000 events per second and manages up to (5) NitroSecurity devices (IPS, DAM, or APM). 5,000 25 Million events/sec 2.5 TB
 NS-ESMRCV-4245-R NitroView ESM 4000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 1.5 TB local storage. 1U appliance. Rated for 1,000 events per second and manages up to (3) NitroSecurity devices (IPS, DAM, or APM). 1,000 25 Million events/sec 1.5 TB
 NS-NRC-4245 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 18,000 events per second. 18,000 - 1 TB
 NS-NRC-2250 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 15,000 events per second. 15,000 - 1 TB
 NS-NRC-2230 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 10,000 events per second. 10,000 - 1 TB
 NS-NRC-1225 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 5,000 events per second. 5,000 - 500GB
 NS-ESS-5205 NitroView ESM 5000 Enterprise Security Server provides management for up to 10 NitroSecurity devices (IPS, DAM, or APM). Does not support 3rd party feeds. Redundant power, 2.5TB local storage. 3U appliance. 150,000 (NitroSecurity devices only) 25 Million events/sec 2.5 TB
 NS-ESS-2230-R NitroView ESM 2000 Enterprise Security Server provides management for up to 10 NitroSecurity devices (IPS, DAM, or APM). Does not support 3rd party feeds. 500GB local storage. 1U appliance. 150,000 (NitroSecurity devices only) 15 Million 500GB

* Typical SIEM reports (queries) will complete in a few seconds, even on very large event stores.

** NitroView ESM 5000 models utilize a raid 10 drive configuration, as well as redundant, dedicated drives for OS storage. The number listed above represents the usable capacity for event, log and flow storage.

*** The maximum number of supported devices per ESM is determined by the receiver model(s) used for collection.

Click to see a current list of supported data sources


NitroView Enterprise Log Manager Specifications

Select a Model for Specifications

model              Description      Logs / Sec     
NS-ESMLM-4245-R NitroView ESM / ELM 4000 Enterprise Security Manager provides SIEM , Compliant Enterprise Log Management, and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 1 TB local storage. 1U appliance. 1,000
NS-ESMLM-5205-R NitroView ESM / ELM 5000 Enterprise Security Manager provides SIEM , Compliant Enterprise Log Management, and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 2.5 TB local storage. 3U appliance. 2,500
NS-ESMLM-5510-R NitroView ESM / ELM 5000 Enterprise Security Manager provides SIEM , Compliant Enterprise Log Management, and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 3.75 TB local storage. 3U appliance. 5,000
NS-ELM-5510-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 3.75 TB local storage. 3U appliance. 35,000
NS-ELM-5205-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 2.5 TB local storage. 3U appliance. 20,000
NS-ELM-4245-R NitroView ELM 4000 Enterprise Log Manager provides Compliant Log Management functions. Supports network / SAN storage options. No local storage. 1U appliance. 40,000
NS-ELM-5750-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 7 TB local storage. 3U appliance. 50,000
NS-NRCLM-4245-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 10,000 events per second. 10,000
NS-NRCLM-2250-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 8,000 events per second. 8,000
NS-NRCLM-2230-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 5,000 events per second. 5,000
NS-LC-2250-R NitroView LogCaster 2000, 1U appliance. Includes (500) LogCaster Agent Licenses. Rated for 10,000 events per second. 10,000
NS-LC-2230-R NitroView LogCaster 2000, 1U appliance. Includes (250) LogCaster Agent Licenses. Rated for 5,000 events per second. 5,000
NS-LC-AGT-200 NitroView LogCaster Large Syslog Device Agent License for quantity 200 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-100 NitroView LogCaster Large Syslog Device Agent License for quantity 100 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-50 NitroView LogCaster Large Syslog Device Agent License for quantity 50 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-25 NitroView LogCaster Large Syslog Device Agent License for quantity 25 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -

NitroGuard IPS Specifications

Select a Model for Specifications [Note: for US Army APL approved models, please visit our government site]

Model                     Description      Throughput      Copper
Ports     
Fiber
Ports     
NS-IPS-5450-R NitroGuard IPS 5000, 3U IPS appliance supporting approximately 4 to 5Gbps & 1.2m connections. Includes redundant power and a bypass NIC. 4-6 Gbps 12x1Gbps 4x10Gbps
NS-IPS-4245-R NitroGuard IPS4000, 1U IPS appliance supporting approximately 2Gbps & 1.5m connections. Includes redundant power and a bypass NIC. 2 Gbps 2, 4, 8 2, 4
NS-IPS-2250-R NitroGuard IPS 2000, 1U IPS appliance supporting approximately 750Mbps & 1.2m connections. Includes redundant power and a bypass NIC. 750 Mbps 2, 4, 8 2, 4
NS-IPS-2230-R NitroGuard IPS 2000, 1U IPS appliance supporting approximately 500Mbps & 1.2m connections. Includes redundant power and a bypass NIC. 500 Mbps 2, 4, 8 2, 4
NS-IPS-1225 NitroGuard IPS 1000, 1U IPS appliance supporting approximately 250Mbps & 1.2m connections. Includes single power and a bypass NIC. 250 Mbps 2, 4 2, 4
NS-IPS-1160 NitroGuard IPS 1000, 1U IPS appliance supporting approximately 150Mbps & 1.2m connections. Includes single power and bypass NIC. 150 Mbps 2 N/A
NS-IPS-110 NitroGuard IPS 100, Set-Top IPS appliance supporting approximately 50Mbps & 1.2m connections. Includes single power and a 2 port 10/100/1000 Base-TX copper NIC (no bypass). 50 Mbps 2 N/A





 

Search NitroSecurity.com