The Guardium solution consists of a modular software suite built on a hardened Linux kernel and deployed as a series of pre-configured appliances. The product can also be deployed as a software-only solution.
All database transactions are monitored and analyzed in real-time, using both policy-based controls and anomaly detection to identify unauthorized or suspicious activities. Simultaneously, all transactions are stored in a structured audit log repository (an embedded, high-performance database) for real-time correlation analysis, compliance reporting, auditing, and forensics.
Unlike traditional database logging solutions, our architecture is non-invasive, network-based, and DBMS-independent. It provides 100% granularity and visibility into all database transactions, including DDL, DML, SELECTs, DCL, stored procedures, security exceptions, before/after data values, and all privileged user activities (including those performed via local access to the DBMS server).
But as remarkable as this solution is for what it does, it’s equally remarkable for what it doesn’t do. It has virtually zero impact on performance, does not require changes to your databases, and does not rely on local database trace or transaction logs.