| Hedgehog is a host-based software solution for real-time database monitoring, auditing and breach prevention.
It is currently available for Oracle and MS SQL Server databases on Windows, Linux and Unix platforms (see supported configurations for details).
Downloadable and Easy to Install
Hedgehog is a software-only product and can be downloaded from this website and installed with ease. It comprises a server application with a Web-based management console, and unique, light-weight sensors that are installed on the host machines of the databases that require monitoring. Using a wizard-style process, it takes literally minutes to set up.
Unprecedented Granularity
Using patent-pending technology, Hedgehog monitors all database transactions in real-time. Based on highly flexible rules and a previously unavailable level of granularity, it generates alerts and prevents suspicious activity.
Virtual Patches = Immediate Protection
Hedgehog comes with a set of predefined rules that instantly provide defense against numerous attack vectors, including:
- SQL injection
- Privilege Escalation
- DBMS-specific exploits
The Sentrigo Red Team is constantly updating this list, with updates being automatically distributed to Hedgehog users.
Uninterrupted Database Operations
Hedgehog does not impact database performance (typical CPU usage of less than 5% of a single CPU, depending on environmental variables), and allows daily operations to continue uninterrupted, even in highly transactional systems.
Unlike previously available host-based solutions, Hedgehog does not need DBMS audit logs, nor does it act as a gateway or create I/O bottlenecks. Authorized users can continue going about their business with the reassurance that their legitimate actions remain uninterrupted.
Enforcement of Security Policies
Hedgehog helps organizations ensure that security policies are implemented. In addition to detecting and preventing unauthorized use, it:
- Maintains separation of duties
- Facilitates forensics and auditing
- Provides an additional layer of defense for sensitive data
|