DBSS
Database Security Service (DBSS) is developed based on Huawei's 30 years of experience in database security practices. It has two subservices, database audit and database protection, which deliver functions such as data breach prevention, database firewall, and database audit to protect your databases and assets on the cloud.
Database Audit
Database audit is deployed in bypass pattern. It records user access to the database in real time, generates fine-grained audit reports, sends real-time alarms for risky operations and attack behaviors. In addition, database audit generates compliance reports that meet data security standards (such as Sarbanes-Oxley) to locate internal violations and improper operations, thus ensuring data asset security.
Database audit provides the database audit function in bypass disposition pattern for the following databases on HUAWEI CLOUD:
- RDS instances
- Databases on ECSs
- Databases on BMSs
|
Database Type |
Version |
|---|---|
|
MySQL |
|
|
Oracle |
|
|
PostgreSQL |
|
|
SQL Server |
|
|
DWS |
1.5 |
|
GaussDB for Mysql |
Mysql 8.0 |
|
DAMENG |
DM8 |
|
KINGBASE |
V8 |
- Help you meet security compliance requirements.
- Comply with DJCP (graded protection) standards for database audit.
- Comply with security laws and regulations, and provide compliance reports that meet data security standards (such as Sarbanes-Oxley).
- Back up and restore database audit logs and meet the audit data retention requirements.
- Monitor risks, sessions, session distribution, and SQL distribution in real time.
- Report alarms for risky behaviors and attacks and responds to database attacks in real time.
- Locate internal violations and improper operations and keep data assets secure.
- Monitors database login, operation type (data definition, operation, and control), and operation object based on risky operations to effectively audit the database.
- Analyzes risks, sessions, and SQL injection to help you master the database situation in a timely manner.
- Provides a report template library to generate daily, weekly, or monthly audit reports according to your configurations. Sends real-time alarm notifications to help you obtain audit reports in a timely manner.
Database Protection
- Attack prevention
Multiple policies prevent database attacks and ensure database security on the cloud.
- Sensitive data masking
Sensitive data discovery complies with industry standards. Once sensitive data is detected in user's database and it will be dynamically masked.
- Database audit
Performance, data, and behavior exceptions are monitored, and audit logs are remotely stored to ensure compliance.
Database protection provides protection and audit functions for the following databases on HUAWEI CLOUD:
- Relational Database Service (RDS) instances
- Databases on Elastic Cloud Servers (ECSs)
- Databases on Bare Metal Servers (BMSs)
Database protection supports Distributed Database Middleware (DDM). However, only some functions of DDM are supported currently due to the defect of the DDM mechanism. For details about the restrictions on using the DDM, see Constraints.
- Microsoft SQL Server 2008 to Microsoft SQL Server 2014
- MySQL 5.5 to MySQL 5.7
- PostgreSQL 9.4 to PostgreSQL 9.5
- DWS 1.2.3
Next Article: Database Audit
Did this article solve your problem?
Thank you for your score!Your feedback would help us improve the website.