Spotting system intrusions a challenge for IT

29.01.2007

The technology also enables USEC to monitor compliance with Sarbanes-Oxley financial reporting regulations and provides the company with a real-time security-alerting capability, Vordick said.

Accor North America, a Carrollton, Texas-based operator of hotel chains such as Red Roof Inns and Sofitel, is using an appliance from Imperva Inc. to detect unusual database activity as it occurs. Such tools let companies move from a "passive security" model to a more aggressive one, said Jaimin Shah, a senior security engineer at Accor.

Being able to do the same kind of monitoring of all network and system assets could help companies detect suspicious activity more quickly, Shah said. "The problem is that monitoring generates a tremendous amount of logs," he said, adding that "getting the right information as quickly as we can" is a challenge.

Vendors such as LogLogic Inc. are beginning to offer more efficient ways to sift through log data, Maness said. But he still expects it to take up to 10 years to develop true end-to-end capabilities for tracking networks.