IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  MSSQL DDL Commands policy blocking issue

    Posted 01/05/21 12:09 AM
    Hi Everyone,

    If I login MSSQL server through MSSQL management studio, below listed SQL verbs are able to see in Guardium Collector.
    BEGIN
    create table
    DECLARE
    drop table
    exec
    IF
    insert
    SELECT
    SET
    sp_executesql
    UPDATE
    I have started blocking based on object wise but If I want to block CREATE TABLE OR DROP TABLE command, Its simply blocking the connection without making me to login the MSSQL server itself. If I ignore the session for above commands, how can I get succeed for blocking above commands?Can anyone give solution to login to mssql server successfully and also block above commands?

    Thanks,
    Panendar Rao.C

    ------------------------------
    PHANENDRA RAO CHAVANA
    ------------------------------


  • 2.  RE: MSSQL DDL Commands policy blocking issue

    Posted 02/02/21 09:18 AM
    Hi Phanendra,

    Yes you can with S-TAP Firewall Blocking.
    Example for mode: 

    S-Tap firewall Open mode -----> attaching session ----> S-Gate terminate

    S-Tap firewall Close Mode ------> S-Gate Terminate



    ------------------------------
    Regards,

    Fırat Bişkin
    System Security Specialist
    IBM Global Technology Services
    ------------------------------