平安

Ping An Securities

Ping An Securities Co., Ltd. is an important member of China Ping An (Insurance) Group Co., Ltd. At present, Ping An Securities is actively exploring the improvement and innovation of financial services, technology, and services, providing diversified investment services such as stocks, funds, and investment and wealth management; And innovative services such as 7 * 24-hour subscription and intelligent market monitoring. Having a comprehensive compliance and risk control system, it is one of the mainstream securities firms in China.
平安
Detailed Description

Ping An Securities Co., Ltd. is a key member of Ping An (Insurance) Group Co., Ltd. Currently, Ping An Securities is actively exploring the improvement and innovation of financial services, technology, and support, offering diversified investment services such as stocks, funds, and wealth management, as well as innovative services like 24/7 subscription and intelligent market monitoring. With a comprehensive compliance and risk control system, it stands as one of the leading domestic securities firms.

Main Functions
```Unique three-tier audit```

For B/S architecture application systems, users access the database through a WEB server. Traditional database auditing systems can only audit information related to the WEB server but cannot identify which original visitor initiated the request. The AhnLab DAS-DBAuditor correlates application layer access with database layer access operations, enabling it to trace back to the original visitor at the application layer and request details (e.g., the URL where the operation occurred, the client's IP address, etc.). By implementing three-tier auditing, it more accurately identifies all access and operation requests across all levels before and after an event occurs.

Fine-grained auditing

Unlike the traditional restoration of simple SQL statements, it extracts relevant elements (users, SQL operations, tables, fields, etc.) from SQL through semantic analysis of different databases

Comprehensive real-time auditing: Monitor all database activities across all levels in real time. For example, database operation requests initiated by applications or operation requests from database client tools.

SQL commands executed via remote command line can also be audited and analyzed.

Comprehensive bidirectional auditing: The system not only performs real-time auditing of database operation requests but also enables complete restoration and auditing of the results returned by the database system.

Precision-based behavior backtracking

In the event of a security incident, provide fully customizable audit queries and audit data visualization based on database objects (users, tables, fields, and record content), completely eliminating the black-box state of the database (quickly grasp: who performed operations on the database before and after the security incident? What operations were performed? When were the operations performed? How were the operations performed?)

Comprehensive Risk Control

Flexible Strategy Customization: Define important events and risk events of concern to customers based on flexible combinations of logged-in users, source IP addresses, database objects (including database users, tables, and fields), operation times, SQL commands, returned record counts or affected row numbers, associated table quantities, SQL execution results, SQL execution durations, and message content.

Multi-format real-time alerts: When suspicious operations or actions that violate audit rules are detected, the system can notify database administrators via monitoring center alerts, SMS alerts, email alerts, Syslog alerts, and other methods.

Multi-protocol layer remote access monitoring: It not only monitors access to client tools and application layer JDBC/ODBC but also supports real-time monitoring and playback of remote database server access (e.g., FTP, Telnet), aiding in security incident investigation, root cause analysis, and accountability determination.

Separation of duties

The SOX Act or professional duty standards (such as PCI) explicitly require the separation of duties for staff. The system implements role-based permission separation, such as system administrators responsible for operational settings of devices; rule configuration officers responsible for setting relevant database operation rules; auditors responsible for reviewing audit logs and rule violations; and log reviewers responsible for monitoring overall device operation logs and rule modifications, among others.

```Friendly and Authentic Operation Process Replay```

For operations of concern to clients, the entire related process can be replayed, allowing clients to view the actual input and screen display content.

The industry's first audit model

In addition to providing real-time dynamic auditing capabilities, it also offers an optional scanning audit module to detect and audit insecure database configurations, weak passwords, and more.

Scheme Value
• Effectively resolved issues such as massive internal data leakage and unauthorized tampering.

• Effectively deter relevant management and maintenance personnel from easily stealing or tampering with data.

• It truly achieves compliance auditing for key business operations, ensuring post-event traceability and evidence-based auditing.

• Comply with national classification protection-related laws and regulations to ensure compliance.

扫二维码用手机看
未找到相应参数组,请于后台属性模板中添加