Oracle Information InDepth


Oracle Database 12c
Oracle Database 12c Plug into the Cloud

Stay Connected

Oracle Blog Oracle on Twitter Oracle on Facebook Oracle on Youtube Oracle on LinkedIn

January 2014

Subscribe Subscribe Forward Forward

Back to the main page

New SANS Institute Report Puts Oracle Audit Vault and Database Firewall to the Test

A new report from leading security organization SANS Institute finds that Oracle Audit Vault and Database Firewall successfully achieves three key security objectives: audit collection, SQL traffic monitoring, and security event reporting.

With Oracle Audit Vault and Database Firewall, organizations can monitor both Oracle and non-Oracle database traffic, and detect and block threats. It also enhances compliance by consolidating audit data from disparate sources—including databases, operating systems, directories, custom applications, and more—into a secure data warehouse for reporting and alerting.

Thumbs Up from SANS
To evaluate Oracle Audit Vault and Database Firewall, SANS simulated real-world scenarios and found that the solution "did what it claimed to do and is a valuable solution for organizations looking for a first line of defense that protects their data and databases," the report's author Tanya Baccam, SANS Institute Analyst, writes.

In particular, the study finds the solution successfully

  • Monitors traffic and blocks threats. SANS was able to observe Oracle Audit Vault and Database Firewall detect a SQL injection attempt—and then block it.
  • Provides consolidated reporting on IT system events. The report finds that the solution enables monitoring of multiple hosts and disparate systems and delivers simplified compliance reporting.
Cross-Enterprise Reach
Most organizations have multiple database platforms, typically requiring disparate reporting tools that complicate risk management. In response, Oracle Audit Vault and Database Firewall centralizes information from across the data infrastructure.

"The ability to monitor and protect enterprisewide systems in a single console can help break down the information silos that leave IT environments vulnerable," the report's author writes.

Ease of Use
The solution's intuitive interface and out-of-the-box reporting capability are another key benefit, according to the report.

"The centralized web console makes it easy to set up and view the systems that Oracle Audit Vault and Database Firewall monitors," writes the report's author. "The built-in reports provide details about database activity, and when needed, customized reports can be created. Alerts could also be easily set up to communicate relevant data in a more timely fashion."

Download the complete SANS report.

Learn more about Oracle Audit Vault and Database Firewall.
Back to Top

Please send questions or comments to

This document is provided for information purposes only, and the contents hereof are subject to change without notice. This document is not warranted to be error-free, nor is it subject to any other warranties or conditions, whether expressed orally or implied in law, including implied warranties and conditions of merchantability or fitness for a particular purpose. We specifically disclaim any liability with respect to this document, and no contractual obligations are formed either directly or indirectly by this document. This document may not be reproduced or transmitted in any form or by any means, electronic or mechanical, for any purpose, without our prior written permission.

Copyright © 2014, Oracle and/or its affiliates. All rights reserved.
Oracle and Java are registered trademarks of Oracle and/or its affiliates. Other names may be trademarks of their respective owners.

Intel and Intel Xeon are trademarks or registered trademarks of Intel Corporation. All SPARC trademarks are used under license and are trademarks or registered trademarks of SPARC International, Inc. AMD, Opteron, the AMD logo, and the AMD Opteron logo are trademarks or registered trademarks of Advanced Micro Devices. UNIX is a registered trademark of The Open Group.

  Hardware and Software, Engineered to Work Together

Contact Us | Legal Notices and Terms of Use | Privacy

Oracle Corporation


Oracle Corporation - Worldwide Headquarters, 500 Oracle Parkway, OPL - E-mail Services, Redwood Shores, CA 94065, United States

Your privacy is important to us. You can login to your account to update your e-mail subscriptions or you can opt-out of all Oracle Marketing e-mails at any time.

Please note that opting-out of Marketing communications does not affect your receipt of important business communications related to your current relationship with Oracle such as Security Updates, Event Registration notices, Account Management and Support/Service communications.