Hi Roee,
I am not aware of a way to work around this in the DAM arena. In the WAF arena we can do certain things like use plugins on URLs where a section of the URL changes, but not all of it, but this doesn't help you.
Have you looked at what is actually being received by the MSSQL server? What I mean is, is the .net application prepending this different prefix to the Application name it reports to the SQL server? Or does the SQLserver only see the .net sqlclient data provider name without the prefix?
------------------------------
Stefan Pynappels
Escalation Engineer
Imperva
------------------------------
Original Message:
Sent: 01-23-2020 16:08
From: Roee Sharon
Subject: working with .net sqlclient source application
Hi,
Many MSSQL users I work with use the ".net sqlclient" source application to connect to their MSSQL servers.
Often, their "source application" data, presented in SecureSphere, has a long variable string at the beginning.
For example -
[aaaa-1111].net sqlclient data provider
aaaa2222].net sqlclient data provider
[bbbb1111].net sqlclient data provider
[zzzzz-3333].net sqlclient data provider
etc...
Each time a user logs in, they may get a different variable.
This makes profiling impossible since each connection is considered by SecureSphere to be from a different source app.
Alert aggregation also suffers as the source app name cannot be aggregated, even though it's the same source app for all events.
Any idea how to resolve this?
#DatabaseActivityMonitoring
------------------------------
Roee Sharon
RSECURE
------------------------------