McAfee Global Threat Intelligence Proxy (McAfee GTI Proxy)

McAfee Global Threat Intelligence Proxy (McAfee GTI Proxy)

Enable McAfee GTI to operate in DNS proxy environments

Next Steps:

Overview

McAfee Global Threat Intelligence Proxy (McAfee GTI Proxy) enables McAfee VirusScan Enterprise nodes to perform McAfee GTI file reputation (formerly known as Artemis) queries from within the enterprise network without requiring direct access to the public McAfee cloud from all McAfee VirusScan Enterprise (version 8.7 or later) endpoint systems. With McAfee GTI Proxy, organizations ensure that they have up-to-date threat protection and robust virus detection capabilities, including a strong defense against advanced persistent threats and botnets, even if Internet access is limited.

Consolidated cloud communications — Driven by compliance or other factors, organizations often have unique requirements for allowing applications to access resources on the Internet. For organizations operating limited Internet access environments, McAfee GTI Proxy consolidates communications between McAfee VirusScan Enterprise clients that have McAfee GTI file reputation queries activated and the McAfee cloud via a set of auditable proxy servers.

Streamlined deployment and management — McAfee GTI Proxy is delivered as a VMware virtual appliance and managed by the McAfee ePolicy Orchestrator (ePO) platform. Optimized for efficiency, McAfee GTI Proxy requires little additional network overhead.

Real-time threat protection — Leveraging McAfee GTI via the cloud to resolve real-time file reputation queries, McAfee GTI Proxy identifies suspicious files that may contain malware.

Features & Benefits

Leverage local intelligence

McAfee GTI Proxy supports custom reputation entries enabling local intelligence to override the McAfee Global Threat Intelligence reputation response. Administrators can specify whether a triggered file should have a clean or unclean response regardless of the reputation given by McAfee, enabling rapid response to suspected threats and false positive prevention.

Stop malware in real time

Close the protection gap with McAfee Global Threat Intelligence (GTI). McAfee GTI offers comprehensive, real-time protection against both known and emerging threats and McAfee GTI Proxy enables GTI support for VirusScan Enterprise clients. McAfee GTI, a cloud-based service using reputation-based threat protection in addition to other techniques, correlates real-world data collected from millions of sensors globally and delivers automated intelligence to VirusScan Enterprise via the GTI Proxy.

Implement a highly scalable, cost-effective solution

Support up to 100,000 PCs per virtual appliance, reducing management costs.

Ensure secure data transmission

Communications between GTI Proxy and the McAfee cloud are handled via UDP wrapped in SSL (which is DTLS on port 443).

System Requirements

These are minimum system requirements. Actual requirements will vary depending on the nature of your environment.

McAfee Components

  • McAfee ePolicy Orchestrator (ePO), version 4.6
  • McAfee VirusScan Enterprise, version 8.7 or 8.8
  • McAfee Global Threat Intelligence file reputation (formerly known as Artemis) technology

VM Infrastructure

  • VMware Workstation 8
  • VMware ESX 4.x
  • VMware ESXi 4.x/5.x

Server

  • Distributed as VMware appliance image
  • 64-bit guest operating system running McAfee Linux (MLOS)
  • Disk space: Minimum of 35 GB available
  • Minimum of 2 GB RAM available
  • 64-bit CPU

Resources

Data Sheets

McAfee GTI Proxy

For a technical summary on the McAfee product listed above, please view the product data sheet.

FAQ

Community

Forums

No results found

Blogs

  • NCCDC 2013 – Red Team Recap
    Jim Walter - May 07, 2013
              This past April (4/19 to 4/21) I had the great pleasure and experience of joining the Red Team at 9th NCCDC competition.   It was actually my 2nd year on the Red Team and 4th year to attend in total (I judged in 2010 and 2011).  McAfee is actually a perpetual Read more...
  • Botnets Remain a Leading Threat
    Neeraj Thakar - March 28, 2013
    One threat has evolved and dominated the threats landscape like no other: botnets. Practically every day a new set of online criminals attempt to exploit users in some way or the other. The best way to stop this threat at the perimeter is to identify its communication channel and block the bot from connecting to Read more...
  • Securing the Global Digital Infrastructure (GDI) Together
    Raj Samani - February 07, 2013
    Intel and McAfee welcome European Union resolve to fight cyber threats By David Hoffman, Raj Samani and Christoph Luykx Today, the European Commission and the EU’s External Action Service (EEAS) presented its response to the growing threats presented in cyberspace by releasing a policy document (the “Communication”), outlining the longer term required actions together with Read more...
  • Looking into the Cyber Threats Crystal Ball: McAfee Threats Predictions Report
    Pat Calhoun - December 27, 2012
    Proactive and preemptive.  That’s the caliber of protection we are working toward integrating into all of our network security products.  Because without proactive and preemptive protection, online security will never be completely secure.  Thankfully for all of us, McAfee Labs knows this is the key too.  That’s why, every year McAfee Labs publishes its Threat Read more...
  • Tool Talk: Cracking the Code on XtremeRAT
    Jim Walter - October 31, 2012
    Late last week, reports began to surface that the Israeli police (along with other regional law enforcement) were targeted by a malware attack.  The entry vector was described as a phishing campaign sent from Benny Gantz (head of the Israeli Defense Forces).  Initially, details and indicators around the malware were beyond sparse. Aside from the FROM: address, Read more...