McAfee Vulnerability Manager

McAfee Vulnerability Manager

准确识别漏洞和违反策略的行为,排定资产优先级,有效降低风险

后续步骤:

概述

McAfee Vulnerability Manager 可以让您快速、精确、全面地了解所有联网资产存在的漏洞。这款易于部署的解决方案拥有卓越的扩展能力,无论网络中的用户点只有几百还是高达数百万,都可以轻松满足其需要。不间断的全球性研究让您能够始终掌握最新威胁和漏洞的第一手资讯。我们的可控化关联性单一漏洞视图与已获专利的 FoundScore 风险公式有助于您在最需要的地方进行修补工作。

Vulnerability Manager 提供了:

基于优先级的审核与补救 — 综合漏洞、严重程度和资产关键性等多方面信息,快速识别联网系统和设备中存在的漏洞和违反策略的行为并排定优先级,进而逐一解决。

证明“无懈可击” — 审核人员的一项主要要求就是证明不会遭受各种威胁的侵袭,这正是 McAfee Vulnerability Manager 的优势。

新威胁识别和关联 — 将事件与您的资产和漏洞数据相关联,自动排定新威胁的潜在风险等级。

策略审核与合规性评估 — 确定策略检查的价值及企业是否遵循了主要的法规规定。通过一个易于使用的向导,您可以获得针对 SOX、FISMA、HIPAA、PCI 等法规的模板。

灵活的报告 — 按照资产或网络进行数据分类,并可使用强大的过滤器选择和组织报告中的结果。您甚至可以在扫描过程中创建报告。

广泛、深入的内容覆盖 — 执行认证和非认证检查,这些检查由全球顶级威胁研究中心迈克菲实验室提供全天候自动更新。这有助于您深入了解操作系统和网络设备,以查找其中的漏洞和违反策略行为。

特点和优势

深层分析 Web 应用程序

执行对 Web 应用程序的深入扫描,从而了解需要集中精力重点编码的部分,以防止将来黑客利用您的业务关键数据进行攻击。这些扫描包括 PCI 所需的检查项,以及 2010 年 OWASP 排名前 10 位和 CWE-25 中的类别。

数分钟内即可启动扫描

您可以选择在物理或虚拟硬件或者我们的增强型设备上进行一体化安装或自定义安装;使用现有的 LDAP、Active Directory 或 McAfee ePolicy Orchestrator (ePO) 资产管理系统或借助首次扫描来识别您的资产。

使用全面的可定制内容进行检查和报告

借助 SCAP 支持和预定义的最新策略模板显著节省时间。我们丰富的检查可以帮助您验证对联邦和法规要求的合规性,同时能通过编写自定义脚本和检查来测试专有和旧系统。

满足苛刻的政府和行业要求

让您轻松证明对 EAL 通用标准和 FIPS-140-2 加密标准的合规性。McAfee Vulnerability Manager 包括面向当今最常见法规和标准的模板。

享受强大的漏洞覆盖、扫描准确率以及恶意软件防护

超载端口和配置以检测系统、数据库及所有联网资产(包括智能手机、安全服务器等)中应用程序。

显著提高灵活性和性能

无论您是集中运营还是分散运营,都可以以极快的速度(甚至能满足包含数百万用户点的网络的需求)定制自己的部署、扫描、报告和管理控制台。

证明“无懈可击”

生成确凿的证据(如预期和实际扫描结果、未扫描的系统以及未完成的扫描),以证明特定系统“无懈可击”,这是一项日益普遍的审核要求。

通过迈克菲全球威胁智能感知系统及时对威胁作出响应

利用全球数百万台传感器为数百名迈克菲实验室研究人员提供最新威胁动态,同时也为实时风险评估和威胁顾问提供强大支持。

系统要求

Vulnerability Manager 软件
可以在您的硬件或虚拟环境中将 Vulnerability Manager 作为软件进行部署。软件部署有以下最低要求:

  • 硬件
    • CPU:x86 多核,2 GHz 或更快频率(推荐使用四核处理器)
    • RAM:最低 2 MB(推荐使用 4 GB)
    • 磁盘空间:最低 80 GB(数据库需要 200 GB)
  • 虚拟主机
    • VMware Virtual Infrastructure 3/vSphere (ESX/ESXi)
    • VMware Workstation
  • 操作系统
    • Microsoft Windows 2003 Server(32 位)SP2 或更高版本
  • 数据库
    • Microsoft SQL Server 2005 SP2 或更高版本(任何版本)
    • 所有 SQL 修补程序和补丁程序

Vulnerability Manager MVM3100 Appliance
选择这款专用增强型设备,让您更快、更轻松地进行部署。它包含了一切所需的软件和一个企业级数据库。硬件部署有以下最低要求:

  • 硬件
    • 1U 机架式安装
    • 4 核 Xeon
    • 4 GB RAM
    • 2 x 500 GB RAID 1
    • 备援电源
    • 无人值守型管理
    • 4 GbE 扫描端口(支持 VLAN)

演示/教程

演示

Learn how McAfee Risk and Compliance products scan your entire network, providing complete visibility and ensuring proper protection.

课程

奖项/评述

Gartner MarketScope for Vulnerability Assessment

“McAfee Vulnerability Manager 可提供无代理安全配置评估,并可与基于代理的 McAfee Policy Auditor(包括 DISA STIG、NSA、FDCC 和 CIS 控件)集成。McAfee Vulnerability Manager 具有灵活的资产管理、补救报告和工作流程功能。”

McAfee Vulnerability Manager 产品预览

在由 S3KUR3 Inc. 开展的独立评估中,McAfee Vulnerability Manager 被誉为“唯一将灵活性、全面扫描和强大的补救功能融于单个软件包中的解决方案”。

《SC》杂志“最值得购买产品”奖
Vulnerability Manager 荣获《SC》杂志“最值得购买产品”奖

McAfee Vulnerability Manager 是一款基于设备的强大工具,提供漏洞评估、渗透测试、 Web 应用程序扫描以及强大的恶意设备检测功能,同时还兼容 LDAP(轻量级目录访问协议)和 Microsoft Active Directory 以实现轻松的资产管理。

迈克菲系统安全和漏洞管理产品通过了 Citrix Ready 认证

2009 年 8 月 17 日,美国加州圣克拉拉市 — 迈克菲公司(纳斯达克股票代码:MFE)日前宣布旗下 McAfee VirusScan Enterprise、McAfee Anti-spyware Enterprise、McAfee ePolicy Orchestrator 和 McAfee Vulnerability Manager 产品通过了 Citrix Ready™ 认证。Citrix Ready 计划旨在确定能为 Citrix Delivery Center™ 基础设施带来最大价值的可靠第三方解决方案。 上述迈克菲产品通过了严格的验证流程,确认能够与 Citrix® XenApp™ 兼容。

客户案例

Abtran (English)

McAfee security risk management solutions help Abtran meet clients’ increasing security requirements.

产品特色
  • Provided multiple layers of security risk management protection for Abtran’s clients
  • Reduced IT hours spent supporting, administering, and monitoring endpoint security
  • Cut time to produce weekly security reports from three or four hours to less than two minutes
  • Migrated easily and seamlessly from existing anti-virus solutions

Alcatel-Lucent Shanghai Bell (English)

Alcatel-Lucent Shanghai Bell uses McAfee Network Security Platform to secure 100 Mbps to 10 Gbps corporate networks against threats and attacks.

产品特色
  • Increased identification and interception of up to 99% of the threats
  • Improved the work efficiency and allowed the information security and network departments to cooperate with each other in monitoring security threats and risks

California State University, Chico (English)

California State University, Chico, remediates system vulnerabilities and mitigates risk with McAfee Vulnerability Manager.

产品特色
  • Increased risk visibility at department and campus levels, enabling snapshot of security status at any time
  • Accelerated time to remediation by providing clear remediation steps for systems administrators
  • Reduced time spent scheduling vulnerability scans, and preparing and analyzing reports
  • Improved and accelerated decision making by providing user-friendly metrics, graphical reports, and trend analysis
  • Improved overall security risk posture

Cardnet (English)

Cardnet eliminates malware infections with comprehensive network, email, and endpoint security from McAfee.

产品特色
  • Total absence of known infections of any kind
  • Protected the entire IT infrastructure
  • Maintained IT security with a staff of three, versus 20 or more if the McAfee suite was not in place

CEMEX (English)

CEMEX relies on McAfee to find system vulnerabilities and prevent data loss.

产品特色
  • Discovered and assessed systems vulnerabilities
  • Provided in-depth visibility regarding network assets
  • Reduced vulnerability false positives by 80%
  • Saved IT hours each week thanks to easy-to-use reports and minimal false positives
  • Prioritized threat response

Citrix Systems (English)

Citrix reduces risk with McAfee’s integrated security risk management platform.

产品特色
  • Deployed quickly and easily, saving $40,000 in deployment costs
  • Reduced incident response rate by 40% and overall TCO of security risk management
  • Dramatically eased security administration and accelerated patch deployment
  • Reduced remediation time by 70%

DSM (English)

DSM enlists McAfee to strengthen enterprise network security control and compliance.

产品特色
  • Provided full visibility into network traffic and connected systems
  • Simplified patch management
  • Improved compliance with regulations and policies
  • Increased efficiencies for significant cost savings

HCF (English)

HCF gets comprehensive anti-malware protection and streamlined security management with McAfee.

产品特色
  • Smooth implementation
  • Easy identification of vulnerable areas
  • Meaningful reports for IT administrators who are only advised about attacks that are relevant to the environment
  • Enabled automatic enforcement of security policies; ensuring network integrity
  • Automation of patch management freed up IT staff to focus on strategic work

Idaho State Tax Commission (English)

Idaho State Tax Commission chooses McAfee to embed security in a new network infrastructure.

产品特色
  • Identified vulnerabilities and blocked threats
  • Delivered reliable endpoint protection
  • Enabled compliance with National Institute of Standards and Technology (NIST) security guidelines
  • Provided support for the commission’s defense-in-depth security strategy
  • Helped increase security awareness among network users

Integral Energy (English)

Integral Energy proactively assesses and manages vulnerabilities with McAfee Vulnerability Manager.

产品特色
  • Discovered and assessed system vulnerabilities quickly and accurately
  • Enabled threat prioritization and proactive, informed decision making
  • Provided in-depth visibility regarding network assets
  • Facilitated compliance with ISO 27001 standard

Intelsat (English)

Intelsat trusts McAfee to protect user and network devices globally.

产品特色
  • Protected a diverse environment from internal and external threats, including the inherent risks of a fluctuating population of 250 to 500 contractors
  • Managed the entire server system with 1.5 full-time employees (FTEs)
  • Reduced solution cost by 75% over a la carte purchases from separate vendors
  • Standardized a security environment that previously required five vendors
  • Complied with regulations, including SOX, HIPAA, and Department of Defense (DoD)

Manteca Unified School District (English)

Manteca Unified School District protects students with McAfee solutions.

产品特色
  • Increased bandwidth by 20% after eliminating IM and file sharing
  • Reduced virus outbreaks to zero per year, compared with one or more in prior years
  • Enabled systems administrators to quickly learn new solutions through centralized management capabilities of McAfee ePolicy Orchestrator (ePO) platform

NYC Department of IT and Telecommunications (English)

NYC Department of IT and Telecommunications uses McAfee for for vulnerability management, endpoint encryption, and other areas of security functionality.

产品特色
  • Increased protection with a savings of $18 million
  • Provided centralized control across highly distributed IT environment

Scottrade (English)

Scottrade partners with McAfee to secure customer data.

产品特色
  • Eliminated network vulnerabilities and protected customer information
  • Improved monitoring and control of workstations and servers via a single management console
  • Streamlined and accelerated security management and vulnerability assessment
  • Simplified deployment, patches, and upgrades
  • Helped Scottrade garner multiple awards for customer satisfaction and IT excellence

TeliaSonera AB (English)

A leading telecommunications group in the Nordic and Baltic regions strengthens anti-virus security with McAfee.

产品特色
  • Protected 23,000 endpoints against viruses
  • Enforced blacklisting of potentially malicious applications
  • Delivered powerful functionality, ease of use, and simplified administration
  • Helped secure the patch update process

新闻/活动

新闻

活动

未找到结果

资源

产品简介

McAfee Vulnerability Manager

有关上面所列迈克菲产品的技术摘要,请查看产品简介。

报告

解决方案简介

白皮书

社区

博客

  • Cultural Security: Promoting Security Policies Using Organizational Culture
    Steven Fox - 九月 06, 2011
    Most of us refer to security policies in much the same way as we refer to our car manuals – when something unexpected happens.  We know these documents have useful information.  However, their utility is tied to situations where answers do not present themselves readily. According to Chris Noel, SVP of Product Management at ANXeBusiness, Read more...
  • Building an Arsenal of Best-in-Breed Database Security Solutions
    Eric Schou - 八月 19, 2011
    Visit any news site on the Web, and undoubtedly you’ll come across a barrage of articles publicizing the details of yet another data breach. With the prominence of SQL injection attacks, and malicious insiders and hackers exploiting sensitive data stored on unpatched and vulnerable databases, enterprise organizations have found themselves reevaluating their security strategies. Following Read more...
  • Hackers vs. Hackers: The New Frontier Of Embedded Devices
    Stuart McClure - 六月 27, 2011
    If we look at the evolution of hacking, certain techniques never go out of style, but we’re at the beginning of a big shift in terms of the targets.  The threat landscape has evolved beyond PCs, tablets, and smartphones to a whole new battleground: connected devices all around us. According to Ericsson, there will be Read more...
  • The Consumer Experience, The Data Center And 99.9% Uptime
    Evelyn de Souza - 五月 23, 2011
    While 99.9% network and server uptime has long been an established standard in data centers, the consumer experience so often fails to live up to that, and I as I was reminded of again this weekend.    Unplanned network or server changes or vulnerabilities are often the cause of website outages.  And, as the website Read more...
  • My Recent Travels to Italy and Spain
    Gert Jan Schenk - 五月 19, 2011
    Recently I have been meeting with customers and resellers throughout Italy and Spain and it was interesting to hear that their needs from a security partner are very similar to those from the other countries I have recently visited.  I have started to see strong interest in the McAfee DLP, Database Protection and Encryption technologies Read more...