McAfee Advanced Correlation Engine

McAfee Advanced Correlation Engine

위험 및 실시간 데이터에 기반한 정교한 전용 위협 탐지

다음 단계:
  • McAfee와 상담
    McAfee를 구매할 준비가 되셨거나 구매 전에 알고싶은 내용이 있으십니까? McAfee 전문가와 상담해 보십시오. 월요일부터 금요일까지 상담 서비스를 이용하실 수 있습니다. 영어로만 제공됨.
  • 리셀러 찾기
  • 연락처
  • 전화:82 2 3458 9800

개요

McAfee Advanced Correlation Engine은 실시간으로 데이터를 모니터링하여 두 상관 관계 엔진을 동시에 사용하여 위험 및 위협이 발생하기 전에 탐지할 수 있도록 합니다. Advanced Correlation Engine을 McAfee Enterprise Security Manager와 함께 배포하여 규칙 기반 로직과 위험 기반 로직을 모두 사용하여 실시간으로 위협 이벤트를 식별하고 점수를 매길 수 있습니다.

2개의 전용 상관 관계 엔진과 맞춤형 성능 — Advanced Correlation Engine은 "무규칙" 위험 점수 상관 관계를 사용하여 "위험 점수"를 생성하는 위험 탐지 엔진과 기존의 규칙 기반 이벤트 상관 관계를 사용하여 위협을 탐지하는 위협 탐지 엔진을 통해 McAfee Enterprise Security Manager 이벤트 상관 관계를 보완합니다.

기업 전반에서 풍부한 이벤트 상관 관계를 지원하는 처리 능력 — 독립형 Advanced Correlation Engine은 최대 규모의 네트워크도 수용할 수 있도록 확장됩니다.

경고 및 실시간 위험 평가 — 자산(사용자 또는 그룹, 응용프로그램, 특정 서버 또는 서브넷)을 식별하고 자산이 위협 받는 경우 Advanced Correlation Engine이 경고를 보냅니다. 감사 추적 및 기록 재생은 포렌식, 컴플라이언스 및 규칙 조정을 지원합니다.

위협 식별 및 점수 — Advanced Correlation Engine은 McAfee Enterprise Security Manager와 함께 배포되어 규칙 기반 로직과 위험 기반 로직을 모두 사용하여 실시간으로 위협 이벤트를 식별하고 점수를 매깁니다.

기능 및 이점

실시간 및 기록 위협 감지 모드

McAfee Advanced Correlation Engine을 실시간 또는 기록 모드로 배포할 수 있습니다. 실시간 모드의 Advanced Correlation Engine은 이벤트 수집과 동시에 위협 및 위험을 감지합니다. 발생에 따른 위협 감지를 위한 실시간 이벤트 데이터의 규칙 기반 상관 관계 또는 위협 진행에 따른 위협 감지를 위한 실시간 이벤트 데이터의 무규칙 상관 관계를 얻을 수 있습니다.

엔터프라이즈 위험 모델링

특성에 점수를 매겨 조직 위험의 무결점 모델링을 제공합니다. 기준선을 개발하고 정상 임계값을 초과할 때 통보합니다.

중요 데이터에 대한 사전 위험 평가 활용

두 상관 관계 엔진을 동시에 사용하여 위험 및 위협이 발생하기 전에 탐지하여 기존 상관 관계 로직 내에서 위험 점수를 사용할 수 있습니다.

재귀 위협 평가 달성

Advanced Correlation Engine을 기록 모드에서 배포하면 기존 및 무규칙 상관 관계 엔진을 통해 설정된 기록 데이터를 재생할 수 있습니다.

시스템 사양

하드웨어 사양 ACE-2600 ACE-3450
수집률 초당 50,000개 이벤트1 초당 100,000개 이벤트1
로컬 저장 장치 1.8TB2 1.8TB2

  1. 평균 이벤트 및 흐름 집계를 사용하는 일반 네트워크 환경을 기반으로 합니다.
  2. RAID 구성 후 사용할 수 있는 이벤트 및 흐름 스토리지를 나타냅니다.

데모/자습서

데모

Built for big security data, McAfee Global Threat Intelligence for McAfee Enterprise Security Manager (ESM) puts the power of McAfee Labs directly into the security monitoring flow using McAfee’s high-speed, highly intelligent security information and event management (SIEM) solution.

상/리뷰

Gartner
McAfee는 경영진의 비전과 능력을 기반으로 Gartner에서 SIEM을 위한 MQ 분야의 선도 기업으로 선정

SIEM(보안 정보 및 이벤트 관리) 마켓은 내부 및 외부 위협 관리 분야에서 실시간으로 보안 이벤트 데이터를 분석하고, 컴플라이언스 규제정책 및 포렌식에 대한 로그 데이터를 수집하고 저장하고 분석하고 관련 보고서를 작성하려는 고객의 필요에 따라 정의됩니다. Gartner 분석 대상에 포함되는 공급업체는 이러한 목적으로 고안된 기술을 보유하고 있으며, 이러한 기술을 보안 구매 센터에 능동적으로 마케팅하고 판매하고 있습니다.

고객 사례

McAfee (English)

McAfee integrates NitroSecurity products into its portfolio, improving its SIEM offering.

주요 사항
  • Significantly shortens time to analyze security events from four to six days to less than 10 minutes
  • Decreases time to produce PCI compliance reports from eight to 12 hours to 10 minutes
  • Saves administrative time and manual maintenance while eliminating unnecessary activities
  • Facilitates disaster recovery and allows for proper use of virtual machines
  • Improves the organization’s overall security posture in the industry

뉴스/이벤트

리소스

기술 청사진

상황 인식 구현

The McAfee solution has two primary components: McAfee ePolicy Orchestrator (McAfee ePO) software and McAfee Enterprise Security Manager, with additional integrations to extend visibility and control across the entire security and compliance management environment.

데이터시트

McAfee Collector Plug-in (English)

For a technical summary on the McAfee product listed above, please view the product data sheet.

Advanced Correlation Engine

위에 나열된 McAfee 제품의 기술 요약은 제품 데이터 시트를 참조하십시오.

백서

The Big Security Data Challenge (English)

This paper addresses the Big Security Data challenge and highlights the key criteria organizations need to consider for processing security information in light of today’s dynamic threat landscape.

Security Management 2.5 – Replacing Your SIEM Yet? (English)

This paper will walk you through the entire process — from soup to nuts — of evaluating, selecting, and deploying a SIEM. It offers pragmatic advice on how to get it done based on years working through this process as both consumers and vendors of SIEM technology. The process is not always painless, but we are certain it will help you avoid foundering on bad technology and inter-office politics. You owe it to yourself and your organization to ask the right questions and to get answers. It is time to slay the sacred cow of your substantial SIEM investment, and to figure out your best path forward.

Security Information and Event Management (English)

McAfee EDB data management technology handles all of these SIEM/logging requirements. It is designed, implemented, maintained, and tested by our world-class in-house development team to meet the demanding requirements of SIEM/logging and leverage all of the capabilities of appropriate emerging technologies such as modern operating systems, multicore CPUs, solid state and RAM drives, and large amounts of main memory.

SANS Institute: Correlating Event Data for Vulnerability Detection & Remediation (English)

Learn how network attacks can be avoided by utilizing a SIEM platform that combines historical data with real-time data from network sources and security policies to provide context around application usage, user behaviors, and other operations — for better, more accurate reporting.

Pike Research: Monitoring and Securing SCADA Networks (English)

This white paper examines cyber security issues for industrial control systems with a specific focus on security event monitoring as it applies to industrial control networks such as SCADA.

Continuous Compliance: Is It a Reality? (English)

In this paper, we explore the subject of continuous compliance versus audit-driven compliance, as well as how an ongoing approach to compliance makes compliance a positive force for securing data and systems.

보고서

Security Management 2.0—Time to Replace Your SIEM? (English)

This report takes a candid look at triggers for considering a new security management platform, walking through each aspect of the decision, and presenting a process to migrate.

Pike Pulse Report: Smart Grid Cyber Security Governance, Risk Management, and Compliance (English)

This Pike Pulse report presents an analysis of the current governance, risk management, and compliance (GRC) vendors that are believed to be the best positioned for the future. McAfee scores the highest in assessment of GRC vendors for smart grid security.

McAfee Positioned in Leaders Quadrant of the Magic Quadrant for SIEM (English)

Broad adoption of SIEM technology is being driven by the need to detect threats and breaches, as well as by compliance needs. Early breach discovery requires effective user activity, data access and application activity monitoring. Leading analyst firm Gartner has placed McAfee as a Leader in the Magic Quadrant for Security Information and Event Management.

[Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.]

브로셔

Focus on 5 - Threat Intelligence SIEM Requirements (English)

McAfee spoke with customers about integrating SIEM with Threat Intelligence and how it helped their effort to mitigate bad actors.

5대 중점 요소 SIEM 요건 사항 (English)

SIEM과 관련 상위 5 개 문제에 대해 알아보기: 빅 보안 데이터, 콘텐츠 및 사용자 인식, 동적 컨텍스트, 솔루션 사용자 정의 및 비즈니스 가치.

커뮤니티

블로그

  • Top 10 Reasons to Upgrade to ePO 5.1
    McAfee Enterprise - 4월 15, 2014

    Enterprises today are fighting an uphill battle when it comes to security. While there is a proliferation of security management and reporting tools available, the lack of integration and visibility can add more complexity and snags rather than less. Working between multiple security systems diverts attention from other tasks in addition to costing money and […]

    The post Top 10 Reasons to Upgrade to ePO 5.1 appeared first on McAfee.

  • Securing the Internet of Things with McAfee
    McAfee Enterprise - 4월 11, 2014

    With Google Glass, FitBit, smart cars, smart televisions, and more, it seems like the world is getting closer to the reality of the Internet of Things. In fact, according to IDC, the installed base of the Internet of Things will be approximately 212 billion “things” worldwide by 2020. Whether it’s wearable technology, household items, transportation […]

    The post Securing the Internet of Things with McAfee appeared first on McAfee.

  • Keeping Domain Controllers Safe
    Swaroop Sayeram - 4월 10, 2014

      I came across an excellent book titled, Assessing Network Security. It’s written by three Microsoft security researchers who understand Domain Controllers (DCs) inside out. I found it quite insightful and I strongly recommend it if you are in charge of IT Security. They describe DC security with a single sentence – “Defending the keys to […]

    The post Keeping Domain Controllers Safe appeared first on McAfee.

  • Microsoft Patch Tuesday: April 2014
    Doug Neuman - 4월 9, 2014

    Hello Everyone, For April’s edition of Patch Tuesday, we are presenting the final patches for the beloved Windows XP. Those of you still running Windows XP systems in your environment are highly recommended to speak with your McAfee sales team about Application Control. Application Control can provide your EOL systems protection against an unpatched vulnerability. […]

    The post Microsoft Patch Tuesday: April 2014 appeared first on McAfee.

  • Intel and McAfee Join Forces, Dazzle at Intel Security Innovation Summit
    Ken Kartsen - 4월 8, 2014

    Wow, what an incredible week we just wrapped up. In case you missed it, April 2nd was the Intel Security Through Innovation Summit, produced by FedScoop. We could not have been more thrilled with the outcome. Nearly 1,000 attendees came, including federal government and enterprise customers, McAfee and Intel personnel, partner companies and other DC-based […]

    The post Intel and McAfee Join Forces, Dazzle at Intel Security Innovation Summit appeared first on McAfee.