McAfee Database Activity Monitoring

McAfee Database Activity Monitoring

Cost-effective database protection to meet your compliance requirements

Next Steps:

Overview

McAfee Database Activity Monitoring automatically finds databases on your network, protects them with a set of preconfigured defenses, and helps you build a custom security policy for your environment — making it easier to demonstrate compliance to auditors and improve critical asset data protection. Database Activity Monitoring cost-effectively protects your data from all threats by monitoring activity locally on each database server and by alerting or terminating malicious behavior in real time, even when running in virtualized or cloud computing environments.

Comprehensive threat protection — Protect even your unpatched databases against zero-day attacks by blocking attacks that exploit known vulnerabilities and terminating sessions that violate your security policies.

Detailed audit trail reports — Audit trail reports are available to meet SOX, PCI, and other compliance audit requirements. During post-incident forensic analysis, this audit trail can help you understand the amount of lost data and gain greater insight into malicious activity.

Streamlined patching with no required downtime — Applying missing patches and fixing misconfigurations found by the Database Activity Monitoring vulnerability scan will improve the security posture of your databases immediately — without requiring any downtime via McAfee’s virtual patching technology.

Features & Benefits

Get maximum protection for sensitive data, meet compliance requirements, and reduce exposure to costly breaches

Demonstrate compliance and minimize the likelihood of a breach by monitoring threats to databases from all sources, including network/application users, local privileged accounts, and sophisticated attacks from within the database itself.

Save time and money with faster deployment and a more efficient architecture

Simplify the process of building custom security policies to audit and protect databases with preconfigured rules and templates.

Minimize risk and liability by identifying attacks as they occur, and stopping them before they cause damage

Stop breaches by terminating suspicious sessions and quarantining malicious users with real-time monitoring and intrusion prevention for Oracle, Microsoft SQL Server, and Sybase databases.

Increase your flexibility by deploying McAfee Database Activity Monitoring on the IT infrastructure of your choice

Install sensors on physical servers, provision sensors along with the database on virtual machines, and deploy sensors remotely on cloud servers.

Discover databases automatically and organize them for monitoring and management

Find databases by scanning the network or by importing them from existing tools, and then group them by vendor, version, or custom tags (for example, HR, finance, or QA).

Get out-of-the-box protection for known vulnerabilities and common threats

Receive more than 380 predefined rules that address specific issues patched by the database vendors, as well as generic attack profiles.

Leverage templates for compliance regulations

Use a simple, step-by-step interface for building customized security policies for PCI DSS, SOX, HIPAA, GLBA, and SAS-70, as well as best practices based on experience at hundreds of customer sites.

Receive granular protection of sensitive data at the object level, regardless of the source of the attack

Evaluate process memory to determine execution plan and affected objects, identifying policy violation even from local users or obfuscated code.

System Requirements

These are minimum system requirements only. Actual requirements will vary depending on the nature of your environment.

Minimum System Requirements

  • McAfee ePolicy Orchestrator 4.5
  • Microsoft Windows Server 2003 with Service Pack 2 (SP2) or higher
  • Microsoft SQL Server 2005 with SP1 or higher
  • 2 GB RAM
  • 1 GB free disk space
  • Browser (for management console): Firefox 2.0 or later, or Microsoft Internet Explorer 7.0 or later

Supported Databases for Monitoring

  • Oracle version 8.1.7 or later, running on Sun Solaris, IBM AIX, Linux, HP-UX, Microsoft Windows
  • Microsoft SQL Server 2000 or later on any supported Windows platform
  • Sybase ASE 12.5 or later on all supported platforms

Demos / Video

Demos

Learn how the McAfee Database Security Solution protects you from database breaches and falling victim to cybercrime. This solution includes McAfee Vulnerability Manager for Databases, McAfee Database Activity Monitoring, and McAfee ePolicy Orchestrator software.

Use a single solution and achieve continuous compliance with McAfee Configuration Control.

Customer Stories

University of Bristol

Implementing Real-Time Database Activity Monitoring

Highlights
  • Implemented solution campus-wide with minimal IT resources
  • Immediate visibility into all suspicious activity across Oracle and Microsoft SQL server databases
  • Identified and remediated vulnerabilities in internally developed applications by working closely with developers

News / Events

Resources

Data Sheets

McAfee Database Activity Monitoring

McAfee Database Activity Monitoring automatically finds databases on your network, protects them with a set of preconfigured defenses, and helps you build a custom security policy for your environment.

Solution Briefs

White Papers

Community

Forums

No results found

Blogs

  • McAfee Q4 Threats Report Shows Malware Surpassed 75 Million Samples in 2011
    David Marcus - February 21, 2012
    Today we released our Fourth Quarter 2011 Threat Report, revealing that malware surpassed the our estimate of 75 million unique malware samples last year. Although the release of new malware slowed a bit in Q4, mobile malware continued to increase and recorded its busiest year to date. Malware The overall growth of PC-based malware actually Read more...
  • Cultural Security: Promoting Security Policies Using Organizational Culture
    Steven Fox - September 06, 2011
    Most of us refer to security policies in much the same way as we refer to our car manuals – when something unexpected happens.  We know these documents have useful information.  However, their utility is tied to situations where answers do not present themselves readily. According to Chris Noel, SVP of Product Management at ANXeBusiness, Read more...
  • Building an Arsenal of Best-in-Breed Database Security Solutions
    Eric Schou - August 19, 2011
    Visit any news site on the Web, and undoubtedly you’ll come across a barrage of articles publicizing the details of yet another data breach. With the prominence of SQL injection attacks, and malicious insiders and hackers exploiting sensitive data stored on unpatched and vulnerable databases, enterprise organizations have found themselves reevaluating their security strategies. Following Read more...
  • Hackers vs. Hackers: The New Frontier Of Embedded Devices
    Stuart McClure - June 27, 2011
    If we look at the evolution of hacking, certain techniques never go out of style, but we’re at the beginning of a big shift in terms of the targets.  The threat landscape has evolved beyond PCs, tablets, and smartphones to a whole new battleground: connected devices all around us. According to Ericsson, there will be Read more...
  • The Consumer Experience, The Data Center And 99.9% Uptime
    Evelyn de Souza - May 23, 2011
    While 99.9% network and server uptime has long been an established standard in data centers, the consumer experience so often fails to live up to that, and I as I was reminded of again this weekend.    Unplanned network or server changes or vulnerabilities are often the cause of website outages.  And, as the website Read more...