McAfee Virtual Patching for Databases

McAfee Virtual Patching for Databases

Comprehensive protection from unpatched vulnerabilities

Next Steps:

Overview

McAfee Virtual Patching for Databases shields databases from the risk presented by unpatched vulnerabilities by detecting and preventing attempted attacks and intrusions in real time, without requiring database downtime or application testing. With Virtual Patching for Databases, organizations secure protection from threats even if they have not yet installed a vendor-released patch to deal with a known vulnerability.

Security for older versions of database management systems — Protect older versions of database management systems, even those no longer supported by the vendor. For applications running on older versions of the database where patches are no longer provided, Virtual Patching for Databases can protect the systems from attacks, helping to satisfy governance requirements.

Uninterrupted protection for production databases — Installation is nonintrusive, as the sensor is read-only, installs as a user process, and makes no changes to the database management system software. Only minimal testing of applications is necessary.

No database downtime required — Implement patch protection without having to take down databases during installation.

Features & Benefits

Protect sensitive databases between the release and installation of vendor patches

Safeguard databases with virtual patches. McAfee host-based software uses a small, nonintrusive sensor on each database server to detect and prevent attempted exploits of vulnerabilities.

Get ongoing updates to defend against exploits

Trust continuous research of the evolving threat landscape to provide timely patch updates that keep organizations protected despite the changing nature of attack vectors.

Facilitate compliance by keeping systems up to date

Meet compliance standards, including PCI DSS, HIPAA, SOX, and other corporate governance rules.

Secure your databases with an easy-to-implement solution

Save time with less frequent patches, reducing the effort required for application regression testing and physical patch installation.

System Requirements

These are minimum system requirements only. Actual requirements will vary depending on the nature of your environment.

Minimum system requirements

  • McAfee ePolicy Orchestrator 4.5
  • Microsoft Windows Server 2003 with Service Pack 2 (SP2) or higher
  • Microsoft SQL Server 2005 with SP1 or higher
  • 2 GB RAM
  • 1 GB free disk space
  • Browser (for management console): Firefox 2.0 or later, or Microsoft Internet Explorer 7.0 or later

Supported Databases

  • Oracle version 8.1.7 or later, running on Sun Solaris, IBM AIX, Linux, HP-UX, Microsoft Windows
  • Microsoft SQL Server 2000 or later on any supported Windows platform
  • Sybase ASE 12.5 on all supported platforms

News / Events

News

Events

No results found

Resources

Data Sheets

McAfee Virtual Patching for Databases

For a technical summary on the McAfee product listed above, please view the product data sheet.

White Papers

Community

Forums

No results found

Blogs

  • Urchins, LizaMoons, Tigers, and Bears
    Jim Walter - October 21, 2011
    In early April, I wrote about the famed “LizaMoon” SQL-injection attacks. I said it then, and I’ll say it again now: SQL-injection (SQLi) attacks are a constant. Some of these attacks are more visible than others.  Some adversaries find intelligent ways to hide their tracks so as not to splatter evidence of their misdeeds all over various search Read more...
  • In the Wake of the Week: Need Sleep
    Lang Tibbils - October 07, 2011
    They are keeping me busy here at McAfee. Beginning to think that “Safe” isn’t the only thing that “Never Sleeps” around here. This weeks highlights include, our re-designed channel partner website, a blog recap of the Sept. 12 Global Channel Partner Town Hall Meeting, staying focused while attending the McAfee Partner Summit, a new market Read more...
  • Building an Arsenal of Best-in-Breed Database Security Solutions
    Eric Schou - August 19, 2011
    Visit any news site on the Web, and undoubtedly you’ll come across a barrage of articles publicizing the details of yet another data breach. With the prominence of SQL injection attacks, and malicious insiders and hackers exploiting sensitive data stored on unpatched and vulnerable databases, enterprise organizations have found themselves reevaluating their security strategies. Following Read more...
  • McAfee Acquires Leading Provider of Database Security Technology
    David DeWalt - April 06, 2011
    I am excited to announce another important milestone in our growth as the world’s largest dedicated security company.  Today, McAfee completed the acquisition of privately owned Sentrigo, a leading provider of database security and compliance, assessment, monitoring and intrusion prevention solutions. Through this acquisition, we believe McAfee can broaden its security portfolio to now secure Read more...
  • Database Security: A Profitable and Differentiated Offering
    MFEChannelChief - March 30, 2011
    Find out how McAfee partners can add recently-acquired Sentrigo solutions to their portfolio.