McAfee Database Activity Monitoring v4.2
November 01, 2011
starting under $5,000
- Ease of Use:
- Value for Money:
- Overall Rating:
- Strengths: A strong rule-creation tool. Users can easily create active responses based on the details in an alert.
- Weaknesses: Rules and signature driven. Have to create very complex rules system to prevent zero-day threats.
- Verdict: Vulnerability assessment tool with great tuning ability and a solid compliance reporting engine.
McAfee Database Security is a software solution that monitors the database management system (DBMS) and protects it from both internal and external threats. The McAfee Database Security solution comprises three components: the Database Security Sensor, Database Security Server and the Database Security Web Console. The sensor monitors access to the DBMS and sends transaction data to the security server. Based on the policies defined via the web console, the server logs the transaction, issues an alert and/or prevents access to the DBMS.
The software was simple to load. It is wizard driven and provides options to install any required dependencies. Once deployed, the user interface is accessed through a web browser. The interface is a tabbed page providing easy navigation between various admin, dashboard and reporting features. McAfee Database Activity Monitoring finds databases that exist on the networks and deploys quickly if using the preconfigured policies with which it ships.
Database Activity Monitoring protects sensitive data from threats by tracing activity locally on each database server, and by alerting or terminating malicious behavior in real time. Admins can actively terminate a session based on security policy violations. There is also some good best practice and compliance reports available, including those focused on segregation of duties and privileged user activity.
Reporting was good out of the box, with a handful of system- and compliance-based templates available. Alerting was strong, integrated with lightweight directory access protocol (LDAP), simple network management protocol (SNMP), Syslog and Twitter for inband, and out-of-band alerting.
Pricing starts under $5,000, based on server capacity, including the first year of support. Volume discounts apply.
SC Magazine Articles
- Yahoo breach; State-sponsored actors suspected, at least 500 million accounts affected
- Education sector bullied by ransomware and can barely defend itself, report
- DetoxCrypto ransomware imitates Malwarebytes software
- Cisco warns of exploitation of new flaws linked to Shadow Brokers exploits
- House Committee urges Obama not to pardon Snowden
- Microsoft Office 365 hit with massive Cerber ransomware attack, report
- Hard Rock Hotel & Casino Las Vegas hit with POS breach
- X-ray and MRI machines among devices used as springboards for data breach attacks
- Hacker purportedly selling over 650,000 stolen medical records on dark web marketplace
- Wi-Fi warning! Study finds U.S. unaware of public Wi-fi risks
- OpenSSL patches 14 vulns, including high-severity flaw that can be exploited for DoS attacks
- IoT assault, connected devices increasingly used for DDoS attacks
- Cybercriminals already able to hack ATM biometric readers
- Cities planning transparency laws for police surveillance tech
- Malicious apps leveraging top UK brands has increased by 130%