McAfee Database Activity Monitoring v4.2
November 01, 2011
starting under $5,000
- Ease of Use:
- Value for Money:
- Overall Rating:
- Strengths: A strong rule-creation tool. Users can easily create active responses based on the details in an alert.
- Weaknesses: Rules and signature driven. Have to create very complex rules system to prevent zero-day threats.
- Verdict: Vulnerability assessment tool with great tuning ability and a solid compliance reporting engine.
McAfee Database Security is a software solution that monitors the database management system (DBMS) and protects it from both internal and external threats. The McAfee Database Security solution comprises three components: the Database Security Sensor, Database Security Server and the Database Security Web Console. The sensor monitors access to the DBMS and sends transaction data to the security server. Based on the policies defined via the web console, the server logs the transaction, issues an alert and/or prevents access to the DBMS.
The software was simple to load. It is wizard driven and provides options to install any required dependencies. Once deployed, the user interface is accessed through a web browser. The interface is a tabbed page providing easy navigation between various admin, dashboard and reporting features. McAfee Database Activity Monitoring finds databases that exist on the networks and deploys quickly if using the preconfigured policies with which it ships.
Database Activity Monitoring protects sensitive data from threats by tracing activity locally on each database server, and by alerting or terminating malicious behavior in real time. Admins can actively terminate a session based on security policy violations. There is also some good best practice and compliance reports available, including those focused on segregation of duties and privileged user activity.
Reporting was good out of the box, with a handful of system- and compliance-based templates available. Alerting was strong, integrated with lightweight directory access protocol (LDAP), simple network management protocol (SNMP), Syslog and Twitter for inband, and out-of-band alerting.
Pricing starts under $5,000, based on server capacity, including the first year of support. Volume discounts apply.
Sign up to our newsletters
SC Magazine Articles
- Long list of devices believed to be affected by NetUSB vulnerability
- Website observed serving 83 executable files, more than 50 percent malware
- Scammers target oil companies with sneaky attack
- CareFirst BlueCross BlueShield breached, more than one million individuals notified
- TeslaCrypt used to extort over $76K in recent months
- Hackers exploit Starbucks auto-reload feature to steal from customers
- Study: Nearly all SAP systems remain unpatched and vulnerable to attacks
- Former Nuclear Regulatory Commission employee arrested for alleged spear phishing campaign
- Millions of WordPress websites vulnerable to XSS bug
- FireEye first cybersecurity firm awarded DHS SAFETY Act certification
- Thousands of Bellevue Hospital Center patients notified of data breach
- Study: 86 percent of websites contain at least one 'serious' vulnerability
- Investigation ongoing in reported multimillion member Adult FriendFinder breach
- Report: $19M breach settlement between MasterCard, Target terminated
- FTC gives thumbs up to companies that cooperate during breach probes