McAfee HISCDE-AB-IA Product Guide - Page 7

Introducing Host Intrusion Prevention, Host IPS protection

Page 7 highlights

Introducing Host Intrusion Prevention McAfee® Host Intrusion Prevention is a host-based intrusion detection and prevention system that protects system resources and applications from external and internal attacks. It provides a manageable and scalable intrusion prevention solution for workstations, notebooks, and critical servers, including web and database servers. Its patented technology blocks zero-day and known attacks. Host Intrusion Prevention (sometimes abbreviated in the product as Host IPS or HIP) can protect information and prevent the compromising of system and network resources and applications that store and deliver information. It accomplishes this with an end-point firewall feature and an intrusion prevention system (IPS) feature. The IPS feature has monthly content updates, which reduces the urgency of patches for new threats. The Host Intrusion Prevention firewall feature is purchased separately or in combination with the Host Intrusion Prevention IPS feature. Host Intrusion Prevention is fully integrated with ePolicy Orchestrator and uses its framework to deliver and enforce policies. This approach provides a single management solution that allows for mass deployment of up to 100,000 systems in multiple languages across an entire enterprise for true global coverage. Contents Host IPS protection Host IPS policies Host IPS policy management Host IPS policy tracking and tuning Host IPS protection After all the required components for Host Intrusion Prevention are installed and communicating, you are ready to apply protection, monitor events, and update policies and content as needed. Basic protection Host Intrusion Prevention ships with a set of default settings that provide basic protection for your environment. These settings include: • For IPS protection: • High severity signatures are prevented and all other signatures are ignored • McAfee applications are listed as trusted applications for all rules except IPS self-protection rules • Predefined applications and processes are protected • For firewall protection: McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Introducing Host Intrusion Prevention
McAfee
®
Host Intrusion Prevention is a host-based intrusion detection and prevention system
that protects system resources and applications from external and internal attacks. It provides
a manageable and scalable intrusion prevention solution for workstations, notebooks, and critical
servers, including web and database servers. Its patented technology blocks zero-day and
known attacks.
Host Intrusion Prevention (sometimes abbreviated in the product as Host IPS or HIP) can protect
information and prevent the compromising of system and network resources and applications
that store and deliver information. It accomplishes this with an end-point firewall feature and
an intrusion prevention system (IPS) feature. The IPS feature has monthly content updates,
which reduces the urgency of patches for new threats. The Host Intrusion Prevention firewall
feature is purchased separately or in combination with the Host Intrusion Prevention IPS feature.
Host Intrusion Prevention is fully integrated with ePolicy Orchestrator and uses its framework
to deliver and enforce policies. This approach provides a single management solution that allows
for mass deployment of up to 100,000 systems in multiple languages across an entire enterprise
for true global coverage.
Contents
Host IPS protection
Host IPS policies
Host IPS policy management
Host IPS policy tracking and tuning
Host IPS protection
After all the required components for Host Intrusion Prevention are installed and communicating,
you are ready to apply protection, monitor events, and update policies and content as needed.
Basic protection
Host Intrusion Prevention ships with a set of default settings that provide basic protection for
your environment. These settings include:
For IPS protection:
High severity signatures are prevented and all other signatures are ignored
McAfee applications are listed as trusted applications for all rules except IPS self-protection
rules
Predefined applications and processes are protected
For firewall protection:
7
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5