Pete Finnigan's Oracle Security Forum (http://www.petefinnigan.com/forum/yabb/YaBB.cgi)
Oracle Security >> Oracle Security tools >> McAfee products
(Message started by: Pete Finnigan on May 9th, 2014, 1:33pm)

Title: McAfee products
Post by Pete Finnigan on May 9th, 2014, 1:33pm
Hi all,
 I'm working at a site that has a large Oracle database estate, mainly of AIX and Tru64, consisting of databases versions from 7 through to 11g.
 Due to various issues (number of databases, gaining business approval, testing resource availability etc) they would like to evaluate the use of tools such as Application Control and/or Virtual Patching for Databases, to try to secure the databases without having the necessary downtime etc.  I'd be interested to hear if anybody has any experiences (good or bad) that they could share.
Regards,
 Rob

Title: Re: McAfee products
Post by Pete Finnigan on Jul 2nd, 2014, 10:49am
Hi,

Its a late response, sorry. VP should only be considered really as a stop gap not a permanent solution to not patching. The problem with VP is that the products tend to block remote attacks only and not local attacks and the actual VP technology does not solve other database security issues such as weak passwords, bad privilege design on data  etc.

A VP product is fine as a belt and braces and I am sure all tghe vendors would agree with me. You cannot replace patching for a long period with these products

hth

Pete



Powered by YaBB 1 Gold - SP 1.4!
Forum software copyright 2000-2004 Yet another Bulletin Board