
• Integration with Network Security Platform — This deployment involves integrating McAfee
Advanced Threat Defense with Network Security Platform Sensor and Manager.
Based on how you have configured the corresponding Advanced Malware policy, an inline Sensor
detects a file download and sends a copy of the file to McAfee Advanced Threat Defense for
analysis. If McAfee Advanced Threat Defense detects a malware within a few seconds, the Sensor
can block the download. The Manager displays the results of the analysis from McAfee Advanced
Threat Defense.
If McAfee Advanced Threat Defense requires more time for analysis, the Sensor allows the file to be
downloaded. If McAfee Advanced Threat Defense detects a malware after the file has been
downloaded, it informs Network Security Platform, and you can use the Sensor to quarantine the
host until it is cleaned and remediated. You can configure the Manager to update all the Sensors
about this malicious file. Therefore, if that file is downloaded again anywhere in your network, your
Sensors might be able to block it.
For information on how to integrate Network Security Platform and McAfee Advanced Threat
Defense, refer to the latest Network Security Platform Integration Guide.
Figure 1-3 Integration with Network Security Platform and McAfee ePO
Malware detection and McAfee
®
Advanced Threat Defense
The McAfee Advanced Threat Defense solution
1
McAfee Advanced Threat Defense 3.0.4 Product Guide
13
Comentarios a estos manuales