Specifications/Technical Information
- McAfee Network Security Platform Technical Information - High Performance Intrusion Prevention IPS
- McAfee Network Security Platform Specifications - High Performance Intrusion Prevention IPS
- McAfee Advanced Threat Defense Technical Information - Malware Detection
- McAfee Advanced Threat Defense Specification - Malware Detection
- McAfee SIEM Knowledge Base - Threat Visibility with Log Analysis

McAfee
McAfee
McAfee Network Security Platform

McAfee Network Security Platform(旧名称:IntruShield)は、ネットワークへの様々な既知の攻撃・未知のゼロデイ攻撃に対し、高精度で包括的な侵入防御をリアルタイムに行う、ハイパフォーマンス不正侵入防御アプライアンス(IPS)です。
ASIC、FPGAを採用し、IPS専用に設計されたハードウェアならではのハイパフォーマンスを実現します。
3つの検知手法(シグネチャ検知、アノマリ検知、DDos/Dos検知)により、精度の高い検知/防御を行います。
customer link
For resellers
high performance
Hardware designed specifically for IPS.
(Uses ASIC and FPGA)
- Available from 100M model to 100G model. Achieve high performance and scalability.
Highly accurate detection method

High-precision signature detection, heuristic anomaly detection, self-learning Dos/DDos detection, and parallel operation of three detection methods achieve high detection accuracy and reliability.
Easy operation management
- A graphical and intuitive management console. Detailed attack information can also be confirmed by drilling down.
- Early operation can be started with recommended defense settings. (Can be customized)
- Automatically updates the latest signatures, including regular signatures and emergency signatures.
- Automatic generation of reports (PDF, CSV, HTML). Automatic delivery by e-mail is also possible.
*Reports, attack commentary, manuals, and online help are also available in Japanese.
Virtual IPS function
A single sensor (hardware) can set security policies for multiple segments and servers. Since it can be used virtually as multiple sensors, it is possible to greatly reduce and optimize the introduction and management costs. Optimized security policies also reduce unnecessary alerts.

SSL decryption detection function
Reading the private key from the SSL server allows the Sensor to decrypt and parse encrypted communications.
IPv6 support
You can analyze IPv6 communication. It operates with high performance even in a mixed environment of IPv4/IPv6 and an environment with tunneled IPv6 communication.