McAfee Advanced Correlation Engine
McAfee Advanced Correlation Engine monitors real-time data, allowing you to simultaneously use both correlation engines to detect risks and threats before they occur. You can deploy Advanced Correlation Engine with McAfee Enterprise Security Manager to identify and score threat events in real time using both rule- and risk-based logic.
Two dedicated correlation engines and purpose-built performance — Advanced Correlation Engine supplements McAfee Enterprise Security Manager event correlation with a risk detection engine that generates a risk score using rule-less risk score correlation, and a threat detection engine that detects threats using traditional rule-based event correlation.
Processing power to support rich event correlation across your enterprise — The standalone Advanced Correlation Engine scales to accommodate even the largest networks.
Alerts and real-time risk assessment — Identify an asset (users or groups, applications, specific servers, or subnets) and Advanced Correlation Engine alerts you if the asset is threatened. Audit trails and historical replays support forensics, compliance, and rule tuning.
Threat identification and scoring — Advanced Correlation Engine deploys alongside McAfee Enterprise Security Manager to identify and score threat events in real time using both rule- and risk-based logic.
Features & Benefits
Get real-time and historical threat detection
Deploy McAfee Advanced Correlation Engine in either real-time or historical modes. In real-time mode, Advanced Correlation Engine analyzes events as they are collected for immediate threat and risk detection. You get rule-based correlation of real-time event data for detection of threats as they occur or rule-less correlation of real-time event data for detection of threats as they develop.
Model your enterprise risk
Provide impeccable modeling of your organizations risks by scoring attributes that matter. Develop a baseline and send notifications when normal thresholds are exceeded.
Leverage proactive risk assessments against critical data
Use both correlation engines simultaneously to detect risks and threats before they occur, so you can use risk scores within traditional correlation logic.
Achieve recursive threat assessment
Deploy Advanced Correlation Engine in historical mode and you can replay any historical data set through the traditional and rule-less correlation engines.