Foxboro Evo™ Process Automation System: Product Specifications

Download as pdf or txt
Download as pdf or txt
You are on page 1of 8

Foxboro Evo™

Process Automation
System
Product Specifications

PSS 31S-4McAfee

McAfee® Security Products

INTRODUCTION Managed Solution


Schneider Electric incorporates globally recognized The Managed solution allows you to install and
third-party security packages that provide additional monitor the McAfee products on your endpoints from
security enhancement features to help complement a single, centralized location using the ePolicy
the security features already built into our products. Orchestrator (ePO) console. You can also update
Contemporary security applications go beyond DAT files, Exploit Prevention content, and patches on
traditional firewall and antivirus software to provide the endpoints from the ePO console. In Managed
advanced host intrusion prevention, application and mode, Endpoint Security along with additional
device control, and more. These security suites are applications such as Rogue System detection,
referred to as Endpoint Protection (EPP). Device Control, and Integrity Control are supported.

A system with I/A Series v8.8 or Control Core


Self-Managed Solution
Services v9.0 or later supports the addition of these
The Self-Managed solution only supports McAfee
packages from McAfee. McAfee EPP products can
Endpoint Security. You need to install and update
be installed in two ways:
each endpoint manually.
 Managed Solution

 Self-Managed Solution
PSS 31S-4McAfee
Page 2

FEATURES virus scanning software with virus definition files


(DAT files) that are part of ENS Threat Prevention.
Endpoint Security (ENS) 10.5 McAfee frequently releases new DAT files to
ENS is the only supported McAfee product that can incorporate results of its ongoing research on the
be installed without ePO in a Self-Managed mode. characteristics of new viruses.
The other applications such as McAfee Agent, RSD,
 Exploit Prevention Content: An exploit is a
Device Control, and Integrity Control need ePO.
sequence of commands that allows an attacker
ENS is also the only supported McAfee product that to take advantage of a vulnerability or a bug in a
can be installed on the Standard edition of Foxboro process or software application. To control a
EvoTM. The rest of the McAfee applications need the system, the attacker needs to take advantage of
Security Enhanced edition of Foxboro Evo. a chain of vulnerabilities in the system. Blocking
Endpoint Security consists of these modules: any attempt to exploit a vulnerability in the chain
results in blocking the entire exploitation attempt.
 Threat Prevention
The Threat Prevention module in McAfee ENS
 Firewall
provides a content based Exploit Prevention update
 Web Control every month. This content helps provide protection
Threat Prevention against zero-day exploits.

 Threat Prevention replaces traditional antivirus Firewall


protection and intrusion prevention. There is also a host based firewall available in the
package, which is not turned on by default because
 It improves performance and productivity by
its configuration will be specific to each customer
optimizing the scanning.
endpoint.
 It prioritizes suspicious processes and
The firewall monitors communication between the
applications.
computer and other resources on the network,
 It also provides adaptive behavioral scanning to helping intercept suspicious communication. The
monitor and report on suspicious activity. firewall rules determine how to manage network
Keeping this solution patched and up to date with traffic. Each rule provides a set of conditions that the
the latest qualified version is crucial to the security of network traffic has to meet.
a system. When ENS finds traffic that matches the conditions
Threat Prevention consists of ENS AMCore DAT File of a rule, it either allows or blocks the traffic based on
and Exploit Prevention content products that the user the rule conditions. ENS applies the rule at the top of
needs to update as per the need. the firewall rules list first.

In addition to these types of changes, they also Web Control


provide product patches to incorporate fixes for ENS Web Control works as a browser extension or
installed security applications. add-on with Internet Explorer, Google Chrome™,
and Mozilla Firefox™.
 ENS AMCore DAT File: Users need to continually
update the security products to address new NOTE
vulnerabilities as they are discovered. For We recommend that endpoints used in a
example, users need to continually update the control system are not connected to the
PSS 31S-4McAfee
Page 3

Internet. Web Control can add a layer of ePolicy Orchestrator®


protection in case any inadvertent McAfee ePolicy Orchestrator provides the ability to
connections are made. centrally manage the following McAfee components:
Before using web control, users need to activate the Agent, RSD, DLP, Solidcore/Integrity Control, and
ENS web control extensions manually on each ENS. It allows users to install, configure, update,
endpoint for these browsers. Below are the features monitor, and deploy these applications to client
for Managed and Self-Managed Web Control that workstations and servers. For example, ePO can be
users can configure in the system and create policies used to keep the virus signature (DAT) files up to date
for. from a single location, which helps avoid updating
Managed Web Control DAT files and performing other tasks manually on
each machine in the system.
 Enable or disable Web Control on the user’s
system with an option for disabling the software ePO can be installed on any server running Microsoft
and browser plug-ins. Windows Server 2008 SP2 or later and I/A Series
software v8.8 or Control Core Services software v9.0
 Help control access to sites, pages, and
or later. ePO provides the ability to deploy the
downloads, based on their type of content. For
McAfee security products automatically, from one
example, for file downloads, users can block red
location on the Windows-based workstations and
sites (vulnerable sites) and send a notification
servers on the control network that are in the I/A
when users try to access yellow sites (that do not
Series or the Foxboro Evo Active Directory domain. It
have a reputation for being vulnerable). Green-
also manages and distributes the policy settings and
rated (safe sites) sites and downloads are allowed
other options of the packages.
automatically.
Another major benefit of ePO is the ability to monitor
 Identify sites as blocked or allowed, based on the these packages from the ePO console. Dashboards
URLs and domains. help users to quickly view the status of the products
 Help prevent a user from uninstalling or changing and stations that ePO is managing. They also contain
Web Control files, registry keys, registry values, monitors that run queries and display the results.
services, and processes. When the ePO console is opened, it initially displays
the dashboard window, displaying McAfee provided
 Customize the notification that appears when a
or customized dashboards. A set of predefined
user attempts to access a blocked website.
dashboards is provided with the ePO software.
Self-Managed Web Control However, users can build their own dashboards.
 Enable or disable Web Control on the user’s
system with an option for disabling the software McAfee Agent
and browser plug-ins. The McAfee Agent is the client-side component that
 Help control access to sites, pages, and helps provide secure communication between the
downloads, based on their safety rating or type of ePO and managed products. It performs the
content. For example, users can block red sites following tasks:
and send a notification to users trying to access  Serves as an updater for McAfee products
yellow sites. including DATs and Exploit Prevention content.
PSS 31S-4McAfee
Page 4

 Runs in the background, gathers information and Control. It uses an application called Solidcore that
events from managed systems, and sends them helps block unauthorized applications and changes
to the ePO server. to the process control networks by combining
whitelisting and change control technology.
 Installs products and their updates on managed
systems. Integrity Control functions by listing the processes
that are allowed to run (whitelisting) on fixed function
 Enforces policies and tasks on managed systems
devices. It helps block vulnerable, unauthorized, or
and sends events back to the ePO server.
malicious applications that can compromise the
integrity of systems. Whitelisting helps secure the
Rogue System Detection
system and allows only authorized updates or
Rogue devices are devices that do not have the
changes that are defined by administrators or trusted
McAfee Agent installed and as such are unknown to
sources.
ePO and not part of the management framework.
This means that they are not part of any standards, Integrity Control software also supports change-
security controls, policies, or patch updates. control technology that can block unwanted, out-of-
policy changes before they occur. Solidcore/Integrity
Rogue systems are unprotected systems that create
Control enabled systems block the changes
entry points for potentially harmful programs to
attempted outside of policy. The change attempt is
access the network. Rogue System Detection (RSD)
logged and sent as an alert to administrators.
provides near real-time discovery of rogue systems
through the use of a Rogue System Sensor installed Application Control
on your network. The sensor monitors the network Application Control operates in four modes and can
broadcast messages to detect systems connected to change from one mode to another mode:
the network. If the server cannot recognize the  Disabled mode
system, RSD provides information to ePO through a
 Enabled mode
notification in the dashboard.
 Observe mode
Device Control  Update mode
Device Control is the subset of Data Loss Prevention
Application Whitelisting (AWL) Advantages
(DLP) that is used with Foxboro DCS products. It
helps organizations to reduce the risk of an  Malware applications can use self-modifying
unintentional disclosure of confidential information. It polymorphic code techniques that avoid
helps prevent unauthorized use of removable media signature-based detection by constantly
devices (such as CD/DVD, USB, and floppy disk) to changing. AWL provides a solution because it
guard against data leaks. Such devices are one of allows only pre-approved programs to run on the
the common ways malware can transfer itself from system.
relatively unsecured home or business networks to  Additionally, AWL typically needs less
the control network. maintenance than antivirus applications.
Therefore, it is a good alternative in cases where
Integrity Control/Solidcore daily or weekly maintenance is not feasible.
McAfee Integrity Control consists of two
components: Application Control and Change
PSS 31S-4McAfee
Page 5

SYSTEM REQUIREMENTS

Software Requirements Hardware Requirements


 Windows 7 Standard  Server: HP DL380 Gen 7/Gen 9, H90/V90/V91

 Windows Server 2008 R2 Standard  Workstation: HP Z440/Z420

 I/A Series v8.8 or Control Core Services 9.0 or


later
 FCS 4.0 or Control Software 6.0 or later

ORDERING INFORMATION

Part Number Description

K0204AF McAfee Security Products kit with ePolicy Orchestrator 5.3.2, Endpoint Security
(previously K0204AB) (ENS) 10.5, McAfee Agent 5.0.4, Device Control 10.0.1, Integrity Control 8.0,
and Rogue System Detection 5.0.4. The kit does not contain the J0202AS
license, which is needed for each endpoint that runs any McAfee applications.
The required number of J0202AS licenses are now included with all new
platform purchases but can also be ordered separately as needed for older
platforms.
PSS 31S-4McAfee
Page 6
PSS 31S-4McAfee
Page 7
PSS 31S-4McAfee
Page 8

Schneider Electric Systems USA, Inc. Copyright 2016-2017 Schneider Electric.


38 Neponset Avenue All rights reserved.
Foxborough, MA 02035-2037
United States of America
www.schneider-electric.com Schneider Electric, Foxboro, and Foxboro Evo are
trademarks owned by Schneider Electric SE, its
subsidiaries and affiliates.
Global Customer Support All other trademarks are the property of their respective
Inside US: 1-866-746-6477 owners.
Outside US: 1-508-549-2424
https://pasupport.schneider-electric.com MB 031 0917

You might also like