How do insider threats work?

While insider attacks can take on numerous diverse forms, the main constituent is that the threat is originated from inside your network set against outside where most of the protection technologies are focused. The insider threat is already on your network, so old-style barricades such as firewalls, antivirus and IDS/IPS will not be enabled to identify his/her activities. There are 3 main kinds of insider attacks:

  • Careless Insiders – Insiders who unintentionally expose information including a staff member who forgets their device on a plane.
  • Malevolent Insiders – Insiders who steal information on purpose or terminate systems in place including dissatisfied staff members who erase company records on their last day of work.
  • Compromised Insiders – Insiders whose login IDs and/or device have been compromised by an outside threat.

The Cisco Stealthwatch Solution

One of the main apprehensions regarding insider threats is that old-style network protection tools are seldom able to identify them. Usually attackers work behind firewalls and other border protections and are able to carry out their attacks without being identified. Complicating the state of affairs even further is the advent and proliferation of the Bring Your Own Device (BYOD) workplace, in which staff members often use individual devices like smartphones at work, enhancing the susceptibility of enterprise networks.

To identify insider attacks, enterprises have to use wide-ranging inside network visibility and protection analysis. Regrettably, old-style protection technologies including SIEM and complete packet capture can only give a small slice of visibility into the inside network, and usually become unpractical when scaled beyond restricted installations. By gathering and examining huge quantities of telemetry data, the Stealthwatch System allows enterprises to tie together existing infrastructure to get a full picture of network movements and find behaviors that could indicate an insider attack.

Extreme quantities of network traffic going from one user’s device to a printer could indicate an attempted stealing of intellectual property. Or, in case a user is often interacting with an unaccustomed IP address in a different country, it could point to the user’s device being compromised. An important differentiator of the Cisco Stealthwatch System is the capability to screen not only traffic going in and out of the corporate network, but also crosswise communications, which is of high importance for finding insider attacks functioning inside the network.

Cisco’s Stealthwatch System supplies the inside visibility and complete audit trail required to fill in hazardous network blind spots and find harmful insider threats. Nevertheless, once distrustful activity is found, you also have to be able to tie it to a definite user or device for operational extenuation. The Stealthwatch System supplies numerous layers of protection context to build a perfect picture of user activities and help system Admins in making educated judgements. These include:

  • User Characteristics – Tying up network activities to the user liable is important for finding insider attacks.
  • Device Cognizance – Device data assists you to find unapproved or unprotected devices, as well as quickly expose devices that may have been compromised.
  • Application Level Visibility – The capability to view which applications are in use can assist in pinpointing threats and malevolent programs.
  • Threat Feed Data – Assists in identifying devices or users who have been working in tandem with known malevolent hosts.

Stealthwatch’s context-aware protection analytics considerably enhance threat identification and event response for a range of threats comprising insider attacks, often minimizing troubleshooting down from days and months to just a few minutes. In addition, the Cisco Stealthwatch System can save months or even years of network traffic information to assist with more wide-ranging forensic inquiries into preceding security events – a critical constituent for serving to preempt future attacks.

To speak with one of our Licensing Specialists, please click here.