Battling APTs with Cisco NetFlow and Stealthwatch – Part 2

For most cutting edge threats, the attacker will perform a mixture of some or all of these activities: 1) network scouting, 2) spear phishing, 3) taking advantage of 0-day susceptibilities, 4) use mystification to dodge COTS protection products, 5) clandestine command-and-control communications, 6) inside pivoting that dodges identification by inside IPS systems, and 7) data extraction. Most of these steps are not found easily via perimeter/signature based solutions, but can be exposed using internal network screening.

It is imperative to identify the role of human event responders in fighting innovative protection attacks. No protection solution is going to spontaneously find and block APTs while your IT staff is asleep at home. The best solutions utilize the powers of both computerized and human scrutiny – assisting expert event responders screen their systems/networks and understand the mass of data present to identify the elusive signs that cutting edge threats leave behind. Next-generation network visibility and protection analytics solutions can assist here by turning the network into an always-on sensor grid for finding distrustful activities, and spontaneously interpreting huge amounts of information into actionable intelligence.

The Cisco Stealthwatch Solution

Cisco’s Stealthwatch System acts as a critical layer of defense against APTs by giving in-depth, inside network visibility and cutting edge protection analysis for finding furtive threats. By gathering and examining huge quantities of telemetry data from current network devices, Stealthwatch gives IT and protection Admins a full, cost-efficient picture of all that is occurring on the network, making it simpler to examine and alleviate irregular activities that can indicate an APT attack.

Not like other solutions which only screen traffic coming in and out of the network, Stealthwatch can also screen lateral traffic to find attackers doing bad inside the corporate network. This ability is crucial for finding APTs as they are usually able to infiltrate perimeter protection defenses easily.

Stealthwatch empowers enterprises to find the numerous steps that APTs follow to penetrate a network, like network investigation, interior malware proliferation, communication with command-and-control servers and information extraction. Cutting-edge features like application, device and identity cognizance, alongwith Threat Feed information, further enhance protection circumstance and situational cognizance.

The over dependence on A/V and IDS solutions has debilitated the shared protection position, as these solutions can’t stand up to face the unconventional attacks we now see. New solutions fixated on network/traffic intelligence are the best method of fighting innovative attacks, and much wider embracing is needed.

Beyond enhancing real-time attack identification, the Stealthwatch System radically quickens event response times, usually minimizing troubleshooting from days and months at a time to just a few minutes. The capability to save network information for years, along with cutting edge protection analysis, also makes Stealthwatch perfect for performing more accurate post-event scientific inquiries to better comprehend and avert future attacks.

Regrettably, there are no solutions today that will keep hackers totally out of corporate networks. However, there are solutions like Stealthwatch System that can rapidly find, frustrate and alleviate network attacks before they transform into overwhelming data breaches which make headlines.

To speak with one of our Cisco Licensing Specialists, please click here.

Battling APTs with Cisco NetFlow and Stealthwatch – Part 1

Resolute attackers will ultimately infiltrate their target’s corporate network, usually using social engineering stratagems to pinch IDs and get access. To fight APTs, it is critical that corporations get visibility into their inside networks to fill in gaps left by perimeter protection solutions.

How do APTs work?

Cutting-edge attackers often go to extreme lengths to aim at certain companies and employ specifically personalized amalgamations of threat vectors and unpatched susceptibilities to penetrate a specific setting. These attackers may have a long-term purpose of gathering information from a particular target network, which means that they must preserve access to the corporate network without being identified.

APT attackers will use muddying methods and even check their activities against frequently used protection products to stay under the radar. If one part of the threat attack bombs, they will carry on trying to break down the doors until they are able to gain entry. In addition, cutting-edge attackers can find methods to access more protected centralized offices using less-protected far-flung offices or even contractor or partner corporate networks, implying that nearly any enterprise or far flung site office may fall victim to an APT.

Due to the triumph of these tactics, monetarily driven cyber villains have also started to mimic some of the techniques used by APTs, further widening the swath of organizations that are susceptible to advanced attacks. Many of these operations involve well-funded organizations with large numbers of participants who have highly specialized skills. These factors contribute to their success, making them a very formidable threat.

APT Challenges

Unfortunately, there is a pervasive misunderstanding among a lot of security organizations that if they have an antivirus, a firewall, IDS/IPS, SIEM and a cutting-edge malware detection system, then they are well safeguarded from all threats which come their way. In a time of increasing insider attacks and APTs, this is just not true. In reality, we have malware functioning for years before any antivirus software can find it, and that malware usually will spread out by abusing zero-day protection susceptibilities for which there are no patches in existence, utilizing exploits that are not detectable.

Keeping in mind the tailored, persistent and well-supported nature of APTs, it is crucial that enterprises know what is happening inside their internal corporate networks to fill in the spaces left behind by orthodox protection mechanisms. A full audit trail of network activities can be utilized to completely evaluate the influence of a breach and search for continuing spying and information exfiltration happening in real time.

To speak with one of our Cisco Licensing Specialists, please click here.