Battling APTs with Cisco NetFlow and Stealthwatch – Part 2

For most cutting edge threats, the attacker will perform a mixture of some or all of these activities: 1) network scouting, 2) spear phishing, 3) taking advantage of 0-day susceptibilities, 4) use mystification to dodge COTS protection products, 5) clandestine command-and-control communications, 6) inside pivoting that dodges identification by inside IPS systems, and 7) data extraction. Most of these steps are not found easily via perimeter/signature based solutions, but can be exposed using internal network screening.

It is imperative to identify the role of human event responders in fighting innovative protection attacks. No protection solution is going to spontaneously find and block APTs while your IT staff is asleep at home. The best solutions utilize the powers of both computerized and human scrutiny – assisting expert event responders screen their systems/networks and understand the mass of data present to identify the elusive signs that cutting edge threats leave behind. Next-generation network visibility and protection analytics solutions can assist here by turning the network into an always-on sensor grid for finding distrustful activities, and spontaneously interpreting huge amounts of information into actionable intelligence.

The Cisco Stealthwatch Solution

Cisco’s Stealthwatch System acts as a critical layer of defense against APTs by giving in-depth, inside network visibility and cutting edge protection analysis for finding furtive threats. By gathering and examining huge quantities of telemetry data from current network devices, Stealthwatch gives IT and protection Admins a full, cost-efficient picture of all that is occurring on the network, making it simpler to examine and alleviate irregular activities that can indicate an APT attack.

Not like other solutions which only screen traffic coming in and out of the network, Stealthwatch can also screen lateral traffic to find attackers doing bad inside the corporate network. This ability is crucial for finding APTs as they are usually able to infiltrate perimeter protection defenses easily.

Stealthwatch empowers enterprises to find the numerous steps that APTs follow to penetrate a network, like network investigation, interior malware proliferation, communication with command-and-control servers and information extraction. Cutting-edge features like application, device and identity cognizance, alongwith Threat Feed information, further enhance protection circumstance and situational cognizance.

The over dependence on A/V and IDS solutions has debilitated the shared protection position, as these solutions can’t stand up to face the unconventional attacks we now see. New solutions fixated on network/traffic intelligence are the best method of fighting innovative attacks, and much wider embracing is needed.

Beyond enhancing real-time attack identification, the Stealthwatch System radically quickens event response times, usually minimizing troubleshooting from days and months at a time to just a few minutes. The capability to save network information for years, along with cutting edge protection analysis, also makes Stealthwatch perfect for performing more accurate post-event scientific inquiries to better comprehend and avert future attacks.

Regrettably, there are no solutions today that will keep hackers totally out of corporate networks. However, there are solutions like Stealthwatch System that can rapidly find, frustrate and alleviate network attacks before they transform into overwhelming data breaches which make headlines.

To speak with one of our Cisco Licensing Specialists, please click here.

Battling APTs with Cisco NetFlow and Stealthwatch – Part 1

Resolute attackers will ultimately infiltrate their target’s corporate network, usually using social engineering stratagems to pinch IDs and get access. To fight APTs, it is critical that corporations get visibility into their inside networks to fill in gaps left by perimeter protection solutions.

How do APTs work?

Cutting-edge attackers often go to extreme lengths to aim at certain companies and employ specifically personalized amalgamations of threat vectors and unpatched susceptibilities to penetrate a specific setting. These attackers may have a long-term purpose of gathering information from a particular target network, which means that they must preserve access to the corporate network without being identified.

APT attackers will use muddying methods and even check their activities against frequently used protection products to stay under the radar. If one part of the threat attack bombs, they will carry on trying to break down the doors until they are able to gain entry. In addition, cutting-edge attackers can find methods to access more protected centralized offices using less-protected far-flung offices or even contractor or partner corporate networks, implying that nearly any enterprise or far flung site office may fall victim to an APT.

Due to the triumph of these tactics, monetarily driven cyber villains have also started to mimic some of the techniques used by APTs, further widening the swath of organizations that are susceptible to advanced attacks. Many of these operations involve well-funded organizations with large numbers of participants who have highly specialized skills. These factors contribute to their success, making them a very formidable threat.

APT Challenges

Unfortunately, there is a pervasive misunderstanding among a lot of security organizations that if they have an antivirus, a firewall, IDS/IPS, SIEM and a cutting-edge malware detection system, then they are well safeguarded from all threats which come their way. In a time of increasing insider attacks and APTs, this is just not true. In reality, we have malware functioning for years before any antivirus software can find it, and that malware usually will spread out by abusing zero-day protection susceptibilities for which there are no patches in existence, utilizing exploits that are not detectable.

Keeping in mind the tailored, persistent and well-supported nature of APTs, it is crucial that enterprises know what is happening inside their internal corporate networks to fill in the spaces left behind by orthodox protection mechanisms. A full audit trail of network activities can be utilized to completely evaluate the influence of a breach and search for continuing spying and information exfiltration happening in real time.

To speak with one of our Cisco Licensing Specialists, please click here.

Cisco Stealthwatch 6.9.0 Released

Updated User Interface, Competences and Enhancements

Stealthwatch 6.9.0 supplies a more enriched user experience inside the Stealthwatch Management Console by enabling the user to see large tables and graphical output more quickly and easily.

Some improvements include the following:

  • New Alarming Hosts pane view which displays the quantity of hosts which have raised an alarm today for each alarm category with one week trends analysis available
  • The Top Alarm Raising Hosts widget enables you to view at a glimpse a highlighted list of hosts in order of their risk severity
  • Top Reports gives quick access to top Apps, port protocols, etc.
  • Host Group reporting with interactive graphs of traffic reports and top Apps traffic

Enhanced Security Incidents and Alarm Documentation

Gives enhanced visibility, security, and response as it quickens the time to threat identification with improved reporting and alarm functionality that allows:

  • An enhanced capability to managed alarm policies by the addition policies control feature
  • An improved system security category model for ranking of identified security incidents
  • Improved security events and alarm documentation for better correlation between security events and traffic flows.
  • Common and Shared Services
  • Integrated management and configuration of the Cisco UDP Director inside the Stealthwatch Management Console

Improved Assimilation with the Cisco Identity Services Engine (ISE)

Improved incorporation with Cisco ISE to better leverage the Platform Exchange Grid (pXGrid) for both telemetry and resolution, leading to a more precise extension of visibility into user data and statistics. Also incorporated is support for the Identity Services Engine Passive Identity Concentrator, simplifying amplification of user information without necessitating Cisco ISE to directly validate users or manage access to the corporate network.

To learn more about how Stealthwatch can protect your network, click here.

To speak with one of our Licensing Specialists, please click here.

Cisco Stealthwatch Versus the WannaCry Epidemic

Apprehended in the wild and scrutinized by members of Cisco’s industry leading Talos threat intelligence team, the early strain of WannaCry comprises a malware payload which depolys ransomware on an infested host computer. It scans comprehensively over TCP port 445 and can employ a susceptibility existing in some unpatched Windows OS running devices. WannaCry has the capability to spread all over a network, comparable to a worm, causing pervasive infestations.

This blog post outlines how clients can utilize Cisco security solutions to protect their company networks and devices against this malware and its probable alternatives that are anticipated in the near future.

Infection Identification 

The preliminary strain of WannaCry malware depends on on the Server Message Block (SMB) protocol to contaminate and proliferate devices operating MS Windows on the corporate network. By utilizing Cisco Stealthwatch, network operators can screen SMB movements inside the corporate network.  

  • Cisco Stealthwatch has built in reports which can specially track and provide reports on SMB traffic amongst in-house host computers and Internet-based hosts, which is a warning of systems infested with WannaCry.
  • WannaCry malware also employs SMB traffic to proliferate inside. SMB traffic in use by hosts on the same subnet is identified as a distrustful activity by Stealthwatch.
  • Stealthwatch has quite a few warnings based on doubtful SMB activity. To be exact, high SMB traffic and SMB connections to many dissimilar hosts. This gives a simple suggestion of hosts affected with WannaCry.
  • Stealthwatch also has the ability to find and report on connects to the TOR network, Bogon IP addresses, and the known command and control hosts. 
  • Host communications with the TOR network and Bogon IP addresses are identified by Stealthwatch based on the constantly updated threat intelligence feeds. This enables security personnel to find any in-house IP which is connecting to doubtful hosts on the Internet.

Propagation Identification  

The preliminary strain of WannaCry malware will attempt to proliferate inside the network laterally (from host to host) in an effort to infest as many hosts as it can. This proliferation action has been seen sometimes even before the malware has triggered its ransomware payload. Stealthwatch is intended to identify all such lateral movements, particularly amongst systems existing on the same subnet.

  • Any scouting and scanning activities, even amongst systems existing on the same subnet, is trackable by Stealthwatch.
  • The Stealthwatch Worm Propagation identification report tracks and associates scanning activities with effective connections to outside command and control hosts, which is in line with activities from WannaCry and other worms. 

Association  

Cisco Stealthwatch will associate dissimilar activities seen on a particular host computer and mark that IP as being suspect based on numerical scores connected to each scrutiny. Stealthwatch then accrues those scores under one index for each respective host IP address and raises a warning called Concern Index. The higher this concern index numerical value is, the more likely the host is participating in malevolent activities.

Scoping and Extenuation

Using the Cisco Stealthwatch Management Center and dashboards, you can simply create a report to list all systems which show suspicious activities and likely contamination. With Cisco Identity Services Engine (ISE) assimilation, you can then isolate suspected devices, stopping the further spread of WannaCry until the time when the threat has been fixed.

Halt the WannaCry Tears

WannaCry is causing chaos across the Internet, and we are likely to see variations for many years to come. Using the universal visibility and cutting-edge analytics of Stealthwatch, you can identify WannaCry activities in a timely manner and react to halt them from spreading all over your network.

To learn more about protecting your network from WannaCry, click here.

To speak with one of our Licensing Specialists, please click here.

Cisco pxGrid

Robust Security

Easier integration: You can utilize one API for open, automated information sharing and control amongst more than 50 security products. Cisco pxGrid assists in enabling a complete ecosystem of differentiated IETF standards-acquiescent technologies to work in tandem. You need to manage and maintain just a singular interface as an alternative to a collection of unconnected APIs.

Immediate visibility: Get all circumstantial and pertinent information on a single screen.

Tailor the methods you share and see security information. View your security position more plainly and succinctly, counting challenging incidents on your network. Increase staff productivity.

Quick examinations: Perform a complete analysis on one system for quick answers. Security intelligence can be shared spontaneously amongst almost all pxGrid-integrated technologies. You don’t need to perform lengthy examinations. Your security processes are able to come up with the answers.

Even quicker responses: Halt threats immediately by using your network as an enforcer. pxGrid enables any incorporated and proficient technology on a pxGrid instance to educate the Cisco Identity Services Engine (ISE) to halt a threat. Any attack anywhere in the network can be stopped instantaneously.

Industry-Standards-Powered Technology

Cisco is a participant of Internet Engineering Task Force (IETF) groups dedicated to designing open, protected, and scalable intelligence sharing. pxGrid and its technology partners will be accommodating as these standards continue to evolve. Cisco also takes part in the IETF Secure Automation and Continuous Monitoring (SACM) and the Managed Incident Lightweight Exchange (MILE) groups.

Cisco pxGrid Components

pxGrid controller:The controller arranges connections amongst platforms. It approves which circumstantial data gets shared amongst those platforms. This control feature is supplied by Cisco ISE.

pxGrid connection agent:A connection agent is incorporated into the partner platform to communicate with the pxGrid controller. The platform aligns which data to share and with which other partner platforms.

Partner technologies:More than 100 pertinent, foremost security technologies are systematized in 13 different security disciplines.

Cisco technologies:Via numerous APIs, more than 10 Cisco products provision incorporation with other Cisco products and with technology partner products.

Cisco DevNet:Cisco’s developers’ community simplifies high-quality product assimilations, like validation and certification.

Marketplace:Find partner integration information on the Cisco sales site.

Technical support:Cisco Support Services will triage with Cisco’s Security Technical Alliance partners to help fix assimilation issues.

Incorporate and step up your protection today

To find out which products in your security arsenal assimilate with Cisco pxGrid, go to http://www.cisco.com/go/csta , or reach out to our Cisco Security Technology Alliance Specialists here.

Migrating from Cisco Secure ACS to Cisco ISE

Cisco ISE is the market-leading security policy administration platform. It amalgamates and systematizes access control to proactively impose role-based access to enterprise networks and resources. It doesn’t matter if a user connects via a wired or wireless network or a VPN. Cisco ISE provides improved user and device visibility to give simplified mobility capabilities. It shares important circumstantial information with incorporated technology partner solutions to hasten their capability to find, alleviate, and remediate threats.

The platform combines substantiation, approval, posture valuation, summarizing, and guest management services in an integrated appliance. A single management console for organizing and directing facilities provides you constancy and streamlined administration. Less hardware is needed as numerous services can now be run on a single node.

End-of-Sale and End-of-Life Announcement for the Cisco Secure Access Control System

NOTE: The Cisco ACS is not being sold anymore after August 30, 2017 and may not be supported. View the End-of-Life Notice to learn:

  • End-of-sale and end-of-life dates
  • Which replacement products are obtainable
  • Data about product support

Guarding Your Cisco Investment

The switch from Cisco Secure ACS to Cisco ISE is simple and cost-efficient. Cisco ISE runs on the same Secure Network Server (SNS) hardware platform as the Cisco Secure ACS. Migrate simply with current Cisco SNS 3515 and 3595 hardware. The Cisco ISE software is also supported on VMware.

Cisco Secure ACS capabilities are obtainable in the base software version of Cisco ISE, that now comprises most TACACS+-based network device management attributes.

All Cisco Secure ACS users with device management arrangements can move to the latest Cisco ISE software release.

Migration Tools and Cisco Services

Cisco ISE comes packaged with a tool to assist clients move from Cisco Secure ACS 5.5 or later to Cisco ISE Software 2.X. The tool will spontaneously move Cisco Secure ACS configuration information (like user and device data and policies) to Cisco ISE, but it will not move monitoring and troubleshooting information.

Cisco Secure ACS users who have installed the Cisco Network Admission Control (NAC) Guest Server and NAC Profiler will have to manually move guest and profiler configuration policies.

Migration tools from Cisco Secure ACS 5.x to Cisco ISE are inbuilt in the Cisco ISE Software Release Software Application Support and Upgrades (SASU) contract excluding those used for monitoring and troubleshooting. There is also a standalone version of this tool obtainable.

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Enterprise Mobility Management Integrations with Cisco ISE

This balance becomes even more difficult to maintain as employees bring their own mobile devices into the office and try to access network resources. How can companies handle these new production devices while still safeguarding the network from external and internal threats? Although network access policy is vital in averting unsanctioned access to networks, enterprises need to also find methods to protect the actual devices themselves in order to be able to impose endpoint compliance. The Cisco Identity Services Engine (ISE), with its assimilations with the leading mobile device management (MDM) and enterprise mobility management (EMM) software, serves as a critical bond amongst protecting devices and securing the network access.

Providing Device Visibility and Dynamic Access Control

As opposed to old-style corporate-provisioned endpoints, personal mobile devices are not provided to employees by the company. Consequently, the problem lies in ensuring that they conform with security policies prior to granting them network access. The key to safeguarding these devices to minimize global risk lies in increased visibility and expanded dynamic control: increased visibility into the mobile devices accessing your network and more dynamic control to correctly categorize and safeguard the devices to make sure that only compliant devices are able to get the right access to the company network.

Enterprises which use assimilations amongst Cisco ISE and MDM/EMM platforms obtain increased comprehension into the bearing of mobile devices to impose suitable network access policies.

How Cisco ISE Works

  • Cisco ISE screens mobile devices as they try to access the network. This detection process gives IT professionals the first step of network visibility. Mobile devices are subjected by Cisco ISE to a security posture assessment as outlines by the enterprise’s IT policy. Cisco ISE asks for posture data related with mobile devices as gathered by the MDM/EMM platforms.
  • Cisco ISE imposes access policy founded on the posture status conveyed by the MDM partner platforms. Access policy can be built on explicit features within Cisco ISE or at a global level of “in compliance” or “not in compliance” within the respective MDM/ EMM platform. End users are able to manage the status of their mobile devices via the Cisco ISE MyDevices portal. End users can lock, suspend, or unenroll devices if they lose or replace them. Cisco ISE can accomplish these processes natively or via MDM/EMM integrations.

Cisco ISE gathers and provides circumstantial information which includes the below:

  • User: User name, IP address, authentication status, location
  • User class: Authorization group, guest, quarantined
  • Device: Manufacturer, model, OS, OS version, MAC address, IP address, network connection method (wired or wireless), location
  • Posture: Posture compliance status, antivirus installed, antivirus version, OS patch level, mobile device posture compliance status (through MDM or MDM ecosystem partners)

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Cisco TrustSec

The Cisco TrustSec classification and policy enforcement functions have been embedded within Cisco switching, routing, wireless LAN, and firewall products. By categorizing traffic based on the circumstantial identity of the endpoint versus its IP address, Cisco TrustSec allows more malleable access controls for vibrant networking environments and data centers.

At the point of network access, a Cisco TrustSec policy group called a Security Group Tag (SGT) is allocated to an endpoint, normally grounded on that endpoint’s user, device, and location features. The SGT signifies the endpoint’s access prerogatives, and all traffic from the endpoint will transport the SGT data. The SGT is utilized by switches, routers, and firewalls to make forwarding choices. Since SGT assignments can represent business parts and roles, Cisco TrustSec controls can be demarcated in terms of business requirements and not causal networking details.

With Cisco TrustSec, a system administrator is able to implement wide-ranging network subdivision and endpoint access controls without the modifying of the network topology (e.g., additional VLANs) and rule administration, which vastly streamlines IT engineering and operations. Cisco TrustSec policies are centrally managed by Cisco Identity Services Engine (ISE) with enforcement roles accessible in campus switches, data center switches, firewalls, and routers.

Business Issues Addressed

Reduce Operational Expenses

Virtual footprints enable flexible and elastic operations. Cisco TrustSec enables firewall and access control rules to be set by an asset or application’s role, and systematizes management of these rules, saving substantial operational efforts and time.

Allows Secure, “Any Device” Access to Resources

To assist companies, get visibility into, and effective control over, unmanaged mobile devices gaining access to their networks, Cisco TrustSec gives flexible and high-performance controls in network devices to regulate access to resources founded upon features like user role, location, device type, and posture.

Dynamic Campus Segmentation

Unlike old-style campus network subdivision methods, Cisco TrustSec is a scalable, nimble, and effective method to enforce security policy in today’s increasingly dynamic environments.

Caters for Changing Workforces and Business Relationships

Users are even more mobile and businesses are ever more cooperative. Enabling controlled access to resources for mobile users, contractors, partners, and guests has now become operationally exhaustive and technically perplexing for many companies.

To learn more visit www.cisco.com/go/ise

For more details contact our Cisco Licensing Specialists here.

Using Cisco TrustSec for Campus Network Segmentation

If some communication between user segments is required or shared services are transported to numerous user groups, meticulous interactions tend to be defined in static switch and router configurations, which can become complex. Furthermore, regulating communication within a VLAN or segment is hard to put in force.

Cisco TrustSec Solution

Utilizing a Cisco TrustSec role or SGT as the means to outline permissions on the network permits the cooperation of differentiated systems to be concluded by comparing SGT values. This avoids the necessity for additional VLAN provisioning, keeping the access network design simple and avoiding VLAN proliferation and alignment tasks required as the number of roles grows. Communication amongst user groups may be rejected, or controlled interaction on accurate ports and protocols can be allowed. This allows a much simpler and more flexible way to handling security policies.

Cisco TrustSec SG-ACLs can also stop unwelcome traffic among users of the same role, so that malicious scouting behavior and even remote misuse from malware can be efficiently prevented.

Access Controls

Typical Situation

IP-address-based ACLs are easy to install, given an understanding of the network design structure and the precise assets that require protection. They need ongoing management, but for simple role structures this is not difficult. However, as the number of access roles goes up, it can become problematic to not only manage these ACLs, but also make sure that downloaded ACLs will not surpass the memory and processing abilities of any given network access device applying them.

Cisco TrustSec Solution

Cisco TrustSec uses protected group ACLs (SG-ACL) for role-based access control. These lists comprise of source and destination roles and Layer 4 services (ports). You don’t have to maintain IP addresses in these ACLs, so they are easy to maintain, even as the environment expands.

SG-ACLs are automatically downloaded from Cisco ISE as needed by the network device, so modifications to SG-ACLs do not have to be provisioned on the network. On many Cisco platforms, the SG-ACL enforcement functions are operating at line rate, permitting ACLs to be implemented at 10G, 40G, and even 100G.

Secure BYOD or “Any Device” Access

Cisco TrustSec can utilize the wide-ranging ISE profiling, posture validation, and mobile device management integration functions as a part of the classification process. Cisco TrustSec can give wide-ranging controls applied across the network, or precisely in firewall functions if needed, that take account of the back ground classification from ISE.

Summary of Benefits

• Streamlined policy using business circumstance

–          Based on expressive business language, not networking detail

–          Based on groups that are not modified when resources are moved

–          Returns policy administration to the security team

• Improved security and reduced intricacy

–          Simplified design reduces traffic engineering and improves data center Performance

–          Highly scalable line-rate marking and policy implementation on compatible devices

–          Decreased network intricacy as compared to other segmentation methods, like VLANs.

To learn more visit www.cisco.com/go/ise

For more details contact our Cisco Licensing Specialists here.

Cisco ISE with Integrated Security, Event Management and Threat Defense

Cisco ISE employs Cisco Platform Exchange Grid (pxGrid) technology to share circumstantial information with leading SIEM and TD partner solutions. The amalgamation of these incorporated technologies provides security analysts the capability to quickly and easily evaluate the importance of security events by associating expanded context with the security alerts. Cisco ISE enables the SIEM and TD system management consoles to display contextual information pulled from the engine about each security event.

The data can include the characteristics and level of access for each user and the kind of device which has been used. This data allows the analyst to more quickly find out where this event is originating from, whether it requires more investigation, and, if so, how critical is the threat. Cisco ISE can then be employed to undertake extenuation actions. Cisco ISE integrations with SIEM and TD platforms also enable improved security monitoring, like mobility-aware security analytics. The improved capabilities from Cisco ISE with SIEM and TD integration restructure the process of threat identification, make easy the execution of responses by IT teams, and vastly minimize the time needed for remediation of any network security threats.

How Cisco ISE Assimilations with SIEM and TD Solutions Works

The Identity Services Engine gives its user identity and device contingent data to SIEM and TD partner platforms. Then:

• Make new security investigation classes for high-risk user populations or devices, like policies adapted to mobile devices or users with access to exceedingly sensitive data.

• Appended to associated events in the SIEM and TD partner solutions to provide the extra circumstance of the user, device, and access level. The data assists analysts improved decode the importance of a security incident.

• Take extenuation steps within the Cisco network infrastructure. ISE can assume a quarantine action on users and devices.

• Log and report within the SIEM and TD products, giving cohesive, network-encompassing security reporting.

A few of the main features of the Identity Services Engine obtainable for use SEIM and TD for user- and device-related context are:

  • User: User name, IP address, authentication status, location
  • User class: Authorization group, guest, quarantined
  • Device: Manufacturer, model, OS, OS version, MAC address, IP address, network connection method (wired or wireless), location
  • Posture: Posture compliance status, antivirus installed, antivirus version, OS patch level, mobile device posture compliance status through mobile device management (MDM) ecosystem partners.

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.