Battling APTs with Cisco NetFlow and Stealthwatch – Part 2

For most cutting edge threats, the attacker will perform a mixture of some or all of these activities: 1) network scouting, 2) spear phishing, 3) taking advantage of 0-day susceptibilities, 4) use mystification to dodge COTS protection products, 5) clandestine command-and-control communications, 6) inside pivoting that dodges identification by inside IPS systems, and 7) data extraction. Most of these steps are not found easily via perimeter/signature based solutions, but can be exposed using internal network screening.

It is imperative to identify the role of human event responders in fighting innovative protection attacks. No protection solution is going to spontaneously find and block APTs while your IT staff is asleep at home. The best solutions utilize the powers of both computerized and human scrutiny – assisting expert event responders screen their systems/networks and understand the mass of data present to identify the elusive signs that cutting edge threats leave behind. Next-generation network visibility and protection analytics solutions can assist here by turning the network into an always-on sensor grid for finding distrustful activities, and spontaneously interpreting huge amounts of information into actionable intelligence.

The Cisco Stealthwatch Solution

Cisco’s Stealthwatch System acts as a critical layer of defense against APTs by giving in-depth, inside network visibility and cutting edge protection analysis for finding furtive threats. By gathering and examining huge quantities of telemetry data from current network devices, Stealthwatch gives IT and protection Admins a full, cost-efficient picture of all that is occurring on the network, making it simpler to examine and alleviate irregular activities that can indicate an APT attack.

Not like other solutions which only screen traffic coming in and out of the network, Stealthwatch can also screen lateral traffic to find attackers doing bad inside the corporate network. This ability is crucial for finding APTs as they are usually able to infiltrate perimeter protection defenses easily.

Stealthwatch empowers enterprises to find the numerous steps that APTs follow to penetrate a network, like network investigation, interior malware proliferation, communication with command-and-control servers and information extraction. Cutting-edge features like application, device and identity cognizance, alongwith Threat Feed information, further enhance protection circumstance and situational cognizance.

The over dependence on A/V and IDS solutions has debilitated the shared protection position, as these solutions can’t stand up to face the unconventional attacks we now see. New solutions fixated on network/traffic intelligence are the best method of fighting innovative attacks, and much wider embracing is needed.

Beyond enhancing real-time attack identification, the Stealthwatch System radically quickens event response times, usually minimizing troubleshooting from days and months at a time to just a few minutes. The capability to save network information for years, along with cutting edge protection analysis, also makes Stealthwatch perfect for performing more accurate post-event scientific inquiries to better comprehend and avert future attacks.

Regrettably, there are no solutions today that will keep hackers totally out of corporate networks. However, there are solutions like Stealthwatch System that can rapidly find, frustrate and alleviate network attacks before they transform into overwhelming data breaches which make headlines.

To speak with one of our Cisco Licensing Specialists, please click here.

Identifying Malware and Botnets via Cisco Stealthwatch

How Malware Works

Malware is an umbrella term employed to talk about a diversity of forms of aggressive or invasive software comprising computer viruses, worms, Trojan horses, ransomware, spyware, adware and other such malevolent programs. Malware is intended to be surreptitious in disposition, and is commonly used to steal personal data or spy on computer users for lengthy periods of time without their knowledge. Other uses include incapacitating victim computers/networks, or encrypting files to obtain payments under duress/blackmail.

How Botnets Work

Botnet operators employ networks of command-and-control (C&C) servers situated all over the world to control malevolent software that they have installed on victim’s devices. Hackers have deployed malware onto millions of computers all over the globe so that they possess an army of devices standing by to follow their commands. A single device infested with this kind of payload is known as a “bot.” Together, all devices under the control of their attacker are known as a “botnet” or in some cases a “zombie network.”

The extraordinary surreptitiousness of these attacks and their extensively distributed nature make them exceptionally perilous. Each and every botnet-infested system can leak personal data or attack other companies at any time. Botnets can be employed for an assortment of reasons alternating from forwarding spam to DDoS and network infiltration.

By employing clandestine command-and-control methods, criminals are able to use infested internal systems as a launch pad for performing reconnaissance activities, dispersing malware and stealing information to abuse and compromise complete enterprises. As companies have now started to permit personnel to bring their own personal laptops, tablets and smartphones onto the network (a policy known as “bring-your-own-device” or BYOD), it has supplied a new way for attackers to get bots under their control inside otherwise unapproachable networks.

Cisco’s Stealthwatch Solution

Via cutting edge behavior scrutiny, Lancope’s Stealthwatch System can quickly find and alleviate the spread of malware across inside hosts. Using the Stealthwatch Worm Tracker, Admins can easily see where a worm has been on the network and where it is likely to go next. The Worm Tracker visually graphs the spreading of a worm/virus over the network from node to node, giving immediate visibility into the scope and impact of the outbreak. In this way, malware proliferation can be stopped inside a few hours instead of weeks.

Lancope’s Stealthwatch System can also find the command-and-control communications amongst botnet attackers and affected hosts inside the network. In addition, Lancope’s Stealthwatch Labs Intelligence Center (SLIC) Threat Feed gives cutting edge botnet identification, incessantly screening client networks for millions of known C&C servers and the addition of new botnets to its locating system as they are recognized in the wild. From there, Stealthwatch produces warnings to flag these communications for Admins so they can be quickly alleviated.

Lancope’s Stealthwatch Labs performs continuing, in-depth examination into the newest attack kinds to unceasingly reinforce network security. Via Stealthwatch Labs security updates, Lancope gives behavioral security algorithms for the leading threats prowling online to clients outside of their normal product upgrade cycles. These security updates supply yet another layer of reassurance for protecting networks from the newest malware and threat vectors.

Outside enhancing threat detection in real time, the Stealthwatch System radically hastens incident response times, reducing troubleshooting down from days and months to a few minutes. The capability to save network data for months or even years, with the addition of cutting edge security analytics, also make Stealthwatch the ideal choice for performing more accurate post-incident forensic inquiries to help avert future attacks.

To speak with one of our Licensing Specialists, please click here.

Halting Insider Threats via Cisco Stealthwatch

How do insider threats work?

While insider attacks can take on numerous diverse forms, the main constituent is that the threat is originated from inside your network set against outside where most of the protection technologies are focused. The insider threat is already on your network, so old-style barricades such as firewalls, antivirus and IDS/IPS will not be enabled to identify his/her activities. There are 3 main kinds of insider attacks:

  • Careless Insiders – Insiders who unintentionally expose information including a staff member who forgets their device on a plane.
  • Malevolent Insiders – Insiders who steal information on purpose or terminate systems in place including dissatisfied staff members who erase company records on their last day of work.
  • Compromised Insiders – Insiders whose login IDs and/or device have been compromised by an outside threat.

The Cisco Stealthwatch Solution

One of the main apprehensions regarding insider threats is that old-style network protection tools are seldom able to identify them. Usually attackers work behind firewalls and other border protections and are able to carry out their attacks without being identified. Complicating the state of affairs even further is the advent and proliferation of the Bring Your Own Device (BYOD) workplace, in which staff members often use individual devices like smartphones at work, enhancing the susceptibility of enterprise networks.

To identify insider attacks, enterprises have to use wide-ranging inside network visibility and protection analysis. Regrettably, old-style protection technologies including SIEM and complete packet capture can only give a small slice of visibility into the inside network, and usually become unpractical when scaled beyond restricted installations. By gathering and examining huge quantities of telemetry data, the Stealthwatch System allows enterprises to tie together existing infrastructure to get a full picture of network movements and find behaviors that could indicate an insider attack.

Extreme quantities of network traffic going from one user’s device to a printer could indicate an attempted stealing of intellectual property. Or, in case a user is often interacting with an unaccustomed IP address in a different country, it could point to the user’s device being compromised. An important differentiator of the Cisco Stealthwatch System is the capability to screen not only traffic going in and out of the corporate network, but also crosswise communications, which is of high importance for finding insider attacks functioning inside the network.

Cisco’s Stealthwatch System supplies the inside visibility and complete audit trail required to fill in hazardous network blind spots and find harmful insider threats. Nevertheless, once distrustful activity is found, you also have to be able to tie it to a definite user or device for operational extenuation. The Stealthwatch System supplies numerous layers of protection context to build a perfect picture of user activities and help system Admins in making educated judgements. These include:

  • User Characteristics – Tying up network activities to the user liable is important for finding insider attacks.
  • Device Cognizance – Device data assists you to find unapproved or unprotected devices, as well as quickly expose devices that may have been compromised.
  • Application Level Visibility – The capability to view which applications are in use can assist in pinpointing threats and malevolent programs.
  • Threat Feed Data – Assists in identifying devices or users who have been working in tandem with known malevolent hosts.

Stealthwatch’s context-aware protection analytics considerably enhance threat identification and event response for a range of threats comprising insider attacks, often minimizing troubleshooting down from days and months to just a few minutes. In addition, the Cisco Stealthwatch System can save months or even years of network traffic information to assist with more wide-ranging forensic inquiries into preceding security events – a critical constituent for serving to preempt future attacks.

To speak with one of our Licensing Specialists, please click here.

Battling APTs with Cisco NetFlow and Stealthwatch – Part 1

Resolute attackers will ultimately infiltrate their target’s corporate network, usually using social engineering stratagems to pinch IDs and get access. To fight APTs, it is critical that corporations get visibility into their inside networks to fill in gaps left by perimeter protection solutions.

How do APTs work?

Cutting-edge attackers often go to extreme lengths to aim at certain companies and employ specifically personalized amalgamations of threat vectors and unpatched susceptibilities to penetrate a specific setting. These attackers may have a long-term purpose of gathering information from a particular target network, which means that they must preserve access to the corporate network without being identified.

APT attackers will use muddying methods and even check their activities against frequently used protection products to stay under the radar. If one part of the threat attack bombs, they will carry on trying to break down the doors until they are able to gain entry. In addition, cutting-edge attackers can find methods to access more protected centralized offices using less-protected far-flung offices or even contractor or partner corporate networks, implying that nearly any enterprise or far flung site office may fall victim to an APT.

Due to the triumph of these tactics, monetarily driven cyber villains have also started to mimic some of the techniques used by APTs, further widening the swath of organizations that are susceptible to advanced attacks. Many of these operations involve well-funded organizations with large numbers of participants who have highly specialized skills. These factors contribute to their success, making them a very formidable threat.

APT Challenges

Unfortunately, there is a pervasive misunderstanding among a lot of security organizations that if they have an antivirus, a firewall, IDS/IPS, SIEM and a cutting-edge malware detection system, then they are well safeguarded from all threats which come their way. In a time of increasing insider attacks and APTs, this is just not true. In reality, we have malware functioning for years before any antivirus software can find it, and that malware usually will spread out by abusing zero-day protection susceptibilities for which there are no patches in existence, utilizing exploits that are not detectable.

Keeping in mind the tailored, persistent and well-supported nature of APTs, it is crucial that enterprises know what is happening inside their internal corporate networks to fill in the spaces left behind by orthodox protection mechanisms. A full audit trail of network activities can be utilized to completely evaluate the influence of a breach and search for continuing spying and information exfiltration happening in real time.

To speak with one of our Cisco Licensing Specialists, please click here.

Branch Protection via Cisco’s Stealthwatch Learning Network License – Part 2

The Learning Agent employs Cisco NetFlow and Deep Packet Inspection (DPI), and Network Based Application Recognition (NBAR); abilities which are at present in all Cisco branch routers, to gather, associate, and scrutinize security data to implement cutting-edge irregularity and zero-day attack identification. There is a well-defined Flexible NetFlow record in the router installation which forwards that information to the agent running in the router’s memory.

A crucial Learning Network feature is the solution’s capabilities to adapt; to find new irregularities and functioning with an operator to do fix them on the spot by recognizing the irregular features and generating and applying extenuations for circumstances as they arise. This level of automation is actually required due to how intricate and capacious traffic torrents and movements are becoming.

Old-style irregularity and incursion discovery and deterrence are resilient at catching threats which are already known and recognizable. They are not able to find new risks as they are heavily reliant on what they have been programmed to know and not what they learn as events are unfolding in real time.

One more benefit of the Learning Network as compared with old-style protection solutions is its level of accuracy. Traditionally, irregularity discovery systems have been rated based on the amount of possible security happenings they are able to find. Given that many of these incidents turn out to be non-risks based or unrelated, old-style systems need regular fine tuning or else they will produce large numbers of needless warnings and commotion.

The Cisco Stealthwatch Learning Network concentrates on keeping its findings accurate and only warning you and taking action on events which pose real threats confirmed by an operator, with simple Like/Dislike feedback features, enabling the Learning Network to find only pertinent irregularities.

It’s crucial to keep in mind that the learning manager functions independently from the Cisco Prime Network Management App. Therefore, it allows you to separate your protection processes from networking processes, which can be extremely beneficial, contingent on how your business is set up.

The Cisco Learning Network encompasses the abilities of Cisco’s market leading Stealthwatch Network Anomaly Detection (NBAD) and Visibility solution and both can be installed in the same Cisco ISR device.

The Cisco Learning Network can incorporate information from the Cisco Identity Services Engine (ISE) or access to Cisco Talos Threat intelligence feeds to give an operator even more data and more granular visibility.

The Cisco Stealthwatch Learning Network license transforms your ISR routers into security devices. The Learning network is not required to continually keep updating signatures or rules/lists. It learns what’s standard and what isn’t by acclimatizing itself with day to day traffic patterns. This provides you a much more dynamic, always up-to-date methodology to branch-office protection.

To learn more, please speak to our licensing specialists today.

Cisco Stealthwatch 6.9.0 Released

Updated User Interface, Competences and Enhancements

Stealthwatch 6.9.0 supplies a more enriched user experience inside the Stealthwatch Management Console by enabling the user to see large tables and graphical output more quickly and easily.

Some improvements include the following:

  • New Alarming Hosts pane view which displays the quantity of hosts which have raised an alarm today for each alarm category with one week trends analysis available
  • The Top Alarm Raising Hosts widget enables you to view at a glimpse a highlighted list of hosts in order of their risk severity
  • Top Reports gives quick access to top Apps, port protocols, etc.
  • Host Group reporting with interactive graphs of traffic reports and top Apps traffic

Enhanced Security Incidents and Alarm Documentation

Gives enhanced visibility, security, and response as it quickens the time to threat identification with improved reporting and alarm functionality that allows:

  • An enhanced capability to managed alarm policies by the addition policies control feature
  • An improved system security category model for ranking of identified security incidents
  • Improved security events and alarm documentation for better correlation between security events and traffic flows.
  • Common and Shared Services
  • Integrated management and configuration of the Cisco UDP Director inside the Stealthwatch Management Console

Improved Assimilation with the Cisco Identity Services Engine (ISE)

Improved incorporation with Cisco ISE to better leverage the Platform Exchange Grid (pXGrid) for both telemetry and resolution, leading to a more precise extension of visibility into user data and statistics. Also incorporated is support for the Identity Services Engine Passive Identity Concentrator, simplifying amplification of user information without necessitating Cisco ISE to directly validate users or manage access to the corporate network.

To learn more about how Stealthwatch can protect your network, click here.

To speak with one of our Licensing Specialists, please click here.

Cisco Stealthwatch Versus the WannaCry Epidemic

Apprehended in the wild and scrutinized by members of Cisco’s industry leading Talos threat intelligence team, the early strain of WannaCry comprises a malware payload which depolys ransomware on an infested host computer. It scans comprehensively over TCP port 445 and can employ a susceptibility existing in some unpatched Windows OS running devices. WannaCry has the capability to spread all over a network, comparable to a worm, causing pervasive infestations.

This blog post outlines how clients can utilize Cisco security solutions to protect their company networks and devices against this malware and its probable alternatives that are anticipated in the near future.

Infection Identification 

The preliminary strain of WannaCry malware depends on on the Server Message Block (SMB) protocol to contaminate and proliferate devices operating MS Windows on the corporate network. By utilizing Cisco Stealthwatch, network operators can screen SMB movements inside the corporate network.  

  • Cisco Stealthwatch has built in reports which can specially track and provide reports on SMB traffic amongst in-house host computers and Internet-based hosts, which is a warning of systems infested with WannaCry.
  • WannaCry malware also employs SMB traffic to proliferate inside. SMB traffic in use by hosts on the same subnet is identified as a distrustful activity by Stealthwatch.
  • Stealthwatch has quite a few warnings based on doubtful SMB activity. To be exact, high SMB traffic and SMB connections to many dissimilar hosts. This gives a simple suggestion of hosts affected with WannaCry.
  • Stealthwatch also has the ability to find and report on connects to the TOR network, Bogon IP addresses, and the known command and control hosts. 
  • Host communications with the TOR network and Bogon IP addresses are identified by Stealthwatch based on the constantly updated threat intelligence feeds. This enables security personnel to find any in-house IP which is connecting to doubtful hosts on the Internet.

Propagation Identification  

The preliminary strain of WannaCry malware will attempt to proliferate inside the network laterally (from host to host) in an effort to infest as many hosts as it can. This proliferation action has been seen sometimes even before the malware has triggered its ransomware payload. Stealthwatch is intended to identify all such lateral movements, particularly amongst systems existing on the same subnet.

  • Any scouting and scanning activities, even amongst systems existing on the same subnet, is trackable by Stealthwatch.
  • The Stealthwatch Worm Propagation identification report tracks and associates scanning activities with effective connections to outside command and control hosts, which is in line with activities from WannaCry and other worms. 

Association  

Cisco Stealthwatch will associate dissimilar activities seen on a particular host computer and mark that IP as being suspect based on numerical scores connected to each scrutiny. Stealthwatch then accrues those scores under one index for each respective host IP address and raises a warning called Concern Index. The higher this concern index numerical value is, the more likely the host is participating in malevolent activities.

Scoping and Extenuation

Using the Cisco Stealthwatch Management Center and dashboards, you can simply create a report to list all systems which show suspicious activities and likely contamination. With Cisco Identity Services Engine (ISE) assimilation, you can then isolate suspected devices, stopping the further spread of WannaCry until the time when the threat has been fixed.

Halt the WannaCry Tears

WannaCry is causing chaos across the Internet, and we are likely to see variations for many years to come. Using the universal visibility and cutting-edge analytics of Stealthwatch, you can identify WannaCry activities in a timely manner and react to halt them from spreading all over your network.

To learn more about protecting your network from WannaCry, click here.

To speak with one of our Licensing Specialists, please click here.

Branch Protection via Cisco’s Stealthwatch Learning Network License – Part 1

Cisco is tackling the complications associated with network security by the deployment a new self-learning, router-based solution known as the Cisco Stealthwatch Learning Network License. The Learning Network functions inside a Cisco router and is capable of discovering and learning about your network and adapting as the network and the associated evolving threats to the network are faced.

The Cisco Stealthwatch Learning Network License employs a diverse variety of machine learning algorithms on premise (the router) to model standard activities and find irregularities inside the network. This employment of machine learning signifies a disrupting method to some of the usual issues of network security and incongruity identification. Different from security contrivances of the past, this method needs no exceptional configuration or programming of rules, access control lists, and signature libraries; rather, the learning agent powered router continually learns about network activities and traffic patterns and employing cutting-edge analytics recognizes irregular traffic. New and cutting-edge techniques are employed to radically minimize the identification of benevolent irregularities via an easy to use user feedback (Like/Dislike) mechanism, resolving one of the primary issues with irregularity discovery.  The Stealthwatch Learning Network License is able to rapidly learn the environment it is installed in and pinpointing pertinent irregularities with unmatched accuracy.

This Learning Network is the only solution obtainable that associates and combines machine learning with network content examination and packet-capture installed in a router to systematize branch traffic visibility, defense, and remediation. The Learning Network is software which is retailed as a smart license to the Cisco Integrated Service Router (ISR) 4000 branch-office router. It augments an adaptive component to your protection efforts, which are no longer reliant on finding threats that are already known. Rather, the learning network is focused on the relevance of irregularities; and having the ability to quickly react to modern day threat environment and Zero-Day Attacks.

Learning Network mechanisms are a learning manager and one or more than one router deployed learning agents installed at the brink of the network. A Learning Agent is virtual machine installed into a Linux Container running in memory on a Cisco ISR 4000 series router. These agents examine traffic, build models, and report irregularities in real time to the consolidated Learning Manager. You may install at the most one agent per router, and up to a maximum of 1000 agents which are able to communicate with a single manager inside your network. At the time of launch, the Cisco ISR 4451 and ISR 4431 routers are supported, with further platforms to be supported in the near future.

To learn more, please speak to our licensing specialists today.

Acquire real visibility with Cisco Stealthwatch and ISE

Even if staff are aware that their system is compromised, they don’t constantly know where it’s occuring and how, making them vulnerable to network exploitation and insider threats. Companies require a solution that gives them widespread network visibility heightened by rich user and device data to speed up threat detection and response times.

Only the combination of Stealthwatch and Cisco’s Identity Services Engine assists organizations in getting a 360° view, react to threats quicker, and protect a growing digital business.

Get a 360° view with Cisco Stealthwatch and ISE

Get matchless visibility and control with incorporation of Cisco Stealthwatch and ISE.

•  Unceasingly screen, examine, separate, classify, and store host and user data from your network with Stealthwatch.

•  Facilitate system administrators to view data about each distinct device – type, operating system, compliance status, connection method, geographical location and more with ISE.

•  Find irregular traffic in your environment. Implementing context-cognizant security scrutiny to automatically find irregular activities, Stealthwatch can find a wide range of attacks, like malware, zero-day attacks, distributed denial-of-service (DDoS) attempts, advanced persistent threats (APTs), and insider attacks.

•  Identify exactly when specific user activities become suspicious. Stealthwatch allows admins to set their own activities thresholds, once a user crosses the brink it activates an alert.

Respond with Rapid Threat Containment

•  Once Stealthwatch finds irregular traffic, it activates an alert, providing the admin an option to quarantine the user. pxGrid activates Stealthwatch to hand off the quarantine command straight to ISE.

•  Admins can make a judgement based on scrutiny, rescinding users access and isolating them through ISE with a single click. Admins don’t have to change or modify the whole system policies in place as ISE reallocates the access policy of the quarantined user.

•  Identify the root source of a breach with post-incident audit trails. Stealthwatch saves records of all network goings-on for months and years.

Protect your expanding digital business

To move ahead with novel initiatives or technologies assuredly, companies must know that they can scale without needing to create new security problems.

•  Stop worrying about security as a hindrance and supply a foundation for network subdivision for protected access & visibility.

•  Empower admins to prudently control access to delicate assets, know exactly when somebody attempts to access data, and spread out that visibility to any new area of the network, environment or the cloud.

•  Augment users, devices and business without the compromising of network visibility. Decrease the administrative load of setting up new devices with continually updating device profile feeds from Cisco ISE.

•  Scale the environment without the creation of blind spots. A deployment of Stealthwatch is able to process information from 50,000 flow sources at 6 million flows per second (fps) all while stitching and de-duplicating flows.

•  Minimize the managerial burden linked with silo’d management sources. Network-wide flow is centrally exhibited in the Stealthwatch Management Console. Simply assimilate third party technologies and services via a REST API.

To learn more visit www.cisco.com/go/Stealthwatch , www.cisco.com/go/ise

For more details contact our Cisco Licensing Specialists here.