Security Monitoring
Determining Your Events per Second
Although the numbers presented in Table 3-3 might not be realistic in your network, they do give you an idea of which types of devices tend to send the most events. The noisiest devices on your network are likely in this order 3 Intrusion detection systems intrusion prevention systems (IDS IPS) 4 Virtual Private Network (VPN) devices 7 Other devices, such as databases, operating systems, antivirus software, desktop and server protection software (such as Cisco Security Agent), and so on This...
False Positives
CS-MARS considers a false positive an attack that was unsuccessful against the target, either because the host was not vulnerable to the attack or because other products prevented the attack from succeeding. This is somewhat of a misnomer, because the real definition of a false positive is when a product incorrectly identifies an attack, when in reality it was not an attack. For example, if legitimate communication between a network printer and a host is incorrectly detected by your...
Ingress Firewall Rules
To simplify the work involved, you should define some network object groups on your firewall. If you're not familiar with this term, think of object groups as variables that you can use while configuring the firewall to make life easier. Rather than referring to a large list of IP addresses or TCP UDP ports, you can simply refer to a name instead. The following examples use an object group called CORP_NET, which consists of all IP addresses used on your organization's network. Ingress traffic...
Understanding NAC Framework Communications
Although this chapter isn't meant to be a tutorial on NAC, it is helpful to have a basic understanding of how NAC Framework functions. Be aware that the descriptions provided are applicable to NAC Framework only. NAC Appliance functions similarly, but also contains significant differences in how the various components communicate, as described in the sections that follow. You must install an agent, known as the Cisco Trust Agent (CTA), on each computer that is going to be posture-checked. This...
Security Device Event Exchange SDEE
SDEE is a somewhat open standard used by many IPS IDS vendors, including Cisco, ISS, Sourcefire, and TruSecure. Somewhat open means that you can use it, but it is ultimately owned by the International Computer Security Association (ICSA). SDEE uses Extensible Markup Language (XML) to organize the format of IDS alerts (or events) and specifies the protocol as HTTP. SDEE was designed to be both flexible and extensible. SDEE, when used on Cisco IDS IPS sensors, is backward compatible with Remote...
Degraded RAID Array
MARS-100E and larger appliances feature Redundant Array of Independent Disks (RAID) to provide protection against data loss. RAID allows MARS to lose a hard drive without losing data, or even requiring a reboot. A degraded RAID array can occur when the data on a hard disk is damaged. This usually occurs when an appliance is not cleanly shut down or rebooted, such as when power is lost. Power surges and drops (also known as brownouts) can also cause damage to your hard disks. You can help...
Batch Reports and the Report Wizard
The following sections show you how to create a report that is automatically generated at regular intervals, such as daily, weekly, or hourly. Additionally, you can predefine reports to be available on demand. A new proxy server has been placed on the network. Your organization's policy specifies that all web and FTP traffic must use this proxy. Your manager needs a report that identifies potential violators of this policy. Your internal network uses IP addresses in the range of 10.0.0.1...
Egress Firewall Rules
Egress firewall rules refer to filters that restrict traffic from the protected network to less trusted networks. Ideal security would restrict outbound traffic to only those ports that are necessary for proper functioning of the MARS appliance. However, in real life, this might be unmanageable. You need to determine the proper balance between security and manageability. For example, a strict default egress policy might make sense for your company's public-facing web server. Hopefully,...
Configuring Csmars to Integrate with CSManager
CS-Manager is added to CS-MARS in much the same way as any other security or network device is added. You treat CS-Manager as security software running on a host. This means, from within CS-MARS, you first add the server that it is running on, and then you add CS-Manager as software running on that server. From any screen in MARS, click the ADMIN tab, and then click on Security and Monitor Devices. Click the Add button, and select Add SW security apps on new host or Add SW security apps on...
Inherent Security of MARS Appliances
Management access to all MARS appliances is through Secure Socket Layer (SSL)-encrypted web access (HTTPS) and Secure Shell (SSH). These protocols, using TCP 443 and TCP 22, respectively, are inherently secure because they use encryption, authentication, and authorization. Unencrypted protocols that serve similar functions, such as HTTP and Telnet, are both disabled on the MARS appliance and cannot be enabled. MARS appliances are hardened Linux servers that run a variety of services, including...
Unknown Reporting Device IP
When your event logs contain entries from unknown reporting devices, this usually means that a device is configured to send logs to MARS, but MARS isn't configured to receive them. You might have also simply forgotten to click the Activate button at the upper-right corner of the MARS screen. If you're sure that you've correctly configured MARS to receive logs from a device, but they are still showing up from an unknown reporting device, try activating your changes. Figure 9-3 shows an example...
Network Based IDS and IPS Issues
A network-based IPS offers an additional level of protection to complement that provided by a stateful inspection firewall. An IPS is closely related to an IDS. At first glance, the most obvious difference between the two is how they are deployed. An IDS examines copies of network traffic, looking for malicious traffic patterns. It then identifies them and can sometimes be configured to take an automated response action, such as resetting TCP connections or configuring another network device to...
Requirement 1 Install and Maintain a Firewall Configuration to Protect Data
You must establish firewall configuration standards that include such things as A formal change control process for approving and testing all external network connections and changes to the firewall configuration. A current network diagram showing all connections to cardholder data, including wireless networks. Requirements for a firewall to be deployed at each Internet connection and between any demilitarized zone (DMZ) and the intranet. Descriptions of groups, roles, and responsibilities for...
Command Line Query
The simplest way to access the archive data is with the zgrep command. This command is identical to the commonly used grep command, except it is used for searching within gzipped files. A simple query example is as follows Show me all raw events from my Cisco 3750 switch where an interface was unplugged or plugged. You can change directories to the date you're interested in, and then change to the ES directory and run the following command This command results in the following output 00 38 13...
Software Upgrades
A useful feature of the GC is the capability to deploy new software and rules updates automatically across multiple local controllers. When you click the ADMIN button, click the System Maintenance tab, and then click the Upgrade button, you see a page like Figure 12-16. On this page, if you're using the web interface for upgrading your software, you can optionally select LCs to be upgraded at the same time as the GC is upgraded. Figure 12-16 Simultaneously Upgrading Global and Local Controllers...
Introducing CSMARS
A Security Information Event Manager (SIEM, or commonly called a SIM) is a relatively simple tool. In its most basic sense, these devices collect Simple Network Management Protocol (SNMP) and syslog data from security devices and software, and insert it into a database. These devices then provide you with an easy user interface with which to access that information. By itself, this is nothing special, but what is done after the data is received is important. The Cisco Security Monitoring,...







