Self Defending Networks

Understanding Types of DDoS Attacks

Table 2-1 describes several varieties of generic DDoS attacks. Source and destination IP addresses are the same, causing the TCP response to loop. Sends large numbers of TCP connection initiation requests to the target. The target system must consume resources to keep track of these partially opened connections. Internet Control Message Protocol (ICMP) Sends ICMP ping requests to a directed broadcast address. The forged source address of the request is the target of the attack. The recipients...

S m t S I to e s

B Q> Sensor Setup ' Network ' Allowed Hosts 0- < X SSH B-Q. Certificates S ime Susers B Qi Interface Configuration Flow Notification B- Q, Analysis Engine f virtual Sensor 'pGlobal Variables Q Signature Definition f custom Signature Wiza ' Miscellaneous B Q Event Action Rules 'pEvent Variables ' Target Value Rating Action Overrides Action Filters eneral Settings B Q> Blocking ' Blocking Properties evice Login Profiles ocking Devices outer Blocking Device Signature Configuration Select By...

Cisco Security Monitoring Analysis and Response System

Chapter 9discussed Cisco Security Manager in detail. Cisco Security Manager is the centralized configuration management product for a self-defending network. The Cisco Security Monitoring, Analysis, and Response System (Cisco Security MARS) product is the monitoring and mitigation platform for a self-defending network. Cisco Security Manager creates and deploys configurations to self-defending network devices including Cisco IOS routers, Catalyst 6500 7600 Firewall Services Modules, and...

TME Lab Guardl

J Start 11 j I i i Cisco Guard Web chapQ2orig.doc - Mic. Acrobat Reader - cc. , ijlSiaglt Capture Previ . 'jSb 0 File Rules Search Options Tools Wizards Help Device Information General j License Host Name ASA40-88.default.domain.invalid ASA Version 7.0(0)104 Device Uptime 1d 19h 34rn 57s ASDM Version 5.0(0)60 Device Type ASA5540 Firewall Mode Routed Context Mode Single Total Flash 128 MB Total Memory 1024 MB 172.23.62.88 24 10.1 0.20.88 24 2.3.4.5 24 192.1.2.3 24 'outside' Interface Traffic...

Cisco Adaptive Security Appliance Overview

The Cisco Adaptive Security Appliance (ASA) line combines the functions of a firewall, Virtual Private Network (VPN), and intrusion prevention system (IPS) in a single appliance. This product line is adaptive, which means that it provides several mechanisms that enable the network to be self-defending. The ASA product line is also built to be extensible to add new self-defending capabilities like antivirus, antispam, antiphishing, and antispyware protection, which are supported in the Content...

Configuring Firewall Access Control List ACLs Rules from Topology

The Device View section of this chapter detailed how to add an access control list (ACLs) to a device from the device view. You can also configure access control list (ACLs) rules on a firewall device from a topology map in the map view. The topology map view is a good fit for smaller networks or for security or network operators who prefer to view their network graphically with a topology map. In addition to smaller networks, topology maps can also be a good fit for the commercial or...

Trademark Acknowledgments

All terms mentioned in this book that are known to be trademarks or service marks have been appropriately capitalized. Cisco Press or Cisco Systems, Inc., cannot attest to the accuracy of this information. Use of a term in this book should not be regarded as affecting the validity of any trademark or service mark. Paul Boger Anthony Wolfenden Jeff Brady Brett Bartow Patrick Kanouse Dayna Isley Mandie Frank Paul Wilson Darrin Miller, Chris Tobkin Vanessa Evans Louisa Adair Mark Shirar Ken...

OOB Real IP Gateway OOB Virtual IP Gateway and Oob Nat Gateway

Cisco introduced support for out-of-band (OOB) deployments with the CCA 3.5 release. Prior to OOB support, the server was always inline with all user traffic from the client. This user traffic includes the initial authentication traffic and all of the actual data traffic from the client. OOB support allows the server to participate only in the authentication, scanning, and remediation flows for the user client and not the data traffic from the client for web browsing, e-mail, and so on. OOB...

Apply Access Control List ACL Rules to Multiple Devices

Cisco Security Manager offers several mechanisms to apply a list of access rules to a group of devices. Once you are satisfied with the access control lists (ACLs) that are configured for one device, you can share and copy the access control lists (ACLs) to multiple devices from the Device View. The ability to share policy between multiple devices types is a powerful feature because you can apply this firewall access-rule table policy to a wide variety of devices, including a Cisco IOS router...

Figure 77 User Agreement

Cisco Self Defending Networks

RFiv c'iiiH, 'ALL' EHiHV)t prlv*1'1 cl nt oppvn* ' if w v* je *ah*d- The Us-er AgraEP-FSPt pa * cont-cins usor sarce-Ticnfcte-vt sflcurty nrwrrsftioi, or any irformafcicn you wiriit usefs t& ackrwwiBdge co be srtSfiec iaf nstweffe isps-s. Uw the r ro maton Pag nliijuraii bnlc-w tq indien infnrm tinn m ttis Usnr aarn .-iarr psga -spg HksJ y 1er uEflrs wrt tri - snlccteil rc4e and DDcr-zi'jrg system in tojr rotwar* . rn I m m st un Psq i i-tess uqv fur URL) i h -rat- EinirKiitA tfeJd rr-.i ir bit...

HTTP Inspection Engine

HTTP or web traffic is one of the most popular types of traffic on networks today. ASA includes the ability to inspect HTTP traffic flows to detect possible network attacks. You can initiate the process to configure the inspection of an HTTP traffic flow under the Service Policy Rules section. This process to initiate the creation of a traffic flow for HTTP inspection is similar to the process to define a traffic flow with Service Policy Rules for IPS inspection as described in the Intrusion...

Implementing Outbreak Management with Cisco ICS

Cisco Self Defending Networks

Cisco ICS is a centralized management product from Cisco that manages the automated IPS signature update service with Trend Micro for new security incidents. Cisco ICS can deploy a broad access control lists (ACLs) to stop the spread of a newly identified infection through the network. These ACLs are known as OPACLs. After analysis of the new network incident by Trend Micro, Cisco ICS can also deploy a specific signature to mitigate a new network infection outbreak such as a worm.

Figure 331 URL Blocking in Trend Micro Inter Scan

Cisco Self Defending Networks

Phishing is a type of malware with which an e-mail is sent to an unsuspecting user with a link to a fake website. These phishing e-mails can attempt to trick the user to log on to what appears to be a valid banking or e-commerce site. However, what the user is really logging on to is a fake website, and the attacker's purpose is the gathering of the user's account information. Trend Micro collects and maintains a list of these phishing or fake websites. The CSC-SSM module can block the HTTP...

Ciscocertified Mail

CSC-SSM can provide protection for the POP3 and SMTP mail protocols. The CSC-SSM module supports the following mail security functions for incoming and outgoing POP3 and SMTP network traffic Scanning Spam protection Content filtering Scanning allows incoming and outgoing e-mail to be scanned for viruses, spyware, and other malware. Infected attachments can be either cleaned or deleted before they are delivered to the user. Figure 3-33 displays an example of configuring virus and other malware...

Self Defending Networks

How The Internet Works Today Wan

ASA (Active) CSC Module for Anti-Virus Catalyst with Firewall Module and NAC Wireless Access Point (Ajuthenticator) ASA (Active) CSC Module for Anti-Virus Calalyst with Firewall Module and NAC Cisco Detector Web Management - Microsoft Internet Explorer provided by Cisco Systems, Inc. Qfcck - - 0 g LP Search - Favorite, ' , 08 50 09 00 09 10 09 20 09 30 09 40 09 50 10 00 10 10 10 20 10 30

CCA Servers

Phone Boot Sequence Cisco Deatl

The CCA Servers option displays a list of managed servers and also allows the ability to define a new server to be managed. The process to add a new server and select the server mode is displayed in Figure 7-2. Figure 7-2. Add New CCA Server with Server Type Figure 7-2. Add New CCA Server with Server Type The Cisco Clean Access Server can be configured in the following modes Virtual IP Gateway (in-band) NAT Gateway (in-band)demo only Out-of-band (OOB) Real IP Gateway OOB IP NAT Gatewaydemo only...

Figure 922 Policy Inheritance

Cisco Self Defending Networks

A security policy created from the Policy View can be either mandatory or default. Mandatory security policies take precedence over default security policies. Mandatory security policies can also be applied to specific administrative privileges. The ability to have mandatory security policies allows for multiple security operations and the network operations group to view and configure the same set of devices. For example, a senior security operator may define the security policy to deny IPSec...

Figure 413 Automated Outbreak Management Alert Level

Outbreak H-an ag e-fnairt cvki Lafl Upd-atcs CFob-al Se-tting i ni I ji -siV Mnn.igiimcmt Summary Lifrift 'j '-J i'.i'J li'ViOCifc- lii-S& iii km -m inj urlirr.il -l-tofi-buv-n iVl Ta T k Munt Hi- t To Wii> i List IrniiKed Date Ti s OFt-arr- Jfr'njK M in iBtmtnl' Tt ia PutaiiHilk. Uulbnr-ih H n*p rTHPit I * ki Ent T-a Zltfi 1C-S HD d*pk-v nutbruk iifc-ii- - irri-- twk r i-jl-irr v far .'i-d jnd v-bII i'I Jf1. Vfrt*'. H-Tiiyf'itTl F i Ir.rt4t.il fl.j K fllFPT 'J'ATI-I liaKl C Luji nmb*<...