Cisco Security Monitoring Analysis and Response System
Chapter 9discussed Cisco Security Manager in detail. Cisco Security Manager is the centralized configuration management product for a self-defending network. The Cisco Security Monitoring, Analysis, and Response System (Cisco Security MARS) product is the monitoring and mitigation platform for a self-defending network. Cisco Security Manager creates and deploys configurations to self-defending network devices including Cisco IOS routers, Catalyst 6500/7600 Firewall Services Modules, and Adaptive Security Appliances. Cisco Security MARS complements the Cisco Security Manager by providing best-of-breed monitoring of the self-defending network.
This chapter provides an overview of Cisco Security MARS. You learn about Cisco Security MARS features, the dashboard, how Cisco Security MARS displays a security incident, and how Cisco Security MARS can mitigate an attack or allow a network to be self-defending. This chapter also provides details on Cisco Security MARS integration with Cisco Security Manager, including how to select a syslog from an incident in Cisco Security MARS and receive a display of the access control list (ACL) rule in Cisco Security Manager that created the syslog.
4 PREY
Understanding Cisco Security MARS Features
Cisco Security MARS is different from the conventional Security Information Management Solution (SIMS) or other traditional security monitoring products. Cisco Security MARS offers several advantages based upon the following features:
• Import Netflow data
• Create baseline of normal network traffic
• Import configurations of monitored devices
• Understand traffic flow across Network Address Translation (NAT) boundaries
• Integrated Nessus Vulnerability Scanner input
• Display topology map of network and attack vectors
• Reduce false positives by reporting incidents
• Provide mitigation by deploying configuration to shut specific ports to stop an attack
• Provide mitigation by displaying an access list to stop an attack close the source of the attack
Cisco Security MARS is offered as a turnkey appliance. Cisco Security MARS includes an integrated Oracle database and can handle up to 10,000 events per second. The Cisco Security MARS product line also features different appliance form-factors including a lowend model that supports 500 events per second, excluding Netflow data. A turnkey appliance allows the Cisco Security MARS product to be up-and-running quickly without an extensive installation or tuning process. Cisco Security MARS displays a security incident during an attack, based upon input and events from devices within the selfdefending network. A partial list of the sources from which Cisco Security MARS can accept input and events includes the following:
® Cisco IOS routers
• Cisco Catalyst LAN Switches (Catalyst OS 6.x)
• Cisco PIX Firewalls ® Checkpoint Firewalls
® Cisco VPN Concentrators
• Netscreen Firewalls ® Cisco IPS Sensors
® Enterasys Dragon IPS Sensors
• Snort IPS Sensors
• ISS IPS Sensors
® Cisco Security Agent
® Symantec Anti-Virus
® Windows Host Log ® Solaris Host Log ® Linux Host Log
• IIS Web Server Log
® Apache Web Server Log ® Oracle Audit Logs ® NetApp Logs
Cisco Security MARS has the ability to see the entire self-defending network based upon input and events from the preceding sources. This diverse selection of input, combined with the network configurations and baseline traffic, allows Cisco Security MARS to report on specific, high-level, actionable security incidents rather than displaying and reporting based upon individual and voluminous firewall syslog and IPS Sensor events. Cisco Security MARS also supports a global controller functionality. The global controller provides a centralized management station for multiple Cisco Security MARS local controllers.
4 PREY
Summary Dashboard
Cisco Security MARS uses a web browser for the client GUI. Cisco Security MARS also facilitates the download of Adobe SVG to display the topology graphs. Cisco Security MARS requires Internet Explorer for the web browser and uses HTTPS to ensure secure monitoring. After a successful logon to Cisco Security MARS, you are presented with the dashboard under the Summary tab. Figure 10-1 displays an example of the top of the Cisco Security MARS dashboard.
Figure 10-1. Cisco Security MARS Dashboard
[View full size imagel
Figure 10-1. Cisco Security MARS Dashboard
The dashboard includes a summary of security incidents, or a high-level indication of a possible network attack or vulnerability based upon input from devices and hosts in the self-defending network. In addition to incidents, the dashboard also includes information on events within the last 24 hours, false positives that are detected, a hotspot, and an attack diagram including source and destination of the attack.
Incidents
The focal point of the Cisco Security MARS dashboard is a list of recent incidents. In addition to the dashboard, incident information is also available by selecting the Incident tab at the top of the Cisco Security MARS GUI. All incidents are supplied with an incident ID, event type, matched rule, time, and path information. Figure 10-2 provides an example of an incident ID selected from the dashboard (highlighted). In addition to selecting an incident from the Summary Dashboard, incidents can also be selected from the Incident tab at the top of the Cisco Security MARS GUI. Figure 10-3 displays the resulting information from the incident selection irFigure 10-2. Figure 10-3 also provides an example of how an incident is displayed with the matching rule that triggered the incident and the subcomponents of the incident. Subcomponents of the incident include the following fields:
• Destination IP/Port
• Protocol
• Reporting Device
• Reported User
• Path/Mitigate
• False Positive
Figure 10-2. Select Incident from Dashboard
[View full size imagel
7c i liera itr.rE-r
DjtU
7c i liera itr.rE-r
DjtU
|
tour Incident»- |
||
|
WÊ ^ |
Al |
17* |
|
Ëfl Mti^n |
4 |
|
|
■ u^ |
*7 |
|
|
Toi*! |
L3'3 |
30C% |
|
!•«■■ M!« fijiHIMif |
||
C 3-35L&2 HfrMkirii He-
C:34H4BL QIh4 HÉrh«n £f eca43î?OT in-Swe fifmi rr.rrJV
I EHm779utf Qwil m !c-
: .■.:,-!-i^-h1 lltD'ïTppT cxE'Zimti], ll*rd* PukRl lit Ov fri! C'+fthOQ.
WWIV :i 5 Urncc-i» D --c■:»:•:r i ir*vsn ari"
i 5*3>?i77iar lit cw l-11 cshci-.gj iiflny! fjé ■
WUTM I iMvjm lit Ctt OvjU*
I ::è2T73 rPl^jT ËûJVtoMMtotfnmfj Ss rtim f-.tf*. Cka--A Eapfcri ■ 3nur Wc-rm[a] |P .v.r^oior.E]
JUM PÇT malH>Îb| Jui II. [ ifùt L3 :M+7 AH HT
2 we
m pot
|
| LK« ■ï'K- |
K ||H-t| |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
■ |
Figure 10-3. Incident Details [View full size image!
Cisco Security MARS displays security incidents to the user that may require action as opposed to simply providing a real-time viewer of IDS and firewall events. In addition to providing high-level security incidents to the user, another powerful feature of Cisco Security MARS is the ability to recommend or apply a mitigation action to stop the incident or attack. Displaying Path of Incident and Mitigating the Attack Figure 10-3 displayed details of the security incident for a Nimda worm. Selecting the red icon in the Path/Mitigate field for this incident results in the display of the path of the network attack. Figure 10-4 provides the resulting display of the path of the security incident through the network. Figure 10-4. Path of Incident [View full size image!
In addition to displaying the path of the network attack, Cisco Security MARS can also generate the command-line interface (CLI) commands to mitigate or stop the network attack. The CLI commands used to mitigate an attack are displayed with the path by selecting the path/mitigate option in the incident. Cisco Security MARS has the ability to automatically shut a LAN port to mitigate the attack. Cisco Security MARS will generate the CLI for an access control list (ACL) rule to stop an attack, but will not deploy the CLI. The suggested CLI recommendation is typically based upon the device closest to the source of the attack. This choice may not be the optimal mitigation point based upon the user's point of view. Cisco Security MARS allows the selection of alternate devices within the path of the network attack in case the user does not wish to mitigate the attack at the device that is closest to the source of the network attack. Figure 10-5 displays the suggested CLI to configure an access list to stop the Nimda attack. Figure 10-5. Suggested CLI to Mitigate the Attack [View full size image!
'**' up dadebi-lii< mririn Ctll-kl-ruihlyiuiI/D d«Fi7 c.np hoit 10.i.A.J •lib' Cc^i' ;■■: I[■]rMt Cncc- I ■ ■■■■■■TI, in n^i; .■^('■■rc Hotspot Graph and Attack DiagramCisco Security MARS relies heavily on SNMP to gain topological awareness of the network. Cisco Security MARS requires SNMP read access to construct a Layer 3 and Layer 2 topological map of the network. Cisco Security MARS uses Simple Network Management Protocol (SNMP) to gather information about the device. Cisco Security MARS also uses SNMP and a seed device to discover the neighboring devices for each known device in the network. A seed device is a starting device to discover the network by attempting to discover every device known by the seed device and then attempting to discover every device known by each newly discovered device. SNMP allows Cisco Security MARS to create the hotspot graph and the attack diagrams. Use of SNMP by Cisco Security MARS is complemented by the integrated network scanner. The integrated network scanner is used to gain information about the hosts and applications that exist on the network. Cisco Security MARS combines the device discovery of SNMP with the scanning information about the hosts and applications to construct the hotspot graph. Cisco Security MARS uses the host scanning for OS and application fingerprinting. OS and application fingerprinting is used to assist in ensuring that an incident is relative to the target and valid. For example, a detected Windows exploit attack against a Linux server is not a valid incident. Both the hotspot graph and the attack diagram can be displayed on the main Cisco Security MARS dashboard. Figure 10-6 provides a sample of a hotspot topology graph. In our example, the hotspot diagram displays the network for the Nimda incident on the dashboard. Figure 10-6. Hotspot Graph HotSpnt Graph
The hotspot graph displays the path of the incident or attack across the network. An attack diagram allows the user to highlight a vulnerable path between two points in the network and receive a display of the session IDs of the events that are incorporated into the security incident. Figure 10-7 provides an example of an attack diagram for the Nimda incident. Both the hotspot graph and the attack diagram are launched from the icons next to the incident ID from the details on the incident. The hotspot graph and attack diagram on the dashboard typically correspond with the latest incident listed on the dashboard. Figure 10-7. Attack Diagram [View full size image! 4-iau 2,ri a MI* MkTTPfH poi SiHtriilt lb! llit'il MtU C+wdt in DOT co" mcinc otv nsjirtdw C. ifft Tippi: li: CCJ C-prcdi Jti Cl«OK{ l-bjh ww* wliitfr crTrJ.irc- [kl lli-CKJT MTEHLTuTi Cl JEO i-pjIiT. I™< r sua r bih 4 PREY Rules To display an incident, a matching rule was used to trigger that a possible security incident or attack was in progress. Cisco Security MARS includes a set of system rules that are automatically configured and applied to detect security incidents or attacks. Figure 10-8 displays a system rule to detect an active backdoor connection. An active backdoor connection typically signifies that a host has been attacked and that a connection is open for someone to remotely access and control this host, perhaps for use in a botnet. Figure 10-8. System Inspection Rule to Detect an Active Backdoor Connection [View full size imagel Figure 10-8. System Inspection Rule to Detect an Active Backdoor Connection
In addition to the active backdoor system rule, some of the automatic or system inspection rules include detection of client exploits, firewall configuration issues, password attacks, scans, viruses found, viruses cleaned, worm propagation, and sudden traffic increases to a port. In addition to the canned or predefined system inspection rules, Cisco Security MARS also features the ability to create customized or user inspection rules. User inspection rules can be ideal for homegrown or custom applications. These customized rules are created with the following parameters or fields: ® Keyword ® Operation Rule information for a specific incident is available by selecting the incident details from the dashboard. General rule information is also available by selecting the Rules tab from the top ofthe Cisco Security MARS GUI. Cisco Security MARS was one of the first security monitoring products on the market to incorporate Netflow data. Netflow is a feature of Cisco IOS routers and Catalyst LAN switches. Netflow is essentially a record of a traffic flow between a particular source and destination through the IOS router. Netflow contains a high-level record ofthe source IP address, destination IP address, the time ofthe connection, and the duration ofthe connection. Cisco IOS routers and Catalyst LAN switches running IOS periodically send a Netflow record to a Netflow collector such as Cisco Security MARS. This Netflow record is sent over User Datagram Protocol (UDP) and is highly efficient because it is merely a record of a traffic flow as opposed to a packet-by-packet dump ofthe traffic flow. Netflow contains the following information: ® Source IP address ® Destination IP address ® Ports/protocol ® Total packets ® Total bytes Netflow is used by Cisco Security MARS to create a baseline of normal network traffic. This baseline is used to identify anomalous network behavior that can be indicative of several types of network attacks, including distributed denial-of-service (DDoS) attacks and worms that are sending large amounts of network traffic. Cisco Security MARS also contains integrated system inspection rules for IPS (Intrusion Prevention Service) that leverage Netflow information to signify a security incident or network attack, thus reducing the false positives that are sometimes associated with IPS. Netflow information, including the number of Netflow events received in the last 24 hours, is available on the dashboard. 4 PREY Query/Reports Cisco Security MARS features a collection of predefined reports in addition to the ability to create a custom report. Reports are generated from the event data in Cisco Security MARS that is collected from the devices in the self-defending network, including routers, LAN switches, firewalls, IPS sensors, and hosts. Cisco Security MARS also features groups of reports. Figure 10-9 displays a sample of the report groups in Cisco Security MARS. Figure 10-9. Report Groups [View full size imagel Figure 10-9. Report Groups
There are several report groups in Cisco Security MARS for topics that you have previously learned about in this book. For example, there are report groups for attacks and DoS, firewall control, malware outbreak (Cisco ICS), and security posture compliance (Cisco NAC). In addition to the topics previously discussed in this book, Cisco Security MARS also features a report group for Distributed Threat Mitigation (DTM). DTM is designed to enable branch IOS routers, specifically Integrated Services Routers (ISRs), to dynamically configure themselves with the necessary IPS signatures to reduce the risk of an attack at the branch office in an automated, self-defending fashion. DTM is an emerging technology, and it is strongly recommended that DTM be tested in a small pilot network to verify scalability prior to any deployments in production networks. In addition to the DTM report group, Cisco Security MARS also includes the option to be a DTM controller. The DTM controller is essentially the brains behind the DTM battlefield. The DTM controller in Cisco Security MARS receives input in the form of IPS Security Device Event Exchange (SDEE) events and syslogs to help to determine what specific attack is occurring in the branch network. Cisco Security MARS can then automatically enable the identified and necessary IPS signature on the branch IOS ISR. Figure 10-10 provides an example of the reports that are available as part of the DTM report group. Figure 10-10. DTM Reports [View full size image! Figure 10-10. DTM Reports
Cisco IOS ISRs can implement many features, including voice, routing, and security in a single device at a very cost-effective price point. The combination of feature-richness and low price point enables ISR routers to be deployed in remote branch offices in environments where an organization may have thousands of remote branches. To keep the price point of the ISRs attractive, their memory footprint, or capacity, is often substantially less than that of a dedicated security appliance such as an ASA (Advanced Security Appliance). The reduced memory footprint of the ISR creates a situation in which the entire IPS signature set cannot be simultaneously enabled on the ISR. The branch environment is often remote, and there may be no security or IT professionals resident at the remote branch to manage these devices. The combination of the remoteness of the branch and the limited memory capacity of the ISR can be addressed in certain, small-scale situations by managing the IPS signatures on the ISR with a DTM in Cisco Security MARS. DTM is currently not scalable to ISRs contain a file called named attack-drop.sdf. This attack-drop.sdf file lists all the IPS signatures that are enabled on that ISR device. In addition to the attack-drop.sdf file, some ofthe larger ISR routers may also run the 128MB.sdf or 256MB.sdf signature files if they have enough memory. These attack-drop.sdf, 128MB.sdf, and 256MB.sdf files are frequently updated on Cisco.com to contain the latest, most relevant IPS signatures. DTM can automatically enable the desired IPS signature on the ISR by monitoring network events that originate from networks around the ISR and updating the attack.sdf file on the ISR with the desired IPS signature. The monitored network events that are used by Cisco Security MARS to apply dynamically apply IPS signatures to ISR to mitigate a threat can originate from an IPS appliance, ASA IPS (AIP-SSM), a Catalyst 6500/7600 IPS service module, or an ISR router. Cisco Security MARS cannot create the initial attack-drop.sdf file on the router. This attack-drop.sdf file must be initially created by CLI, Security Device Manager (SDM), or Cisco Security Manager. 4 PREY Management The Management tab in the Cisco Security MARS graphical user interface (GUI) enables the user to view events and create IP addresses, services (ports or protocols), and admin accounts in Cisco Security MARS through the following tabs: • Event Management displays the network events that are seen by Cisco Security MARS that can be used to trigger an incident. The event management tab is one of the more commonly used management tabs in Cisco Security MARS. An example of the event display in event management is provided in Figure 10-11. Figure 10-11. Event Management rView full size imaqel Figure 10-11. Event Management rView full size imaqel
• IP Management displays what IP addresses or networks are known by Cisco Security MARS. • Service Management displays what ports or protocols can be used in rules. • User Management tab enables the creation or modification of a user account in Cisco Security MARS. 4 PREV Admin The Admin tab ofthe Cisco Security MARS GUI enables the configuration of administrative functions like system setup, maintenance, user management, system parameters, and custom setup. System setup is a critical step because system setup controls how devices are discovered or imported into Cisco Security MARS. Figure 10-12 provides a display ofthe system setup options. Figure 10-12. System Setup [View full size imagel Figure 10-12. System Setup
4 PREY Cisco Security Manager Linkages Cisco Security MARS supports integration or "linkages" with Cisco Security Manager. The ability to directly integrate between Cisco Security MARS and Cisco Security Manager enables security operators to cross-launch between the monitoring and configuration components. The ability to correlate or cross-launch between monitoring and configuration components can be especially useful in debugging or trouble-ticket situations. Cisco Security MARS contains a feature that directly links an incident with a security policy in Cisco Security Manager. Specifically, Cisco Security MARS enables the user to select a syslog from a security incident and display the access control list (ACL) rule in Cisco Security Manager that generated the syslog. Cisco Security MARS provides an incident to signify to the security operator that something of significance is occurring within the network. The incident is composed of various events that are reported by the devices within the self-defending network. Cisco Security MARS contains an entry under Reporting Devices in the Event entries for the incident. Figure 10-13 displays an example of how an incident can indicate that a reporting device has a policy link to Cisco Security Manager. Figure 10-13. Incident with Cisco Security Manager Policy Entry [View full size image! 3 | null litfHftiil DuLilb AflkiinvlE lnlúi ml E apLiiir-' piuríftd bqp CHiu SpEnira. Jit. £to frfc Tflwi fptrW tfci1 SiaMis.: Tlnio Roita*; Wiiifcr M Jilr Man!*" ScwW-z^- lluLFrrnk Action; KWfatfijP»** i iftPiJttfcWiflffl IE1 ItoñrttÉ HMftfl IfcÉMUfriWtS Ifa&flHMril ijWftF IfetyMrilárvrrii yK ■j-.HM| 1 Alf-i Uff A Iff I IjKMM ID; 5J7BW50 IjKMM ID; 5J7BW50
Cinr pici.it í.cvurrl f p-afcc ftL^/iwdwisjiHkréii4 0 Gram; - T*tai: + I* K^rw^ji-ril '| Cinr pici.it í.cvurrl f p-afcc ftL^/iwdwisjiHkréii4 0 Gram; - T*tai: + I* K^rw^ji-ril '| l:f J9F2H ■ 30.3 .L.S £ 114 L C] I&.1.S 3 ft| fíl U : ¡U ■ " í> S0=M r AM ?DT nirfr* & u: "gj [ S 5-35ÍMÍS„ jSG.S.LD.Í 0 . ■■: 0 « L Rl 7W* TCS» 0 ■V :. ¿i- ■■ ■ ■ ' ■■ mppii^ »■. , ,«r-|3t bufefa Wfcwitórtrttiiri I7J.-Ki.LJ B 'l is El IWM-TQtM B) +»¥ tí ' E El■ wdkñy Capirote O ¿TÍO]. ¿W5- Crua "5 i-HÍTOS. !>■•<: Al nqíta. n-L-fln«*-± Sumiwirp Que** / PüOH RüJiJ Hiftifcjímfr-u <ld#h¡A HClr | r.,.:i-,.:L ~] This policy entry is supported only for Cisco devices that are configured by Cisco Security Manager to deploy access list rules to these devices. Selecting this policy entry displays the access list configured by the Cisco Security Manager that generated the syslog in the security event. The ability to display the access list rules from the security event in Cisco Security MARS allows for quick debugging of many security situations and can allow the user to quickly address and rectify the security event that is reported by Cisco Security MARS. The policy link in Cisco Security MARS displays a copy ofthe desired access list rules configured in Cisco Security Manager. Figure 10-14 displays an example of how to launch the policy link from the reporting device in Cisco Security MARS, and Figure 10-15 displays the resulting access control list (ACL) rule table from Cisco Security Manager. Figure 10-14. Launch Policy Link from Cisco Security MARS [View full size image! Figure 10-14. Launch Policy Link from Cisco Security MARS
Figure 10-15. Access Control List (ACL) Rule Table Display [View full size image!
The linkages between Cisco Security MARS and Cisco Security Manager provide another example of how centralized management is the "coach" that allows the self-defending network to be deployed and managed in an integrated and holistic fashion. 4 PREY Summary Cisco Security MARS is a monitoring and reporting component of a self-defending network. Cisco Security MARS can also mitigate or generate configurations that can stop certain attacks and can allow the network to be self-defending. Some of the configurations that can be generated by Cisco Security MARS include the CLI to shut a LAN port, enable an IPS signature on an IOS ISR or an access control list (ACL) rule. Cisco Security MARS can automatically generate CLI to reduce the risk of an attack, or Cisco Security MARS can recommend the CLI to be manually deployed by SSH (Secure Shell) or the Cisco Security Manager. Cisco Security MARS will only recommend and will not deploy the CLI to configure an access control list (ACL) rule. Cisco Security MARS contains a high-level summary dashboard that includes incidents, hotspot graphs, and attack diagrams. An incident can be an indication that a high-level security attack, such as a Nimda attack, has been detected on the network. An incident is composed of security events and monitoring data that is received from known devices in the self-defending network, including routers, LAN switches, firewalls, IPS devices, hosts, databases, and storage appliances. Netflow data can be used to establish a baseline of normal traffic on a network. Netflow can be used to identify and filter false positives from valid security incidents. Rules are used to trigger a security incident. Cisco Security MARS contains many default or system inspection rules. Cisco Security MARS also features the ability to create custom or user-defined rules. The dashboard lists actionable, high-level security incidents. A hotspot graph and attack diagram are also created for a significant security incident. A hotspot graph contains the path of the network attack, including the source, destination, and known devices within the attack path. The attack diagram displays the session IDs reported by devices for the incident. Cisco Security MARS and Cisco Security Manager are components of the Cisco Security Management suite. Cisco Security MARS contains linkages with Cisco Security Manager. For example, a user can select a syslog from an incident and see the access control list (ACL) rule policy in Cisco Security Manager that generated the syslog. 4 PREY References Cisco Systems, Inc. Cisco Security Monitoring, Analysis and Response System 4.2 Data Sheet. http://www.cisco.com/en/US/products/ps6241/products data sheet0900aecd80272e64.html Cisco Systems, Inc. Cisco Security Monitoring, Analysis and Response System Q&A. http://www.cisco.com/en/US/products/ps6241/products qanda item0900aecd8027a051 .shtml Cisco Systems, Inc. Cisco Router and Security Device Manager.http://www.cisco.com/en/US/products/sw/secursw/ps5318/index.html Cisco Systems, Inc. Technology Preview: Configuring Distributed Threat Mitigation in Cisco Security MARS. http://www.cisco.com/en/US/products/ps6241 /products configuration example09186a008067a2b0.shtml 4 PREV Continue reading here: [SYMBOLi A i C Q i E rn tl ID y Ml CsU E El Ml EJ y IY W Was this article helpful? |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||