
Cisco Cyber Threat Defense Solution
At-A-Glance
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks.
Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R)
Overview
The network security threat landscape is ever evolving. But always at the cutting edge
are custom-written, stealthy threats that evade traditional security perimeter defenses.
The Cisco® Cyber Threat Defense Solution provides greater visibility into these threats
by identifying suspicious network traffic patterns within the network interior. These
suspicious patterns are then supplemented with contextual information necessary to
discern the level of threat associated with the activity.
Solution Highlights
Cisco Cyber Threat Defense focuses on the most complex and dangerous information
security threats—threats that lurk in networks for months or years at a time stealing vital
information and disrupting operations. Cisco provides visibility into these threats and
context to decipher their targets and potential damage. Security analysts gain visibility
into advanced cyber threats such as:
• Network reconnaissance
• Network interior malware proliferation
• Command and control traffic
• Data exfiltration
The Cisco Cyber Threat Defense Solution is built upon the following components:
• Unique interior network traffic telemetry capabilities of Cisco Catalyst® switches,
Cisco routers and Cisco ASA 5500.
• Network traffic analysis capabilities provided by the StealthWatch System from
Lancope, Cisco’s cyber threat solution partner. Cisco offers the StealthWatch
System via its development partnership with Lancope.
• Identity, security, and application-type contextual information for discerning the
target and severity of the threat. These context points are delivered by the Cisco
Identity Services Engine, NAT correlation on ASR 1000 routers and ASA 5500
appliances, and Network-Based Application Recognition (NBAR) on Cisco routers,
and are presented in a unified view via the StealthWatch Management Console.
Unied View
Threat analysis and context
in Lancope StealthWatch
Flexible NetFlow Telemetry
from Cisco routers, switches,
and ASA 5500
Threat Context Data Identity,
device proling, posture,
NBAR and NAT context
Benefits
The Cisco Cyber Threat Defense Solution:
• Provides threat defense in the network interior, where the most elusive and
dangerous threats are
• Enables scalable, ubiquitous, and cost-effective security telemetry throughout the
network using NetFlow data from the Cisco network infrastructure
• Simplifies error-prone and expensive manual threat investigation processes
• Uses existing Cisco switch, router, and ASA 5500 network footprint
评论