Your trusted security advisors for Check point, Cisco, CipherTrust, Commtouch, FrontBridge, Juniper Networks solutions


Search Networkguys Web site:


Important Links
CISSP
CISSP
Assessments
Assessments
Security Policy
Security Policy
CSA Bundle
CSA Bundle


Section Links
SolutionsOverview
Solutions
Email
Solutions
Anti Virus
Solutions
Spam
Solutions
Intrusion Detection & Prevention
Solutions
Wireless Security
Solutions
URL Filtering
Solutions
Network Security
Solutions
Internal
Solutions
Perimeter
Solutions
Remote Access
Solutions
SSL
Solutions
IPSEC
Solutions
Event Correlation
Solutions
Logging Monitoring
Solutions
Strong Authentication
Solutions

Security Monitoring and Mitigation     

 

OVERVIEW

 

CISCO SECURITY MONITORING, ANALYSIS AND RESPONSE SYSTEM (MARS)

 

The Cisco Security Monitoring, Analysis and Response System (Cisco Security MARS) is an appliance based, all inclusive solution, that provides unmatched insight and control of your existing security deployment. A key component of Cisco’s security management lifecycle, Cisco SecurityMARS empowers your security and network organizations to identify, manage, and counter security threats. It leverages your existing network and security investments to identify, isolate and recommends precision removal of offending elements. It also helps maintain internal policy compliance and can be an integral part of the overall regulatory compliance solution kit.The problems faced by security and Network administrators are:

  • Security and network information overload
  •  Poor attack and fault identification, prioritization, and response· Increased attack sophistication,     velocity, and remediation costs
  •  Meeting compliance and audit requirements
  •  Moderate security staff and budgets

Cisco Security MARS addresses their needs by:

  •  Integrating network intelligence to modernize correlation of network anomalies and security events
  •  Visualizing validated incidents and automate investigation
  •  Mitigating attacks by fully leveraging network and security infrastructure
  •  Monitoring systems, network, and security operations to aid in compliance
  •  Delivering a scalable appliance that is easy to deploy and use with the lowest TCO

Cisco Security MARS transforms raw network and security data into actionable intelligence used to subvert valid security incidents and maintain compliance. This easy to use family of threat mitigation appliances enables operators to centralize, detect, mitigate, and report on priority threats by leveraging the network and security devices already deployed in your infrastructure.

THE DEFENSE-IN-DEPTH DILEMMA

Information security practices have evolved from Internet, perimeter protection to an in-depth defense model in which multiple countermeasures are layered throughout the infrastructure to address vulnerabilities and attacks. This is a necessity due to increased attack frequency, diverse attack sophistication, and the rapid nature of attack velocity all blurring the boundaries between the network and perimeter. Network access points and systems are probed thousands of times a day in the attempt to exploit vulnerabilities. Modern blended/hybrid attacks use multiple and deceptive attack methodologies to gain unauthorized system access and control from outside and within organizations. The proliferation of worms, zero-day attacks, viruses, trojans, spyware, and attack tools challenges even the most fortified infrastructures---resulting in smaller reaction time, downtime, and costly remediation. Beyond the mere number of servers and network devices, each security component offers isolated event log and alert features for anomaly detection, threat reaction, and forensics. Unfortunately, this yields a tremendous amount of noise, alarms, log files and false positives for operators to discern or effectively utilize---assuming the time and resources are available to parse through and understand this information. In addition, compliance legislature requires strict data privacy, improved operational security, and maintained audit processes.

ADVANCING SECURITY INFORMATION MANAGEMENT

Security Information/Event Management (SIM) products logically seem to alleviate these problems---you can’t manage what you can’t measure. SIMs enable operators the ability to centrally: aggregate security events and logs, analyze this data through limited correlation and query techniques, and generate alarms and reports on isolated events.

Unfortunately, many first and second generation SIMs do not yield sufficient network intelligence and performance attributes to more precisely identify and validate correlated events, better pinpoint attack paths, surgically remove threats, or maintain high event loads.

Cisco Systems addresses these security issues and management deficiencies with a family of scalable, enterprise threat mitigation appliances. Cisco Security MARS complements your network and security infrastructure investment by delivering a security command and control solution that is easy to deploy, easy to use, and cost-effective. Cisco Security MARS is a family of high performance, scalable threat mitigation appliances that fortify deployed network devices and security countermeasures by combining network intelligence, ContextCorrelation™, SureVector™ analysis and AutoMitigate™ capability which empowers companies to readily identify, manage and eliminate network attacks and maintain compliance.

CISCO SECURITY MARS KEY FEATURES AND BENEFITS

Network Intelligent Event Aggregation and Performance Processing                                            Cisco Security MARS obtains network intelligence by understanding the topology and device configurations from routers, switches, and firewalls, and by profiling network traffic. The system’s integrated network discovery builds a topology map containing device configuration and current security policies which enables Cisco Security MARS to model packet flows through your network. Since the appliance does not operate inline and makes minimal use of existing software agents, there is minimal impact on network or system performance.

The appliance centrally aggregates logs and events from a wide range of popular network devices (such as routers and switches), security devices and applications (such as firewalls, intrusion detection, vulnerability scanners, and anti-virus), hosts (such as Windows, Solaris and Linux syslogs), applications (such as databases, web servers, and authentication servers), and network traffic (such as Cisco Netflow).

ContextCorrelation™ As events and data are received, the information is normalized against the topology, discovered device configurations, same source and destination applications (across NAT boundaries), and similar attack types. Similar events are grouped into sessions in real-time. System and user-defined correlation rules are then applied to multiple sessions to identify incidents. The system ships with a full complement of pre-defined rules, frequently updated by Protego, that identify a majority of blended attack scenarios, zero-day attacks, and worms. A graphical rule definition framework simplifies the creation of user-defined custom rules for any application. ContextCorrelation significantly reduces raw event data, facilitates response prioritization, and maximizes results from deployed countermeasures.

High Performance Aggregation and Consolidation The Cisco Security MARS solution captures thousands of raw events, efficiently classifies incidents with unprecedented data reduction, and compresses this information for archive. Managing the high volume of security events requires a secure and stable centralized logging platform. The Cisco Security MARS appliances are security hardened and optimized for receiving extremely high levels of event traffic---over 10,000 events per second or over 300,000 Netflow events per second. This is made possible through patent pending Protego in-line processing logic and employing embedded Oracle®. All the database functionality and tuning is transparent to the user. On-board storage and continually compressing historical data archives to NFS secondary storage devices makes Cisco Security MARS a sound security log/event aggregation solution.

Incident Visualization and Leveraged Mitigation

Cisco Security MARS helps to accelerate and simplify the process of threat identification, investigation, validation, and mitigation. Staff are often confronted with escalated events requiring time consuming analysis for resolution and remediation. Cisco Security MARS provides a powerful, interactive security management dashboard. The operator GUI provides a topology map comprised of real-time hotspots, incidents, attack paths, and drill-down investigation with full incident disclosure---allowing immediate verification of valid threats.

SureVector™ analysis processes like event sessions to determine if threats are valid or have been countered by assessing the entire attack path down to the end point MAC address. This automated process is accomplished by analyzing device logs such as firewalls and intrusion prevention applications, third party vulnerability assessment data, and through Cisco Security MARS end point scans to eliminate false positives. Users can quickly fine-tune the system to further reduce false positives.

The end-goal of any security program is to keep systems on-line and functioning properly… this equates to preventing security exposures, containing incidents, and facilitating remediation. With Cisco Security MARS, operators have a rapid means to understand all of the components involved within an attack down to the offending and compromised system MAC address. AutoMitigate™ capabilities identifies available choke point devices along the attack path and automatically provides the appropriate device commands that the user can employ to mitigate the threat. The results can be used to quickly and accurately prevent or contain an attack by leveraging the infrastructure.

Real-time Investigation and Compliance Reporting

Cisco Security MARS boasts an easy-to-use analysis framework which streamlines conventional security workflow providing automated case assignment, investigation, escalation, notification, and annotation for daily operations and specialized audits. It can graphically replay attacks and retrieve stored event data to analyze previous events. The system fully supports ad hoc queries for real-time and subsequent data-mining efforts.

Cisco Security MARS offers numerous pre-defined reports to satisfy operational requirements and assist in regulatory compliance efforts including Sarbox, GLBA, HIPPA, FISMA, and Basel II . An intuitive report generator can modify the more than 80 standard reports or generate new reports for an unlimited means to build: action and remediation plans, incident and network activity, security posture and audit, as well as departmental reports - in data, trend and chart formats. The system also provides for batch and email reporting.

Rapid Deployment and Scalable Management

Cisco Security MARS is placed on a TCP/IP network where it can send and receive syslog, SNMP traps, and establish secure sessions with deployed network and security devices through standard secure or vendor-specific protocols. Plug it in and go. No additional hardware, operating system patches, licensing, or lengthy professional service engagements are required to install and deploy the Cisco Security MARS system. Simply configure your log sources to point to the MARS appliance and define any network and source through the web-based GUI.

The appliance is centrally managed through a secure web-based interface supporting role-based administration. The optional Cisco Security MARS GC appliance centralizes expansive security operations to provide a single view of the entire enterprise, disseminate access privileges, configurations, updates, customized rules, and report templates, as well as coordinate complex investigations with accelerated queries and reports which are processed locally.

As the local Cisco Security MARS appliances execute queries and rules across the enterprise, the results are efficiently rolled up and consolidatedfor rapid and centralized analysis at the Cisco Security MARS GC. This scalable architecture yields an additional level of distributed processing and storage. The result is more cost-effective deployment and greater manageability which address the requirements of large and geographically dispersed organizations.

Cisco Security MARS Technical Specifications

Cisco Security MARS family offers different performance characteristics and prices to meet a variety of organization and deployment scenarios.

 Cisco Part Number        Performance      NetFlows/Sec    Storage     Form Factor    Power Supply      (Protego Models)             Events/Sec


Cisco SecurityMARS-20-K9        500            15,000               120GB           1RU x16"          300W             (PN-MARS 20)                                                                   (non-RAID)                                                Cisco Security MARS-50-K9       1,000          30,000            240GB RAID0   1RU x25.6"       300W          (PN-MARS 50)                                                                                                                                    Cisco Security MARS-100EK9    3,000          75,000          750GB RAID10    3RU x25.6"      500W Dual     (PN-MARS 100e)                                                              Hot Swappable                           Redundant Cisco Security MARS-100K9      5,000          150,000        750GB RAID10    3RU x25.6"      500W Dual     (PN-MARS 100)                                                                Hot Swappable                           Redundant Cisco Security MARS-200EK9    10,000         300,000        1TB RAID10       4RU x25.6"       500W Dual     (PN-MARS 200)                                                                 Hot Swappable                           Redundant

Cisco Part Number                    Distributed     Maximum     Storage       Form Factor    Power Supply(Protego Number                      Monitoring   Connections                            Controller Models)             Models Supported   


Cisco Security MARS-GCM-K9  From MARS          5            1TB RAID10        4RU x25.6"      500W Dual     (PN-MARS 100 GCm)                 20/50 Only                         Hot Swappable                           Redundant

Cisco Security MARS-GC-K9          Any        Not Currently   1TB RAID10        4RU x25.6"      500W Dual     (PN-MARS 100 GC)                                       Restricted       Hot Swappable                           Redundant


* EPS: maximum events per second with dynamic correlation and all features enabled.

Dynamic Session-based Correlation

  •  Anomaly detection including NetFlow
  • Behavior-based and rules-based event correlation
  • Comprehensive built-in and user-defined rules
  • Automated NAT normalization

Topology Discovery

  • Layer 3 and layer 2; routers, switches, firewalls
  • Network IDS: blades and appliances
  • Manual and scheduled discovery
  • SSH, SNMP, Telnet and device-specific communications

Vulnerability Analysis

  •  Incident triggered targeted network and host based fingerprinting
  •  Switch, router, firewall, and NAT configuration analysis
  •  Automated vulnerability (VA) scanner data capture
  •  Automated and user-tuned false positive analysis

Incident Analysis and Response

  • Personalized security event management dashboard
  • Session-based event consolidation with full-rule context
  • Graphical attack path visualization with drill-down investigation
  • Attack path device profiles with end point MAC identification
  • Graphical and detailed sequential attack pattern display
  • Incident details: rules, raw events, CVE, and mitigation options
  • Immediate incident investigation and false positive determination
  • GUI rule definition supports custom rules and keyword parsing
  • Incident escalation with user-based ‘to do’ work list
  • Notification: Email, pager, syslog, SNMP

Query and Reporting

  • GUI supports numerous default queries and customized queries
  • Over 80 popular reports: management, operational, and regulatory
  • Intuitive report generation yields unlimited customized reports
  • Data, chart, and trend formats support HTML and CSV export
  • Live, batch, template, and email forwarding reporting system

Administration

  •  Web interface (HTTPS); roles-based administration with defined privileges
  •  Cisco Security MARS GC (Global Controller) hierarchical management of multiple Cisco Security MARS
  •  Automated, verified updates: device support, new rules, and features
  •  Continuous compressed raw data and incident archive to offline NFS storage

Device Support (more current list on website)

  •  Network: Cisco IOS 11.x, 12.2, Catalyst OS 6.x, NetFlow 5.0, 7.0, Extreme Extremeware 6.x
  •  Firewall/VPN: Cisco PIX Firewall 6.x, IOS Firewall, FWSM 1.x, 2.2, Concentrator 4.0, Checkpoint Firewall-1 NGx, VPN-1, NetScreen Firewall
  • 4.0, 5.0, Nokia Firewall
  •  IDS: Cisco NIDS 3.x, 4.x, Network IDS module 3.x, 4.x, Enterasys Dragon NIDS 6.x ISS RealSecure Network Sensor 6.5, 7.0, Snort NIDS 2.x,
  • McAfee Intrushield NIDS 1.x, NetScreen IDP 2.x, OS 4.x, 5.x, Symantec MANHUNT
  •  VA: eEye REM 1.x, FoundStone FoundScan 3.x
  •  Host Security: Cisco Security Agent (CSA) 4.0, McAfee Entercept 2.5, 4.0, ISS RealSecure Host Sensor 6.5, 7.0
  •  Antivirus: Symantec A/V
  •  Authentication Servers: Cisco ACS
  •  Host Log: Windows NT, 2000, 2003 (agent and agentless), Solaris, Linux
  •  Application: Web Servers (ISS, iPlanet, Apache), Oracle 9i, 10i audit logs, Network Appliance NetCache, Oracle 9i and 10i
  •  Universal Device Support to aggregate and monitor any application syslog

Additional Hardware Specifications

  • Purpose-built 19’’ rack-mountable appliances; UL approved
  •  Security hardened OS; firewalled with reduced services
  • Two (2) 10/100/1000 Ethernet interfaces, DVD-ROM with recovery media
  • Storage:                                                                                                                                           – Cisco Security MARS 20 and Cisco Security MARS 50: RAID 0                                                     – CS- MARS 100, Cisco Security MARS 200, Cisco Security MARS GC: RAID 10 Hot-swappable
  •  Redundant (MARS 100, MARS 200 and MARS GC) load sharing 500-watt power/120/240 Volt auto-switch

 


      


NetworkGuys Achieves
Cisco Global Security Partner of the Year!


Read more



Cisco Security Agent Bundle
Security health check PDF
Websense bundles
Wireless security posture assessment

  
© Copyright 2005 NetworkGuys Inc.