Cisco Adds Visibility into Cloud Security

Cisco today is adding a new intelligence capability to its cloud security portfolio that allows customers to analyze the flow of traffic and the types of security attacks that are being made on their networks.

According to Spencer Parker, a product manager for Cisco, the Web Intelligence Reporting (WIRe) was built from the ground up by Cisco to provide an analytics application that could monitor transaction flow across a network in real time. In contrast, other analytic applications only work against static sets of data, he said.

The service leverages cloud security technology that Cisco acquired when it bought ScanSafe earlier this year and can be used to deliver reports about not only what is happening on specific customer networks, but to also provide information on what is happening on the Internet in aggregate.

Cisco today will also announce to that via a pact with RSA, the company is adding data loss prevention software to its cloud security platform. That offering complements existing DLP capabilities that Cisco already offers. But as more customers continue to specify DLP software from RSA, Cisco has decided to add the RSA software to its portfolio as well.

Comments

1. Comprehensive channels coverage. It is impossible to predict which outbound channel the next data leak will occur. Some expected avenues are: corporate email, private email, webmail, blog, instant messenger, P2P application, internal web or FTP server etc. Therefore, the DLP system must cover ALL the relevant channels. The majority of "DLP" systems do not even try to cover all network channels. Typically, they cover SMTP, FTP, HTTP (client side), sometimes HTTPS and instant messaging. This coverage is further handicapped. For example, scanning SMTP, these systems require integration with the corporate email server and inspect only emails sent through it. Emails sent through an external ISP are overlooked. Emails accessed from outside the perimeter through POP3 or HTTP (server side) are ignored by such solutions. The dangers of file sharing applications and exposure of the internal web servers are disregarded. 2. Enforcement - Blocking Data Leak Prevention, by its definition, requires electronic enforcement of the data security policy ? i.e. the product must be able to effectively block transmission of protected data. Many "DLP" products being sold are actually DLD ? Data Leak Detection products. They are designed to report what data breaches have occurred, instead of stopping them in real time. 3. Content Inspection The true DLP solution must inspect content. Making decisions based on the form (file type, file attributes etc.) or meta-data (author, language, size of attachment etc.) is not enough. 4. Accuracy The DLP solution must be sufficiently accurate. Among two types of errors (false positives and undetected leaks) the more dangerous error is a false positive. In the enforcement mode, even a small amount (0.1%-0.2%) of false positives can wreak havoc in the organization. Therefore, a DLP solution has to employ detection technology with virtually zero false positives. Another aspect of accuracy is that the DLP system must protect data and not a specific form of its representation. Therefore, the DLP system must be resilient to typical modifications of the data, such as excerpting, embedding, changing file format, re-ordering, re-typing, text re-formatting etc. 5. Non-duplicating protected data. The DLP solution must not duplicate the protected data in any form! If it does, then DLP becomes Data Leak Provoking. But many vendors still sell products, copying the data they are supposed to protect into their internal database. Encrypting such data, or keeping it in the form of the search index is not enough to satisfy this requirement!

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
  • Allowed HTML tags: <b> <i>

More information about formatting options