Thursday, February 08, 2007

Collaborative Threat Control: Securing the Whole Network

Cisco released a news article yesterday, revealing the updates to many products in the Security Portfolio.

Read about it here.... or summarised on Mikes Mars Blog here, hopefully MARS 4.3 is just around the corner then!

Cisco® today announced significant new capabilities for enhanced collaboration among several products and services in its security portfolio, simplifying the ability for organizations to control and contain information security threats in a more coordinated, flexible fashion across networks while streamlining management and protecting confidential communications to remote users.

The collective enhancements involve Cisco's Intrusion Prevention System (IPS), Cisco Security Agent (CSA), Cisco Security Mitigation Analysis and Response System (CS-MARS), Cisco Security Manager (CSM) and Cisco's Secure Sockets Layer virtual private network (SSL VPN). Together, the enhancements mark the latest evolution of Cisco's Self-Defending Network - a comprehensive framework incorporating various endpoint and network security products into an integrated, collaborative and adaptive security solution for organizations of all sizes.

Cisco's enhanced security portfolio includes Cisco IPS 6.0, CSA 5.2, CS-MARS 4.3, and CSM 3.1 - four products that combine to coordinate visibility, network-wide protection, simplified policy management and dynamic threat mitigation in order to maintain business continuity. These releases strengthen Cisco's approach to coordinated defense by extending beyond the typical standalone nature of these product classes and establishing a vital relationship between the network and its endpoints. This helps ensure that all potential entry points can be protected in a coordinated fashion.

Monday, February 05, 2007

Guest Articles and User Group

I`m always on the lookout for Cisco Partners who have MARS experience, to share information here on the blog.

I`ve already been let down by a couple of US based resellers, but i`m sure there must be some MARS experts out there somewhere!

If you are interested in writing an article, please get in contact.


Also remember, you can post your MARS Questions on the Cisco MARS User Group, join below...


http://groups.google.com/group/cs-mars-ug?hl=en-GB

Connection to Remote NFS Archive Fails

What happens when your NFS Archive Server goes down?

Well i must admit, i was surprised earlier today, when changing some configs in the LAB, that i received an email from my MARS box, telling me the NFS Archive was unreachable.


I`m not sure if this is a new feature, or its always been in there, but it looks like MARS will automatically email the Adminstrator email address, every 2 hours if the NFS is unreachable.


Now i will try to confirm this, but i cannot find a MARS rule for this event. (Unless someone can point me to one?)

So it looks like this is backend stuff.

Tuesday, January 30, 2007

New Cisco MARS Deployment Guide

Cisco have published a new Deployment Guide for CS-MARS.

This document provides guidance on how to best deploy Cisco® Security Monitoring Analysis and Response System (MARS), an appliance-based, all-inclusive solution that provides unmatched insight and control of your existing security deployment. It discusses, among other topics, how to position the appliance in your network, how to tune it, and how to implement a distributed scenario.



This document is for security engineers, network engineers, engineering managers, and the network and security operations staff that plan, design, and implement security monitoring with MARS.

The document is based on a MARS 4.2.x release.


Monday, January 29, 2007

CS-MARS Case Management

One of the many features of CS-MARS is Case Management.

The Case Management feature can combine and preserve user selected MARS data, in a special report called a CASE.


Why would we want to do this?

Well when we see suspicious behavior alerted to us by MARS, we may want to tie multiple incidents together and keep a textual log, of what action/s the MARS admins have taken regarding these events. This level of information may be needed later for legal/audit/forensic use.

So what information can we add to a Case?

The following data can be added to a case...
  • Text Annotations
  • Incident ID Page
  • Incident Device Information - Source IP/Destination IP Device Info. Reporting Devices
  • Session Information Page
  • Query Results Page
  • Report Results Page
  • Build Reports Page
  • View Case Page (the current case can reference a different case!)

As an example, take the investigation of Peer-to-Peer software on the network.

A case has been created and assigned to a user on the MARS box.


The MARS user logs onto the box, and selects the CASE to work with...

Now reviewing the other incidents that have fired, he/she decides that there a few that they would like to group together for further investigation. This is achived via the "Add This Incident" button.


And maybe they want to add some comments, or re-assign to a different user....


Or maybe add a Device or Source IP/Destination IP Address information into the Case...




And Session information....


And maybe we have run some queries against a particular host, and want to add the results of those queries into the case...



And lastly, maybe we want to reference a different case, that has already been created...


Once done, and we view our case, we will see all the data collated together...



Now if we click on the "View Case Document" button, on the bottom of the CASE, we will see that CASE in full detail, with all the incident and session information expanded, as if we were viewing the individual Incident/Session Pages. This complete display can be emailed, by clicking the email button, and then a MARS user selected.



Any user can create or alter any case, and also add or remove incidents from the case, but this is all tracked in the CASE history.


In order to change or add to a case, we need to select it first, by simply clicking on the case, when found on the dashboard, (or via the Incidents TAB/Cases) or in the To-do List. This particular case is then always highlighted at the top of the dashboard. Once finished we can deselect the case.

Since in many environments multiple users are logging into the MARS box under different usernames, we can also assign cases to different personnel, and only the cases relevant to that particular user will appear under the To-Do List, on the main CS-MARS console.


Another thing to be aware of, is that once a CASE is created, it cannot be deleted. Hell No!, the auditors would just do their nut! It can be closed or resolved. Once in this state it can still be added to, but the status of a closed case cannot be changed.


In the Incident View, we can also narrow down the displayed Incidents, by CASE status, of New,Open, Assigned, Resolved or Closed.


Case information collected together builds up your forensic evidence pertinent to Audits, Policy Change Justifications, MARS False Positive Tuning and examples of allowed and prohibited behaviour.

The information collected by a CASE is preserved. ie, the data that is displayed within a case, is as it was, when the data was actually added to the case, regardless of subsequent changes to the MARS state.

So for example, the CS-MARS data can be purged due to disk partitions being full, (remember earlier articles), the topology can change etc.. but the data reported within a case remains the same as the time it was captured.



Thursday, January 25, 2007

CS-MARS User Group Sign Up

I`ve had great interest in the Cisco MARS User Group, with lots of people signing up.

A few of you though, have had problems, getting an approval email back.

If you have had any problems getting on, please email me direct.

I have also added a signup link to the group opposite.

Tuesday, January 23, 2007

Cisco MARS User Group

For those of you interested, there is a new Cisco MARS User Group that has been created, in google groups, with discussions around MARS features/problems/Useful Resources etc.....

To join go here

Friday, January 19, 2007

Cisco Security Advisory: SSL/TLS Certificate and SSH Public Key Validation Vulnerability

Posted: January 18, 2007

Summary: The Cisco Security Monitoring, Analysis and Response System (CS-MARS) and the Cisco Adaptive Security Device Manager (ASDM) do not validate the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) certificates or Secure Shell (SSH) public keys presented by devices they are configured to connect to. Malicious users may be able to use this lack of certificate or public key validation to impersonate the devices that these affected products connect to, which could then be used to obtain sensitive information or misreport information.

Affected Products
The following products are affected by the vulnerability described in this document:

Cisco Security Monitoring, Analysis and Response System (CS-MARS)

All CS-MARS versions prior to 4.2.3 are affected.

Cisco Adaptive Security Device Manager (ASDM)

All ASDM versions prior to 5.2(2.54) are affected when the ASDM Launcher (the stand-alone version of ASDM) is used.

Cisco has made free software available to address this vulnerability for affected customers.

URL:
http://www.cisco.com/en/US/customer/products/products_security_advisory09186a00807c517f.shtml
(available to registered users)

http://www.cisco.com/en/US/products/products_security_advisory09186a00807c517f.shtml
(available to non-registered users)

Thursday, January 18, 2007

Guest Article - MARS Overview


I have great pleasure in releasing another guest Article (PDF Presentation), to the Cisco MARS Blog.



Edgar Reinke is a senior consultant with Netfarmers, a leading German Consultancy and Training Company, specializing in Enterprise/ISP security, Unified Communications and as he would term Big Clouds (MPLS, QoS, TE, IPv6, BGP-4, OSPF, IS-IS).

This PDF presentation gives an unbiased overview of Cisco MARS, and also provides some insight into the operation and flow of event data. (sample below).

Archiving - Remote Storage Capacity in Days

I blogged a couple of weeks ago, regarding the Remote Storage in Days value, when Archiving.

I had come across an error, where by only a single directory was being created, and no data.

I believed at the time it was due to the Remote Storage Capacity in Days value. I had some comments on this, so i thought i would test this out.

So i set my archiving value to 1 day



And let it run for a couple of days. The correct operation is that, older data will be deleted from the NFS Archive, and from my tests, Yep, that is what happens!





So as can be seen, 1 full days archive is still present on the archive server.

So i have pulled the previous article, as it is complete garbage, but i still havent figured out, what caused it!

Still on the subject of Archiving, i received an email from Nathan, who has had an archiving problem recently, on the new 4.2.3 code. He was archiving to a Windows box running Windows Services for UNIX.

He found that the directories were being created, but no data was actually being stored. Looking into his NFS log file on the windows box, he found..

01-17-2007 11:41:31 CREATE SUCCESS 10.X.X.X \DosDevices\C:\archive\testNfsServer
01-17-2007 11:41:32 DELETE SUCCESS 10.X.X.X \DosDevices\C:\archive\testNfsServer
01-17-2007 11:41:37 CREATE SUCCESS 10.X.X.X \DosDevices\C:\archive\testNfsServer
01-17-2007 11:41:38 DELETE SUCCESS 10.X.X.X \DosDevices\C:\archive\testNfsServer
01-17-2007 11:41:43 CREATE SUCCESS 10.X.X.X \DosDevices\C:\archive\testNfsServer

All seemed fine, except there were no WRITE statements in the logs.

The archive process had hung in some fashion and the solution was restarting the MARS services "pnstop > pnstart" and everything went back to normal.