Book description
Identify, manage, and counter security threats with the Cisco Security Monitoring, Analysis, and Response System
Dale Tesch
Greg Abelar
While it is commonly understood that deploying network security devices is critical to the well-being of an organization’s systems and data, all too often companies assume that simply having these devices is enough to maintain the integrity of network resources. To really provide effective protection for their networks, organizations need to take the next step by closely examining network infrastructure, host, application, and security events to determine if an attack has exploited devices on their networks.
Cisco® Security Monitoring, Analysis, and Response System (Cisco Security MARS) complements network and security infrastructure investment by delivering a security command and control solution that is easy to deploy, easy to use, and cost-effective. Cisco Security MARS fortifies deployed network devices and security countermeasures, empowering you to readily identify, manage, and eliminate network attacks and maintain compliance.
Security Threat Mitigation and Response helps you understand this powerful new security paradigm that reduces your security risks and helps you comply with new data privacy standards. This book clearly presents the advantages of moving from a security reporting system to an all-inclusive security and network threat recognition and mitigation system. You will learn how Cisco Security MARS works, what the potential return on investment is for deploying Cisco Security MARS, and how to set up and configure Cisco Security MARS in your network.
“Dealing with gigantic amounts of disparate data is the next big challenge in computer security; if you’re a Cisco Security MARS user, this book is what you’ve been looking for.”
–Marcus J. Ranum, Chief of Security, Tenable Security, Inc.
Dale Tesch is a product sales specialist for the Cisco Security MARS product line for the Cisco Systems® United States AT Security team. Dale came to Cisco Systems through the acquisition of Protego Networks in February 2005. Since then, he has had the primary responsibilities of training the Cisco sales and engineering team on SIM systems and Cisco Security MARS and for providing advanced sales support to Cisco customers.
Greg Abelar has been an employee of Cisco Systems since December 1996. He was an original member of the Cisco Technical Assistance Security team, helping to hire and train many of the team’s engineers. He has held various positions in both the Security Architecture and Security Technical Marketing Engineering teams at Cisco.
Understand how to protect your network with a defense-in-depth strategy
Examine real-world examples of cost savings realized by Cisco Security MARS deployments
Evaluate the technology that underpins the Cisco Security MARS appliance
Set up and configure Cisco Security MARS devices and customize them for your environment
Configure Cisco Security MARS to communicate with your existing hosts, servers, network devices, security appliances, and other devices in your network
Investigate reported threats and use predefined reports and queries to get additional information about events and devices in your network
Use custom reports and custom queries to generate device and event information about your network and security events
Learn firsthand from real-world customer stories how Cisco Security MARS has thwarted network attacks
This security book is part of the Cisco Press® Networking Technology Series. Security titles from Cisco Press help networking professionals secure critical data and resources, prevent and mitigate network attacks, and build end-to-end self-defending networks.
Category: Cisco Press–Security
Covers: Security Threat Mitigation
Table of contents
- Copyright
- About the Authors
- About the Technical Reviewers
- Acknowledgments
- Foreword
- Introduction
-
I. The Security Threat Identification and Response Challenge
- 1. Understanding SIM and STM
- 2. Role of CS-MARS in Your Network
- 3. Deriving TCO and ROI
-
II. CS-MARS Theory and Configuration
- 4. CS-MARS Technologies and Theory
- 5. CS-MARS Appliance Setup and Configuration
-
6. Reporting and Mitigative Device Configuration
- Identifying CS-MARS–Supported Devices
-
Configuring Devices to Communicate with CS-MARS
- Configuring Routers
- Configuring Switches
- Configuring Firewalls
-
Enabling IDS and IPS in a CS-MARS Environment
- Cisco IPS Appliance Configuration
- Cisco IPS Catalyst Switch Modules
- Cisco IPS Enable Routers (Integrated Security Routers)
- Cisco Security Service Modules (IPS Modules) for ASA (ASA/SSM)
- IntruVert IntruShield V1.8
- Juniper NetScreen IDP
- Symantec ManHunt
- ISS RealSecure Sensor
- Snort IPS Sensor
- Enterasys Dragon
- Operating Systems and Web Servers
- VPN Concentrators
- Antivirus Hosts and Servers
- Database Servers
- Oracle
- Summary
-
III. CS-MARS Operation
-
7. CS-MARS Basic Operation
- Using the Summary Dashboard, Network Status Graphs, and My Reports Tab
- Using the Incidents Page
- Simple Queries
- Summary
- 8. Advanced Operation and Security Analysis
-
7. CS-MARS Basic Operation
- IV. CS-MARS in Action
-
V. Appendixes
- A. Useful Security Websites
- B. CS-MARS Quick Data Sheets
- C. CS-MARS Supplements
- D. Command-Line Interface
- E. CS-MARS Reporting
- F. CS-MARS Console Access
- G. CS-MARS Check Point Configuration
Product information
- Title: Security Threat Mitigation and Response: Understanding Cisco Security MARS
- Author(s):
- Release date: September 2006
- Publisher(s): Cisco Press
- ISBN: 9781587052606
You might also like
book
Tidy First?
Messy code is a nuisance. "Tidying" code, to make it more readable, requires breaking it up …
book
Modern Software Engineering: Doing What Works to Build Better Software Faster
Improve Your Creativity, Effectiveness, and Ultimately, Your Code In Modern Software Engineering, continuous delivery pioneer David …
book
CHFI Computer Hacking Forensic Investigator Certification All-in-One Exam Guide
An all-new exam guide for version 8 of the Computer Hacking Forensic Investigator (CHFI) exam from …
book
Learning Web Design, 5th Edition
Do you want to build web pages but have no prior experience? This friendly guide is …