Understanding Cisco Security MARS Features


Cisco Security MARS is different from the conventional Security Information Management Solution (SIMS) or other traditional security monitoring products. Cisco Security MARS offers several advantages based upon the following features:

  • Import Netflow data

  • Create baseline of normal network traffic

  • Import configurations of monitored devices

  • Understand traffic flow across Network Address Translation (NAT) boundaries

  • Integrated Nessus Vulnerability Scanner input

  • Display topology map of network and attack vectors

  • Reduce false positives by reporting incidents

  • Provide mitigation by deploying configuration to shut specific ports to stop an attack

  • Provide mitigation by displaying an access list to stop an attack close the source of the attack

Cisco Security MARS is offered as a turnkey appliance. Cisco Security MARS includes an integrated Oracle database and can handle up to 10,000 events per second. The Cisco Security MARS product line also features different appliance form-factors including a lowend model that supports 500 events per second, excluding Netflow data. A turnkey appliance allows the Cisco Security MARS product to be up-and-running quickly without an extensive installation or tuning process. Cisco Security MARS displays a security incident during an attack, based upon input and events from devices within the selfdefending network. A partial list of the sources from which Cisco Security MARS can accept input and events includes the following:

  • Cisco IOS routers

  • Cisco Catalyst LAN Switches (Catalyst 0S 6.x)

  • Cisco PIX Firewalls

  • Checkpoint Firewalls

  • Cisco VPN Concentrators

  • Netscreen Firewalls

  • Cisco IPS Sensors

  • Enterasys Dragon IPS Sensors

  • Snort IPS Sensors

  • ISS IPS Sensors

  • eEye REM

  • Foundstone

  • Cisco Security Agent

  • Symantec Anti-Virus

  • Cisco ACS

  • Windows Host Log

  • Solaris Host Log

  • Linux Host Log

  • IIS Web Server Log

  • Apache Web Server Log

  • Oracle Audit Logs

  • NetApp Logs

Cisco Security MARS has the ability to see the entire self-defending network based upon input and events from the preceding sources. This diverse selection of input, combined with the network configurations and baseline traffic, allows Cisco Security MARS to report on specific, high-level, actionable security incidents rather than displaying and reporting based upon individual and voluminous firewall syslog and IPS Sensor events. Cisco Security MARS also supports a global controller functionality. The global controller provides a centralized management station for multiple Cisco Security MARS local controllers.



Setf-Defending Networks(c) The Next Generation of network Security
Self-Defending Networks: The Next Generation of Network Security
ISBN: 1587052539
EAN: 2147483647
Year: N/A
Pages: 112

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net