Home > Networking News > Cisco adds new layers to network defense
Networking News:
EMAIL THIS

Cisco adds new layers to network defense

By Eric B. Parizo, News Editor
27 Sep 2005 | SearchNetworking.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Anyone paying attention to Cisco Systems Inc. during the past year knows that the San Jose, Calif.-based vendor vehemently believes the future of enterprise network security depends on numerous layers of protection.

Tuesday the networking giant added a pair of new layers to its paradigm, the Cisco Incident Control System (ICS) and the Cisco Distributed Threat Mitigation for Intrusion Prevention Systems (IPS).

The first element, the ICS, is intended to boost security on a corporate network before an emerging Internet threat reaches the perimeter. Based on a Cisco 5500 Series adaptive security appliance (APA), the ICS relies on regular updates from Trend Micro Inc.'s TrendLabs to keep tabs on worm and virus activity worldwide.

Joel McFarland, manager of security product marketing for Cisco, said ICS allows a network security manager to put policies in place prior to an outbreak so that, when threat global threat activity reaches a predetermined level, ICS changes the settings on Cisco routers and switches into a more defensive posture.

The second piece, Distributed Threat Mitigation (DTM), is actually an enhancement to Cisco's Security Monitoring, Analysis and Response System (CS-MARS), which manages internal network security policies.

Its objective is to mitigate threats that have made their way into the network.When DTM for IPS isolates the existence of an internal attack or infection, it uses Cisco IPS appliance sensors to change the posture of the network so that the threat doesn't spread inadvertently.

For example, should a notebook carrying the Zotob worm gain access to the network, DTM for IPS adjusts routers on the network edge to ensure other PCs stay safe.

Complementing the two products is a new version of Cisco Internetwork Operating System. IOS 12.4(4)T debuts a capability Cisco calls flexible packet matching, which enables deep packet inspections using pre-defined, customizable XML templates.

For more information

Read about Cisco's latest network management offerings.

Check out our exclusive interview with Cisco's top security executive.

 

See more articles written by News Editor Eric B. Parizo.

ICS will be available in October starting at $9,200, while DTM for IPS and the new version of IOS will be released in October and November, respectively, to customers with existing Cisco support contracts.

Joel Conover, principal analyst with Sterling, Va.-based research firm Current Analysis, said while the ICS is particularly interesting, what's most compelling is that Cisco is making an effort to tie together the numerous components in its stable of network security products.

"Cisco's got a lot of room to make further improvements because there are a lot of pieces," Conover said. "But ICS addresses a top-of-mind IT issue, which is patching your system in time to stop an outbreak from slamming you."

Though DTM for IPS may seem redundant when compared side-by-side with Cisco's Network Access Control products, Conover said the vendor is targeting organizations with all-Cisco networks that either want as many network security safeguards as possible, as well as those that haven't yet invested in NAC.

"Even if you have NAC, you're going to have policies in your NAC infrastructure that allow certain types of client devices into the network, and those devices can always have worms or viruses," Conover said.

Tags: Network Security Monitoring and AnalysisNetwork Security Best Practices and ProductsNetwork Access ControlVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Network Security Monitoring and Analysis
Application-specific network intrusion detection systems emerge
Anomaly-based intrusion protection configuration and installation
How can I calculate perimeter firewall throughput?
How do I find the application on my network that's dropping packets?
Integrating NAC with network security tools
Where can I find a sample security audit report? How can I run my own?
The firewall remains the network traffic cop, but its role is changing
Troubleshooting VLANs: How to monitor 802.1q tagged traffic
Poor data-loss prevention practices almost cost Intel a billion
How can I block my competitor's IP address range from my website?

Network Security Best Practices and Products
Enterprises demand next-generation firewalls with IPS, app visibility
Preventing hacker attacks with network behavior analysis IPS
Is there a way to trace my stolen laptop computer?
Integrating NAC with network security tools
Should organizations separate technical from administrative security?
What network equipment is needed to secure a small business LAN?
Ethical hacking and countermeasures: Network penetration testing intro
Are you on a domain name system (DNS) blacklist database?
Rogue access points: Preventing, detecting and handling best practices
Network security threats solved by risk management: John Pironti explains

Network Access Control
Network security risks multiply when enterprises begin outsourcing
Dynamic policy ensures faster, safer network for school district
NAC appliance vendors: Can you depend on them?
NAC integration at the endpoint
Extending NAC enforcement to network security devices
Integrating NAC with network security tools
Network access control market crushed by economy, but future is bright
Joel Snyder discusses Network Access Control Day at Interop Las Vegas
Maturing NAC market gets its first Gartner Magic Quadrant
Poor data-loss prevention practices almost cost Intel a billion

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
deep packet inspection (DPI)  (SearchNetworking.com)
FCAPS  (SearchNetworking.com)
Nessus  (SearchNetworking.com)
netstat  (SearchNetworking.com)
port mirroring  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Comprehensive network management resources, expert solutions, and professional research informing your technology decisions
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts