Intrusion Prevention System Modules For Integrated Services Routers
Intrusion Prevention System Modules For Integrated Services Routers
System Modules
for Integrated
Services Routers
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 1
Organizational Impacts
of Security Threats
Distributed Denial
Disruption impacts productivity
of Service
Virus out-break CIO Problem
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 2
Reducing the Grey:
U
Uncertainty
t i t Equals
E l Ri
Risk
k and
dCCostt
NAC
GOOD: Allow Traffic Shaping
IPS GOOD: Allow
RELEVANT:
Pass and Log
Monitoring
g and Relevant: Pass and Log
Correlation Suspicious: Pass and Alarm
SUSPICIOUS:
Pass and Alarm
IPS,
Anti-X, DDoS, BAD: Block
BAD: Block Firewall
Self-
Inefficient; Efficient Operations;
D f di
Defending
Highly Manual Network Effective Security
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 3
Cisco Intrusion Prevention Strategy
C
Comprehensive
h i ThThreatt P
Protection
t ti ffor the
th SDN
Cisco IPS 4200 Series
Cisco ASA 5500 Cisco Cisco
Cisco Security Cisco Integrated Adaptive Security CiscoCatalyst® Security Security
Agent Services Routers Appliance Services Modules MARS Manager
Internet Intranet
The most diverse line of IPS Modular inspection engines: On-box and network-wide
sensors: the right tool for respond rapidly with correlation to provide greater
the right job, anywhere in minimal downtime accuracy and confidence
the network Behavioral anomaly Endpoint and network
IPS integrated into the detection: protect against sensors sharing live network
fabric of the network zero-day attacks information
B
Built
ilt on Cisco
Ci security
it and
d D
Dynamic i risk-based
i kb d threat
th t R
Reduced
d d operational
ti l costs
t
network intelligence rating: adapt threats policy with a common, solution-
in real time based management interface
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 4
Intrusion Prevention System (IPS)
Ad
Advanced
d IIntegration
t ti M Module
d l and
dNNetwork
t kMModule
d l
Incorporates
Accelerated Threat ControlNetwork ® ISR
Admission
for Cisco
NEW
Enables inline Control (NAC) appliance
and promiscuous Intrusion server
Enforces security policies,
Prevention (IPS)
NME-IPS-K9
Cisco 2811, 2821, S (CIPS
Scans
Runs same software ffor latest
l 6.1)
t t and
anti-virus
ti enables
i software
ft
2851, 3800
Prevents
same features as Cisco IPSunauthorized
4200 access and
spread of viruses on the network
AIM IPS K9
AIM-IPS-K9 Performance improvement
p byy hardware
S
Supports
t wired,
i d wireless
i l and
d guestt NAC
Cisco 1841, 2800, 3800 acceleration; dedicated CPU and DRAM
to offload host Integrated
CPU into Cisco ISRs
Cisco IOS® Advanced Security AIM—Up to 45 Mbps
Provides size and scale ideal for
or Above remote offices (<100 users)
NME—Up to 75 Mbps
AIM—12.4(15)XY, 12.4(20)T Works with NAC appliances at
NME—12.4(20)YA Device management through Cisco IPS
headquarters in a network system
Device Manager
g ((IDM),), Cisco Configuration
g
Benefits
Professional (CCP); of router integration
network-wide management
Systems
through Cisco Security Integration
Manager (CSM)
Supported
pp y IPS Lower
by gOperating
Manager p Costs
Express ((IME)) and
AIM-IPS CS-MARS on event monitoring and correlation
NME-IPS
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 5
Cisco IPS Product Portfolio
IPS 4200 Series
Dedicated appliances for IPS 4255
high performance, data IPS 4270
IPS 4240
center, and focused IPS 4260
function environments
Performance
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 6
Branch Needs for Self
Self-Defending
Defending Network
Trends Security
PCI Compliance (Retail); HIPAA (Healthcare); Sarbanes- Moves protection to the
Oxley/GLBA (Finance) edge before threats enter
corporate or SP network
Prone to attacks from split tunnels
tunnels, contaminated laptops
and rogue APs Helps to manage
unmanaged devices
Protect Servers
Threat at Branch
Servers
192.168.3.14-16/24
Threat
Internet Corporate
Office
ISR with IPS AIM
or IPS NME Threat
Wireless Guests
192.168.2.x/24
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 7
Benefits of Integrated IPS on ISR
42xx IPS Sensor Corporate Office
SMB Network
MSSP CE Router
AIM IPS
CS-MARS Cisco
Internet/ Security
ISR Manager
SP Network
Full feature, high performance threat protection in the Branch or SMB network
Requires no additional footprint, cabling, and power requirements
Systems integration with data,
data security and voice features on ISR
Supports any routed WAN link—transport agnostic: T1/E1, T3/E3, Ethernet, xDSL,
MPLS, 3G WWAN
P
Provides
id d defense-in-depth
f i d th tto th
the perimeter
i t off the
th network:
t k ICSA-certified
ICSA tifi d Cisco
Ci IOS
Firewall, IPSec and SSL VPN, NAC, URL Filtering
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 8
Securing Cisco Unified Communication
Manager and Phones with Cisco IPS
In-line inspection of voice and video traffic
Protect infrastructure that voice runs on:
Protect Call Management infrastructure from attack
Real-time anomaly detection for day-zero threats
Drop calls that are coming from IP addresses identified
on the Cisco Security Agent “watch list”
Legitimate
Traffic
Protection against:
Application misuse
Firewall IPS DoS/hacking
Known attacks
Zero-day attacks
Viruses/worms, spyware
infecting traffic
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 9
Cisco High-Performance
IPS Applications:
Wireless Intrusion Prevention
Protect the enterprise from wireless users
Cisco High-Performance IPS
High-performance IPS helps protect at
WLAN speeds for guest users’ and employees’
infected computers
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 10
Cisco IPS Manager Express (IME) NEW
All-in-One IPS Management Application
for up to Five IPS SensorsAt-A-Glance
At A Glance Dashboard
Startup Wizard: At-a-Glance Dashboard
Get up and running in
just minutes
Dashboard:
Put needed information
at your fingertips
Configuration:
Save time with intuitive
interface
Reporting:
Create and share security
and compliance reports
Monitoring:
See what’s happening with
real time and historical
real-time
security events
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 11
Cisco Security Manager
I t
Integrated
t d Security
S it Configuration
C fi ti Management
M t
Support for PIX®, Support for PIX, Support for IPS Unified security
ASA, FWSM, and ASA, VPNSM, VPN Sensors, modules management for
Cisco IOS Routers SPA, and Cisco and Cisco IOS IPS Cisco devices
Rich FW rule IOS Routers Automatic policy-
policy supporting FW,
definition: shared Support for wide based IPS Sensor VPN, and IPS
objects, rule array of VPN software and Efficiently manage
grouping, and technologies such signature updates up to 5000 devices
inheritance as DMVPN, Easy Signature Update per server
Powerful analysis VPN, and SSL VPN Wizard allowing Multiple views for
tools: conflict VPN Wizard easy review/editing task optimization
detection rule
detection, for Three-Step
Three Step prior to deployment D i Vi
Device View
combiner, hit Point-and-Click Policy View
counts, … VPN Creation Topology View
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 12
Cisco Services for IPS
R id Si
Rapid Signature
t U
Updates
d t ffor E
Emerging
i ThThreats
t
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 13
Cisco Security IntelliShield Alert
Manager Service
Now Includes IPS Signature-to-Threat Correlation
Complete vulnerability and threat
information in a single database
Notification of only those vulnerabilities
relevant to a p
pre-defined infrastructure
Actionable alerts in a standardized format
based on user-customized profiles
Each vulnerability or threat is analyzed and
validated by security analysts
Vulnerability and threat information is
vendor-neutral
vendor neutral and objectively graded
Comprehensive library of over 10,000
threats and vulnerabilities
B
Built-in
ilt i workflow
kfl allows
ll easy managementt
of tasks and remediation efforts
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 14
Cisco License Manager
Automates license management for IPS AIM
AIM, IPS NME and more
Increased productivity
Rapidly roll out new services—500 licenses deployed in two minutes
Scales to 30,000 devices
Reduced complexity
Automated licensing workflows
License reports aid in audit compliance
Investment protection
Full-functionality Java and Perl Software Development Kits (SDK)
to integrate with existing applications
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 15
C97-494048-00 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 16