SECURING THE INTELLIGENT INFORMATION NETWORK - Ijma3

Transcription

SECURING THE INTELLIGENTINFORMATION NETWORKFadi MoubarakRegional Sales Manager, Levant AreaFebruary 2006 2004 Cisco Systems, Inc. All rights reserved.1

Security Vision:Comprehensive Architecture (NAC)Firewalls andIntrusionDetectionDDoSMitigationEncrypted LAN / arantine VLAN(Remediation)Network InfectionContainmentCisco Trust AgentNetwork AdmissionControl“5–7 Years to Drive Architecture” 2004 Cisco Systems, Inc. All rights reserved.2

Adaptive Threat Defense (ATD)Technology ConvergenceIncreases Effectiveness and Security (L 4-7) NETWORKCONTROLIP FabricServicesVirtualized Fabric Smarter SecurityAdaptiveThreat DefenseOperational EfficiencyTrafficSecurity (L 2-3) 2004 Cisco Systems, Inc. All rights reserved.3

Adaptive Threat Defense in ActionProducts, Services and Architecture ExampleAccess Control,Packet InspectionApplication Intelligence, ContentInspection, Virus MitigationIdentity, Virtualization, QoSSegmentation, Traffic VisibilityFirewall ServicesIPS and NW-AV ServicesNetwork IntelligenceAppApp Inspection,Inspection, UseUseEnforcement,WebControlEnforcement, Web ControlMalware/ContentMalware/Content Defense,Defense,AnomalyDetectionAnomaly DetectionTraffic/AdmissionTraffic/Admission Control,Control,ProactiveResponseProactive ResponseApplication SecurityAnti-X DefensesContainmentContainment // ControlControlCatalystCSACisco RouterCisco DDoSVPNCisco RouterVPNVPN AccessAccessCatalystQuarantine VLANNACCSA 2004 Cisco Systems, Inc. All rights reserved.PIXIdentity-BasedNetworkingCisco IPSCSA4

Implementing Adaptive Threat DefenseProduct AnnouncementsProductsIPS 5.0Application Security Multi-Vector ThreatIdentificationVPN 3000 SSL VPN Tunnel ClientConcentrator 4.7 Fully Clientless CitrixAnti-X Malware, virus,worm mitigationContainment and Control Cisco Secure Desktop Cisco NAC Accurate PreventionTechnologies In-Line IPSIOS 12.3(14)T Application Inspection/ Enhanced In-Line IPSControl for IOS Firewall Network FoundationProtection, Virtual Firewall,IPSec Virtual InterfacePIX 7.0 Application Inspection/Control for Firewall Enhanced VoIP Security Virtual firewall, QoS,transparent firewall, IPv6Cisco SecurityAgent 4.5 Spyware mitigationCatalyst DDoSModules Anomaly Guard Module Traffic AnomalyDetector Context-based policies System inventory/auditingCisco MARS Event correlationfor proactive responseCisco SecurityAuditor Network-wide securitypolicy auditing 2004 Cisco Systems, Inc. All rights reserved.5

Implementing Adaptive Threat DefenseProduct AnnouncementsProductsIPS 5.0Application Security Multi-Vector ThreatIdentificationVPN 3000 SSL VPN Tunnel ClientConcentrator 4.7 Fully Clientless CitrixAnti-X Malware, virus,worm mitigationContainment and Control Cisco Secure Desktop Cisco NACAppliancesIOS 12.3(14)T Application Inspection/ Enhanced In-Line IPSControl for IOS FirewallPIX 7.0 Application Inspection/Control for Firewall Enhanced VoIP SecurityCisco SecurityAgent 4.5Catalyst DDoSModules Accurate PreventionTechnologies In-Line IPS Network FoundationProtection, Virtual Firewall,IPSec Virtual InterfaceRouters / Switches Virtual firewall, QoS,transparent firewall, IPv6 Spyware mitigationSoftware Anomaly Guard Module Context-based policies System inventory/auditing Traffic AnomalyDetectorCisco MARS Event correlationfor proactive responseCisco SecurityAuditor Network-wide securitypolicy auditing 2004 Cisco Systems, Inc. All rights reserved.6

Value of Integrated Security SystemSecurity is no longer an option It’s a necessitySecurity as an OptionSecurity as INTEGRAL of a SystemSecurity is an add-onSecurity is built-inChallenging integrationIntelligent collaborationNot cost-effectiveAppropriate securityCannot focus on core priorityDirect focus on core priority 2004 Cisco Systems, Inc. All rights reserved.7

2004 Cisco Systems, Inc. All rights reserved.8

Cisco Security Agent 4.5 IOS 12.3(14)T Catalyst DDoS Modules Cisco MARS Application Inspection/ Control for IOS Firewall Application Inspection/ Control for IOS Firewall Enhanced In-Line IPSEnhanced In-Line IPS Network Foundation Protection, Virtual Firewall, IPSec Virtual Interface Network Foundation Protection, Virtual .