35
© 2016 Cisco and/or its affiliates. All rights reserved. 1 Cisco Connect Accelerating Incident Response in organizations of Any Size Sean Earhard Advanced Threat Solution Specialist October, 2017 Jean-Paul Kerouanton Advanced Threat Solution CSE

Cisco Connect Toronto 2017 - Accelerating Incident Response in Organizations of Any Size - final

Embed Size (px)

Citation preview

Page 1: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

© 2016 Cisco and/or its affiliates. All rights reserved. 1

CiscoConnect

Accelerating Incident Response in organizationsof Any SizeSean EarhardAdvanced Threat Solution Specialist

October, 2017

Jean-Paul KerouantonAdvanced Threat Solution CSE

Page 2: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

2© 2016 Cisco and/or its affiliates. All rights reserved.

Sean EarhardAdvanced Threat Solution Specialist

(aka “Today’s Victim)

Jean-Paul KerouantonAdvanced Threat Solution

Specialist

(aka “Our hero”)

Jean-Paul KerouantonAdvanced Threat Solution

Specialist

(aka “The attacker”)

Page 3: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

3© 2016 Cisco and/or its affiliates. All rights reserved.

AM

Page 4: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

4© 2016 Cisco and/or its affiliates. All rights reserved.

chrome.exe

a273.exe

winword.exe

C&C Connection

Page 5: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

5© 2016 Cisco and/or its affiliates. All rights reserved.

How does your current security infrastructure help you respond to incidents?

Page 6: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

6© 2016 Cisco and/or its affiliates. All rights reserved.

ANTIVIRUS

ANTIVIRUS

Vendors pumping out update after

update after update after

update…

Firewall

Web filter

Email filter

ANTIVIRUS SERVER

consoles pumping out alert after alert after alert after

alert…

! ! ! !

Page 7: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

7© 2016 Cisco and/or its affiliates. All rights reserved.

Security tools

before an incident

Security tools during an incident

Page 8: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

© 2016 Cisco and/or its affiliates. All rights reserved. 8

“… organizations should be aware that no matter how much effort they put into malware incident prevention, incidents will still occur…”

Guide to Malware Incident Prevention and Handling for

Desktops and Laptops

Page 9: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

© 2016 Cisco and/or its affiliates. All rights reserved. 9

GARTNER

“Organizations should move their investments from 90% prevention and 10% detection and response to a 60/40 split”

Peter Sondergaard,Senior VP and Global Head of

Research

Page 10: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

10© 2016 Cisco and/or its affiliates. All rights reserved.

Typical Incident Response workflow

Page 11: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

11© 2016 Cisco and/or its affiliates. All rights reserved.

INVESTIGATEINCIDENTS RECOVER IMPROVE

DEFENSE

REDUCE THE ATTACK

SURFACE

ALERTS

SECURITY ARCHITECTURE

BLOCK

Page 12: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

12© 2016 Cisco and/or its affiliates. All rights reserved.

Where does Incident Response begin – for you?

Page 13: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

© 2016 Cisco and/or its affiliates. All rights reserved. 13

Which of these scenarios is your organizations “this is an incident” starting point?

Page 14: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

© 2016 Cisco and/or its affiliates. All rights reserved. 14

chrome.exe

jp2launcher.exe

java.exe

Blocked Payload

chrome.exe

a273.exe

winword.exe

C&C Connection

When?

How?

What?

Business Impacting Event

Page 15: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

15© 2016 Cisco and/or its affiliates. All rights reserved.

The problem is a lack of translation between raw events and meaningful intelligence

Page 16: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

16© 2016 Cisco and/or its affiliates. All rights reserved.

Wilson-CarterData Source

ApproachQuotient

1The distance

from the sourceof the data

Page 17: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

17© 2016 Cisco and/or its affiliates. All rights reserved.

Cisco’s solution to accelerating incident response

Page 18: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

© 2016 Cisco and/or its affiliates. All rights reserved. 18

INCIDENT RESPONSE STARTS HERE

chrome.exe

jp2launcher.exe

java.exe

Blocked Payload

chrome.exe

a273.exe

winword.exe

C&C Connection

When?

How?

What?

Business Impacting Event

PROTECT

ACCELERATE

AUTOMATE

AUTOMATE

HUNT

RESPOND

Page 19: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

19© 2016 Cisco and/or its affiliates. All rights reserved.

Cisco’s solution to accelerating incident response

Page 20: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

20© 2016 Cisco and/or its affiliates. All rights reserved.

PROTECT RESPONDHUNT

INTEGRATE

SIMPLIFY

AUTOMATE

ACCELERATE

TRAJECTORY: 30+ DAY RECORDED HISTORY

CONTINUOUS ANALYSIS OF THAT HISTORY

RETROSPECTIVE DETECTION: IN THAT HISTORY

VISIBILITY & CONTROL: END-TO-END

Page 21: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

21© 2016 Cisco and/or its affiliates. All rights reserved.

What we will show today

Page 22: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

22© 2016 Cisco and/or its affiliates. All rights reserved.

Page 23: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

23© 2016 Cisco and/or its affiliates. All rights reserved.

EmailSecurity

Cisco ISE

ThreatGridUmbrella

SIG

Cisco ISE

NextGenFirewall

EmailSecurity

AMP forEndpoints

CISCOTALOS

AMP

AMP

AMP

AMP

Cisco ISE

UmbrellaInvestigate

AMP AMP

Page 24: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

24© 2016 Cisco and/or its affiliates. All rights reserved.

Cisco ISENextGenFirewall

Cisco ISE

EmailSecurity

AMP forEndpoints

Cisco ISE

Cisco ISE

ThreatGridUmbrella

SIG

Cisco ISE

NextGenFirewall

EmailSecurity

AMP forEndpoints

CISCOTALOS

AMP

AMP

AMP

AMP

UmbrellaInvestigate

AMP AMP

30+ day recorded history = accelerated IR

Continuous analysis of that recorded history =

automated hunting

Page 25: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

25© 2016 Cisco and/or its affiliates. All rights reserved.

EMAIL

WEB

FIREWALL

MERAKI

UMBRELLA

THREATGRID

Blocking

AMP

AMP

COGNITIVETHREATANALYTICS

Page 26: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

26© 2016 Cisco and/or its affiliates. All rights reserved.

Today’s IR scenarios

Page 27: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

27© 2016 Cisco and/or its affiliates. All rights reserved.

Want to try it out yourself?

Page 28: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

28© 2016 Cisco and/or its affiliates. All rights reserved.

Cisco ISENextGenFirewall

Cisco ISE

EmailSecurity

AMP forEndpoints

Cisco ISE

Cisco ISE

ThreatGridUmbrella

SIG

Cisco ISE

NextGenFirewall

EmailSecurity

AMP forEndpoints

CISCOTALOS

AMP

AMP

AMP

AMP

UmbrellaInvestigate

AMP AMP

30+ day recorded history = accelerated IR

Continuous analysis of that recorded history =

automated hunting

Page 29: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

29© 2016 Cisco and/or its affiliates. All rights reserved.

Page 30: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

30© 2016 Cisco and/or its affiliates. All rights reserved.

AMP for EmailPROTECT

• File Reputation – up to the millisecond • File Behavioral analysis – cloud or appliance

HUNT

• Continuous Analysis – by Cisco TALOS• Retrospective Detection – everywhere

RESPOND

• Message tracking – accelerate IR

Page 31: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

31© 2016 Cisco and/or its affiliates. All rights reserved.

AMP ThreatGridPROTECT

• Behavioral Analysis• Integrations with non-Cisco security tools

HUNT

• Confirm threats – Glovebox• Generate Threat Intel – From local to global

RESPOND

• Generate Threat Intel – From local to global

Page 32: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

32© 2016 Cisco and/or its affiliates. All rights reserved.

AMP for NetworkPROTECT

• File Analysis – up to the millisecond• Machine Learning Engine – Spero• File Behavioral analysis – cloud or appliance

HUNT

• Continuous Analysis – by Cisco TALOS• Retrospective Detection – everywhere

RESPOND

• File Trajectory – Interactive search

Page 33: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

33© 2016 Cisco and/or its affiliates. All rights reserved.

AMP for EndpointPROTECT

• Multi-Engine analysisHUNT

• Low Prevalence Analysis• Continuous Analysis – by Cisco TALOS

• Retrospective Detection – everywhereRESPOND

• Full history of endpoint behavior (30 days)• Elastic Search• IoCs

Page 34: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

34© 2016 Cisco and/or its affiliates. All rights reserved.

Page 35: Cisco Connect Toronto  2017 - Accelerating Incident Response in Organizations of Any Size - final

35© 2016 Cisco and/or its affiliates. All rights reserved.