cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4005
Views
114
Helpful
77
Comments
Alexander Stevenson
Cisco Employee
Cisco Employee

Cisco offers several products that use machine learning to enhance network performance, security, and management.

Here are a few examples:

- Click on the product name (in blue) to learn more -

 

 

ACI

ACI.png


Cisco ACI (Application Centric Infrastructure) is a comprehensive data center networking architecture that leverages ML to:

 

- Automate Network Configurations: Streamline network setup and policy enforcement.

- Analyze Traffic Patterns: Adjust policies dynamically based on traffic and application requirements.

 

 

 

Cisco Catalyst Center

Catalyst.png

Cisco Catalyst Center, formerly known as Cisco DNA (Digital Network Architecture), is a comprehensive network management and command center, which uses ML for:

 

- Network Assurance and Analytics: ML algorithms analyze network telemetry data to provide insights, predict issues, and recommend solutions.

- Automation: Automates routine tasks and network configurations based on learned patterns and behaviors.

- Security: Uses ML for threat detection and mitigation by identifying anomalies in network traffic that may indicate security threats.



 

Cisco Secure Endpoint

Secure-Endpoint.png

Cisco Secure Endpoint, formerly AMP for Endpoints, provides visibility into endpoint activity across the organization, enabling security teams to quickly respond to incidents and mitigate potential risks. It integrates seamlessly with Cisco's broader security ecosystem, enhancing overall threat detection and response capabilities. Secure Endpoint uses ML to:

- Detect Malware: Identify and block malicious software on endpoints.

- Analyze Behavioral Patterns: Recognize unusual activity that may indicate a security threat.

- Respond to Threats: Provide automated responses to detected threats to minimize impact.

 

 

 

Cisco Secure Network Analytics

Secure-Network.png

Cisco Secure Network Analytics, formerly known as Stealthwatch, is a network security analytics and visibility solution that uses ML for:

 

- Threat Detection: Detects and responds to threats by analyzing network traffic patterns.

- Anomaly Detection: ML algorithms identify unusual behaviors that could indicate a security breach or network issue.

- Network Monitoring: Provides comprehensive visibility into network traffic and performance.

 

 

 

Cisco Secure Workload

Secure-Workload.png

Cisco Secure Workload, formerly known as Cisco Tetration, is a data center and cloud workload protection platform that uses ML for:

- Workload Behavior Analysis: Understands and monitors normal behavior of workloads to detect deviations that could indicate a security issue.

- Policy Recommendations: Provides micro-segmentation policy recommendations to improve security based on ML analysis of application dependencies.

- Compliance Monitoring: Uses ML to continuously monitor and ensure compliance with security policies.

 

 

 

Cisco Umbrella

Umbrella.png

Cisco Umbrella is a cloud-delivered security service that uses ML for:

 

- DNS Layer Security: Uses ML to analyze and predict which domains are likely to be malicious and block access to those sites.

- Secure Web Gateway: Uses ML to inspect web traffic and enforce security policies.

- Threat Intelligence: Continuously updates its threat intelligence database using ML to identify and categorize new threats.

 

 

 

Cisco XDR

XDR.png

Cisco XDR (Extended Detection and Response) enhances security operations by unifying security data, detecting sophisticated threats, and automating responses to mitigate potential risks effectively. XDR uses ML to:

- Unify Security Data: Integrate data from multiple sources to provide a comprehensive view of threats.

- Detect Advanced Threats: Identify sophisticated threats that may evade traditional security measures.

- Automate Response: Provide coordinated and automated responses to detected threats.

77 Comments
ServerWrangler
Level 1
Level 1

Are there any designs for fusing data from each of the above platforms to gather a more overall view of network behavior?

Xingxing Zhang
Spotlight
Spotlight

NICE! Be optimistic about ACI

WLMorris
Level 1
Level 1

Great article.  I would like to point out that I don't believe the products do the same thing but they all utilize machine learning and provide protection and security in ways that complement each other and can be brought together in products like XDR to provide even more dimension to the data collected.

airiosm
Level 1
Level 1

Ya llegue hasta aca jajajajaj

Alexander Stevenson
Cisco Employee
Cisco Employee

Hi @Gallifrean 

 

You asked "Does Cisco ACI work MultiCloud with Cisco HyperShiled?"

Yes, Cisco ACI can integrate with multi-cloud environments, and Cisco HyperShield enhances this by adding security and segmentation. ACI automates network management across various cloud setups, while HyperShield ensures consistent security policies and segmentation, making multi-cloud management both efficient and secure.

Alexander Stevenson
Cisco Employee
Cisco Employee

Hi @ServerWrangler ,

You asked "Are there any designs for fusing data from each of the above platforms to gather a more overall view of network behavior?"

I'm not aware of a single platform in the works which will give a complete, holistic view of the entire IT landscape, but there are already some integrations between them, e.g.

Catalyst Center integrates with Cisco ACI and other network elements to provide end-to-end visibility.

Cisco XDR collects and correlates data from Cisco’s security products, including Cisco Secure Endpoint, Umbrella, and Secure Network Analytics.

Cisco Secure Network Analytics integrates with Cisco ACI and other network components to monitor traffic and detect anomalies.

Cisco Secure Workload collects data on workload behavior and integrates with other Cisco security solutions for comprehensive protection.

Cisco Umbrella feeds data into Cisco XDR and other security platforms to enhance threat detection and response while also integrating with Cisco Secure Network Analytics for a unified view of web traffic and security.

 

@Nashers I believe this answers your question as well : )

Alexander Stevenson
Cisco Employee
Cisco Employee

@bezeddin,

You asked "Is there any code library we can use to deploy EPG/ESG using automation?"

Please see this repo on the Code Exchange: https://developer.cisco.com/codeexchange/github/repo/cisco-apjc-cloud-se/aci-basic-day2/

 

Alexander Stevenson
Cisco Employee
Cisco Employee

@Mark Healey,

You asked "Are there any plans to integrate Splunk into Cisco Secure Network Analytics?"

Please see the following: 

Cisco Secure Network Analytics (Stealthwatch) App for Splunk Enterprise | Splunkbase

Cisco Endpoint Security Analytics Built on Splunk (CESA) At a Glance

Alexander Stevenson
Cisco Employee
Cisco Employee

Hi @devnetdexter ,

You asked "which of these platforms have you seen the most automation created with?"

From a real-world use-case standpoint, my view of automation is often filtered through Cisco Code Exchange repos. Here is the breakdown, by product, of the 348 current repos labeled with "With Automation Use Case"

 

AlexanderStevenson_0-1723643820821.png

https://developer.cisco.com/codeexchange/search/?complexity=usecase

That may not reflect real-world use-case statistics, though, only what people have submitted to Code Exchange.

My research indicates that Cisco DNA Center, Cisco ACI, and Cisco Secure Network Analytics, with their extensive features and widespread use, are the top choices for automation. They excel in automating network setup, data center management, and security analytics, making them ideal for organizations aiming to improve and simplify their network and security operations.

 

 

Alexander Stevenson
Cisco Employee
Cisco Employee

Hi @Paulo Thame,

You asked "Cisco Secure Network Analytics need's Cisco Secure Endpoint or Workload to run ?"

No, Cisco Secure Network Analytics (formerly Stealthwatch) does not require Cisco Secure Endpoint or Cisco Secure Workload to function. However, integrating these solutions can enhance its effectiveness.

Alexander Stevenson
Cisco Employee
Cisco Employee

@fracjackmac 

The Network Assurance and Analytics engine within Cisco Catalyst Center does use OpenTelemetry to gather data. OpenTelemetry provides a standardized way to collect and correlate telemetry data from various sources, allowing Cisco Catalyst Center to offer detailed insights into network performance and health.

To leverage the benefits of Network Assurance and Analytics within Cisco Catalyst Center, you typically need a Cisco DNA Advantage or Cisco DNA Premier subscription. These subscription tiers include access to advanced network analytics and assurance features, such as:

- Network performance monitoring
- Automated troubleshooting
- Policy-based network management

The Cisco DNA Advantage and Premier tiers provide enhanced capabilities beyond the basic features included with Cisco DNA Essentials.

Complete network security threat detection and prevention. 

milan.petrovic
Level 1
Level 1

Awesome list!

Sam-Barnes
Level 1
Level 1

How many years are we away from ML being able to significantly reduce network infrastructure staff or are we already there?

Jacques1
Level 1
Level 1

Thanks for sharing

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: