A Discussion on Cisco Encrypted Traffic Analytics (ETA) with the Experts
Kevin Klous, Technical Leader, Cisco
David White Jr., Principal Engineer, Cisco Matt Robertson, Principal Technical Marketing Engineer, Cisco Darrin Miller. Distinguished Technical Marketing Engineer, Cisco
In the Cisco Live US 2018 speaker room: The podcast team steals a few minutes from Cisco ETA and Stealthwatch experts Matt Robertson and Darrin Miller to discuss the basics of the technology and how it is helping organizations in detecting malicious content in network traffic as it increasingly goes dark (becomes encrypted).
Subscribe to the Podcast in iTunes by clicking the image below:
Quotes from the Pros:
"The reality is that the networks are encrypted and threats are actually happening in those environments. We need to be able to detect threats inside of encrypted traffic. It's not really scalable to do inline decryption on everything. That's what the ETA solution was designed to do--[answer] how do we detect threats without decrypting traffic?" - Matt Robertson, Principal Technical Marketing Engineer, Cisco
"Every security architect I deal with is always saying, 'How do I turn something into an actionable event?'. That is what I really think ETA inside of Stealthwatch does...it allows us to turn all this data into actionable events." - Darrin Miller, Distinguished Technical Marketing Engineer, Cisco
How ETA works: 3 Major Components
1. Netflow Enhancements to carry additional markers to aid in malicious traffic detection 2. Cisco Stealthwatch Enterprise - Collector, aggregator, and analyzer of network telemetry (Netflow data) 3. Cloud-hosted analytics engine. Multi-layer machine learning engine that leverages the global risk map and correlates with your organization and how it interacts with those risks.
Hi all,I have been experienced S2S VPN disconnet every period of time on ASA 5525-X, software version is 9.5(2). VPN configuration are ikev2, AES-256, SHA-256Group 2, IKE-phase1 renegotiation 1440 mins, IKE-phase2 renegotiation 3 hours. Please be adv...
The Cisco 2020 CISO Benchmark Report provides valuable takeaways and data on the most pressing topics: the impact of vendor consolidation, cybersecurity fatigue, outsourcing, top causes of downtime, the most impactful threats, and more. The repo...
Hi, Has anyone run into the "Channel down" issue when updating the identity certificate on the Stealthwatch SMCv and SFCv. I'm doing a POC for a client and every time I go an update the identity cert the SMC says "it could save the configuration" and...
I have received the notification to upgrade our ESAV C100V from ASync OS 12.5.0-66 to ASync OS 13.x.x and up. However, when I check to see if the C100V is compatible I do not see any reference for the C100V. I don't want to start any upgrade and then run ...