A Discussion on Cisco Encrypted Traffic Analytics (ETA) with the Experts
Kevin Klous, Technical Leader, Cisco
David White Jr., Principal Engineer, Cisco Matt Robertson, Principal Technical Marketing Engineer, Cisco Darrin Miller. Distinguished Technical Marketing Engineer, Cisco
In the Cisco Live US 2018 speaker room: The podcast team steals a few minutes from Cisco ETA and Stealthwatch experts Matt Robertson and Darrin Miller to discuss the basics of the technology and how it is helping organizations in detecting malicious content in network traffic as it increasingly goes dark (becomes encrypted).
Subscribe to the Podcast in iTunes by clicking the image below:
Quotes from the Pros:
"The reality is that the networks are encrypted and threats are actually happening in those environments. We need to be able to detect threats inside of encrypted traffic. It's not really scalable to do inline decryption on everything. That's what the ETA solution was designed to do--[answer] how do we detect threats without decrypting traffic?" - Matt Robertson, Principal Technical Marketing Engineer, Cisco
"Every security architect I deal with is always saying, 'How do I turn something into an actionable event?'. That is what I really think ETA inside of Stealthwatch does...it allows us to turn all this data into actionable events." - Darrin Miller, Distinguished Technical Marketing Engineer, Cisco
How ETA works: 3 Major Components
1. Netflow Enhancements to carry additional markers to aid in malicious traffic detection 2. Cisco Stealthwatch Enterprise - Collector, aggregator, and analyzer of network telemetry (Netflow data) 3. Cloud-hosted analytics engine. Multi-layer machine learning engine that leverages the global risk map and correlates with your organization and how it interacts with those risks.
I have a network with Cisco components. I would like to manage them only over IPSEC (I am working with asymmetric model - x509 certificates with PKI).So I would like that only computers which has the correct private key could manage the cisco device...
With reference to this advisory : https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-vman-cmd-injectionIt says "A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allo...
Hi, Can someone please let me know if there are any known issue with the upgrade from 9.8(2) to 9.12(2) on ASA5525. I have asa9-12-2-smp-k8.bin downloaded but cant see any known issues,since this is live in production,we need to be aware of any known issu...
Got a question regarding VMware machine hardware 'upgrade'.
Is it also safe to change the hardware version on an existing ISE server to something newer than machine hardware version 9?
VMware Virtual Hardware Version/Hy...