Encrypted Visibility Engine
The encrypted visibility engine (EVE) is used to provide more visibility into the encrypted sessions without the need to decrypt them. These insights into encrypted sessions are obtained by Cisco's open-source library that is packaged in Cisco's vulnerability database (VDB). The library fingerprints and analyzes incoming encrypted sessions and matches it against a set of known fingerprints. This database of known fingerprints is also available in the Cisco VDB.
Key capabilities
Important features of Encrypted Visibility Engine (EVE) include the following:
-
Access control policy actions on traffic using information derived from EVE
-
Vulnerability Database (VDB) integration with Cisco Secure Firewall for assigning applications to EVE-detected processes with high confidence values
-
Custom application detector creation for mapping EVE-detected processes to user-defined applications and overriding built-in process confidence values
-
Detection of the operating system type and version of clients that create Client Hello packets in encrypted traffic
-
Quick UDP Internet Connections (QUIC) traffic fingerprinting and analysis with server name display in the URL field of the Connection Events page
For custom application detector configuration, see the Configuring Custom Application Detectors and Specifying EVE Process Assignments sections in the Application Detection chapter of the Cisco Secure Firewall Management Center Device Configuration Guide.
Note |
The encrypted visibility engine feature is supported only on Cloud-Delivered Firewall Management Center-managed devices running Snort 3. This feature is not supported on Snort 2 devices and Firewall Device Manager-managed devices. |
Attention |
To use EVE on Cloud-Delivered Firewall Management Center, you must have a valid IPS license on your device. In the absence of a IPS license, the policy displays a warning and deployment is not allowed. |
Note |
|


Feedback