Cisco Multicloud Defense User Guide

PDF

Cisco Multicloud Defense User Guide

Security Insights

Want to summarize with AI?

Log in

Connect a cloud account, enable inventory, and view Cisco Multicloud Defense security insight findings for discovered AWS, Azure, and GCP assets.


Insights are a rules-based evaluations of assets discovered in AWS, Azure and GCP that are presented asfindings. Insights can be used without deploying Multicloud Defense Gateways since they operate on the periodic and real-time inventory monitoring accommodated by the Multicloud Defense Controller.

Procedure

1.

In the Multicloud Defense Controller interface, click Add Account. As an alternative, we strongly recommend using the Easy Setup wizard to connect to an account. Go through the steps to connect the account.

2.

Once the account is connected and onboarded, Enable Inventory.

3.

Navigate to Inventory > Summary. This page displays a summary view of all discovered assets and the Insight Findings.


Types of Security Insights

Security insights refer to the analysis and understanding of data related to the security of a system, such as a cloud-based gateway. These insights are gathered from monitoring and analyzing network traffic, user behavior, threat intelligence, and other security-related data. By leveraging the following apsects of security insights, a cloud-based gateway can enhance its overall security, ensuring data protection, reliability, and trustworthiness for users and clients.

  • Threat Detection helps identify potential threats and vulnerabilities in real-time. By analyzing patterns and anomalies, they can alert administrators to suspicious activities or breaches.

  • Compliance within your insights assists witht compliance maintenance for industry standards and regulations by providing detailed reports and audits of security measures and incidents.

  • Incident Responses enable quicker response times to security incidents by providing detailed information about the nature and scope of the threat, helping to minimize damage.

  • Resource Optimization provides a better understanding the types of threats most likely to affect their systems, organizations can allocate resources more effectively, focusing on the most significant risks.

Read through the following types of security insights to understand what the dashboard can do.


Security Groups

Customers often struggle with the proliferation of Security Groups. Security groups are often shared amongst resources that could present risk. Changes made to a security group intended for a specific resource could impact a larger group of resources.

Security groups provides a list of all security group, their details and the set of resources utilizing the security group. The Is Inbound Public and Is Outbound Public fields indicate security groups configured with 0.0.0.0/0.

In the search window, define the search criteria based on fields and their values with the option to create a rule based on the search criteria.

Rules

Rules provide a view of security groups based on their configured Inbound and outbound rules.

Ports

Ports provide a view of security groups based on their configured inbound and outbound ports.


Application Security Groups

Application Security Groups are an Azure construct similar to the AWS security group. Azure application security groups have a member of the security group that contains that system and its interfaces. It has both membership and security controls. As a result, Multicloud Defense uses this membership construct to build dynamic policies. Create and use an application security group within an Azure environment, Multicloud Defense recognizes the change and adapts the policy to incorporate it.

For more information about Azure's application security groups and how they operate, see the Microsoft Azure documentation.


Network ACL

Network access control list (ACL) provides a list of all network ACLs and their details. The Is Inbound Public and Is Outbound Public fields indicate network ACLs configured with 0.0.0.0/0.

Rules

Rules provide a view of network ACLs based on their configured inbound and outbound rules.


Subnets

Subnets provides a list of all subnets and their details. The Is Public field indicate subnets that are publicly accessible based on whether auto-assign public IP is enabled.


Route Tables

Route Tables provides a list of all route tables and their details. The Is Inbound Public and Is Outbound Public fields indicate route tables that are configured to provide default access the internet.


Network Interfaces

Network Interfaces provides a list of all network interfaces and their details. The Is Inbound Public and Is Outbound Public fields indicate network interfaces that are configured with a security group that is open (0.0.0.0/0), or route tables that allows default access to the internet.


VPCs\VNets

VPCs/VNets provides a list of all VPCs/VNets and their details.


Applications

Applications provides a list of all deployed application load balancers and their details. The Secured field identifies whether a Multicloud Defense Gateway and security policy is applied to secure the application and offers an ability to invoke a workflow to protect the application.


Load Balancers

Load Balancers generally improve application performance by increasing response time and reducing network latency. They perform several critical tasks such as distributing the load evenly between servers to improve application performance and redirecting client requests to a geographically closer server to reduce latency.

Load Balancers and Supported Cloud Service Providers

At this time you can configure load balancers for an AWS gateway.

When you configure a load balancer in Multicloud Defense, the Public field shows whether resource is an internet-facing load balancer. The CSP WAF Enabled shows whether a CSP WAF has been enabled for the application load balancer.


Instances

Instances provides a list of all instances along with summary information on the number of security groups and interfaces that are assigned and configured for the resource. The Is Inbound Public and Is Outbound Public fields indicate instances that have network interfaces that are configured with a security group that is open (0.0.0.0/0), or route tables that allows default access to the internet.


Tags

Tags in a cloud-based environment are metadata labels that can be attached to resources such as virtual machines, storage accounts, and network interfaces. When appropriately utilized, tags can help categorize and organize resources based on various attributes like environment, department, or application. Likewise, they can also be used to enforce security policies or assist in defining and managing access controls. By tagging resources, administrators can set permissions that align with the roles and responsibilities associated with those tags. Within the Multicloud Defense Controller, tags provide a list of all VPCs/VNets, subnets, security groups, instances and load balancers that are configured with tags.


Certificates

Certificates provides a list of all certificates available in AWS certificates manager along with summary information on issuer, domain name and expiry date.


Topology

This tab shows a high-level map view by region of cloud assets in cloud accounts. You can finetune the visuals with the Filter bar at the top of the screen. From here you can determine what cloud service provider accounts you want to pull data drom, which region of the world, specific VNet or VPCs, instances, and a period of time in history.

The Global View of the world map allows you to scroll in for a closer look at specific regions that are dictated by the Filter bar mentioned above. Immediately to the left of the map you can dictate which types of traffic and inventory you want to view. Check and uncheck the boxes appropriately for what you want to see .


Insights

Insights are a rules-based evaluations of assets discovered in AWS, Azure and GCP that are presented as findings.

Rules

Rules are a set of evaluations to identify findings in discovered assets. Multicloud Defense provides a set of default rules. New rules can be created by selecting an inventory category (e.g., security groups, applications, load balancers, tags, etc.), defining a search criteria, selecting Add Rule and specifying additional required information. Navigate to Insights > Rules to view the new rule. From there you can operate against existing and newly discovered assets.

Findings

Findings is a list of discovered assets that match the defined set of rules.