Cisco Cyber Vision New UI Administration Guide, Release 5.6.0

PDF

Cisco Cyber Vision New UI Administration Guide, Release 5.6.0

Communication maps

Want to summarize with AI?

Log in

Describes how communication maps visually represent communication flows among industrial assets to help teams quickly investigate and assess risks based on abnormal flows, observed protocols, and asset relationships.


A communication map is a network visualization tool that

  • Displays communication patterns at the asset-interface level.

  • Organizes map data by asset groups and enables filtering of the displayed data.

  • Supports investigation with details about asset interfaces, asset groups, and intra-group communications, including observed protocols, data exchange volumes, and source and destination asset-interface information.

This functionality enables operational technology (OT) and information technology (IT) teams to quickly visualize and understand the communication context of industrial assets. It provides a clear visual reference to abnormal communications and potential risks.

Feature history table

Feature

Release Information

Feature Description

Communications page enhancement

Release 5.6.x

The Communications page organizes map data by asset groups and displays communications at the asset-interface level. Asset groups can be network groups or custom groups. Functional groups are no longer supported.

You can view details for asset interfaces, groups, and communications within a group. The control panel provides filter options and display settings.

External IP country mapping

Release 5.5.x

You can view the countries of external IP addresses your asset connects with. Use this map to identify geographical locations and quickly decide which communications to investigate, improving your network insight and security.

ASN and ASN organization insight for external communications

Release 5.5.x

You can view ASN (Autonomous System Number) and ASN Organization information for external communications. Use this information to identify traffic sources and network owners so that you can quickly detect suspicious communications and reduce investigation time.

Communication maps and their filter enhancements

Release 5.4.x

Easily spot communications between assets, including those outside your active view. Communication maps highlight assets outside your active view filter with dotted lines.

External communications visibility

Release 5.4.x

View all communications between a selected asset and external entities. You can identify unexpected external communications that may expose your organization to attacks.

Group by network functionality in communications

Release 5.4.x

The communication map displays all communications between network groups and simplifies network interaction analysis.

See functional group–centric views of the communication map

Release 5.3.x

The communications map displays the communication activity between the configured functional groups. The communication links between groups are not actionable.

Using asset vendor names and icons

Release 5.3.x

In the New UI, communication maps include vendor icons that make asset identification easier.


Apply active view filters to the communication map

Use the common active-view filtering procedure to filter the Dashboard, Alerts, Assets, Vulnerabilities, and Communications pages. For that procedure, refer to Filter views in Cyber Vision New UI.

The active view lets you filter assets and communication links in the communication map so you can focus on specific groups. Any asset or communication outside the applied filters is shown as a dotted line, indicating it is excluded from your current view.

Follow these steps to apply active view filters to the communication map.

Procedure

  1. From the main menu, select Communications.

  2. On the Communications page, click the Edit link in the upper-right corner.

  3. Under Available filters, configure the filters you need:

    1. Click the Select link next to Networks, Asset types, or Vendors .
    2. Choose the values to include for each filter.
    3. Click Apply.
  4. Click Apply filters to update the map.

The selected filter tags appear at the top of the Communications page. The map and control panel refresh to show the groups, assets, communications, and protocols associated with the active filters.


Communication map control panel

Use the control panel on the map to view and analyze network communications and subnet details for each node on the map.

Control panel views

You can access the communication map from the Communications option in the main menu. The collapsible control panel appears on the left side of the map. Use it to filter map data, adjust the display, and understand map legends.

  • Filter Options

  • Settings

  • Legend

The table lists the available views in the control panel and describes their uses.

Table 1. Control panel views

View

Use

Filter Options

Filter map data by time interval, Layer 2 network visibility, group, and protocol. Refer to Filter communications on the map.

Settings

Configure the map layout, visibility, communication scope, and asset labels. Refer to Configure communication map display settings.

Legend

Identify the symbols and line styles used for groups and communications. Refer to View communication map legend indicators.

You can collapse the control panel to an icon-only bar to create more space for the map. Expand it again whenever you need to update a control.


Filter communications on the map

Filtering communications allows you to view specific traffic and network details, making it easier to analyze patterns or anomalies.

Follow these steps to filter communications on the map.

Procedure

  1. From the main menu, select Communications.

  2. In the left control panel, click the filter icon to open Filter Options.

  3. Under Filter Options, set the filters you need:

    Filter Options

    Use

    Interval

    Select the required time filter to focus on communications during specific periods.

    The Last 7 days filter is selected by default.

    Show unknown (L2 Network)

    Select this option to display subnets that contain MAC addresses but no IP addresses.

    Groups

    Select one or more asset groups to focus on their assets. Asset groups can be network groups or custom groups. Functional groups are no longer supported.

    IPv4 and IPv6 link-local addresses are excluded by default; select them when needed for local network discovery.

    Protocols

    Select the protocols to display. All protocols are selected by default, except Traffic-heavy Protocols, which are excluded to keep the map easier to read. Select them manually to include their data.

  4. Click Apply to update the map.

    The Clear button removes the current, unapplied filter selections.

The map displays only the communications that match the selected filters.


Configure communication map display settings

Use display settings to emphasize specific assets or communications, control map arrangement, and modify labels for improved clarity during investigations.

Follow these steps to configure communication map display settings.

Procedure

  1. From the main menu, select Communications.

  2. In the left-side control panel, select the Settings icon to open Settings.

  3. Under Settings, configure any of the following settings:

    Settings

    Use

    Assets & Groups

    Allow rearranging

    Reposition nodes on the map by dragging them. Changes are temporary and are lost when you exit the map view.

    This setting is enabled by default.

    Hide assets outside active view

    Hide assets that are outside the current active view.

    This setting is disabled by default.

    Show only assets with communications

    Display only asset interfaces with observed communications.

    This setting is enabled by default.

    Communications

    Show all communications

    Display all non-aggregated communication links at the asset-interface level.

    This setting is disabled by default.

    Show internal communications

    Display internal communications within a group.

    This setting is enabled by default.

    Note

    If you enable Show all communications, the Show internal communications setting is automatically disabled.

    Asset Label

    IP address

    Show only the IP address on each asset label.

    This option is selected by default.

    Asset name (IP address)

    Show the asset name and IP address on each asset label.

    This option is not selected by default.

The communication map updates based on your selections.


View communication map legend indicators

Use the communication map legend to identify group types, assets, and communication lines shown within or outside the active view.

Follow these steps to view communication map legends indicators.

Procedure

  1. From the main menu, select Communications.

  2. In the left control panel, select the Legend icon.

  3. Review the legend indicators.

    The legend includes the following types:
    Table 2. Communication map legend

    Indicator

    Meaning

    Asset Group Type

    Network Group

    Identifies a network group.

    Custom Group

    Identifies a custom group.

    Assets & Groups

    Within active view

    Identifies assets and groups within the active view.

    Outside active view

    Identifies assets and groups outside the active view.

    Communications

    Within active view

    Identifies an asset, group, or communication that matches the active-view.

    Outside active view

    Identifies an asset, group, or communication that is shown for context but does not match the active-view.

    Aggregated between groups

    Identifies communications aggregated between two groups.

You can now clearly identify the group types and communication status of map elements.


Exploring groups in a communication map

This process helps you examine asset interfaces and communications as groups are expanded or collapsed, without losing map context.

Summary

Group exploration on a communication map allows users to examine assets and communication paths within a group, without losing visibility of the overall network context.

The key components involved in the process are:

  • Asset groups: Collections of assets and communication paths that can be expanded or collapsed.

  • Child group: An asset group can contain child groups. When you expand a parent asset group, its child groups appear within it on the map.

  • Assets interfaces: Individual interfaces within an asset group., each with associated communication and summary details. However, when Show only assets with communications is turned off, the map can display asset interfaces that have no observed communications.

  • Conduits: Aggregated communication links between groups that display both summary and detailed information.

Workflow

The following stages describe group exploration on the communication map.

  1. Select a group on the map.

    A details pop-up opens with information such as the group’s assets, type, protocols, and communication summary. The map continues to show the other groups.

  2. Expand the group.

    Use Expand group in the details pop-up to expand the group. You can also use the drop-down arrow in the group label to expand the group. The map displays the group’s assets, subgroups, and internal communications while keeping nearby groups visible.

  3. View asset details.

    Select an asset in an expanded group. In the details pop-up, you can select:

    • Communication Details to view communication details of the interface in the right pane.

    • View assets summary to open the asset summary page in a new tab.

  4. Review inter-group communication.

    When a group is expanded, communications between groups appear as aggregated conduits. Each conduit summarizes the communication between two groups to maintain cross-group context.

  5. Expand a conduit for more detail.

    Expanding a conduit shows the individual communication links, including observed protocols and total data volume. Select a communication link to view the protocol and payload size.

    Collapse the conduit to return to the aggregated view.

  6. Collapse groups when finished.

    Collapsing a group returns it to a summarized node and hides its internal assets and communications. Select Collapse All to return the entire map to the initial group-level view.


Use the communication map context menu

Use the context menu to navigate the communication map, view group details, and adjust how the map is displayed.

Follow these steps to access context menus and adjust the communication map display:

Procedure

  1. From the main menu, select Communications.

  2. Right-click an empty area of the map canvas to open the context menu.

  3. Select the action you need:

    Option

    Usage

    Fit to view

    Display all groups and nodes in the map.

    Collapse All

    Return every group to the group-level view.

    Show all communications

    Display communication links at the asset-interface level.

    Show internal communications

    Display communications within a group using a non-aggregated-link view.

  4. To work with a specific group, right-click the group and select one of the following options:

    • Expand group - Shows the contents of the group.

    • Fit group - Focus the map on the group.

    • Open details - Opens the group details.

The map updates to reflect the action you select.