Cisco Secure Access Help

PDF

Cisco Secure Access Help

App Discovery Report

Want to summarize with AI?

Log in

Describes App Discovery Report in Cisco Secure Access. Monitor the cloud apps in use by your organization with the App Discovery report.


Monitor the cloud apps in use by your organization with the App Discovery report. To effectively reduce the risk introduced by apps, monitor app use and look for a reduction over time in the number of DNS requests made by apps with high and very high-risk assessments. You can monitor this with the App Discovery report.

Apps can be blocked through rules when risk levels are unacceptable or when an app category is inappropriate for your organization. For more information, see Control Apps.

App Discovery data is aggregated and processed once a day. It may take up to 24 hours for new data to populate an App Discovery report. Logging of traffic is required for App Discovery to function.


View the App Discovery Report

Monitor the cloud apps in use by your organization with the App Discovery report. To effectively reduce the risk introduced by apps, monitor app use and look for a reduction over time in the number of DNS requests made by apps with high and very high-risk assessments.


View the App Discovery Report

Before you begin

A minimum user role of Read-Only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > App Discovery.


    The App Discovery interface.
  2. View the discovered apps in your environment.

    • Unreviewed—The app has not yet been assigned any label.

    • Under Audit—The app is currently being reviewed.

    • Not Approved—The app should not be approved for use in your environment.

    • Approved—The app may be used in your environment.

    Note
    Once you relabel an Unreviewed app, you cannot change the app label back to Unreviewed. Use the Under Audit label for apps that still need review.
    Note
    Labels do not automatically block apps from use. You must configure a rule to block specific apps or apps with specific labels. For more information, see Control Apps.
  3. View the flagged categories.

    Cisco's Cloud Security researchers categorize apps according to function, source, and other factors. The categories of most interest (and most risk) are:

    • Anonymizers—Services that provide an anonymous proxy tool that attempts to make activity on the Internet untraceable. Apps in this category can introduce data exfiltration risks.

    • Cloud Storage—Applications that offer massively scalable storage capacity that can be used for applications and file storage. Apps in this category can also be used for data exfiltration.

    • Collaboration—Applications that may store sensitive data in unreliable services or unsecured environments.

    • Games—Online and mobile games. While games are not notable for data exfiltration risks, some can be used as attractive ways to introduce malware.

    • Generative AI—Applications that have the potential to generate misleading or fraudulent content and copyright or intellectual property infringements.

    • Media—Applications that can contribute to productivity loss and are frequently managed as unwanted bandwidth consumers.

    • P2P—Peer to Peer torrents like apps and protocols. These apps can be used for data exfiltration.

    • Social Networking—Can be used to transmit sensitive data as well as contribute to productivity loss.


    The Flagged Categories interface.

    For a complete list of application categories, see Application Categories.

  4. View the flagged application protocols.

    These protocols are flagged based on the protocol used by the application.

    Note
    Dismissing a flagged app card hides it from the overview. It does not label or block the app.

    The Flagged Protocol interface.
  5. View DNS requests and traffic by App Risk.

    The graph shows the total number of DNS requests for apps discovered in the past 30 days. Secure Access assigns a risk score to apps based on several factors. The DNS requests made by a high-risk app can be considered more problematic than the same number of requests made by an app with a lower risk score.


    Apps based on several factors. The DNS requests made by a high-risk app can be considered more problematic than the same number of requests made by an app with a lower risk score.
    1. Filter the graph by label and risk.


      Filter the graph by label and risk.
    2. Select Web and review Traffic (bytes in and out) by App Risk for the last 30 days.


      Select Web and review Traffic (bytes in and out) by App Risk for the last 30 days.
    3. View All Traffic, Outbound Traffic or Inbound Traffic.


      View All Traffic, Outbound Traffic or Inbound Traffic.
  6. View apps by category and risk.

    Click a bar on the chart to view apps in that category in the App Grid.


    The Apps by Categoryrisk interface.
    1. Filter by label and risk.


      The Apps by Category Filtered interface.

View the Highest Risk Apps

You can view the highest-risk apps in the App Discovery Report by filtering for apps with the highest number of DNS requests.

The App Discovery report is used to help review apps in your environment. To block risky apps, you must configure application settings within a policy rule to control apps.


Procedure

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > App Discovery.


    The App Discovery interface.
  2. From the overview, click Unreviewed Apps. The App Grid appears depicting data for the last 90 days.

  3. Filter the list by selecting Very High or High from the Risk menu. Only the riskiest apps will be listed.

  4. Filter the list by DNS Requests to display the apps with the highest number of requests at the top.


    The App DNS interface.

    The apps at the top of the list should now represent the highest number of DNS requests made by the riskiest apps.


Review Apps in the Apps Grid

The Apps Grid provides an overall view of application activity in your environment and the potential risk indicated by this traffic.

Note
Packages and Feature Availability

Not all of the features described here are available to all Secure Access packages. Information about your current package is listed on the Admin > Licensing page. For more information, see Determine Your Current Package.

If you encounter a feature here that you do not have access to, contact your sales representative for more information.


Procedure

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > App Discovery and click one of the app labels to open the Apps Grid.


    The App Discovery interface.
  2. Filter by label.

    • Unreviewed—The app has not yet been assigned any label.

    • Approved—The app may be used in your environment.

    • Not Approved—The app should not be approved for use in your environment.

    • Under Audit—The app is currently under review.


    The Select Label Filter interface.
    Note
    Once you relabel an Unreviewed app, you cannot change the app label back to Unreviewed. Use the Under Audit label for apps that still need review.
    Note
    Labels do not automatically block apps from use. You must configure a rule to block specific apps or apps with specific labels. For more information, see Control Apps.
  3. Filter by Controllable Apps.

    You can filter the apps listed by apps that are controllable and apps that have advanced app controls.


    The Controllable Apps Filter interface.
  4. Filter by Risk.

    For more information on how risk is calculated, see Risk Details.


    The Risk Filter interface.
  5. Filter by category.

    For more information on app categories, see Application Categories.


    The Cateory Filter interface.
  6. Filter by app type.

    • SaaS—Software as a service

    • PaaS—Platform as a service

    • IaaS—Infrastructure as a service


    The App Type Filter interface.
  7. Filter by date. The app grid will display data for 24 hours based on the date selected. The default is the current date.


    The Date Filter interface.

Configure Columns to Display

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

You can customize what columns are displayed.

Procedure

  1. Click the Actions icon.


    You can customize what columns are displayed. Click the Actions icon.
  2. Select columns to display and click Apply.

    Note
    Rearrange the order of settings by dragging and dropping the column fields,

    Rearrange the order of settings by dragging and dropping the column fields,.
    • App Type—The type of app: SaaS, PaaS or IaaS.

    • Blocked DNS—The percentage of DNS requests blocked by Secure Access based on policy configurations.

    • Blocked Traffic—The percentage of all traffic blocked.

    • DNS Requests—The number of DNS requests for this app.

    • First Detected—The date the app was first detected.

    • Identities—The number of identities affected by the app. Click this number to view the app's details and the list of identities with requests for that app.

    • Inbound Traffic—Bytes inbound.

    • Last Detected—The date the app was last detected.

    • Outbound Traffic—Bytes outbound.

    • Total Traffic—The total number of bytes inbound and outbound for this app in your environment.

    • Vendor—The vendor that owns the app.

    • Weighted Risk—The risk the app poses to the environment.


Change the Label of an App

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Reporting > Core Reports > App Discovery and click one of the app labels to open the Apps Grid.


    The App Discovery interface.
  2. Check the checkbox for the app or apps you want to change the label of, click the Label drop-down menu, and select the new label.


    The App Label interface.
    Note
    Once you relabel an Unreviewed app, you cannot change the app label back to Unreviewed. Use the Under Audit label for apps that still need review.
    Note
    Labels do not automatically block apps from use. You must configure a rule to block specific apps or apps with specific labels. For more information, see Control Apps.

View App Details

The details page for an app lists summary information about the app, including:

  • The risk score for the app, and the details on how it was calculated.
  • The identities that have made DNS requests and seen traffic for the app.
  • The detailed attributes of the app, which can help you perform a risk/benefit analysis of permitting the app to be used in your environment.
Note
App details are also accessible from the Third-Party Apps Report.

Procedure

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > App Discovery and click one of the app labels to open the Apps Grid.


    The App Discovery interface.
  2. Click the name of an app to view its details and traffic data for the last 90 days.

  3. View the initial details of the app, including the name and a description of the app.


    The App Discovery Step 3a interface.
    • Risk Score—The overall score assigned to the app. This could be calculated by Umbrella or assigned by you. Hover over the Risk Score icon to display the Risk Summary for the app.


      The Step3 Bcustom interface.

      The risk summary displays:

      • The Custom risk score, which appears if you have chosen to override the Weighted risk score calculated by Umbrella. To apply a Custom risk score see Change App Details.

        Note
        If you apply a Custom risk score to an App, it will be noted in the Apps Grid display as shown below:

        The Custom Risk in App List interface.
      • The Weighted risk score calculated by Umbrella based on Business risk, Usage risk, Vendor compliance, and Community risk (if available).

      • The Community risk score, which appears if one or more other users have assigned a Custom risk score to the app. Umbrella calculates the Community risk score as a median of the Custom risk scores assigned to the app by all users.

    • A label describing the review status of the app for your installation: Unreviewed, Approved, Not Approved, or Under Audit. To change the label assigned to the app, see Change App Details.

      Note
      App labels are primarily used for tracking and filtering, to help you keep track of the app review process within your organization. They do not of themselves control access to an app. However, if you establish an app risk profile that uses Label Status as a criteria, and that profile is used in an internet access rule, that rule may cause an application to be blocked or allowed based on the value of its app label.
    • A link to control the app. The link text may appear as Control this app, Edit app controls, or Block this app.

      • Control this app—Available only when Block or Allow have not been configured for this app. If the app setting is configured but has not yet been applied to a policy, a red tooltip appears.

      • Edit app controls—Available only when the app has previously configured application settings and you can enable advanced activities for the application.

      • Block This App—Appears when a block has not been configured for this app, or a red tooltip icon will appear if the app setting is configured but has not yet been applied to a policy.

        For more details, see Control Apps.

    • App URL—The URL of the app.

    • Category—The category the app falls under. For more information, see Application Categories.

    • Identities—The number of sources that accessed the app.

    • Vendor—The owner of the app.

    • Traffic—The number of bytes of total traffic and bytes blocked.

    • DNS Requests—The total number of DNS requests and the percentage of requests blocked by Secure Access.

    • First Detected—The date the app was first detected.

    • Last detected—The date the app was last detected.

  4. Click Risk Details.

    The Risk Details tab displays the app's risk score and how it was calculated, including Business Risk, Usage Risk, and Vendor Compliance.


    The Risk Details interface.
  5. Click Identities.

    The Identities tab lists your organization's sources that have made DNS requests and traffic for this app.

    Click the Download CSV icon to download this information as a CSV file.


    Click the Download CSV icon to download this information as a CSV file.
  6. Click Attributes.

    The Attributes tab lists the various attributes associated with this app.


    The Attributes tab lists the various attributes associated with this app.

    Attributes are divided into categories. Click a category name to view the attributes associated with it. (Not all applications will show all attribute categories.)

    For each displayed attribute, Secure Access shows whether the attribute applies to the application and the dates when the attribute information was collected and updated. Use the attributes to evaluate the risk that the application will expose your environment to data breaches, identity theft, financial fraud, and other cyber threats.

    The attribute categories are:

    • Compliance attributes — Indicate whether the application complies with the requirements of a number of certifications such as GDPR, HIPAA, and FEDRAMP.

    • Vulnerabilities attributes — Indicate whether the application is vulnerable to exploits that attackers could use to compromise the security of the affected systems, steal sensitive data, or cause other types of damage.

    • Access control attributes — Indicate the methods the application supports to manage and restrict access based on a user's identity, role, and authorization level.

    • Data security attributes — Indicate the practices and technologies the application uses to protect data from unauthorized access, use, disclosure, modification, or destruction.

    • Auditability attributes — Indicate the abilities the application provides for an administrator to review the activity and transactions of a system, to ensure that it is operating in a compliant and secure manner.

    • Email authenticity attributes — Indicate what methods the app provides to verify that email is actually from the sender that it claims to be from, and that the message has not been tampered with or altered in any way during transit.


Change App Details

You can change details about apps from within the App Discovery Report:

  • You can change the review status label assigned to an app. Labels help you keep track of the review status of apps, so you know which ones are approved for use in your environment. The possible label values are:
    • Unreviewed—The app has not yet been assigned any label.

    • Approved—The app may be used in your environment.

    • Not Approved—The app should not be used in your environment.

    • Under Audit—The app is currently under review.

    Note
    App labels are primarily used for tracking and filtering, to help you keep track of the app review process within your organization. They do not of themselves control access to an app. However, if you establish an app risk profile that uses Label Status as a criteria, and that profile is used in an internet access rule, that rule may cause an application to be blocked or allowed based on the value of its app label.
  • You can change the risk score for the app, overriding the value calculated by Umbrella. The possible risk scores are:
    • Very High

    • High

    • Medium

    • Low

    • Very Low

    Note
    Changing the risk score for an app does not change whether Secure Access blocks or allows the app. (You must configure application settings within a policy to block apps. For more information, see Manage the Access Policy or Manage Security Profiles for Internet Access.) Secure Access provides risk scores strictly for your own information, to help you keep track of the risk levels for different apps and decide whether to block or allow them. You can accept the risk levels calculated by Secure Access, or assign different risk scores based on the risk tolerances within your organization.

Change the Risk Score for an App

Before you begin

A minimum of Read Only access to the Secure Access dashboard. See Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > App Discovery and click one of the app labels to open the Apps Grid.


    The Change Risk Score Step1 interface.
  2. You have two choices:

    1. To change the risk score for an app from the Apps Grid, hover over the risk score for an app to view its Risk Summary.


      The Change Risk Score from App Grid interface.
    2. To change the risk score for an app from its Details page, click the name of the app on the Apps Grid, then from the Details page hover over the risk score to view the Risk Summary.


      The Change Score from Detail Page interface.
  3. From the Risk Summary, click on CHANGE RISK SCORE to display the Risk Score Change dialog.


    The Risk Score Change Dialog interface.
  4. Select the new value to assign:

    • Very High

    • High

    • Medium

    • Low

    • Very Low


    The Risk Score Menu interface.
  5. Click SAVE.


Change the Label of an App

Labels within the App Discovery report help you keep track of the review status of apps, so you know which ones are approved for use in your environment. You can change the label for an app anytime.

Note
App labels are primarily used for tracking and filtering, to help you keep track of the app review process within your organization. They do not of themselves control access to an app. However, if you establish an app risk profile that uses Label Status as a criteria, and that profile is used in an internet access rule, that rule may cause an application to be blocked or allowed based on the value of its app label.
Note
Once an app has been given a label, it cannot be set back to Unreviewed. You can use the Under Audit label for apps that still need review.

Before you begin

A minimum of Read Only access to the Secure Access dashboard. See Manage Accounts.

Procedure

  1. Navigate to Reporting > Core Reports > App Discovery and click one of the app labels to open the Apps Grid.


    You can use the Under Audit label for apps that still need review. Navigate to Reporting Core Reports App Discovery and click one of the app labels to open the Apps Grid.
  2. You have two choices:

    1. To change the label for an app from the Apps Grid, hover over its label to view the label menu.


      To change the label for an app from the Apps Grid, hover over its label to view the label menu.
    2. To change the label for an app from its Details page, click the name of the app on the Apps Grid, then on the Details page hover over the label to view the Label menu.


      The Change Label from Detail Page interface.
  3. From the Label menu, select your choice of new value to assign:

    • Approved—The app may be used in your environment.

    • Not Approved—The app should not be approved for use in your environment.

    • Under Audit—The app is currently under review.


Control Apps

You can control applications through rules and through the App Discovery report in View App Details and the App Grid. The application settings are a rule component that enables controlling of supported apps, regardless of usage, at the policy level. The App Discovery report allows you to review apps in your organization and control apps individually.

Note
App blocking requires enablement within a rule. Apps that are not present in application settings, or do not have the Edit app controls, Control this app, or Block this app options in App Discovery cannot be blocked. If you need to block an app we don't have yet, contact Support to request it.

Procedure

Before you begin

Full Admin user role. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > App Discovery.


    The App Discovery interface.
  2. From the overview, click Unreviewed Apps. The App Grid appears depicting data for the last 90 days.

  3. Select a Controllable Apps filter: All Controllable Apps or Advanced Controls.


    The App Control interface.
  4. Click Edit App Controls, Control This App, or Block This App.

    • Block This App—Appears when a block has not been configured for this app, or a red tooltip icon will appear if the app setting is configured but has not yet been applied to a policy.

    • Control This App—Appears when Block or Allow have not been configured for this app, or a red tooltip icon will appear if the app setting is configured but has not yet been applied to a policy.

    • Edit App Controls—Appears when the app has already had settings configured but can be edited.

  5. On clicking Control This App, the Control Application Name window appears. Choose one or more application lists to add this application to and click Save. Once saved, the internet access rules set for the application lists are applied to the application.

    The application can only be added to application lists currently active in a policy.


    The Control App interface.

Control Application Lists


Control Advanced Apps

Applications within App Discovery can be blocked or allowed based on risk assessment. In addition to blocking all content for an application, you have the option to instead block only specific content, such as file uploads or posts.

Note
Secure Access Packages

Advanced App Controls are not available to all Secure Access packages. To determine your current package, navigate to Admin > Licensing. For more information, see Determine Your Current Package

You can edit the controls of apps with advanced app controls while reviewing applications in the App Discovery Report. You can filter out apps with advanced controls and edit their application settings in the Apps Grid, or edit the application settings in the app's Details page.


Procedure

Before you begin

Full Admin user role. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > App Discovery.


    The App Discovery interface.
  2. Click any of the discovered apps labels to enter the Apps Grid.


    Full Admin user role. For more information, see Manage Accounts. Navigate to Monitor Reports App Discovery. Click any of the discovered apps labels to enter the Apps Grid.
  3. Choose Advanced Controls under the Controllable Apps filter.


    The Advanced Cotrols Filter interface.
  4. Choose an app to control and click Control this app.


    The App Unreviewed interface.
  5. On clicking Control This App, the Control Application Name window appears. Choose one or more application lists to add this application to and click Save. Once saved, the internet access rules set for the application lists are applied to the application.


    The Control App interface.

    The application can only be added to application lists that are currently active in a policy.


View Traffic Data Through SWG Service

App Discovery provides traffic data through the Secure Web Gateway (SWG ) service. Traffic is reported in bytes in and bytes out.


View Traffic

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > App Discovery and locate the DNS Requests by App Risk graph.


    The App Discovery interface.
  2. Click Web to display Traffic by App Risk.


    The App Discovery Dashboard Step2 interface.
  3. Click All Traffic to open the drop-down and then choose to view All Traffic, Inbound Traffic, or Outbound Traffic.


    The View Traffic App Discovery Dashboard 03 interface.
  4. Hover on a point in the graph to view details about the traffic by app risk for that date.


    The App Discovery Dashboard4 interface.

View Traffic in the Apps Grid

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Reports > App Discovery and click one of the app labels to open the Apps Grid.


    The App Discovery interface.
  2. Click the action menu to open the drop-down of options for columns displayed in the grid. Select the columns relevant to traffic and then click Apply.


    The Traffic Columns interface.
  3. View the traffic, bytes in and out, of applications by total, outbound, or inbound traffic.


    The Traffic Columns 2 interface.

View Traffic in the App Details

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Reporting > Core Reports > App Discovery and click the name of an app to view its details for the last 90 days.


    The App Discovery interface.

    Details include the total and blocked traffic in bytes.


    The View Traffic in App Details Step2 interface.
  2. Navigate to the Identities section of the app details and view the total Traffic and Blocked Traffic.


    The App Details3 interface.