Cisco Secure Access Help

PDF

Cisco Secure Access Help

Threat Intelligence Feeds

Want to summarize with AI?

Log in

Integrate supported threat intelligence feeds in Secure Access to share collections of information about security threats and indicators of compromise.


Secure Access supports the integration of threat intelligence feeds in a Secure Access organization. Threat intelligence feeds are services that provide collections of information about security threats and indicators of compromise (IOCs).

In Secure Access, you can add a Third-party Integration and configure the integration of a threat intelligence feed.

  • The threat intelligence feed must provide the collections of data in the Structured Threat Information eXpression (STIX) JSON schema.

  • The threat intelligence feed must deliver the data using the Trusted Automated eXchange of Intelligence Information (TAXII) protocol.

  • Integrated threat intelligence feeds must support a collection of IOCs that include: IPv4 or IPv6 addresses, fully-qualified domain names (FQDNs), and URLs.

When you integrate a threat intelligence feed in your organization, Secure Access creates and manages a dedicated destination list in the organization.

After Secure Access begins to collect data from the integrated threat intelligence feed, you can view the destinations in the destination list. The new destination list is available to add on the internet access rules in the organization's Access policy.

Requirements for Integrating a Threat Intelligence Feed

To integrate with Secure Access, a threat intelligence feed must meet the following requirements:

  • Support for the STIX 2.0/2.1 JSON schema over the TAXII 2.0/2.1 protocol.

  • Support at a minimum for basic authentication with a username and password.

  • Have a publicly accessible URL.

  • Provide a unique identifier for the STIX collection.

  • Provide a collection of IOCs with IPv4 or IPv6 addresses, fully qualifed domain names (FQDNs), and URLs.

How to Integrate a Threat Intelligence Feed in Secure Access

  1. Subscribe to a threat intelligence feed.

  2. Add a third-party integration in Secure Access with the configuration details for the threat intelligence feed.

  3. Add the destination list associated with the threat intelligence feed in the internet access rules in the organization's access policy.

  4. View the details about the impacted internet destinations in the Secure Access Activity Search report or with the Cisco Secure Access Reporting API.

Add a Third-Party Integration for a Threat Intelligence Feed

For more information, see Add Third-Party Integrations for Threat Intelligence Feeds.

View Integrated Threat Intelligence Feeds

For more information, see View Integrated Threat Intelligence Feeds.

Manage a Threat Intelligence Feed in Secure Access

For more information, see Edit or Delete a Threat Intelligence Feed.

The Threat Intelligence Feeds interface.

Add Third-Party Integrations for Threat Intelligence Feeds

Add a Third-party Integration for a threat intelligence feed.

  • Configure the settings for the threat intelligence feed in Secure Access and enable the integration. Secure Access supports Basic authentication and a username and password in all communications with the threat intelligence feed service.

  • Configure the settings for the collection that Secure Access will ingest from the threat intelligence feed.

Before you begin

Procedure

  1. Navigate to Admin > Third-party Integrations.

  2. Click + Integrate.


    The Resized Threat Intel Feeds interface.
  3. Expand Security Feed Configuration.

  4. Toggle on Integration to enable the threat intelligence feed.

  5. For Integration Name, enter a name that distinguishes the threat intelligence feed in the organization.

  6. For Discovery URL, enter the URL for the threat intelligence feed.

  7. For Authentication method, choose Basic.

  8. For Username, enter the username for the account that Secure Access will use to authenticate with the threat intelligence feed.

  9. For Password, enter the password for the user account that Secure Access will use to authenticate with the threat intelligence feed.

  10. Click Next.


    The Resized Feed Configuration interface.
  11. Expand Security Feed Collections.

  12. For Root URL, enter a root URL for the threat intelligence feed.

  13. For Collections, enter an identifier for a collection in the threat intelligence feed.

  14. Click Integrate.


    The Resized Feed Collections interface.

View Integrated Threat Intelligence Feeds

After you add a third-party integration for a threat intelligence feed, you can view the details about the settings configured in Secure Access and the destinations in the destination list for the integration.

You can view the status and details about the threat intelligence feeds integrated in Secure Access.

Before you begin

Procedure

  1. Navigate to Admin > Third-party Integrations.

  2. Navigate to Threat Intelligence Feeds.


    The Resized Threat Intel Feeds interface.
  3. Click View details.

  4. Navigate to Integrated instances.


    The Threat Intelligence Feeds Integrated Instances Focused interface.
  5. You can view the details about a threat intelligence feed, and edit or remove the integration of the threat intelligence feed.


    The List Instances Threat Intel Focused interface.
  6. Navigate to a row in the table.

  7. Click Close.


Edit or Delete a Threat Intelligence Feed

Before you begin

Procedure

  1. Navigate to Admin > Third-party Integrations.

  2. Navigate to Threat Intelligence Feeds.

  3. Click View Details.


    The Resized Threat Intel Feeds interface.
  4. Navigate to Integrated instances.

  5. To edit an integrated threat intelligence feed, navigate to the Action column in a row in the table and then click the pencil icon.

    1. Expand Security Feed Configuration.

      The Edit Security Feed Configuration Only interface.
    2. Toggle on Integration to enable the threat intelligence feed.
    3. For Integration Name, enter a name that distinguishes the threat intelligence feed in the organization.
    4. For Authentication method, choose Basic.
    5. For Username, enter the username for the account that Secure Access will use to authenticate with the threat intelligence feed.
    6. For Password, enter the password for the user account that Secure Access will use to authenticate with the threat intelligence feed.
    7. Click Save.
  6. To delete an integrated threat intelligence feed, navigate to the Action column in a row in the table and then click the trash can icon.

    1. Click Delete and then click Delete again to confirm the removal of the threat intelligence feed.