Integrate supported threat intelligence feeds in Secure Access to share collections of information about security threats and indicators of compromise.
Secure Access supports the integration of threat intelligence feeds in a Secure Access organization. Threat intelligence feeds are services that provide collections of information about security threats and indicators of compromise (IOCs).
In Secure Access, you can add a Third-party Integration and configure the integration of a threat intelligence feed.
-
The threat intelligence feed must provide the collections of data in the Structured Threat Information eXpression (STIX) JSON schema.
-
The threat intelligence feed must deliver the data using the Trusted Automated eXchange of Intelligence Information (TAXII) protocol.
-
Integrated threat intelligence feeds must support a collection of IOCs that include: IPv4 or IPv6 addresses, fully-qualified domain names (FQDNs), and URLs.
When you integrate a threat intelligence feed in your organization, Secure Access creates and manages a dedicated destination list in the organization.
After Secure Access begins to collect data from the integrated threat intelligence feed, you can view the destinations in the destination list. The new destination list is available to add on the internet access rules in the organization's Access policy.
Requirements for Integrating a Threat Intelligence Feed
To integrate with Secure Access, a threat intelligence feed must meet the following requirements:
-
Support for the STIX 2.0/2.1 JSON schema over the TAXII 2.0/2.1 protocol.
-
Support at a minimum for basic authentication with a username and password.
-
Have a publicly accessible URL.
-
Provide a unique identifier for the STIX collection.
-
Provide a collection of IOCs with IPv4 or IPv6 addresses, fully qualifed domain names (FQDNs), and URLs.
How to Integrate a Threat Intelligence Feed in Secure Access
-
Subscribe to a threat intelligence feed.
-
Add a third-party integration in Secure Access with the configuration details for the threat intelligence feed.
-
Add the destination list associated with the threat intelligence feed in the internet access rules in the organization's access policy.
-
View the details about the impacted internet destinations in the Secure Access Activity Search report or with the Cisco Secure Access Reporting API.
Add a Third-Party Integration for a Threat Intelligence Feed
For more information, see Add Third-Party Integrations for Threat Intelligence Feeds.
View Integrated Threat Intelligence Feeds
For more information, see View Integrated Threat Intelligence Feeds.
Manage a Threat Intelligence Feed in Secure Access
For more information, see Edit or Delete a Threat Intelligence Feed.