Introduction to Advanced Threat Defense
In today's evolving threat landscape, enterprises face sophisticated attacks like Advanced Persistent Threats (APTs) that bypass traditional perimeter security. The data center, housing critical information, requires robust defense mechanisms to detect and mitigate these internal threats.
Solution Overview
The Cisco Cyber Threat Defense Solution for the Data Center provides proactive threat detection capabilities by offering deep visibility into network traffic. It leverages Cisco networking technology and Lancope's StealthWatch System to enable security operators to understand network activity, identify suspicious patterns, and respond effectively to potential breaches.
Key Technologies and Components
This solution integrates core Cisco technologies with Lancope's advanced security monitoring tools. Key components include:
- Cisco NetFlow for traffic telemetry.
- Lancope StealthWatch System for NetFlow analysis and management.
- Cisco Identity Services Engine (ISE) for identity and policy services.
- Specific Cisco hardware and software, such as ASA security appliances and Nexus switches.
Purpose and Benefits
The primary goal is to enhance security posture within the data center by providing comprehensive visibility and context. This allows for the detection of various threats, including botnet command and control, network reconnaissance, malware spread, data loss events, and denial-of-service attacks, thereby reducing vulnerability windows and empowering security operations.
Further Information
This document serves as a Cisco Validated Design, offering guidance on the architecture, design, and implementation of the Cyber Threat Defense Solution for the Data Center. For detailed deployment and configuration, refer to the Cisco Cyber Threat Defense Solution Cisco Validated Design Guide.
Visit Cisco.com/go/designzone for more Cisco Validated Design resources.