Site icon IT World Canada

Cisco extends anti-malware, data centre security portfolio

New network security products from Cisco Systems Inc. address zero-day exploits and advanced persistent threats (APTs) from the enterprise network to the endpoint to the cloud, the company says.

The new malware and data centre security offerings were unveiled at the Cisco Live event in San Francisco this week.

Cisco has also announced that it is buying security intelligence firm ThreatGrid. The acquisition reflects Cisco’s determination to pursue its cloud and IoT buildout. ThreatGrid’s malware products will be melded into Cisco’s AMP line in a clear extension of Cisco’s acquisition of security vendor Sourcefire last October. The deal will close by the end of Q4 this year.

The new products and enhancements are focused on – though not restricted to – Cisco’s Advanced Malware Protection (AMP) line. The AMP updates correlate Indications of Compromise (IoC) data between network and endpoint with integrated threat defence and shared intelligence. Cisco says that this correlation provides continuous and pervasive protection against the most advanced threats. AMP provides malware detection and response across the extended network, including endpoints, mobile devices, virtual systems and Web and e-mail gateways.

Cisco has added MacOSX support to AMP, along with an on-premises private cloud appliance that provides continuous analysis. The newly acquired ThreatGrid technology adds dynamic analysis on-premises and in the cloud. Working as a complement to AMP, it performs aggregation and correlation of threat data across the network and across Cisco’s portfolio of services and solutions.

Cisco also announced enhancements to its ASA firewall product family that will improve security in the data centre and into the cloud. The upgrades support software-defined networking (SDN) and Application Centric Infrastructure (ACI) environments.

New capabilities in the AMP portfolio include:

Cisco (Nasdaq: CSCO) also released a new version of its Secure Data Center Cisco Validated Design (CVD), which supports the secure deployment of new solutions.

The new ASAv virtual appliance has dynamic, on‐demand scalability within virtual environments, with ACI integration, without hypervisor or vSwitch limitations. Cisco says it delivers high-level performance marks in throughput and connections per second. Enhancements to the ASA 5585-X firewall support traditional, SDN and ACI data centre environments.

Jason Brvenik, principal engineer with Cisco’s Security Business Group, came to the company as part of the Sourcefire acquisition. In an advance briefing for IT World Canada, Brvenik defined the new product announcements as they fit into Cisco’s notion of an “attack continuum” – the security measures and threat assessments that need to be executed before, during and after an attack.

“In each of these phases, there are technologies that are well suited to helping you solve the specific challenges of security,” Brvenik told IT World Canada. “The before part is knowing what your assets are, what systems your users are using, who’s active – as well as enforcing policy. During the attack of course you need to do the basics – detect, interdict and block the threat. If you can’t do those things you can’t do anything else.” The follow-up phase is perhaps the most complex, involving analysis of the scope of the compromise, remediation, and reporting.

“You can’t do all this as a point technology at a single point of observation – it has to be across all the attack points,” Brvenik said. “That’s why we talk about the network, the endpoint, mobile devices, virtual devices, the cloud, everything. Enterprises need a technology that gives them that visibility, to control and protect assets. And you can’t do this at a single point in time, it needs to be a continuous process.”

Exit mobile version