36
CISCO UMBRELLA 03.10.2018 | Bolzano, Andrea Dainese PROTECTION AND VISIBILITY FOR ENTERPRISE NETWORKS

Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

CISCO UMBRELLA

03.10.2018 | Bolzano, Andrea Dainese

PROTECTION AND VISIBILITY FOR ENTERPRISE NETWORKS

Page 2: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

ABO

UT

§ Network and Security Architect (15+ years’ exp.)§ Security Evangelist (Blue Team)§ Automation Addicted/Developer (UNetLab)§ Cisco CCIE #38620/VMware VCP/Red Hat RHCE

ANDREA DAINESE - SENIOR SYSTEMS ENGINEER

@adainese

[email protected]

www.linkedin.com/in/adainese

Page 3: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

INTRODUCTION

Page 4: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

INTR

OD

UCTI

ON

You cannot protect what you don’t know

Page 5: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

INTR

ODU

CTIO

N

§ Where users navigate?§ What they download?§ What they execute?§ What they attach to the computer/laptop?§ Where they are used to work?§ Are endpoints left unattended?

WHAT ABOUT ENDPOINTS?

Page 6: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

INTR

OD

UCTI

ON

Multi layered security approach

Page 7: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

INTR

OD

UCTI

ON

Must:§ Categorized web sites§ Set policies for user groups (AD integration)§ Protect on premises and mobile users

Should:§ Work for all protocols§ Easy to setup and maintain

PREREQUISITES FOR A WEB CONTENT FILTER

Page 8: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

INTR

OD

UCTI

ON

SWG SIGProtection Enterprise

NetworksEverywhere

Control Granular web usage*

Any protocol

Setup Time Days Minutes

User experience

Can break some sites/apps**

No latency

WEB CONTENT FILTER COMPARISON

*: Encrypted websites require a MITM approach**: Some applications do not work behind a proxy server

Page 9: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

CISCO UMBRELLA

Page 10: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

CIS

CO

UM

BREL

LABRIEF HISTORY§ 2006: OpenDNS Founded§ 2012: Umbrella enters the enterprise market§ 2015: Cisco squires OpenDNS/Umbrella

WHAT IS OPENDNS/UMBRELLA?The largest cloud-based DNS service (and more)

TODAY§ 100B requests/day§ 85M daily users§ 12k Enterprise Customers

Page 11: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

CIS

CO

UM

BREL

LA

Threat prevention for:§ Homes (OpenDNS)*§ Enterprises (Umbrella)

*: Dynamic IP Internet connection require to update the OpenDNS account using a DDNS protocol (link).

Page 12: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

CIS

CO

UM

BREL

LA

§ Unwanted Websites§ Suspicious Websites§ Advertising§ Malware§ Phishing Attacks§ Newly Seen Domains (and DGA*)§ Command and Control Callbacks§ DNS Tunnelling VPN**

CISCO UMBRELLA PROTECT AGAINST:

*: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com**: A MRZGS3TLEBWW64TFEBXXMYLMOR.t.example.com

CNAME WW2IDPOZQWY5DJNZSQ.t.example.com

Page 13: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

VISIBILITY

Page 14: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

VISIBILITY

Cisco Umbrella v1 - Instant Demo @ Cisco dCloud

DASHBOARD

Page 15: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

VIS

IBIL

ITY

ACTIVITY SEARCH (C&C)

Page 16: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

VIS

IBIL

ITY

ACTIVITY SEARCH (DETAIL)

Page 17: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

VIS

IBIL

ITY

ACTIVITY SEARCH (GENERIC)

Page 18: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

VIS

IBIL

ITY

CLOUD SERVICES

Page 19: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

A FAMOUS CRYPTOLOCKER

Page 20: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

#WA

NN

AC

RYA BRIEF STORY

• A Long Time Ago: EternalBlue by NSA• March 14th, 2017: Microsoft Security Bulletin (MS17-010)• April 15th, 2017: Shadow Brokers release

• May 12th, 2017 | 07:24 UTC: #WannaCry Patient Zero• May 12th, 2017 | 07:30 UTC: @MalwareTechBlog Post• May 12th, 2017 | 07:43 UTC: Kill Switch on Umbrella

Page 21: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

UMBRELLA INVESTIGATE

Page 22: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

INVE

STIG

ATE

#WANNACRY (SUMMER 2017)

Page 23: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

INVE

STIG

ATE

#WANNACRY (AUTUMN 2017)

Page 24: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

INVE

STIG

ATE

#WANNACRY (GEOGRAPHIC DISTRIBUTION)

Page 25: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

INVE

STIG

ATE

TARGETED MALWARE

Page 26: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

ARCHITECTURE

Page 27: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

ARC

HITE

CTU

RE DEPLOYMENT MODES

§ Networks§ Internal Networks (VA)§ Network Devices

Roaming Computers§ Mobile Devices

Page 28: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

ARCHITECTURE NETWORKS

Page 29: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

ARC

HITE

CTU

RE INTERNAL NETWORKS

Page 30: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

ARC

HITE

CTU

RE ROAMING CLIENTS

Page 31: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

ARC

HITE

CTU

RE HIGH AVAILABILITY (GLOBAL)

Anycast:§ 208.67.220.0/24 (.220 and .222)§ 298.67.222.0/24 (.220 and .222)

Page 32: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

ARC

HITE

CTU

RE HIGH AVAILABILITY (LOCAL)

Windows:§ timeout 1s§ attempts 1§ use the last one for 15mOS X:§ timeout 1s§ attempts 2§ use the last one for 10mLinux:§ timeout 5s§ attempts 2§ use always the first one

Page 33: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

ARC

HIT

ECTU

RE

Know your networkor

Start with non blocking policy

Page 34: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

ARC

HIT

ECTU

RE

Multi-Layer Security1. DNS: Cisco Umbrella2. Url Filtering

Page 35: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware

DEMO

Page 36: Cisco Umbrella and... · 2020-06-23 · CISCO UMBRELLA 03.10.2018 | Bolzano ... §Security Evangelist (Blue Team) §AutomationAddicted/Developer (UNetLab) §Cisco CCIE #38620/VMware