Cisco helps the Open Cybersecurity Schema Framework and is a launch companion of AWS Safety Lake
The Cisco Safe Technical Alliance helps the open ecosystem and AWS is a valued know-how alliance companion, with integrations throughout the Cisco Safe portfolio, together with SecureX, Safe Firewall, Safe Cloud Analytics, Duo, Umbrella, Internet Safety Equipment, Safe Workload, Safe Endpoint, Id Companies Engine, and extra.
Cisco Safe and AWS Safety Lake
We’re proud to be a launch companion of AWS Safety Lake, which permits clients to construct a safety knowledge lake from built-in cloud and on-premises knowledge sources in addition to from their non-public functions. With assist for the Open Cybersecurity Schema Framework (OCSF) customary, Safety Lake reduces the complexity and prices for patrons to make their safety options knowledge accessible to deal with a wide range of safety use circumstances equivalent to risk detection, investigation, and incident response. Safety Lake helps organizations combination, handle, and derive worth from log and occasion knowledge within the cloud and on-premises to offer safety groups better visibility throughout their organizations.
With Safety Lake, clients can use the safety and analytics options of their alternative to easily question that knowledge in place or ingest the OCSF-compliant knowledge to deal with additional use circumstances. Safety Lake helps clients optimize safety log knowledge retention by optimizing the partitioning of knowledge to enhance efficiency and cut back prices. Now, analysts and engineers can simply construct and use a centralized safety knowledge lake to enhance the safety of workloads, functions, and knowledge.
Cisco Safe Firewall serves as a corporation’s centralized supply of safety data. It makes use of superior risk detection to flag and act on malicious ingress, egress, and east-west visitors whereas its logging capabilities retailer data on occasions, threats, and anomalies. By integrating Safe Firewall with AWS Safety Lake, by Safe Firewall Administration Middle, organizations will be capable to retailer firewall logs in a structured and scalable method.
eNcore Shopper OCSF Implementation
The eNcore consumer offers a strategy to faucet into message-oriented protocol to stream occasions and host profile data from the Cisco Safe Firewall Administration Middle. The eNcore consumer can request occasion and host profile knowledge from a Administration Middle, and intrusion occasion knowledge solely from a managed gadget. The eNcore utility initiates the information stream by submitting request messages, which specify the information to be despatched, after which controls the message movement from the Administration Middle or managed gadget after streaming begins.

These messages are mapped to OCSF Community Exercise occasions utilizing a collection of transformations embedded within the eNcore code base, performing as each creator and mapper personas within the OCSF schema workflow. As soon as validated with an inside OCSF schema the messages are then written to 2 sources, first a neighborhood JSON formatted file in a configurable listing path, and second compressed parquet information partitioned by occasion hour within the S3 Amazon Safety Lake supply bucket. The S3 directories include the formatted log are crawled hourly and the outcomes are saved in an AWS Safety Lake database. From there you may get a visible of the schema definitions extracted by the AWS Glue Crawler, establish fieldnames, knowledge sorts, and different metadata related along with your community exercise occasions. Occasion logs will also be queried utilizing Amazon Athena to visualise log knowledge.
Get Began
To make the most of the eNcore consumer with AWS Safety Lake, first go to the Cisco public GitHub repository for Firepower eNcore, OCSF department.

Obtain and run the cloud formation script eNcoreCloudFormation.yaml.

The Cloud Formation script will immediate for extra fields wanted within the creation course of, they’re as follows:
Cidr Block: IP Tackle vary for the provisioned consumer, defaults to the vary proven beneath
Occasion Sort: The ec2 occasion dimension, defaults to t2.medium
KeyName A pem key file that may allow entry to the occasion
AmazonSecurityLakeBucketForCiscoURI: The S3 location of your Information Lake S3 container.
FMC IP: IP or Area Identify of the Cisco Safe Firewall Mangement Portal

After the Cloud Formation setup is full it might take anyplace from 3-5 minutes to provision assets in your surroundings, the cloud formation console offers an in depth view of all of the assets generated from the cloud formation script as proven beneath.

As soon as the ec2 occasion for the eNcore consumer is prepared, we have to whitelist the consumer IP deal with in our Safe Firewall Server and generate a certificates file for safe endpoint communication.
Within the Safe Firewall Dashboard, navigate to Search->eStreamer, to seek out the enable listing of Shopper IP Addresses which might be permitted to obtain knowledge, click on Add and provide the Shopper IP Tackle that was provisioned for our ec2 occasion. Additionally, you will be requested to provide a password, click on Save to create a safe certificates file in your new ec2 occasion.

Obtain the Safe Certificates you simply created, and replica it to the /encore listing in your ec2 occasion.

Use CloudShell or SSH out of your ec2 occasion, navigate to the /encore listing and run the command bash encore.sh take a look at


You’ll be prompted for the certificates password, as soon as that’s entered you must see a Profitable Communication message as proven beneath.

Run the command bash encore.sh foreground
This can start the information relay and ingestion course of. We are able to then navigate to the S3 Amazon Safety Lake bucket we configured earlier, to see OCSF compliant logs formatted in gzip parquet information in a time-based listing construction. Moreover, a neighborhood illustration of logs is on the market below /encore/knowledge/* that can be utilized to validate log file creation.

Amazon Safety Lake then runs a crawler activity each hour to parse and eat the logs information within the goal s3 listing, after which we are able to view the ends in Athena Question.

Extra data on configure and tune the encore eStreamer consumer will be discovered on our official web site, this contains particulars on how filter sure occasion sorts to focus your knowledge retention coverage, and pointers for efficiency and different detailed configuration settings.
Take part within the public preview
You may take part within the AWS Safety Lake public preview. For extra data, please go to the Product Web page and evaluation the Consumer Information.
re:Invent
If you are at AWS re:Invent, go see a demo video of the Safety Lake integrations within the Cisco Sales space #2411, from November 29 to December 2, 2022, on the Cloud, Community and Consumer Safety with Duo demo station.
Be taught extra about Cisco and AWS on the Cisco Safe Technical Alliance web site for AWS.
Acknowledgement
Thanks to Seyed Khadem-Djahaghi, who spend lengthy hours working with the beta to develop this integration and is the first for developer of eNore.
We’d love to listen to what you suppose. Ask a Query, Remark Under, and Keep Linked with Cisco Safe on social!
Cisco Safe Social Channels
Share:

