- Post History
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
3 hours ago
nderstanding the complexity of your IT assets and vulnerabilities is a critical step towards cyber resilience. We're here to help guide you through the process with practical insights and best practices.
Your use cases determine your deployment. Most start with one goal which is to understand all IT assets. You may move toward wanting to understand your vulnerabilities on these IT assets as well. All of this falls under CAASM. What is CAASM?
Cyber Asset Attack Surface Management (CAASM) is the technology focused on eliminating these asset visibility and exposure challenges. With CAASM you can achieve complete visibility over all your cyber assets, identify gaps in security faster, streamline manual processes to ultimately achieve the goal of being cyber resilient.
The Armis platform delivers on many foundational CAASM concepts:
- See all assets (internal and external) in your environment through integrations with existing tools. This includes all information technology (IT), Internet of Things (IoT) and operational technology (OT) assets.
- Uncover technical debt caused by end-of-service (EOS), end-of-life (EOL) or unpatched operating systems and applications that open additional attack vectors for bad actors.
- Identify gaps in security controls, because knowing how policies are or are not being enacted, is critical to understand the complete context associated with every asset.
- Enrich a CMDB with additional contextual information about known or possibly unknown assets on the network, so IT and Security teams can act quickly to remediate risky situations.
- Identify the scope of vulnerabilities, with a risk-based approach that uses threat intelligence and analytics to correlate asset exposure, the severity of vulnerabilities, and threat actor activity.
- Remediate issues: once a vulnerability, risk, or security gap is identified, it needs to be addressed immediately.
You can achieve a good understanding of IT assets through integrations only. Please follow Best Practice for Deployment Order to avoid issues when using integrations.
But let’s say you want to start working on the following use cases:
- Identify all IT devices that are not in compliance meaning they do not have endpoint software installed. This is critical for large BYOD programs.
- Identify all IoT devices.
- Identify all BMS and/or OT devices.
- Want to understand the traffic behavior of devices.
- Want to be able to research all connections a device is making.
- Want to identify rogue devices.
- Want to capture all activity for devices.
- Want to generate alerts based traffic triggers.
- Want to generate dynamic network diagrams of your network.
All of the above requires the deployment of Armis collectors connected to switches for passive traffic analysis. There are two ways of deploying collectors. The simplest is North/South only deployments. This deployment would be at data centers and at core switches.
Positives:
- Faster deployment
- Captures data on all devices communicating with the data center and Internet
- Requires the least number of collectors
Negatives:
- Does not capture traffic on all devices
- Does not capture lateral movement
- Does not capture East/West communications of devices
The second method is deploying to capture East/West traffic that includes North/South communications. The rule is you want to capture traffic as close to the endpoints as possible. This means connecting the collectors to distribution switches.
This is a multiple building/location environment. You want a collector at each distribution layer for each building/location plus collectors at the data center. You would typically have two distribution switches running in a pair. Depending on the traffic load, you can connect both switches to a single collector. This method will capture communications between access switches and traffic going to the data center/Internet. Many collectors are needed for the deployment type, but the positive is you get the majority of devices in your environment.
When configuring the SPAN/Mirror off of the distribution switches we prefer you to configure using interface spanning vs VLAN. The reason for this is network teams are always making changes to VLAN configuration this method will not provide you with complete coverage. If they spin up a new VLAN or modify the IDs then you will miss traffic after these changes. Interface spanning will help to identify all devices including the shadow IT devices. When the network team makes changes you will still see all devices.
Please consult with your Customer Success representative on how to achieve the best deployment. Your network design may be unique on how you process L2 and L3 data. The collector should be installed where L2 terminates and L3 begins. The goal is to capture as much traffic on endpoints as possible.