About (Edit profile)

This author has not yet filled in any details.
So far has created 1829 blog entries.

Collaboration Comes Together in San FranCISCO Cisco Interns on October 31, 2023 at 12:00 pm

This post was authored by Mira Kohen Morhayim, a recent Persona Audience Marketing Intern on the Customer Solutions Marketing team.

Readout Week is the culmination of a Cisco Marketing Internship,… Read more on Cisco Blogs

This post was authored by Mira Kohen Morhayim, a recent Persona Audience Marketing Intern on the Customer Solutions Marketing team.

Readout Week is the culmination of a Cisco Marketing Internship, where teams present the projects they’ve worked on throughout the program. This year, more than 30 interns and I travelled to Cisco’s San Jose headquarters for our presentations and also visited San Francisco, the city where Cisco got its name. Little did I know that this week would end up being one of the most unforgettable experiences of my life.

At the start of the summer, we met with our program managers to learn that we would be split into six groups tasked with coming up with recommendations to improve Cisco’s marketing efforts in a key area of focus: its sustainability story. Each group was assigned to represent an area of Cisco’s product portfolio, ours being Collaboration. Collaboration was not just the business focus of our Readout project but a challenge we had meeting weekly as a team of interns from the U.K. and Singapore, finding compatible times for us and the sustainability experts we needed input from in the lead-up to Readout Week.

At the end of July, we travelled to San Jose (My first time in the U.S.!) to present our group project live on Cisco TV. Leading up to the Readout, we had a Q&A session with Cisco’s Chief Marketing Officer that was a super insightful and fruitful conversation. She got to tell us about some of her career experiences as well as give us some feedback and recommendations for our presentation. It was nerve-wracking but an incredible opportunity to present our recommendations for the company in front of an open audience. Once we shared our project, we took questions from the audience, including several VPs, and from the audience watching virtually — a true hybrid Cisco experience.

One of the highlights of the trip was meeting other interns from various nations as well as the program directors who coordinated the internship program and were critical in fostering a welcoming and inclusive environment from the start. It was amazing to see how, despite our diverse backgrounds, we all shared a passion for marketing, innovation, and technology. When we met face-to-face, we all had that big connection, yet everyone’s unique personalities really shined.

Throughout the week, the other interns and I got to know each other better through icebreakers, meals together, social events, and exploring the San Jose and San Francisco offices. I expected to be wowed by the San Jose campus, but the technology in the San Francisco office was mind-blowing! We also participated in a volunteer event with Rise for Hunger, packaging 10,000 meals to help end hunger globally. It was such a rewarding experience to come together as a team and put our efforts into giving back.

On our last day together, we got to see the entire city of San Francisco and all the hallmarks of the city. I was absolutely blown away by seeing the Golden Gate Bridge — the inspiration for Cisco’s logo — in person with its incredible engineering, architecture, and breathtaking views of the city. We also visited Alcatraz Island, explored North America’s oldest Chinatown, and watched the sea lions as we enjoyed the sea breeze and lively atmosphere on Pier 39. That evening, we had a farewell dinner by a marina, greeted by the yachts and the bay before everyone began travelling home.

As I left the States, I thought to myself, ‘This is why I love working here.” When applying for this position, I never thought of myself going on TV and presenting in front of so many people. But throughout time, with the lead of our program managers, mentors, and their feedback, they instilled this confidence in me that I know how to stand in front of people, speak publicly, and, most importantly, I can convey a message. I had just proven that to myself at one of the world’s top companies.

I also reminisced about the amazing opportunities I had just experienced over the past week, the incredible cohort of marketing interns, and the executives who were actually there to listen. It was such a welcoming and accepting feeling that continued even when I went home, where I hopped on a meeting with a new team. Two people told me they had watched our presentation, which made them reflect on their sustainability choices and how they conducted their current marketing activities. It was a really nice moment to experience as my internship is coming to a close.

Overall, I couldn’t have asked for a better mix of work and fun, from growing professionally to exploring San Francisco’s amazing culture. This trip really left a lasting impression on me as an intern. It ignited a passion for my work, gave me a profound appreciation for the power of travel, and made me understand how many incredible possibilities exist in the realm of this company.

Are you ready to explore the possibilities within Cisco? Browse benefits, perks, careers, and more.

Subscribe to the We Are Cisco Blog.

Share

  Mira M. discusses the culmination of a Cisco Marketing Internship: Readout Week and her other #LoveWhereYouWork moments from Intern Week in San Jose.  Read More Cisco Blogs 

By |2023-11-01T00:50:26+00:00November 1, 2023|Cisco: Learning|0 Comments

Determining the 10 most critical vulnerabilities on your network Ben Nahorney on October 31, 2023 at 12:00 pm

When it comes to staying on top of security events, a good application that alerts on security events is better than none. It stands to reason then that two would be better than one, and so on.

More… Read more on Cisco Blogs

When it comes to staying on top of security events, a good application that alerts on security events is better than none. It stands to reason then that two would be better than one, and so on.

More data can be a double-edged sword. You want to know when events happen across different systems and through disparate vectors. However alert fatigue is a real thing, so quality over quantity matters. The real power of having event data from multiple security applications comes when you can combine two or more sources to uncover new insights about your security posture.

For example, let’s take a look at what happens when we take threat intelligence data available in Cisco Vulnerability Management and use it to uncover trends in IPS telemetry from Cisco Secure Firewall.

This is something that you can do yourself if you have these Cisco products. Start by looking up the latest threat intelligence data in Cisco Vulnerability Management, and then gather Snort IPS rule data for vulnerabilities that have alerted on your Secure Firewall. Compare the two and you may be surprised with what you find.

Collect the vulnerability threat intelligence

It’s very easy to stay on top of a variety of vulnerability trends using the API Reference that is available in Cisco Vulnerability Management Premier tier. For this example, we’ll use a prebuilt API call, available in the API Reference.

This API call allows you to set a risk score and choose from a handful of filters that can indicate that a vulnerability is a higher risk:

Active Internet Breach—The vulnerability has been used in breach activity in the wild.
Easily Exploitable—It is not difficult to successfully exploit the vulnerability.
Remote Code Execution—If exploited, the vulnerability allows for arbitrary code to be run on the compromised system from a remote location.

To obtain a list of high-risk CVEs, we’ll set the risk score to 100, enable these three filters, and then run a query.

With the output list in hand, let’s go see which of these are triggering IPS alerts on our Secure Firewall.

Obtaining IPS telemetry from Secure Firewall is easy and there are a several of ways that you can organize and export this data. (Setting up reporting is beyond the scope of this example,  but is covered in the Cisco Secure Firewall Management Center Administration Guide.) In this case we will look at the total number of alerts seen for rules associated with CVEs.

Naturally, if you’re doing this within your own organization, you’ll be looking at alerts seen from firewalls that are part of your network. Our example here will be slightly different in that we’ll look across alerts from organizations that have opted in to share their Secure Firewall telemetry with us. The analysis is similar in either case, but the added bonus with our example is that we’re able to look at a larger swath of activity across the threat landscape.

Let’s filter the IPS telemetry by the CVEs pulled from the Cisco Vulnerability Management API. You can do this analysis with whatever data analytics tool you prefer. The result in this case is a top ten list of high-risk CVEs that Secure Firewall has alerted on.

CVE
Description
1
CVE-2021-44228
Apache Log4j logging remote code execution attempt
2
CVE-2018-11776
Apache Struts OGNL getRuntime.exec static method access attempt
3
CVE-2014-6271
Bash CGI environment variable injection attempt
4
CVE-2022-26134
Atlassian Confluence OGNL expression injection attempt
5
CVE-2022-22965
Java ClassLoader access attempt
6
CVE-2014-0114
Java ClassLoader access attempt
7
CVE-2017-9791
Apache Struts remote code execution attempt (Struts 1 plugin)
8
CVE-2017-5638
Apache Struts remote code execution attempt (Jakarta Multipart parser)
9
CVE-2017-12611
Apache Struts remote code execution attempt (Freemaker tag)
10
CVE-2016-3081
Apache Struts remote code execution attempt (Dynamic Method Invocation)

What’s interesting here is that, while this is a list of ten unique CVEs, there are only five unique applications here. In particular, Apache Struts comprises 5 of the top 10.

By ensuring that these five applications are fully patched, you cover the top ten most frequently exploited vulnerabilities that have RCEs, are easily exploitable, and are known to be used in active internet breaches.

In many ways analysis like this can greatly simplify the process of deciding what to patch. Want to simplify the process even further? Here are a few things to help.

Check out the Cisco Vulnerability Management API for descriptions of various API calls and make sample code that you can use, written from your choice of programming languages.

Want to run the analysis outlined here? Some basic Python code that includes the API calls, plus a bit of code to save the results, is available here on Github. Information on the CVEs associated with various Snort rules can be found in the Snort Rule Documentation.

We hope this example is helpful. This is a fairly basic model, as it’s meant for illustrative purposes, so feel free to tune the model to best suit your needs. And hopefully combining these sources provides you with further insight into your security posture.

Methodology

This analysis looks at the standard text rules and Shared Object rules in Snort, both provided by Talos. We compared data sets using Tableau, looking at Snort signatures that only belong to the Connectivity over Security, Balanced, and Security over Connectivity base policies.

The IPS data we’re using comes from Snort IPS instances included with Cisco Secure Firewall. The data set covers June 1-30, 2023, and the Cisco Vulnerability Management API calls were performed in early July 2023.

Looking at the total number of alerts will show us which rules alert the most frequently. In-and-of-itself this isn’t a great indicator of severity, as some rules cause more alerts than others. This is also why we’ve looked at the percentage of organizations that see an alert in past analysis instead. However, this time we compared the total number of alerts against a list of vulnerabilities that we know are severe thanks to the risk score and other variables. This makes the total number of alerts more meaningful within this context.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Secure on social!

Cisco Secure Social Channels

InstagramFacebookTwitterLinkedIn

Share

  Learn how to take threat intelligence data available in Cisco Vulnerability Management and use it to uncover trends in Cisco Secure Firewall, uncovering new insights.  Read More Cisco Blogs 

By |2023-11-01T00:50:25+00:00November 1, 2023|Cisco: Learning|0 Comments

Cisco’s Catalyst SD-WAN: Now available through Azure Marketplace Multiparty Partner Offers Program Amy Bahlo on October 31, 2023 at 3:00 pm

As a partner-led organization, with over 90 percent of our business conducted through Cisco partners, we are thrilled to be part of Microsoft’s new Multiparty Private Offers (MPO) program. The MPO… Read more on Cisco Blogs

As a partner-led organization, with over 90 percent of our business conducted through Cisco partners, we are thrilled to be part of Microsoft’s new Multiparty Private Offers (MPO) program. The MPO program empowers ISVs like Cisco and our partners to collaborate in creating customer offers and conducting transactions on Microsoft’s Azure Marketplace.

MPO provides customers with a seamless marketplace experience for purchasing essential software and services needed to run their businesses through their trusted partners. Additionally, customers have the option to reduce their Microsoft Azure Consumption Commitment (MACC) to effectively manage their IT budgets, as every eligible dollar spent on Cisco solutions through MPO contributes towards their MACC. Azure Marketplace streamlines the procurement process by offering consolidated billing and reporting for all their SaaS spend with Microsoft.

Furthermore, MPO empowers Cisco partners to generate upfront revenue by streamlining the transaction process for Cisco solutions available on the Azure Marketplace. Here’s how it operates: Cisco publishes an offer on the Azure Marketplace, and a Cisco partner subsequently presents this offer directly to their customers.

Cisco Hosted Catalyst SD-WAN first available Cisco MPO offer

Cisco Hosted Catalyst SD-WAN is the inaugural Cisco product officially included in the MPO program. Catalyst SD-WAN’s Cloud on Ramp for Azure vWAN is perfectly suited for enterprises of all sizes that are transitioning workloads to the cloud or prioritizing cloud-based workloads. In addition, Catalyst SD-WAN’s integration with Microsoft Sentinel presents a dashboard to visualize Cisco SD-WAN Security data. Together, our customers can expand their infrastructure into public clouds, reaping the full advantages of their investments in Cisco and Microsoft. Moreover, customers who operate their Cisco SD-WAN Fabric in Azure can allocate their spending toward their MACC.

“Microsoft Azure Multiparty Private Offers represent a win-win for our customers and partners. Cisco SD-WAN is market leading and has been recognized by IDC Marketscape for SD-WAN Infrastructure and by Gartner® in the 2023 Magic Quadrant™ for SD-WAN. And now, our customers can seamlessly access Cisco Catalyst SD-WAN in the Azure Marketplace.

Customers looking to migrate their workloads to Azure can seamlessly connect from branches, campuses, or data centers with Cisco’s Catalyst 8000 family and can continue to leverage the trusted partners they rely on, all while effectively optimizing their MACC spending. Cisco’s active participation underscores our joint commitment to driving agility in our shared customer networks and hybrid environments, solidifying the Microsoft and Cisco partnership.”

—Vikas Butaney, SVP | General Manager, Cisco SD-WAN, Multi-Cloud and Industrial IoT

Furthermore, rest assured that we have additional Cisco SaaS products in the pipeline for inclusion in the MPO program. Stay tuned for more exciting developments.

Learn more about

Cisco DNA Software for SD-WAN and Routing

on the Azure Marketplace

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!

Cisco Partners Facebook  |  @CiscoPartners Twitter  |  Cisco Partners LinkedIn

Share

  As a partner-led organization, with over 90 percent of our business conducted through Cisco partners, we are thrilled to be part of Microsoft's new Multiparty Private Offers (MPO) program. The MPO program empowers ISVs like Cisco and our partners to collaborate in creating customer offers and conducting transactions on Microsoft's Azure Marketplace.  Read More Cisco Blogs 

By |2023-11-01T00:50:24+00:00November 1, 2023|Cisco: Learning|0 Comments

Preventing E-Communication Fines in Financial Services Adam Neiberg on October 31, 2023 at 12:00 pm

A new use case in the annual refresh of Cisco Portfolio Explorer for financial services is e-communication compliance. This hot button issue is in the news it seems almost weekly. Financial… Read more on Cisco Blogs

A new use case in the annual refresh of Cisco Portfolio Explorer for financial services is e-communication compliance. This hot button issue is in the news it seems almost weekly. Financial institutions, mainly Wall Street firms, have been heavily fined for using unauthorized communication channels and not recording these communications.

The punitive financial damage to these Wall Street firms so far has been over $2.5 billion dollars. More fines are likely to come and to a wider base of financial institutions as regulatory bodies are just getting started in enforcement in this age of hybrid work and plethora of communication channels.

Communication compliance regulations

Compliance requirements for communications in financial services has always been very strict and certain sub verticals such as capital markets, trading and investing and insurance even stricter. Fast forward to today, and the financial services sector faces more regulations than ever. This is due to different regulatory bodies but also district, state, national, zonal and even industry agencies.  With the vast array of digital communication channels, mobile phones, text and chat, video, social media, it is overwhelming.

The most common compliance laws fall into two camps:

Surveillance and supervision. These laws govern internal policies, review, audit trail, retention and internal monitoring.
Digital communications. These deal with content, audiences and communication channels.

The main U.S. laws that impact financial services are:

SEC

Securities & Exchange Act, Rule 17a-4(b)(4). This law requires broker-dealers to keep the originals of all the communications they receive. They must also keep copies of all communications they send that are related to “business as such” for at least three years. The first two years of these records must be kept easily accessible. Updated Rule 17a-4 requires firms to retain and preserve all transactions and official business records, which includes all communications. These electronic records must be stored in a secure, non-erasable place.
Commodities Futures Trading Commission, CFTC SEA 15 F (g) (1). For the trading of commodity futures broker-dealers must keep all daily trading communications related to security-based swaps, including email, instant messages, phone calls and social media. All regulated records must be kept for the period required by the commission.

FINRA

FINRA Notice 10-06. This law requires firms to adopt policies and procedures to ensure that people who communicate for business via social channels are properly supervised. Anyone communicating through these channels must also be provided with training. And they must not put investors at risk.
FINRA Notice 07-59Similar to 10-06, this notice provides additional guidance on reviewing and supervising electronic communications.

The SEC and FINRA are serious about enforcement.  Noncompliance has led to fines and brand damage. While the actions were caused by broker-dealers and investment advisers who kept poor records and used unapproved tools the institutions were unable to record and preserve their messages.

It is not due to lack of internal controls, company policies, or related trainings, but most often it’s due to unauthorized use by employees. Unfortunately, the companies are then at fault and liable for the fines. Not all companies are standing by.

Drastic measures

An American investment firm has taken action against its own employees in the form of claw backs. They held training sessions explaining when bankers should move communication from personal devices to company communication channels, and instituted a penalty system. Penalties are scored according to a points system that considers the number of messages sent, the banker’s seniority, and whether they received prior warnings. When warranted, they either claw back funds from previous bonuses or deducting money from future pay—with a few penalties approaching seven figures.

Sometimes claw backs aren’t enough, and losing one’s job is a possibility for breaking compliance rules and putting the institution at risk. Another large investment bank fired its transaction banking executives, including the head of a business unit, over compliance lapses. Correspondingly, they terminated several leaders from this unit who communicated on unauthorized channels and didn’t comply with an internal review. A handful of companies have fired some of their top commodities traders over their use of personal apps.

Fines are spreading

It was once thought that the administration of fines would be limited only to financial regulators or just in the United States, but that has not proven to be the case. Ofgem, the U.K.’s energy regulator, fined an American investment firm £5.4M ($6.9M) due to communications on energy market transactions made by wholesale traders on privately owned phones in a breach of rules designed to protect consumers, ensure market transparency, and prevent insider trading.

This fine and the source of the penalty may send “shock waves” through the banking industry, Rob Mason, the director of regulatory intelligence at Global Relay, told Bloomberg.  “It puts firms on warning that it’s not just the financial regulators they need to be wary of,” said Mason. The energy traders discussed transactions over WhatsApp on privately owned phones between January 2018 and March 2020, and the bank failed to record and save those communications.

Best practices

Compliance laws for digital communications are complex and constantly changing. To stay compliant, consider adopting these best practices:

Determine which laws are relevant to your organization
Have a clear understanding of how those laws are evolving
Hire compliance officers or consultants to help you understand how those laws impact your management of digital communications
Evaluate your enterprise compliance solution with all stakeholders to see if it meets compliance requirements for all your communications channels
Review corporate policies and procedures for the use of communication devices and platforms, including “bring your own device” (BYOD)
Implement and review employee compliance training programs

In reality, one of the most effective ways financial institutions can safeguard themselves is by training employees to never use their personal devices for business. Taking that a step further recently one European bank has started disabling text capabilities on company-issued phones.

What’s ahead

We’ll likely see more regulators in the United States and abroad focus on both global financial services and smaller institutions. Regulators will probably increase fines for repeat violators and cite more instances of “failure to supervise” as well.

So how do companies strike the right balance between securing communications and allowing convenience? Implementing some of the best practices mentioned above and finding a partner that can help you comply with laws related to recording and recordkeeping is an important next step in the process.

Cisco can help

Cloud calling allows institutions to move their phone systems to the cloud, enabling users to access their phone system from anywhere, on any device, and eliminates the need for on-premise physical infrastructure. With Cisco Cloud Calling, gain flexibility, scalability, cost savings while preserving key features such as call recording, call forwarding, voicemail transcription, and analytics. It helps businesses streamline their communication infrastructure, reduce costs, and enhance productivity across their workforce.

Cisco Cloud Calling can now take your business calling and collaborative experiences on the go with Webex Go with AT&T. This joint partnership extends Webex Calling capabilities to AT&T provided data plans and mobile phones via a single business phone number that becomes your identity for all your phone and messaging Communications.

Pairing with Theta Lake a leading provider of compliance and risk management solutions for video and audio communication is a great next step. Their AI-powered platform helps financial institutions automatically detect and mitigate risks in their communications. Theta Lake’s technology focuses on areas like data loss prevention, regulatory compliance, and surveillance, enabling institutions to streamline their compliance processes and ensure secure and compliant communication across all channels.

Cisco Webex Connect a centralized, enterprise-grade CPaaS platform helps you deliver richer customer experiences across numerous digital communication channels. It includes a flexible integration framework that lets you connect the information in your backend systems with digital channels such as WhatsApp, SMS, email and more. Integrating with Webex Connect, you can easily access and apply the data you need to trigger contextual interactions across the customer journey.

Visit Cisco Portfolio Explorer for Financial Services

Share

  $2.5 billion dollars worth of fines have been levied against financial institutions due to employees using unauthorized communication channels and not recording these communications. What can be done to try and prevent this from happening.  Read More Cisco Blogs 

By |2023-11-01T00:50:24+00:00November 1, 2023|Cisco: Learning|0 Comments

The Power of AI, New Products, and Partner Excellence Kristyn Hogan on October 31, 2023 at 5:30 pm

Did you attend or tune-in to WebexOne last week?  I hope you are as excited as I am about the innovation taking place. An even more powerful and comprehensive technology platform at the core of our … Read more on Cisco Blogs

Did you attend or tune-in to WebexOne last week?  I hope you are as excited as I am about the innovation taking place. An even more powerful and comprehensive technology platform at the core of our business fuels our channel strategy and provides partners with differentiated collaboration experiences to deliver to customers.

Here are a few key takeaways from last week

Groundbreaking AI and hybrid work announcements! 

We have been innovating with AI for several years, bringing language intelligence, audio intelligence and video intelligence to our product suite. Last week we took AI leadership in collaboration to a new level by announcing our plans to make AI pervasive across the entire platform with real-time media models, the new Webex AI Assistant, Webex AI Codex, and Super Resolution. We have truly reimagined and reinvented our portfolio to be AI-enabled, making Webex smarter, more efficient, and easier to use in every way.

New products and amazing features across the portfolio.

To help customer reimagine workspaces our device portfolio has been enhanced with Cisco Room kit EQX, a dual-screen room experience creating an effortless way to deploy virtually, in-person experiences in flagship spaces, and the Bang & Olufsen Cisco 950, a new premium wireless ear bud solution to complement our already extensive headset portfolio. There are also twenty new feature enhancements to reimagine work with Webex Suite, eighteen new Contact Center and CPaaS features announcements to reimagine customer experiences, and security and manageability features to help customer reimagine IT. For the full rundown and details check the Salesconnect Launch and Events page.

Our partners are AWESOME!

The depth and support of our channel community was on full display with over 550 partners attending in-person and 4200 tuning-in virtually. I had the opportunity to engage with many of our partners during 1:1 meetings and dedicated partner sessions and the feedback was amazing. We also hosted an award session to recognize a few of the most innovative Collaboration partners through our Webex Partner Awards. Check out the 2023 award categories and please join me in congratulating the winners.

Our channel strategy is built around our best in the world Webex platform, and we are intently focused on driving simplicity, profitability, and earning your mindshare. There is so much progress being made in these areas, I want to highlight a few key updates that will get you excited for Q2 and our next event, Partner Summit.

Simplicity through Wholesale:

Our Wholesale offer is built to easily integrate Webex Calling into Partner-led managed services, by leveraging the market power of Cisco’s providers around the world. The partner feedback has been amazing, and interest continues to build due to the flexibility, predictable pricing, and frictionless growth that the Wholesale offer delivers. It enables a wide variety of partner types to create use cases addressing a wide range of customer segments and verticals. If you are looking for a winning collaboration engine to accelerate your managed services collaboration practice, you need to learn more!

Profitability with LCI 2.0

Lifecycle Incentives 2.0 was just launched! This is a major evolution of our incentives portfolio which rewards partners for focusing on software and recurring revenue streams. LCI 2.0 is now completely telemetry-based, allowing partners to focus on what really matters, which is working with customers and not submitting claims. Webex Contact Center is one of three Collaboration use cases launching and will revolutionize Cisco Collaboration incentives.

Mindshare through enablement:

We know that announcing new features, offers and programs of this magnitude is only the first step. To earn your mindshare, we need to train and enable your teams. As you experienced with FY23 Partner Sales Kickoff our channel teams are hard at work bringing together the programs, resources, tools for your success. It does not stop there. Be sure to stay plugged in to Partner Readiness page on Salesconnect and attend our weekly regional enablement sessions to keep you in the know.

There is so much to be excited about and we are going to tie it all together at Cisco Partner Summit 2023!

If you are joining us in-person in Miami Beach, do not miss our Business Impact Session where Javed Khan, and Brett Harrison, and I will discuss the latest technology announcements, channel enablement strategy, and profitability programs. Plus, we will be joined by Eileen Collins, the first-ever female pilot to command a space shuttle mission!

Add this session to your agenda today!
BIS11 – Cisco Collaboration Session: The Rocket Fuel for Growth
Wednesday, November 8th
2:00 – 2:45pmET

Cannot wait to see you there!

Register for the Cisco Partner Summit 2023 Live Digital Broadcast!

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!

Cisco Partners Facebook  |  @CiscoPartners Twitter  |  Cisco Partners LinkedIn

Share

  I hope you are as excited as I am about the innovation taking place. An even more powerful and comprehensive technology platform at the core of our business fuels our channel strategy and provides partners with differentiated collaboration experiences to deliver to customers.  Read More Cisco Blogs 

By |2023-11-01T00:50:23+00:00November 1, 2023|Cisco: Learning|0 Comments

The myth of the long-tail vulnerability Ben Nahorney on October 30, 2023 at 12:00 pm

Modern-day vulnerability management tends to follow a straightforward procedure. From a high level, this can be summed up in the following steps:

Identify the vulnerabilities in your… Read more on Cisco Blogs

Modern-day vulnerability management tends to follow a straightforward procedure. From a high level, this can be summed up in the following steps:

Identify the vulnerabilities in your environment
Prioritize which vulnerabilities to address
Remediate the vulnerabilities

When high-profile vulnerabilities are disclosed, they tend to be prioritized due to concerns that your organization will be hammered with exploit attempts. The general impression is that this malicious activity is highest shortly after disclosure, then decreases as workarounds and patches are applied. The idea is that we eventually reach a critical mass, where enough systems are patched that the exploit is no longer worth attempting.

In this scenario, if we were to graph malicious activity and time, we end up with what is often referred to as a long-tail distribution. Most of the activity occurs early on, then drops off over time to form a long tail. This looks something like the following:

A long tail distribution of exploit attempts sounds reasonable in theory. The window of usefulness for an exploit is widest right after disclosure, then closes over time until bad actors move on to other, more recent vulnerabilities.

But is this how exploitation attempts really play out? Do attackers abandon exploits after a certain stage, moving on to newer and more fruitful vulnerabilities? And if not, how do attackers approach vulnerability exploitation?

Our approach

To answer these questions, we’ll look at Snort data from Cisco Secure Firewall. Many Snort rules protect against the exploitation of vulnerabilities, making this a good data set to examine as we attempt to answer these questions.

We’ll group Snort rules by the CVEs mentioned in the rule documentation, and then look at CVEs that see frequent exploit attempts. Since CVEs are disclosed on different dates, and we’re looking at alerts over time, the specific time frame will vary. In some cases, the disclosure date is earlier than the range our data set covers. While we won’t be able to examine the initial disclosure period for these, we’ll look at a few of these as well for signs of a long tail.

Finally, looking at a count of rule triggers can be misleading—a few organizations can see many alerts for one rule in a short time frame, making the numbers look larger than they are across all orgs. Instead, we’ll look at the percentage of organizations that saw an alert. We’ll then break this out on a month-to-month basis.

Log4J: The 800-pound gorilla

The Log4J vulnerability has dominated our vulnerability metrics since it was disclosed in December 2021. However, looking at the percentage of exploit attempts each month since, there was neither a spike in use right after disclosure, nor a long tail afterwards.

That first month, 27 percent of organizations saw alerts for Log4J. Since then, alerts have neither dropped off nor skyrocketed from one month to the next. The percent of organizations seeing alerts range from 25-34 percent through June 2023, averaging out at 28 percent per month.

Perhaps Log4J is an exception to the rule. It’s an extremely common software component and a very popular target. A better approach might be to look at a lesser-known vulnerability to see how the curve looks.

Spring4Shell: The Log4J that wasn’t

Spring4Shell was disclosed at the end of March 2022. This was a vulnerability in the Spring Java framework that managed to resurrect an older vulnerability in JDK9, which had initially been discovered and patched in 2010. At the time of Spring4Shell’s disclosure there was speculation that this could be the next Log4J, hence the similarity in naming. Such predictions failed to materialize.

We did see a decent amount of Spring4Shell activity immediately after the disclosure, where 23 percent of organizations saw alerts. After this honeymoon period, the percentage did decline. But instead of exhibiting the curve of a long tail, the percentages have remained between 14-19 percent a month.

Keen readers will notice the activity in the graph above that occurs prior to disclosure. These alerts are for rules covering the initial, more-than-a-decade-old Java vulnerability, CVE-2010-1622. This is interesting in two ways:

The fact that these rules were still triggering monthly on a 13-year-old vulnerability prior to Spring4Shell’s disclosure provides the first signs of a potential long tail.
It turns out that Spring4Shell was so similar to the previous vulnerability that the older Snort rules alerted on it.

Unfortunately, the time frame of our alert data isn’t long enough to say what the initial disclosure phase for CVE-2010-1622 looked like. So since we don’t have enough information here to draw a conclusion, what about other older vulnerabilities that we know were in heavy rotation?

ShellShock: A classic

It’s hard to believe, but the ShellShock vulnerability recently turned nine. By software development standards this qualifies it for senior citizen status, making it a perfect candidate to examine. While we don’t have the initial disclosure phase, activity remains high to this day.

Our data set begins approximately seven years after disclosure, but the percentage of organizations seeing alerts ranges from 12-23 percent. On average across this timeframe, about one in five organizations see ShellShock alerts in a month.

A pattern emerges

While we’ve showcased 3-4 examples here, a pattern does emerge when looking at other vulnerabilities, both old and new. For example, here is CVE-2022-26134, a vulnerability discovered in Atlassian Confluence in June 2022.

Here is ProxyShell, which was initially discovered in August 2021, followed by two more related vulnerabilities in September 2022.

And here is another older, commonly targeted vulnerability in PHPUnit, originally disclosed in June 2017.

Is the long tail wagging the dog?

What emerges from looking at vulnerability alerts over time is that, while there is sometimes an initial spike in usage, they don’t appear to decline to a negligible level. Instead, vulnerabilities stick around for years after their initial disclosure.

So why do old vulnerabilities remain in use? One reason is that many of these exploitation attempts are automated attacks. Bad actors routinely leverage scripts and applications that allow them to quickly run exploit code against a large swaths of IP addresses in the hopes of finding vulnerable machines.

This is further evidenced by looking at the concentration of alerts by organization. In many cases we see sudden spikes in the total number of alerts seen each month. If we break these months down by organization, we regularly see that alerts at one or two organizations are responsible for the spikes.

For example, take a look at the total number of Snort alerts for an arbitrary vulnerability. In this example, December was in line with the months that preceded it. Then in January, the total number of alerts began to grow, peaking in February, before declining back to average levels.

The cause of the sudden spike, highlighted in light blue, is one organization that was hammered by alerts for this vulnerability. The organization saw little-to-no alerts in December before a wave hit that lasted from January through March. It then completely disappeared by April.

This is a common phenomenon seen in overall counts (and why we don’t draw trends from this data alone). This could be the result of automated scans by bad actors. These attackers may have found one such vulnerable system at this organization, then proceeded to hammer it with exploit attempts in the months that followed.

So is the long tail a myth when it comes to vulnerabilities? It certainly appears so—at least when it comes to the types of attacks that target the perimeter of an organization. The public facing applications that reside here present a large attack surface. Public proof-of-concept exploits are often readily available and are relatively easy to fold into attacker’s existing automated exploitation frameworks. There’s little risk for an attacker involved in automated exploit attempts, leaving little incentive to remove exploits once they’ve been added to an attack toolkit.

What is left to explore is whether long-tail vulnerabilities exist in other attack surfaces. The fact is that there are different classes of vulnerabilities that can be leveraged in different ways. We’ll explore more of these facets in the future.

It only takes one

Finding that one vulnerable, public-facing system at an organization is a needle-in-a-haystack operation for attackers, requiring regular scanning to find it. But all it takes is one new system without the latest patches applied to give the attackers an opportunity to gain a foothold.

The silver lining here is that a firewall with an intrusion prevention system, like Cisco Secure Firewall, is designed specifically to prevent successful attacks.  Beyond IPS prevention of these attacks, the recently introduced Cisco Secure Firewall 4200 appliance and 7.4 OS bring enterprise-class performance and a host of new features including SD-WAN, ZTNA, and the ability to detect apps and threats in encrypted traffic without decryption.

Also, if you’re looking for a solution to assist you with vulnerability management, Cisco Vulnerability Management has you covered. Cisco Vulnerability Management equips you with the contextual insight and threat intelligence needed to intercept the next exploit and respond with precision.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Secure on social!

Cisco Secure Social Channels

InstagramFacebookTwitterLinkedIn

Share

  A long tail distribution of exploit attempts sounds reasonable. But is this how exploitation attempts really play out? Do attackers abandon exploits after a certain stage? To answer these questions, we’ll look at Snort data from Cisco Secure Firewall.  Read More Cisco Blogs 

By |2023-10-30T23:50:02+00:00October 30, 2023|Cisco: Learning|0 Comments

Cisco Networking Academy introduces Professional Skills – empowering tomorrow’s leaders Dave Free on October 30, 2023 at 12:00 pm

Cisco Networking Academy started with a vision to develop the workforce of the future, one student at a time. Over the years, we have developed and launched technical courses in networking,… Read more on Cisco Blogs

Cisco Networking Academy started with a vision to develop the workforce of the future, one student at a time. Over the years, we have developed and launched technical courses in networking, cybersecurity, data science, and more, turning our vision into a reality.

Technical skills alone are not enough

Problem-solving skills, the ability to work on a team, and communication skills were listed among the top five attributes employers look for on a candidate’s resume in Job Outlook 2023 published by the National Association of Colleges and Employers.

According to Strategic human resource management (SHRM):

97 percent of employers surveyed said that interpersonal skills are either as important or more important than hard skills, and
89 percent of employees fail because of a lack of interpersonal skills, such as professionalism or the ability to get along with others.

Additionally, companies are prioritizing candidates that have strong technical and interpersonal skills. Put simply, they want to employ people withwell-rounded skills with the ability to communicate, collaborate, and adapt.

Trent Dorroh, Leader of Cisco’s Talent Bridge Program, focuses on connecting our Cisco Channel Partners and Distributors with a diverse pool of talent. He has deep insight into employers’ needs. We asked Trent what qualities employers look for in candidates.

“We consistently hear that employers want to hire technical candidates who are also well-rounded individuals. They stress the importance of needing collaborative team members who can also effectively communicate both internally and externally. The Professional Skills course package offered by Cisco Networking Academy offers a foundation for these candidates looking to enhance their skills and differentiate themselves.”

At Cisco Networking Academy, we strive to provide educational resources that set up our students for success in the workplace.

This is why we recently released a new category of courses: Professional Skills. Professional Skills are essential interpersonal skills for success in the workplace. Our courses are designed to complement technical training and equip you with skills to thrive in the workplace.

Professional Skills are free, online, self-paced courses

Versatile, practical, and empowering

Our new Professional Skills courses focus on skill-building in three areas:

Core Skills: essential skills for any professional, regardless of industry
Entrepreneurship: entrepreneurial skills and a solution-oriented approach to problem solving
English for IT: English language skills to become proficient in tech phrases and terminology and prepare for the English for IT B2/GST 59-75 certification exam.

This initial Professional Skills release features four courses, with more planned in the future.

Cisco Networking Academy’s new Professional Skills courses are steppingstones to unlocking a student’s true potential. In our fast-paced and interconnected world, the importance of technical and interpersonal skills cannot be overstated. Students and professionals who develop both skills are setting themselves up for success to be invaluable contributors and future leaders.

Learn more about Professional Skills today.

Share

  Introducing the new Professional Skills courses by Cisco Networking Academy, designed to complement technical training, these courses focus on developing essential interpersonal skills for success in the workplace.  Read More Cisco Blogs 

By |2023-10-30T23:50:01+00:00October 30, 2023|Cisco: Learning|0 Comments

An Anchor in the Race John Brookbank on October 30, 2023 at 7:46 pm

The theme for DistiNext 2023 was Growing Together. This theme ties perfectly into our theme for Americas Distribution, Going Hypersonic to Fuel Partner Success.

As relay racers run down the track,… Read more on Cisco Blogs

The theme for DistiNext 2023 was Growing Together. This theme ties perfectly into our theme for Americas Distribution, Going Hypersonic to Fuel Partner Success.

As relay racers run down the track, they rely on each other for speed, agility, and accuracy to gracefully pass the baton from teammate to teammate. Similarly, we must work together to ensure we reach the finish line together and, as often as possible, first! In racing, the fourth and last runner of the race is called the anchor. This runner is typically the fastest and strongest member of the team. This runner is often called on to make up the difference in time for the other three runners and leave it all on the track to win.

Growing Together

Although I’d love to say we at Cisco are the anchor for our distributors, I have been in distribution long enough to know that our mutual efforts enable us to look after each other. After all, a good anchor means they’re a good watchman, a strategic thinker, and a confided partner to everyone on the team.

Andrew Sage, VP of Global Distribution Sales, shared a few of his top priorities. I’d like to highlight three of them which align well with the priorities for our Americas team.

Foundational Listening

We want to help you build up strong foundations in your partnerships. One of the ways we are going to enhance the benefits of working with distributors is through the unique offers and services you can provide. This is especially beneficial around enabling MSPs to rapidly create Meraki-powered services offers. The more you are in tune and listening to your partners, the more they’ll see how you are uniquely equipped with services they need to drive greater success.

Voicing the Scale

By increasing rebates for recurring offers, migration opportunities in EA data packs, and CCW-R quote automation, we are resetting your ability to scale and maximize partner growth. You are the voice of reason when it’s time for a refresh. Help them continue to experience the success of Cisco solutions.

Accelerating Partnerships

By giving you aggressive discounts and competitive offers, you can help your partners sell more Meraki SD-WAN, Secure Firewall, and so much more. Through additional investments in key distribution to partner programs, you are enabled to drive greater SMB specializations and demand.

Pairing with Perspective

Like I mentioned live during DistiNEXT, “Just one great partnership with the right people can have an incredible impact on your business success.” We are listening to you, and your voices are spanning across everything we are planning for FY24 and beyond. We are working on shaping up our communications practices, increasing discounts and promotions, and driving business where it’s going to make the biggest impact for you. You help us see things from a unique perspective and this will help us go Hypersonic to Fuel Partner Success this year.

Watch DistiNEXT event recordings here!

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!

Cisco Partners Facebook  |  @CiscoPartners Twitter  |  Cisco Partners LinkedIn

Share

  The theme for DistiNext 2023 was Growing Together. This theme ties perfectly into our theme for Americas Distribution, Going Hypersonic to Fuel Partner Success.  Read More Cisco Blogs 

By |2023-10-30T23:50:00+00:00October 30, 2023|Cisco: Learning|0 Comments

Cisco Americas Partner Organization: Laser Focused on Customer and Partner Success Rhonda Henley on October 30, 2023 at 3:00 pm

I couldn’t be more excited in my relatively new role as VP of Americas Partner Organization (APO) here at Cisco. My organization is where we put the “Cisco is partner-led” messaging into action, helpi… Read more on Cisco Blogs

I couldn’t be more excited in my relatively new role as VP of Americas Partner Organization (APO) here at Cisco. My organization is where we put the “Cisco is partner-led” messaging into action, helping our America’s-based partners succeed by helping them deliver truly exceptional outcomes for our mutual customers.

As you’ve probably heard, our partner-centric global sales go-to-market strategy revolves around three key components: Growth, Transformation, and Culture.

Growth: We’re dedicated to boosting top-line growth through the Growth Sprints framework, aiming to increase average contract value and renewal revenue.
Transformation: We’re committed to transformation by meeting our customers where they are, adopting a customer-centric approach, and enhancing selling experiences through innovative tools and processes.
Culture: We present a united front as One Cisco, leveraging our culture as a competitive edge to support our partners.

This aligns seamlessly with our strategic pillars in the Americas. These four pillars serve as our guiding principles for FY24 as we shape and execute our initiatives.

Being “better together” emphasizes collaboration within the Cisco organization and, critically, with our partners, forging a formidable alliance with an exceptionally extensive and diverse portfolio.
Our commitment to remaining “customer-obsessed” remains unwavering, continuously prioritizing their needs and striving to keep them at the forefront of innovation.
We maintain a “growth mindset” that encourages both individual and collaborative creativity, fostering experimentation with new ideas, in tandem with our partners.
Furthermore, our drive for “innovation and execution,” along with unwavering commitment to technology, underpin our ability to execute effectively, driven by appreciation for our portfolio and a passion for all things tech.

And many of our partners are thriving working with Cisco. Here are just a few (of many) examples:

One of our largest partners, WWT, worked with Cisco to bring down a large network transformation project that included many sites of deployment and services. And in this deal, the Cisco and WWT teams became aligned prior to the execution of the sale all the through the solution design and close. And then after the sale, we remained aligned in clear swim lanes of responsibility to drive the most effective results for the customer in a timely manner.
One of our LATAM partners, ConNext by Migesa, has been partnering with us for over 20 years from pre-sales through delivery. ConNext makes it a point to utilize data to create even better solutions that more precisely meet their requirements, leveraging both Cisco and ConNext’s unique value propositions.
One of more innovative distributors, Scansource, focuses on bringing out the best of breed and our partners, to leverage our Cisco sauce to deliver successful Cisco solutions within their partner programs to deliver those business outcomes. For instance, Scansource and Cisco have partnered to deep dive into our security offerings, understanding how we can leverage these marketing leading technologies in their existing customer base.

Many of our partners are transforming with us, transitioning from more hardware-centric, project-based organizations to also offering a balance of software-oriented offerings. Across the customer lifecycle, we’re committed to offering insights to our shared customers, harnessing the power of Cisco technology and partner value-added services. This ensures that customers maximize the value derived from their investments with us.

Defining a mission to help our partners thrive

Now, let’s explore what FY24 holds in store. Put simply, it’s all about delivering tomorrow’s growth today, which is something we know we can’t do without our partners.

In the coming year, we’ll remain aligned with the APO’s core priorities, including hunting for new logos and franchises, propelling software platforms, driving adoption, refreshing hardware, and enhancing premium services. All the while, we’ll be evolving our go-to-market strategies, both internally and externally.

What sets the Americas Partner Organization apart is our unique position within the best-in-class Americas partner ecosystem. We serve as a formidable force multiplier, leveraging partner innovation to redefine possibilities and accelerate profitable growth. Together, we’re poised for an exciting journey in FY24.

So, with this in mind, I invite you to join me at Partner Summit or via the Cisco Partner Summit 2023 Live Digital Broadcast. For more information and insights into the future of APO and how we can be Greater Together, be sure to check out the America’s Geo Session – Delivering Tomorrow’s Growth Today, on Nov. 7, from 2:30-3:15pm.

Register for the Cisco Partner Summit 2023 Live Digital Broadcast!

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!

Cisco Partners Facebook  |  @CiscoPartners Twitter  |  Cisco Partners LinkedIn

Share

  The Americas Partner Organization (APO) at Cisco is where we put the “Cisco is partner-led” messaging into action, helping our America’s-based partners succeed by helping them deliver truly exceptional outcomes for our mutual customers.  Read More Cisco Blogs 

By |2023-10-30T23:50:00+00:00October 30, 2023|Cisco: Learning|0 Comments
Go to Top