About (Edit profile)

This author has not yet filled in any details.
So far has created 1829 blog entries.

From Academia to Cisco: How I’m Inspired and Empowered as a Woman in Tech on March 26, 2024 at 12:00 pm

Graduating with my Ph.D. in Electrical Engineering and securing a post-doctorate position, I was well on my way to staying in academia and becoming a professor. After a year into my post-doctorate, I… Read more on Cisco Blogs

​[[{"value":"

Graduating with my Ph.D. in Electrical Engineering and securing a post-doctorate position, I was well on my way to staying in academia and becoming a professor. After a year into my post-doctorate, I realized I sought something beyond the satisfaction of publishing in scientific journals and peer recognition. I found myself standing at a crossroads, contemplating my next move. That is when an exciting opportunity at Cisco arrived. The position — Wireless System Engineer — seemed tailored perfectly to my academic background. So, I decided to take a leap of faith.

As soon as I joined Cisco, I immersed myself in the cutting-edge realms of security, networking, and wireless communication technologies. Every day is intellectually stimulating. I am surrounded by brilliant peers who inspire me to learn and grow. The collaborative spirit here is infectious and fuels my passion for professional development. Despite being relatively new to the company, I’ve had the chance to contribute to various high-impact projects, from indoor location services utilizing the latest ultra-wideband technology to Automated Frequency Coordination (AFC), OpenAFC, tapping into potentials of 6 GHz band spectrum for Wi-Fi, FCC radio regulations, and I’ve even been given an incredible opportunity to apply my expertise in AI and machine learning to the development of Wi-Fi 7 products. The work I am part of is making wireless more accessible for all. I get to apply my knowledge in tackling real-world challenges, finding great fulfillment in transforming my ideas into products that impact people’s daily lives. Seeing my efforts make a real difference outside a university or lab is truly rewarding.

I’ve felt Cisco’s unwavering commitment to personal and professional growth since my first day. Here, every individual is not only valued, but celebrated for their unique contributions. Our leaders are dedicated to recognizing each individual’s unique strengths and strive to match responsibilities with our superpowers, ensuring that each one of us has the opportunity to shine in our roles. At Cisco, this diversity and inclusivity is the cornerstone of our collective success. It was also evident from the start of the onboarding process when I saw all the amazing Inclusive Communities you can be a part of, like Women of Cisco, which I immediately joined. As a woman in tech, discovering a workplace that truly champions the presence and advancement of women has been essential for my career contentment. At Cisco, I don’t just feel like an employee. I feel like part of a supportive community.

After some time in my role, I wondered how to gain more visibility for my work. With Cisco being such a huge company, I wanted to learn how to navigate the corporate landscape and reach new heights in my career.

So, I joined the Executive Shadow Program, a unique Women of Cisco initiative tailored to its female and male ally members. I matched with my executive, and she invited me to join her at one of her offsites, where I observed how she managed her day-to-day tasks for a few days. We had great conversations. She listened to my concerns and gave me advice on navigating tough situations and reaching my goals.

Shadowing her was an eye-opening experience, providing valuable insights into leadership communication, decision-making in uncertain circumstances, and the career trajectory of our leaders. When you see female leaders who started where you did, took a path like yours, and faced similar challenges, it gives you power and inspires you to do the same thing. The networking opportunities outside my immediate team have broadened my horizons and enriched my professional network, and I continue to connect with my executive mentor regularly. Thanks to this invaluable experience, I better understand how different organizations work internally and in connection with others at Cisco.

As I reflect on my journey at Cisco so far, I’m filled with gratitude for the opportunities, support, and growth that have come my way. This isn’t just a job — it’s a fulfilling adventure where every day brings new challenges and opportunities to learn and grow. With a company culture that nurtures diversity and inclusion and fosters professional development, I’m excited to continue down this path and see where it leads next. Here’s to navigating new horizons and embracing the endless possibilities that lie ahead.

Explore the ways Cisco empowers us and creates ways to support our professional and personal growth and more through the power of our purpose.

Subscribe to the WeAreCisco Blog.

Share

"}]]  At a career crossroads, Niloo took a leap, joining Cisco as a Wireless System Engineer, finding fulfillment through innovation, inclusivity, and mentorship.  Read More Cisco Blogs 

By |2024-03-26T14:51:17+00:00March 26, 2024|Cisco: Learning|0 Comments

Hiding in Plain Sight: How Subdomain Attacks Use Your Email Authentication Against You on March 26, 2024 at 12:00 pm

For years, analysts, security specialists, and security architects alike have been encouraging organizations to become DMARC compliant. This involves deploying email authentication to ensure their… Read more on Cisco Blogs

​[[{"value":"

For years, analysts, security specialists, and security architects alike have been encouraging organizations to become DMARC compliant. This involves deploying email authentication to ensure their legitimate email has the best chance of getting to the intended recipients, and for domain owners to be quickly notified of any unauthorized usage of their domains. While together we are making progress thanks to DMARC adoption and reporting services such as Cisco’s OnDMARC offering, there’s an opportunity to do better particularly with on-going monitoring to address new and emerging threats, such as this Subdo campaign.

What’s happened?

Recently a totally new attack type has been seen that takes advantage of the complacency that an organization may have when they approached their DMARC rollout with a ‘ticked the box’ mindset.

The SubdoMailing (Subdo) campaign has been ongoing for about two years now. It sends malicious mail – that is typically authenticated – from domains and subdomains that have been compromised through domain takeover and dangling DNS issues.

These attacks were initially reported by Guardio Labs who reported the discovery of 8,000 domains and 13,000 subdomains being used for these types of attacks since 2022.

Several weeks before that, Cisco’s new DMARC partner, Red Sift, discovered what they initially thought was an isolated incident of bad senders passing SPF checks and sending emails fraudulently on behalf of one of their customers. In the customer’s instance of Red Sift OnDMARC, they noticed email was coming from a sender with a poor reputation and a subdomain that appeared unrelated to their customer’s main domain. But these emails had fully passed SPF checks with the customer’s current SPF record. Upon alerting the customer who then investigated all the ‘includes’ in their SPF record, several outdated CNAME addresses were found that had been taken over by attackers, which is what caused the issue.

What should I look out for?

The bad actors in this campaign are capitalizing on stale, forgotten or misconfigured records that were wrongfully included in DNS to send unauthorized emails. The attackers then send phishing emails as images to avoid text-based spam detection.

It is this oversight that has seen many notable organizations be impacted by these new subdomain attacks in the last few months, solely because they have not been actively monitoring in the right areas.

Proactive steps to start today:

Don’t let your domain names expire – these are what provide fraudsters the opportunity to carry out the attack.
Keep your DNS clean – Remove resource records from your DNS that are no longer in use and remove third-party dependencies from your DNS when they become redundant.
Use a trusted email protection provider – It makes sense to use a vendor for DMARC, DKIM and SPF requirements but be sure to use a trusted vendor with the capability to proactively identify problems, such as when part of a SPF policy is void or insecure.
Check for dangling DNS records – Have an inventory of hostnames that are monitored continuously for dangling resource records and third-party services. When identified, remove them immediately from your DNS.
Monitor what sources are sending from owned domains – If the domain or subdomain is taken over for sending, then it is important to know if mail is being sent from it as quickly as possible.

What else should I do?

If you are wondering if you have been impacted by SubdoMailing, the best place to start is Red Sift Investigate, this will provide you with a review of your domain such as can be seen below:

Should this valuable tool reveal any ‘SubdoMailers’ – also known as poisoned includes – the Red Sift SPF Checker allows you to visualize them in a dynamic ‘SPF tree’, allowing you to quickly pinpoint where they are and speed up remediation efforts, an example of a dynamic SPF tree can be seen below: –

The OnDMARC Adoption and Reporting Solution that Cisco partners with Red Sift on has already been updated to uncover exactly these issues directly within the tool to ensure our customers are protected.

If you’re a Cisco Secure Email customer, find out how you can quickly add Red Sift domain protection to your security suite and better detect that image-based spam. To check out the sophisticated threat protection capabilities of Secure Email Threat Defense, start a free trial today.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!

Cisco Security Social Channels

InstagramFacebookTwitterLinkedIn

Share

"}]]  Understanding the tricky way that subdomain attacks use your email authentication against you.  Read More Cisco Blogs 

By |2024-03-26T14:51:16+00:00March 26, 2024|Cisco: Learning|0 Comments

Differentiated Experience with Cisco Catalyst Center and CX Services on March 25, 2024 at 3:00 pm

Cisco Catalyst Center is a powerful network controller and management dashboard that simplifies customer IT operations in enterprise and campus networks via valuable insights, time-saving automation,… Read more on Cisco Blogs

​[[{"value":"

Cisco Catalyst Center is a powerful network controller and management dashboard that simplifies customer IT operations in enterprise and campus networks via valuable insights, time-saving automation, and robust security capabilities. To help customers reduce risk and respond to network changes and challenges even faster and more intelligently, Cisco has integrated advanced insights and analytics capabilities from the Cisco Success Tracks service into the Catalyst Center platform.

These advanced capabilities enable the platform to securely submit customer configurations to Cisco Services to digitally verify if known issues like security advisories, hardware defects, and software bugs are impacting the customer’s assets. Success Tracks, which is part of the CX Cloud platform, is designed to digitally connect customers to expertise, learning, insights, and support via a curated use-case journey.

The new Catalyst Center customer experience enables predictable business outcomes by combining the best Catalyst Center telemetry, orchestration, and automation capabilities with CX expertise, intellectual capital, and analytics. These Catalyst Center capabilities—now available to customers with Smart Net Total Care contracts—can help minimize operational expenses by avoiding unnecessary device upgrades.

This integration provides Catalyst Center customers with:

A consistent user experience with insights, reports, and alerts based on shared technology components and telemetry—whether workflows start in Catalyst Center or CX Cloud
Innovation of advanced capabilities using the best of Catalyst Center telemetry, automation, and orchestration combined with CX experience, expertise, and intellectual capital

Advanced features

Insights customized to specific device configurations and inventory include:

Advanced security advisories—Significantly improve the accuracy of identifying critical and high-impact vulnerabilities, eliminate the need for further validation, avoid unnecessary software upgrades, and improve security posture and operational efficiency with analysis of Cisco Security Advisories against deployed software features.
Advanced field notices—Improve the accuracy of identifying non-security-related vulnerabilities, eliminate the need for further troubleshooting of known hardware and software issues, and help to remediate operational risks more quickly via analysis of Field Notices against detailed deployed inventory.
Advanced network bug identifier—Improve the visibility of known issues; and identify problems that can be addressed proactively to prevent incidents, service outages, and support cases with analysis of key bugs curated by the Cisco Technical Assistance Center (TAC) experts—against deployed software features.
End-of-life notices—Improve the accuracy of identification of end-of-sales, software maintenance, last day of support dates, and more by eliminating unnecessary business risks and contributing to technology refresh planning with analysis of End-of-Life Policy milestones against deployed inventory.
Remote support authorization—Accelerate troubleshooting, help reduce mean time to resolution (MTTR), and maximize network availability by securely sharing the latest operational data from Catalyst Center–managed devices with a TAC engineer during an incident via the embedded Cisco RADKit network-wide orchestrator.
Wireless troubleshooting workflows—Troubleshoot events and solve incidents without needing to escalate to TAC via Catalyst Center workflows developed with TAC expertise.

How to leverage advanced features

Customers can access these advanced features in three ways:

Campus devices covered by Success Tracks service contracts
Campus devices covered by Smart Net Total Care service contracts
Free 90-day trial for customers without the above service contract coverage

These features are available to customers with Catalyst Center version 2.3.7 and newer. You have access to these features for all assets that are covered by any of the above service contracts.

Below are the steps to enable the new CX features in Catalyst Center:

Note: Customers without applicable service contracts can activate the free, 90-day trial by clicking the Start CX Trial button and accepting the Consent to Connect (as shown below). Note that Start CX Trial will not appear as an option for customers with the service contract coverage listed above.

Navigate to the Catalyst Center home page, scroll down to the lower left area (as shown below), and select Authorize Consent to Connect to CX Cloud.
After selecting Authorize Consent to Connect, check the box that appears to confirm that you read and agree to the conditions, then click the Authorize button (as shown below).
On the Catalyst Center home page, click on System from the left-hand dropdown and then select Settings (as shown below).
On the Setting window, select the Machine Reasoning Engine tab and ensure that Auto Update, CX Cloud Service, and Recurring Scan are all enabled (as shown below).

To learn more about Catalyst Center

and  Cisco CX Cloud and Success Tracks,

contact your Account team.

Share

"}]]  Discover how the latest version of Cisco Catalyst Center reduces risk by integrating with Cisco Lifecycle Services’ Success Tracks to enable predictable business outcomes by combining the best Catalyst Center telemetry, orchestration, and automation capabilities with CX expertise, intellectual capital, and analytics. Advanced features include security advisories, field notices, network bug identifiers, end-of-life notices, remote support authorization, wireless troubleshooting workflows, and more.  Read More Cisco Blogs 

By |2024-03-26T01:52:49+00:00March 26, 2024|Cisco: Learning|0 Comments

Simplify Manufacturing Operations with Cloud Platforms on March 25, 2024 at 3:47 pm

Introduction

In the ever-evolving landscape of modern manufacturing, operational simplicity stands as a cornerstone for success. Manufacturers grapple with an array of challenges, from complex supply… Read more on Cisco Blogs

​[[{"value":"

Introduction

In the ever-evolving landscape of modern manufacturing, operational simplicity stands as a cornerstone for success. Manufacturers grapple with an array of challenges, from complex supply chains to the pressing need for real-time insights. To address these challenges head-on, cloud platforms emerge as transformative solutions, streamlining processes, reducing costs, and fostering innovation. In this comprehensive exploration, we delve into the pivotal role of cloud-based network management platforms in helping to revolutionize manufacturing operations, empowering companies to navigate complexity with agility and resilience. 

Simplifying Operations in Manufacturing 

Manufacturers operate in an environment characterized by complexity and rapid change. The traditional approach to managing operations often involves a fragmented array of tools and systems, leading to inefficiencies and siloed data. Cloud platforms offer a paradigm shift, consolidating essential capabilities onto unified interfaces. This platform-centric approach enables manufacturers to leverage AI-driven automation, standardized policies, and seamless APIs, simplifying operations across the network, data center, and service delivery. The challenges associated with managing manufacturing operations have become more pronounced in recent times, underscoring the importance of agility and resilience. Cloud platforms offer a versatile and scalable framework, allowing manufacturers to quickly respond to shifts in market dynamics and evolving customer needs. By simplifying the operational landscape, cloud platforms empower manufacturers to prioritize innovation and expansion, rather than being weighed down by administrative complexities. 

Harnessing Cloud Platforms for Network Scaling in Manufacturing Facilities 

Scalable and responsive networks are essential for modern manufacturing facilities. Cloud platforms offer a robust solution for efficiently scaling network operations, dynamically adjusting resources based on demand, and optimizing connectivity for machines and devices. By leveraging AI-driven insights and automation, manufacturers can ensure a seamless and responsive network environment, tailored to the unique requirements of manufacturing processes. Efficient network scaling is particularly crucial in the context of Industry 4.0, where interconnected systems and IoT devices drive digital transformation. Cloud platforms enable manufacturers to harness the power of data analytics and real-time monitoring, optimizing network performance and enhancing operational efficiency. Whether it’s facilitating remote diagnostics, monitoring equipment health, or enabling predictive maintenance, cloud-enabled networks empower manufacturers to unlock new levels of productivity and competitiveness.  

Streamlined Data Center Operations for Manufacturing Processes 

Data centers serve as the backbone of modern manufacturing operations, housing critical infrastructure and supporting a myriad of applications and services. However, managing data center operations can be complex and resource-intensive, especially as manufacturing processes become increasingly digitized and data-driven. Cloud platforms offer a compelling solution for streamlining data center operations, automating routine tasks, and ensuring the reliability and security of critical infrastructure. By adopting a platform-centric approach, manufacturers can implement common policies for data management, leverage AI-driven insights for predictive maintenance, and integrate diverse data sources through APIs. This streamlined approach to data center operations not only reduces downtime and improves operational efficiency but also lays the foundation for future growth and innovation. With cloud-enabled data centers, manufacturers can scale seamlessly, adapt to changing business requirements, and drive continuous improvement across their operations.

Facilitating Collaborative Manufacturing Through Enhanced Connectivity  

Collaborative manufacturing environments require robust and reliable connectivity solutions to enable seamless communication and collaboration between disparate systems and stakeholders. Cloud platforms offer a unified and integrated approach to connectivity, enabling manufacturers to bridge the gap between IT and operational technology (OT) systems, optimize supply chain visibility, and enhance collaboration across the value chain. By leveraging cloud-enabled connectivity solutions, manufacturers can streamline communication between machines, devices, and personnel, facilitating real-time data exchange and decision-making. Whether it’s enabling remote monitoring and control, facilitating predictive maintenance, or optimizing resource allocation, cloud-enabled connectivity solutions empower manufacturers to operate more efficiently, respond rapidly to changing market conditions, and drive continuous improvement across their operations. 

Conclusion

In conclusion, cloud platforms represent a transformative force in the manufacturing industry, enabling companies to streamline operations, reduce costs, and foster innovation. By embracing a platform-centric approach, manufacturers can leverage AI-driven automation, standardized policies, and seamless APIs to simplify operations across the network, data center, and service delivery. Whether it’s scaling network operations, streamlining data center operations, or enhancing connectivity for collaborative manufacturing, cloud platforms empower manufacturers to navigate complexity with agility and resilience. As we look to the future, the role of cloud platforms in driving efficiency, innovation, and agility in manufacturing will only continue to grow. By embracing cloud-enabled solutions, manufacturers can unlock new opportunities for growth, differentiate themselves in the marketplace, and position themselves for long-term success.  

Explore these possibilities further at the Hannover Messe from April 22 to 26 in Hannover, Germany. Visit Cisco’s booth at F18 in Hall 14/15, Digital Ecosystem Area, and our event microsite and discover how we can empower your manufacturing journey.

Share

"}]]  In the modern manufacturing landscape, operational simplicity is paramount. Cloud platforms streamline processes, reduce costs, and foster innovation, empowering companies to navigate complexity with agility and resilience.  Read More Cisco Blogs 

By |2024-03-26T01:52:48+00:00March 26, 2024|Cisco: Learning|0 Comments

Identify and Investigate Uncommon DNS Traffic on March 25, 2024 at 4:29 pm

Programmatically filter uncommon DNS Requests with Cisco Umbrella APIs

We use the Internet in our everyday lives to get work done, manage our lives, and even socialize. We take this Internet usage… Read more on Cisco Blogs

​[[{"value":"

Programmatically filter uncommon DNS Requests with Cisco Umbrella APIs

We use the Internet in our everyday lives to get work done, manage our lives, and even socialize. We take this Internet usage for granted these days, but the reality is that we are communicating more than ever on a global scale, instantaneously, and often, with folks we’ve never met in-person or with third-party services we don’t fully understand.

From a cybersecurity perspective, this looks like a lot of DNS traffic to have to monitor, understand, and investigate. And, there are increasing reasons to do just that. After the major Colonial Pipeline ransomware attack that resulted in a $4.4 million ransom payment in 2021, the TSA issued (and has since, reissued) a security directive to pipeline utility companies that, in part, asked them to better understand their DNS traffic.

Of course, pipelines are not the only targets of such attacks, meaning we need reasonable methodologies for identifying and investigating potentially malicious domains. In this article, we walk you through how you might programmatically gain visibility into and investigate uncommon DNS requests using Cisco Umbrella APIs.

Initial developer setup

To create this automation, we assume you have an active Cisco Umbrella account with API access, Python3, and an integrated developer environment (IDE) that supports Python.

If you’re not yet an Umbrella user, or you’d simply like to create a proof-of-concept (POC) around this, you can leverage the always-on Umbrella Secure Internet Gateway sandbox through Cisco DevNet.

Defining what traffic is “uncommon”

The day before writing this article, Cisco Umbrella processed over 800 billion DNS requests. As a result of this consistently massive amount of traffic processing and analysis, Umbrella maintains an up to date “Top 1-Million Domains” list as a CSV. This information establishes a baseline of what traffic is common.

We can determine what traffic coming from your Umbrella network is uncommon by comparing it to this Top 1-Million Domains list.

To do this, we make an API call using the Umbrella Reports API to retrieve the Top Destinations seen by your Umbrella network in the past week. The call returns a list of domains from most to least common, one per row, as a CSV, that we can clean to remove the rank order and non-domains. (For example, remove the 8 in this row: 8,www.google.com, and remove IP address destinations because they won’t match an Umbrella Top 1-Million domain)

We can then write logic that compares the domains seen by your network to Umbrella’s Top 1-Million and adds any of your domains that are not on that list to a new CSV.

Sample Code

We’ve written a sample Python script to help you achieve this using your own DNS traffic! That script, along with instructions for running it, can be found here.

Investigating uncommon domains with Umbrella APIs

Once you’ve identified which domains seen by your network are considered less common, you may choose to further investigate some—or all—of them using Umbrella Investigate.

If you have an Umbrella DNS Security Advantage or Secure Internet Gateway (SIG) package, in the Umbrella dashboard, you can navigate to Investigate > Smart Search and search for the domain you’d like to investigate. You’ll see results that provide information looking something like what you see below for examplemalwaredomain.com:

Figure 1: The beginning of Umbrella Investigate results for examplemalwaredomain.com

The results first show you both the content and security categories for the domain, provided by Cisco Talos. We can see that this domain is classified as malware and is already on a Malware Block List; though, if we wanted to, we could find additional information on this domain across Talos, Google, or VirusTotal (top right).

Figure 2: The risk score and security indicators for examplemalwaredomain.com

Scrolling down the results, we next see the risk score assigned to this domain and the security indicators that went into calculating that score. In this case, the domain is classified as High Risk, with additional information on the security indicators used here.

After viewing basic information on the domain, such as when it was created and from what country it originates, as well as associated observables like IP addresses, name servers, and files, you’ll find WHOIS record information on the domain (see below). You’ll notice that Umbrella Investigate allows you to further investigate the associated email address and nameservers.

Figure 3: WHOIS record data for examplemalwaredomain.com

Finally, we can view a global map showing where DNS requests to examplemalwaredomain.com. In the example map below, over 95% of DNS requests to this domain originate from the United States.

Figure 4: Global requestor distribution map for examplemalwaredomain.com

These Umbrella Investigate results are also available as part of the Umbrella Investigate API, meaning that the investigation of these uncommon domains can also be done programmatically.

Additional opportunities for automation

What are the possibilities for building upon the automation we’ve provided in the sample code?

Investigate – adding logic that for each uncommon domain, an API call is made to the Umbrella Investigate endpoint to retrieve info and any threat intel
Ticketing – you could integrate a ticketing system, like Jira, by leveraging its API to create and assign a ticket for each uncommon domain
Policy Changes – use the Umbrella Destinations List API to allow or block one or more of the uncommon domains
Reporting – export the uncommon domains, and perhaps info on them from Umbrella Investigate, into a more palatable format like PDF. Domain info could also be enhanced by intel from other security products, by viewing associated devices and their relationships with the domain using JupiterOne, and/or used in a visualization.
Orchestration – you can orchestration an automation workflow with multiple steps (not all of those steps need be automated) using Cisco XDR. The workflow might include all steps your organization requires for investigation and incident response.
Communication – rather than save the resulting CSV of domains locally, you may choose to automatically email the results to interested parties or post the results to a messaging platform like WebEx.

Share

"}]]  See how you can programmatically gain visibility into and investigate uncommon DNS requests using Cisco Umbrella APIs.  Read More Cisco Blogs 

By |2024-03-26T01:52:48+00:00March 26, 2024|Cisco: Learning|0 Comments

A Solution Engineer’s Journey into Programmability on March 25, 2024 at 7:00 pm

Hi there! I´m a Solutions Engineer working with Collaboration and Customer Experience solutions, and one thing I’ve learned is “one size does not fit all.” To deliver the most impactful business outco… Read more on Cisco Blogs

​[[{"value":"

Hi there! I´m a Solutions Engineer working with Collaboration and Customer Experience solutions, and one thing I’ve learned is “one size does not fit all.” To deliver the most impactful business outcomes, customers need digital solutions tailored to their unique needs. Thankfully we are surrounded by SaaS applications and powerful platforms that provide open APIs available to anyone with the skills to use them. In short, if you supply the motivation, the tools are there to embrace automation as the foundation for building custom use cases. This is how you can really differentiate in the marketplace, and bring value to our customers.

My interest in leveraging automation to integrate applications and optimize workflows was the trigger that started my journey into network programmability. I knew I wanted to start by connecting with a community of like-minded people who could help me get started. That’s when I found Cisco DevNet.

Getting started with a DevNet Learning Track

My first step was to learn the basics of APIs – how they work, what they are used for, how to test them, and how to integrate them into other applications. RESTful APIs are widely used in web development, allowing applications to interact with each other and exchange data in a standard and scalable manner. They provide a flexible and efficient way for different systems to communicate and integrate with each other.

To get familiar with APIs I started practicing with Learning Labs available in the Cisco DevNet developer portal. Because I’m a Solutions Engineer working with Collaboration solutions, I choose the Webex – Start Now – Learning Track. Follow this link to access this learning track and many others that can get you started. This Learning Track guided me to install all the required applications in my PC to start working with APIs and coding. It also gave me the tools I needed to start doing my first tests with coding and APIs.

Once I had some basics under my belt, my next step was to create a use case and start a “real” programmability project. I decided to integrate Webex with ChatGPT using the OpenAI APIs. The main building blocks to implement this project are:

Webex Bot
OpenAI APIs
Middleware that runs the bot logic

After I learned how to create a Webex bot, my next step was to get familiar with the OpenAI APIs. Anyone can create a free OpenAI account. (At the time of writing this blog, you get a free credit of $5.00 to use, which is enough to do some experimentation with their APIs.)

Getting the basics of Python

Next up, I needed to create my bot logic. Talking with my mentor, Julio Gomez, he shared with me a project that he did for a similar use case, and I was able to reuse his Phyton code. I had learned the basics of Phyton and how it works. Thus, I was able to adapt the Phyton code to use with my Webex bot and the OpenAI API that I had identified as the most appropriate for developing my Q&A bot based in the ChatGPT user experience.

To make it easier to adapt the code, I divided it into building blocks based on the different functions: receive a text message from the Webex Bot; process the message and send it to OpenAI APIs; receive the answer from the OpenAI; and finally send it back to the Webex Bot.

I faced another challenge

I was running the bot logic on my PC and I had to expose it to the internet. The Webex cloud platform requires your bot to be reachable from a publicly accessible endpoint. Using Webhooks, the Webex bot sends notifications as events to the endpoint that subscribed to the webwook, for every interaction between you and the bot.

For that purpose, I created an inbound tunnel between my local PC and the internet so that the port your bot is listening on becomes publicly accessible. Ngrok is a popular tool I used to create these tunnels. The Ngrok service creates a URL that can be used to access your application running in your local PC. This URL is then used to create a Webhook for your Webex bot to send notifications when someone interacts with it.

When I reached the point where I had a working application, I was ready to start my initial testing. I had to fine tune the code to obtain the desired outcome. In fact, it was as straight forward as changing a few parameters in the JSON payload, related to the OpenAI APIs. Here is the documentation of the OpenAI API that I used:

Finally, I was able to create a Q&A bot in Webex leveraging the LLM (Large Language Model) developed by OpenAI. The end users are then able to ask questions to ChatGPT from the Webex App, as if they were chatting in the native ChatGPT user interface.

The diagram below is a high-level architecture of what I built. You can see my project in this GitHub repository.

APIs have transformed the way we customize experiences and integrate applications. I am not a software developer, but I was able to achieve my goal, which was to build a Q&A Bot based on new technologies like ChatGPT. For me, working with APIs is like playing with Lego blocks. It’s fun!

My journey in programming continues

Then another thought came to my mind – Would I be able to create the bot with very little code, or even no code? I put myself into another challenge, which was to use an orchestration platform that leverages a low code / no code framework to create workflows and automation using APIs.

In fact, at Cisco we have our very own Low Code orchestration platform. It’s called Webex Connect and is one of the most recognized Communications Platform as a Service (CPaaS) in the market.

Webex Connect is a platform that empowers the creation of smart, proactive, and personalized interactions across digital channels such as WhatsApp, Apple Messages for Business, Google Business Messages, Facebook Messenger, Instagram, SMS, etc. It orchestrates customer journeys end-to-end by automating business processes.

I opened the drawing canvas of the application called Flow Designer and started building my Bot logic. It was as simple as dragging and dropping boxes, connecting them with arrows, and following the process. Again, like playing with Legos.
Using this platform is much simpler, because I didn’t have to deal with programming languages and coding for my use case. I just need to master the applications I wanted to connect, and learn how to use their APIs.

In a matter of a few hours I had my bot up and running. This time I integrated WhatsApp with ChatGPT. What took me a few days with Phyton was reduced to a few hours because I was dealing with APIs, webhooks, and parsing JSON payload data. Webex Connect (CPaaS) did its “magic” and executed the code behind the scenes which simplified the whole project.

Here is the final flow:

Low code platforms like CPaaS can unlock the Art of Possible, with APIs to create delightful user experiences.

I hope this was helpful. And perhaps even made you curious to start your own journey into programmability. If so, Cisco DevNet is a great place to start.

Good luck!!

Related resources

Launch your DevNet learning journey and explore network programmability, developer fundamentals with video tutorials.
Get to know Cisco technologies with DevNet Learning Labs.
Explore DevNet Professional Certifications. View exam topics

Sign up for Cisco U. | Join the Cisco Learning Network.

Follow Cisco Learning & Certifications

Twitter | Facebook | LinkedIn | Instagram | YouTube

Use #CiscoU and #CiscoCert to join the conversation.

Read next:

Intern to DevNet Professional Certification: My Personal Journey

Share

"}]]  Solutions Engineer Marcio Costa created a Q&A bot in Webex by integrating it with ChatGPT using OpenAI APIs. Follow along as Marcio explains how he learned the basics of APIs, practiced with Cisco DevNet Learning Labs, and used Webex Connect to create workflows and automation using APIs to make the process much simpler and faster.  Read More Cisco Blogs 

By |2024-03-26T01:52:47+00:00March 26, 2024|Cisco: Learning|0 Comments

Sustainability 101: What is environmental reporting? on March 25, 2024 at 9:25 pm

Do you feel a bit lost when people refer to certain environmental sustainability topics and aren’t sure where to start when it comes to learning more? Sustainability 101 is a blog series that you can … Read more on Cisco Blogs

​[[{"value":"

Do you feel a bit lost when people refer to certain environmental sustainability topics and aren’t sure where to start when it comes to learning more? Sustainability 101 is a blog series that you can turn to for information about different environmental terms that may come up at work, during discussions with friends, and even at your annual holiday gathering.

Companies play a pivotal role in addressing the climate challenges of today and tomorrow, with initiatives and innovations helping to build a more sustainable future. Technology companies can especially play a crucial role in helping to reduce global emissions. According to a World Economic Forum (WEF)  report published in 2023, “Estimates reveal that the adoption of digital technology solutions in different sectors could help reduce global GHG emissions by 6–20 percent by 2030, depending on modeling scenarios and the sectors taken into account.” And besides the potential from innovation, there is also an expectation from investors, customers, and employees for companies to implement environmental initiatives and transparently report on their progress. Many regulators around the world are requiring companies to report on these initiatives as well.  According to WEF, “Stakeholders nowadays are pressing organizations to go beyond expectations, imagine a better way to do business, address environmental, social and governance (ESG) concerns concretely and transparently, and to set goals and report progress for business sustainability.”

Environmental reporting is an important part of this journey; it is how companies disclose their environmental impact and progress on sustainability efforts to stakeholders. According to the Governance and Accounting Institute (G&A), 98% of companies in the largest half of the Russell 1000 by market cap published a sustainability report in 2022. Setting clear public goals, measuring progress against them, and reporting on that progress is a best practice and, increasingly, a regulatory requirement. Not only does reporting help increase transparency and trust, but it also helps promote best practices and collaboration by demonstrating a more proactive approach to sustainability.

Changes in environmental reporting

Many companies have been voluntarily reporting on their environmental performance and progress against their goals for years. Companies have traditionally reported in two ways: by publishing their own public reports aligning with standard environmental reporting frameworks, such as the Global Reporting Initiative (GRI), and by submitting information to formal indices, raters, and rankers, such as CDP (formerly the Carbon Disclosure Project).

In recent years, we have seen a shift from voluntary reporting to mandatory reporting. The need for comparability, accountability, and defendable and auditable data and progress across companies contributes to this change.

For example, in the European Union, the Corporate Sustainability Reporting Directive (CSRD) modernizes and strengthens existing rules concerning the social and environmental information that companies have to report. The CSRD aims to ensure that investors and other stakeholders have access to the information they need to assess the impact of companies on people and the environment, and for investors to assess the financial risks and opportunities arising from climate change and other sustainability issues. A broader set of companies will now be required to report on sustainability, and companies subject to the CSRD will have to report according to European Sustainability Reporting Standards (ESRS).

Mandatory regulations are still evolving in many parts of the world. For example, in the United States, the U.S. Securities and Exchange Commission (SEC) recently finalized a rule to enhance and standardize climate-related disclosures by public companies and in public offerings. And multiple jurisdictions around the world are actively pursuing or considering adoption roadmaps and pathways toward mandatory application of International Sustainability Standards Board (ISSB) IFRS® Sustainability Disclosure Standards (SDS).

Due to the urgency of climate change and the risks it poses, many companies recognize the importance of sustainability initiatives and transparent reporting regardless of the mandatory regulatory status. According to the WEF Global Risks Report, two-thirds of respondents rank extreme weather as the top risk most likely to present a material crisis on a global scale in 2024.

The future of environmental reporting

As we innovate in the climate space, there is also room to innovate on the way we approach environmental reporting.

Scenario modeling can help enhance the quality of environmental reporting by helping us gain a deeper understanding of potential future environmental impacts, risks, and opportunities such as climate change projections, regulatory changes, and advancements in technology.

Transition plans help companies gain a better understanding of how they intend to change their operations, practices, or business models to address environmental challenges. Robust scenario modeling can help project future performance against a defined baseline, and strategies and actions can be developed in response. In addition, these scenarios help us understand and make updates based on the latest climate science.

The complexity of the questionnaires and methodologies that raters and rankers (such as CDP, mentioned earlier) use to assess companies is growing. Reporting into these increasingly detailed frameworks relies on having quality data and estimations, which depends on a collective effort with customers, suppliers, and other partners to help gather the best data.

How Cisco approaches environmental reporting

Cisco has a long history of voluntary reporting on sustainability, and we want to continue to share our progress in an authentic and transparent way. To remain transparent, we publish an annual Purpose Report and maintain an ESG Reporting Hub. The report describes our commitments, goals, progress, and impact for the ESG topics that are important to our stakeholders from our most recent fiscal year. The ESG Reporting Hub includes in-depth information and historical data on all reporting topics.

Cisco’s 2040 net-zero target and near- and long-term targets are approved by the Science Based Targets initiative (SBTi) under its Net-Zero Standard, the world’s first framework for corporate net-zero target setting in line with climate science. This builds on our history of setting meaningful goals, measuring our progress and impact, and reporting on them transparently.

Cisco is trusted in the IT space, and we are committed to maintaining that trust in our environmental reporting. Since quality reporting depends on a collective effort across the value chain to gather reliable data and estimations, we strive to influence our customers, suppliers, and partners to embrace robust reporting as well. For example, our suppliers are expected to report GHG emissions and energy consumption to CDP (a not-for-profit organization that runs a global disclosure system) on an annual basis. We know we must all work together to drive meaningful change for our planet’s health and future generations. Likewise, a collective emphasis on clear and accurate reporting will help inform our efforts and measure the progress we are all making for the planet.

Learn more in our ESG Reporting Hub.

Share

"}]]  Curious about environmental reporting? Learn how it helps increase transparency and trust, and helps promote best practices.  Read More Cisco Blogs 

By |2024-03-26T01:52:46+00:00March 26, 2024|Cisco: Learning|0 Comments
Go to Top