Self Defending Networks

Information theft often occurs without network or security personnel suspecting it. Therefore, security systems must react quickly and automatically to suspicious network behavior. A security system must be fully integrated into all aspects of the network, so that the network and its managers can proactively recognize suspicious activity, identify if the threat is real, react appropriately and quickly to the theft attempt. The Self-Defending Network strategy outlines comprehensive theft of information protection. Organizations can use their existing investments in routing, switching, wireless, and security platforms to deploy a self-defending network that will help them identify, prevent, and adapt to security threats originating both inside and outside of the organization.

Confiance has great experience designing, implementing, and supporting the following components that comprise the “Self Defending Network” solution.

         · NAC (Network Access Control) Solutions
         · RSA enVision - Security Monitoring, Analysis, and Event Correlation System Solution
         · VPN Solutions – AnyConnect SSL VPN, IPSEC VPN, Dynamic Routed VPN’s (GRE/IPSEC)
         · Firewall and Intrusion Prevention Solutions
         · LAN/WAN Infrastructure Security Solutions

Cisco NAC (Network Access Control)

Cisco NAC Appliance (formerly Cisco Clean Access) is an easily deployed Network Admission Control (NAC) product that uses the network infrastructure to enforce security policy compliance on all devices seeking to access network computing resources. With NAC Appliance, network administrators can authenticate, authorize, evaluate, and remediate wired, wireless, and remote users and their machines prior to network access. It identifies whether networked devices such as laptops, IP phones, or game consoles are compliant with your network's security policies and repairs any vulnerabilities before permitting access to the network.
Networks with Cisco NAC Appliance can realize benefits such as:
Minimized network outages
Enforcement of security policies
Significant cost savings with automated device repairs and updates

Cisco NAC Appliance extends NAC to all network access methods, including access through local area networks (LANs), remote-access gateways, and wireless access points. Cisco NAC Appliance also supports posture assessment for guest users.
When deployed, Cisco NAC Appliance provides the following benefits:
Recognizes users, their devices, and their roles in the network. This first step occurs at the point of authentication, before malicious code can cause damage.
Evaluates whether machines are compliant with security policies. Security policies can include specific antivirus or anti-spyware software, OS updates, or patches. Cisco NAC Appliance supports policies that vary by user type, device type, or operating system.
Enforces security policies by blocking, isolating, and repairing noncompliant machines.

Noncompliant machines are redirected into a quarantine area, where remediation occurs at the discretion of the administrator

Cisco ASA 5500 Security Appliance

Cisco ASA 5500 Series Adaptive Security Appliances are easy-to-deploy solutions that integrate world-class firewall, Unified Communications (voice/video) security, SSL and IPsec VPN, intrusion prevention (IPS), and content security services in a flexible, modular product family. Designed as a key component of the Cisco Self-Defending Network, the Cisco ASA 5500 Series provides intelligent threat defense and secure communications services that stop attacks before they impact business continuity. Designed to protect networks of all sizes, the Cisco ASA 5500 Series enables organizations to lower their overall deployment and operations costs while delivering comprehensive multilayer security.