The Cisco Security Monitoring, Analysis, And Response System (CS-MARS) complements the self-defending network architecture by empowering your security and network organization to monitor, analyze, and mitigate security threats. It transforms raw network and security data into usable information to validate security incidents and maintain compliance. It leverages your existing network and security investments to identify, isolate, and recommend precision removal of offending elements.
The CS-MARS extends the portfolio of security management products for the Cisco Self-Defending Network initiative. A result of the Protego acquisition, CS-MARS offers a family of high-performance, scalable appliances for threat management, monitoring, and mitigation, enabling customers to make more effective use of network and security devices.
CS-MARS combines network intelligence, context correlation, vector analysis, anomaly detection, hotspot identification, and automated mitigation capabilities. The result is a system that helps customers to readily and accurately identify, manage, and eliminate network attacks and maintain network security compliance.
The Cisco MARS-Protego course is a two-day, instructor-led class, consisting of five chapters and six labs designed to provide a solid foundation on which a student can build. The course prepares you to install the product, add network devices, create & manage rules, and create reports to better secure and manage your network. It also covers incident investigations, event management, and system maintenance.
Course Outline
- CS-MARS Overview
- Hardware Models
- How CS-MARS Works
- CLI Overview
- GUI Overview
- Adding Devices
- Adding Routes
- Adding Applications
- Using the Dashboard
- Determining Network Status
- Creating Reports
- Incident Overview
- Incident Investigation
- Event Management
- IP Management
- Service Management
- User Management
- Rule Management
- System Maintenance
- Viewing Logs
- Viewing Audit Trails
- Data Archiving
- Upgrading the Appliance
Day 1:
Chapter 1 – Introduction
- course outline
- course objectives
- housekeeping
- student/instructor introductions
Chapter 2 – Getting Started with CS-MARS
- hardware models
- how CS-MARS works
- CS-MARS Technologies
- Logging in
- User roles
- CLI Overview
- GUI Overview
- Lab
Day 2:
Chapter 3 – CS-MARS Administration
- Adding Devices
- Adding Routes
- Adding Applications
- Understanding Discovery
- Dashboard
- Network Status
- Upgrade Rules and Operating System
- View, archive, and retrieve log files
- Lab
Chapter 4 – Incidents, Rules, Mitigation, and Alerts
- Incident overview
- Incident Analysis
- False Positives
- Activating
- Threat Mitigation
- Event management
- IP management
- Service Management
- User management
- Rule management
- Lab
Chapter 5 – Query/Reports & System Maintenance
- Viewing Logs
- Viewing Audit Trail
- Queries
- Reports
- Data Archiving
- Upgrading the Appliance
- Lab