39 · Implementing Threat Defense Technologies實作威脅防禦技術

Protection Against Data Loss and Phishing Attacks防範資料外洩與網路釣魚攻擊

Targeted or directed attacks, such as phishing attacks, try to mislead employees into releasing sensitive information such as credit card numbers, social security numbers, or intellectual property. Phishing attacks might direct employees to inadvertently browse malicious websites that distribute additional malware to computer endpoints. No matter how much the threat landscape changes, malicious email remains a vital tool for adversaries to distribute malware because they take threats straight to the endpoint. By applying the right mix of social engineering techniques, such as phishing and malicious links and attachments, adversaries need only to sit back and wait for unsuspecting users to activate their exploits.

針對性或定向攻擊,例如網路釣魚(phishing)攻擊,會試圖誤導員工洩露敏感資訊,例如信用卡號、社會安全號碼或智慧財產。網路釣魚攻擊可能會誘導員工不經意瀏覽惡意網站,導致額外的惡意軟體散布到電腦端點。無論威脅態勢如何變化,惡意電子郵件仍是攻擊者散布惡意軟體的重要工具,因為這能將威脅直接送到端點。透過結合適當的社交工程(social engineering)技巧,例如網路釣魚以及惡意連結與附件,攻擊者只需坐等毫無防備的使用者觸發其漏洞利用(exploit)。

Cisco Email Security Appliance (Cisco ESA) keeps your inbox highly secure. This all-in-one appliance defends against spam, advanced malware, phishing, and data loss. The Cisco ESA protects the email infrastructure and employees who use email at work by filtering unsolicited and malicious email before it reaches the user.

Cisco 電子郵件安全設備(Cisco ESA)能讓您的收件匣保持高度安全。這款一體化設備可防禦垃圾郵件、進階惡意軟體、網路釣魚與資料外洩。Cisco ESA 透過在惡意或未經請求的電子郵件送達使用者之前將其過濾掉,保護電子郵件基礎架構及使用電子郵件工作的員工。

Graymail is categorized as marketing, social networking, and bulk messages. Using an unsubscribe mechanism, end users can indicate to the sender that they want to opt out of receiving such emails. Since mimicking an unsubscribe mechanism is a popular phishing technique, users are wary of clicking the unsubscribe links. For that reason, the Cisco ESA uses graymail detection and filters out the graymail according to the rules and actions that you configure.

灰色郵件(graymail)被歸類為行銷、社群網路及大量寄送的郵件。透過取消訂閱機制,終端使用者可以向寄件者表示希望不再收到此類郵件。由於模仿取消訂閱機制是常見的網路釣魚手法,因此使用者對點擊取消訂閱連結會有所警惕。因此,Cisco ESA 使用灰色郵件偵測功能,依您所設定的規則與動作過濾掉灰色郵件。

On the other side, the anti-malware system gives the Cisco Secure Web Appliance (formerly, Cisco Web Security Appliance [WSA]), the distinction of being the first solution on the market to offer multiple anti-malware scanning engines on a single, integrated appliance. This system uses the Cisco Dynamic Vectoring and Streaming (DVS) engine, and third-party verdict engines from Webroot, Sophos, and McAfee, to provide protection against the widest variety of web-based threats. These threats can range from adware, browser hijackers, phishing, and pharming attacks to more malicious threats such as rootkits, Trojans, worms, system monitors, and keylogger. Furthermore, Cisco Web-Based Reputation Filtering prevents client devices from accessing dangerous websites that contain viruses, spyware, malware, or phishing links. Web reputation filters analyze web server behavior and assign a reputation score to a URL to determine the likelihood that it contains URL-based malware. Web reputation filtering helps protect against URL-based malware that threatens end-user privacy and sensitive corporate information. The Cisco Secure Web Appliance uses URL reputation scores to identify suspicious activity and stop malware attacks before they occur.

另一方面,防惡意軟體系統讓 Cisco Secure Web Appliance(前身為 Cisco 網頁安全設備[WSA])成為市場上第一款在單一整合設備上提供多重防惡意軟體掃描引擎的解決方案。此系統使用 Cisco 動態向量與串流(DVS)引擎,以及來自 Webroot、Sophos 與 McAfee 的第三方裁定引擎,以提供對抗最廣泛網頁威脅的防護。這些威脅範圍涵蓋廣告軟體、瀏覽器綁架程式、網路釣魚、域名嫁接(pharming)攻擊,乃至於更惡意的威脅,例如 rootkit、木馬程式、蠕蟲、系統監控程式與鍵盤側錄程式。此外,Cisco 網頁信譽過濾功能可防止用戶端裝置存取含有病毒、間諜軟體、惡意軟體或網路釣魚連結的危險網站。網頁信譽過濾器會分析網頁伺服器行為,並為 URL 指定信譽分數,以判斷其含有以 URL 為基礎之惡意軟體的可能性。網頁信譽過濾有助於防範威脅終端使用者隱私與企業敏感資訊的 URL 型惡意軟體。Cisco Secure Web Appliance 使用 URL 信譽分數來識別可疑活動,並在惡意軟體攻擊發生之前將其阻止。

In addition to protecting against phishing attacks, enterprises can also protect against data loss by scanning the web and email traffic leaving the networks. Intellectual property is one of an organization's most important business assets and it can be lost through inadvertent disclosure, or through malicious action by an employee or an outsider. Businesses lose billions of dollars each year from theft of trade secrets.

除了防範網路釣魚攻擊之外,企業也可以透過掃描離開網路的網頁與電子郵件流量來防範資料外洩。智慧財產是組織最重要的商業資產之一,可能因為員工或外部人員的疏忽揭露或惡意行為而遺失。企業每年因商業機密遭竊而損失數十億美元。

Sensitive data can leave the network perimeter by many different means, such as email, web applications, file transfers, and instant messaging. Enforcing content policies at the network perimeter is an effective defense against accidental data loss. Cisco partners with RSA, a data loss prevention (DLP) solution provider, to provide integrated DLP technology on Cisco ESA and Cisco Secure Web Appliance.

敏感資料可能透過電子郵件、網頁應用程式、檔案傳輸與即時通訊等多種方式離開網路邊界。在網路邊界強制執行內容政策,是防範意外資料外洩的有效手段。Cisco 與資料外洩防護(DLP)解決方案供應商 RSA 合作,在 Cisco ESA 與 Cisco Secure Web Appliance 上提供整合式 DLP 技術。

A primary goal of data security systems is to protect against theft of intellectual property and confidential customer data. Doing so helps organizations comply with legal and regulatory standards. The DLP feature secures your organization's proprietary information and intellectual property and enforces compliance with government regulations by preventing users from maliciously or unintentionally emailing sensitive data from your network or uploading content on public cloud services. You define the types of data that your employees are not allowed to email or upload by creating DLP policies that are used to scan email and web traffic for any data that violate laws or corporate policies.

資料安全系統的主要目標是防範智慧財產與機密客戶資料遭竊。這麼做有助於組織遵循法律與法規標準。DLP 功能可保護貴組織的專有資訊與智慧財產,並透過防止使用者惡意或無意間從網路電子郵件傳送敏感資料,或將內容上傳到公有雲服務,來確保符合政府法規。您可以透過建立 DLP 政策來定義員工不得以電子郵件傳送或上傳的資料類型,這些政策用於掃描電子郵件與網頁流量,找出任何違反法律或企業政策的資料。

The Cisco Secure Firewall also provides protection against phishing attacks and other malware, such as viruses, worms, or Trojans that might be included in the incoming and outgoing traffic, as well as various malware sites and applications.

Cisco Secure Firewall 也能防範進出流量中可能包含的網路釣魚攻擊及其他惡意軟體(例如病毒、蠕蟲或木馬程式),以及各種惡意網站與應用程式。

What is the main functionality of the Cisco Secure Web Appliance?Cisco Secure Web Appliance 的主要功能是什麼?