Identifying who and what is connecting is the first step towards network security and protecting your enterprise. The automated application of wired and wireless policy enforcement ensures that only authorized and authenticated users and devices are allowed to connect. At the same time. real-time attack response and threat protection is required to secure and meet audit and compliance requirements.
The boundaries of IT’s domain now extend beyond the four walls of the business’ physical location. With the need to connect anywhere, anytime, how does IT maintain visibility and control without sacrificing security? It starts with a three-step plan.
Network security starts with visibility of all devices, because you can’t secure what you can’t see. Here’s a look at the tools being rolled out to increase visibility:
The final element of network security is response: the ability to respond to attack event data presented by other security vendors. Aruba 360 Security Exchange lets you automate security threat remediation or enhance a service using popular third-party solutions like firewalls, MDM/EMM, MFA, visitor registration, and SIEM tools. Leveraging the context intelligence included in Aruba ClearPass allows organizations to ensure that security and visibility is provided at a device, network access, traffic inspection, and threat protection level.
Using a common-language (REST) API, syslog messaging, and a built-in repository called ClearPass Exchange, automated workflows and decisions help simplify tasks and secure the enterprise – no more complex scripting languages and tedious manual configuration. And for faster integration, ClearPass Extensions allows partners to upload an extension, for real time delivery of new services to joint customers.
With ClearPass Exchange, networks can automatically take action:
Network events can also prompt firewalls, SIEM, and other tools to inform ClearPass to take action on a device by triggering actions in a bidirectional manner. For example, if a user fails network authentication multiple times, ClearPass can trigger a notification message directly to the device or blacklist the device from accessing the network.
Modern threats to network security are now evolving from inside organizations. They may involve malicious, compromised, or negligent users, systems, and devices. An enterprise can no longer look at security the same way. Machine learning and behavior analysis are the next steps to solving the dual crisis of better resourced threats and undervalued security operations.
Aruba’s IntroSpect UEBA plugs the gap between device visibility and control, and the secondary threat of malicious behavior. It detects small changes in behavior that, when put into context over a period of time, become indicative of attacks that have evaded traditional security defenses.
With the integration of IntroSpect and ClearPass, the prevision alerts generated by one mean that the other can respond with pre-determined policy-based actions and cut off the threat before it does damage.
Over 7,000 customers in 100 countries have secured their network and their enterprise with Aruba ClearPass for better visibility, control, and response. To start the conversation about how you can better protect your organization, contact WEI today.