TECSEC-2345.Pdf
Total Page:16
File Type:pdf, Size:1020Kb
>250 not OK Going on the defensive with Cisco Email Security Robert Sherwin, Filipe Lopes TECSEC-2345 Cisco Webex Teams Questions? Use Cisco Webex Teams to chat with the speaker after the session How 1 Find this session in the Cisco Events Mobile App 2 Click “Join the Discussion” 3 Install Webex Teams or go directly to the team space 4 Enter messages/questions in the team space TECSEC-2345 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 3 • Introductions • Understanding the Email Pipeline • Base Configuration Settings • IP & Domain Reputation • Sender Group and Mail Flow Policies • Engine setup and tuning Agenda • Delivery recommendations • Threat Defense Configuration • Spoofing and Phishing Detection • Attachment Control and Defense • Cisco Threat Response • Monitoring & Tools • Summary & Checklist TECSEC-2345 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 5 Introductions This sessions speakers •Technical Marketing Engineer, Email Security •Technical Marketing Engineer, Email Security •12 years at Cisco since CSAP, joined TME •Joined Cisco December 2011 team 2019 •Cisco Live Speaker in US, EMEA, APJC •MsC degree in Systems Engineering •18 years of combined Network, Data Center, •Speaker at Multiple Conferences (Portugal and Security experience Wireless Conference, Smart Mobility Summit, •6 years in Cisco TAC, joined TME team in IoT Vodafone Conference) 2018 •Cisco’s Technical Lead for Web Summit •Based out of Morrisville, NC (US) (~60.000 attendees) •Part of the Core Team that Designs, Builds and Operates CiscoLive! Europe •Based out of Lisbon, Portugal (EU) Filipe Lopes Robert Sherwin ([email protected]) ([email protected]) TECSEC-2345 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 6 Introductions Email Security specific sessions this week 250 not OK: Going on the From Zero to DMARC Hero API Integrations for Cisco Email defensive with Cisco Email • TECSEC-2310 Security Security • Monday, January 27 | 02:30 PM - 06:45 • DEVNET-2326 • TECSEC-2345 PM • Tuesday, January 28 | 10:00 AM - 10:45 • Monday, January 27 | 08:45 AM - 01:00 • Hall 8.0, Session Room D138 AM PM • Hall 6 - The Hub, DevNet Classroom 2 • Hall 8.1, CC8, Room 8.29/8.30 SPF is not an acronym for AsyncOS Release 13.0 - What's Fixing Email! - Cisco Email "Spoof"! Let's utilize the most new in Email Security Security Advanced out of the next layer in Email • LTRSEC-2319 Troubleshooting Security! • Thursday, January 30 | 09:00 AM - • BRKSEC-3265 • BRKSEC-2327 01:00 PM • Friday, January 31 | 09:00 AM - 10:30 • Thursday, January 30 | 02:45 PM - • Hall 8.0, Session Room B110 AM 04:15 PM • Hall 8.0, Session Room A104 • Hall 8.0, Session Room B115 TECSEC-2345 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7 Introductions Our schedule for this session • Technical Seminar Agenda – Morning Half Day • 08:45 – 10:45 (2 hours) • 10:45 – 11:00 Break • 11:00 – 13:00 (2 hours) • 13:00 – 14:30 Lunch TECSEC-2345 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 8 Audience Questions We have 4.25 hours... Let’s get to know each other! • Are you new to Cisco Email Security? Or, are you a Pro? • What is your primary purpose of attending our TECSEC? • Have you attended our session previous years, or at another Cisco Live? • What is the top 3 items for Email Security that you want to take away today? • What tools, software makes your daily life easier? As we go along – if you have a question or comment, let us know! We are happy to make this an interactive session. We’re here to help you. (And, perhaps you will help us, too!) We hope that you enjoy the session and your week at Cisco Live! TECSEC-2345 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 9 Versions of AsyncOS Recommended version(s) that we will discuss today include: • General Deployment • General Deployment (GD) (GD) • 12.5.1-037 • 12.5.0-658 • Limited Deployment • Limited Deployment (LD) (LD) • 13.0.0-375 • 13.0.0-239 Email Security Security Management Note: Cloud Email Security (CES) ESA and SMA versions are managed by Cisco TECSEC-2345 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 10 Release Notes & User Guide for AsyncOS 12.0 http://cs.co/email_security_support http://cs.co/12_0_release_notes http://cs.co/12_0_user_guide TECSEC-2345 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 11 Release Notes & User Guide for AsyncOS 13.0 http://cs.co/email_security_support http://cs.co/13_0_release_notes http://cs.co/13_0_user_guide TECSEC-2345 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 12 Not getting notifications of new versions? Cisco Support Community – Email Security Cisco Notification Service: https://supportforums.cisco.com/community/5756/email-security https://www.cisco.com/cisco/support/notifications.html TECSEC-2345 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 13 Bookmark & Subscribe to these today! Global Email Issues / Notifications Cloud Email Status https://urgentnotices.statuspage.io/ https://status.ces.cisco.com TECSEC-2345 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 14 The Email Pipeline Cisco Email Security Mail Flow Pipeline INCOMING Connection level protection Sender Reputation Filtering (SBRS) Anti-spoof, throttling & verification Connection Filtering Sending domain verdict analysis Sender Domain Reputation (SDR) * Message Filtering Spam protection, URL analysis Content Scanning (CASE) Virus protection Anti-virus Scanning (AV) Per Malware protection Advanced Malware Protection (AMP) - policy Marketing/Social/Bulk email detection Graymail Detection Content protection Content Filtering Malware, Phishing, URL threat protection Outbreak Filtering (VOF) Phishing behavioral analytics & protection Advanced Phishing Protection (APP) TECSEC-2345 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 16 Cisco Email Security Mail Flow Pipeline OUTBOUND Connection level protection Sender Reputation Filtering (SBRS) Encryption & authentication enforcement Connection Filtering * Message Filtering Spam protection, URL analysis Content Scanning (CASE) Virus protection Anti-virus Scanning (AV) Malware protection Advanced Malware Protection (AMP) Per - Marketing/Social/Bulk email detection Graymail Detection policy Content protection Content Filtering Malware, Phishing, URL threat protection Outbreak Filtering (VOF) Sensitive data protection & encryption Data Loss Prevention (DLP) Brand protection, SPF/DKIM/DMARC administration Domain Protection (DP) TECSEC-2345 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 17 Cisco Email Security Mail Flow Pipeline Post Delivery Unsubscribe validation and management Graymail Unsubscribe URL reporting + end-user click tracking URL rewrite & tracking Verdict change alerting & mailbox administration AMP retrospection & remediation Threat detection, investigation, remediation Cisco Threat Response (CTR) TECSEC-2345 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 18 Within these layers of email security, Cisco Email Security features, and services that always come with acronyms... Typical acronyms used in email security Who loves acronyms? Cisco loves to utilize acronyms a lot... ADFS : Active Directory Federation Services HAT : Host Access Table TA : Threat Analyzer AMP : Advanced Malware Protection ICID : Incoming Connection ID TLS : Transport Layer Security API : Application Programming Interface IETF : Internet Engineering Task Force TME : Technical Marketing Engineer APPC : Advanced Phishing Protection Console IMS : Intelligent Multi-Scan TOC : Threat Operations Center AS (A/S) : Anti-spam IPAS : IronPort Anti-Spam UI : User Interface AV (A/V) : Anti-virus ISQ : IronPort Spam Quarantine vESA (ESAv/ESAV) : Virtual Email Security BATV : Bounce Address Tag Validation LDAP : Lightweight Directory Access Protocol Appliance BEC : Business Email Compromise MAR : Mailbox Auto Remediation vSMA (SMAv/SMAV) : Virtual Security BIMI : Brand Indicator Message Identification MFP: Mail Flow Policy Management Appliance CASE : Context Adaptive Scanning Engine MID : Message ID VOF : Virus Outbreak Filtering CDP (DMP) : Cisco Domain Protection MX : Mail Exchange (DNS record) WBRS : Web Base Reputation Service CES : Cloud Email Security NTP : Network Time Protocol WSA : Web Security Appliance CLI : Command Line Interface PoC : Proof of Concept XML : Extensible Markup Language CRES (see RES) PoV : Proof of Value 2FA : (2) Two Factor Authentication CTR : Cisco Threat Response PXE : PostX Encryption DCID : Delivery Connection ID RAT : Recipient Access Table DHAP : Directory Harvest Attack Prevention REPENG : Reputation Engine DKIM : DomainKeys Identified Mail RID : Recipient ID DLP : Data Loss Prevention RES : Registered Envelope Service DMARC : Domain-based Message SAML : Security Assertion Markup Language Authentication, Reporting and Conformance SBG : Security Business Group DNS : Domain Name System SBRS : Sender Base Reputation Service ESA : Email Security Appliance SDR : Sender Domain Reputation ESMTP : Extended (or Enhanced) Simple Mail SLBL : Safe List Block List Transfer Protocol SMA: Security Management Appliance ETF : External Threat Feed S/MIME : Secure/Multipurpose Internet Mail EUQ : End-user Quarantine (aka Spam Extensions Quarantine) SMTP : Simple Mail Transfer Protocol FA : File Analysis (Threat Grid) SNMP : Simple Network Management Protocol FED : Forged Email Detection SOC : Security