Cisco Umbrella - allowed request to unsafe URL category

cisco-umbrella-dns

Classification:

attack

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detect allowed requests to URLs associated with unsafe categories.

Strategy

This rule monitors Cisco Umbrella proxy logs to determine when a host accesses URLs related to unsafe categories, such as Chat and Instant Messaging, Extreme content, Hacking, Illegal Activities, Illegal Downloads, Illegal Drugs, Terrorism and Violent Extremism, Child Abuse Content, Hate Speech, and Pornography. This indicates a potential risk to the network’s security.

Triage and response

  1. Assess whether the site identified in the logs is allowed according to the organization’s acceptable use policy.
  2. Contact the user associated with the device to determine if they actively browsed to the sites identified in the log.
  3. If users should not be accessing the site, block the URL via Cisco Umbrella.
  4. If required, begin your organization’s incident response process and investigate.