Cisco Umbrella - access to personal network detected

cisco-umbrella-dns

Classification:

attack

이 페이지는 아직 한국어로 제공되지 않으며 번역 작업 중입니다. 번역에 관한 질문이나 의견이 있으시면 언제든지 저희에게 연락해 주십시오.

Goal

Detect allowed access to personal network through proxy.

Strategy

This rule monitors Cisco Umbrella proxy logs to determine when a host accesses content related to personal VPNs or dynamic and residential IPs, possibly indicating that a user has accessed their personal network.

Triage and response

  1. Assess whether the site identified in the logs is allowed according to the organization’s acceptable use policy.
  2. Contact the user associated with the device to determine if they actively browsed to the sites identified in the log.
  3. If users should not be accessing the site, block the URL via Cisco Umbrella.
  4. If required, begin your organization’s incident response process and investigate.