Understanding EVE
Learn more about the Encrypted Visibility Engine, an exclusive Cisco Secure Firewall feature
Almost all traffic across firewalls is encrypted, making it invisible to traditional inspection. Complex, high-volume traffic is originating from and going to more sources and destinations, across more protocols and applications than ever before. What can be done to gain visibility into these communications, where threats may loom unnoticed and important policies for client applications go unenforced? And what can we do to see and classify encrypted application traffic to ensure accurate policy are enforced across traffic types? Cisco’s Encrypted Visibility Engine (EVE) applies Machine Learning to metadata extracted from many network protocols to provide insights on possible cyber threat activity and client applications. Supported protocols include TLS, QUIC, HTTP, STUN, SSH, and the custom protocol used by Tofsee Malware. Because EVE is dynamically updated via the Vulnerability Database (VDB) update system, dynamic updates can be delivered to firewalls when they are ready for release, including net new protocols and classifiers for firewalls on version 10.0.
EVE employs an inline machine learning classifier, providing more specificity and accuracy than traditional methods that rely upon looking up hashes of fingerprints in hopes of matching a previously identified bad connection. EVE’s inline machine learning is trained and improved by continuous analysis of nearly 40 billion network communications per day within Cisco and partner networks to classify and characterize the traffic based upon real-world findings and signals. Potentially malicious traffic is rated with a Threat Confidence Score, ranging from 0% (high confidence the traffic is benign) to 100% (high confidence the traffic is malicious). Once a fingerprint is generated and analysis is performed, the resulting analysis is cached to allow efficient characterization of this traffic as more of it passes through the firewall.
Encrypted Inspection
Every TLS and QUIC encrypted session starts with a session handshake, beginning with a message called the Client Hello. This is where the parameters and protocol options used in the connection are negotiated. EVE looks within the unencrypted handshake data and generates fingerprints incorporating the TLS client hello, destination IP address, port, server name, and other signals. EVE can identify thousands of different client processes to assist in policy enforcement and provide valuable information on whether the traffic is likely associated with malware or other cyber threats. All of this is accomplished without needing to decrypt the traffic itself.
Unencrypted Inspection
EVE applies the same machine learning analysis to unencrypted traffic as well. HTTP and STUN sessions are also inspected, as threat actors leverage these protocols due to their common appearance in enterprise networks and their utility for passing malicious control signals. As it does for encrypted traffic, EVE analyzes the beginning parts of the connection and performs ML-based verification. Because this traffic is not encrypted, the firewall performs traditional intrusion and malware inspection also. In conjunction with Secure Firewall AppID, EVE helps to characterize HTTP and STUN traffic to identify client applications, assign a Threat Confidence Score, and support per-application policy enforcement.
Intelligent Decryption Bypass
Cisco Secure Firewall includes simple and powerful decryption capabilities, such as Intelligent Decryption Bypass (a capability enabled by EVE) to exempt low-risk traffic from decryption. By performing its analysis of the decrypted traffic and providing the Threat Confidence Score, EVE informs Intelligent Decryption Bypass as to which traffic is more likely to be benign, simplifying the decisions on which traffic ought to be most targeted for decryption and deep inspection.
Using Intelligent Decryption Bypass, organizations can leverage EVE threat analysis to automatically bypass decryption of very low risk traffic (such as Apple, Google, or Microsoft traffic) and conserve firewall hardware resources for decryption of higher risk or unknown traffic. This allows firewall administrators to optimize their decryption with just a few settings, freeing up significant firewall resources.
Monitor and Protect Modes
EVE operates in one of two modes: Monitor, where inspected traffic and detected applications are classified and alerts are generated for communications determined to be malicious, and Protect, which also blocks traffic identified as malicious. With either mode, EVE augments the application detection and capabilities of Cisco AppID, Secure Firewall’s application identification engine. Applications can be allowed or blocked as normal via the Access Control policy, but with EVE enabled, the visibility and accuracy of AppID is improved. Using the EVE Protect setting, traffic with a Threat Confidence Score of 99% (Very High) or higher is blocked by default, with an option to also block traffic with a Threat Confidence Score of 90% (High) or above. Traffic with a lower Threat Confidence Score is logged to Unified Events and can be exported to any SIEM or external log destination (such as Splunk), providing valuable visibility into endpoint behavior and potential compromise.
Handling Exceptions
Exceptions can be easily created to allow traffic to never be blocked by EVE, regardless of threat confidence score. These exceptions can be added from the EVE section in the Access Control policy or from the Unified Events page, allowing simple exception creation when viewing block or alert events pertaining to EVE identified traffic.
Shadow Traffic
Shadow traffic is encrypted communication that is routed through software or protocols that defy access control measures. This kind of traffic avoids inspection and intended security controls, giving opportunity to malware threats, exfiltration attempts, and other cybersecurity risks. Because it provides such in-depth visibility to client applications across even encrypted sessions, EVE is uniquely poised to provide insights into this type of traffic.
EVE provides a Shadow Traffic Widget in Secure Firewall to show indications of the following shadow traffic threats:
- Evasive VPNs: applications that use Virtual Private Networks to route traffic, masking the actual destination of an encrypted session.
- Encrypted DNS: DNS servers and applications that provide Domain Name System lookup responses over encrypted channels, which avoid the controls that may be placed upon DNS resolution and responses.
- Multihop Proxies: traffic passing from a client to a proxy that in turn passes to one or more proxies becomes difficult to trace to origin and may indicate an attempt to hide attack attempts.
- Domain Fronting: a widely trusted host is provided in the TLS handshake, but the HTTP host header specifies a different backend service under the same provider. Attackers exploit CDNs and similar shared-hosting infrastructure to route traffic to undesirable endpoint domains, bypassing filters and controls placed upon those endpoints.
- Fake TLS: sessions with modified handshake data, often involving manipulation of the cipher suite data, where cryptographic capabilities are exchanged. These sessions attempt to masquerade as trusted sessions and applications but are intended to communicate with applications and network locations that are not trusted. For example, a Fake TLS session might represent itself as being a Google Chrome update process, but communicate with an untrusted server, with the encrypted payload containing command-and-control beaconing.
More EVE Dashboard Insights
EVE provides several other dashboard widgets which give insights into the processes and threats that have been evaluated:
- Discovered Processes: displays the top client processes used in the network along with their connection counts. Clicking a process name filters the Connection Events page by that process to allow quick assessment of that application’s communications.
- Threat Confidence: shows connections categorized by confidence levels of threat detection. Clicking a confidence level filters the Connection Events page accordingly to highlight likely malicious communications.
- Connections with Detected Process Names: displays the total count of connections where EVE identified any client processes.
- Malicious Processes: shows counts of malicious client processes identified by EVE with high and very high threat confidence levels.
- Malicious Process Responder IPs: lists the top destination IP addresses identified as malicious, with filtering capabilities to view related connection events.
- Malicious Process Contacted Domains: displays the top domain names identified as malicious, with filtering to view related connection events.
- Blocked Connections: shows the count of total connections blocked by EVE.
Learn More and Try EVE
Curious to get hands-on with EVE and Cisco Secure Firewall? Try the Secure Firewall Test Drive! This free tool allows you to work with a real Secure Firewall environment to better understand EVE and Secure Firewall firsthand.
Updated about 11 hours ago
