Cisco is feeding identity intelligence into its security services and suites, aiming to address today's increasingly complex identity security challenges. The overall aim is to unify identity management, networking and security into one platform. The vendor has also expanded its generative artificial intelligence (genAI)-powered security assistant functionality to its security services edge (SSE) solution.
Currently, there is a “blind trust” between authentication and access solutions, which has left organizations vulnerable to attacks. More than a quarter (26%) of Cisco Talos Incident Response engagements in 2023 involved adversaries exploiting compromised credentials on valid accounts, according to the company.
Jeetu Patel, EVP and GM of security and collaboration at Cisco, noted that in most of the hacks that have occurred in recent months, attackers have bypassed traditional hacking methods in favor of credential theft, facilitated by tactics such as social engineering and deep fake technology.
“That's the problem that we're solving with Identity Intelligence,” which basically is “an analytics layer that sits on top of the identity providers,” Patel told SDxCentral.
Announced at the Cisco Live Amsterdam event, Cisco's new Identity Intelligence product aims to bridge the gap between authentication and access. It operates atop customers' existing identity stores, including Cisco Duo, Microsoft Entra ID (formerly Azure AD) and Okta Auth0.
It takes telemetry and pulls data from these sources so users can discover their whole identity population and clean up legacy permissions and vulnerable accounts.
In addition, Identity Intelligence provides AI-driven behavioral analytics and network visibility to create an identity graph, which proactively and reactively detects what’s going on within users’ environments for human and machine identities.
“Behavior analysis is the core … because what we don't want to do is have identity relegated only to the point in time of the authentication,” Patel said. “You want to monitor it on a continuous basis, all the way through access … what we look at is, when is it going outside of the norms, and when does it become anomalous behavior, and what do we do as it's becoming anomalous?”
For detected anomalous behaviors, users can take a graduated response, such as quarantining an identity, killing active sessions or isolating the network using the Cisco Identity Services Engine.
“For the end user, you would have no idea that this is happening at all,” Patel added. “For the administrator, we would be able to provide them with a full identity console that allows you to go out and look at exactly what's happening in the identity graph, and then be able to make sure that you can either apply manually a set of graduated responses or you can set automatically any of those graduated responses that need to happen.”
Identity Intelligence enhances Cisco’s existing security servicesIdentity Intelligence is part of Cisco Security Cloud, the tech giant’s unified security platform.
Cisco integrated Identity Intelligence with its existing security services, including individual products like Cisco Duo, Secure Access and Cisco Extended Detection and Response (XDR), the company's XDP service, as well as its user protection and breach protection suites, to enhance authentication and access control and correlating identity signals.
“What we did was create this fundamentally different approach that said this identity intelligence is part of the fabric of the platform, and it will feed intelligence into every single application that might actually take advantage of the platform,” Patel said. “That's when you can actually have a holistic view at tackling identity.”
Cisco Identity Intelligence is expected to be launched in July this year.
Expanding AI Assistant for SSE and beyondAlong with Identity Intelligence, Cisco also introduced its AI assistant in Secure Access, which is the networking and security giant’s SSE platform.
Last June, Cisco unveiled its AI Assistant for Security and previewed gen-AI-based security capabilities for security policy and security operations center (SOC) assistance.
To ensure high accuracy and prevent so-called AI hallucinations, Cisco has taken the following steps, according to Patel:
- Implemented retrieval-augmented generation techniques
- Isolated AI operations within a strictly defined dataset
- Limited AI to only respond to queries related to its controlled dataset
- Offered multimodal responses including text, tables and graphs
Following the launch of the AI Assistant for firewalls, Cisco now allows customers to create security access policies using natural language processing (NLP) prompts using the power of genAI within its SSE solution.
“The AI Assistant in the firewall, as well as in the SSE system, is largely built to set policy [and] make sure that you can actually rationalize policy,” Patel said, adding the AI Assistant for SOC is for helping with notifications of unusual activities and breaches.
“You should expect that over time, we will have an AI Assistant for almost every product at Cisco,” he added.
More security news from Cisco Live AmsterdamCisco has also announced the integration of its networking capabilities with Cisco Secure Access, which includes Experience Insights powered by Cisco ThousandEyes, designed to quickly reveal connectivity and application issues and foster faster resolution.
Cisco Secure Access also now integrates Catalyst SD-WAN for a single-vendor secure access service edge (SASE) offering.
Comments