Cisco Security Monitoring, Analysis, and Response System

This is an old revision of this page, as edited by Bswilson (talk | contribs) at 20:17, 7 November 2008 (Created the Supported Types section and added formatting.). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Cisco Security Monitoring, Analysis, and Response System (MARS) is a security monitoring tool for network devices. Together with the Cisco Security Manager (CSM) product, MARS make up the 2 primary components of the Cisco Security Management Suite.

MARS is an appliance-based solution that provides insight and control of existing security deployments. It can monitor security events and information from a wide variety of sources, including third-party devices and hosts. The correlation engine in MARS can identify anomalous behavior and security threats and can use large amounts of information collected for forensics analysis and compliance reporting.


Features

  • Learns the topology, configuration and behavior of your environment
  • Automatically updates knowledge of new Cisco IPS signatures, for up to the minute reporting on your environment
  • Promotes awareness of environmental anomalies with network behavior analysis using NetFlow and syslog
  • Provides simple access to audit compliance reports with more than 150 ready-to-use customizable reports
  • Makes precise recommendations for threat mitigation, including the ability to visualize the attack path and identify the source of the threat with detailed topological graphs that simplify security response at Layer 2 and Layer 3
  • Integrates with the Cisco Security Manager to correlate security events with the configured firewall rules and intrusion prevention system (IPS) signatures that can affect the security event.


Supported Types

MARS centrally aggregates logs and events from a wide range of popular devices:


References

  1. Cisco Security Monitoring, Analysis and Response System product page
  2. Cisco Security Management Suite
  3. Cisco Security Monitoring, Analysis and Response System 4.2 Q&A
  4. The Unofficial Cisco MARS Blog


--bswilson (talk) 20:16, 7 November 2008 (UTC)