{"id":3588,"date":"2024-05-15T16:11:09","date_gmt":"2024-05-15T21:11:09","guid":{"rendered":"https:\/\/bluecatnetworks.com\/?p=276764"},"modified":"2024-05-15T16:11:09","modified_gmt":"2024-05-15T21:11:09","slug":"detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/15\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4\/","title":{"rendered":"Detect anomalies and CVE risks with Infrastructure Assurance 8.4\u00a0"},"content":{"rendered":"<p>For IT operations teams needing deeper and more automated insight into anomalies and vulnerabilities in their security and network infrastructure, BlueCat Infrastructure Assurance 8.4 is now available.<\/p>\n<p><a href=\"https:\/\/bluecatnetworks.com\/products\/infrastructure-assurance\/\">Infrastructure Assurance<\/a> avoids network disruption with automation. It is a proactive observability, troubleshooting, and remediation solution for network and security infrastructure like DDI, firewalls, and load balancers. It continuously scans infrastructure for issues and serves up recommended remediation steps that IT operations teams can use to address issues before they cause harm and avoid costly outages.<\/p>\n<p>In this post, we\u2019ll highlight new features in the Infrastructure Assurance 8.4 release, including an anomaly detection engine that uses machine learning models to identify outliers for several metrics in your Palo Alto Networks and BlueCat Integrity devices. Further, we\u2019ll delve into the new CVE analysis engine that uncovers device vulnerabilities for certain CVEs. And finally, we\u2019ll briefly highlight other reporting, alerting, and knowledge enhancements.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"js-loaded size-full wp-image-23745 wp-image-276785 has-media-category media-cat-blog-pics-and-headers img-fluid format-jpg v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-jpg v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-jpg v-media-processed\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4.jpg?w=640&#038;ssl=1\" alt=\"Diagram depicting how Infrastructure Assurance\" s anomaly detection and cve analysis engines work   align=\"center\" data-image-id=\"276785\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-1.jpg 584w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-2.jpg 1200w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-3.jpg 380w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-4.jpg 790w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-5.jpg 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4.jpg 2048w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-6.jpg 276w\" data-context=\"container\" sizes=\"auto, 100vw\" data-custom-sizes=\"1\" loading=\"lazy\"><\/p>\n<h2>Anomaly detection engine<\/h2>\n<p>The anomaly detection engine uses machine learning models to identify outliers and unusual behaviors for several metrics in your Palo Alto Networks Next-Generation Firewalls and <a href=\"https:\/\/bluecatnetworks.com\/products\/integrity\/\">BlueCat Integrity<\/a> DNS and DHCP Server (BDDS) devices. An anomaly detection generates a warning alert.<\/p>\n<p>With awareness of such anomalies, Infrastructure Assurance can identify early symptoms and emerging issues, allowing you to address them before they become bigger problems. Our implementation uses the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Standard_score\">standard score or z-score<\/a> method to detect anomalies. A z-score measures exactly how many standard deviations above or below the mean a data point is.<\/p>\n<p>The system evaluates several metrics based on a week\u2019s worth of data points. The newly embedded time-series database stores these data points. When a new data point is collected, a z-score is calculated. An alert is generated if the z-score of that data point is greater than 3 (or less than -3). The alert will remain active for 10 minutes. During that time, if no other anomalies are detected, the alert will resolve itself and go into the cooldown state. If another data point has a z-score greater than 3 (or less than -3), the alert will remain active for another 10 minutes.<\/p>\n<p>Next, we\u2019ll look at what metrics we\u2019re applying to the method to detect outliers and why they\u2019re important.<\/p>\n<h3>Anomalies for Palo Alto Networks Next-Generation Firewalls<\/h3>\n<p>Palo Alto Networks Next-Generation Firewalls keep a count of all drops and what causes them. Analyzing these drop counters provides insights into the processes, packet flows, and sessions on the firewall. Infrastructure Assurance 8.4 now analyzes four global drop counters for anomaly detection.<\/p>\n<ul>\n<li><b>flow_tcp_non_sync_drop:<\/b> If this counter increases suddenly and significantly, it is indicative of asymmetric routing in your environment. Applications will encounter issues. For example, websites are only loading partially, or applications are simply not working.<\/li>\n<li><b>flow_policy_deny:<\/b> This counter records increments when a security policy denies a session setup for network traffic. An abnormal increase in this counter could mean an issue such as a misconfigured rule, a scanner on the network, or increased attempted connections from a rogue device.<\/li>\n<li><b>flow_action_close:<\/b> The firewall sends a TCP reset (RST) when it detects a threat in the traffic flow. This counter tracks the number of closed TCP sessions by injecting RST. A sudden increase in this counter can potentially pose a security risk, so you\u2019ll want to investigate immediately.<\/li>\n<li><b>nat_xlat_address_resolved_fail:<\/b> This counter provides information about the number of times that FQDN resolve failed. If nat_xlat_address_resolved_fail suddenly spikes, this could mean there is a problem with resolving DNS on the firewall.<\/li>\n<\/ul>\n<h3>Anomalies for BlueCat Integrity BDDSes<\/h3>\n<p>For Integrity enterprise customers, <a href=\"https:\/\/bluecatnetworks.com\/blog\/five-ways-to-avert-issues-with-bluecat-infrastructure-assurance\/\">Infrastructure Assurance provides proactive observability and automated troubleshooting<\/a> to root out hidden issues in your DDI environment, along with recommended steps to address them.<\/p>\n<p>A new anomaly alert in Infrastructure Assurance 8.4 for Integrity BDDSes is \u201cA sudden increase in SERVFAIL\u201d. A temporary server overload or a temporary connectivity disruption can cause <a href=\"https:\/\/bluecatnetworks.com\/blog\/the-top-four-dns-response-codes-and-what-they-mean\/\">SERVFAIL errors<\/a>. A small number of SERVFAIL errors may not be&nbsp;of&nbsp;concern, but a spike in SERVFAIL errors could mean a combination of many issues that can lead to bigger problems.<\/p>\n<p>For example, it could be a technical problem with your DNS servers, firewalls blocking users from going to a domain, or DNSSEC verification failures. These issues can cause downtime for many domains, users, or both. Any of these cases warrant an investigation.<\/p>\n<p>In the screenshot below, Infrastructure Assurance displays anomalies it has identified in Integrity BDDSes, including issue descriptions and recommended remediation steps.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"js-loaded size-full wp-image-23745 wp-image-276780 has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4.png?w=640&#038;ssl=1\" alt=\"Screenshot of Infrastructure Assurance displaying anomalies it has identified in Integrity BDDSes\"   align=\"center\" data-image-id=\"276780\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-9.png 584w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-10.png 1200w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-11.png 380w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-12.png 790w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-13.png 276w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4.png 1430w\" data-context=\"container\" sizes=\"auto, 100vw\" data-custom-sizes=\"1\" loading=\"lazy\"><\/p>\n<p>And a final note: This anomaly detection feature is not enabled by default. Infrastructure Assurance customers should <a href=\"https:\/\/care.bluecatnetworks.com\/s\/login\/\">contact Customer Success<\/a> for assistance with enabling it.<\/p>\n<h2>CVE analysis engine<\/h2>\n<p><a href=\"https:\/\/www.coalitioninc.com\/blog\/2024-cyber-threat-index\">Coalition\u2019s 2024 Cyber Threat Index<\/a> anticipates that the total count of published common vulnerabilities and exposures (CVEs) for 2024 will rise by 25%. This expected sharp increase in CVEs further heightens security concerns. CVE disclosures put tremendous pressure on an already overloaded security team, making automation essential.<\/p>\n<p>Infrastructure Assurance\u2019s CVE analysis engine analyzes a network device\u2019s vulnerability. The engine automatically compares CVE information from <a href=\"https:\/\/cve.mitre.org\/\">MITRE\u2019s CVE database<\/a> and <a href=\"https:\/\/nvd.nist.gov\/\">NIST\u2019s National Vulnerability Database<\/a> with OS versions running on the devices in your network. Using this comparison, Infrastructure Assurance will automatically generate alerts for devices exposed to certain CVEs.<\/p>\n<p>Imagine the possibility of receiving near real-time alerts about new CVEs that impact your environment. Coupled with Infrastructure Assurance\u2019s new system-defined CVE report, you can get a list of devices with vulnerabilities categorized by severity with just a click. You can run this report after every upgrade to detect new CVEs impacting your environment.<\/p>\n<p>In the screenshots below, Infrastructure Assurance\u2019s system-defined CVE report displays devices with CVE vulnerabilities, categorized by severity.<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"js-loaded size-full wp-image-23745 wp-image-276779 has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-1.png?resize=640%2C406&#038;ssl=1\" alt=\"Screenshot of Infrastructure Assurance\u2019s system-defined CVE report displaying devices with CVE vulnerabilities\" width=\"640\" height=\"406\" align=\"center\" data-image-id=\"276779\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-14.png 584w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-15.png 380w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-16.png 790w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-17.png 276w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-1.png 936w\" data-context=\"container\" sizes=\"auto, 100vw\" data-custom-sizes=\"1\" loading=\"lazy\"><\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" loading=\"lazy\" decoding=\"async\" class=\"js-loaded size-full wp-image-23745 wp-image-276778 has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-2.png?resize=640%2C402&#038;ssl=1\" alt=\"Screenshot of Infrastructure Assurance\u2019s system-defined CVE report displaying devices with CVE vulnerabilities\" width=\"640\" height=\"402\" align=\"center\" data-image-id=\"276778\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-18.png 584w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-19.png 380w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-20.png 790w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-21.png 276w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-2.png 936w\" data-context=\"container\" sizes=\"auto, 100vw\" data-custom-sizes=\"1\"><\/p>\n<p>Infrastructure Assurance 8.4\u2019s new CVE analysis engine brings more than 200 alerts, dated from 2022 and onward, to the release. Supported devices for the CVE analysis engine include Broadcom Symantec (formerly Blue Coat) Content Analysis series and ProxySG, Check Point secure gateways, Cisco ASA, F5 BIG-IP Local Traffic Manager (LTM), Fortinet FortiGate firewalls and Palo Alto Networks Next-Generation Firewalls.<\/p>\n<p>Further, so as not to overwhelm the Issues page with more than 200 new alerts, Infrastructure Assurance 8.4 includes a new rule category called CVE. By design, the Issues page and the Knowledge Explorer page exclude rules from the CVE category.<\/p>\n<p>To see rules in the CVE category, reset the default filters by selecting CVE in the Categories column. The new rule headline shows the CVE ID (CVE-2024-xxx). The description consists of details about the vulnerability.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"js-loaded size-full wp-image-23745 wp-image-276777 has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-3.png?w=640&#038;ssl=1\" alt=\"Screenshot of Infrastructure Assurance displaying rules in the CVE category\"   align=\"center\" data-image-id=\"276777\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-22.png 584w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-23.png 380w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-24.png 790w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-25.png 276w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-3.png 936w\" data-context=\"container\" sizes=\"auto, 100vw\" data-custom-sizes=\"1\" loading=\"lazy\"><\/p>\n<p>You can also navigate to your CVE alerts from the Issues-At-A-Glance widget from the analytics dashboard.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"js-loaded size-full wp-image-23745 wp-image-276777 has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-3.png?w=640&#038;ssl=1\" alt=\"Screenshot of Infrastructure Assurance showing CVE alerts in the issues-at-a-glance widget\"   align=\"center\" data-image-id=\"276777\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-22.png 584w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-23.png 380w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-24.png 790w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-25.png 276w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-3.png 936w\" data-context=\"container\" sizes=\"auto, 100vw\" data-custom-sizes=\"1\" loading=\"lazy\"><\/p>\n<h2>Reporting, alerting, and knowledge enhancements<\/h2>\n<p>Infrastructure Assurance 8.4 also includes enhancements to reporting features, more control over how many alerts you receive, and more than 200 auto-detection knowledge enhancements.<\/p>\n<h3>A new system-defined PCI DSS compliance report<\/h3>\n<p>The release introduces a new out-of-the-box <a href=\"https:\/\/en.wikipedia.org\/wiki\/Payment_Card_Industry_Data_Security_Standard\">Payment Card Industry Data Security Standard<\/a> (PCI DSS) report. More than 100 rules are mapped to the PCI compliance standard.<\/p>\n<p>The screenshots below provide examples of PCI DSS report results.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"js-loaded size-full wp-image-23745 wp-image-276775 has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-4.png?w=640&#038;ssl=1\" alt=\"Screenshot of Infrastructure Assurance displaying PCI DSS report results\"   align=\"center\" data-image-id=\"276775\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-26.png 584w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-27.png 380w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-28.png 790w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-29.png 276w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-4.png 936w\" data-context=\"container\" sizes=\"auto, 100vw\" data-custom-sizes=\"1\" loading=\"lazy\"><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"js-loaded size-full wp-image-23745 wp-image-276774 has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-5.png?w=640&#038;ssl=1\" alt=\"Screenshot of Infrastructure Assurance displaying PCI DSS report results\"   align=\"center\" data-image-id=\"276774\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-30.png 584w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-31.png 380w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-32.png 790w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-33.png 276w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-5.png 936w\" data-context=\"container\" sizes=\"auto, 100vw\" data-custom-sizes=\"1\" loading=\"lazy\"><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"js-loaded size-full wp-image-23745 wp-image-276773 has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-6.png?w=640&#038;ssl=1\" alt=\"Screenshot of Infrastructure Assurance displaying PCI DSS report results\"   align=\"center\" data-image-id=\"276773\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-34.png 584w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-35.png 1200w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-36.png 380w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-37.png 790w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-38.png 276w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-6.png 1430w\" data-context=\"container\" sizes=\"auto, 100vw\" data-custom-sizes=\"1\" loading=\"lazy\"><\/p>\n<h3>Legend improvements for reports<\/h3>\n<p>With Infrastructure Assurance 8.4, you can now change the legend and save it in your report. The new Hide All option in the legend makes it easy for you to hide some of the attributes in your graph.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"js-loaded size-full wp-image-23745 wp-image-276772 has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-7.png?w=640&#038;ssl=1\" alt=\"Screenshot of Infrastructure Assurance\" s hide all option legend for reports   align=\"center\" data-image-id=\"276772\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-39.png 584w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-40.png 1200w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-41.png 380w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-42.png 790w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-43.png 276w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-7.png 1430w\" data-context=\"container\" sizes=\"auto, 100vw\" data-custom-sizes=\"1\" loading=\"lazy\"><\/p>\n<p>You can now change the legend and save it in your report.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"js-loaded size-full wp-image-23745 wp-image-276771 has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed has-media-category media-cat-blog-pics-and-headers img-fluid format-png v-media-processed\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-8.png?w=640&#038;ssl=1\" alt=\"Screenshot of Infrastructure Assurance\" s legend changes for reports   align=\"center\" data-image-id=\"276771\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-44.png 584w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-45.png 380w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-46.png 790w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-47.png 276w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4-8.png 936w\" data-context=\"container\" sizes=\"auto, 100vw\" data-custom-sizes=\"1\" loading=\"lazy\"><\/p>\n<h3>Alerts for every issue item<\/h3>\n<p>Alert fatigue is real. Infrastructure Assurance keeps noise levels down without letting problems escape you. The issue item feature is one technique to reduce noise.<\/p>\n<p>A great example is VPN tunnels. A firewall typically has many VPN tunnels connecting remote sites and users. Instead of alerting you to every event in which a VPN tunnel is down, Infrastructure Assurance associates a tunnel as an issue item. When the first VPN tunnel goes down, it creates a new alert. When the second VPN tunnel goes down, it adds the second VPN tunnel down event as an issue item to the existing alert.<\/p>\n<p>With Infrastructure Assurance 8.4, you can disable issue item collection by changing the configuration file. Instead of concatenating issue items to an existing alert, the system generates a new alert for every issue item. But enabling this feature can greatly increase the number of alerts in your environment.<\/p>\n<h3>Knowledge enhancements<\/h3>\n<p>The Infrastructure Assurance 8.4 release includes more than 200 auto-detection knowledge elements and enhancements. Devices supported by these enhancements include BlueCat Integrity, Broadcom Symantec (formerly Blue Coat) Content Analysis series, Check Point Maestro, and Palo Alto Networks Next-Generation Firewalls. For a complete list of enhancements, see details in the <a href=\"https:\/\/indeni.com\/docs\/release-notes\/release-notes-8-x-x-versions\/release-notes-8-4-0\/\">release notes<\/a>.<\/p>\n<p>Ready to see the anomaly detection engine and CVE analysis engine in Infrastructure Assurance 8.4 for yourself?&nbsp;<a href=\"https:\/\/bluecatnetworks.com\/adaptive-dns\/bluecat-infrastructure-assurance\/#form-bciademo\">Request a live demo<\/a>&nbsp;today.<\/p>\n<p><a href=\"https:\/\/bluecatnetworks.com\/blog\/detect-anomalies-and-cve-risks-with-infrastructure-assurance-8-4\/\">BlueCat Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>For IT operations teams needing deeper and more automated insight<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[94],"tags":[95],"class_list":["post-3588","post","type-post","status-publish","format-standard","hentry","category-blog","tag-blog"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Blue Cat","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/bluecat\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/blog\/\" rel=\"category tag\">Blog<\/a>","tag_info":"Blog","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3588","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3588"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3588\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3588"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3588"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3588"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}