Network Security - CSA

Cisco Security Agent

The Cisco Security Agent is a product that focuses on Zero day virus/spyware/malware protection. The agent learns what is allowed and what is not allowed. The product is similar to a firewall by preventing anything from happening on the system unless a specific allow rule has been created. The difference is that the agent independently protects different sectors of the system, basically hundreds of firewalls. The agent and the rules are managed by a central CSA server at DSTC and events are monitored by NHC-ITS.

The Cisco Security Agent project is a district-wide initiative to improve network security and reliability. This product provides an additional security level in front of our anti-virus and anti-spyware protection. NHC will be 100% protected starting in January of 2007.


Agent Modes
The agent has multiple operational modes to provide protection. These agent modes were developed to provide the maximum protection possible while not inhibiting the instructional needs of the college. The following outlines the modes being used at NHC.

NHC-BASE

This is the default group for the agent when in test mode – the agent monitors and reports but does not block any actions – used to learn how applications behave no user interface just log files.

Protecting mode

This is the normal operational mode of the agent. The agent monitors and blocks actions that are not allowed. Rules are written for the system to allow for normal operations.
We have four different installations of this package
  • Labs agent – lab level permissions - blocks applications that don’t have an allow rule and does not allow user interaction.
  • Employee – employee level permissions - blocks applications that don’t have an allow rule and does not allow user interaction
  • Mobile – blocks applications that don’t have an allow rule and does not allow user interaction, but allows user interaction when not connected to the network
  • IT agent – blocks applications that don’t have an allow rule but allows user interaction – The user can allow actions after reviewing the action. Used for testing software.
  • NHC Special Agent – The same as the IT agent but cannot be uninstalled and can revert back to the original configuration.

Lock Down mode

This mode is for when an actual virus is traveling the network. The PC will still operate but all user interaction is turned off. This mode is only used when an attack is underway.

Our network is critical to instruction and a major network failure will stop instruction. With this product deployed correctly we will both protect our network resources and not put undue restrictions on instruction.
Need Help with CSA?
If at anytime you are not sure what to do or are having problems be sure to contact the NHC - Helpdesk at 5486. We will be glad to help you.
North Harris College - A North Harris Montgomery Community College
2700 W.W. Thorne Drive
Houston TX 77073-3499
Phone 281.618.5400