Cisco Umbrella - access to personal network detected
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect allowed access to personal network through proxy.
Strategy
This rule monitors Cisco Umbrella proxy logs to determine when a host accesses content related to personal VPNs or dynamic and residential IPs, possibly indicating that a user has accessed their personal network.
Triage and response
- Assess whether the site identified in the logs is allowed according to the organization’s acceptable use policy.
- Contact the user associated with the device to determine if they actively browsed to the sites identified in the log.
- If users should not be accessing the site, block the URL via Cisco Umbrella.
- If required, begin your organization’s incident response process and investigate.