eyeSight-eyeInspect Integration Components

 

The eyeSight-eyeInspect integration comprises the following components:

 
Component Description

(eyeInspect) Passive (Monitoring) Sensor and (eyeSight) Passive Sensor Plugin

Each Passive Sensor is connected to the ICS/SCADA (Industrial Control Systems/Supervisory Control and Data Acquisition) network via one or more SPAN/mirroring ports to passively audit the network traffic and detect malicious activities. The detection methods used by Passive Sensors are packaged in modules that can be selectively enabled. A dedicated monitoring interface sends events and logs from the Passive Sensor to the Command Center.

(eyeInspect) Command Center

Each Command Center collects and processes data reported by one or more Sensors, and supports a web interface for endpoint event management.

(eyeSight) Operation Technology Plugin

The Operational Technology Plugin connects to Command Center instances to integrate events and information collected from monitored endpoints. This information is made available for use in Forescout policies and by endpoint management tools.

Content Modules provide regularly updated information to enhance detection and handling of Operational Technology endpoints:

The Operational Technology Vulnerability Database provides periodic updates of the vulnerabilities that Command Center can detect on endpoints, based on published CVEs and advisories.

The Traffic Inspection Library adds protocol parsing capabilities to the Forescout platform. The library provides scripts that enhance traffic inspection by the Operational Technology module and associated eyeInspect components. The library is updated periodically to improve the breadth and precision of inspection.

Representations of basic eyeSight-eyeInspect architecture (single eyeInspect Control Center), and multi Control Center architecture, are shown below.