About the Forescout eyeSegment Module
The de-centralized Forescout eyeSegment Module aggregates traffic from various sources so that you can simplify segmentation planning and automate ACL/VLAN assignment to reduce your attack surface.
eyeSegment allows you to analyze your physical network traffic from a dynamic zone perspective. This helps you decouple the static constraints of a physical network from the dynamic business logic that modern segmentation policies require.
The eyeSegment product provides:
- Segmentation intelligence driven by the fusion of dynamic zone context, and dynamic flow context
- A network traffic baseline using traffic data accumulated over time
- A consolidated visibility pane for mapping and analyzing traffic to and from various sources in and out of the network, and for identifying simulated traffic rule violations and conflicts
- A policy management pane for creating an eyeSegment policy using rules that simulate allowing or denying specific traffic
Use the eyeSegment product to:
- Monitor traffic to understand device dependencies, then map, plan, and deploy network segments.
- Assess devices on the fly to automate segmentation assignment.
- Monitor the network for anomalous communication.
- Focus on a matrix row, column, or cell to view a matrix of all the sub-zones of the selected Source or Destination parent zone. This 'focus' feature allows you to see multiple types and levels of information for hierarchical structures.
- Use dynamic Source and Destination zones to easily create and visualize an eyeSegment policy that simulates denying traffic for a specific segment and filter, and enable notification or other actions when a simulated traffic violation is detected. You can define and manage a single matrix that shows traffic for the eyeSegment zones you select
- Identify simulated traffic violations to improve your enforcement and eyeSegment policy rules.
- Visualize the policy rules as a layer in the matrix, and ensure that devices are not managed by conflicting rules.
- Export details about selected traffic for further study.
You can define and manage a single matrix that shows traffic for the eyeSegment zones you select
How the eyeSegment Module works
- The managing Appliances receive and analyze the mirrored traffic data captured by the traffic sensors configured in your environment.
- The Forescout Cloud Uploader plugin compresses the traffic data, and then uses encrypted protocol to send it to the cloud where the data is processed and analyzed.
- The communication patterns among Forescout policy groups and eyeSight segments are dynamically mapped in a web-based matrix of network traffic connectivity.
- Drill down into the matrix to learn:
- The ports used by the traffic.
- The traffic volume between any pair of zones.
- The IP addresses and other details of the devices that used each traffic pattern.
- Which traffic violated your eyeSegment policy rules.
- Use the displayed information to:
- Redefine your matrix to focus on traffic of interest.
- Plan your eyeSegment policy for controlling the traffic between specific zones.
- Refine your eyeSegment policy to ensure that it tags suspicious traffic.
- Visualize a dashboard for SOC monitoring.
- If a device sends or receives traffic that violates an eyeSegment policy
rule:
- A Forescout policy can send email and Syslog notifications. (Optional)
- You can apply a network or endpoint action, such as a Switch Block or Virtual Firewall action. (Optional)
eyeSegment Components
In this version, you can define a single matrix for all users that shows traffic for the eyeSegment zones you select. Each user can create and maintain their own Advanced Filter criteria for the shared matrix.
eyeSegment uses the following components:
- eyeSegment zones – Dynamically tagged devices based on detected
characteristics, such as function, user role and/or location. Zones are selected
from:
- Forescout eyeSight segments
- Standard Forescout policy groups that can be populated manually or via a
Forescout policy
Single IP addresses can be zones. Segments and groups can be arranged in hierarchical levels where each level of the nested structure below Level 0 is a sub-zone.
In addition to the user-selected zones, the eyeSegment Module automatically creates virtual default zones to include devices that are not in any of the eyeSight segments or Forescout policy groups selected as matrix zones. These default zone names include the symbol
.eyeSegment zones can include the following:
Each eyeSegment zone can be designated as a Source zone or a Destination zone, or both.
- Advanced Filter criteria (optional) – A combination of policy groups, Forescout eyeSight segments, IP addresses, services, inspected protocols, and time range. These criteria filter the displayed matrix traffic to specific conditions, such as London Office, High-Risk Assets, Remote Devices, and the past week, so that the matrix shows only traffic of interest. The Advanced Filter criteria can be used to create accurate, intersected eyeSegment policy rules, and for finding specific traffic. Each user can create and maintain their own Advanced Filter criteria for the shared matrix.
- Forescout properties - The following Forescout eyeSight device properties are
immediately updated the first time each Source and Destination device pair violates
an eyeSegment policy rule. For subsequent violations of the same
policy rule by the same device pair, the properties are updated every minute.
- Traffic Was Denied from This Client: Lists each eyeSegment policy rule that was violated by traffic sent from this device.
- Traffic Was Denied to This Server: Lists each eyeSegment policy rule that was violated by traffic sent to this device.
- Server Groups to Which Traffic Was Denied: Lists the lowest-level Forescout policy group or default zone (for devices that are not members of any of your Forescout policy groups) in each eyeSegment policy rule, including exceptions, that contains members to which this client sent traffic that violated the rule.
- Client Groups from Which Traffic Was Denied: Lists the
lowest-level Forescout policy group or default zone (for devices that are not
members of any of your Forescout policy groups) in each eyeSegment policy rule, including exceptions, that contains
members from which this server received traffic that violated the rule. The following zones are not written to the Server Groups to Which Traffic Was Denied or Client Groups from Which Traffic Was Denied properties:
Internal Network
-Any-
zones that are Forescout eyeSight segments
- eyeSegment Policy Compliance policy template – A template accessible from the Console for creating policies that send notifications when a device's client or server traffic violates an eyeSegment policy rule.
Requirements
Refer to the eyeSegment Release Notes for the list of requirements for eyeSegment.
minute read