© 2006, Cisco Systems, Inc. All rights reserved.Presentation_ID.scr3
© 2008 Cisco Systems, Inc. All rights reserved. Cisco Public
5
BRKSEC-200617796_04_2008_c1
TelePresence Monitoring Architecture
Cisco IDS, NetFlow, and CS-MARS
CCM424CCM424
Cisco IDSData Center
CSIRT monitoringCS-MARS
NetFlow
anomaly detection
IDS events
signature detection
© 2008 Cisco Systems, Inc. All rights reserved. Cisco Public
6
BRKSEC-200617796_04_2008_c1
False Positive Traffic Example:
SSH Sync Between CM’s
False Positive:normal sync trafficbetween callmanagers