Systems and methods for deploying agentless countermeasures in a network environment
Various approaches for providing network maintenance and health monitoring are discussed. In some cases, some approaches include systems, methods, and/or devices that provide for detecting problematic network behavior and deploying countermeasures in relation to the detected behavior without an agent operating on the device where the countermeasures are implemented.
1 . A method for remedying network incidents, the method comprising:
providing, by a processor, telemetry from a plurality of network elements to an incident solution processing service, wherein the processor is deployed in a secure network with at least one of the plurality of network elements;
receiving, by the processor, a remediation command from the incident solution processing service, wherein the remediation command includes:
an indication of at least one remediation maintained in a local remediation database communicably coupled to the processor; and
identification information capable of identifying at least one of the plurality of network elements to which the remediation is to be applied;
determining, by the processor, the at least one of the plurality of network elements to which the remediation is to be applied;
accessing, by the processor, the at least one remediation from the local remediation database; and
causing, by the processor, the at least one remediation to be executed by the at least one of the plurality of network elements to which the remediation is to be applied, including: authenticating, by the processor, to the at least one of the plurality of network elements; and issuing, by the processor, a command line command to execute the remediation on the at least one of the plurality of network elements.
2 . The method of claim 1 , wherein the at least one of the plurality of network elements is selected from a group consisting of: a network security appliance, a network switch, a network access point, a network database server, and a mobile device.
3 . The method of claim 1 , wherein the processor is separate from a network security appliance governing access to the secure network, and wherein causing the at least one remediation to be executed by the at least one of the plurality of network elements to which the remediation is to be applied includes causing the network security appliance to execute the at least one remediation.
4 . The method of claim 3 , wherein executing the at least one remediation by the network security appliance causes the network security appliance to make a modification to an operation of another of the plurality of network elements.
5 . The method of claim 1 , wherein causing the at least one remediation to be executed by the at least one of the plurality of network elements to which the remediation is to be applied includes causing a network security appliance to execute the at least one remediation.
6 . The method of claim 1 , the method further comprising:
accessing, by the processor, the remediation from the local remediation database.
7 . The method of claim 6 , wherein the remediation is a local remediation, and wherein the method further comprises:
receiving, by the processor, the local remediation and at least one rule governing application of the local remediation;
storing, by the processor, the local remediation to the local remediation database; and
communicating, by the processor, an identification of the local remediation and the at least one rule governing application of the local remediation to the incident solution processing service.
8 . The method of claim 1 , wherein the incident solution processing service is operated on a server outside of the secure network.
9 . The method of claim 1 , wherein the telemetry from the plurality of network elements includes telemetry from at least one network service outside of the secure network and one network device within the secure network.
10 . A network incident system, the network incident system comprising:
a processing resource;
a local remediation database, wherein the local remediation database includes at least one remediation;
a non-transitory computer readable medium, wherein all of the processing resource, the local remediation database, and the non-transitory computer readable medium are deployed in a secure network, and wherein the non-transitory computer readable medium includes instructions executable by the processing resource to:
provide telemetry from a plurality of network elements to an incident solution processing service, wherein at least one of the plurality of network elements is deployed in the secure network, and wherein the incident solution processing service is outside of the secure network;
receive a remediation command from the incident solution processing service, wherein the remediation command includes:
an indication of at least one remediation maintained in a local remediation database communicably coupled to the processor; and
identification information capable of identifying at least one of the plurality of network elements to which the remediation is to be applied;
determine the at least one of the plurality of network elements to which the remediation is to be applied;
accessing, by the processor, the at least one remediation from the local remediation database; and
cause the at least one remediation to be executed by the at least one of the plurality of network elements to which the remediation is to be applied, including: authenticating, by the processor, to the at least one of the plurality of network elements; and issuing, by the processor, a command line command to execute the remediation on the at least one of the plurality of network elements.
11 . The system of claim 10 , wherein the at least one of the plurality of network elements is selected from a group consisting of: a network security appliance, a network switch, a network access point, a network database server, and a mobile device.
12 . The system of claim 10 , wherein the processing resource is separate from a network security appliance governing access to the secure network, and wherein causing the at least one remediation to be executed by the at least one of the plurality of network elements to which the remediation is to be applied includes causing the network security appliance to execute the at least one remediation.
13 . The system of claim 12 , wherein executing the at least one remediation by the network security appliance causes the network security appliance to make a modification to an operation of another of the plurality of network elements.
14 . The system of claim 10 , wherein causing the at least one remediation to be executed by the at least one of the plurality of network elements to which the remediation is to be applied includes causing a network security appliance to execute the at least one remediation.
15 . The system of claim 10 , wherein the non-transitory computer readable medium further includes instructions executable by the processing resource to:
access the remediation from the local remediation database.
16 . The system of claim 15 , wherein the remediation is a local remediation, and wherein the non-transitory computer readable medium further includes instructions executable by the processing resource to:
receive the local remediation and at least one rule governing application of the local remediation;
store the local remediation to the local remediation database; and
communicate an identification of the local remediation and the at least one rule governing application of the local remediation to the incident solution processing service.
17 . The system of claim 10 , wherein the telemetry from the plurality of network elements includes telemetry from at least one network service outside of the secure network and one network device within the secure network.
18 . A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by a processing resource deployed within a secure network, cause the processing resource to perform a method comprising:
providing telemetry from a plurality of network elements to an incident solution processing service, wherein at least one of the plurality of network elements is deployed separate from the processing resource in the secure network, and wherein the incident solution processing service is outside of the secure network;
receiving a remediation command from the incident solution processing service, wherein the remediation command includes:
an indication of at least one remediation maintained in a local remediation database communicably coupled to the processor;
access the at least one remediation from the local remediation database; and
identification information capable of identifying at least one of the plurality of network elements to which the remediation is to be applied;
determining the at least one of the plurality of network elements to which the remediation is to be applied; and
causing the at least one remediation to be executed by the at least one of the plurality of network elements to which the remediation is to be applied, including: authenticating, by the processor, to the at least one of the plurality of network elements; and issuing, by the processor, a command line command to execute the remediation on the at least one of the plurality of network elements.