Cisco Secure Application is available for the SaaS environment only.
AppDynamics with Cisco Secure Application reduces the risk of security exposure without compromising the delivery speed for an APM-managed application. Normally, the traditional vulnerability scanning occurs before the application is launched to production, and then continues on a monthly, or quarterly cadence. As soon as the app is deployed to production, new security gaps, and zero-day exploits make the application vulnerable despite pre-production testing. Cisco Secure Application enables continuous vulnerability assessment and protection by scanning code execution to prevent possible exploits.
Cisco Secure Application enables:
- The IT Operations team responsible for performance monitoring to gain real-time access to all security events.
- Application security (AppSec) developers and application developers to gain insights into violations of best practices and to collaborate on a solution without friction.
- AppSec and DevOps to add security into the existing automation, which benefits the DevSecOps environment.
- Businesses to operate at a faster pace with a lower risk profile due to constant run-time protection, real-time remediation, and security automation.
The Cisco Secure Application features are built into AppDynamics Java Agent. To monitor the application security, you must enable the security for the application using the Cisco Secure Application dashboard. Use the Security Events widget on the AppDynamics Application dashboard to navigate to the Cisco Secure Application dashboard. To view the Security Events widget within AppDynamics Performance Monitoring (APM), enable your SaaS account with the subscription license for Secure Application. See License Entitlements and Restrictions.
Cisco Secure Application Components
Cisco Secure Application uses the combination of the APM Agent, Controller, and Cisco Secure Application dashboard to monitor the security of the applications.
- Java APM Agent: Cisco Secure Application library is bundled with the Java Agent. The agent communicates with the Cisco Secure Application service within the Controller, which is maintained in the cloud.
- AppDynamics Controller: The Cisco Secure Application service is maintained in the cloud by AppDynamics.
The APM Agent sends data to the service within the Controller. The service analyzes the data to protect against different types of attacks and vulnerabilities and then the service provides the analysis to the dashboard. For information about the attacks and vulnerabilities that Cisco Secure Application detects, see Cisco Secure Application Policies.
It uses external feeds along with internal data to analyze the behavior of the application. It analyzes the CVEs (Common Vulnerabilities and Exposures) against a curated vulnerability feed.
The service can detect:
- An attack when it is enabled in the policy and abnormal behavior is detected.
- A vulnerability when it is enabled in the policy and when the associated behavior and the library used are considered vulnerable.
- Cisco Secure Application Dashboard: A graphical representation of all the analyzed data. You can view this dashboard based on the role defined in the AppDynamics Controller. The data is updated on the dashboard when the service within the Controller sends the analyzed data to the dashboard.
Cisco Secure Application Architecture
This is a high-level architecture of Cisco Secure Application.
The APM Agent (Java Agent) communicates to the Cisco Secure Application service through the AppDynamics Controller.
- You install the APM Agent and then add the Cisco Secure Application license.
- The APM-managed application runs and the Java Agent retrieves the data to send to the Controller.
- The Cisco Secure Application service retrieves the application, tiers, and nodes data from the Controller.
- The APM Agent communicates with the Cisco Secure Application service to check if the security is enabled for the application.
- If the security is enabled, then the agent downloads the configuration along with the policies from the Cisco Secure Application service.
- Based on the configured policies, the agent sends the security events to the Cisco Secure Application service.
- The service collects all the data, analyzes the application behavior, and then provides the analyzed data to the Cisco Secure Application dashboard.