Cisco Cyber Vision
Visualize your Cisco Cyber Vision OT environment in JupiterOne — the Cyber Vision Center, the industrial assets it discovers (PLCs, controllers, switches, and other devices, with their IP and MAC addresses, VLANs, and networks), and the CVE-backed vulnerabilities detected on them with their CVSS and Cisco Security Risk Scores — map each device to the vulnerabilities that affect it, and monitor OT exposure through queries and alerts.
- Installation
- Authorization
- Data Model
- Types
Installation
This integration connects to your on-premises Cisco Cyber Vision Center using the Cisco Cyber Vision New UI API (https://<center>/cvapi/v1/, Cyber Vision 5.4 and later) and ingests OT assets and the vulnerabilities detected on them. The Center is usually on your own network, so the integration normally runs on a JupiterOne Collector that can reach the Center over HTTPS (port 443 unless you include a different port in the hostname).
Configuration in Cisco Cyber Vision
Before you configure the integration in JupiterOne, prepare the following in your Cisco Cyber Vision Center:
-
The hostname or IP address of the Center, for example
192.168.1.100. The JupiterOne Collector must be able to reach it over HTTPS. -
An API token. In the Center, go to Admin > API > Token, click New Token (or Create your first token), enter a name such as
JupiterOne, leave the Status toggle enabled, optionally set an expiration date, and save. Click Show to see and copy the token. Cisco recommends one token per application so you can expire or remove access separately. The menu location can differ between Center releases; see Cisco's authentication guide.The integration only sends
GETrequests to two endpoints,/cvapi/v1/assetsand/cvapi/v1/assets/vulnerabilities, and never modifies data on the Center. -
If the Center presents a self-signed or internal-CA TLS certificate, get the CA certificate in PEM format so the collector can verify the connection.
Once you have obtained the information above, proceed to JupiterOne to finalize the integration.
Configuration in JupiterOne
To install the Cisco Cyber Vision integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select Cisco Cyber Vision. Click New Instance to begin configuring your integration.
Creating an instance requires the following:
-
The Account Name used to identify the Cisco Cyber Vision account in JupiterOne. Ingested entities will have this value stored in
tag.AccountNamewhen theAccountNametoggle is enabled. -
Description to assist in identifying the integration instance, if desired.
-
Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as
DISABLEDand manually execute the integration. -
The Center Hostname or IP of your Cyber Vision Center, for example
192.168.1.100. You can also enterhost:portor a fullhttps://URL; the integration builds thehttps://<host>/cvapi/v1/base URL from it. -
The API Token created above. It is sent in the
x-token-idrequest header. -
Optionally, a CA Certificate to trust a self-signed or internal-CA certificate, or enable Disable TLS Verification to skip certificate validation (not recommended).
-
Optionally, set Minimum CVSS Score to limit the vulnerabilities that are ingested. Options: All vulnerabilities (default, no filter), 4.0 (medium and above), 7.0 (high and above), 9.0 (critical only). The value is sent to the Center as the
cvssfilter on/assets/vulnerabilities. -
Optionally, set Minimum Cisco Security Risk Score to limit the vulnerabilities that are ingested. Options: All vulnerabilities (default, no filter), 25 and above, 50 and above, 75 and above. The value is sent to the Center as the
csrsfilter on/assets/vulnerabilities. -
Optionally, set Last Active Within to ingest only assets that were last active within the selected window. Options: All assets (default, no filter), 7 days, 30 days, 90 days, 180 days, 365 days.
Raising either score threshold or narrowing Last Active Within removes the vulnerabilities or devices that fall outside the new filter from JupiterOne on the next run.
Data Sources
Each data source can be enabled or disabled on its own. All data sources are disabled by default, so enable the ones you want to ingest. The Center account (cisco_cyber_vision_account) and the Cyber Vision service (cisco_cyber_vision_service) entities are always created.
| Data Source | Description | Entities Created |
|---|---|---|
| Devices | OT assets (PLCs, controllers, switches, etc.) discovered by Cisco Cyber Vision, with asset type, vendor, IP and MAC addresses, VLANs, network names, vulnerability and active alert counts, and first and last active times | cisco_cyber_vision_device |
| Vulnerabilities | CVE-backed vulnerabilities detected on Cisco Cyber Vision OT assets, with title, CVSS score, and Cisco Security Risk Score | cisco_cyber_vision_vulnerability |
One vulnerability entity is created per CVE and shared by every device it affects. Its severity is derived from the CVSS score.
The relationships are built as follows:
- Account to device (
HAS) requires Devices. - Service to vulnerability (
IDENTIFIED) requires Vulnerabilities. - Device to vulnerability (
HAS) requires both Devices and Vulnerabilities.
The integration collects only assets and their vulnerabilities. Other Cyber Vision data, such as activities, flows, events, components, and baselines, is not retrieved.
Click Create once all values are provided to finalize the integration.
Next steps
Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.
Additional resources
Endpoints
API endpoints that the integration makes requests to.
Show Endpoints (2)
/cvapi/v1/assets/cvapi/v1/assets/vulnerabilities
Documentation Links
Links to provider documentation relevant to setup and configuration.
Entities
The following entities are created:
| Resources | Entity _type | Entity _class |
|---|---|---|
| Asset | cisco_cyber_vision_device | Device |
| Center | cisco_cyber_vision_account | Account |
| Service | cisco_cyber_vision_service | Service |
| Vulnerability | cisco_cyber_vision_vulnerability | Finding, Vulnerability |
Relationships
The following relationships are created:
Source Entity _type | Relationship _class | Target Entity _type |
|---|---|---|
cisco_cyber_vision_account | PROVIDES | cisco_cyber_vision_service |
cisco_cyber_vision_account | HAS | cisco_cyber_vision_device |
cisco_cyber_vision_device | HAS | cisco_cyber_vision_vulnerability |
cisco_cyber_vision_service | IDENTIFIED | cisco_cyber_vision_vulnerability |
Cisco Cyber Vision Account
cisco_cyber_vision_account inherits from Account
| Property | Type | Description | Specifications |
|---|---|---|---|
centerHost * | string | The configured hostname or IP of the Cyber Vision Center | |
centerId * | string | null | The Center identifier reported by the Cyber Vision New UI API |
Cisco Cyber Vision Device
cisco_cyber_vision_device inherits from Device
| Property | Type | Description | Specifications |
|---|---|---|---|
activeAlertCount * | number | null | Count of active alerts currently raised on the asset (rolling count, informational) | |
assetType * | string | null | The Cyber Vision OT asset type verbatim (e.g. PLC, Controller, Switch) | |
firstActiveOn * | number | null | Epoch milliseconds when the asset was first seen active | |
networkNames * | array | null | Network names observed across the asset network interfaces | |
vlans * | array | null | VLAN identifiers observed across the asset network interfaces | |
vulnerabilityCount * | number | null | Count of vulnerabilities currently detected on the asset (rolling count, informational) |
Cisco Cyber Vision Service
cisco_cyber_vision_service inherits from Service
Cisco Cyber Vision Vulnerability
cisco_cyber_vision_vulnerability inherits from Finding, Vulnerability
| Property | Type | Description | Specifications |
|---|---|---|---|
ciscoSecurityRiskScore * | number | null | The Cisco Security Risk Score (CSRS) for the CVE (0 - 100) | |
cvssScore * | number | null | The CVSS score assigned to the CVE (0.0 - 10.0) | |
title * | string | null | The human-readable vulnerability title |