SOC within the Network Operations Center

0
133
SOC within the Network Operations Center


Mobile World Congress 2025 in Barcelona delivered on each promise – a record-breaking occasion with 109,000 attendees from 205 international locations, with over 2,900 exhibitors, sponsors, and companions showcasing a formidable array of chopping‐edge matters, from 5G and IoT to Unified Security for the AI-driven Future.

As all the time, Cisco’s presence showcased a set of improvements, resembling the newest safe connectivity options, demonstrated subsequent‐gen wi-fi improvements, and made a number of high-profile media bulletins that underscored our dedication to shaping the way forward for digital communications.

Cisco’s One Cisco technique was on full show, integrating networking, safety, observability, and Splunk options to ship unparalleled outcomes. This holistic strategy showcases how our clients can obtain AI-ready information facilities, future-proofed workplaces, and digital resilience.

Cisco at MWC 2025: A Powerhouse of Innovation

In true Cisco style, our sales space wasn’t only a house however reasonably a hub of innovation and collaboration. Live Demo Highlights included:

Alberto Torralba, Cisco, Presenting to Alberto Núñez Feijóo, Member of the Congress of Deputies of Spain
Fig. 1: Alberto Torralba, Cisco, Presenting to Alberto Núñez Feijóo, Member of the Congress of Deputies of Spain

Lessons From Previous Events

Building on our experiences at Black Hat, NFL Super Bowl, RSA Conference and others the Team introduced the identical power and technical rigor to MWC 2025. Our SNOC staff leveraged the operational excellence honed at these occasions, mixing state-of-the-art safety instruments with real-time community monitoring to make sure seamless occasion operations.

The Splunk Cloud was used as the info platform, including Apps for information ingestion:

With these integrations, our SOC staff was in a position to construct a CISO degree SNOC dashboard for essential telemetry from all community and safety sources.

CISO-level SNOC dashboard
Fig. 2: CISO-level SNOC dashboard

We additionally had SOC Manager degree dashboards for XDR Incidents, Firewall Events and DNS Security.

SOC manager-level dashboard
Fig. 3: SOC manager-level dashboard

We additionally related the integrations with Cisco XDR, for Dashboard visibility and Incident investigation.

Dashboard view of integrations connected to Cisco XDR
Fig. 4: Dashboard view of integrations related to Cisco XDR

We had XDR Automate workflows to advertise menace detections in Splunk to XDR Incidents, and the XDR integration again into Splunk.

Automated XDR workflows
Fig. 5: Automated XDR workflows

The Incidents empowered the SNOC staff to prioritize investigations.

Cisco XDR incident list
Fig. 6: Cisco XDR incident checklist

Additionally, at this yr’s Mobile World Congress in Barcelona, Cisco’s ThousandEyes dashboard was instrumental in offering sturdy community assurance. Attendees benefited from real-time monitoring and insights into community efficiency, making certain a seamless expertise from begin to end. With the potential to trace essential parts just like the occasion homepage and login processes, ThousandEyes ensured that members might entry important sources swiftly and with out interruption. This degree of detailed visibility and management helped keep the integrity and reliability of the community all through the occasion.

Cisco ThousandEyes dashboard
Fig. 7: Cisco ThousandEyes dashboard

Day 1: A Test of Scale

Day 1 was all about dealing with huge community exercise seamlessly. From just a few workers units to 1000’s of units connecting concurrently, our firewall and community monitoring techniques carried out flawlessly, processing a excessive quantity of visitors whereas sustaining pinpoint visibility. The sturdy efficiency of our Cisco safety options reaffirmed that, whether or not in a managed lab surroundings or amidst a vibrant convention, community resilience is just not negotiable.

Fira Network Security architecture
Fig. 8: Fira Network Security structure

Day 2: When a Russian Threat Tried to Crash the Party

Just as you assume the one surprises at MWC 2025 are the revolutionary tech and spontaneous demos, our firewall logs gave us an sudden twist. On Day 2, our vigilant monitoring detected an anomalous occasion: a privilege escalation occasion coming from a Russian supply.

Firewall Management Center (FMC) Intrusion Events
Fig. 9: Firewall Management Center (FMC) Intrusion Events

 

Firewall Management Center (FMC) Intrusion Events, detailed view
Fig. 10: Firewall Management Center (FMC) Intrusion Events, detailed view

Our technical maestro, Jorge Quintero, instantly flagged this as a possible high-risk occasion – a state of affairs the place an endpoint may be compromised. The logs confirmed a sample in step with C2 communications, prompting a speedy investigation and swift remediation measures. In true SNOC type, we ensured that any unwelcome visitor was proven the door earlier than it might wreak havoc. (It appears even at MWC, cyber adversaries can’t resist the attract of the celebration!)

Firewall Management Center (FMC) Intrusion Event, event packet capture
Fig. 11: Firewall Management Center (FMC) Intrusion Event, occasion packet seize

What actually stood out on this IDS occasion was a crafted plain-text script operating on port 80 with Internet Explorer (sure – nonetheless in use).

Intrusion Event Packet Capture, details
Fig. 12: Intrusion Event Packet Capture, particulars

The Snort signature that was triggered additionally highlighted two most important strategies getting used:

Firewall Management Center (FMC) Intrusion Event, MITRE ATT&CK mappings
Fig. 13: Firewall Management Center (FMC) Intrusion Event, MITRE ATT&CK mappings

Using public generative AI instruments, the evaluation of the payload yielded the next outcomes, revealing constant patterns of malicious exercise — together with makes an attempt to establish anti-malware instruments (possible for elimination to keep up persistence) and probably escalate privileges additional.

Example from Public Generative AI Application Prompt Response
Fig. 14: Example from Public Generative AI Application Prompt Response

Finally, what confirmed our suspicions (in the event that they weren’t already) got here from Talos and AlienVault menace intelligence. This IP deal with (belonging to the Russian Federation) had already been flagged for malicious exercise.

Threat Intelligence Information
Fig. 15: Threat Intelligence Information

Day 3: Cryptomining — The Tale of the Good and the Evil

Day 3 introduced an attention-grabbing subject to our consideration — cryptomining. From its humble beginnings to the multi-billion-dollar business, it’s as we speak, we now have witnessed the rise of crypto — now extending past simply cryptocurrency to revolutionary makes use of within the fintech house, together with NFTs and extra.

However, we now have additionally seen how this know-how has been leveraged by malicious actors, particularly to compromise endpoints and hijack computing sources for cryptomining.

Firewall Management Center (FMC), intrusion event details
Fig. 16: Firewall Management Center (FMC), intrusion occasion particulars

 

Intrusion event packet capture details
Fig. 17: Intrusion occasion packet seize particulars

Using public generative AI instruments to decode plain textual content, we recognized mining software program (XMRig) making RPC calls to the Monero cryptocurrency community. Now, it’s price highlighting that, though suspicious, this might nonetheless be a professional case of an endpoint operating mining software program.

Example from Public Generative AI Application Prompt Response
Fig. 18: Example from Public Generative AI Application Prompt Response

However, the illegitimate nature of this exercise was confirmed once more by means of Talos and AlienVault intelligence. The public IP deal with in use had already been flagged for involvement in malicious cryptomining operations.

Threat intelligence information
Fig. 19: Threat intelligence info

Day 4: Slowdown and Event Wrap-Up!

Day 4 confirmed a slowdown in exercise, making it a threat-free day and giving us time to research and combination the complete dataset from the occasion. Here are a few key takeaways from the firewall evaluation:

1. EVE (Encrypted Visibility Engine): Paving the best way for encrypted visitors evaluation.

Cisco’s Encrypted Visibility Engine (EVE) has confirmed that the innovation of latest years is important. Monitoring at Fira was carried out totally utilizing IDS (Intrusion Detection System) with passive evaluation. Even with out decryption capabilities, we had been in a position to establish threats inside encrypted visitors, in addition to the processes producing these visitors move.

Firewall Management Center (FMC) dashboard, Encrypted Visibility Engine statistics
Fig. 20: Firewall Management Center (FMC) dashboard, Encrypted Visibility Engine statistics

2. Event-driven analytics, powered by Splunk

The Cisco + Splunk story is a match made in heaven. With Cisco’s depth and breadth in safety and a robust portfolio, mixed with Splunk’s world-class observability and suppleness, we had been in a position to construct highly effective, actionable dashboards for simple consumption by the SNOC staff.

Below is the aggregated information for the complete occasion — protecting every part from connection occasions, file occasions, and intrusion occasions to a prioritized set of incidents recognized all through the conference.

Secure Firewall Splunk app in Splunk
Fig. 20: Secure Firewall Splunk app in Splunk

This included DNS safety blocks, defending Fira’s Network attendees at MWC, from malicious web sites. Over 14,400 apps had been seen on the MWC community.

Umbrella DNS in Splunk dashboard
Fig. 22: Umbrella DNS in Splunk dashboard

Looking Ahead

The sudden incident on Day 2 solely bolstered one important lesson: in as we speak’s hyper-connected world, innovation should all the time be matched with rigorous safety. As we replicate on the successes of MWC 2025, we’re already planning enhancements to our menace detection and incident response capabilities, drawing on each our MWC, Black Hat, and NFL experiences.

Cisco’s SNOC Team stays dedicated to staying one step forward, turning each problem into a possibility to innovate and shield. Whether it’s managing tens of 1000’s of connections or intercepting a rogue C2 sign, we’re prepared to make sure that the digital future is as safe as it’s sensible.

While know-how was on full show, the true stars of the Security Booth had been the devoted people who introduced these demos and operations to life. A heartfelt thanks to: Alberto Torralba, Filipe Lopes, Jorge Quintero, Jervis Hui, Nirav Shah, John Cardani-Trollinger, and Emile Antone. Their experience and dedication ensured that each demo ran flawlessly and captured the eye of each attendee. Special appreciation to Ivan Padilla Ojeda, who was our liaison with the community staff to attach every part within the SNOC.

Also, thanks to those that helped us put together for the SNOC: Ivan Berlinson, Ryan Maclennan, Aditya Sankar, Seyed Khadem, Tony Iacobelli, Dallas Williams, Nicholas Carrieri and Jessica Oppenheimer.

Wrapping Up

Mobile World Congress 2025 was not nearly showcasing the following wave of technological innovation; it was additionally a robust demonstration of how built-in, resilient safety measures can safeguard even essentially the most bustling, high-stakes environments. The comparative insights from Day 1 and Day 2 underscore the significance of staying one step forward, continually adapting, and repeatedly bettering our protection methods.

Mobile World Congress 2025 team photo

Thank you for becoming a member of us on this journey by means of MWC 2025 and keep tuned for extra insights and behind-the-scenes tales from MWC 2025. After all, on the planet of tech, it’s by no means simply one other day on the workplace!  


 

We’d love to listen to what you assume. Ask a Question, Comment Below, and Stay Connected with Cisco Secure on social!

Cisco Security Social Channels

Instagram 

Facebook 

Twitter 

LinkedIn

Share:

LEAVE A REPLY

Please enter your comment!
Please enter your name here