Zins Assess Network Security

作者 zscaler809f68d6c921無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Assess network security posture using Zscaler Analytics (Z-Insights). Analyzes Zero Trust Firewall effectiveness by action distribution (allow/block ratios), location-based firewall activity, network service usage, and firewall rule hit counts. Use when a security team asks: 'How effective is our firewall?', 'What is being blocked?', 'Show firewall activity by location', 'Which network services are in use?', or 'Generate a firewall report.'

僅含說明Security
AI 產生的概覽

依據 Zscaler Z-Insights 防火牆資料評估網路安全態勢,並產出防火牆有效性報告。

功能
引導代理以五個步驟,透過 Zscaler Analytics(Z-Insights)評估零信任防火牆資料:防火牆動作分布(允許與封鎖)、依據點的防火牆活動、網路服務與連接埠使用情形,以及與網路安全事件資料的關聯分析。它會解讀封鎖比例、標示異常連接埠與已棄用通訊協定,並找出據點異常。最終產出是一份結構化的網路安全態勢報告,包含表格、發現事項與依優先順序排列的建議。
適用情境
適用於安全或網路團隊需要評估防火牆政策有效性、調查遭封鎖的流量、檢視網路服務使用情形,或產出防火牆合規報告的情境。適合例行審查、合規稽核與事件驅動的調查。
執行需求
需要存取 Zscaler Analytics(Z-Insights)工具,例如 zins_get_firewall_by_action、zins_get_firewall_by_location、zins_get_firewall_network_services,以及網路安全事件相關工具。資料為歷史資料,有 24-48 小時的處理延遲,時間範圍必須正好是 7 天或 14 天。未隨附指令碼,僅有操作說明。

Z-Insights: Assess Network Security Posture

Keywords

firewall analytics, zero trust firewall, firewall effectiveness, allow block ratio, firewall by location, network services, firewall rules, policy hits, firewall report, security posture, network security, blocked traffic, firewall monitoring

Overview

Assess your organization's network security posture by analyzing Zero Trust Firewall data through Zscaler Analytics (Z-Insights). This skill examines firewall action distribution (allow vs block), traffic patterns by location, network service usage, and firewall rule hit counts to evaluate policy effectiveness and identify gaps.

Zscaler's Zero Trust Firewall protects web and non-web traffic for all users, applications, and locations with the industry's most comprehensive cloud-native Security Service Edge (SSE) platform. This analysis covers both inbound and outbound traffic enforcement.

Use this skill when: A security or network team needs to evaluate firewall policy effectiveness, investigate blocked traffic patterns, review network service usage, or generate firewall compliance reports.

Important constraints:

  • Z-Insights only supports historical data with a 24-48 hour processing delay
  • Time ranges must be exactly 7 or 14 days
  • All firewall queries support time ranges up to 90 days

Workflow

Follow this 5-step process to assess network security posture.

Step 1: Understand the Assessment Goal

Gather from the requester:

  • What is the goal? (policy effectiveness, compliance audit, incident investigation, baseline review)
  • Time period? (7 days for recent, 14 days for trends)
  • Specific locations of interest?
  • Are there known policy changes to evaluate?
  • Compare with a previous period?

Step 2: Analyze Firewall Action Distribution

Get firewall traffic by action (allow/block):

text
zins_get_firewall_by_action(    start_days_ago=9,    end_days_ago=2,    limit=10)```text
This shows how much traffic is being allowed versus blocked. Key metrics:
- **Block ratio**: What percentage of traffic is being blocked?  - < 1%: Very permissive -- review if policies are too loose  - 1-5%: Typical for well-tuned policies  - 5-15%: Active enforcement -- verify legitimate traffic isn't impacted  - \> 15%: Aggressive blocking -- check for false positives- **Trend**: Is the block ratio increasing or decreasing?- **Volume**: Absolute block counts indicate threat exposure
---
### Step 3: Analyze Firewall Activity by Location
**Get firewall traffic by location:**
```textzins_get_firewall_by_location(    start_days_ago=9,    end_days_ago=2,    limit=20)```text
This identifies which locations generate the most firewall traffic. Look for:
- **Disproportionate traffic**: A small office generating more firewall hits than headquarters- **Location anomalies**: Sudden spikes at specific locations- **Geographic patterns**: High firewall activity in regions with known threat activity- **Remote worker impact**: Firewall activity from remote/roaming users
Cross-reference with web traffic by location to calculate per-location block ratios.
---
### Step 4: Analyze Network Service Usage
**Get firewall traffic by network service:**
```textzins_get_firewall_network_services(    start_days_ago=9,    end_days_ago=2,    limit=30)```text
Network services represent protocol/port combinations in your traffic. Look for:
- **Expected services**: HTTP (80), HTTPS (443), DNS (53) should dominate- **Unusual services**: Unexpected ports or protocols may indicate:  - Malware communication (non-standard ports)  - Unauthorized applications (VPN tunnels, P2P)  - Misconfigured applications  - Shadow IT network activity- **Deprecated protocols**: Telnet (23), FTP (21) -- should be blocked- **High-risk ports**: RDP (3389), SMB (445) from external sources
---
### Step 5: Correlate with Cyber Incident Data
**Get cybersecurity incident overview:**
```textzins_get_cyber_incidents(    start_days_ago=16,    end_days_ago=2,    categorize_by=["THREAT_CATEGORY_ID"],    limit=20)```text
**Get incidents by location to identify hotspots:**
```textzins_get_cyber_incidents_by_location(    start_days_ago=16,    end_days_ago=2,    categorize_by="LOCATION_ID",    limit=20)```text
Correlate firewall blocks with actual security incidents:
- High blocks + high incidents = Active threat targeting- High blocks + low incidents = Firewall preventing threats effectively- Low blocks + high incidents = Possible policy gaps- Low blocks + low incidents = Clean environment or insufficient visibility
---
### Present Assessment
```textNetwork Security Posture Assessment=======================================Date: <current_date>Period: <start_date> to <end_date>Assessment Type: <compliance / routine / incident-driven>
## Executive Summary
- **Total Firewall Transactions:** X,XXX,XXX- **Allowed:** X,XXX,XXX (XX%)- **Blocked:** XX,XXX (X.X%)- **Block Ratio Assessment:** Within normal range / Needs review- **Locations Analyzed:** XX- **Network Services Detected:** XX- **Security Incidents:** XXX- **Overall Posture:** STRONG / ADEQUATE / NEEDS IMPROVEMENT
---
## Firewall Action Summary
| Action   | Count       | Percentage | Assessment           ||----------|------------|-----------|---------------------|| ALLOW    | 2,340,000  | 96.2%     | Normal               || BLOCK    | 92,500     | 3.8%      | Active enforcement   |
Block ratio of 3.8% is within the typical 1-5% range forwell-tuned policies, indicating effective enforcement withoutexcessive false positives.
---
## Firewall Activity by Location (Top 10)
| Rank | Location          | Total Traffic | Blocked | Block % | Status    ||------|------------------|--------------|---------|---------|-----------|| 1    | New York HQ       | 890,000      | 34,000  | 3.8%    | Normal    || 2    | San Francisco     | 456,000      | 22,000  | 4.8%    | Normal    || 3    | London            | 234,000      | 18,000  | 7.7%    | ELEVATED  || 4    | Singapore         | 189,000      | 4,500   | 2.4%    | Normal    || ...  | ...               | ...          | ...     | ...     | ...       |
**London office** shows elevated block ratio (7.7% vs 3.8% average).Investigate whether this reflects targeted threats or overlyrestrictive policies for that location.
---
## Network Services (Top 15)
| Service         | Port  | Traffic Count | % of Total | Risk     ||----------------|-------|--------------|-----------|----------|| HTTPS           | 443   | 1,890,000    | 77.6%     | Low      || HTTP            | 80    | 290,000      | 11.9%     | Medium   || DNS             | 53    | 145,000      | 6.0%      | Low      || SMTP            | 25    | 23,000       | 0.9%      | Low      || SSH             | 22    | 12,000       | 0.5%      | Medium   || RDP             | 3389  | 8,500        | 0.3%      | HIGH     || FTP             | 21    | 2,300        | 0.1%      | HIGH     || Unknown         | 8443  | 1,800        | 0.1%      | REVIEW   |
**Findings:**- RDP traffic (3389): 8,500 transactions -- verify these are  authorized remote desktop sessions only- FTP traffic (21): 2,300 transactions -- FTP is unencrypted;  migrate to SFTP (22) or FTPS- Unknown (8443): 1,800 transactions on non-standard port --  investigate source applications
---
## Security Incident Correlation
| Category           | Incidents | Firewall Blocks | Effectiveness ||-------------------|-----------|----------------|--------------|| Malware            | 234       | 45,000         | 99.5% caught  || Phishing           | 189       | 28,000         | 99.3% caught  || Command & Control  | 45        | 12,000         | 99.6% caught  || Data Exfiltration  | 12        | 3,200          | 99.6% caught  |
Firewall effectiveness is strong across all threat categories.
---
## Recommendations
### Immediate1. Investigate RDP traffic -- ensure all sessions are authorized2. Block FTP (port 21) and migrate to SFTP3. Investigate unknown traffic on port 8443
### Short-Term4. Review London office elevated block ratio5. Create firewall rules for newly detected network services6. Audit SSH access permissions
### Ongoing7. Schedule monthly firewall effectiveness reviews8. Track block ratio trends for anomaly detection9. Review network service inventory quarterly```text
---
## Edge Cases
### Very Low Block Ratio (< 0.5%)
```textFirewall block ratio is unusually low at X.X%.
This could indicate:- Policies are too permissive- Traffic inspection is not enabled for all protocols- Users are bypassing the firewall (split tunnel VPN)- The environment is genuinely clean
Recommendation: Review firewall rule coverage and ensure alltraffic types are being inspected.```text
### Very High Block Ratio (> 15%)
```textFirewall block ratio is elevated at XX.X%.
This could indicate:- An active security incident or attack- Recently deployed restrictive policies- Misconfigured policies causing false positives- Legitimate applications being incorrectly blocked
Recommendation: Review recently changed firewall rules andcheck if users are reporting access issues.```text
---
## Quick Reference
**Primary workflow:** Scope → Action Distribution → Locations → Network Services → Incidents → Report
**Firewall tools:**
- `zins_get_firewall_by_action()` -- allow/block traffic distribution- `zins_get_firewall_by_location()` -- firewall activity by location- `zins_get_firewall_network_services()` -- network service/port usage
**Incident tools (for correlation):**
- `zins_get_cyber_incidents()` -- incident overview by category- `zins_get_cyber_incidents_by_location()` -- incidents by location- `zins_get_cyber_incidents_daily()` -- daily incident trends- `zins_get_cyber_incidents_by_threat_and_app()` -- threat-app correlation
**Key metrics to track:**
- Block ratio: Target 1-5% for well-tuned policies- Location anomalies: Per-location block ratios that deviate from average- Network services: Unexpected ports or deprecated protocols- Incident correlation: High blocks with low incidents = effective policies

來源與署名

來源:zscaler/zscaler-mcp-server位於skills/zins/assess-network-security提交809f68d

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架