19
From Students… …to Professionals The Capstone Experience Team Rook Roy Barnes Matt Hammerly Will McGee Chiyu Song Mark Velez Department of Computer Science and Engineering Michigan State University Spring 2017 Beta Presentation Force Platform Ingestion Tool

Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

From Students…

…to Professionals

The Capstone Experience

Team RookRoy Barnes

Matt HammerlyWill McGeeChiyu SongMark Velez

Department of Computer Science and EngineeringMichigan State University

Spring 2017

Beta PresentationForce Platform Ingestion Tool

Page 2: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Project Overview

• Force platform for security alert management/analysis

• Force accepts data in one format, but clients send data in different formats

• Force PIT provides a way for clients to integrate existing monitoring tools with Force

• Suggests groups of related alerts to save Rook analysts time

The Capstone Experience Team Rook Beta Presentation 2

Page 3: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

System Architecture

The Capstone Experience Team Rook Beta Presentation 3

Page 4: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Data Flow Diagram

The Capstone Experience Team Rook Beta Presentation 4

Elastic

Page 5: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Data Flow Diagram

The Capstone Experience Team Rook Beta Presentation 5

Brief presentation of Data Flow

Page 6: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

API

API

APIRequest alertsSend back alerts Data

Normalizer

Machine Learning

Platform Ingestion Tool

• From clients of Rook

• Endpoints like firewall, database, etc.

• Send out logs of security events (Alerts)

Data Flow Walkthrough

The Capstone Experience Team Rook Beta Presentation

Page 7: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Data Normalizer

Machine Learning

Platform Ingestion Tool

Elastic Database

Data Flow Walkthrough (cont.)

The Capstone Experience Team Rook Beta Presentation

Page 8: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Elastic

Contains data that includes…

• Alerts, new and old

• Tickets, composed of alerts

• Suggestions created from ML

Pull data from Elastic

Push data through to Front end

Pass back analyst changes

Push changes to update data

Data Flow Walkthrough (cont.)

The Capstone Experience Team Rook Beta Presentation

Page 9: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Store new API configuration settings

Elastic Pull data from Elastic

Push data through to Front end

Pass back analyst changes

Push changes to update data

Data Flow Walkthrough (cont.)

The Capstone Experience Team Rook Beta Presentation

Page 10: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Data Flow Diagram

The Capstone Experience Team Rook Beta Presentation 10

Elastic

Page 11: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Login Page

The Capstone Experience Team Rook Beta Presentation 11

To the end…

Page 12: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Alerts Page

The Capstone Experience Team Rook Beta Presentation 12

Page 13: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Alerts Page – Ticket Panel

The Capstone Experience Team Rook Beta Presentation 13

Page 14: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Alerts - Filtered

The Capstone Experience Team Rook Beta Presentation 14

Page 15: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Tickets Page

The Capstone Experience Team Rook Beta Presentation 15

Page 16: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Tickets - Editing Ticket

The Capstone Experience Team Rook Beta Presentation 16

Page 17: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Jobs Page

The Capstone Experience Team Rook Beta Presentation 17

Page 18: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

What’s left to do?

•Update color scheme to Rook’s updated colors

•Continue building out support for more types of APIs

The Capstone Experience Team Rook Beta Presentation 18

Page 19: Read Me (Delete this slide.) [1 of 2] · 2017-04-04 · Beta Presentation Force Platform Ingestion Tool. Project Overview •Force platform for security alert ... The Capstone Experience

Questions?

The Capstone Experience 19

?

? ??

?

?

?

?

?

Team Rook Beta Presentation