Apache Spot (Incubating) A community approach to fighting cyber threats
The hacker community collaborates everyday, it’s time we do the same. Services Products Training $500 $100 Free https://cloudera.my.salesforce.com/06934000001jGcw Hire a hacker - Hack corporate email account without them knowing or needing to change the password. Hacker can then forgot password and reset password to critical applications. Buy a product that helps you hack - Angler exploit kits help infect users with malware. The malware is delivered to the user when they visit a site that has the kit deployed on it. Get trained by the best hackers on Youtube – Anyone can know learn how to hack a corporation. Hack a Corporate Email Account Angler Exploit Kits Learn to Crack Wifi
Status quo can’t keep up with the hacker community Scale Challenge Silo Challenge Analytics Challenge Endpoint Trillions Events Billions Network User Millions Time Storing, processing, and analyzing 100s of billions of events is not economically or technically feasible today Integrating cross applications data for context and new analytics is not trivial Discovering unknown threats with advanced analytics (machine learning) is impossible on traditional systems
A community approach to fighting cyber threats. Apache Spot (Incubating) A community approach to fighting cyber threats.
… to address cybersecurity use cases. Spot delivers… Scalable Platform with an Open Data Model Analytic Collaboration Across the Community Growing Application Ecosystem … to address cybersecurity use cases. Network Traffic Analytics Threat Hunting Incident Detection and Resolution Cybersecurity Data Management Custom Use Case
Custom Analytics Apache Spot Packaged Analytics Network Core Platform (Incubating) Network Core Platform Cloudera Apache Hadoop provides unrivaled data storage scale Apache Spark provide large scale anomaly detection and advanced analytics Cloudera provides data governance, security, and platform management Intel CDH optimized for Intel hardware Leverages Intel MPI library for application performance optimization Data center compute power Endpoint User Packaged Analytics
Custom Analytics Apache Spot Packaged Analytics Network (Incubating) Network Open Data Models Growing catalog of packaged ingestion pipelines for common data sources Enriched events provide full context leading to better, faster analysis and decision making Organizations maintain and control a single copy of their security data Endpoint User http://open-network-insight.org/CybersecurityOpenDataModel0.3.pdf Packaged Analytics
Custom Analytics Apache Spot Packaged Analytics Network (Incubating) Network Packaged Analytics Spot OSS includes machine learning algorithm for network traffic analytics Emerging eco-system of ODM compliant vendor solutions Additional OSS analytics will come from spot community Endpoint User Packaged Analytics
Custom Analytics Apache Spot Packaged Analytics Network (Incubating) Network Custom Analytics Build custom analytics leveraging tools like Jupyter and Sense.io Common data model across peers facilitates analytics collaboration Leverage open source machine learning libraries (e.g. Mllib) Endpoint User Packaged Analytics
Cloudera Cyber based on Apache Spot and TAP Spot ODM Application Marketplace ODM Compliant eco-system, both open source and ISV (Director, Manager, Sentry, Navigator) Management Spot ODM Analytics Network Traffic Analytics, Add’l OSS analytics Analytic Services (Apache Spark, Sense.io, Jupyter) Data Science workbench Spot Sample Data Sets Community sourced, anonymized data sets for model development Apache Spot Open Data Models (ODM) Logical and physical models Ingestion (Kafka, Flume, Streamsets1) Batch and Stream data ingestion Provisioning Management and Security Data Platform (CDH) Scalable storage and distributed processing Infrastructure (On Prem, AWS, Azure) Public or private clouds
Join the community that is fighting cyber threats. Apache Spot (Incubating) Join the community that is fighting cyber threats. spot.incubator.apache.org
An overview of Apache Spot Flow Supervised Learning
An overview of Apache Spot DNS Supervised Learning
An overview of Apache Spot Proxy Supervised Learning
An overview of Apache Spot One out of a million
An overview of Apache Spot Open Data Models + SOLR
An overview of Apache Spot Open Data Models + SOLR
An overview of Apache Spot Investigate
An overview of Apache Spot Investigate Non Suspicious other than choice in news sources
An overview of Apache Spot Investigate Standard View – No Open Data Model
An overview of Apache Spot Investigate User Info (groups, creation dates,etc) + Suspicious info all in one place. Open Data Model Enrichment
An overview of Apache Spot Investigate Determine Incident Scope efficiently. Open Data Model Enrichment
Join the community that is fighting cyber threats. Apache Spot (Incubating) Join the community that is fighting cyber threats. spot.incubator.apache.org
Thank you.