Download presentation
Presentation is loading. Please wait.
1
Apache Spot (Incubating)
A community approach to fighting cyber threats
2
The hacker community collaborates everyday, it’s time we do the same.
Services Products Training $500 $100 Free Hire a hacker - Hack corporate account without them knowing or needing to change the password. Hacker can then forgot password and reset password to critical applications. Buy a product that helps you hack - Angler exploit kits help infect users with malware. The malware is delivered to the user when they visit a site that has the kit deployed on it. Get trained by the best hackers on Youtube – Anyone can know learn how to hack a corporation. Hack a Corporate Account Angler Exploit Kits Learn to Crack Wifi
3
Status quo can’t keep up with the hacker community
Scale Challenge Silo Challenge Analytics Challenge Endpoint Trillions Events Billions Network User Millions Time Storing, processing, and analyzing 100s of billions of events is not economically or technically feasible today Integrating cross applications data for context and new analytics is not trivial Discovering unknown threats with advanced analytics (machine learning) is impossible on traditional systems
4
A community approach to fighting cyber threats.
Apache Spot (Incubating) A community approach to fighting cyber threats.
5
… to address cybersecurity use cases.
Spot delivers… Scalable Platform with an Open Data Model Analytic Collaboration Across the Community Growing Application Ecosystem … to address cybersecurity use cases. Network Traffic Analytics Threat Hunting Incident Detection and Resolution Cybersecurity Data Management Custom Use Case
6
Custom Analytics Apache Spot Packaged Analytics Network Core Platform
(Incubating) Network Core Platform Cloudera Apache Hadoop provides unrivaled data storage scale Apache Spark provide large scale anomaly detection and advanced analytics Cloudera provides data governance, security, and platform management Intel CDH optimized for Intel hardware Leverages Intel MPI library for application performance optimization Data center compute power Endpoint User Packaged Analytics
7
Custom Analytics Apache Spot Packaged Analytics Network
(Incubating) Network Open Data Models Growing catalog of packaged ingestion pipelines for common data sources Enriched events provide full context leading to better, faster analysis and decision making Organizations maintain and control a single copy of their security data Endpoint User Packaged Analytics
8
Custom Analytics Apache Spot Packaged Analytics Network
(Incubating) Network Packaged Analytics Spot OSS includes machine learning algorithm for network traffic analytics Emerging eco-system of ODM compliant vendor solutions Additional OSS analytics will come from spot community Endpoint User Packaged Analytics
9
Custom Analytics Apache Spot Packaged Analytics Network
(Incubating) Network Custom Analytics Build custom analytics leveraging tools like Jupyter and Sense.io Common data model across peers facilitates analytics collaboration Leverage open source machine learning libraries (e.g. Mllib) Endpoint User Packaged Analytics
10
Cloudera Cyber based on Apache Spot and TAP
Spot ODM Application Marketplace ODM Compliant eco-system, both open source and ISV (Director, Manager, Sentry, Navigator) Management Spot ODM Analytics Network Traffic Analytics, Add’l OSS analytics Analytic Services (Apache Spark, Sense.io, Jupyter) Data Science workbench Spot Sample Data Sets Community sourced, anonymized data sets for model development Apache Spot Open Data Models (ODM) Logical and physical models Ingestion (Kafka, Flume, Streamsets1) Batch and Stream data ingestion Provisioning Management and Security Data Platform (CDH) Scalable storage and distributed processing Infrastructure (On Prem, AWS, Azure) Public or private clouds
11
Join the community that is fighting cyber threats.
Apache Spot (Incubating) Join the community that is fighting cyber threats. spot.incubator.apache.org
12
An overview of Apache Spot
Flow Supervised Learning
13
An overview of Apache Spot
DNS Supervised Learning
14
An overview of Apache Spot
Proxy Supervised Learning
15
An overview of Apache Spot
One out of a million
16
An overview of Apache Spot
Open Data Models + SOLR
17
An overview of Apache Spot
Open Data Models + SOLR
18
An overview of Apache Spot
Investigate
19
An overview of Apache Spot
Investigate Non Suspicious other than choice in news sources
20
An overview of Apache Spot
Investigate Standard View – No Open Data Model
21
An overview of Apache Spot
Investigate User Info (groups, creation dates,etc) + Suspicious info all in one place. Open Data Model Enrichment
22
An overview of Apache Spot
Investigate Determine Incident Scope efficiently. Open Data Model Enrichment
23
Join the community that is fighting cyber threats.
Apache Spot (Incubating) Join the community that is fighting cyber threats. spot.incubator.apache.org
24
Thank you.
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.