beta presentation
play

Beta Presentation Force Platform Ingestion Tool The Capstone - PowerPoint PPT Presentation

Beta Presentation Force Platform Ingestion Tool The Capstone Experience Team Rook Roy Barnes Matt Hammerly Will McGee Chiyu Song Mark Velez Department of Computer Science and Engineering Michigan State University Spring 2017 From


  1. Beta Presentation Force Platform Ingestion Tool The Capstone Experience Team Rook Roy Barnes Matt Hammerly Will McGee Chiyu Song Mark Velez Department of Computer Science and Engineering Michigan State University Spring 2017 From Students… …to Professionals

  2. Project Overview • Force platform for security alert management/analysis • Force accepts data in one format, but clients send data in different formats • Force PIT provides a way for clients to integrate existing monitoring tools with Force • Suggests groups of related alerts to save Rook analysts time The Capstone Experience Team Rook Beta Presentation 2

  3. System Architecture The Capstone Experience Team Rook Beta Presentation 3

  4. Data Flow Diagram Elastic The Capstone Experience Team Rook Beta Presentation 4

  5. Data Flow Diagram Brief presentation of Data Flow The Capstone Experience Team Rook Beta Presentation 5

  6. Data Flow Walkthrough API • From clients of Rook Machine Request alerts Send back alerts • Endpoints like firewall, Learning Data API Platform Ingestion Tool database, etc. Normalizer • Send out logs of security events (Alerts) API The Capstone Experience Team Rook Beta Presentation

  7. Data Flow Walkthrough (cont.) Elastic Database Machine Learning Data Platform Ingestion Tool Normalizer The Capstone Experience Team Rook Beta Presentation

  8. Data Flow Walkthrough (cont.) Contains data that includes… Push data through Elastic to Front end Pull data from Elastic • Alerts, new and old • Tickets, composed of alerts Pass back analyst Push changes to changes update data • Suggestions created from ML The Capstone Experience Team Rook Beta Presentation

  9. Data Flow Walkthrough (cont.) Store new API configuration settings Push data through Elastic to Front end Pull data from Elastic Pass back analyst Push changes to changes update data The Capstone Experience Team Rook Beta Presentation

  10. Data Flow Diagram Elastic The Capstone Experience Team Rook Beta Presentation 10

  11. To the end… Login Page The Capstone Experience Team Rook Beta Presentation 11

  12. Alerts Page The Capstone Experience Team Rook Beta Presentation 12

  13. Alerts Page – Ticket Panel The Capstone Experience Team Rook Beta Presentation 13

  14. Alerts - Filtered The Capstone Experience Team Rook Beta Presentation 14

  15. Tickets Page The Capstone Experience Team Rook Beta Presentation 15

  16. Tickets - Editing Ticket The Capstone Experience Team Rook Beta Presentation 16

  17. Jobs Page The Capstone Experience Team Rook Beta Presentation 17

  18. What’s left to do? • Update color scheme to Rook’s updated colors • Continue building out support for more types of APIs The Capstone Experience Team Rook Beta Presentation 18

  19. Questions? ? ? ? ? ? ? ? ? ? The Capstone Experience Team Rook Beta Presentation 19

Recommend


More recommend