# SmartWAN Portal

This is a guide for users to use the security operating center portal of OpenSASE.

# Overview

<div id="bkmrk-"></div>[![1.jpg](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/1.jpg)](https://book.weetizen.com/uploads/images/gallery/2025-04/1.jpg)

#### **SmartWAN Portal**

<div id="bkmrk-the-opensase-dashboa">The SmartWAN Portal provides a centralized, real-time interface for comprehensive security monitoring and management across hybrid IT environments.</div><div id="bkmrk-designed-to-integrat">Designed to integrate on-premises and cloud-based security data, the dashboard offers a unified view of an organization’s security posture, enabling proactive threat detection, alert management, and streamlined compliance tracking.</div><div id="bkmrk--2"></div><div id="bkmrk--3"></div><div id="bkmrk-the-portal-offers-a-"><div>The portal offers a variety of dashboards, including the **Agency Dashboard**, **Event Dashboard**, and **Threat Scoring Dashboard**, each tailored to specific monitoring needs. Upon accessing the SmartWAN Portal, users are directed to the default **Agency Dashboard**, which provides visualized status information on network and security events for agencies with installed SmartWAN Customer Premises Equipment (CPE). Additional features, such as user authentication, event lists, and detailed agency monitoring, empower users to manage incidents effectively and maintain operational security.</div></div>---

# Authentication

<div id="bkmrk-" style="padding: 52.78% 0 0 0; position: relative;"><iframe allow="autoplay; fullscreen; picture-in-picture; clipboard-write; encrypted-media" frameborder="0" height="" src="https://player.vimeo.com/video/1071628623?h=2a1f65a763&title=0&byline=0&portrait=0&badge=0&autopause=0&player_id=0&app_id=58479" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%;" title="Authentication" width=""></iframe>

</div>**SmartWAN Portal Login**

When you access the SmartWAN Portal, you will encounter the login screen as shown in the image below. This screen allows users to authenticate and access the portal's features.

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/raFimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/raFimage.png)

<div id="bkmrk-input-fields%3A-email-">**Input Fields**: - **Email Address or ID**: A field where users enter their registered email address or ID (e.g., "Enter your registered email address or ID").
- **Password**: A field for entering the user’s password (e.g., "Enter your password"), with a visibility toggle icon to show or hide the password.

</div>**Additional Authentication Options**

<div id="bkmrk-top-right-corner-of-">- Top-right corner of the screen.   
    By clicking the "**⋮**" (three dots) icon in the top-right corner, users can access a detailed menu related to user authentication. This menu provides additional options for managing login settings or troubleshooting access issues.

</div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/Xr0image.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/Xr0image.png)

<div id="bkmrk-the-%22additional-logi">The "Additional Login Services Menu" provides options to assist users with authentication-related tasks on the SmartWAN Portal login screen. This menu can be accessed by clicking the vertical "⋮" (three dots) icon in the top-right corner of the login screen.</div><div id="bkmrk--4">  
</div>**Menu Options**

<div id="bkmrk-verify-registered-em"><div>- **Verify Registered Email Address or ID**: Allows users to verify their registered email address or ID to ensure they are using the correct credentials for login.
- **Reset Password**: Provides an option for users to reset their password if they have forgotten it or need to update it for security reasons.
- **Request an Account**: Enables new users to request an account if they do not already have one, initiating the account creation process.

</div></div><p class="callout info">Some features described above are currently in the prototype stage and are scheduled for future implementation.</p>

---

#### **Verification Registered Email Address of ID**

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/kr7image.png)

<div id="bkmrk-as-part-of-the-user-">As part of the user verification process in the SmartWAN Portal, the "Verify Registered Email Address or ID" option allows users to confirm their credentials using a PassKey. </div><div id="bkmrk--7"></div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/kFdimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/kFdimage.png)

<div id="bkmrk-passkey-verification">**PassKey Verification**: - **QR Code**: A QR code is displayed for users to scan with a device that has a registered PassKey, enabling secure verification.

**Alternative Option**: - **Verify with Phone Number Button**: An alternative "Verify with Phone Number" button is provided for users whose devices do not have a registered PassKey.

</div>---

#### **ResetPassword**

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/3GWimage.png)

<div id="bkmrk-after-selecting-the-">After selecting the "Reset Password" option from the "Additional Login Services Menu" on the SmartWAN Portal, users are directed to the following screen to verify their identity before resetting their password.</div><div id="bkmrk--11"></div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/2v7image.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/2v7image.png)

<div id="bkmrk-passkey-verification-1">**PassKey Verification**: - **QR Code**: A QR code is displayed for users to scan with a device that has a registered PassKey, enabling secure verification prior to password reset.

**Alternative Option**: - **Verify with Phone Number Button**: An alternative "Verify with Phone Number" button is provided for users whose devices do not have a registered PassKey.

</div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/cTlimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/cTlimage.png)

<div id="bkmrk-once-the-user%E2%80%99s-iden">Once the user’s identity is successfully verified using a PassKey or phone number, the SmartWAN Portal provides a screen to change the password. This screen allows users to set a new password following the specified guidelines.</div>---

#### **Request an Account**

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/Wovimage.png)

After selecting the "Request an Account" option from the "Additional Login Services Menu" on the SmartWAN Portal, users are directed to the following screen to verify their identity before resetting their password.

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/XUdimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/XUdimage.png)

**PassKey Verification**:

- **QR Code**: A QR code is displayed for users to scan with a device that has a registered PassKey, enabling secure verification prior to request an account.

**Alternative Option**:

- **Verify with Phone Number Button**: An alternative "Verify with Phone Number" button is provided for users whose devices do not have a registered PassKey.

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/6hVimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/6hVimage.png)

<div id="bkmrk-this-screen-allows-u"><div>This screen allows users to request a new account by providing their PassKey-verified phone number, email address, and name. After verifying the email availability, users can submit the request using the "Request Account" button.</div><div>  
</div></div><div id="bkmrk-input-fields%3A-passke">**Input Fields**: - **PassKey-verified phone number**: Displays a pre-filled, non-editable phone number associated with the PassKey.
- **Email Address**: A field to enter the user’s email address (e.g., "markov01@markov.com"), with a "Check Availability" button to verify if the email is available (status: "Email address is available for use").
- **User Name**: A field to enter the user’s name

</div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/wYwimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/wYwimage.png)

<div id="bkmrk-this-screen-confirms">This screen confirms the successful submission of the account request, informing the user that the result will be sent to their email. Users can then click "Go to Login" to return to the login screen and sign in with their new account.</div>---

#### **User Information and Notifications**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/H1Pimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/H1Pimage.png)

<div id="bkmrk-after-logging-in%2C-yo">After logging in, you can see the user information adjacent to the top-right corner.</div>![스크린샷 2025-04-01 오후 12.42.01.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/2025-04-01-12-42-01.png)

<div id="bkmrk-click-on-the-user-in">Click on the user information to view additional settings menus and the current status of notifications. Options such as "Logout" and "Account Management" are available for the user to sign out or manage their account settings.</div>![스크린샷 2025-04-01 오후 12.42.40.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/2025-04-01-12-42-40.png)

**Real-time Alerts**

If any alerts need to be provided to the user, an alert message will be displayed on the left side of the screen in real time.

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/3Q1image.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/3Q1image.png)

**Assigned Case Notification**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/CAlimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/CAlimage.png)

<div id="bkmrk-if-a-user-has-assign">If a user has assigned cases that remain unresolved, a popup notification will appear after logging in to the SmartWAN Portal. This **Assigned Case Notification** alerts the user to the open cases that require attention.</div>---

#### **Logout**

You can log out by clicking the log-out button in the user information.

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/7xkimage.png)

# Home Screen

<div id="bkmrk-" style="padding: 52.78% 0 0 0; position: relative;"><iframe allow="autoplay; fullscreen; picture-in-picture; clipboard-write; encrypted-media" frameborder="0" height="" src="https://player.vimeo.com/video/1071335590?h=92d8fa4f7c&title=0&byline=0&portrait=0&badge=0&autopause=0&player_id=0&app_id=58479" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%;" title="Home Screen" width=""></iframe>

</div><p class="callout info">Some features described below are currently in the prototype stage and are scheduled for future implementation.</p>

[![1.jpg](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/1.jpg)](https://book.weetizen.com/uploads/images/gallery/2025-04/1.jpg)

<div id="bkmrk-upon-logging-in-to-t">Upon logging in to the SmartWAN Portal, the **Home Screen** automatically appears, providing a comprehensive overview of network and security events across locations worldwide.</div>#### **Widgets**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/1Qzimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/1Qzimage.png)

**1. Traffic Widget**

<div id="bkmrk-description%3A-display">- **Description**: Displays real-time network traffic data over a selected time period (e.g., last 24 hours). The graph shows RX (receive) and TX (transmit) traffic in Mbps, with peaks and trends.

</div>**2. Site Overview**

<div id="bkmrk-description%3A-shows-a">- **Description**: Shows a summary of the status sites.

</div>**3. Top5**

<div id="bkmrk-description%3A-display-1">- **Description:** Displays the top 5 sites ranked by network traffic

</div>**4. Case**

- **Description:** Lists critical cases and their affected objects, and provides on pending critical cases

**5. World Map(Map view)**

- **Description:** Provides a global map view of locations, with lines indicating connectivity between sites (e.g., Munich, New York, San Francisco, Sao Paulo, Sydney).

**6. Threat case trends**

- **Description:** A line graph showing trends in threat cases over time. Categories include Critical, High, Medium, and Low, with data points indicating case counts.

**7. Today's Case Distribution**

- **Description:** A scatter plot visualizing the distribution of cases by severity (Critical, High, Medium, Low) over a 24-hour period. Each bubble represents a case, with size indicating the number of incidents (e.g., Critical: 207 cases).

**8. Today's Case Summary**

- **Description**: A pie chart summarizing the total cases for the day.

**9. Case**

- **Description**: A table shows that case-affected objects.

**10. Network Summary Metrics**

- <div>**Topology**: 
    - **Total Topologies**: Displays the total number of network topologies (e.g., 1).
    
    **Intranet Host**: 
    - **Total Intranet Hosts**: Shows the total number of intranet hosts connected (e.g., 342).
    
    **WAN**: 
    - **Total WAN**: Indicates the total number of Wide Area Network (WAN) connections (e.g., 124).
    
    **Bandwidth**: 
    - **Total Bandwidth**: Displays the total bandwidth capacity for both download (↓) and upload (↑) in Mbps (e.g., 16,000 Mbps for both).
    - **Subscription Bandwidth**: Shows the subscribed bandwidth for both download (↓) and upload (↑) in Mbps (e.g., 16,000 Mbps for both).
    
    **Policy**: 
    - **Total SmartWAN Policies**: Lists the total number of SmartWAN policies in place (e.g., 31).
    - **Total SmartWAN Policies (Subscription)**: Indicates the number of subscribed SmartWAN policies (e.g., 237).
    
    </div>

<p class="callout info">The widgets provided on the dashboard may be modified in the future based on evolving requirements.</p>

<div id="bkmrk--3"></div>#### **Map Submenu**

After logging in to the SmartWAN Portal, the Home screen displays the world map by default, featuring a world map in the "Map View." On the right side of the map, users can access additional options through the Map Submenu.

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/By2image.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/By2image.png)

<div id="bkmrk-click-the-vertical-%22"><div>Click the vertical "⋮" (three dots) icon to open the **Map Sub Menu**. This menu allows users to filter and view site information based on specific criteria</div></div><div id="bkmrk--5"></div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/rlWimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/rlWimage.png)

<div id="bkmrk-map-sub-menu-with-th">**Map Sub Menu** with the "Select Country &amp; Region" dropdowns and the resulting site list after applying filters.</div><div id="bkmrk--7"></div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/ylUimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/ylUimage.png)

**Filtering Sites by Country and Region**

The **Map Sub Menu** provides filtering options to narrow down the list of sites displayed on the dashboard.

<div id="bkmrk-select-country-%26-reg">- **Select Country &amp; Region**: 
    - **Country**: A dropdown menu to select a country (e.g., South Korea, USA, China, Germany, Japan).
    - **Region**: A dropdown menu to select a region within the chosen country (e.g., USA &gt; California).
- **Site List**: 
    - After applying the country and region filters, a list of sites within the selected area is displayed.
    - The list includes columns such as: 
        - **Site**: Name of the site (e.g., Head Office, New York Branch).
        - **RX/TX (Mbps)**: Network traffic data for receive (RX) and transmit (TX) in Mbps.
        - **Critical Cases**: Number of critical cases associated with the site.
        - **All Cases**: Total number of cases for the site.

</div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/mmuimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/mmuimage.png)

<div id="bkmrk-the-image-above-show">The image above shows the **Map Sub Menu** with the country filter set to South Korea and the region dropdown expanded, displaying available regions. The map and site list reflect the filtered view for South Korea, with detailed metrics for each site.</div><div id="bkmrk--10"></div><div id="bkmrk--12"></div><div id="bkmrk--13"></div>

# Dashboard

<div id="bkmrk-" style="padding: 52.78% 0 0 0; position: relative;"><iframe allow="autoplay; fullscreen; picture-in-picture; clipboard-write; encrypted-media" frameborder="0" height="" src="https://player.vimeo.com/video/1071626433?h=48497c86cc&title=0&byline=0&portrait=0&badge=0&autopause=0&player_id=0&app_id=58479" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%;" title="Agency monitoring" width=""></iframe>

</div>#### **Getting Started**

**Logging In with an Accessible User Account**

To begin, log in using a user account with access privileges.  
You can find more options for [**user authentication**](https://book.weetizen.com/books/appex-opensase/page/authentication "User Athentication").

[![스크린샷 2025-03-30 오후 7.53.58.png](https://book.weetizen.com/uploads/images/gallery/2025-03/scaled-1680-/2025-03-30-7-53-58.png)](https://book.weetizen.com/uploads/images/gallery/2025-03/2025-03-30-7-53-58.png)

<p class="callout info">This guide is based on SKT’s SmartWAN Portal. Updates will be continuously applied to reflect future changes.</p>

---

#### **Pre-Configured Dashboards**

<div id="bkmrk-the-system-currently">The system currently offers three pre-configured dashboard types for users.</div><div id="bkmrk-the-visualization-of">The visualization of data provided by the SmartWAN Portal is categorized into three distinct types. Upon accessing the SmartWAN Portal, the default landing page is fixed to the **Agency Dashboard**.</div><div id="bkmrk--1"></div><div id="bkmrk--8"></div><div id="bkmrk--9"></div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/Bfqimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/Bfqimage.png)

<p class="callout info">Currently, the dashboards are configured for the monitoring purposes of SKT’s agency SmartWAN system.</p>

---

#### **Event Dashboard (under development)**

<div id="bkmrk-the-event-dashboard-">The Event Dashboard delivers aggregated information and status management insights for Incidents, Alerts, Threats, and other data collected from various data sources.</div><div id="bkmrk--13"></div>[![스크린샷 2025-03-30 오후 5.33.21.png](https://book.weetizen.com/uploads/images/gallery/2025-03/scaled-1680-/2025-03-30-5-33-21.png)](https://book.weetizen.com/uploads/images/gallery/2025-03/2025-03-30-5-33-21.png)

<div id="bkmrk-purpose%3A-provides-a-">- **Purpose**: Provides a centralized view of security and network event data, enabling users to monitor and manage incidents effectively.
- **Data Sources**: Integrates information from multiple origins, including agents, agentless systems, and external feeds.
- **Key Information**: Displays summaries of event counts, severity levels, and current statuses to facilitate quick decision-making.

</div>---

#### **Agency Dashboard**

<div id="bkmrk-the-agency-dashboard">The Agency Dashboard provides visualized status information on network and security events for agencies where SmartWAN CPE (Customer Premises Equipment) is installed, displayed through an interactive map interface.</div><div id="bkmrk--16"></div><div id="bkmrk-there-are-2-monitor-">There are 2 monitor dashboards</div><div id="bkmrk-agency-monitoring-sy">- Agency monitoring
- System monitoring

</div>[![스크린샷 2025-03-30 오후 7.21.07.png](https://book.weetizen.com/uploads/images/gallery/2025-03/scaled-1680-/2025-03-30-7-21-07.png)](https://book.weetizen.com/uploads/images/gallery/2025-03/2025-03-30-7-21-07.png)

---

#### **Agency monitoring**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-03/scaled-1680-/HSbimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-03/HSbimage.png)

##### **Map View**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-03/scaled-1680-/EJJimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-03/EJJimage.png)

<div id="bkmrk-this-view-offers-a-c">This view offers a comprehensive overview of all agency locations and detailed information segmented by major cities. It aggregates and classifies network and security events into four categories. **Block**, **Critical**, **Minor**, and **Info**.</div><div id="bkmrk--21"></div><p class="callout info">Event levels are defined by SKT's requirements.</p>

##### **Agency List**

[![스크린샷 2025-03-30 오후 8.20.03.png](https://book.weetizen.com/uploads/images/gallery/2025-03/scaled-1680-/2025-03-30-8-20-03.png)](https://book.weetizen.com/uploads/images/gallery/2025-03/2025-03-30-8-20-03.png)

When a specific region is selected in the Map View, the dashboard displays a list of agencies registered in that region, along with detailed information on the **Network Status (CPE)** and **Security Status (SDP)** for each agency.

<div id="bkmrk-agency-list%3A-a-compr">- **Agency List**: A comprehensive roster of agencies within the selected region.
- **Network Status (CPE)**: Provides the current operational status of the Customer Premises Equipment for eacßh agency.
- **Security Status (SDP)**: Details the security posture, including Software-Defined Perimeter (SDP) metrics, for each agency.

</div>##### **View details of the agency**

To access an agency's detailed information:

1. Go to the **Agency List** in the dashboard
2. Click the desired **agency name**
3. The system will load the **detailed agency view**

**Network View**

This view provides a granular view of both network performance and security status for the selected agency. Users can toggle between Network View and Security View to access specific metrics.

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-03/scaled-1680-/f7qimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-03/f7qimage.png)

The dashboard is divided into two main tabs:

- **Network View**: Displays real-time CPE status and network performance.
- **Security View**: Shows security-related alerts and SDP metrics (if applicable).

Displays hardware and connectivity details:

- **CPE ID/Name/Model**: Identifies the device.
- **High Availability**: Indicates redundancy status ( Enabled / Disabled).
- **CPE Status**:
    
    
    - **Active**: Normal operation.
    - **Degraded**: Performance issues detected.
    - **Inactive**: Connection lost.
- **Connected Data Centers**: Primary (Seoul) and Secondary (Daejeon) links.

Network Performance Metrics data(Live) for troubleshooting:

- **CPU/RAM/Disk**: Resource usage (% or GB).
- **Latency/Jitter**: Measured in milliseconds (ms).
- **Packet Loss (TX/RX)**: Percentage of lost data packets.

Lists recent events with types and levels:

<table id="bkmrk-column-description-e"><thead><tr><th>**Column**</th><th>**Description**</th><th>**Example**</th></tr></thead><tbody><tr><td>**Type**</td><td>Event category (Network/Security).</td><td>`Network`</td></tr><tr><td>**Event**</td><td>Description of the issue.</td><td>`CPE ETH0 Link Down`</td></tr><tr><td>**Level**</td><td>Severity: `Info`, `High`, `Critical`.</td><td>`Critical`</td></tr><tr><td>**Time**</td><td>Timestamp (HH:MM:SS.milliseconds).</td><td>`16:13:31.00256`</td></tr></tbody></table>

**Security View**

This view provides comprehensive monitoring and management capabilities for the selected agency, displaying real-time network status, user information, security events, and service connectivity. The interface is divided into multiple sections for efficient administration.

[![스크린샷 2025-03-30 오후 8.21.48.png](https://book.weetizen.com/uploads/images/gallery/2025-03/scaled-1680-/2025-03-30-8-21-48.png)](https://book.weetizen.com/uploads/images/gallery/2025-03/2025-03-30-8-21-48.png)

**User Management Section**

- User List 
    - Displays all registered users (currently **3 users**) with:
        
        
        - **ID**: Unique user identifier (e.g., `mskimos3`)
        - **Name**: Full name of the user (e.g., `Minsco.ftm`)
        - **Email**: Associated email address (e.g., `mskim.ios8@tworld.com`)
        - **Lock Status**: 💬 indicates an active session (no lock applied).
- User Detail 
    - Expands on selected user profiles with:
        
        
        - **Department/Role**: Organizational hierarchy (e.g., `Solution Development > Developer`).
        - **Contact**: Email (`tworld_win@tworld.com`) and phone (`010-5587-1154`).
        - **Device List**: Managed devices linked to the user (e.g., `SDP Router` with OS details).

**Agency Policy &amp; Configuration**

- **Connected CPE**
    - Hardware details of the Customer Premises Equipment:
        
        
        - **CPE ID/IP**: Unique identifiers for the network device.
        - **CPE Name**: Label for easy recognition.
- **Mandatory Processes**
    - Critical processes are monitored by type, name, and operating system.

**Security Monitoring**

- Security Events Table 
    - Lists real-time security incidents with:
        
        
        - **Type/Name**: Event description (e.g., `Blocked access to ransomware sites`).
        - **Level**: Severity (`Critical`, `High`).
        - **Time**: Precise timestamp (e.g., `16:13:01.0025`).
- Example Events: 
    - `Critical`: Ransomware detection, essential process violations.
    - `High`: Blocked access to malicious domains, outdated OS alerts.

##### **Agency Groups**

[![스크린샷 2025-03-30 오후 7.32.12.png](https://book.weetizen.com/uploads/images/gallery/2025-03/scaled-1680-/2025-03-30-7-32-12.png)](https://book.weetizen.com/uploads/images/gallery/2025-03/2025-03-30-7-32-12.png)

The Agency Group section provides a summary of agency counts per region and detailed status information for CPE.

<div id="bkmrk-region-based-counts%3A">- **Region-Based Counts**: Displays the total number of agencies in each region.
- **CPE Status Info**: Offers insights into the operational status of CPE devices across the agencies

</div>##### **Event List**

[![스크린샷 2025-03-30 오후 7.39.42.png](https://book.weetizen.com/uploads/images/gallery/2025-03/scaled-1680-/2025-03-30-7-39-42.png)](https://book.weetizen.com/uploads/images/gallery/2025-03/2025-03-30-7-39-42.png)

<div id="bkmrk-the-event-list-secti">The Event List section displays a table of recent events, providing detailed information including the event type, name, severity level, and timestamp for all recorded incidents.</div><div id="bkmrk-columns%3A-type%3A-indic">**Columns**: - **Type**: Indicates the category of the event (e.g., <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">sdp-audit</span>, <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">Security</span>).
- **Event Name**: Specifies the event description (e.g., <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">NdpPerformance</span>, <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">Hardware State Check</span>, <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">ProcessCheck</span>, or security-related messages like <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">\[JAMES\] Blocked access to www…</span>).
- **Level**: Denotes the severity of the event, categorized as <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">Info</span>, Minor, or <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">Critical, Block</span>.
- **Time**: Shows the timestamp of the event in the format <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">MM/DD HH:MM:SS.milliseconds</span> (e.g., <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">03/30 16:13:00.025</span>).

**Examples**: - <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">sdp-audit</span> events such as <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">NdpPerformance</span> and <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">Hardware State Check</span> with <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">Info</span> level.
- <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">Security</span> events like <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">\[JAMES\] Access blocked: Rans…</span> with <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">Critical</span> level or <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">\[JAMES\] Android OS version is to…</span> with <span class="text-sm px-1 rounded-sm !font-mono bg-sunset/10 text-rust dark:bg-dawn/10 dark:text-dawn">High</span> level.

</div>---

#### **System monitoring**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-03/scaled-1680-/8bgimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-03/8bgimage.png)

##### **SecureEdge point of presence**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-03/scaled-1680-/I6aimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-03/I6aimage.png)

It shows SecureEdge's distributed architecture. The visual indicators show system statuses, and on the bottom, highlight critical/security events of the agency.

<p class="callout info">This monitoring supports SKT's internal operations only, providing real-time monitoring of their SecureEdge deployment through redundant controllers and gateways at each location.</p>

##### **Agency List** 

It's the same as the **agency list** in **Agency Monitoring.**

##### **Events List**

It's the same as the **events list** in **Agency Monitoring.**

---

#### **Risk Scoring (under development)**  


This dashboard provides a consolidated view of **network security compliance, threat protection status, and regulatory adherence** for monitoring and reporting purposes.

![스크린샷 2025-03-31 오전 12.48.43.png](https://book.weetizen.com/uploads/images/gallery/2025-03/scaled-1680-/2025-03-31-12-48-43.png)

<p class="callout info">The current visualization serves as a prototype. We will develop optimized data representation formats aligned with operational objectives during the implementation phase.</p>

# Detection & Response

<div id="bkmrk-" style="padding: 52.78% 0 0 0; position: relative;"><iframe allow="autoplay; fullscreen; picture-in-picture; clipboard-write; encrypted-media" frameborder="0" height="" src="https://player.vimeo.com/video/1071338806?h=a157766e78&title=0&byline=0&portrait=0&badge=0&autopause=0&player_id=0&app_id=58479" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%;" title="Detection & Response" width=""></iframe>

</div>#### **Cases**

The user can access the **cases menu**, which is under **Detection &amp; Response.**

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/HBJimage.png)

#### **Case List**

<div id="bkmrk-the-case-list-screen">The **Case List** screen in the SmartWAN Portal, accessible under the "Detection &amp; Response" section, provides a detailed list of cases generated by analyzing event logs. This screen allows users to view and manage security and network-related incidents efficiently.</div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/yyOimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/yyOimage.png)

##### **Key Features**

<div id="bkmrk-filters-and-search%3A-">- **Filters and Search**: 
    - **Customer and Asset Selection**: Dropdown menus at the top (e.g., "Select a customer," "Select an asset") to filter cases by specific customers or assets.
    - **Date Range**: A date picker to filter cases within a specific time period (e.g., 2024/09/30 - 2024/10/30).
    - **Advanced Search**: A button on the right to access advanced search options for more granular filtering.
- **Case Summary**: 
    - Displays the total number of cases (e.g., 279 cases) and the total results (e.g., 2,193 cases) for the selected filters.
- **Case Table**: 
    - A table listing cases with columns such as: 
        - **Event Type**: Type of event (e.g., Raw Packet).
        - **Source Asset**: Source of the event.
        - **Destination Asset**: Destination of the event.
        - **Rule**: Applied rule.
        - **Source IP**: Source IP address.
        - **Destination Port**: Destination port.
        - **Time**: Timestamp of the event.
        - **Raw Packet**: A column with a clickable icon to view raw packet details (e.g., BSX525D9252F...).
- **Notification Settings**: 
    - A "Notification Settings" button at the top-right corner to configure alert preferences.

</div><p class="callout info">The items provided in the Case List may be modified in the future based on evolving requirements.</p>

##### **Case Filtering**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/zpdimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/zpdimage.png)

<div id="bkmrk-after-selecting-a-cu">*After selecting a customer, the case table updates to reflect cases specific to that customer, ensuring users can focus on relevant incidents.*</div><div id="bkmrk--5"></div><div id="bkmrk-customer-selection%3A-">**Customer Selection**: - **Dropdown Menu**: Displays a list of available customers (e.g., SK Telecom, Samsung Electronics, KT&amp;G, Ericsson, Coca Cola, General Electric, BMW).
- **Action**: Click the "Select a customer" dropdown to choose a customer, filtering the case list to show only cases related to the selected customer.

**Multi-Tenant Support**: - Each customer is represented, indicating secure separation of data in the multi-tenant environment.
- The associated assets for the selected customer are displayed.

</div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/r8dimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/r8dimage.png)

<div id="bkmrk-the-select-an-asset-">*The **Select an Asset** dropdown on the **Case List** screen allows users to filter cases by specific assets. It lists assets such as "Seoul IDC LW3007," "T-Store Pangyo LW2308-4G," and "Daejeon IDC LW7009." Users can select an asset and click "Selection Confirmed" to update the case list.*</div><div id="bkmrk--7"></div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/3Zgimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/3Zgimage.png)

<div id="bkmrk-the-advanced-search-">*The **Advanced Search** feature on the **Case List** screen allows users to refine their case search with additional filters. Accessible via the "Advanced Search" button, it includes options to select a customer, asset, severity level (e.g., Critical, High), and enter a search keyword. Users can apply these filters by clicking the "Search" button to update the case list.*</div><div id="bkmrk--9"></div>#### **Case Details**

<div id="bkmrk-the-case-details-pop">The **Case Details** popup in the SmartWAN Portal is displayed when a user selects a case from the **Case List** screen. This popup provides detailed information about the selected case, including event specifics and related events, to assist users in analyzing and managing.</div><div id="bkmrk-case-information%3A-th">- **Case Information**: The default tab, showing detailed case data.
- **Case Management**: A secondary tab for managing the case.

</div>##### **Case Information**

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/1lfimage.png)

<div id="bkmrk-detailed-case-inform">**Detailed Case Information**: - **Event Type**: The type of event
- **Asset Type**: The type of asset involved
- **Asset No.**: The asset identifier
- **Timestamp**: The date and time of the event
- **System IP**: The system IP address
- **Origin Country**: The country of origin
- **Origin IP**: The originating IP address
- **Origin Port**: The originating port
- **Destination Country**: The destination country
- **Destination IP**: The destination IP address (
- **Destination Port**: The destination port
- **Remote IP**: The remote IP address

</div><div id="bkmrk-related-events-list%3A">**Related Events List**: - A table at the bottom listing related events, with columns including: 
    - **Event Type**: Type of related event
    - **Asset Type**: Type of asset involved
    - **Asset No.**: Asset identifier
    - **Timestamp**: Date and time of the related event
    - **System IP**: System IP address

</div>#### **Case Management**

<div id="bkmrk-the-case-management-">The **Case Management** tab in the **Case Details** popup outlines the steps for handling a case in the SmartWAN Portal.</div><div id="bkmrk-the-procedures-guide">The procedures guide users through the process of managing a case from opening to closure. Below is a summary of the steps involved.</div><div id="bkmrk--11"></div>**Case Management Procedure Table**

<div id="bkmrk-step-procedure-descr"><div><div class="overflow-x-auto my-2"><table><thead class="border-b border-primary/20"><tr class="border-primary/10"><th class="break-words">Step</th><th class="break-words">Procedure</th><th class="break-words">Description</th></tr></thead><tbody><tr class="border-primary/10"><td class="break-words">1</td><td class="break-words">Case Open</td><td class="break-words">Initiates the case and assigns it to a user.</td></tr><tr class="border-primary/10"><td class="break-words">2</td><td class="break-words">Initial Investigation</td><td class="break-words">Conducts preliminary analysis of the incident.</td></tr><tr class="border-primary/10"><td class="break-words">3</td><td class="break-words">Prioritization</td><td class="break-words">Assigns a priority level to the case.</td></tr><tr class="border-primary/10"><td class="break-words">4</td><td class="break-words">Analysis and Response</td><td class="break-words">Performs detailed analysis and responds to the incident.</td></tr><tr class="border-primary/10"><td class="break-words">5</td><td class="break-words">Containment and Mitigation</td><td class="break-words">Implements measures to contain and mitigate the issue.</td></tr><tr class="border-primary/10"><td class="break-words">6</td><td class="break-words">Recovery and Remediation</td><td class="break-words">Restores systems and applies fixes to prevent recurrence.</td></tr><tr class="border-primary/10"><td class="break-words">7</td><td class="break-words">Case Closure</td><td class="break-words">Closes the case after resolution.</td></tr><tr class="border-primary/10"><td class="break-words">8</td><td class="break-words">Post-Incident Review</td><td class="break-words">Reviews the incident for lessons learned.</td></tr></tbody></table>

</div></div></div>##### **Step 1. Case Open**

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/Mnkimage.png)

<div id="bkmrk-purpose%3A-the-%22case-o">**Purpose**: The "Case Open" step marks the beginning of the case management process. When a case is identified (e.g., a traffic-related event on a Juniper asset), it is opened in the system, and relevant details are recorded.</div><div id="bkmrk--13"></div><div id="bkmrk-details-displayed%3A-a">**Details Displayed**: - **Assignee**: The user assigned to handle the case (e.g., Bryan Ga).
- **Event Type**: The type of event (e.g., Traffic).
- **Asset Type**: The type of asset involved (e.g., Juniper).
- **Asset No.**: The asset identifier (e.g., 38697).
- **Timestamp**: The date and time the event occurred (e.g., 2024-09-30 10:57:59+09:00).
- **System IP**: The system IP address (e.g., 1.1.1.1).
- **Severity Level**: The severity of the case (e.g., Critical).
- **Threat Classification**: The threat level or classification (e.g., 9)

</div>##### **Step 2. Initial Investigation**

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/rOCimage.png)

<div id="bkmrk-purpose%3A-the-%22initia">**Purpose**: The "Initial Investigation" step involves evaluating the case details and associated events to confirm whether the incident is a legitimate threat that requires further action.</div><div id="bkmrk--15"></div><div id="bkmrk-instructions-provide">**Instructions Provided**: - **Evaluate the Case**: Users are prompted to "Evaluate the case details and associated events to verify if it’s a legitimate threat incident and handle it accordingly."
- **Event Information Access**: Users can find detailed event information for the open case and related events in the "Case Information" tab of the **Case Details** popup.
- **Check for Positive**: Users must determine the legitimacy of the threat by selecting one of two options: 
    - **Confirmed as True Positive**: Indicates the incident is a confirmed threat.
    - **Confirmed as False Positive**: Indicates the incident is not a threat (e.g., a false alarm).

**Action**: - After completing the evaluation and selecting the appropriate "Check for Positive" option, users click the "Save Step" button to record their findings and proceed to the next step in the Case Management process.

</div>##### **Step 3. Prioritization**

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/eoIimage.png)

<div id="bkmrk-purpose%3A-the-%22priori">**Purpose**: The "Prioritization" step involves evaluating the case based on its severity and impact to determine the urgency of response. This helps in allocating resources effectively and addressing high-priority incidents first.</div><div id="bkmrk--17"></div><div id="bkmrk-instructions-provide-1">**Instructions Provided**: - **Priority Evaluation**: Users are informed that "Priority is evaluated based on the severity and impact of the event."
- **Severity Level Selection**: Users can select the severity level of the case from the following options: 
    - **Critical**: For incidents with severe impact requiring immediate action.
    - **High**: For incidents with significant impact needing prompt attention.
    - **Moderate**: For incidents with moderate impact that can be addressed in a standard timeframe.
    - **Low**: For incidents with minimal impact that can be handled with lower urgency.

**Action**: - After selecting the appropriate severity level (e.g., Critical, High, Moderate, or Low), users click the "Save Step" button to record the prioritization and proceed to the next step in the Case Management process.

</div>##### **Step 4. Analysis and Response**

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/40Fimage.png)

<div id="bkmrk-purpose%3A-the-%22analys">**Purpose**: The "Analysis and Response" step aims to analyze the root cause of the threat, identify the affected assets and scope, and develop a response strategy to mitigate the incident.</div><div id="bkmrk--19"></div><div id="bkmrk-instructions-provide-2">**Instructions Provided**: - **Analyze the Threat**: Users are prompted to "Analyze the root cause of the threat and identify the affected assets and scope."
- **Further Analysis**: If needed, users are advised to "conduct further analysis on related logs and events" to gain deeper insights into the incident.
- **Document Findings**: Users are required to "describe the analysis details thoroughly in the text-area below for reporting purposes." A text editor is provided to input detailed notes, with formatting options such as bold, italic, underline, alignment, lists, links, images, and emojis.

**Action**: - Users enter their analysis details in the text area.
- After completing the analysis and documenting the findings, users click the "Save Step" button to record their work and proceed to the next step in the Case Management process.

</div>##### **Step 5. Containment and Mitigation**

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/0tUimage.png)

<div id="bkmrk-purpose%3A-the-%22contai">**Purpose**: The "Containment and Mitigation" step aims to limit the spread and impact of the incident by isolating affected systems and applying necessary security measures.</div><div id="bkmrk--21"></div><div id="bkmrk-instructions-provide-3">**Instructions Provided**: - **Containment Measures**: Users are advised to "perform containment measures or isolate network segments to minimize impact" if the attack is ongoing.
- **Isolation and Blocking**: Users are instructed to "temporarily isolate affected systems or apply security policies to block the attack, if needed."
- **Document Actions**: Users are required to "describe the analysis details thoroughly in the text-area below for reporting purposes." A text editor is provided to input detailed notes, with formatting options such as bold, italic, underline, alignment, lists, links, images, and emojis.

**Action**:  
- Users document the containment and mitigation actions taken in the text area.
- After completing the actions and documenting the details, users click the "Save Step" button to record their work and proceed to the next step in the Case Management process.

</div>##### **Step 6. Recovery and Remediation**

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/u3Simage.png)

<div id="bkmrk-purpose%3A-the-%22recove">**Purpose**: The "Recovery and Remediation" step aims to fully resolve the incident by addressing its root cause, restoring systems or networks to their normal operational state, and applying preventive measures to avoid recurrence.</div><div id="bkmrk--23"></div><div id="bkmrk-instructions-provide-4">**Instructions Provided**: - **Resolve and Restore**: Users are instructed to "resolve the root cause and restore systems or networks to their normal operational state."
- **Apply Security Measures**: Users are advised to "apply security patches and remove malware from infected assets" to secure the environment.
- **Document Actions**: Users are required to "describe the analysis details thoroughly in the text-area below for reporting purposes." A text editor is provided to input detailed notes, with formatting options such as bold, italic, underline, alignment, lists, links, images, and emojis.

**Action**: - Users document the recovery and remediation actions taken in the text area.
- After completing the actions and documenting the details, users click the "Save Step" button to record their work and proceed to the next step in the Case Management process.

</div>##### **Step 7. Case Closure**

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/4K5image.png)

<div id="bkmrk-purpose%3A-the-%22case-c">**Purpose**: The "Case Closure" step marks the completion of the case handling process, confirming that the incident has been resolved and all necessary actions have been taken.</div><div id="bkmrk--25"></div><div id="bkmrk-instructions-provide-5">**Instructions Provided**: - **Update Case Status**: Users are instructed to "refer to the case status and use the button below to update it to ‘Closed’" once processing is complete.
- **Prepare for Next Stage**: Users are informed that "during the next stage, you will be able to document the response process and outcomes, and generate the final report."
- **Document Details**: Users are required to "describe the analysis details thoroughly in the text-area below for reporting purposes." A text editor is provided to input detailed notes, with formatting options such as bold, italic, underline, alignment, lists, links, images, and emojis.

**Action**: - Users document the final details of the case resolution in the text area.
- After documenting the details, users click the "Closed" button to officially close the case and proceed to the final step in the Case Management process.

</div>##### **Step 8. Post-Incident Review**

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/MLXimage.png)

<div id="bkmrk-purpose%3A-the-%22post-i">**Purpose**: The "Post-Incident Review" step aims to summarize the lessons learned from the incident response process and strengthen future security measures to better handle similar threats.</div><div id="bkmrk--27"></div><div id="bkmrk-instructions-provide-6">**Instructions Provided**: - **Summarize Lessons Learned**: Users are instructed to "summarize lessons learned from the response process and strengthen future security measures to better handle similar threats."
- **Generate Final Report**: Users are advised to "document the response and outcomes, click the ‘Generate Report’ button below and complete the final report."
- **Document Details**: Users are required to "describe the analysis details thoroughly in the text-area below for reporting purposes." A text editor is provided to input detailed notes, with formatting options such as bold, italic, underline, alignment, lists, links, images, and emojis.

**Action**: - Users document the lessons learned and post-incident analysis in the text area.
- After documenting the details, users click the "**Generate Report**" button to compile the final report, concluding the Case Management process.

</div>##### **Report Generation**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/Ireimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/Ireimage.png)

<div id="bkmrk-after-completing-all"><div>After completing all eight steps in the Case Management process, including the **Post-Incident Review**, a confirmation message is displayed in the SmartWAN Portal. </div></div><div id="bkmrk--29"></div>
#### **Notification Setting** 

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/jIzimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/jIzimage.png)

<div id="bkmrk-the-alert-subscripti">The **Alert Subscription Settings** screen in the SmartWAN Portal allows users to customize how they receive notifications for cases. This screen is accessed by clicking the "Notification Settings" button on the **Case List** screen.</div><div id="bkmrk-users-can-configure-">Users can configure various aspects of alert subscriptions, including the type of notifications, severity levels, assignees, recipients, and additional metadata, ensuring they are informed about relevant cases in a timely manner.</div><div id="bkmrk--32"></div>##### **Subscription Information**

<div id="bkmrk--33"></div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/Y1cimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/Y1cimage.png)

<div id="bkmrk-subscription-informa-1">**Subscription Information**: - **Title**: A text field to enter a custom title for the alert subscription. 
    - **Type**: Checkboxes to select the type of notifications:
    - **Notify on case opening**: Sends an alert when a new case is created.
    - **Notify on case progress**: Sends an alert when a case’s status is updated.
- **Severity Level**: Radio buttons to select the severity level of cases to be notified about.

**Assignee and Recipient Management**: - **Assignee**: Displays a list of users assigned to receive alerts, including: 
    - **Name**: The assignee’s name (e.g., Bryan Ga, Timo Choi, Jay Cho, Leonardo DiCaprio).
    - **Assigned Role**: The role of the assignee (e.g., Administrator, Customer, Engineer).
    - **Email Address**: The assignee’s email (e.g., markov01@markov.com).
    - **Actions**: Options to "Change Assignee" (reassign to another user) or "Remove Entry" (delete the assignee from the list).
- **Recipient**: Displays a list of additional recipients for alerts, with similar details and actions as the Assignee section.
- **Add to Entry**: A button to add new assignees or recipients to the subscription list.

**Additional Fields**</div><div id="bkmrk-additional-fields-ca">- Additional fields can be defined by users.

</div>
##### **Subscription Note**

<div id="bkmrk--36"></div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/MMTimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/MMTimage.png)

<div id="bkmrk-the-subscription-not">*The **Subscription Note** screen, accessible via a tab in the **Alert Subscription Settings** popup, allows users to add and save notes related to an alert subscription. Users can enter text in a provided text box and save the note for future reference.*</div><div id="bkmrk--38"></div><div id="bkmrk--39"></div>#### **Real-Time New Case Alert**

<div id="bkmrk-the-smartwan-portal-">The SmartWAN Portal provides real-time notifications to alert users of new cases while they are actively using the platform. This feature ensures that users are promptly informed of critical incidents, allowing for immediate action to address potential threats.</div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/o9iimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/o9iimage.png)

<div id="bkmrk--41"></div><div id="bkmrk--42"></div>

# Report

<iframe allow="autoplay; fullscreen; picture-in-picture; clipboard-write; encrypted-media" frameborder="0" height="" src="https://player.vimeo.com/video/1071627060?h=50f958c10a&title=0&byline=0&portrait=0&badge=0&autopause=0&player_id=0&app_id=58479" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%;" title="Report" width=""></iframe>

#### **Event Report**

The Event Report menu can be found in the Report section of the left sidebar.

![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/fxHimage.png)

#### **Event Report List**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/HSLimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/HSLimage.png)

<div id="bkmrk-the-event-report-men-1">The **Event Report** menu in the SmartWAN Portal displays a list of generated reports for events.</div><div id="bkmrk-accessible-under-the">Accessible under the "Report" section, it includes filters for selecting a customer, asset, and date range, a search bar for reports by name or ID, and an "Advanced Search" option.</div><div id="bkmrk--3"></div>#### **Event Report Details**

<div id="bkmrk-the%C2%A0event-report-det"><div><div>The **Event Report Detail Screen** in the SmartWAN Portal is displayed when a report is selected from the **Event Report** menu. It provides a comprehensive view of the report, organized into multiple sections accessible via tabs at the top of the screen.</div></div><div>  
</div></div>**Report Sections (Tabs) Table**

<div id="bkmrk-tab-number-section-n"><div class="overflow-x-auto my-2"><table><thead class="border-b border-primary/20"><tr class="border-primary/10"><th class="break-words">Tab Number</th><th class="break-words">Section Name</th><th class="break-words">Description</th></tr></thead><tbody><tr class="border-primary/10"><td class="break-words">I</td><td class="break-words">Overview</td><td class="break-words">Provides a summary of the report, including title, ID, reporter, date, and analysis period.</td></tr><tr class="border-primary/10"><td class="break-words">II</td><td class="break-words">Statistics</td><td class="break-words">Displays statistical data related to the case, such as event counts and asset details.</td></tr><tr class="border-primary/10"><td class="break-words">III</td><td class="break-words">Analysis</td><td class="break-words">Details the analysis of the case, including root cause and impact assessment.</td></tr><tr class="border-primary/10"><td class="break-words">IV</td><td class="break-words">Remediation</td><td class="break-words">Outlines the remediation steps taken to resolve the incident.</td></tr><tr class="border-primary/10"><td class="break-words">V</td><td class="break-words">Conclusion</td><td class="break-words">Summarizes the outcomes and conclusions of the case response.</td></tr><tr class="border-primary/10"><td class="break-words">VI</td><td class="break-words">Recommendations</td><td class="break-words">Offers recommendations to prevent similar cases in the future.</td></tr></tbody></table>

</div></div>##### **I. OverView**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/ehvimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/ehvimage.png)

The **Event Report Detail Screen** under the "Overview" tab (I) includes the following items, each serving a specific purpose:

<div id="bkmrk-report-title%3A-indica">- **Report Title**: Indicates the main subject or focus of the report, providing a clear identifier for the incident or analysis.
- **Report ID**: A unique identifier assigned to the report for tracking and reference purposes within the system.
- **Reported By**: Identifies the user who generated the report, including their contact information for accountability and follow-up.
- **Report Date**: Specifies the date and time when the report was finalized, helping to establish a timeline for the incident response.
- **Analysis Period**: Defines the time range during which the incident was analyzed, providing context for the duration of the event and response efforts.
- **Distribution Target**: Lists the individuals, teams, or roles to whom the report is distributed, ensuring relevant stakeholders are informed.
- **Summary**: Offers a high-level overview of the incident, including key findings, the nature of the threat, and its impact, to provide a quick understanding of the situation.
- **Related Elements**: Presents statistical data in visual form (e.g., pie charts) to show the distribution of events by severity and the types of assets affected, aiding in understanding the scope and impact of the incident.

</div>##### **II. Statistics**

<div id="bkmrk-the-statistics-tab-%28">The **Statistics** tab (II) in the **Event Report Detail Screen** of the SmartWAN Portal provides statistical insights into the incident, helping users understand the severity, urgency, and distribution of related events.</div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/Zfvimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/Zfvimage.png)

<p class="callout info">This image displays a partial section of the complete report.</p>

---

**Statistics Report Summary**

<table id="bkmrk-section-purpose-key-"><thead><tr><th>**Section**</th><th>**Purpose**</th><th>**Key Details**</th></tr></thead><tbody><tr><td>**Threat Case Classification**</td><td>Prioritizes security cases based on severity and urgency.</td><td>- **Severity**: Measures threat danger (Low/High).  
- **Urgency**: Measures response time needed (Low/High).  
- **Matrix**: Combines both (e.g., High Severity + High Urgency = Critical).</td></tr><tr><td>**Distribution of Related Events**</td><td>Visualizes how related security events spread across time/systems.</td><td>- Tracks event frequency and patterns.  
- Aids in identifying attack scope and hotspots.</td></tr><tr><td>**List of Related Events**</td><td>Groups events with shared attributes to uncover attack sequences.</td><td>**Grouping Criteria**:  
- **Common Indicators**: Shared IPs, users, devices.  
- **Time Correlation**: Events in close proximity.  
- **Attack Patterns**: Matches MITRE ATT&amp;CK tactics.  
- **Behavior Analysis**: Suspicious chains (e.g., file execution → external connection).  
- **Threat Intelligence**: Matches known IOCs.</td></tr></tbody></table>

---

**Threat Case Classification Matrix**

<table id="bkmrk-severity-%5C-urgency-l"><thead><tr><th>**Severity \\ Urgency**</th><th>**Low Urgency**</th><th>**High Urgency**</th></tr></thead><tbody><tr><td>**Low Severity**</td><td>Minor threat; resolve later.</td><td>Less critical but needs prompt handling.</td></tr><tr><td>**High Severity**</td><td>Serious threat; no immediate action.</td><td>Critical; requires immediate response.</td></tr></tbody></table>

---

**Key Takeaways**

1. **Prioritization**: Clear severity/urgency tiers streamline incident response.
2. **Pattern Analysis**: Distribution and event grouping reveal attack trends.
3. **Correlation**: Multi-criteria linking (time, behavior, IOCs) enhances threat detection.

##### **III. Analysis**

The Analysis tab (III) in the Event Report Detail Screen of the SmartWAN Portal provides in-depth **threat pattern analysis**, **response effectiveness, and correlations between threat factors.**

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/btmimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/btmimage.png)

<p class="callout info">This image displays a partial section of the complete report.</p>

**Threat in Similar Case Occurrences and Responses**

<table id="bkmrk-section-purpose-key--1"><thead><tr><th>**Section**</th><th>**Purpose**</th><th>**Key Details**</th></tr></thead><tbody><tr><td>**Threat in Similar Case Occurrences**</td><td>Analyzes the frequency and severity of past security threats over a specified period.</td><td>- Tracks threat patterns (e.g., monthly trends).  
- Visualizes data to identify critical/high-risk periods.</td></tr><tr><td>**Threat in Similar Case Responses**</td><td>Evaluates the effectiveness of organizational responses to past threats.</td><td>- Assesses response strategies (e.g., speed, methods).  
- Identifies areas for improvement.</td></tr></tbody></table>

---

**Threat Factor Correlation Analysis**

<table id="bkmrk-section-purpose-key--2"><thead><tr><th>**Section**</th><th>**Purpose**</th><th>**Key Details**</th></tr></thead><tbody><tr><td>**Threat Level Distribution of Related Factors**</td><td>Maps the severity levels (Critical/High/Moderate/Low) of linked threat factors.</td><td>- Highlights high-risk elements (e.g., IPs, users).  
- Aids in prioritizing response actions.</td></tr><tr><td>**Probability Distribution of Risk Levels**</td><td>Quantifies the likelihood of each risk level occurring among correlated factors.</td><td>- Uses statistical analysis (e.g., "60% Moderate risk").  
- Supports predictive threat assessment.</td></tr></tbody></table>

<p class="callout info">**Correlation Rules**: Time-based or entity-based logic is applied to detect complex attack patterns.</p>

<p class="callout info">**Threat Scores**: Calculated based on severity, context, and threat intelligence to guide decision-making.</p>

##### **IV. Remediation**

Remediation tab (IV) in the Event Report Detail Screen of the SmartWAN Portal provides **threat mitigation actions**, including detection, containment, recovery, and preventive measures for resolved security cases.

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/vkuimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/vkuimage.png)

**Remediation Report Section**

<table id="bkmrk-section-purpose-expl"><thead><tr><th>**Section**</th><th>**Purpose**</th><th>**Explanation**</th></tr></thead><tbody><tr><td>**Detection of Malicious Traffic**</td><td>Identify and analyze suspicious network activities</td><td>Uses SIEM/IDS to detect anomalies like port scanning or unusual connections.</td></tr><tr><td>**Multiple Failed Login Attempts**</td><td>Prevent brute-force attacks and unauthorized access</td><td>Monitors repeated login failures, locks accounts, blocks suspicious IPs, and enforces stronger authentication (e.g., MFA).</td></tr><tr><td>**Detection of Abnormal File Access**</td><td>Protect sensitive data from unauthorized access or exfiltration</td><td>Alerts on unusual file access patterns (e.g., mass downloads). Includes user verification and role-based access reviews.</td></tr><tr><td>**Execution of Unauthorized Applications**</td><td>Block potentially harmful software execution</td><td>Detects unapproved apps (e.g., TeamViewer), terminates processes, and enforces app control policies (e.g., allowlisting).</td></tr></tbody></table>

##### **V. Conclusion**

The Conclusion tab (V) in the Event Report Detail Screen of the SmartWAN Portal provides a synthesis of key findings about cases and indicators of attack.

[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/SjTimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/SjTimage.png)

**Section Overview**

<table id="bkmrk-section-purpose-expl-1" style="width: 100%;"><thead><tr><th style="width: 13.4684%;">**Section**</th><th style="width: 29.4368%;">**Purpose**</th><th style="width: 57.0948%;">**Explanation**</th></tr></thead><tbody><tr><td style="width: 13.4684%;">**Conclusion**</td><td style="width: 29.4368%;">To synthesize key findings about cases.</td><td style="width: 57.0948%;">Provides a high-level analysis of similarities in attack methods (e.g., code reuse, C2 communication) to link incidents to known threat actors or campaigns. Helps analysts identify operational patterns.</td></tr><tr><td style="width: 13.4684%;">**Indicator of Attack**</td><td style="width: 29.4368%;">To map observed tactics to standardized frameworks for threat categorization and response planning.</td><td style="width: 57.0948%;">Aligns attack techniques (e.g., spearphishing, steganography) with MITRE ATT&amp;CK tactics (e.g., T1566.001). Enables defenders to prioritize mitigations based on proven threat models.</td></tr></tbody></table>

##### **VI. Recommendations**

<div id="bkmrk-the-recommendations-">The **Recommendations** tab (VI) is the final section of the **Event Report Detail Screen** in the SmartWAN Portal.</div><div id="bkmrk-this-tab-provides-ac">This tab provides actionable suggestions and best practices to prevent similar incidents in the future. It focuses on improving security measures, addressing vulnerabilities, and enhancing response strategies based on the incident analysis.</div>[![image.png](https://book.weetizen.com/uploads/images/gallery/2025-04/scaled-1680-/VQBimage.png)](https://book.weetizen.com/uploads/images/gallery/2025-04/VQBimage.png)

<p class="callout info">A sample PDF file of the Event Report described in this guide is available for download. You can access the full report, including all sections (Overview, Statistics, Analysis, Remediation, Conclusion, and Recommendations).  
</p>

<p class="callout info">Sample PDF download: [ANRN-00936.pdf](https://appexnetworksadmin.sharepoint.com/:b:/s/AppExKR/EYg4U4vaESBJhCNcILFycwYBMOBfQ211Z2u7zPdEeMeHxQ?e=URy1w2) (APPEX Networks user only)</p>

<div id="bkmrk--14"></div><div id="bkmrk--15"></div>