AppEx OpenSASE
A comprehensive document for the concepts, features and architectures, and how to use the OpenSASE application, monitoring, threat management, etc. It is written based on the Markov project.
- Introduction
- Key Features
- Security Events Collection and Analysis
- Vulnerability Management
- Security Configuration Assessment
- Cloud Security Posture Management
- Network Flow Information Collection and Analysis
- GRC Assessment and Evidence Management
- Topics to discuss [TBD]
- SmartWAN Portal
- Upcoming Content
Introduction
This document will be continuously updated, and not all the features presented may be fully implemented.
Some parts of the content are based on the Markov project.
Overview
Unified Security Platform is to provide real-time security monitoring and response services to the customers.
This document describes the key concepts of the platform and provides key features under development.
Architecture
Technical Architecture
This diagram illustrates the end-to-end architecture of the SmartWAN service platform, integrating presentation, business logic, and data layers. The system leverages modern technologies including Vue.js/Spring Boot for frontend/backend, Kafka for real-time data streaming, and Elasticsearch for analytics. All services are deployed on Linux environments, with RESTful APIs enabling seamless communication between modules.
Defense-in-Depth security model
This architecture diagram maps the key security controls required in each layer of the Defense-in-Depth security model and illustrates how they are supported by this integrated security platform.
The platform is capable of collecting and monitoring logs generated from the security controls highlighted in purple within each layer.
This visual representation clearly demonstrates the scope and capabilities of the integrated security platform across the various layers of the Defense-in-Depth model.
Key Concepts of the Platform
Unified Security Monitoring
The platform integrates traditional on-premises data center security features with cloud environment security capabilities, enabling comprehensive monitoring from a single, unified interface.
This convergence allows customers to maintain consistent security visibility across hybrid infrastructures.
Versatile Data Collection and Analysis
Employing both agent-based and agentless approaches, the platform collects a wide array of log data and vulnerability assessment information.
This multi-faceted data gathering strategy enables thorough security analysis, providing a comprehensive view of the customer’s security posture.
Advanced Security Data Lake
Leveraging a high-performance security data lake capable of sub-second queries on multi-terabyte datasets, the platform offers sophisticated security analytics for network flows.
This capability surpasses traditional security monitoring platforms, providing deep insights into network behavior from a security perspective.
Proactive Security Management
The system incorporates robust vulnerability management features through active security configuration checks and vulnerability identification.
This proactive approach helps customers identify and address potential security weaknesses before they can be exploited.
Streamlined Compliance Management
Offering key compliance management functionalities, the platform facilitates efficient management of compliance evidence.
This feature simplifies the process of meeting regulatory requirements and maintaining audit readiness across various compliance frameworks.
Key Features
This chapter explains the key features of OpenSASE.
Security Events Collection and Analysis
Agent-Based Log Collection
The platform leverages agent-based log collection capabilities, utilizing the Wazuh agent for comprehensive security event monitoring and analysis.
Supported Operating Systems
The Wazuh agent can be deployed on a wide range of operating systems, including:
-
Windows
-
Linux distributions
-
macOS
-
FreeBSD
-
OpenBSD
-
Solaris
For details on supported platforms, refer to the Official Wazuh Agent Documentation.
Flexible Log Collection
The platform offers versatile log collection options:
-
Ability to monitor various log file types and formats
-
Support for Windows event logs
-
Customizable log parsing and formatting
Configurable Log Sources
Administrators can configure the agent to collect logs from:
-
System logs
-
Application logs
-
Custom log files
-
Windows event channels
Advanced Features
-
Real-time log monitoring and analysis
-
File integrity monitoring
-
Command output collection
-
Centralized configuration management
Scalability
The agent-based approach allows for efficient log collection across large-scale environments, from individual endpoints to enterprise-wide deployments.
By leveraging the Wazuh agent's capabilities, the platform provides a robust foundation for comprehensive security event collection and analysis across diverse IT infrastructures.
Agentless Log Collection (Active Mode)
The platform actively collects logs from devices that do not support agent installation, such as network devices. It uses SSH to connect to devices and execute commands for log and status information retrieval.
Agentless Collection Method
The system utilizes Secure Shell (SSH) protocol to establish secure connections with target devices, enabling remote log and status information retrieval without on-device agents.
Supported Devices
This method is ideal for:
-
Network switches and routers
-
Firewalls
-
Load balancers
-
Other network appliances or devices with limited software installation capabilities
Collection Process
-
Secure Connection: The platform initiates an SSH connection to the target device.
-
Command Execution: Pre-configured or custom commands are executed on the device.
-
Data Retrieval: Log data or status information is collected based on command output.
Flexibility
-
Customizable Commands: Administrators can tailor the commands executed on each device type to collect specific logs or information.
-
Scheduled Collection: Log retrieval can be automated regularly to ensure up-to-date information.
This agentless approach significantly enhances the platform's ability to provide a holistic view of an organization's security posture, integrating both agent-supported and agentless devices.
Agentless Log Collection (Passive Mode)
The platform offers advanced log processing capabilities with a focus on syslog protocol integration. Its architecture is highly flexible and scalable, adapting to various log volume requirements.
Syslog Processing
The system efficiently handles logs transmitted via the syslog protocol, a widely used standard for system logging.
Flexible Ingestion Architecture
Depending on anticipated log volume, the platform can be configured with:
-
Multiple Remote Syslog Servers: For distributed log collection and processing.
-
Message Bus Systems: Integration with technologies like Kafka for high-throughput log streaming.
Scalable Design
The platform's architecture is tailored to match expected log volumes, ensuring optimal performance and resource utilization.
This approach enables efficient management of varying loads, from small-scale deployments to enterprise environments with massive log volumes.
Public Cloud Audit Logs Collection
The platform offers comprehensive audit and management log collection for major public cloud environments, including AWS, Google Cloud Platform (GCP), and Microsoft Azure. This integration allows organizations to centralize and analyze critical operational data from their multi-cloud infrastructures.
-
Multi-Cloud Coverage: Native support for major cloud providers ensures broad visibility across diverse cloud environments.
-
Audit and Management Focus: The platform collects security-critical audit and management logs for compliance and operational oversight.
-
Extensible Framework: Custom integrations can be developed for cloud services not natively supported.
-
Tailored Solutions: The platform adapts to unique organizational requirements, enabling additional integrations as needed.
By centralizing these critical logs, the platform enhances cloud governance, security monitoring, and compliance management across multi-cloud environments.
SaaS Audit Logs Collection
The platform supports log collection from various SaaS applications, providing multi-source log integration tailored to client needs.
-
Diverse SaaS Integration: Collect logs from multiple SaaS services, accommodating various application types and data formats.
-
Customizable Implementation: Integration is provided on a per-request basis to meet unique client requirements.
-
Flexible Log Collection: The system handles multiple log types and sources simultaneously for a comprehensive view of an organization’s SaaS ecosystem.
-
Scalable Solution: As new SaaS applications emerge, the platform can incorporate additional log sources as needed.
This flexible and extensible approach enables deeper insights into SaaS operations, enhanced security monitoring, and improved operational visibility across cloud-based services.
Vulnerability Management
Agent-Based Vulnerability Detection
The platform provides comprehensive vulnerability analysis based on operating system and package information collected from deployed agents.
Data Collection
-
Agents gather detailed information about the host's operating system, installed packages, and configurations.
-
This data is continuously collected and sent to the central platform for analysis.
Vulnerability Analysis
-
The collected information is correlated with up-to-date vulnerability databases.
-
The platform identifies potential vulnerabilities by comparing installed software versions against known vulnerabilities.
Real-Time Detection
-
Agents continuously monitor and report changes, enabling real-time detection of new vulnerabilities.
-
This allows for rapid identification of security risks introduced by system updates or new software installations.
Comprehensive Coverage
-
The agent-based approach enables deep scanning of endpoints, including those that may be difficult to assess with network-based scans.
-
It provides visibility into vulnerabilities across a diverse range of operating systems and software packages.
Efficient Processing
-
By leveraging agent-collected data, the platform performs vulnerability assessments more efficiently than traditional network-based scans.
-
This approach reduces network overhead and allows for more frequent vulnerability checks.
By utilizing this agent-based vulnerability detection method, the platform offers organizations a powerful tool for maintaining a robust security posture and quickly identifying potential threats.
SBOM (Software Bill of Materials) Analysis
The platform provides advanced SBOM analysis capabilities, leveraging agent-based systems to generate and analyze comprehensive software component inventories.
SBOM Generation
-
File System Scanning: Agents perform thorough scans of file systems to identify and catalog software components.
-
Container Image Analysis: The system examines container images to extract detailed component information.
-
CycloneDX Format: SBOMs are generated in the industry-standard CycloneDX format, ensuring compatibility and ease of integration.
Vulnerability Identification
-
Component Analysis: Each identified software component is scrutinized for known vulnerabilities.
-
Continuous Monitoring: The system regularly updates its vulnerability database to provide current security insights.
-
Risk Assessment: Vulnerabilities are prioritized based on severity and potential impact.
Comprehensive Reporting
-
Detailed Inventories: Customers receive comprehensive lists of all software components in their systems.
-
Vulnerability Reports: The platform provides detailed reports on identified vulnerabilities associated with SBOM components.
-
Actionable Insights: Reports include recommendations for remediation and risk mitigation.
Integration and Automation
-
CI/CD Pipeline Integration: SBOM generation and analysis can be integrated into continuous integration and deployment (CI/CD) processes.
-
Automated Alerts: The system can be configured to send alerts when critical vulnerabilities are detected in SBOM components.
By utilizing SBOM analysis, customers gain deep visibility into their software supply chain, proactively identify security risks, and maintain a robust security posture across their IT infrastructure.
Remote Vulnerability Analysis
The platform offers comprehensive remote vulnerability analysis, focusing on two key areas:
Public IP Asset Discovery
The system performs thorough scans of customer public IP ranges to identify exposed assets.
-
Utilizes advanced IP range detection techniques to accurately determine the customer's public IP address blocks.
-
Employs network scanning tools to discover active hosts and services within these IP ranges.
-
Identifies and catalogs internet-facing assets such as web servers, databases, and other network services.
-
Provides a detailed inventory of exposed assets, including IP addresses, hostnames, and open ports.
Automated HTTPS URL Vulnerability Assessment
The platform conducts automated security scans on HTTPS URLs to detect vulnerabilities.
-
Comprehensive web application vulnerability scans on discovered HTTPS endpoints.
-
Utilizes a combination of passive and active scanning techniques to minimize impact on target systems.
-
Assess SSL/TLS configurations for potential weaknesses.
-
Checks for common misconfigurations in web servers and application frameworks.
-
Generates detailed reports highlighting discovered vulnerabilities, severity levels, and recommended remediation steps.
This approach enables organizations to proactively identify and address security weaknesses in their internet-facing infrastructure, significantly enhancing their overall security posture.
Security Configuration Assessment
The system offers a comprehensive Security Configuration Assessment feature that evaluates the security settings of registered customer assets. This functionality ensures adherence to industry best practices and company security policies.
Automated Configuration Checks
-
Performs regular, automated scans of host systems to assess their security configurations.
-
Evaluates a wide range of security settings, including operating system parameters, application configurations, and network settings.
Compliance Verification
-
Compares current system configurations against predefined security benchmarks and standards.
-
Identifies deviations from recommended security practices and company-specific policies.
Customizable Rule Sets
-
Allows for the creation and modification of assessment rules to align with specific organizational requirements.
-
Supports the implementation of industry-standard benchmarks as well as custom security policies.
Detailed Reporting
-
Generates comprehensive reports highlighting configuration issues and compliance status.
-
Provides actionable recommendations for remediation of identified security misconfigurations.
Continuous Monitoring
-
Offers real-time visibility into the security posture of assessed systems.
-
Enables quick detection and response to configuration changes that may impact security.
Integration Capabilities
-
Seamlessly integrates with other security tools and processes within the organization's infrastructure.
-
Facilitates a holistic approach to security management and compliance.
By leveraging this Security Configuration Assessment feature, organizations can maintain a robust security posture, ensure compliance with industry standards, and quickly identify and address potential vulnerabilities arising from misconfigurations.
Cloud Security Posture Management
The system offers comprehensive Cloud Security Posture Management (CSPM) capabilities for major public cloud platforms, including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). This feature provides in-depth security analysis at the account level, offering organizations valuable insights into their cloud infrastructure's security stance.
Multi-Cloud Coverage
-
Assesses security configurations across AWS, Azure, and GCP environments, providing a unified view of an organization's cloud security posture.
Account-Level Analysis
-
Performs detailed security assessments at the account level, ensuring thorough coverage of all cloud resources and configurations.
Compliance Checks
-
Evaluates cloud configurations against industry-standard best practices and compliance frameworks.
Automated Assessments
-
Conducts regular, automated scans of cloud environments to identify potential misconfigurations and security risks.
Detailed Reporting
-
Provides comprehensive security posture analysis reports, highlighting vulnerabilities, misconfigurations, and areas for improvement.
Remediation Guidance
-
Offers actionable recommendations to address identified security issues and enhance overall cloud security.
Continuous Monitoring
-
Ensures ongoing assessment of cloud environments to maintain and improve security postures over time.
By leveraging these advanced CSPM capabilities, organizations can significantly enhance their cloud security, ensure compliance with industry standards, and maintain a robust security posture across their multi-cloud environments.
Network Flow Information Collection and Analysis
The platform collects, visualizes, and analyzes network flow information from various sources, including NetFlow/IPFIX from network switches and VPC flow logs from public cloud services. Network flow data is correlated with threat intelligence feeds to perform comprehensive analysis, enabling the detection of potential security incidents and unauthorized access attempts by external threat actors.
Multi-Source Flow Collection
-
Collects NetFlow and IPFIX data from network devices such as switches, routers, and firewalls.
-
Gathers VPC flow logs from major public cloud providers (AWS VPC Flow Logs, Azure NSG flow logs, GCP VPC flow logs).
-
Supports flow data collection from virtualized network infrastructures.
Data Visualization
-
Provides interactive dashboards to present network flow data in a customizable format.
-
Displays network traffic patterns, volume trends, and geo-mapping of network connections.
Advanced Analytics
-
Utilizes behavioral analysis to identify anomalies in network traffic patterns that may indicate security threats.
-
Conducts protocol analysis to gain insights into protocol usage and potential misuse.
-
Evaluates performance metrics to analyze network performance and utilization trends.
Threat Intelligence Integration
-
Real-time correlation of network flow data with up-to-date threat intelligence feeds.
-
Indicator matching to identify traffic involving known malicious IP addresses, domains, or networks.
-
Assigns risk scores to network connections based on threat intelligence data.
Security Incident Detection
-
Utilizes machine learning algorithms for anomaly detection in network traffic.
-
Flags unauthorized access attempts from external sources.
-
Monitors data exfiltration by detecting unusual outbound traffic patterns.
Comprehensive Reporting
-
Generates customizable reports on network activity, security incidents, and compliance status.
-
Provides tools for forensic analysis of security events.
-
Supports regulatory compliance with network traffic documentation.
By combining robust network flow collection with advanced analytics and threat intelligence integration, this platform empowers organizations to maintain a strong security posture, quickly detect potential threats, and gain deep insights into their network activities across both on-premises and cloud environments.
GRC Assessment and Evidence Management
GRC : Governance, Risk & Compliance
The system offers comprehensive assessment reporting capabilities for key compliance audits and certifications, including ISO, PCI-DSS, and ISMS-P. This feature is designed to assist customers in ensuring adherence to various regulatory requirements.
Compliance Mapping and Reporting
-
Data Source Integration: Logs and data collected from various sources are systematically processed and analyzed.
-
Compliance Requirement Mapping: Each piece of collected data is mapped to specific requirements of different compliance standards.
-
Compliance Status Tracking: Provides real-time visibility into the organization's compliance posture across multiple frameworks.
-
Evidence Management: Automated mapping facilitates easy management and retrieval of compliance evidence.
This integrated approach to compliance reporting and evidence management significantly reduces the complexity and workload associated with maintaining multiple compliance certifications.
Topics to discuss [TBD]
LLM/SLM Integration
Anomaly Detection & MLOps
Automated Response
Federated Authentication
SmartWAN Portal
This is a guide for users to use the security operating center portal of OpenSASE.
Overview
SmartWAN Portal
Authentication
SmartWAN Portal Login
When you access the SmartWAN Portal, you will encounter the login screen as shown in the image below. This screen allows users to authenticate and access the portal's features.
- Email Address or ID: A field where users enter their registered email address or ID (e.g., "Enter your registered email address or ID").
- Password: A field for entering the user’s password (e.g., "Enter your password"), with a visibility toggle icon to show or hide the password.
Additional Authentication Options
- Top-right corner of the screen.
By clicking the "⋮" (three dots) icon in the top-right corner, users can access a detailed menu related to user authentication. This menu provides additional options for managing login settings or troubleshooting access issues.
- Verify Registered Email Address or ID: Allows users to verify their registered email address or ID to ensure they are using the correct credentials for login.
- Reset Password: Provides an option for users to reset their password if they have forgotten it or need to update it for security reasons.
- Request an Account: Enables new users to request an account if they do not already have one, initiating the account creation process.
Some features described above are currently in the prototype stage and are scheduled for future implementation.
Verification Registered Email Address of ID
- QR Code: A QR code is displayed for users to scan with a device that has a registered PassKey, enabling secure verification.
- Verify with Phone Number Button: An alternative "Verify with Phone Number" button is provided for users whose devices do not have a registered PassKey.
ResetPassword
- QR Code: A QR code is displayed for users to scan with a device that has a registered PassKey, enabling secure verification prior to password reset.
- Verify with Phone Number Button: An alternative "Verify with Phone Number" button is provided for users whose devices do not have a registered PassKey.
Request an Account
After selecting the "Request an Account" option from the "Additional Login Services Menu" on the SmartWAN Portal, users are directed to the following screen to verify their identity before resetting their password.
PassKey Verification:
- QR Code: A QR code is displayed for users to scan with a device that has a registered PassKey, enabling secure verification prior to request an account.
Alternative Option:
- Verify with Phone Number Button: An alternative "Verify with Phone Number" button is provided for users whose devices do not have a registered PassKey.
- PassKey-verified phone number: Displays a pre-filled, non-editable phone number associated with the PassKey.
- Email Address: A field to enter the user’s email address (e.g., "markov01@markov.com"), with a "Check Availability" button to verify if the email is available (status: "Email address is available for use").
- User Name: A field to enter the user’s name
User Information and Notifications
Real-time Alerts
If any alerts need to be provided to the user, an alert message will be displayed on the left side of the screen in real time.
Assigned Case Notification
Logout
You can log out by clicking the log-out button in the user information.
Home Screen
Some features described below are currently in the prototype stage and are scheduled for future implementation.
Widgets
1. Traffic Widget
- Description: Displays real-time network traffic data over a selected time period (e.g., last 24 hours). The graph shows RX (receive) and TX (transmit) traffic in Mbps, with peaks and trends.
2. Site Overview
- Description: Shows a summary of the status sites.
3. Top5
- Description: Displays the top 5 sites ranked by network traffic
4. Case
- Description: Lists critical cases and their affected objects, and provides on pending critical cases
5. World Map(Map view)
- Description: Provides a global map view of locations, with lines indicating connectivity between sites (e.g., Munich, New York, San Francisco, Sao Paulo, Sydney).
6. Threat case trends
- Description: A line graph showing trends in threat cases over time. Categories include Critical, High, Medium, and Low, with data points indicating case counts.
7. Today's Case Distribution
- Description: A scatter plot visualizing the distribution of cases by severity (Critical, High, Medium, Low) over a 24-hour period. Each bubble represents a case, with size indicating the number of incidents (e.g., Critical: 207 cases).
8. Today's Case Summary
- Description: A pie chart summarizing the total cases for the day.
9. Case
- Description: A table shows that case-affected objects.
10. Network Summary Metrics
-
Topology:
- Total Topologies: Displays the total number of network topologies (e.g., 1).
- Total Intranet Hosts: Shows the total number of intranet hosts connected (e.g., 342).
- Total WAN: Indicates the total number of Wide Area Network (WAN) connections (e.g., 124).
- Total Bandwidth: Displays the total bandwidth capacity for both download (↓) and upload (↑) in Mbps (e.g., 16,000 Mbps for both).
- Subscription Bandwidth: Shows the subscribed bandwidth for both download (↓) and upload (↑) in Mbps (e.g., 16,000 Mbps for both).
- Total SmartWAN Policies: Lists the total number of SmartWAN policies in place (e.g., 31).
- Total SmartWAN Policies (Subscription): Indicates the number of subscribed SmartWAN policies (e.g., 237).
The widgets provided on the dashboard may be modified in the future based on evolving requirements.
Map Submenu
After logging in to the SmartWAN Portal, the Home screen displays the world map by default, featuring a world map in the "Map View." On the right side of the map, users can access additional options through the Map Submenu.
Filtering Sites by Country and Region
- Select Country & Region:
- Country: A dropdown menu to select a country (e.g., South Korea, USA, China, Germany, Japan).
- Region: A dropdown menu to select a region within the chosen country (e.g., USA > California).
- Site List:
- After applying the country and region filters, a list of sites within the selected area is displayed.
- The list includes columns such as:
- Site: Name of the site (e.g., Head Office, New York Branch).
- RX/TX (Mbps): Network traffic data for receive (RX) and transmit (TX) in Mbps.
- Critical Cases: Number of critical cases associated with the site.
- All Cases: Total number of cases for the site.
Dashboard
Getting Started
Logging In with an Accessible User Account
To begin, log in using a user account with access privileges.
You can find more options for user authentication.
This guide is based on SKT’s SmartWAN Portal. Updates will be continuously applied to reflect future changes.
Pre-Configured Dashboards
Currently, the dashboards are configured for the monitoring purposes of SKT’s agency SmartWAN system.
Event Dashboard (under development)
- Purpose: Provides a centralized view of security and network event data, enabling users to monitor and manage incidents effectively.
- Data Sources: Integrates information from multiple origins, including agents, agentless systems, and external feeds.
- Key Information: Displays summaries of event counts, severity levels, and current statuses to facilitate quick decision-making.
Agency Dashboard
- Agency monitoring
- System monitoring
Agency monitoring
Map View
Event levels are defined by SKT's requirements.
Agency List
When a specific region is selected in the Map View, the dashboard displays a list of agencies registered in that region, along with detailed information on the Network Status (CPE) and Security Status (SDP) for each agency.
- Agency List: A comprehensive roster of agencies within the selected region.
- Network Status (CPE): Provides the current operational status of the Customer Premises Equipment for eacßh agency.
- Security Status (SDP): Details the security posture, including Software-Defined Perimeter (SDP) metrics, for each agency.
View details of the agency
To access an agency's detailed information:
-
Go to the Agency List in the dashboard
-
Click the desired agency name
-
The system will load the detailed agency view
Network View
This view provides a granular view of both network performance and security status for the selected agency. Users can toggle between Network View and Security View to access specific metrics.
The dashboard is divided into two main tabs:
-
Network View: Displays real-time CPE status and network performance.
-
Security View: Shows security-related alerts and SDP metrics (if applicable).
Displays hardware and connectivity details:
-
CPE ID/Name/Model: Identifies the device.
-
High Availability: Indicates redundancy status ( Enabled / Disabled).
-
CPE Status:
-
Active: Normal operation.
-
Degraded: Performance issues detected.
-
Inactive: Connection lost.
-
-
Connected Data Centers: Primary (Seoul) and Secondary (Daejeon) links.
Network Performance Metrics data(Live) for troubleshooting:
-
CPU/RAM/Disk: Resource usage (% or GB).
-
Latency/Jitter: Measured in milliseconds (ms).
-
Packet Loss (TX/RX): Percentage of lost data packets.
Lists recent events with types and levels:
| Column | Description | Example |
|---|---|---|
| Type | Event category (Network/Security). | Network |
| Event | Description of the issue. | CPE ETH0 Link Down |
| Level | Severity: Info, High, Critical. |
Critical |
| Time | Timestamp (HH:MM:SS.milliseconds). | 16:13:31.00256 |
Security View
This view provides comprehensive monitoring and management capabilities for the selected agency, displaying real-time network status, user information, security events, and service connectivity. The interface is divided into multiple sections for efficient administration.
User Management Section
- User List
-
Displays all registered users (currently 3 users) with:
-
ID: Unique user identifier (e.g.,
mskimos3) -
Name: Full name of the user (e.g.,
Minsco.ftm) -
Email: Associated email address (e.g.,
mskim.ios8@tworld.com) -
Lock Status: 💬 indicates an active session (no lock applied).
-
-
- User Detail
-
Expands on selected user profiles with:
-
Department/Role: Organizational hierarchy (e.g.,
Solution Development > Developer). -
Contact: Email (
tworld_win@tworld.com) and phone (010-5587-1154). -
Device List: Managed devices linked to the user (e.g.,
SDP Routerwith OS details).
-
-
Agency Policy & Configuration
- Connected CPE
-
Hardware details of the Customer Premises Equipment:
-
CPE ID/IP: Unique identifiers for the network device.
-
CPE Name: Label for easy recognition.
-
-
- Mandatory Processes
-
Critical processes are monitored by type, name, and operating system.
-
Security Monitoring
- Security Events Table
-
Lists real-time security incidents with:
-
Type/Name: Event description (e.g.,
Blocked access to ransomware sites). -
Level: Severity (
Critical,High). -
Time: Precise timestamp (e.g.,
16:13:01.0025).
-
-
- Example Events:
-
Critical: Ransomware detection, essential process violations. -
High: Blocked access to malicious domains, outdated OS alerts.
-
Agency Groups
The Agency Group section provides a summary of agency counts per region and detailed status information for CPE.
- Region-Based Counts: Displays the total number of agencies in each region.
- CPE Status Info: Offers insights into the operational status of CPE devices across the agencies
Event List
- Type: Indicates the category of the event (e.g., sdp-audit, Security).
- Event Name: Specifies the event description (e.g., NdpPerformance, Hardware State Check, ProcessCheck, or security-related messages like [JAMES] Blocked access to www…).
- Level: Denotes the severity of the event, categorized as Info, Minor, or Critical, Block.
- Time: Shows the timestamp of the event in the format MM/DD HH:MM:SS.milliseconds (e.g., 03/30 16:13:00.025).
- sdp-audit events such as NdpPerformance and Hardware State Check with Info level.
- Security events like [JAMES] Access blocked: Rans… with Critical level or [JAMES] Android OS version is to… with High level.
System monitoring
SecureEdge point of presence
It shows SecureEdge's distributed architecture. The visual indicators show system statuses, and on the bottom, highlight critical/security events of the agency.
This monitoring supports SKT's internal operations only, providing real-time monitoring of their SecureEdge deployment through redundant controllers and gateways at each location.
Agency List
It's the same as the agency list in Agency Monitoring.
Events List
It's the same as the events list in Agency Monitoring.
Risk Scoring (under development)
This dashboard provides a consolidated view of network security compliance, threat protection status, and regulatory adherence for monitoring and reporting purposes.
The current visualization serves as a prototype. We will develop optimized data representation formats aligned with operational objectives during the implementation phase.
Detection & Response
Cases
The user can access the cases menu, which is under Detection & Response.
Case List
Key Features
- Filters and Search:
- Customer and Asset Selection: Dropdown menus at the top (e.g., "Select a customer," "Select an asset") to filter cases by specific customers or assets.
- Date Range: A date picker to filter cases within a specific time period (e.g., 2024/09/30 - 2024/10/30).
- Advanced Search: A button on the right to access advanced search options for more granular filtering.
- Case Summary:
- Displays the total number of cases (e.g., 279 cases) and the total results (e.g., 2,193 cases) for the selected filters.
- Case Table:
- A table listing cases with columns such as:
- Event Type: Type of event (e.g., Raw Packet).
- Source Asset: Source of the event.
- Destination Asset: Destination of the event.
- Rule: Applied rule.
- Source IP: Source IP address.
- Destination Port: Destination port.
- Time: Timestamp of the event.
- Raw Packet: A column with a clickable icon to view raw packet details (e.g., BSX525D9252F...).
- A table listing cases with columns such as:
- Notification Settings:
- A "Notification Settings" button at the top-right corner to configure alert preferences.
The items provided in the Case List may be modified in the future based on evolving requirements.
Case Filtering
- Dropdown Menu: Displays a list of available customers (e.g., SK Telecom, Samsung Electronics, KT&G, Ericsson, Coca Cola, General Electric, BMW).
- Action: Click the "Select a customer" dropdown to choose a customer, filtering the case list to show only cases related to the selected customer.
- Each customer is represented, indicating secure separation of data in the multi-tenant environment.
- The associated assets for the selected customer are displayed.
Case Details
- Case Information: The default tab, showing detailed case data.
- Case Management: A secondary tab for managing the case.
Case Information
- Event Type: The type of event
- Asset Type: The type of asset involved
- Asset No.: The asset identifier
- Timestamp: The date and time of the event
- System IP: The system IP address
- Origin Country: The country of origin
- Origin IP: The originating IP address
- Origin Port: The originating port
- Destination Country: The destination country
- Destination IP: The destination IP address (
- Destination Port: The destination port
- Remote IP: The remote IP address
Case Management
Case Management Procedure Table
| Step | Procedure | Description |
|---|---|---|
| 1 | Case Open | Initiates the case and assigns it to a user. |
| 2 | Initial Investigation | Conducts preliminary analysis of the incident. |
| 3 | Prioritization | Assigns a priority level to the case. |
| 4 | Analysis and Response | Performs detailed analysis and responds to the incident. |
| 5 | Containment and Mitigation | Implements measures to contain and mitigate the issue. |
| 6 | Recovery and Remediation | Restores systems and applies fixes to prevent recurrence. |
| 7 | Case Closure | Closes the case after resolution. |
| 8 | Post-Incident Review | Reviews the incident for lessons learned. |
Step 1. Case Open
- Assignee: The user assigned to handle the case (e.g., Bryan Ga).
- Event Type: The type of event (e.g., Traffic).
- Asset Type: The type of asset involved (e.g., Juniper).
- Asset No.: The asset identifier (e.g., 38697).
- Timestamp: The date and time the event occurred (e.g., 2024-09-30 10:57:59+09:00).
- System IP: The system IP address (e.g., 1.1.1.1).
- Severity Level: The severity of the case (e.g., Critical).
- Threat Classification: The threat level or classification (e.g., 9)
Step 2. Initial Investigation
- Evaluate the Case: Users are prompted to "Evaluate the case details and associated events to verify if it’s a legitimate threat incident and handle it accordingly."
- Event Information Access: Users can find detailed event information for the open case and related events in the "Case Information" tab of the Case Details popup.
- Check for Positive: Users must determine the legitimacy of the threat by selecting one of two options:
- Confirmed as True Positive: Indicates the incident is a confirmed threat.
- Confirmed as False Positive: Indicates the incident is not a threat (e.g., a false alarm).
- After completing the evaluation and selecting the appropriate "Check for Positive" option, users click the "Save Step" button to record their findings and proceed to the next step in the Case Management process.
Step 3. Prioritization
- Priority Evaluation: Users are informed that "Priority is evaluated based on the severity and impact of the event."
- Severity Level Selection: Users can select the severity level of the case from the following options:
- Critical: For incidents with severe impact requiring immediate action.
- High: For incidents with significant impact needing prompt attention.
- Moderate: For incidents with moderate impact that can be addressed in a standard timeframe.
- Low: For incidents with minimal impact that can be handled with lower urgency.
- After selecting the appropriate severity level (e.g., Critical, High, Moderate, or Low), users click the "Save Step" button to record the prioritization and proceed to the next step in the Case Management process.
Step 4. Analysis and Response
- Analyze the Threat: Users are prompted to "Analyze the root cause of the threat and identify the affected assets and scope."
- Further Analysis: If needed, users are advised to "conduct further analysis on related logs and events" to gain deeper insights into the incident.
- Document Findings: Users are required to "describe the analysis details thoroughly in the text-area below for reporting purposes." A text editor is provided to input detailed notes, with formatting options such as bold, italic, underline, alignment, lists, links, images, and emojis.
- Users enter their analysis details in the text area.
- After completing the analysis and documenting the findings, users click the "Save Step" button to record their work and proceed to the next step in the Case Management process.
Step 5. Containment and Mitigation
- Containment Measures: Users are advised to "perform containment measures or isolate network segments to minimize impact" if the attack is ongoing.
- Isolation and Blocking: Users are instructed to "temporarily isolate affected systems or apply security policies to block the attack, if needed."
- Document Actions: Users are required to "describe the analysis details thoroughly in the text-area below for reporting purposes." A text editor is provided to input detailed notes, with formatting options such as bold, italic, underline, alignment, lists, links, images, and emojis.
- Users document the containment and mitigation actions taken in the text area.
- After completing the actions and documenting the details, users click the "Save Step" button to record their work and proceed to the next step in the Case Management process.
Step 6. Recovery and Remediation
- Resolve and Restore: Users are instructed to "resolve the root cause and restore systems or networks to their normal operational state."
- Apply Security Measures: Users are advised to "apply security patches and remove malware from infected assets" to secure the environment.
- Document Actions: Users are required to "describe the analysis details thoroughly in the text-area below for reporting purposes." A text editor is provided to input detailed notes, with formatting options such as bold, italic, underline, alignment, lists, links, images, and emojis.
- Users document the recovery and remediation actions taken in the text area.
- After completing the actions and documenting the details, users click the "Save Step" button to record their work and proceed to the next step in the Case Management process.
Step 7. Case Closure
- Update Case Status: Users are instructed to "refer to the case status and use the button below to update it to ‘Closed’" once processing is complete.
- Prepare for Next Stage: Users are informed that "during the next stage, you will be able to document the response process and outcomes, and generate the final report."
- Document Details: Users are required to "describe the analysis details thoroughly in the text-area below for reporting purposes." A text editor is provided to input detailed notes, with formatting options such as bold, italic, underline, alignment, lists, links, images, and emojis.
- Users document the final details of the case resolution in the text area.
- After documenting the details, users click the "Closed" button to officially close the case and proceed to the final step in the Case Management process.
Step 8. Post-Incident Review
- Summarize Lessons Learned: Users are instructed to "summarize lessons learned from the response process and strengthen future security measures to better handle similar threats."
- Generate Final Report: Users are advised to "document the response and outcomes, click the ‘Generate Report’ button below and complete the final report."
- Document Details: Users are required to "describe the analysis details thoroughly in the text-area below for reporting purposes." A text editor is provided to input detailed notes, with formatting options such as bold, italic, underline, alignment, lists, links, images, and emojis.
- Users document the lessons learned and post-incident analysis in the text area.
- After documenting the details, users click the "Generate Report" button to compile the final report, concluding the Case Management process.
Report Generation
Notification Setting
Subscription Information
- Title: A text field to enter a custom title for the alert subscription.
- Type: Checkboxes to select the type of notifications:
- Notify on case opening: Sends an alert when a new case is created.
- Notify on case progress: Sends an alert when a case’s status is updated.
- Severity Level: Radio buttons to select the severity level of cases to be notified about.
- Assignee: Displays a list of users assigned to receive alerts, including:
- Name: The assignee’s name (e.g., Bryan Ga, Timo Choi, Jay Cho, Leonardo DiCaprio).
- Assigned Role: The role of the assignee (e.g., Administrator, Customer, Engineer).
- Email Address: The assignee’s email (e.g., markov01@markov.com).
- Actions: Options to "Change Assignee" (reassign to another user) or "Remove Entry" (delete the assignee from the list).
- Recipient: Displays a list of additional recipients for alerts, with similar details and actions as the Assignee section.
- Add to Entry: A button to add new assignees or recipients to the subscription list.
- Additional fields can be defined by users.
Subscription Note
Real-Time New Case Alert
Report
Event Report
The Event Report menu can be found in the Report section of the left sidebar.
Event Report List
Event Report Details
Report Sections (Tabs) Table
| Tab Number | Section Name | Description |
|---|---|---|
| I | Overview | Provides a summary of the report, including title, ID, reporter, date, and analysis period. |
| II | Statistics | Displays statistical data related to the case, such as event counts and asset details. |
| III | Analysis | Details the analysis of the case, including root cause and impact assessment. |
| IV | Remediation | Outlines the remediation steps taken to resolve the incident. |
| V | Conclusion | Summarizes the outcomes and conclusions of the case response. |
| VI | Recommendations | Offers recommendations to prevent similar cases in the future. |
I. OverView
The Event Report Detail Screen under the "Overview" tab (I) includes the following items, each serving a specific purpose:
- Report Title: Indicates the main subject or focus of the report, providing a clear identifier for the incident or analysis.
- Report ID: A unique identifier assigned to the report for tracking and reference purposes within the system.
- Reported By: Identifies the user who generated the report, including their contact information for accountability and follow-up.
- Report Date: Specifies the date and time when the report was finalized, helping to establish a timeline for the incident response.
- Analysis Period: Defines the time range during which the incident was analyzed, providing context for the duration of the event and response efforts.
- Distribution Target: Lists the individuals, teams, or roles to whom the report is distributed, ensuring relevant stakeholders are informed.
- Summary: Offers a high-level overview of the incident, including key findings, the nature of the threat, and its impact, to provide a quick understanding of the situation.
- Related Elements: Presents statistical data in visual form (e.g., pie charts) to show the distribution of events by severity and the types of assets affected, aiding in understanding the scope and impact of the incident.
II. Statistics
This image displays a partial section of the complete report.
Statistics Report Summary
| Section | Purpose | Key Details |
|---|---|---|
| Threat Case Classification | Prioritizes security cases based on severity and urgency. | - Severity: Measures threat danger (Low/High). - Urgency: Measures response time needed (Low/High). - Matrix: Combines both (e.g., High Severity + High Urgency = Critical). |
| Distribution of Related Events | Visualizes how related security events spread across time/systems. | - Tracks event frequency and patterns. - Aids in identifying attack scope and hotspots. |
| List of Related Events | Groups events with shared attributes to uncover attack sequences. | Grouping Criteria: - Common Indicators: Shared IPs, users, devices. - Time Correlation: Events in close proximity. - Attack Patterns: Matches MITRE ATT&CK tactics. - Behavior Analysis: Suspicious chains (e.g., file execution → external connection). - Threat Intelligence: Matches known IOCs. |
Threat Case Classification Matrix
| Severity \ Urgency | Low Urgency | High Urgency |
|---|---|---|
| Low Severity | Minor threat; resolve later. | Less critical but needs prompt handling. |
| High Severity | Serious threat; no immediate action. | Critical; requires immediate response. |
Key Takeaways
-
Prioritization: Clear severity/urgency tiers streamline incident response.
-
Pattern Analysis: Distribution and event grouping reveal attack trends.
-
Correlation: Multi-criteria linking (time, behavior, IOCs) enhances threat detection.
III. Analysis
The Analysis tab (III) in the Event Report Detail Screen of the SmartWAN Portal provides in-depth threat pattern analysis, response effectiveness, and correlations between threat factors.
This image displays a partial section of the complete report.
Threat in Similar Case Occurrences and Responses
| Section | Purpose | Key Details |
|---|---|---|
| Threat in Similar Case Occurrences | Analyzes the frequency and severity of past security threats over a specified period. | - Tracks threat patterns (e.g., monthly trends). - Visualizes data to identify critical/high-risk periods. |
| Threat in Similar Case Responses | Evaluates the effectiveness of organizational responses to past threats. | - Assesses response strategies (e.g., speed, methods). - Identifies areas for improvement. |
Threat Factor Correlation Analysis
| Section | Purpose | Key Details |
|---|---|---|
| Threat Level Distribution of Related Factors | Maps the severity levels (Critical/High/Moderate/Low) of linked threat factors. | - Highlights high-risk elements (e.g., IPs, users). - Aids in prioritizing response actions. |
| Probability Distribution of Risk Levels | Quantifies the likelihood of each risk level occurring among correlated factors. | - Uses statistical analysis (e.g., "60% Moderate risk"). - Supports predictive threat assessment. |
Correlation Rules: Time-based or entity-based logic is applied to detect complex attack patterns.
Threat Scores: Calculated based on severity, context, and threat intelligence to guide decision-making.
IV. Remediation
Remediation tab (IV) in the Event Report Detail Screen of the SmartWAN Portal provides threat mitigation actions, including detection, containment, recovery, and preventive measures for resolved security cases.
Remediation Report Section
| Section | Purpose | Explanation |
|---|---|---|
| Detection of Malicious Traffic | Identify and analyze suspicious network activities | Uses SIEM/IDS to detect anomalies like port scanning or unusual connections. |
| Multiple Failed Login Attempts | Prevent brute-force attacks and unauthorized access | Monitors repeated login failures, locks accounts, blocks suspicious IPs, and enforces stronger authentication (e.g., MFA). |
| Detection of Abnormal File Access | Protect sensitive data from unauthorized access or exfiltration | Alerts on unusual file access patterns (e.g., mass downloads). Includes user verification and role-based access reviews. |
| Execution of Unauthorized Applications | Block potentially harmful software execution | Detects unapproved apps (e.g., TeamViewer), terminates processes, and enforces app control policies (e.g., allowlisting). |
V. Conclusion
The Conclusion tab (V) in the Event Report Detail Screen of the SmartWAN Portal provides a synthesis of key findings about cases and indicators of attack.
Section Overview
| Section | Purpose | Explanation |
|---|---|---|
| Conclusion | To synthesize key findings about cases. | Provides a high-level analysis of similarities in attack methods (e.g., code reuse, C2 communication) to link incidents to known threat actors or campaigns. Helps analysts identify operational patterns. |
| Indicator of Attack | To map observed tactics to standardized frameworks for threat categorization and response planning. | Aligns attack techniques (e.g., spearphishing, steganography) with MITRE ATT&CK tactics (e.g., T1566.001). Enables defenders to prioritize mitigations based on proven threat models. |
VI. Recommendations
A sample PDF file of the Event Report described in this guide is available for download. You can access the full report, including all sections (Overview, Statistics, Analysis, Remediation, Conclusion, and Recommendations).
Sample PDF download: ANRN-00936.pdf (APPEX Networks user only)
Upcoming Content
Assets
Assets
Endpoint
Endpoint
Configuration
configuration