05. Markov(ProactiveXDR) Key Features

This chapter explains the key features of OpenSASE.

Introduction

This document will be continuously updated, and not all the features presented may be fully implemented.
Some parts of the content are based on the Markov project.

Overview

Unified Security Platform is to provide real-time security monitoring and response services to the customers.
This document describes the key concepts of the platform and provides key features under development.

Architecture

Technical Architecture

image.png

This diagram illustrates the end-to-end architecture of the SmartWAN service platform, integrating presentation, business logic, and data layers. The system leverages modern technologies including Vue.js/Spring Boot for frontend/backend, Kafka for real-time data streaming, and Elasticsearch for analytics. All services are deployed on Linux environments, with RESTful APIs enabling seamless communication between modules.

Defense-in-Depth security model

Architecture-Defense-in-Depth.png

This architecture diagram maps the key security controls required in each layer of the Defense-in-Depth security model and illustrates how they are supported by this integrated security platform.

The platform is capable of collecting and monitoring logs generated from the security controls highlighted in purple within each layer.

This visual representation clearly demonstrates the scope and capabilities of the integrated security platform across the various layers of the Defense-in-Depth model.

Key Concepts of the Platform

Unified Security Monitoring

The platform integrates traditional on-premises data center security features with cloud environment security capabilities, enabling comprehensive monitoring from a single, unified interface.
This convergence allows customers to maintain consistent security visibility across hybrid infrastructures.

Versatile Data Collection and Analysis

Employing both agent-based and agentless approaches, the platform collects a wide array of log data and vulnerability assessment information.
This multi-faceted data gathering strategy enables thorough security analysis, providing a comprehensive view of the customer’s security posture.

Advanced Security Data Lake

Leveraging a high-performance security data lake capable of sub-second queries on multi-terabyte datasets, the platform offers sophisticated security analytics for network flows.
This capability surpasses traditional security monitoring platforms, providing deep insights into network behavior from a security perspective.

Proactive Security Management

The system incorporates robust vulnerability management features through active security configuration checks and vulnerability identification.
This proactive approach helps customers identify and address potential security weaknesses before they can be exploited.

Streamlined Compliance Management

Offering key compliance management functionalities, the platform facilitates efficient management of compliance evidence.
This feature simplifies the process of meeting regulatory requirements and maintaining audit readiness across various compliance frameworks.


Cloud Security Posture Management

The system offers comprehensive Cloud Security Posture Management (CSPM) capabilities for major public cloud platforms, including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). This feature provides in-depth security analysis at the account level, offering organizations valuable insights into their cloud infrastructure's security stance.

Multi-Cloud Coverage

Account-Level Analysis

Compliance Checks

Automated Assessments

Detailed Reporting

Remediation Guidance

Continuous Monitoring

By leveraging these advanced CSPM capabilities, organizations can significantly enhance their cloud security, ensure compliance with industry standards, and maintain a robust security posture across their multi-cloud environments.

GRC Assessment and Evidence Management

GRC : Governance, Risk & Compliance

The system offers comprehensive assessment reporting capabilities for key compliance audits and certifications, including ISO, PCI-DSS, and ISMS-P. This feature is designed to assist customers in ensuring adherence to various regulatory requirements.

Compliance Mapping and Reporting

This integrated approach to compliance reporting and evidence management significantly reduces the complexity and workload associated with maintaining multiple compliance certifications.

Network Flow Information Collection and Analysis

The platform collects, visualizes, and analyzes network flow information from various sources, including NetFlow/IPFIX from network switches and VPC flow logs from public cloud services. Network flow data is correlated with threat intelligence feeds to perform comprehensive analysis, enabling the detection of potential security incidents and unauthorized access attempts by external threat actors.

Multi-Source Flow Collection

Data Visualization

Advanced Analytics

Threat Intelligence Integration

Security Incident Detection

Comprehensive Reporting

By combining robust network flow collection with advanced analytics and threat intelligence integration, this platform empowers organizations to maintain a strong security posture, quickly detect potential threats, and gain deep insights into their network activities across both on-premises and cloud environments.

Security Configuration Assessment

The system offers a comprehensive Security Configuration Assessment feature that evaluates the security settings of registered customer assets. This functionality ensures adherence to industry best practices and company security policies.

Automated Configuration Checks

Compliance Verification

Customizable Rule Sets

Detailed Reporting

Continuous Monitoring

Integration Capabilities

By leveraging this Security Configuration Assessment feature, organizations can maintain a robust security posture, ensure compliance with industry standards, and quickly identify and address potential vulnerabilities arising from misconfigurations.


Security Events Collection and Analysis

Agent-Based Log Collection

The platform leverages agent-based log collection capabilities, utilizing the Wazuh agent for comprehensive security event monitoring and analysis.

Supported Operating Systems

The Wazuh agent can be deployed on a wide range of operating systems, including:

For details on supported platforms, refer to the Official Wazuh Agent Documentation.

Flexible Log Collection

The platform offers versatile log collection options:

Configurable Log Sources

Administrators can configure the agent to collect logs from:

Advanced Features

Scalability

The agent-based approach allows for efficient log collection across large-scale environments, from individual endpoints to enterprise-wide deployments.

By leveraging the Wazuh agent's capabilities, the platform provides a robust foundation for comprehensive security event collection and analysis across diverse IT infrastructures.


Agentless Log Collection (Active Mode)

The platform actively collects logs from devices that do not support agent installation, such as network devices. It uses SSH to connect to devices and execute commands for log and status information retrieval.

Agentless Collection Method

The system utilizes Secure Shell (SSH) protocol to establish secure connections with target devices, enabling remote log and status information retrieval without on-device agents.

Supported Devices

This method is ideal for:

Collection Process

Flexibility

This agentless approach significantly enhances the platform's ability to provide a holistic view of an organization's security posture, integrating both agent-supported and agentless devices.


Agentless Log Collection (Passive Mode)

The platform offers advanced log processing capabilities with a focus on syslog protocol integration. Its architecture is highly flexible and scalable, adapting to various log volume requirements.

Syslog Processing

The system efficiently handles logs transmitted via the syslog protocol, a widely used standard for system logging.

Flexible Ingestion Architecture

Depending on anticipated log volume, the platform can be configured with:

Scalable Design

The platform's architecture is tailored to match expected log volumes, ensuring optimal performance and resource utilization.
This approach enables efficient management of varying loads, from small-scale deployments to enterprise environments with massive log volumes.


Public Cloud Audit Logs Collection

The platform offers comprehensive audit and management log collection for major public cloud environments, including AWS, Google Cloud Platform (GCP), and Microsoft Azure. This integration allows organizations to centralize and analyze critical operational data from their multi-cloud infrastructures.

By centralizing these critical logs, the platform enhances cloud governance, security monitoring, and compliance management across multi-cloud environments.


SaaS Audit Logs Collection

The platform supports log collection from various SaaS applications, providing multi-source log integration tailored to client needs.

This flexible and extensible approach enables deeper insights into SaaS operations, enhanced security monitoring, and improved operational visibility across cloud-based services.

Topics to discuss [NDA]

LLM/SLM Integration

Anomaly Detection & MLOps

Automated Response

Federated Authentication

Vulnerability Management

Agent-Based Vulnerability Detection

The platform provides comprehensive vulnerability analysis based on operating system and package information collected from deployed agents.

Data Collection

Vulnerability Analysis

Real-Time Detection

Comprehensive Coverage

Efficient Processing

By utilizing this agent-based vulnerability detection method, the platform offers organizations a powerful tool for maintaining a robust security posture and quickly identifying potential threats.


SBOM (Software Bill of Materials) Analysis

The platform provides advanced SBOM analysis capabilities, leveraging agent-based systems to generate and analyze comprehensive software component inventories.

SBOM Generation

Vulnerability Identification

Comprehensive Reporting

Integration and Automation

By utilizing SBOM analysis, customers gain deep visibility into their software supply chain, proactively identify security risks, and maintain a robust security posture across their IT infrastructure.


Remote Vulnerability Analysis

The platform offers comprehensive remote vulnerability analysis, focusing on two key areas:

Public IP Asset Discovery

The system performs thorough scans of customer public IP ranges to identify exposed assets.

Automated HTTPS URL Vulnerability Assessment

The platform conducts automated security scans on HTTPS URLs to detect vulnerabilities.

This approach enables organizations to proactively identify and address security weaknesses in their internet-facing infrastructure, significantly enhancing their overall security posture.