Upload
austin-leahy
View
453
Download
0
Embed Size (px)
Citation preview
AGENDA
Where is the need The new approach Moving to real investigation Value of anomaly based detection ONI –Demo Open Data Model Q&A
START WITH THE HARDEST PILL TO SWALLOW
Operational Analytics
• Visualization, attack heuristics, noise filter
Machine Learning
• Filter billion of events to a few thousands
• Unsupervised learning
Parallel Ingest Framework
• Open source decoders
• Load data in Hadoop
Telemetry
• Network Flows (nfcapd)
• DNS (PCAP)• Proxy
• Partners Should control their Data
• Application framework is rocket fuel for the build instead of buy decision
• Community engagement means ever increasing value describing the landscape
Network Apache Hadoop*
Spark + ML
Intel Platform
Cybe
rsecu
rity IT Operations
FraudUs
er Ex
perie
nce
OPEN NETWORK INSIGHT OPEN DATA MODEL
Identity
Endpoint
Open Network Insight