Upgrade to Pro — share decks privately, control downloads, hide ads and more …

MozDef: The Mozilla Defense Platform

Elastic Co
March 10, 2015

MozDef: The Mozilla Defense Platform

This talk was presented at the inaugural Elastic{ON} conference, http://elasticon.com

Session Abstract:

From the brains behind MozDef: The Mozilla Defense Platform, this talk will focus on their SIEM overlay on top of Elasticsearch. Highlight will include security incident response, alerting, and operations integrations.

Presented by Jeff Bryner, Mozilla

Elastic Co

March 10, 2015
Tweet

More Decks by Elastic Co

Other Decks in Technology

Transcript

  1. 7 Mozilla Defense Platform SIEM overlay for Elasticsearch •  Incident

    Response •  Event Management •  Event Correlation/Alerts •  Threat Management •  Real-time interactions between defenders •  Integrations into defensive infrastructure
  2. 8

  3. CC-BY-ND 4.0 9   Under the hood: 5 node ES

    cluster: All are Vmware VMs 4 cores each node 32GB memory (16 for ES JVM) 5 TB NFS Netapp storage 5 nodes of RabbitMQ Generic VMs 2 in each physical data center 1 as a DMZ proxy for AWS sites 1 of above Rabbit nodes is also Meteor UI/Mongo DB
  4. CC-BY-ND 4.0 10   Performance: 5k EPS idle 7-10k EPS

    burst 300+ million events/day 20 days of online storage (backed up to AWS for offline)
  5. 11

  6. Fledgling features: •  Aggregations to alert on event category stats

    out of normal (working, just to email) •  Aggregations of least common terms (awaiting pyes, cluster upgrades) •  Oculus/myo support in the attackers screen (semi-working)
  7. Jeff Bryner MozDef: The Mozilla Defense Platform @0x7eff [email protected] irc.mozilla.org:

    [jeff] MozDef: http://mozdef.rocks http://demo.mozdef.com:3000