SlideShare a Scribd company logo
ProtectWise Revolutionizes Enterprise Network
Security in the Cloud with DataStax Platform
Gene Stevens
Co-founder & CTO
gene@protectwise.com
Thank you for joining. We will begin shortly.
Eric Stevens
Principle Architect
eric@protectwise.com
ProtectWise Revolutionizes Enterprise Network Security in the Cloud with DataStax Platform
All attendees
placed on mute
Input questions at any time
using the online interface
Webinar Housekeeping
© 2015 DataStax, All Rights Reserved. 4
Founded April 2013
Based in Denver
Enterprise Network Security
Launched March 2015
About ProtectWise
The Enterprise Network Security Problem
© 2015 DataStax, All Rights Reserved. 5
• Complex threats execute over time
• Point solutions overwhelm the human ability to process
• Responders don’t scale, they don’t hunt and they are
outmatched
• Legacy technology not built for modern problems
© 2015 DataStax, All Rights Reserved. 6
The Solution
The World’s First Security DVR Platform
A single solution that combines
Detection, Visibility and Response
© 2015 DataStax, All Rights Reserved. 7
How It Works
Egress
Core
Cloud
Remote
Ingest
Secure Vault
Time Machine
Visualizer
Network
Sensors
Optimized
Network Replay
Security DVR
Platform
Time Machine Analytics
© 2015 DataStax, All Rights Reserved. 8
Behavioral Analytics
Machine
Learning
Reputation
Signatures
Real Time Analysis
+24 hours
+1 month
+6 months
Predictive Analysis
C1 C2 C3
Collective Correlation
24 hours
1 month
6 months
1 year
Automated Retrospective Analysis
Network Traffic
ProtectWise Demo
© 2015 DataStax, All Rights Reserved. 9
Security DVR Visualizer
Network Security and High Scalability
Scale meets Security delivered as a Utility
• Enterprise networks produce massive intel output
• Real time workloads surge wildly
• Latency is king
• Infinite I/O
• A high fidelity memory for the network in the cloud
• Fault tolerant, distributed, asynchronous, parallel and concurrent
© 2015 DataStax, All Rights Reserved. 10
Building a Memory for the Network
© 2014 DataStax, All Rights Reserved. 11
A high fidelity Memory for the Network in the Cloud
• Turning the network into a database which speaks IP
• High fidelity emphasis on packets: the network does not lie
• Haystack is inherently advantaged to being asked new questions
• The bad guys are always one step ahead
• Linear scale requirements
• Constant response times
Building a Time Machine
© 2014 DataStax, All Rights Reserved. 12
A massive State Machine in the Cloud
with a comprehensive sense of time
• Strong focus on time-series and time oriented views
• Half a billion new records per day
• Write demand increases with growth
• Performance becomes more strict with growth
• Retrospection fires tens of thousands of times per day
• Constant time performance must be assumed
• We need to be able to recall those records with consistent high performance
• Shortening the OODA Loop (Observe, Orient, Decide, Act) improves analyst
performance
Core Characteristics
• Stream processing, not batch
processing
• Unbounded data processing
• Out of order data
• Accuracy and correctness
• Not lambda architecture
© 2015 DataStax, All Rights Reserved. 13
Stream Processing at Scale
On massive I/O streams
• Packet processing at Gigabits per
second
• Network shattering: destructuring at
wire speed
• Near real time threat detection
• Data processing at millions of
transactions per second
Cassandra at ProtectWise
© 2015 DataStax, All Rights Reserved. 14
Why Cassandra
• Time Series
• Write optimized
• Surge friendly
• Cluster sophistication
• Atypical data structures
• Hot spots
Use Cases
• Network flows
• Applications and protocols
• Observations & Events
• Context
• Incident Response
• Forensics
DSE Search at ProtectWise - Solr
© 2015 DataStax, All Rights Reserved. 15
Why DSE Search
• Solves data parity/synchronization
issues
• Very low effort to get online, lets
us focus on core business
• Enables query classes difficult to
solve with Cassandra alone
Use Cases
• Open ended search of the entire
haystack
• Relationship graphing
• Conversation tracing
• Threat indicator history and
performance
• Incident Response
• Forensics
Why Not RDBMS or Hadoop?
© 2014 DataStax, All Rights Reserved. 16
Industry shift away from Batch to Stream
RDBMS
• Lack of horizontal linear scalability
• Relational structures not core challenge
Hadoop
• Can’t answer questions in real time
• We’re looking through history tens of thousands of times per day
• An analyst can’t afford repeated multiple-second response times
when investigating an incident: seconds matter
Analytics and Other Tech
© 2014 DataStax, All Rights Reserved. 17
New TechFamiliar Tech
Scala + Akka - pretty much everything
Kafka - async message passing,
offline queues
Storm - Simple counters
Spark - Historic schema processing
Thrift - Tuple messaging, transport,
RPC
Node.js - Visualizer, customer APIs
Impala - Offline threat research,
operational validation
Scala + Akka - All custom tech
Swarm - Distributed packet delivery
and processing, module
containerization
Streamy - Framework for streaming
tuple processing
Count Sumula - Advanced counters
Broski - Threat engine, state machine
Custom data formats - packet
handling, binary protocols
Future Tech
Graph databases - Edge walking, property distribution, relationship
discovery, distance calculations
Attack Prediction - Early warning system, organizational profiling, risk
forecast, anticipation engine
Asset Profiling - Unsupervised deep learning, baselining, behavioral
profile shifts
Deep Learning – Neural nets, supervised and unsupervised,
retrospective propagation, layered intelligence, automated fitness
© 2014 DataStax, All Rights Reserved. Company Confidential 18
Thank you!
Input questions at any time
using the online interface

More Related Content

What's hot (20)

PPTX
How jKool Analyzes Streaming Data in Real Time with DataStax
DataStax
 
PPTX
Webinar - Macy’s: Why Your Database Decision Directly Impacts Customer Experi...
DataStax
 
PPTX
Getting Big Value from Big Data
DataStax
 
PDF
C*ollege Credit: Is My App a Good Fit for Cassandra?
DataStax
 
PDF
Real-time personal trainer on the SMACK stack
Anirvan Chakraborty
 
PDF
Building a Digital Bank
DataStax
 
PPTX
Webinar | How to Understand Apache Cassandra™ Performance Through Read/Writ...
DataStax
 
PPTX
Announcing Spark Driver for Cassandra
DataStax
 
PPT
Webinar: 2 Billion Data Points Each Day
DataStax
 
PPTX
Webinar | Building Apps with the Cassandra Python Driver
DataStax Academy
 
PPTX
C*ollege Credit: Keep the DB, Lose the A
DataStax
 
PPTX
Webinar: ROI on Big Data - RDBMS, NoSQL or Both? A Simple Guide for Knowing H...
DataStax
 
PPTX
Webinar: Buckle Up: The Future of the Distributed Database is Here - DataStax...
DataStax
 
PDF
Data Modeling a Scheduling App (Adam Hutson, DataScale) | Cassandra Summit 2016
DataStax
 
PPTX
How to Successfully Visualize DSE Graph data
DataStax
 
PPTX
Webinar: Bitcoins and Blockchains - Emerging Financial Services Trends and Te...
DataStax
 
PPTX
Webinar | From Zero to 1 Million with Google Cloud Platform and DataStax
DataStax
 
PDF
Microsoft: Building a Massively Scalable System with DataStax and Microsoft's...
DataStax Academy
 
PPTX
Webinar: Eventual Consistency != Hopeful Consistency
DataStax
 
PDF
End of the Myth: Ultra-Scalable Transactional Management by Ricardo Jiménez-P...
Big Data Spain
 
How jKool Analyzes Streaming Data in Real Time with DataStax
DataStax
 
Webinar - Macy’s: Why Your Database Decision Directly Impacts Customer Experi...
DataStax
 
Getting Big Value from Big Data
DataStax
 
C*ollege Credit: Is My App a Good Fit for Cassandra?
DataStax
 
Real-time personal trainer on the SMACK stack
Anirvan Chakraborty
 
Building a Digital Bank
DataStax
 
Webinar | How to Understand Apache Cassandra™ Performance Through Read/Writ...
DataStax
 
Announcing Spark Driver for Cassandra
DataStax
 
Webinar: 2 Billion Data Points Each Day
DataStax
 
Webinar | Building Apps with the Cassandra Python Driver
DataStax Academy
 
C*ollege Credit: Keep the DB, Lose the A
DataStax
 
Webinar: ROI on Big Data - RDBMS, NoSQL or Both? A Simple Guide for Knowing H...
DataStax
 
Webinar: Buckle Up: The Future of the Distributed Database is Here - DataStax...
DataStax
 
Data Modeling a Scheduling App (Adam Hutson, DataScale) | Cassandra Summit 2016
DataStax
 
How to Successfully Visualize DSE Graph data
DataStax
 
Webinar: Bitcoins and Blockchains - Emerging Financial Services Trends and Te...
DataStax
 
Webinar | From Zero to 1 Million with Google Cloud Platform and DataStax
DataStax
 
Microsoft: Building a Massively Scalable System with DataStax and Microsoft's...
DataStax Academy
 
Webinar: Eventual Consistency != Hopeful Consistency
DataStax
 
End of the Myth: Ultra-Scalable Transactional Management by Ricardo Jiménez-P...
Big Data Spain
 

Viewers also liked (18)

PDF
Cassandra Community Webinar | In Case of Emergency Break Glass
DataStax
 
PDF
Webinar | How Clear Capital Delivers Always-on Appraisals on 122 Million Prop...
DataStax
 
PPTX
Webinar: Dyn + DataStax - helping companies deliver exceptional end-user expe...
DataStax
 
PPTX
Webinar | Introducing DataStax Enterprise 4.6
DataStax
 
PPTX
Cassandra Community Webinar: Back to Basics with CQL3
DataStax
 
PDF
Cassandra TK 2014 - Large Nodes
aaronmorton
 
PDF
Cassandra Community Webinar | Practice Makes Perfect: Extreme Cassandra Optim...
DataStax
 
PPT
Webinar: Getting Started with Apache Cassandra
DataStax
 
PPTX
Cassandra Community Webinar | Make Life Easier - An Introduction to Cassandra...
DataStax
 
PPTX
Webinar: DataStax Training - Everything you need to become a Cassandra Rockstar
DataStax
 
PPTX
Webinar: Building Blocks for the Future of Television
DataStax
 
PDF
Webinar: Diagnosing Apache Cassandra Problems in Production
DataStax Academy
 
PDF
Cassandra Community Webinar | Become a Super Modeler
DataStax
 
PDF
Cassandra Community Webinar: Apache Cassandra Internals
DataStax
 
PPTX
Webinar | Real-time Analytics for Healthcare: How Amara Turned Big Data into ...
DataStax
 
PPT
Community Webinar: 15 Commandments of Cassandra DBAs
DataStax
 
PDF
Cassandra Community Webinar | The World's Next Top Data Model
DataStax
 
PDF
Shift: Real World Migration from MongoDB to Cassandra
DataStax
 
Cassandra Community Webinar | In Case of Emergency Break Glass
DataStax
 
Webinar | How Clear Capital Delivers Always-on Appraisals on 122 Million Prop...
DataStax
 
Webinar: Dyn + DataStax - helping companies deliver exceptional end-user expe...
DataStax
 
Webinar | Introducing DataStax Enterprise 4.6
DataStax
 
Cassandra Community Webinar: Back to Basics with CQL3
DataStax
 
Cassandra TK 2014 - Large Nodes
aaronmorton
 
Cassandra Community Webinar | Practice Makes Perfect: Extreme Cassandra Optim...
DataStax
 
Webinar: Getting Started with Apache Cassandra
DataStax
 
Cassandra Community Webinar | Make Life Easier - An Introduction to Cassandra...
DataStax
 
Webinar: DataStax Training - Everything you need to become a Cassandra Rockstar
DataStax
 
Webinar: Building Blocks for the Future of Television
DataStax
 
Webinar: Diagnosing Apache Cassandra Problems in Production
DataStax Academy
 
Cassandra Community Webinar | Become a Super Modeler
DataStax
 
Cassandra Community Webinar: Apache Cassandra Internals
DataStax
 
Webinar | Real-time Analytics for Healthcare: How Amara Turned Big Data into ...
DataStax
 
Community Webinar: 15 Commandments of Cassandra DBAs
DataStax
 
Cassandra Community Webinar | The World's Next Top Data Model
DataStax
 
Shift: Real World Migration from MongoDB to Cassandra
DataStax
 
Ad

Similar to ProtectWise Revolutionizes Enterprise Network Security in the Cloud with DataStax Platform (20)

PPTX
How to get Real-Time Value from your IoT Data - Datastax
DataStax
 
PPTX
DataStax
Michael Shaler
 
PDF
Big Data, Simple and Fast: Addressing the Shortcomings of Hadoop
Hazelcast
 
PPTX
The Big Data Ecosystem for Financial Services
DataStax
 
PPTX
5 Things that Make Hadoop a Game Changer
Caserta
 
PDF
Highly available, scalable and secure data with Cassandra and DataStax Enterp...
Johnny Miller
 
PDF
DataStax GeekNet Webinar - Apache Cassandra: Enterprise NoSQL
DataStax
 
PDF
20160331 sa introduction to big data pipelining berlin meetup 0.3
Simon Ambridge
 
PPTX
Datastax - Why Your RDBMS fails at scale
Ruth Mills
 
PDF
How Virtual Reality and Machine Learning Are Powering the New Age of Network ...
DataStax
 
PPTX
Trivento summercamp masterclass 9/9/2016
Stavros Kontopoulos
 
PPTX
The Evolution of Data Architecture
Wei-Chiu Chuang
 
PDF
Data Pipelines with Spark & DataStax Enterprise
DataStax
 
PDF
Apache Cassandra For Java Developers - Why, What and How. LJC @ UCL October 2014
Johnny Miller
 
PDF
The Top 5 Factors to Consider When Choosing a Big Data Solution
DATAVERSITY
 
PDF
Cassandra introduction 2016
Duyhai Doan
 
PPTX
In-Memory Computing Webcast. Market Predictions 2017
SingleStore
 
PDF
Streaming Analytics with Spark, Kafka, Cassandra and Akka
Helena Edelson
 
PPTX
New trends in data
VMware vFabric
 
PDF
Apache Cassandra: NoSQL in the enterprise
jbellis
 
How to get Real-Time Value from your IoT Data - Datastax
DataStax
 
DataStax
Michael Shaler
 
Big Data, Simple and Fast: Addressing the Shortcomings of Hadoop
Hazelcast
 
The Big Data Ecosystem for Financial Services
DataStax
 
5 Things that Make Hadoop a Game Changer
Caserta
 
Highly available, scalable and secure data with Cassandra and DataStax Enterp...
Johnny Miller
 
DataStax GeekNet Webinar - Apache Cassandra: Enterprise NoSQL
DataStax
 
20160331 sa introduction to big data pipelining berlin meetup 0.3
Simon Ambridge
 
Datastax - Why Your RDBMS fails at scale
Ruth Mills
 
How Virtual Reality and Machine Learning Are Powering the New Age of Network ...
DataStax
 
Trivento summercamp masterclass 9/9/2016
Stavros Kontopoulos
 
The Evolution of Data Architecture
Wei-Chiu Chuang
 
Data Pipelines with Spark & DataStax Enterprise
DataStax
 
Apache Cassandra For Java Developers - Why, What and How. LJC @ UCL October 2014
Johnny Miller
 
The Top 5 Factors to Consider When Choosing a Big Data Solution
DATAVERSITY
 
Cassandra introduction 2016
Duyhai Doan
 
In-Memory Computing Webcast. Market Predictions 2017
SingleStore
 
Streaming Analytics with Spark, Kafka, Cassandra and Akka
Helena Edelson
 
New trends in data
VMware vFabric
 
Apache Cassandra: NoSQL in the enterprise
jbellis
 
Ad

More from DataStax Academy (20)

PDF
Forrester CXNYC 2017 - Delivering great real-time cx is a true craft
DataStax Academy
 
PPTX
Introduction to DataStax Enterprise Graph Database
DataStax Academy
 
PPTX
Introduction to DataStax Enterprise Advanced Replication with Apache Cassandra
DataStax Academy
 
PPTX
Cassandra on Docker @ Walmart Labs
DataStax Academy
 
PDF
Cassandra 3.0 Data Modeling
DataStax Academy
 
PPTX
Cassandra Adoption on Cisco UCS & Open stack
DataStax Academy
 
PDF
Data Modeling for Apache Cassandra
DataStax Academy
 
PDF
Coursera Cassandra Driver
DataStax Academy
 
PDF
Production Ready Cassandra
DataStax Academy
 
PDF
Cassandra @ Netflix: Monitoring C* at Scale, Gossip and Tickler & Python
DataStax Academy
 
PPTX
Cassandra @ Sony: The good, the bad, and the ugly part 1
DataStax Academy
 
PPTX
Cassandra @ Sony: The good, the bad, and the ugly part 2
DataStax Academy
 
PDF
Standing Up Your First Cluster
DataStax Academy
 
PDF
Real Time Analytics with Dse
DataStax Academy
 
PDF
Introduction to Data Modeling with Apache Cassandra
DataStax Academy
 
PDF
Cassandra Core Concepts
DataStax Academy
 
PPTX
Enabling Search in your Cassandra Application with DataStax Enterprise
DataStax Academy
 
PPTX
Bad Habits Die Hard
DataStax Academy
 
PDF
Advanced Data Modeling with Apache Cassandra
DataStax Academy
 
PDF
Advanced Cassandra
DataStax Academy
 
Forrester CXNYC 2017 - Delivering great real-time cx is a true craft
DataStax Academy
 
Introduction to DataStax Enterprise Graph Database
DataStax Academy
 
Introduction to DataStax Enterprise Advanced Replication with Apache Cassandra
DataStax Academy
 
Cassandra on Docker @ Walmart Labs
DataStax Academy
 
Cassandra 3.0 Data Modeling
DataStax Academy
 
Cassandra Adoption on Cisco UCS & Open stack
DataStax Academy
 
Data Modeling for Apache Cassandra
DataStax Academy
 
Coursera Cassandra Driver
DataStax Academy
 
Production Ready Cassandra
DataStax Academy
 
Cassandra @ Netflix: Monitoring C* at Scale, Gossip and Tickler & Python
DataStax Academy
 
Cassandra @ Sony: The good, the bad, and the ugly part 1
DataStax Academy
 
Cassandra @ Sony: The good, the bad, and the ugly part 2
DataStax Academy
 
Standing Up Your First Cluster
DataStax Academy
 
Real Time Analytics with Dse
DataStax Academy
 
Introduction to Data Modeling with Apache Cassandra
DataStax Academy
 
Cassandra Core Concepts
DataStax Academy
 
Enabling Search in your Cassandra Application with DataStax Enterprise
DataStax Academy
 
Bad Habits Die Hard
DataStax Academy
 
Advanced Data Modeling with Apache Cassandra
DataStax Academy
 
Advanced Cassandra
DataStax Academy
 

Recently uploaded (20)

PDF
The Builder’s Playbook - 2025 State of AI Report.pdf
jeroen339954
 
PDF
Empower Inclusion Through Accessible Java Applications
Ana-Maria Mihalceanu
 
PDF
July Patch Tuesday
Ivanti
 
PDF
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
PDF
SFWelly Summer 25 Release Highlights July 2025
Anna Loughnan Colquhoun
 
PDF
Complete JavaScript Notes: From Basics to Advanced Concepts.pdf
haydendavispro
 
PDF
Windsurf Meetup Ottawa 2025-07-12 - Planning Mode at Reliza.pdf
Pavel Shukhman
 
PDF
Predicting the unpredictable: re-engineering recommendation algorithms for fr...
Speck&Tech
 
PDF
CIFDAQ Weekly Market Wrap for 11th July 2025
CIFDAQ
 
PDF
HubSpot Main Hub: A Unified Growth Platform
Jaswinder Singh
 
PDF
Fl Studio 24.2.2 Build 4597 Crack for Windows Free Download 2025
faizk77g
 
PDF
Log-Based Anomaly Detection: Enhancing System Reliability with Machine Learning
Mohammed BEKKOUCHE
 
PPTX
Building Search Using OpenSearch: Limitations and Workarounds
Sease
 
PDF
SWEBOK Guide and Software Services Engineering Education
Hironori Washizaki
 
PDF
Blockchain Transactions Explained For Everyone
CIFDAQ
 
PPTX
Top iOS App Development Company in the USA for Innovative Apps
SynapseIndia
 
PDF
HCIP-Data Center Facility Deployment V2.0 Training Material (Without Remarks ...
mcastillo49
 
PDF
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
PPTX
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
PDF
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 
The Builder’s Playbook - 2025 State of AI Report.pdf
jeroen339954
 
Empower Inclusion Through Accessible Java Applications
Ana-Maria Mihalceanu
 
July Patch Tuesday
Ivanti
 
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
SFWelly Summer 25 Release Highlights July 2025
Anna Loughnan Colquhoun
 
Complete JavaScript Notes: From Basics to Advanced Concepts.pdf
haydendavispro
 
Windsurf Meetup Ottawa 2025-07-12 - Planning Mode at Reliza.pdf
Pavel Shukhman
 
Predicting the unpredictable: re-engineering recommendation algorithms for fr...
Speck&Tech
 
CIFDAQ Weekly Market Wrap for 11th July 2025
CIFDAQ
 
HubSpot Main Hub: A Unified Growth Platform
Jaswinder Singh
 
Fl Studio 24.2.2 Build 4597 Crack for Windows Free Download 2025
faizk77g
 
Log-Based Anomaly Detection: Enhancing System Reliability with Machine Learning
Mohammed BEKKOUCHE
 
Building Search Using OpenSearch: Limitations and Workarounds
Sease
 
SWEBOK Guide and Software Services Engineering Education
Hironori Washizaki
 
Blockchain Transactions Explained For Everyone
CIFDAQ
 
Top iOS App Development Company in the USA for Innovative Apps
SynapseIndia
 
HCIP-Data Center Facility Deployment V2.0 Training Material (Without Remarks ...
mcastillo49
 
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 

ProtectWise Revolutionizes Enterprise Network Security in the Cloud with DataStax Platform

  • 1. ProtectWise Revolutionizes Enterprise Network Security in the Cloud with DataStax Platform Gene Stevens Co-founder & CTO [email protected] Thank you for joining. We will begin shortly. Eric Stevens Principle Architect [email protected]
  • 3. All attendees placed on mute Input questions at any time using the online interface Webinar Housekeeping
  • 4. © 2015 DataStax, All Rights Reserved. 4 Founded April 2013 Based in Denver Enterprise Network Security Launched March 2015 About ProtectWise
  • 5. The Enterprise Network Security Problem © 2015 DataStax, All Rights Reserved. 5 • Complex threats execute over time • Point solutions overwhelm the human ability to process • Responders don’t scale, they don’t hunt and they are outmatched • Legacy technology not built for modern problems
  • 6. © 2015 DataStax, All Rights Reserved. 6 The Solution The World’s First Security DVR Platform A single solution that combines Detection, Visibility and Response
  • 7. © 2015 DataStax, All Rights Reserved. 7 How It Works Egress Core Cloud Remote Ingest Secure Vault Time Machine Visualizer Network Sensors Optimized Network Replay Security DVR Platform
  • 8. Time Machine Analytics © 2015 DataStax, All Rights Reserved. 8 Behavioral Analytics Machine Learning Reputation Signatures Real Time Analysis +24 hours +1 month +6 months Predictive Analysis C1 C2 C3 Collective Correlation 24 hours 1 month 6 months 1 year Automated Retrospective Analysis Network Traffic
  • 9. ProtectWise Demo © 2015 DataStax, All Rights Reserved. 9 Security DVR Visualizer
  • 10. Network Security and High Scalability Scale meets Security delivered as a Utility • Enterprise networks produce massive intel output • Real time workloads surge wildly • Latency is king • Infinite I/O • A high fidelity memory for the network in the cloud • Fault tolerant, distributed, asynchronous, parallel and concurrent © 2015 DataStax, All Rights Reserved. 10
  • 11. Building a Memory for the Network © 2014 DataStax, All Rights Reserved. 11 A high fidelity Memory for the Network in the Cloud • Turning the network into a database which speaks IP • High fidelity emphasis on packets: the network does not lie • Haystack is inherently advantaged to being asked new questions • The bad guys are always one step ahead • Linear scale requirements • Constant response times
  • 12. Building a Time Machine © 2014 DataStax, All Rights Reserved. 12 A massive State Machine in the Cloud with a comprehensive sense of time • Strong focus on time-series and time oriented views • Half a billion new records per day • Write demand increases with growth • Performance becomes more strict with growth • Retrospection fires tens of thousands of times per day • Constant time performance must be assumed • We need to be able to recall those records with consistent high performance • Shortening the OODA Loop (Observe, Orient, Decide, Act) improves analyst performance
  • 13. Core Characteristics • Stream processing, not batch processing • Unbounded data processing • Out of order data • Accuracy and correctness • Not lambda architecture © 2015 DataStax, All Rights Reserved. 13 Stream Processing at Scale On massive I/O streams • Packet processing at Gigabits per second • Network shattering: destructuring at wire speed • Near real time threat detection • Data processing at millions of transactions per second
  • 14. Cassandra at ProtectWise © 2015 DataStax, All Rights Reserved. 14 Why Cassandra • Time Series • Write optimized • Surge friendly • Cluster sophistication • Atypical data structures • Hot spots Use Cases • Network flows • Applications and protocols • Observations & Events • Context • Incident Response • Forensics
  • 15. DSE Search at ProtectWise - Solr © 2015 DataStax, All Rights Reserved. 15 Why DSE Search • Solves data parity/synchronization issues • Very low effort to get online, lets us focus on core business • Enables query classes difficult to solve with Cassandra alone Use Cases • Open ended search of the entire haystack • Relationship graphing • Conversation tracing • Threat indicator history and performance • Incident Response • Forensics
  • 16. Why Not RDBMS or Hadoop? © 2014 DataStax, All Rights Reserved. 16 Industry shift away from Batch to Stream RDBMS • Lack of horizontal linear scalability • Relational structures not core challenge Hadoop • Can’t answer questions in real time • We’re looking through history tens of thousands of times per day • An analyst can’t afford repeated multiple-second response times when investigating an incident: seconds matter
  • 17. Analytics and Other Tech © 2014 DataStax, All Rights Reserved. 17 New TechFamiliar Tech Scala + Akka - pretty much everything Kafka - async message passing, offline queues Storm - Simple counters Spark - Historic schema processing Thrift - Tuple messaging, transport, RPC Node.js - Visualizer, customer APIs Impala - Offline threat research, operational validation Scala + Akka - All custom tech Swarm - Distributed packet delivery and processing, module containerization Streamy - Framework for streaming tuple processing Count Sumula - Advanced counters Broski - Threat engine, state machine Custom data formats - packet handling, binary protocols
  • 18. Future Tech Graph databases - Edge walking, property distribution, relationship discovery, distance calculations Attack Prediction - Early warning system, organizational profiling, risk forecast, anticipation engine Asset Profiling - Unsupervised deep learning, baselining, behavioral profile shifts Deep Learning – Neural nets, supervised and unsupervised, retrospective propagation, layered intelligence, automated fitness © 2014 DataStax, All Rights Reserved. Company Confidential 18
  • 19. Thank you! Input questions at any time using the online interface

Editor's Notes

  • #6: It’s not that responders don’t hunt, it’s that they cannot hunt b/c of resource and tech constraints
  • #11: Enterprise networks produce massive intel output Real time workloads surge wildly Latency is king Remediation follows discovery Timeliness affects usefulness Batch processing has latency baked in by design Infinite I/O Can never lose data Must scale indefinitely A high fidelity memory for the network in the cloud: The network does not lie Retrospection matters Fault tolerant, distributed, asynchronous, parallel and concurrent
  • #14: “Lambda Architecture” = Streaming inaccurate results; batching for accurate results Lambda is inherently hard to synchronize: two massive distributed systems meant to agree? heh
  • #16: Open ended search of the entire haystack Netflow Applications and Protocols Threat detections
  • #19: Unsupervised pattern analysis Supervised classification