预测是理解安全异常的一个大数据环境,因为它们在项目中呈现,旨在帮助收集端到端CICD管道的数据。
Forecast is a big data environment for understanding security anomalies using AWS services and Open Source projects. Forecast helps DevSecOps team to operate a single framework for Red and Blue Team activities to support faster feedback and security remediation. It can be used to ingest data from a reconnaissance library, logs and event feeds to support Continuous Delivery of software projects, security monitoring and incident response. And it is intended to utilize a catalog of rules for forecasting security issues as they progress through a Continuous Delivery pipeline.
Forecast is community driven and has a variety of sub-projects that are part of the Forecast Ecosystem. Additionally, Forecast pulls in the best of other projects to help reduce the amount of systems that need to be operated to support DevOps teams.
Intended Benefits:
Forecast is simple to install and can be run in a variety of modes using AWS as supporting infrastructure. You can choose to support your forecast environment using ELK or AWS EMR. We have chosen AWS EMR for Forecast because it gives us big data tools to work with without the overhead.
Data Feeds are a critical element of the Forecast Ecosystem and when organized well are highly useful in producing a scalable security information processing matched against a Continuous Delivery pipeline.
We are in the process of figuring out how to divide and conquer to make Forecast easier to work on to extend and improve it.