Plan of Mata Elang Stable Development

Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 11

Plan of Mata Elang Stable Development

July 2022 – April 2023

Copyright Mata Elang Committee


Overview
[Project Period]
July 2022 – April 2023

[Objectives]
1. Enhancement of Mata Elang Committee and Community
- Establishment of Mata Elang technical team
- Acceptance testing and release management
- Launch of the publicity of Mata Elang Stable
2. Development of Mata Elang Stable 1.1
- New feature releases & performance improvements *
- Offline installer development *
(* Tentative development requirements)

Copyright Mata Elang Committee


Enhancement of Mata Elang Committee and Community
Establishment of Mata Elang technical team

- Who is the project leader for next Mata Elang 1.1?


• Ferry san or someone from UI?

- Assignment of a manager who has software development experience


• Responsibilities: Define requirements and control project for OSS development

- Assignment of a core-engineer for Mata Elang


• Responsibilities: Provide the technical support for Mata Elang users

Copyright Mata Elang Committee


Enhancement of Mata Elang Committee and Community
Acceptance testing and release management

- Lending equipment (2 network taps and 2 notebook PCs) for Mata Elang
development and acceptance testing

- Venue for 2-week acceptance testing in February 2023

- Several equipment needed for acceptance testing


• Internet connection, LAN cables, several switching hubs, attacker PCs, etc.

- Secure members to implement the acceptance testing

Copyright Mata Elang Committee


Enhancement of Mata Elang Committee and Community
Launch of the publicity of Mata Elang Stable

Who is in charge of the publicity of Mata Elang?


- Building the website of Mata Elang - ???

- Preparing email addresses for contact and support team – ???

- Mata Elang Introduction at seminars – Gde san.

Copyright Mata Elang Committee


Strategy of Mata Elang Stable Development
Version July 2022

Copyright Mata Elang Committee


Strategy Roadmap – Basics (1/2)
This section describes the development strategy of ME Stable for next 5 years.

Three versions of ME stable are proposed here.


1. ME Stable v1.0 : Initial release of ME Stable with JICA support
2. ME Stable v1.1 : New features release & performance improvement with JICA support
3. ME Stable v2.0 : Comprehensive update of ME Stable
ME R&D ME Stable v1.0 ME Stable v1.1 ME Stable v2.0
(Draft)
Release Released April 2022 April 2024 April 2026
Lifetime (n/a) At least 2 years At least 2 years At least 2 years
JICA Support NO YES Possibly, YES NO

ME Stable will be used by idCARE “SOC exercise” from September 2022.


Apr. 2022 Apr. 2024 Apr. 2026

ME Stable v1.0 ME Stable v1.1 ME Stable v2.0


PENDING
⇩ Sep. 2022

idCARE “CMP0020 Comprehensive Exercise: SOC”

Copyright Mata Elang Committee


Strategy Roadmap – Basics (2/2)
(cont.)
ME R&D ME Stable v1.0 ME Stable v1.1 ME Stable v2.0
(Draft)
Release Released April 2022 April 2024 April 2026
Lifetime (n/a) At least 2 years At least 2 years At least 2 years
JICA Support NO YES Possibly, YES NO

Requirements of ME Stable v1.0


• ME Stable will be used by idCARE
• ME Stable must be well-tested and well-documented
• Bug fix activities must be continued for at least 24 months

Development Policy of ME Stable v1.1


• No architecture changes
• Adding new features to improve practicality
• Additional 2-year support

Possible Strategic Direction of ME Stable v2.0


• Improvement of practicality
• Reducing the use of system resources
• Multi-tenant system
• Cloud IDS etc.
Copyright Mata Elang Committee
Strategy Roadmap – Functions (1/2)
The following table shows the strategy roadmap from the perspective of ME functionality.
ME R&D ME Stable v1.0 ME Stable v2.0 or later (Draft)

IDS Network IDS Network IDS Cloud IDS?


Data Collecting MQTT MQTT Optimized MQTT?
Data Processing Streaming Data Processing Streaming Data Processing Distributed Streaming Data
- Realtime Processing - Realtime Processing Processing?
- Batch Data Aggregation

Data Storage Big Data Storage Big Data Storage Distributed Big Data Storage?
Search Engine (n/a) Data Aggregation Data Aggregation
Dashboard Simple Dashboard Customizable Dashboard Multi-Tenant Dashboard?
- Signature-base and - Signature-base and Risk-Threat Analysis?
protocol-base analysis protocol-base analysis
- Time-series analysis - Time-series analysis
- Geographical analysis

 ME 2.0 roadmap will be revised at future re-planning.

Copyright Mata Elang Committee


Strategy Roadmap – Functions (2/2)
(cont.)
ME R&D ME Stable v1.0 ME Stable v2.0 or later (Draft)

Operation & (n/a) [Operation] Functions of ME Stable v1.0


Management  Server Resource Monitoring +
 Log Rotation [Management]
 Sensor Management
 User Management
 Rule Management

ME Stable v1.1 [Notification]


 IPv6 Support
 Incident Notification
-e.g. High Severity Incident
 Anomaly Detection Alert
 Offline installer -e.g. Change-point Detection

[Data Analysis]
 Enrich Query for detail analysis
 Threat-intelligent for detail analysis
and risk analysis
 Some of these functions come from the ME documents.
 Some others are for improvement of practicality.
[Visualization]
 ME 2.0 roadmap will be revised at future re-planning.
 Enrich Visualization

[Inter-organizational Cooperation]
Copyright Mata Elang Committee
 STIX Format Support
Strategy Roadmap – Products
The next table shows the strategy roadmap from the perspective of OSS product.
ME R&D ME Stable v1.0 ME Stable v2.0 or later
(Draft)

Sensor Snort v2 Snort 2 / Snort 3 on v1.1 Snort v3 ?


Sensor Installer (Original) Sensor Installer (Original) Sensor Installer (Original)

Data Eclipse Mosquitto (MQTT) MQTT / (removed on v1.1) Apache Kafka


Collecting Apache Kafka Apache Kafka

Data Apache Spark Apache Spark Apache Spark


Processing Apache Hadoop Apache Hadoop Apache Hadoop
- Hadoop YARN & MapReduce - HDFS - HDFS
- HDFS

Data Storage Apache Cassandra Apache Cassandra Apache Cassandra


MongoDB MongoDB (removed)
Search Engine (n/a) Elasticsearch Elasticsearch
Logstash Logstash
Dashboard Kaspa Service/Client Kibana Kibana
(Original)
Stevia (Original)
 ME 2.0 roadmap will be
Operation & (n/a) Zabbix Zabbix
revised at future re-planning.
Management
Copyright Mata Elang Committee

You might also like