SlideShare a Scribd company logo
Security	Data	Lake Leveraging	Big	Data	Platform	
to	build	stronger	cyber	defense
Rujirapong	Ritwong
CEO,	Co-founder
Softnix Technology
You	Can’t	Protect	
What	You	Can’t	See
IT	Security	need	to	
Visibility
(source	:	www.fbi.gov)
Unauthorized	access	
to	data	system
Data	leakage	/	loss
72	%
(source	:	www.fbi.gov)
Way	to	increase	your	visibility
Definition
• Security	Data	Lake	is	Data	Lake	
appearing	in	the	security	field.
• Data	Lake	is	a	method	of	storing	
data	within	Big	Data	system
• Security	Data	Lake	central	
location	where	all	security	data
• Similar	Log	Management,	SIEM
Traditional	Security	Management
• SIEM	are	security	monitor,	log	management	acted	as	
the	data	store	for	security	data.
• Technologies	used	15	years	ago.
• Relational	databases	are	not	well	suited	for	large	
amounts	of	data.
• ACID- Fast	writes	or	fast	reads,	but	not	both
• Real	time	correlation	(rules)	engine	run	on	single	
machine.
• Not	build	to	let	other	products	reuse.
• Expensive	for	explaining
How	long	do	you	currently	store	event	
and	log	data for	SIEM
http://go.cyphort.com/rs/181-NTN-682/images/Cyphort-Ponemon-SIEM-Report.pdf
Retention	data	for	compliance
ISO27001 ,	PCI-DSS,	HIPAA,	FISMA,	Sarbanes-Oxley	(SOX)
Unknown	Events	Data
Credit:	Hortonworks
Comparing	Security	Data	Lake	to	SIEM
Security	Data	Lake	is	not	a	replace	for	SIEM
Security	Data	Lake	Objective;
◦ data	storage
◦ data	processing
◦ Purpose	function	of	a	SIEM	covers
Limitation	of	
SIEMs
Scalability
Openness
Big	Data	Technology	
Attempting	solutions	to	the	
TWO	main	problems	of	SIEMs
Hadoop	basic
2.25x
More	likely
To	detect	threats
Within	minutes
Time	to	detect	and	identify	a	security	
incident
https://www.cloudera.com/content/dam/www/marketing/resources/analyst-reports/big-data-cybersecurity-analytics-
research-report.pdf.landing.html
Report	user	demand	for	
cybersecurity	analytics	on	the	rise	
the	past	12	months
71%
Organizations	need	to	report
More	information:	https://www.ponemon.org/local/upload/file/Big_Data_Analytics_in_Cyber_Defense_V12.pdf
82%
Big	Data	Platform	+	Security	Technologies	=	Stronger	Cyber	Defense
It’s	still	difficult	to	deploy	Big	Data	cybersecurity	analytics.
What	is	stopping	Big	Data	analytics	
adoption	?
https://www.cloudera.com/content/dam/www/marketing/resources/analyst-reports/big-data-cybersecurity-analytics-research-report.pdf.landing.html
Of	organizations	say	it’s	
impossible	to	leverage	Big	
Data	analytics	with	
traditional	system
72%
https://www.cloudera.com/content/dam/www/marketing/resources/analyst-reports/big-data-cybersecurity-analytics-research-report.pdf.landing.html
But	Security	Data	Lake	(Hadoop	based)	can.
29% 72% 43%
increase	data
volumes	more	
than	100%
increase	data
processing	more	
than	76%
increase	data
access	for	
analytics	more	
than	100%
https://www.cloudera.com/content/dam/www/marketing/resources/analyst-reports/big-data-cybersecurity-analytics-
research-report.pdf.landing.html
Top	Use	Case
BIG	DATA	
Analytics
Use	Case
Vodafone	UK’s	new	
SIEM	system	relies	on	
Apache	Flume	and	
Apache	Kafka	to	
ingest	nearly	1	million	
events	per	second.
Open	Source
Big	Data	for	Cybersecurity
http://spot.incubator.
apache.org
Apache	Spot
Open	Source
Big	Data	for	Cybersecurity
http://metron.apache
.org
Apache	Metron
Data	feed	for	Security	Data	Lake
Security	Technologies	Data Non	Security	Data
http://go.cyphort.com/rs/181-NTN-682/images/Cyphort-Ponemon-SIEM-Report.pdf
100%
All	organization	use Firewall	bypass Can’t	monitor.	
It’s	Big	Data.
100% 100%
DNS	traffic
Optimize	your	SIEM
Optimize	your	SIEM
Split	connection	setup
Security	Data	lake	help	optimize	SIEM
Cost-Effectively	Increase	Enterprise	Visibility
Analytics	Flexibility
SIEM	Lock-in
Deployment	Flexibility
Our	history
Logger Logger	Cloud
for	MSP
Data	PlatformAuthenticator
Logger	for	AWS
Logger	for	Azure
“Big	Data	Platform	Company”
Collector
Edge	Point
All-in-one Law	Compliance Security	&	IT	Services
Monitoring	by	ZABBIX
Big	Data	Analytics
Softnix Security Data Lake
Technology	Partner
Softnix Data	Platform
Big	Data	Analytic	Platform
Any Device
Any	Platform
Dashboard	&	VisualizeIntegration	to	Enterprise	
Analytic	System
Softnix Data	Platform
Big	Data	Analytic	Platform
Solution	of	Softnix Data	Platform
Architecture	Softnix	Data	Platform
Softnix	Data	Platform	Architecture
Capability
üSupport	machine	data	with	any	type
üData	extraction	to	analytic	format
üSupport	data	indexing	and	aggregation
üFull-text	search	or	specific	search
üVisualize	data	for	human	understand
üSchedule	send	report	to	email
Our	Process
Collection	of	
Data
Data	
Enrichment
Convert	into	
Structured
Analysis	of	
Data
Virtualization	
of	Data
Dashboard	System
Full-Text	Search	&	Specific	search	
Event	Detection
Data	Extraction
Visualize	data
Simple	Data	Visualization
Data	Aggregation
Use	Case:
Security	Dashboard
Softnix Security Data Lake
Use	Case:
Authentication	Monitor
Use	Case:
DNS	Dashboard
Use	Case:
Cloud	Firewall	for	MSP
Multiple	dashboard	per	project
Contact	Us
www.softnix.co.th
facebook.com/softnixtech
twitter.com/softnix
medium.com/@softnix
info@softnix.co.th

More Related Content

PDF
Talend introduction v1
PDF
How to Swiftly Operationalize the Data Lake for Advanced Analytics Using a Lo...
PDF
The New Basics of Business Intelligence Lesson 3: Multi Source Analysis
PDF
Empower Splunk and other SIEMs with the Databricks Lakehouse for Cybersecurity
PDF
Elastic @ Adobe: Making Search Smarter with Machine Learning at Scale
PPTX
CI/CD for a Data Platform
PDF
Monitoring and Securing a Geo-Dispersed Data Center at Hill AFB
PPTX
GDPR: 20 Million Reasons to Get Ready - Part 2: Living Compliance
Talend introduction v1
How to Swiftly Operationalize the Data Lake for Advanced Analytics Using a Lo...
The New Basics of Business Intelligence Lesson 3: Multi Source Analysis
Empower Splunk and other SIEMs with the Databricks Lakehouse for Cybersecurity
Elastic @ Adobe: Making Search Smarter with Machine Learning at Scale
CI/CD for a Data Platform
Monitoring and Securing a Geo-Dispersed Data Center at Hill AFB
GDPR: 20 Million Reasons to Get Ready - Part 2: Living Compliance

What's hot (20)

PDF
Business Insight
PPTX
Momentum in Big Data, IoT and Machine Intelligence
PPTX
Cloudera - IoT & Smart Cities
PPTX
How to get Real-Time Value from your IoT Data - Datastax
PPTX
2016 Cybersecurity Analytics State of the Union
PPTX
Harnessing the Power of Big Data at Freddie Mac
PDF
How a Media Data Platform Drives Real-time Insights & Analytics using Apache ...
PDF
ttec - ParStream
PPTX
Xanadu Big Data Platform Technology BMT@ Rackspace Cloud
PDF
It's All about Insight: Unlocking Effective Risk Management for Your Unstruct...
PPTX
Cloudera training secure your cloudera cluster 7.10.18
PPTX
How an Industrial DataOps Solution Improves OEE With a Time Series Database
PDF
Hopper energyservices
PPTX
Michael Hummel - Stop Storing Data! - Parstream
PPTX
Momentum v2.0
PPTX
IoT and Big Data - Iot Asia 2014
PDF
Datenvirtualisierung: Wie Sie Ihre Datenarchitektur agiler machen (German)
PDF
Extending Operations from On-premises Solutions Towards Hybrid and Cloud - Da...
PDF
Logicalis IoT & Smart Cities (Use Case)
PPTX
Realtime stream analytics with momentum
Business Insight
Momentum in Big Data, IoT and Machine Intelligence
Cloudera - IoT & Smart Cities
How to get Real-Time Value from your IoT Data - Datastax
2016 Cybersecurity Analytics State of the Union
Harnessing the Power of Big Data at Freddie Mac
How a Media Data Platform Drives Real-time Insights & Analytics using Apache ...
ttec - ParStream
Xanadu Big Data Platform Technology BMT@ Rackspace Cloud
It's All about Insight: Unlocking Effective Risk Management for Your Unstruct...
Cloudera training secure your cloudera cluster 7.10.18
How an Industrial DataOps Solution Improves OEE With a Time Series Database
Hopper energyservices
Michael Hummel - Stop Storing Data! - Parstream
Momentum v2.0
IoT and Big Data - Iot Asia 2014
Datenvirtualisierung: Wie Sie Ihre Datenarchitektur agiler machen (German)
Extending Operations from On-premises Solutions Towards Hybrid and Cloud - Da...
Logicalis IoT & Smart Cities (Use Case)
Realtime stream analytics with momentum
Ad

Viewers also liked (20)

PDF
Apache Spark—Apache HBase Connector: Feature Rich and Efficient Access to HBa...
PDF
Softnix Messaging Server
PDF
빅데이터윈윈 컨퍼런스_데이터시각화자료
PPTX
Using Big Data to Transform Your Customer’s Experience - Part 1

PDF
Zoomdata
PPTX
Partner Ecosystem Showcase for Apache Ranger and Apache Atlas
PPTX
Ibm watson
PDF
Spark as part of a Hybrid RDBMS Architecture-John Leach Cofounder Splice Machine
PDF
Spark meetup - Zoomdata Streaming
PPTX
The Evolution of Data Architecture
PDF
CWIN17 Frankfurt / Cloudera
PDF
Cloudera and Qlik: Big Data Analytics for Business
PPTX
Webinar - Sehr empfehlenswert: wie man aus Daten durch maschinelles Lernen We...
PPTX
Security implementation on hadoop
PPTX
Real-Time Analytics Visualized w/ Kafka + Streamliner + MemSQL + ZoomData, An...
PDF
Building the Ideal Stack for Real-Time Analytics
PPTX
Put Alternative Data to Use in Capital Markets

PDF
The Fast Path to Building Operational Applications with Spark
PDF
MatFast: In-Memory Distributed Matrix Computation Processing and Optimization...
PPTX
Benefits of Transferring Real-Time Data to Hadoop at Scale
Apache Spark—Apache HBase Connector: Feature Rich and Efficient Access to HBa...
Softnix Messaging Server
빅데이터윈윈 컨퍼런스_데이터시각화자료
Using Big Data to Transform Your Customer’s Experience - Part 1

Zoomdata
Partner Ecosystem Showcase for Apache Ranger and Apache Atlas
Ibm watson
Spark as part of a Hybrid RDBMS Architecture-John Leach Cofounder Splice Machine
Spark meetup - Zoomdata Streaming
The Evolution of Data Architecture
CWIN17 Frankfurt / Cloudera
Cloudera and Qlik: Big Data Analytics for Business
Webinar - Sehr empfehlenswert: wie man aus Daten durch maschinelles Lernen We...
Security implementation on hadoop
Real-Time Analytics Visualized w/ Kafka + Streamliner + MemSQL + ZoomData, An...
Building the Ideal Stack for Real-Time Analytics
Put Alternative Data to Use in Capital Markets

The Fast Path to Building Operational Applications with Spark
MatFast: In-Memory Distributed Matrix Computation Processing and Optimization...
Benefits of Transferring Real-Time Data to Hadoop at Scale
Ad

Similar to Softnix Security Data Lake (20)

PDF
A Pragmatic Approach to SIEM: Buy for Compliance, Use for Security
PPTX
The Data Defenders: SIEM and Log Management in Cybersecurity
PPTX
Apply big data and data lake for processing security data collections
PPTX
Big Data Analytics for Cyber Security: A Quick Overview
PDF
Big Data Analytics to Enhance Security คุณอนพัทย์ พิพัฒน์กิติบดี Technical Ma...
PPTX
Security Information and Event Management (SIEM)
PPTX
Data lake protection ft 3119 -ver1.0
PPTX
Security Information Event Management Security Information Event Management
PDF
PDF
The SIEM Buyer Guide the siem buyer guide
PPTX
Introduction to SIEM.pptx
PDF
El contexto de la integración masiva de datos
PPTX
SIEM : Security Information and Event Management
PPTX
Five SIEM Futures (2012)
PDF
Organization And Management Case Study Report, (IOE, TU)
PDF
Maceo Wattley Contributor Infosec
PPTX
SIEM - Your Complete IT Security Arsenal
PDF
Big Data Visualization
PPTX
SIEM Primer:
PDF
Big Data Analytics to Enhance Security
A Pragmatic Approach to SIEM: Buy for Compliance, Use for Security
The Data Defenders: SIEM and Log Management in Cybersecurity
Apply big data and data lake for processing security data collections
Big Data Analytics for Cyber Security: A Quick Overview
Big Data Analytics to Enhance Security คุณอนพัทย์ พิพัฒน์กิติบดี Technical Ma...
Security Information and Event Management (SIEM)
Data lake protection ft 3119 -ver1.0
Security Information Event Management Security Information Event Management
The SIEM Buyer Guide the siem buyer guide
Introduction to SIEM.pptx
El contexto de la integración masiva de datos
SIEM : Security Information and Event Management
Five SIEM Futures (2012)
Organization And Management Case Study Report, (IOE, TU)
Maceo Wattley Contributor Infosec
SIEM - Your Complete IT Security Arsenal
Big Data Visualization
SIEM Primer:
Big Data Analytics to Enhance Security

Recently uploaded (20)

PDF
168300704-gasification-ppt.pdfhghhhsjsjhsuxush
PPTX
STERILIZATION AND DISINFECTION-1.ppthhhbx
PPTX
A Complete Guide to Streamlining Business Processes
PDF
22.Patil - Early prediction of Alzheimer’s disease using convolutional neural...
PPTX
Qualitative Qantitative and Mixed Methods.pptx
PDF
Data Engineering Interview Questions & Answers Cloud Data Stacks (AWS, Azure,...
PPTX
01_intro xxxxxxxxxxfffffffffffaaaaaaaaaaafg
PPTX
(Ali Hamza) Roll No: (F24-BSCS-1103).pptx
PDF
REAL ILLUMINATI AGENT IN KAMPALA UGANDA CALL ON+256765750853/0705037305
PPTX
Market Analysis -202507- Wind-Solar+Hybrid+Street+Lights+for+the+North+Amer...
PDF
Introduction to Data Science and Data Analysis
PDF
Data Engineering Interview Questions & Answers Batch Processing (Spark, Hadoo...
PPTX
AI Strategy room jwfjksfksfjsjsjsjsjfsjfsj
PPTX
Acceptance and paychological effects of mandatory extra coach I classes.pptx
PPTX
Introduction-to-Cloud-ComputingFinal.pptx
PDF
[EN] Industrial Machine Downtime Prediction
PPTX
Topic 5 Presentation 5 Lesson 5 Corporate Fin
PPTX
IBA_Chapter_11_Slides_Final_Accessible.pptx
PDF
Introduction to the R Programming Language
168300704-gasification-ppt.pdfhghhhsjsjhsuxush
STERILIZATION AND DISINFECTION-1.ppthhhbx
A Complete Guide to Streamlining Business Processes
22.Patil - Early prediction of Alzheimer’s disease using convolutional neural...
Qualitative Qantitative and Mixed Methods.pptx
Data Engineering Interview Questions & Answers Cloud Data Stacks (AWS, Azure,...
01_intro xxxxxxxxxxfffffffffffaaaaaaaaaaafg
(Ali Hamza) Roll No: (F24-BSCS-1103).pptx
REAL ILLUMINATI AGENT IN KAMPALA UGANDA CALL ON+256765750853/0705037305
Market Analysis -202507- Wind-Solar+Hybrid+Street+Lights+for+the+North+Amer...
Introduction to Data Science and Data Analysis
Data Engineering Interview Questions & Answers Batch Processing (Spark, Hadoo...
AI Strategy room jwfjksfksfjsjsjsjsjfsjfsj
Acceptance and paychological effects of mandatory extra coach I classes.pptx
Introduction-to-Cloud-ComputingFinal.pptx
[EN] Industrial Machine Downtime Prediction
Topic 5 Presentation 5 Lesson 5 Corporate Fin
IBA_Chapter_11_Slides_Final_Accessible.pptx
Introduction to the R Programming Language

Softnix Security Data Lake