DZone
Thanks for visiting DZone today,
Edit Profile
  • Manage Email Subscriptions
  • How to Post to DZone
  • Article Submission Guidelines
Sign Out View Profile
  • Post an Article
  • Manage My Drafts
Over 2 million developers have joined DZone.
Log In / Join
Refcards Trend Reports Events Over 2 million developers have joined DZone. Join Today! Thanks for visiting DZone today,
Edit Profile Manage Email Subscriptions Moderation Admin Console How to Post to DZone Article Submission Guidelines
View Profile
Sign Out
Refcards
Trend Reports
Events
Zones
Culture and Methodologies Agile Career Development Methodologies Team Management
Data Engineering AI/ML Big Data Data Databases IoT
Software Design and Architecture Cloud Architecture Containers Integration Microservices Performance Security
Coding Frameworks Java JavaScript Languages Tools
Testing, Deployment, and Maintenance Deployment DevOps and CI/CD Maintenance Monitoring and Observability Testing, Tools, and Frameworks
Partner Zones AWS Cloud
by AWS Developer Relations
Culture and Methodologies
Agile Career Development Methodologies Team Management
Data Engineering
AI/ML Big Data Data Databases IoT
Software Design and Architecture
Cloud Architecture Containers Integration Microservices Performance Security
Coding
Frameworks Java JavaScript Languages Tools
Testing, Deployment, and Maintenance
Deployment DevOps and CI/CD Maintenance Monitoring and Observability Testing, Tools, and Frameworks
Partner Zones
AWS Cloud
by AWS Developer Relations
Securing Your Software Supply Chain with JFrog and Azure
Register Today

Trending

  • Competing Consumers With Spring Boot and Hazelcast
  • Observability Architecture: Financial Payments Introduction
  • The SPACE Framework for Developer Productivity
  • Operator Overloading in Java

Trending

  • Competing Consumers With Spring Boot and Hazelcast
  • Observability Architecture: Financial Payments Introduction
  • The SPACE Framework for Developer Productivity
  • Operator Overloading in Java
  1. DZone
  2. Data Engineering
  3. Big Data
  4. OpenSoc 101: Using Hadoop For Security

OpenSoc 101: Using Hadoop For Security

Hortonworks, Cisco, and a host of other contributors are working on a Hadoop-based, extensible security analytics tool.

Tim Spann user avatar by
Tim Spann
CORE ·
Jan. 09, 16 · News
Like (8)
Save
Tweet
Share
8.45K Views

Join the DZone community and get the full member experience.

Join For Free

OpenSOC is a great idea. It's a open source project using Hadoop to develop an extensible security analytics tool. Hortonworks and Cisco are working on it with a host of others. Security is something that could use an open project as all companies need this.  It's accessible code, so if you are a big data Java programmer with some Apache Storm, please consider it as a project to work on.  Coming from a security startup, I can tell you that you don't realize how insecure your network and servers are until you actively and passively scan from inside and outside and then analyze that huge volume of data. Download and install these open source tools and set it up.   After that you can quickly see what features you might want to contribute or documentation or just finding bugs.  Open Source works when everyone realizes they are on the team once they start using it. If you have no security scanning in place, download and setup a Kali box and start generating some data and find some glaring issues.  There are some great tools to check for SQL Injection, open ports and various issues. Kali is a great Linux distribution that is easy to setup and has all the tools you will need to scan for problems.

OpenSoc requires a lot of software, but it's items you should have in Hadoop cluster already:

  • Apache Flume 1.4.0 +
  • Apache Kafka 0.8.1+
  • Apache Storm 0.9 +
  • Apache Hadoop 2.x (any distribution)
  • Apache Hive 12 + (13 recommended)
  • Apache Hbase 0.94+
  • Elastic Search 1.1 +
  • MySQL 5.6+

You will also need a server with 2 network cards, OpenSoc has a suggestion for which type if you haven't purchased a server for this purpose yet.   To get things started look at the slides below and check out the wiki.

  • http://www.slideshare.net/Hadoop_Summit/analyzing-12-million-network-packets-per-second-in-realtime

  • https://github.com/OpenSOC/opensoc

  • http://www.slideshare.net/SheetalDolas/open-soc-v010

  • http://www.slideshare.net/JamesSirota/cisco-opensoc

  • http://www.slideshare.net/Hadoop_Summit/design-patterns-for-real-time-streaming-data-analytics

  • http://www.slideshare.net/JamesSirota/hadoop-summit-final

Spark

http://www.slideshare.net/Hadoop_Summit/spark-crash-course-workshop-at-hadoop-summit

hadoop security Open source Big data

Opinions expressed by DZone contributors are their own.

Trending

  • Competing Consumers With Spring Boot and Hazelcast
  • Observability Architecture: Financial Payments Introduction
  • The SPACE Framework for Developer Productivity
  • Operator Overloading in Java

Comments

Partner Resources

X

ABOUT US

  • About DZone
  • Send feedback
  • Careers
  • Sitemap

ADVERTISE

  • Advertise with DZone

CONTRIBUTE ON DZONE

  • Article Submission Guidelines
  • Become a Contributor
  • Visit the Writers' Zone

LEGAL

  • Terms of Service
  • Privacy Policy

CONTACT US

  • 600 Park Offices Drive
  • Suite 300
  • Durham, NC 27709
  • support@dzone.com

Let's be friends: