-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathflowchart2.code
More file actions
137 lines (119 loc) · 7.37 KB
/
Copy pathflowchart2.code
File metadata and controls
137 lines (119 loc) · 7.37 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
direction right
// Detection Phase
Detection Phase [icon: alert-triangle, color: orange] {
Falco [icon: shield, label: "Falco: Syscall rule-based anomaly detection"]
Detection API Gateway [icon: aws-api-gateway, label: "Amazon API Gateway: Trigger endpoint for alerts"]
Initial Alert Handler Lambda [icon: aws-lambda, label: "AWS Lambda (Alert Handler): Parses and logs Falco alerts"]
Detection CloudWatch Logs [icon: aws-cloudwatch, label: "Amazon CloudWatch Logs: Stores alert logs"]
}
// Unified Trigger System
Unified Trigger System [icon: shuffle, color: purple] {
Admission Controller [icon: kubernetes, label: "Kubernetes Admission Controller: Intercepts new pods"]
Event Processing Lambda [icon: aws-lambda, label: "AWS Lambda (Event Processor): Unifies detection events"]
Unified EventBridge [icon: aws-eventbridge, label: "Amazon EventBridge: Routes events to targets"]
SSM Parameter Store [icon: aws-ssm, label: "AWS SSM Parameter Store: Stores config and secrets"]
Unified CloudTrail [icon: aws-cloudtrail, label: "AWS CloudTrail: Logs AWS API events"]
}
// Collection Phase
Collection Phase [icon: search, color: blue] {
Forensic Collection Lambda [icon: aws-lambda, label: "AWS Lambda (Collector): Orchestrates evidence collection"]
EKS API Server [icon: k8s-api, label: "Amazon EKS API Server: Controls Kubernetes cluster"]
Forensic Sidecar Pod [icon: k8s-pod, label: "Kubernetes Pod: Sidecar collecting filesystem via docker diff/export/overlay + process info"]
Forensic Worker Node [icon: aws-ec2, label: "Amazon EC2 (K8s Node): Runs the container workload"]
Live Evidence [icon: file, label: "Captured Evidence: Filesystem (tar, overlay), process data"]
Encrypted EBS Volume [icon: aws-ebs, label: "Amazon EBS (Encrypted): Temporary disk for evidence"]
Amazon ECR [icon: aws-ecr, label: "Amazon ECR: Stores forensic sidecar container image"]
}
// Privileged DaemonSet
Privileged DaemonSet [icon: shield, color: red] {
DaemonSet Agent [icon: k8s-daemonset, label: "Kubernetes DaemonSet Agent: Runs on every node"]
eBPF Kernel Programs [icon: cpu, label: "eBPF: Syscall tracing programs"]
Tracing Agent [icon: activity, label: "Tracing Agent: Buffers syscall data and writes to DynamoDB every 10s"]
DaemonSet CloudWatch Logs [icon: aws-cloudwatch, label: "Amazon CloudWatch Logs: Stores syscall logs"]
"DaemonSet X-Ray" [icon: aws-xray, label: "AWS X-Ray: Distributed tracing of agent activity"]
}
// Secure Evidence Storage
Secure Evidence Storage [icon: lock, color: green] {
Evidence S3 [icon: aws-s3, label: "Amazon S3: Evidence bucket with Object Lock"]
Evidence KMS [icon: aws-kms, label: "AWS KMS: Encrypts evidence at rest"]
Evidence DynamoDB [icon: aws-dynamodb, label: "Amazon DynamoDB: Stores metadata, syscall logs (TTL 30 mins), and hash info"]
Storage CloudTrail [icon: aws-cloudtrail, label: "AWS CloudTrail: Logs access to S3 and DynamoDB"]
}
// Automated Analysis
Automated Analysis [icon: cpu, color: blue] {
Analysis Step Functions [icon: aws-step-functions, label: "AWS Step Functions: Orchestrates analysis workflow"]
Analysis Batch [icon: aws-batch, label: "AWS Batch/ECS: Runs forensic tools (e.g. Sleuth Kit CLI, Volatility)"]
Artifact Parsers [icon: code, label: "Memory & Artifact Parsers: Extracts structured data"]
TSK Tools [icon: code, label: "TSK Toolset: Uses tsk_recover/mmls/fls to analyze disk.img"]
Preliminary Findings [icon: file-text, label: "Preliminary Findings: Intermediate analysis output"]
Analysis Redis [icon: redis, label: "Amazon ElastiCache Redis: Caches analysis data"]
}
// AI-Powered Intelligence
"AI-Powered Intelligence" [icon: brain, color: purple] {
Intelligence OpenSearch [icon: aws-opensearch, label: "Amazon OpenSearch: Indexed document and logs"]
Intelligence Bedrock [icon: aws-bedrock, label: "AWS Bedrock (LLM): Natural language summaries"]
Threat Summaries [icon: file-text, label: "Threat Summaries: LLM-generated narratives"]
Intelligence Timestream [icon: aws-timestream, label: "Amazon Timestream: Time-series event data"]
Timeline Generator [icon: clock, label: "Timeline Generator: Creates forensic timelines"]
}
// Reporting Phase
Reporting Phase [icon: bar-chart, color: yellow] {
Reporting QuickSight [icon: aws-quicksight, label: "Amazon QuickSight: Forensic dashboards"]
Analyst Portal [icon: monitor, label: "Web Analyst Portal: UI for human review"]
Report Lambda [icon: aws-lambda, label: "AWS Lambda (Report): Assembles final report"]
PDF Report [icon: file, label: "PDF Report: Final deliverable"]
Reporting SES [icon: aws-ses, label: "Amazon SES: Sends email reports"]
Reporting CloudFront [icon: aws-cloudfront, label: "Amazon CloudFront: Serves analyst portal"]
External API Gateway [icon: aws-api-gateway, label: "Amazon API Gateway: Access for external tools"]
}
// Connections
// Detection Phase
Falco > Detection API Gateway: webhook alert
Detection API Gateway > Initial Alert Handler Lambda: triggers
Initial Alert Handler Lambda > Detection CloudWatch Logs: log alert
// Unified Trigger System
Admission Controller > Event Processing Lambda: intercept pod events
Initial Alert Handler Lambda > Event Processing Lambda: send Falco alert
Event Processing Lambda > Unified EventBridge: add metadata
Event Processing Lambda <-- SSM Parameter Store: config/secrets
Event Processing Lambda <-- Unified CloudTrail: AWS API audit logs
// Collection Phase
Unified EventBridge > Forensic Collection Lambda: trigger collection
Forensic Collection Lambda > EKS API Server: describe pod
EKS API Server > Forensic Sidecar Pod: deploy sidecar
Amazon ECR --> Forensic Sidecar Pod: pull forensic image
Forensic Sidecar Pod > Forensic Worker Node: run on node
Forensic Worker Node > Live Evidence: capture filesystem and process data
Live Evidence > Encrypted EBS Volume: write artifacts
Live Evidence > Evidence S3: upload with hash
// Privileged DaemonSet
DaemonSet Agent > eBPF Kernel Programs: host access
eBPF Kernel Programs > Tracing Agent: hook syscalls
Tracing Agent > DaemonSet CloudWatch Logs: real-time logs
Tracing Agent > Evidence DynamoDB: store syscall data (TTL 30 mins)
Tracing Agent <-- "DaemonSet X-Ray": trace interactions
// Secure Evidence Storage
Evidence KMS --> Evidence S3: encryption
Evidence S3 > Evidence DynamoDB: store metadata
Storage CloudTrail --> Evidence DynamoDB: track access
// Automated Analysis
Evidence S3 > Analysis Step Functions: trigger workflow
Analysis Step Functions > Analysis Batch: schedule analysis
Analysis Batch > TSK Tools: run disk image analysis (mmls, fls, tsk_recover)
Analysis Batch > Artifact Parsers: extract data from filesystem & memory
Artifact Parsers > Preliminary Findings: yield findings
Analysis Redis <-> Preliminary Findings: cache lookups
Preliminary Findings > Evidence DynamoDB: insert for search
Evidence DynamoDB > Intelligence OpenSearch: index docs
Intelligence OpenSearch > Intelligence Bedrock: vector embeddings
Intelligence Bedrock > Threat Summaries: narrative summaries
Evidence DynamoDB > Intelligence Timestream: events/timestamps
Intelligence Timestream > Timeline Generator: generate timeline
// Reporting Phase
Evidence DynamoDB > Reporting QuickSight: findings/metadata
Reporting QuickSight > Analyst Portal: dashboard
Threat Summaries > Report Lambda: feed summaries
Report Lambda > PDF Report: produce report
PDF Report > Reporting SES: send email
Analyst Portal > Reporting CloudFront: serve via CDN
Evidence DynamoDB <> External API Gateway: third-party tools