3 ms·
> Anyways, my solution currently is a peer-to-peer approach where the systems themselves decide to mitigate issues, propagate patches (or even vaccines for zero
by helloooooooo 3y ago
> Anyways, my solution currently is a peer-to-peer approach where the systems themselves decide to mitigate issues, propagate patches (or even vaccines for zero-days) and also share incidents that look suspicious, so the surrounding nodes can start to quarantine themselves off, for example, when something really bad happened.
How do you intend to run analytics on a single node? A modern EDR needs a lot of processing power to analyze logs. You are going to have to push down potentially sensitive analytics to endpoints, and have the potentially compromised endpoint decide what to share. How is this scenario accounted for?
- cookiengineer 3y ago> How do you intend to run analytics on a single node? A modern EDR needs a lot of processing power to analyze logs eBPF solves the performance problem, as it's blazingly fast and can run as an IDS/packet filter _before_ the data packets even reach the Kernelspace. A lot of drivers have support for it already, and some Smart NICS in data centers allow even offloading it to the NIC directly. Most of the analytics and incident generators that are already integrated are in the milliseconds-range, as this approach does not need to push Petabytes of data to a centralized ELK cluster. The noise is already filtered out based on the processes that are running, and a combination of detection mechanisms ranging from execve kernelprobes and XDP programs filtering the network traffic up to analyzing what's going on in /proc/ and /sys/. > You are going to have to push down potentially sensitive analytics to endpoints, and have the potentially compromised endpoint decide what to share. How is this scenario accounted for? This scenario is actually accounted for already. Agents only share the processed strategies (incidents/mitigations/aggrevations) with each other, having the idea that these represent the state of "what type of malicious behaviour" and "what type of target/source" was communicated. This can be something as simple as the www-data user suddenly executing "whoami" up to a malicious recorded network payload that resulted in a zeroday and changed the library.so files on the filesystem or led to e.g. an "nc" backdoor. The beauty of golang and eBPF is that they play very well together in this regard, and don't sacrifice performance like e.g. python or other scripting languages would.