Overview
There are a lot of interesting cases which you can find while investigating anomalies in the traffic baselines, for example in FTP, SSH, or HTTPS. This guide describes using the Imperva WAF - Kibana Dashboard, Watchers and Machine Learning for ELK Stack Content Pack to detect abnormal spikes of attacks identified by WAF from a single IP to a single web application.
Downloading Content Pack for Detecting Network Spikes for the Elastic Stack
Log in to the SOC Prime Platform with your user credentials.
Go to Content > Advanced Search, select Content Pack in the Content Type filter and click Apply.
In the Search field, enter “imperva waf”.
Select the Content Pack to open its page.
Check the Dependencies and Log Source Requirements sections to make sure your system is suitable for the content deployment.
Click the Download button.
Deploying Content into Your Kibana Instance
Log in to your Kibana and import content using the following steps:
Create a new ML (Machine Learning) job by clicking the Create new job button in the upper right-hand corner of the page.
Select the required index pattern or a saved search Imperva WAF logs.
Select the Advanced tile from the list of wizards to create the advanced job.
In the Edit JSON tab, paste the JSON configuration of the downloaded ML Job.
Click the Next button to pass validation.
Note:
In case you have a different field template, please make the corresponding changes in the JSON code.
After successful validation, save the changes to complete the job creating by clicking the Start button. Here you can specify the time frame or set the job to Real-time search.
As a result, you will get the visualization of network spikes or abnormal SSH traffic activity that needs investigation.
Content Rating & Reviewing
We encourage security practitioners to leave a review on the recently explored threat detection content so we can make your experience with the SOC Prime Platform even better and increase the content quality.
To share your feedback on the downloaded content:
Click the Write Review button if the review panel is hidden.
Choose how to provide your feedback.
Rate content using the star rating system
Write your review on the content quality
For an anonymous review, select the corresponding checkbox.
Click the Submit button.
Troubleshooting
If you have encountered any issues and need assistance, contact us in the live chat available on any page of the SOC Prime Platform:
