Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Integrate threat intel feeds #669

Merged
merged 39 commits into from
Oct 25, 2023
Merged

Integrate threat intel feeds #669

merged 39 commits into from
Oct 25, 2023

Conversation

eirsep
Copy link
Member

@eirsep eirsep commented Oct 16, 2023

Description


Job Scheduler and threat intel feed Integration

  • Integrates Job Scheduler Plugin in Security Analytics
  • Adds framework in Security Analytics for configuring pre-package feeds.
  • Adds support for job to constantly update system indices with feed data
  • Configures 1 free feed - otx alienvault ip reputation ( a feed of malicious IPs)
  • Adds support for IoC(indicator of Compromise) To ECS Field mapping for each log type which tells us fields where the given type of IoC may occur
  • Feed data is stored in system indices. new data is populated in new system index and the old index is deleted.

Detector creation/updation flow changes

  • Adds framework to convert threat intel IoCs data into doc level queries
  • new boolean field added to Detector model - threat_intel_enabled. (Value is False by default). If set to true, we will create threat intel data based queries
  • When feed data is updated, all detectors having threat intel data are also updated with queries built from the fresh feeds
  • Doc level monitor created to execute sigma rules will have new queries.

Detector trigger:

  • Detector trigger now supports new field detection_types which is a list with 2 possible values "rules" and "threat_intel"
  • If trigger is configured and detection_types is passed with only "rules" in the list , we will create alerts when documents match sigma rules.
  • If detection_types is passed with only "threat_intel" in the list , we will create alerts when documents match threat intel based queries.
  • If detection_types is passed with both "rules" and "threat_intel" in the list , we will create alerts when documents match either sigma rules or threat intel based queries
  • Detection types list param cannot be empty.

Detector findings and threat_intel_based queries:

  • Findings created from matching threat intel based queries will contain the tags threat_intel, ioc_type:<ioc_type>, "field:<field>, feed_name:<feed_name>
  • Threat intel based queries will have query id starting with the prefix threat_intel
  • Threat intel based queries will have severity level high

Get Mapping VIew changes:

  • We have added a new field threat_intel_field_aliases which returns a list of field aliases per ioc for each log type that the user needs to provide mappings for, from his source data.

Issues Resolved

Threat intel feeds in Security Analytics

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

eirsep and others added 15 commits October 16, 2023 15:18
Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Surya Sashank Nistala <[email protected]>
* fix doc level query constructor (#651)

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (#626)


Signed-off-by: Joanne Wang <[email protected]>

* with listener and processor

Signed-off-by: Joanne Wang <[email protected]>

* removed actions

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* added parser

Signed-off-by: Joanne Wang <[email protected]>

* add unit tests

Signed-off-by: Joanne Wang <[email protected]>

* refactored class names

Signed-off-by: Joanne Wang <[email protected]>

* before moving db

Signed-off-by: Joanne Wang <[email protected]>

* after moving db

Signed-off-by: Joanne Wang <[email protected]>

* added actions to plugin and removed user schedule

Signed-off-by: Joanne Wang <[email protected]>

* unit tests

Signed-off-by: Joanne Wang <[email protected]>

* fix build error

Signed-off-by: Joanne Wang <[email protected]>

* changed transport naming

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>
@eirsep eirsep force-pushed the feature/threat_intel_feeds branch from 721364e to c7a0a2a Compare October 16, 2023 22:18
@eirsep eirsep force-pushed the feature/threat_intel_feeds branch from 89984cb to 98bbd42 Compare October 16, 2023 22:23
Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Surya Sashank Nistala <[email protected]>
@eirsep eirsep force-pushed the feature/threat_intel_feeds branch from 8d27781 to a79b8ac Compare October 17, 2023 01:17
eirsep and others added 2 commits October 17, 2023 02:09
* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (#626)


Signed-off-by: Joanne Wang <[email protected]>

* create doc level query from threat intel feed data index docs"

Signed-off-by: Surya Sashank Nistala <[email protected]>

* handle threat intel enabled check during detector updation

* add tests for testing threat intel feed integration with detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Threat intel feeds job runner and unit tests (#654)

* fix doc level query constructor (#651)

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (#626)


Signed-off-by: Joanne Wang <[email protected]>

* with listener and processor

Signed-off-by: Joanne Wang <[email protected]>

* removed actions

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* added parser

Signed-off-by: Joanne Wang <[email protected]>

* add unit tests

Signed-off-by: Joanne Wang <[email protected]>

* refactored class names

Signed-off-by: Joanne Wang <[email protected]>

* before moving db

Signed-off-by: Joanne Wang <[email protected]>

* after moving db

Signed-off-by: Joanne Wang <[email protected]>

* added actions to plugin and removed user schedule

Signed-off-by: Joanne Wang <[email protected]>

* unit tests

Signed-off-by: Joanne Wang <[email protected]>

* fix build error

Signed-off-by: Joanne Wang <[email protected]>

* changed transport naming

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>

* converge job scheduler code with threat intel feed integration in detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* refactored out unecessary

Signed-off-by: Joanne Wang <[email protected]>

* added headers and cleaned up

Signed-off-by: Joanne Wang <[email protected]>

* converge job scheduler and detector threat intel code

Signed-off-by: Surya Sashank Nistala <[email protected]>

* working on testing

Signed-off-by: Joanne Wang <[email protected]>

* fixed the parser and build.gradle

Signed-off-by: Joanne Wang <[email protected]>

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (#626)


Signed-off-by: Joanne Wang <[email protected]>

* create doc level query from threat intel feed data index docs"

Signed-off-by: Surya Sashank Nistala <[email protected]>

* handle threat intel enabled check during detector updation

* add tests for testing threat intel feed integration with detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Threat intel feeds job runner and unit tests (#654)

* fix doc level query constructor (#651)

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (#626)


Signed-off-by: Joanne Wang <[email protected]>

* with listener and processor

Signed-off-by: Joanne Wang <[email protected]>

* removed actions

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* added parser

Signed-off-by: Joanne Wang <[email protected]>

* add unit tests

Signed-off-by: Joanne Wang <[email protected]>

* refactored class names

Signed-off-by: Joanne Wang <[email protected]>

* before moving db

Signed-off-by: Joanne Wang <[email protected]>

* after moving db

Signed-off-by: Joanne Wang <[email protected]>

* added actions to plugin and removed user schedule

Signed-off-by: Joanne Wang <[email protected]>

* unit tests

Signed-off-by: Joanne Wang <[email protected]>

* fix build error

Signed-off-by: Joanne Wang <[email protected]>

* changed transport naming

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>

* converge job scheduler code with threat intel feed integration in detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* converge job scheduler and detector threat intel code

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add feed metadata config files in src and test

Signed-off-by: Surya Sashank Nistala <[email protected]>

* clean up some tests

Signed-off-by: Joanne Wang <[email protected]>

* fixed merge conflicts

Signed-off-by: Joanne Wang <[email protected]>

* adds ioc fields list in log type config files and ioc fields object in LogType POJO

* update csv parser and new metadata field

Signed-off-by: Joanne Wang <[email protected]>

* fixed job scheduler interval settings

Signed-off-by: Joanne Wang <[email protected]>

* add tests for ioc to fields for each log type

Signed-off-by: Surya Sashank Nistala <[email protected]>

* removed wildcards

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Joanne Wang <[email protected]>
Co-authored-by: Joanne Wang <[email protected]>
@eirsep eirsep force-pushed the feature/threat_intel_feeds branch from 1a5ab82 to f2068f1 Compare October 22, 2023 10:44
Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Surya Sashank Nistala <[email protected]>
@codecov
Copy link

codecov bot commented Oct 25, 2023

Codecov Report

Merging #669 (bed73ff) into main (294785f) will increase coverage by 1.92%.
The diff coverage is 43.11%.

@@             Coverage Diff              @@
##               main     #669      +/-   ##
============================================
+ Coverage     25.04%   26.96%   +1.92%     
- Complexity      946     1068     +122     
============================================
  Files           255      274      +19     
  Lines         11158    12345    +1187     
  Branches       1250     1342      +92     
============================================
+ Hits           2794     3329     +535     
- Misses         8111     8743     +632     
- Partials        253      273      +20     
Files Coverage Δ
...yanalytics/settings/SecurityAnalyticsSettings.java 96.87% <100.00%> (+0.87%) ⬆️
...urityanalytics/threatIntel/common/TIFJobState.java 100.00% <100.00%> (ø)
...tics/transport/TransportGetMappingsViewAction.java 0.00% <ø> (ø)
...opensearch/securityanalytics/util/RuleIndices.java 0.00% <ø> (ø)
.../securityanalytics/action/GetDetectorResponse.java 18.91% <0.00%> (-0.53%) ⬇️
...ecurityanalytics/action/IndexDetectorResponse.java 57.14% <0.00%> (-1.69%) ⬇️
...ytics/threatintel/common/StashedThreadContext.java 83.33% <83.33%> (ø)
...analytics/threatIntel/action/PutTIFJobRequest.java 90.90% <90.90%> (ø)
...ecurityanalytics/threatIntel/common/Constants.java 0.00% <0.00%> (ø)
...ytics/transport/TransportSearchDetectorAction.java 0.00% <0.00%> (ø)
... and 24 more

Dockerfile Outdated
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

remove

// create doc
for (String field : fields) {
queries.add(new DocLevelQuery(
constructId(detector, entry.getKey()), tifdList.get(0).getFeedId(),
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why are we getting the feed id based on the first item in tifdList? Is it the same throughout?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Currently yes,

Signed-off-by: Joanne Wang <[email protected]>
@amsiglan amsiglan merged commit 884ddd0 into main Oct 25, 2023
5 of 15 checks passed
@opensearch-trigger-bot
Copy link
Contributor

The backport to 2.x failed:

The process '/usr/bin/git' failed with exit code 1

To backport manually, run these commands in your terminal:

# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add .worktrees/backport-2.x 2.x
# Navigate to the new working tree
cd .worktrees/backport-2.x
# Create a new branch
git switch --create backport/backport-669-to-2.x
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 884ddd04f63fb833153beaaeeb4ffd28ed5b395c
# Push it to GitHub
git push --set-upstream origin backport/backport-669-to-2.x
# Go back to the original working tree
cd ../..
# Delete the working tree
git worktree remove .worktrees/backport-2.x

Then, create a pull request where the base branch is 2.x and the compare/head branch is backport/backport-669-to-2.x.

@opensearch-trigger-bot
Copy link
Contributor

The backport to 2.11 failed:

The process '/usr/bin/git' failed with exit code 1

To backport manually, run these commands in your terminal:

# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add .worktrees/backport-2.11 2.11
# Navigate to the new working tree
cd .worktrees/backport-2.11
# Create a new branch
git switch --create backport/backport-669-to-2.11
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 884ddd04f63fb833153beaaeeb4ffd28ed5b395c
# Push it to GitHub
git push --set-upstream origin backport/backport-669-to-2.11
# Go back to the original working tree
cd ../..
# Delete the working tree
git worktree remove .worktrees/backport-2.11

Then, create a pull request where the base branch is 2.11 and the compare/head branch is backport/backport-669-to-2.11.

jowg-amazon added a commit to jowg-amazon/security-analytics that referenced this pull request Oct 26, 2023
* add mapping for indices storing threat intel feed data

Signed-off-by: Surya Sashank Nistala <[email protected]>

* fix feed indices mapping

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

Signed-off-by: Surya Sashank Nistala <[email protected]>

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (opensearch-project#626)

Signed-off-by: Joanne Wang <[email protected]>

* create doc level query from threat intel feed data index docs"

Signed-off-by: Surya Sashank Nistala <[email protected]>

* handle threat intel enabled check during detector updation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add tests for testing threat intel feed integration with detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Threat intel feeds job runner and unit tests (opensearch-project#654)

* fix doc level query constructor (opensearch-project#651)

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (opensearch-project#626)

Signed-off-by: Joanne Wang <[email protected]>

* with listener and processor

Signed-off-by: Joanne Wang <[email protected]>

* removed actions

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* added parser

Signed-off-by: Joanne Wang <[email protected]>

* add unit tests

Signed-off-by: Joanne Wang <[email protected]>

* refactored class names

Signed-off-by: Joanne Wang <[email protected]>

* before moving db

Signed-off-by: Joanne Wang <[email protected]>

* after moving db

Signed-off-by: Joanne Wang <[email protected]>

* added actions to plugin and removed user schedule

Signed-off-by: Joanne Wang <[email protected]>

* unit tests

Signed-off-by: Joanne Wang <[email protected]>

* fix build error

Signed-off-by: Joanne Wang <[email protected]>

* changed transport naming

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>

* converge job scheduler code with threat intel feed integration in detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* converge job scheduler and detector threat intel code

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add feed metadata config files in src and test

Signed-off-by: Surya Sashank Nistala <[email protected]>

* adds ioc fields list in log type config files and ioc fields object in LogType POJO

Signed-off-by: Surya Sashank Nistala <[email protected]>

* fix compilation issues in tests

Signed-off-by: Surya Sashank Nistala <[email protected]>

* test udpate detector disabling threat intel

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add tests for detector creation and updation with threat intel

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Threat intel test (opensearch-project#673)

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (opensearch-project#626)

Signed-off-by: Joanne Wang <[email protected]>

* create doc level query from threat intel feed data index docs"

Signed-off-by: Surya Sashank Nistala <[email protected]>

* handle threat intel enabled check during detector updation

* add tests for testing threat intel feed integration with detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Threat intel feeds job runner and unit tests (opensearch-project#654)

* fix doc level query constructor (opensearch-project#651)

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (opensearch-project#626)

Signed-off-by: Joanne Wang <[email protected]>

* with listener and processor

Signed-off-by: Joanne Wang <[email protected]>

* removed actions

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* added parser

Signed-off-by: Joanne Wang <[email protected]>

* add unit tests

Signed-off-by: Joanne Wang <[email protected]>

* refactored class names

Signed-off-by: Joanne Wang <[email protected]>

* before moving db

Signed-off-by: Joanne Wang <[email protected]>

* after moving db

Signed-off-by: Joanne Wang <[email protected]>

* added actions to plugin and removed user schedule

Signed-off-by: Joanne Wang <[email protected]>

* unit tests

Signed-off-by: Joanne Wang <[email protected]>

* fix build error

Signed-off-by: Joanne Wang <[email protected]>

* changed transport naming

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>

* converge job scheduler code with threat intel feed integration in detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* refactored out unecessary

Signed-off-by: Joanne Wang <[email protected]>

* added headers and cleaned up

Signed-off-by: Joanne Wang <[email protected]>

* converge job scheduler and detector threat intel code

Signed-off-by: Surya Sashank Nistala <[email protected]>

* working on testing

Signed-off-by: Joanne Wang <[email protected]>

* fixed the parser and build.gradle

Signed-off-by: Joanne Wang <[email protected]>

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (opensearch-project#626)

Signed-off-by: Joanne Wang <[email protected]>

* create doc level query from threat intel feed data index docs"

Signed-off-by: Surya Sashank Nistala <[email protected]>

* handle threat intel enabled check during detector updation

* add tests for testing threat intel feed integration with detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Threat intel feeds job runner and unit tests (opensearch-project#654)

* fix doc level query constructor (opensearch-project#651)

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (opensearch-project#626)

Signed-off-by: Joanne Wang <[email protected]>

* with listener and processor

Signed-off-by: Joanne Wang <[email protected]>

* removed actions

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* added parser

Signed-off-by: Joanne Wang <[email protected]>

* add unit tests

Signed-off-by: Joanne Wang <[email protected]>

* refactored class names

Signed-off-by: Joanne Wang <[email protected]>

* before moving db

Signed-off-by: Joanne Wang <[email protected]>

* after moving db

Signed-off-by: Joanne Wang <[email protected]>

* added actions to plugin and removed user schedule

Signed-off-by: Joanne Wang <[email protected]>

* unit tests

Signed-off-by: Joanne Wang <[email protected]>

* fix build error

Signed-off-by: Joanne Wang <[email protected]>

* changed transport naming

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>

* converge job scheduler code with threat intel feed integration in detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* converge job scheduler and detector threat intel code

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add feed metadata config files in src and test

Signed-off-by: Surya Sashank Nistala <[email protected]>

* clean up some tests

Signed-off-by: Joanne Wang <[email protected]>

* fixed merge conflicts

Signed-off-by: Joanne Wang <[email protected]>

* adds ioc fields list in log type config files and ioc fields object in LogType POJO

* update csv parser and new metadata field

Signed-off-by: Joanne Wang <[email protected]>

* fixed job scheduler interval settings

Signed-off-by: Joanne Wang <[email protected]>

* add tests for ioc to fields for each log type

Signed-off-by: Surya Sashank Nistala <[email protected]>

* removed wildcards

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Joanne Wang <[email protected]>
Co-authored-by: Joanne Wang <[email protected]>

* fix threat intel integ tests and add update detector logic

Signed-off-by: Surya Sashank Nistala <[email protected]>

* JS for Threat intel feeds - changed extension (opensearch-project#675)

* merge conflicts

Signed-off-by: Joanne Wang <[email protected]>

* fixed java wildcards and changed update key name

Signed-off-by: Joanne Wang <[email protected]>

* integ test failing

Signed-off-by: Joanne Wang <[email protected]>

* fix job scheduler params

Signed-off-by: Joanne Wang <[email protected]>

* changed extension and has debug messages

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* fixed job scheduler plugin spi jar resolution

* cleaned up TODOs and changed job scheduler name

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>

* TIF Job Runner Cleanup (opensearch-project#676)

* merge conflicts

Signed-off-by: Joanne Wang <[email protected]>

* fixed java wildcards and changed update key name

Signed-off-by: Joanne Wang <[email protected]>

* integ test failing

Signed-off-by: Joanne Wang <[email protected]>

* fix job scheduler params

Signed-off-by: Joanne Wang <[email protected]>

* changed extension and has debug messages

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* fixed job scheduler plugin spi jar resolution

* cleaned up TODOs and changed job scheduler name

Signed-off-by: Joanne Wang <[email protected]>

* removed google commons unused import, updated interval setting, removed rest action

Signed-off-by: Joanne Wang <[email protected]>

* removed policy file and updated name for job scheduler

Signed-off-by: Joanne Wang <[email protected]>

* responded to comments about parameter validator and TIFMetadata

Signed-off-by: Joanne Wang <[email protected]>

* refactored ThreatIntelFeedDataService and changed variables to public static final where possible

Signed-off-by: Joanne Wang <[email protected]>

* changed opensearch-sap-threatintel to opensearch-sap-threat-intel

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>

* fix TIFJobParameter class

Signed-off-by: Surya Sashank Nistala <[email protected]>

* test detector updation when feed updation job runs

Signed-off-by: Surya Sashank Nistala <[email protected]>

* removed delete job scheduler code and cleaned up (opensearch-project#678)

Signed-off-by: Joanne Wang <[email protected]>

* working integ test (opensearch-project#680)

Signed-off-by: Joanne Wang <[email protected]>

* fix timeout of tif job creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* remove unncessary thread forking in put tif job action

Signed-off-by: Surya Sashank Nistala <[email protected]>

* refactoring code to address review comments

Signed-off-by: Surya Sashank Nistala <[email protected]>

* detector trigger detection types
Signed-off-by: Surya Sashank Nistala <[email protected]>

* pull out threat intel rest tests into separate test class

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add detection types testing in detector trigger for rules and threat intel detection scenarios

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add license header

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel field aliases in mapping view response

Signed-off-by: Surya Sashank Nistala <[email protected]>

* fix threat intel feed parser

Signed-off-by: Surya Sashank Nistala <[email protected]>

* fix workflow failing test

Signed-off-by: Surya Sashank Nistala <[email protected]>

* spotless check failures fixed

Signed-off-by: Surya Sashank Nistala <[email protected]>

* remove dockerfile (opensearch-project#689)

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Joanne Wang <[email protected]>
Co-authored-by: Joanne Wang <[email protected]>
jowg-amazon added a commit to jowg-amazon/security-analytics that referenced this pull request Oct 26, 2023
* add mapping for indices storing threat intel feed data

Signed-off-by: Surya Sashank Nistala <[email protected]>

* fix feed indices mapping

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

Signed-off-by: Surya Sashank Nistala <[email protected]>

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (opensearch-project#626)

Signed-off-by: Joanne Wang <[email protected]>

* create doc level query from threat intel feed data index docs"

Signed-off-by: Surya Sashank Nistala <[email protected]>

* handle threat intel enabled check during detector updation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add tests for testing threat intel feed integration with detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Threat intel feeds job runner and unit tests (opensearch-project#654)

* fix doc level query constructor (opensearch-project#651)

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (opensearch-project#626)

Signed-off-by: Joanne Wang <[email protected]>

* with listener and processor

Signed-off-by: Joanne Wang <[email protected]>

* removed actions

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* added parser

Signed-off-by: Joanne Wang <[email protected]>

* add unit tests

Signed-off-by: Joanne Wang <[email protected]>

* refactored class names

Signed-off-by: Joanne Wang <[email protected]>

* before moving db

Signed-off-by: Joanne Wang <[email protected]>

* after moving db

Signed-off-by: Joanne Wang <[email protected]>

* added actions to plugin and removed user schedule

Signed-off-by: Joanne Wang <[email protected]>

* unit tests

Signed-off-by: Joanne Wang <[email protected]>

* fix build error

Signed-off-by: Joanne Wang <[email protected]>

* changed transport naming

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>

* converge job scheduler code with threat intel feed integration in detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* converge job scheduler and detector threat intel code

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add feed metadata config files in src and test

Signed-off-by: Surya Sashank Nistala <[email protected]>

* adds ioc fields list in log type config files and ioc fields object in LogType POJO

Signed-off-by: Surya Sashank Nistala <[email protected]>

* fix compilation issues in tests

Signed-off-by: Surya Sashank Nistala <[email protected]>

* test udpate detector disabling threat intel

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add tests for detector creation and updation with threat intel

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Threat intel test (opensearch-project#673)

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (opensearch-project#626)

Signed-off-by: Joanne Wang <[email protected]>

* create doc level query from threat intel feed data index docs"

Signed-off-by: Surya Sashank Nistala <[email protected]>

* handle threat intel enabled check during detector updation

* add tests for testing threat intel feed integration with detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Threat intel feeds job runner and unit tests (opensearch-project#654)

* fix doc level query constructor (opensearch-project#651)

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (opensearch-project#626)

Signed-off-by: Joanne Wang <[email protected]>

* with listener and processor

Signed-off-by: Joanne Wang <[email protected]>

* removed actions

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* added parser

Signed-off-by: Joanne Wang <[email protected]>

* add unit tests

Signed-off-by: Joanne Wang <[email protected]>

* refactored class names

Signed-off-by: Joanne Wang <[email protected]>

* before moving db

Signed-off-by: Joanne Wang <[email protected]>

* after moving db

Signed-off-by: Joanne Wang <[email protected]>

* added actions to plugin and removed user schedule

Signed-off-by: Joanne Wang <[email protected]>

* unit tests

Signed-off-by: Joanne Wang <[email protected]>

* fix build error

Signed-off-by: Joanne Wang <[email protected]>

* changed transport naming

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>

* converge job scheduler code with threat intel feed integration in detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* refactored out unecessary

Signed-off-by: Joanne Wang <[email protected]>

* added headers and cleaned up

Signed-off-by: Joanne Wang <[email protected]>

* converge job scheduler and detector threat intel code

Signed-off-by: Surya Sashank Nistala <[email protected]>

* working on testing

Signed-off-by: Joanne Wang <[email protected]>

* fixed the parser and build.gradle

Signed-off-by: Joanne Wang <[email protected]>

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (opensearch-project#626)

Signed-off-by: Joanne Wang <[email protected]>

* create doc level query from threat intel feed data index docs"

Signed-off-by: Surya Sashank Nistala <[email protected]>

* handle threat intel enabled check during detector updation

* add tests for testing threat intel feed integration with detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Threat intel feeds job runner and unit tests (opensearch-project#654)

* fix doc level query constructor (opensearch-project#651)

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threatIntelEnabled field in detector.

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel feed service and searching feeds

Signed-off-by: Surya Sashank Nistala <[email protected]>

* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* Preliminary framework for jobscheduler and datasource (opensearch-project#626)

Signed-off-by: Joanne Wang <[email protected]>

* with listener and processor

Signed-off-by: Joanne Wang <[email protected]>

* removed actions

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* added parser

Signed-off-by: Joanne Wang <[email protected]>

* add unit tests

Signed-off-by: Joanne Wang <[email protected]>

* refactored class names

Signed-off-by: Joanne Wang <[email protected]>

* before moving db

Signed-off-by: Joanne Wang <[email protected]>

* after moving db

Signed-off-by: Joanne Wang <[email protected]>

* added actions to plugin and removed user schedule

Signed-off-by: Joanne Wang <[email protected]>

* unit tests

Signed-off-by: Joanne Wang <[email protected]>

* fix build error

Signed-off-by: Joanne Wang <[email protected]>

* changed transport naming

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>

* converge job scheduler code with threat intel feed integration in detectors

Signed-off-by: Surya Sashank Nistala <[email protected]>

* converge job scheduler and detector threat intel code

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add feed metadata config files in src and test

Signed-off-by: Surya Sashank Nistala <[email protected]>

* clean up some tests

Signed-off-by: Joanne Wang <[email protected]>

* fixed merge conflicts

Signed-off-by: Joanne Wang <[email protected]>

* adds ioc fields list in log type config files and ioc fields object in LogType POJO

* update csv parser and new metadata field

Signed-off-by: Joanne Wang <[email protected]>

* fixed job scheduler interval settings

Signed-off-by: Joanne Wang <[email protected]>

* add tests for ioc to fields for each log type

Signed-off-by: Surya Sashank Nistala <[email protected]>

* removed wildcards

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Joanne Wang <[email protected]>
Co-authored-by: Joanne Wang <[email protected]>

* fix threat intel integ tests and add update detector logic

Signed-off-by: Surya Sashank Nistala <[email protected]>

* JS for Threat intel feeds - changed extension (opensearch-project#675)

* merge conflicts

Signed-off-by: Joanne Wang <[email protected]>

* fixed java wildcards and changed update key name

Signed-off-by: Joanne Wang <[email protected]>

* integ test failing

Signed-off-by: Joanne Wang <[email protected]>

* fix job scheduler params

Signed-off-by: Joanne Wang <[email protected]>

* changed extension and has debug messages

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* fixed job scheduler plugin spi jar resolution

* cleaned up TODOs and changed job scheduler name

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>

* TIF Job Runner Cleanup (opensearch-project#676)

* merge conflicts

Signed-off-by: Joanne Wang <[email protected]>

* fixed java wildcards and changed update key name

Signed-off-by: Joanne Wang <[email protected]>

* integ test failing

Signed-off-by: Joanne Wang <[email protected]>

* fix job scheduler params

Signed-off-by: Joanne Wang <[email protected]>

* changed extension and has debug messages

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* fixed job scheduler plugin spi jar resolution

* cleaned up TODOs and changed job scheduler name

Signed-off-by: Joanne Wang <[email protected]>

* removed google commons unused import, updated interval setting, removed rest action

Signed-off-by: Joanne Wang <[email protected]>

* removed policy file and updated name for job scheduler

Signed-off-by: Joanne Wang <[email protected]>

* responded to comments about parameter validator and TIFMetadata

Signed-off-by: Joanne Wang <[email protected]>

* refactored ThreatIntelFeedDataService and changed variables to public static final where possible

Signed-off-by: Joanne Wang <[email protected]>

* changed opensearch-sap-threatintel to opensearch-sap-threat-intel

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>

* fix TIFJobParameter class

Signed-off-by: Surya Sashank Nistala <[email protected]>

* test detector updation when feed updation job runs

Signed-off-by: Surya Sashank Nistala <[email protected]>

* removed delete job scheduler code and cleaned up (opensearch-project#678)

Signed-off-by: Joanne Wang <[email protected]>

* working integ test (opensearch-project#680)

Signed-off-by: Joanne Wang <[email protected]>

* fix timeout of tif job creation

Signed-off-by: Surya Sashank Nistala <[email protected]>

* remove unncessary thread forking in put tif job action

Signed-off-by: Surya Sashank Nistala <[email protected]>

* refactoring code to address review comments

Signed-off-by: Surya Sashank Nistala <[email protected]>

* detector trigger detection types
Signed-off-by: Surya Sashank Nistala <[email protected]>

* pull out threat intel rest tests into separate test class

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add detection types testing in detector trigger for rules and threat intel detection scenarios

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add license header

Signed-off-by: Surya Sashank Nistala <[email protected]>

* add threat intel field aliases in mapping view response

Signed-off-by: Surya Sashank Nistala <[email protected]>

* fix threat intel feed parser

Signed-off-by: Surya Sashank Nistala <[email protected]>

* fix workflow failing test

Signed-off-by: Surya Sashank Nistala <[email protected]>

* spotless check failures fixed

Signed-off-by: Surya Sashank Nistala <[email protected]>

* remove dockerfile (opensearch-project#689)

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Joanne Wang <[email protected]>
Co-authored-by: Joanne Wang <[email protected]>
AWSHurneyt pushed a commit that referenced this pull request Oct 26, 2023
* add mapping for indices storing threat intel feed data



* fix feed indices mapping



* add threat intel feed data dao



* add threatIntelEnabled field in detector.



* add threat intel feed service and searching feeds



* ti feed data to doc level query convertor logic added



* plug threat intel feed into detector creation



* Preliminary framework for jobscheduler and datasource (#626)



* create doc level query from threat intel feed data index docs"



* handle threat intel enabled check during detector updation



* add tests for testing threat intel feed integration with detectors



* Threat intel feeds job runner and unit tests (#654)

* fix doc level query constructor (#651)



* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao



* add threatIntelEnabled field in detector.



* add threat intel feed service and searching feeds



* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation



* Preliminary framework for jobscheduler and datasource (#626)



* with listener and processor



* removed actions



* clean up



* added parser



* add unit tests



* refactored class names



* before moving db



* after moving db



* added actions to plugin and removed user schedule



* unit tests



* fix build error



* changed transport naming



---------





* converge job scheduler code with threat intel feed integration in detectors



* converge job scheduler and detector threat intel code



* add feed metadata config files in src and test



* adds ioc fields list in log type config files and ioc fields object in LogType POJO



* fix compilation issues in tests



* test udpate detector disabling threat intel



* add tests for detector creation and updation with threat intel



* Threat intel test (#673)

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao



* add threatIntelEnabled field in detector.



* add threat intel feed service and searching feeds



* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation



* Preliminary framework for jobscheduler and datasource (#626)



* create doc level query from threat intel feed data index docs"



* handle threat intel enabled check during detector updation

* add tests for testing threat intel feed integration with detectors



* Threat intel feeds job runner and unit tests (#654)

* fix doc level query constructor (#651)



* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao



* add threatIntelEnabled field in detector.



* add threat intel feed service and searching feeds



* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation



* Preliminary framework for jobscheduler and datasource (#626)



* with listener and processor



* removed actions



* clean up



* added parser



* add unit tests



* refactored class names



* before moving db



* after moving db



* added actions to plugin and removed user schedule



* unit tests



* fix build error



* changed transport naming



---------





* converge job scheduler code with threat intel feed integration in detectors



* refactored out unecessary



* added headers and cleaned up



* converge job scheduler and detector threat intel code



* working on testing



* fixed the parser and build.gradle



* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao



* add threatIntelEnabled field in detector.



* add threat intel feed service and searching feeds



* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation



* Preliminary framework for jobscheduler and datasource (#626)



* create doc level query from threat intel feed data index docs"



* handle threat intel enabled check during detector updation

* add tests for testing threat intel feed integration with detectors



* Threat intel feeds job runner and unit tests (#654)

* fix doc level query constructor (#651)



* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao



* add threatIntelEnabled field in detector.



* add threat intel feed service and searching feeds



* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation



* Preliminary framework for jobscheduler and datasource (#626)



* with listener and processor



* removed actions



* clean up



* added parser



* add unit tests



* refactored class names



* before moving db



* after moving db



* added actions to plugin and removed user schedule



* unit tests



* fix build error



* changed transport naming



---------





* converge job scheduler code with threat intel feed integration in detectors



* converge job scheduler and detector threat intel code



* add feed metadata config files in src and test



* clean up some tests



* fixed merge conflicts



* adds ioc fields list in log type config files and ioc fields object in LogType POJO

* update csv parser and new metadata field



* fixed job scheduler interval settings



* add tests for ioc to fields for each log type



* removed wildcards



---------







* fix threat intel integ tests and add update detector logic



* JS for Threat intel feeds - changed extension (#675)

* merge conflicts



* fixed java wildcards and changed update key name



* integ test failing



* fix job scheduler params



* changed extension and has debug messages



* clean up



* fixed job scheduler plugin spi jar resolution

* cleaned up TODOs and changed job scheduler name



---------




* TIF Job Runner Cleanup (#676)

* merge conflicts



* fixed java wildcards and changed update key name



* integ test failing



* fix job scheduler params



* changed extension and has debug messages



* clean up



* fixed job scheduler plugin spi jar resolution

* cleaned up TODOs and changed job scheduler name



* removed google commons unused import, updated interval setting, removed rest action



* removed policy file and updated name for job scheduler



* responded to comments about parameter validator and TIFMetadata



* refactored ThreatIntelFeedDataService and changed variables to public static final where possible



* changed opensearch-sap-threatintel to opensearch-sap-threat-intel



---------





* fix TIFJobParameter class



* test detector updation when feed updation job runs



* removed delete job scheduler code and cleaned up (#678)



* working integ test (#680)



* fix timeout of tif job creation



* remove unncessary thread forking in put tif job action



* refactoring code to address review comments



* detector trigger detection types


* pull out threat intel rest tests into separate test class



* add detection types testing in detector trigger for rules and threat intel detection scenarios



* add license header



* add threat intel field aliases in mapping view response



* fix threat intel feed parser



* fix workflow failing test



* spotless check failures fixed



* remove dockerfile (#689)



---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>
eirsep added a commit that referenced this pull request Oct 26, 2023
* add mapping for indices storing threat intel feed data



* fix feed indices mapping



* add threat intel feed data dao



* add threatIntelEnabled field in detector.



* add threat intel feed service and searching feeds



* ti feed data to doc level query convertor logic added



* plug threat intel feed into detector creation



* Preliminary framework for jobscheduler and datasource (#626)



* create doc level query from threat intel feed data index docs"



* handle threat intel enabled check during detector updation



* add tests for testing threat intel feed integration with detectors



* Threat intel feeds job runner and unit tests (#654)

* fix doc level query constructor (#651)



* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao



* add threatIntelEnabled field in detector.



* add threat intel feed service and searching feeds



* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation



* Preliminary framework for jobscheduler and datasource (#626)



* with listener and processor



* removed actions



* clean up



* added parser



* add unit tests



* refactored class names



* before moving db



* after moving db



* added actions to plugin and removed user schedule



* unit tests



* fix build error



* changed transport naming



---------





* converge job scheduler code with threat intel feed integration in detectors



* converge job scheduler and detector threat intel code



* add feed metadata config files in src and test



* adds ioc fields list in log type config files and ioc fields object in LogType POJO



* fix compilation issues in tests



* test udpate detector disabling threat intel



* add tests for detector creation and updation with threat intel



* Threat intel test (#673)

* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao



* add threatIntelEnabled field in detector.



* add threat intel feed service and searching feeds



* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation



* Preliminary framework for jobscheduler and datasource (#626)



* create doc level query from threat intel feed data index docs"



* handle threat intel enabled check during detector updation

* add tests for testing threat intel feed integration with detectors



* Threat intel feeds job runner and unit tests (#654)

* fix doc level query constructor (#651)



* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao



* add threatIntelEnabled field in detector.



* add threat intel feed service and searching feeds



* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation



* Preliminary framework for jobscheduler and datasource (#626)



* with listener and processor



* removed actions



* clean up



* added parser



* add unit tests



* refactored class names



* before moving db



* after moving db



* added actions to plugin and removed user schedule



* unit tests



* fix build error



* changed transport naming



---------





* converge job scheduler code with threat intel feed integration in detectors



* refactored out unecessary



* added headers and cleaned up



* converge job scheduler and detector threat intel code



* working on testing



* fixed the parser and build.gradle



* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao



* add threatIntelEnabled field in detector.



* add threat intel feed service and searching feeds



* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation



* Preliminary framework for jobscheduler and datasource (#626)



* create doc level query from threat intel feed data index docs"



* handle threat intel enabled check during detector updation

* add tests for testing threat intel feed integration with detectors



* Threat intel feeds job runner and unit tests (#654)

* fix doc level query constructor (#651)



* add mapping for indices storing threat intel feed data

* fix feed indices mapping

* add threat intel feed data dao



* add threatIntelEnabled field in detector.



* add threat intel feed service and searching feeds



* ti feed data to doc level query convertor logic added

* plug threat intel feed into detector creation



* Preliminary framework for jobscheduler and datasource (#626)



* with listener and processor



* removed actions



* clean up



* added parser



* add unit tests



* refactored class names



* before moving db



* after moving db



* added actions to plugin and removed user schedule



* unit tests



* fix build error



* changed transport naming



---------





* converge job scheduler code with threat intel feed integration in detectors



* converge job scheduler and detector threat intel code



* add feed metadata config files in src and test



* clean up some tests



* fixed merge conflicts



* adds ioc fields list in log type config files and ioc fields object in LogType POJO

* update csv parser and new metadata field



* fixed job scheduler interval settings



* add tests for ioc to fields for each log type



* removed wildcards



---------







* fix threat intel integ tests and add update detector logic



* JS for Threat intel feeds - changed extension (#675)

* merge conflicts



* fixed java wildcards and changed update key name



* integ test failing



* fix job scheduler params



* changed extension and has debug messages



* clean up



* fixed job scheduler plugin spi jar resolution

* cleaned up TODOs and changed job scheduler name



---------




* TIF Job Runner Cleanup (#676)

* merge conflicts



* fixed java wildcards and changed update key name



* integ test failing



* fix job scheduler params



* changed extension and has debug messages



* clean up



* fixed job scheduler plugin spi jar resolution

* cleaned up TODOs and changed job scheduler name



* removed google commons unused import, updated interval setting, removed rest action



* removed policy file and updated name for job scheduler



* responded to comments about parameter validator and TIFMetadata



* refactored ThreatIntelFeedDataService and changed variables to public static final where possible



* changed opensearch-sap-threatintel to opensearch-sap-threat-intel



---------





* fix TIFJobParameter class



* test detector updation when feed updation job runs



* removed delete job scheduler code and cleaned up (#678)



* working integ test (#680)



* fix timeout of tif job creation



* remove unncessary thread forking in put tif job action



* refactoring code to address review comments



* detector trigger detection types


* pull out threat intel rest tests into separate test class



* add detection types testing in detector trigger for rules and threat intel detection scenarios



* add license header



* add threat intel field aliases in mapping view response



* fix threat intel feed parser



* fix workflow failing test



* spotless check failures fixed



* remove dockerfile (#689)



---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>
jowg-amazon added a commit to jowg-amazon/security-analytics that referenced this pull request Nov 8, 2023
jowg-amazon added a commit to jowg-amazon/security-analytics that referenced this pull request Nov 8, 2023
jowg-amazon added a commit to jowg-amazon/security-analytics that referenced this pull request Nov 8, 2023
AWSHurneyt pushed a commit that referenced this pull request Nov 8, 2023
* Revert "make threat intel async (#703) (#704)"

This reverts commit 5b4ab6c.

Signed-off-by: Joanne Wang <[email protected]>

* Revert "Integrate threat intel feeds (#669) (#690)"

This reverts commit 559d97e.

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
riysaxen-amzn pushed a commit to riysaxen-amzn/security-analytics that referenced this pull request Mar 25, 2024
* Added support for "nested" mappings (opensearch-project#645)

* example

Signed-off-by: Petar Dzepina <[email protected]>

* fixed updating mappings for queryIndex

Signed-off-by: Petar Dzepina <[email protected]>

Signed-off-by: Petar Dzepina <[email protected]>

* mappings traversal bug fix (opensearch-project#669)



Signed-off-by: Petar Dzepina <[email protected]>

Signed-off-by: Petar Dzepina <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

7 participants