AIOPS
AIOPS Concepts XDR(Extended Detection and Response):综合网络、终端、云等层面 EDR(Endpoint Detection and Response):主要关注终端层面的威胁和响应 NDR(Network Detection and Response):主要关注网络层面的威胁和响应 SIEM(Security Information and Event Management) Splunk Elastic SIEM Log Rhythm DXL(Data Exchange Layer):用于安全产品之间通信的协议 SOC(Security Operations Center) IDS(Intrusion Detection System) HIDS (Host-Based Intrusion Detection System) FIM (File Integrity Monitoring) NIDS (Network-Based IDS) Signature-based IDS (Knowledge-based IDS) Anomaly-based IDS NTA(Network Traffic Analysis) DLP(Data Loss Prevention) EDLP(Endpoint-based DLP) NDLP(Network-based DLP) NAC(Network Access Control):网络准入控制,确保只有符合条件的设备才能访问 Projects OpenDXL OpenXDR OpenEDR OpenSOC GrayLog OSSIM Security Onion Apache Matron IDS Snort Suricata Wazuh Rules Syntax OSSEC Log monitoring/analysis Zeek (Bro) Samhain Labs OpenDLP Sigma OpenSearch-Using Security Analysis OpenSearch Neural Search Plugin Tutorial MSTIC: msticpy is a library for InfoSec investigation and hunting in Jupyter Notebooks Anomaly Detection Log-based Log Parser Github - logpai - Drain3 Github - logpai - Logparser Projects Github - Log-based Anomaly Detection with Deep Learning: How Far Are We? Github - logpai - loglizer Researchers Chongqing University - Hongyu Zhang Microsoft Research Asia - Shaohan Huang References Github - Anomaly Detection Learning Resources Github - Awesome Log Analysis Github - AIOps handbook Mechine Learning Libraries Github - PyOD Time series Libraries Github - tslearn DLP Document Classification Articles ...