your indicator single pane of glass · your indicator single pane of glass enorasys© lookup...

4
encodegroup.com ©2001-2017 Encode. All rights reserved. Do not distribute Your indicator single pane of glass Enorasys© Lookup Service (ELS) is a cloud platform which interfaces with multiple information sources and provides a common interface to query such sources for data related to an IPv4, domain or hash. The platform provides additional processing modules which ingest source information and by utilizing machine learning algorithms provide an overall, human friendly, evaluation for the requested indicator. ELS can be accessed via a rich web interface with rich visualization widgets or via REST API. The common uses cases for ELS is to be able to visit one place and acquire all available information about a specific indicator and to integrate with other applications which can consume the data. Source clients are developed based on our client SAS module framework which provides native support for caching and multithreading. SAS modules are integrated to the cloud ELS platform which in turn provides: Access control Subscription packages Synchronous and Asynchronous API User management Caching Statistics Web interface portal The ELS Platform is deployed on the cloud and is built from the ground with support for horizontal scaling. ELS provides a predefined set of providers and their accompanying data schema for API consumption as well as ready made JavaScript widgets for data visualization.

Upload: others

Post on 25-Aug-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Your indicator single pane of glass · Your indicator single pane of glass Enorasys© Lookup Service (ELS) is a cloud platform which interfaces with multiple information sources and

encodegroup.com©2001-2017 Encode. All rights reserved. Do not distribute

Yourindicatorsinglepaneofglass

Enorasys©LookupService(ELS)isacloudplatformwhichinterfaceswithmultipleinformationsourcesandprovidesacommoninterfacetoquerysuchsourcesfordatarelatedtoanIPv4,domainorhash.Theplatformprovidesadditionalprocessingmoduleswhichingestsourceinformationandbyutilizingmachinelearningalgorithmsprovideanoverall,humanfriendly,evaluationfortherequestedindicator.

ELScanbeaccessedviaarichwebinterfacewithrichvisualizationwidgetsorviaRESTAPI.ThecommonusescasesforELSistobeabletovisitoneplaceandacquireallavailableinformationaboutaspecificindicatorandtointegratewithotherapplicationswhichcanconsumethedata.

Source clients are developed based on ourclient SAS module framework which providesnativesupportforcachingandmultithreading.SAS modules are integrated to the cloud ELSplatformwhichinturnprovides:

• Accesscontrol• Subscriptionpackages• SynchronousandAsynchronousAPI• Usermanagement• Caching• Statistics• Webinterfaceportal

TheELSPlatformisdeployedonthecloudandisbuiltfromthegroundwithsupportforhorizontalscaling.ELSprovidesapredefinedsetofprovidersand their accompanying data schema for APIconsumption as well as ready made JavaScriptwidgetsfordatavisualization.

Page 2: Your indicator single pane of glass · Your indicator single pane of glass Enorasys© Lookup Service (ELS) is a cloud platform which interfaces with multiple information sources and

encodegroup.com©2001-2017 Encode. All rights reserved. Do not distribute

|KeyBenefits

Supportfordifferentprovidertypes

ELS provides integration with a number ofinformationsourceswhetherpublicorprivate.Provider types include DNS information,Passive DNS, Geolocation, OSINT historicaldata, WHOIS, 3rd party providers informationlike VirustTotal, ranking of domains andmostimportantly Encode proprietary Domainsuspiciousness evaluation and lexicographicalanalysisbasedonmachinelearningmodels.

WebinterfaceandRESTAPIAccess

ELSdatacanbeprovidedviaawebinterfaceorconsumedbyotherapplicationsbyprovidingaRESTAPIformachinereadabledataformats.

Extendedsourcessupport

CurrentlyELSprovidesthefollowingdatasourceinformation:

• DNSdata• WHOIS• Geolocation• OSINT aggregation and history (20+

sources)• Alexarankingservices• Weboftrust• PassiveDNSdata• Enorasys©domainEvaluation(ML)• Enorasys©Lexicographicalanalysis(ML)

Page 3: Your indicator single pane of glass · Your indicator single pane of glass Enorasys© Lookup Service (ELS) is a cloud platform which interfaces with multiple information sources and

encodegroup.com©2001-2017 Encode. All rights reserved. Do not distribute

|KeyFeatures

Enorasys©domainevaluation

Enorasys©domainevaluationisutilizingmachinelearning to provide an evaluation of howquestionable or suspicious a certain domainindicatoris.Thiswaydecisionscanbetakenfasterwithout the need of lengthy analysis of theavailabledata from thedifferentproviders. TheELSdomainevaluationmachinelearningmodeliscontinuouslyimproved.Enorasys©Lexicographicalanalysis

Enorasys© provides a machine learning basedevaluationtodetectifthedomaininquestionsishumanormachinegenerated.

Scalability

Horizontalscalingallowingtheplatformtocopewithtensofthousandsofqueriesandapplicationconsumers.

APIaccess

API access to the platform allows for otherapplications to query the available services in acommonwayandpredefinedstructuredindicatorresults.

JavaScriptWidgets

ELSJavaScriptwidgetsallowotherapplicationstoquery and visualize ELS providers within a webbasedapplication.

Performanceoptimizations

Both caching and asynchronous support isprovidedtotheconsumersoftheserviceallowingfasterresponsetimesandcostreduction.

Page 4: Your indicator single pane of glass · Your indicator single pane of glass Enorasys© Lookup Service (ELS) is a cloud platform which interfaces with multiple information sources and

encodegroup.com©2001-2017 Encode. All rights reserved. Do not distribute

|UseCases

ELSisdevelopedtosupportawidenumberofusecasessuchas:

• AnySOC,SIEMplatform• CIRTandIRteams/professionals• MSSPs• VendorsofInternetsecurityproducts(SWG,FWs,SMGs,AV/Endpointsecurity,etc.)• SecuritySystemsoperationsteamsandvirtuallyanysecurityprofessional• Internet Destination/Site classification as of its “suspiciousness level”, along with aggregated,

threat-relatedandcontextualinformationontheInternetdestination/site.• Noclientfootprint:FullCloudAPI/UI/SDKaccess

SummarizedviewofinformationBriefviewmodeprovideseasytoshowandunderstandindicatorsummarywithspecialviewofinformationthatmatters.