SlideShare a Scribd company logo
UNCLASSIFIED
UNCLASSIFIED 1
Cyber Situational Awareness - Big
Data Solution
Dan Bart & Bob Landreth
17 Jun 2015
DISA ID61
UNCLASSIFIED
UNCLASSIFIED
Cyber Situational Awareness Analytical Capabilities (CSAAC) is a set of NIPRNet and
SIPRNet solutions that will provide the ability to collect, analyze, visualize, and share
DODIN & Mission Partner information for collaborative DODIN Operations and Defensive
Cyberspace Operations. CSAAC enables greater visibility into the enterprise allowing
critical decisions to be made based on a richer and broader set of information. The Rapid
Deployment Kit (RDK) is the big data solution that supports the data ingest, correlation,
and visualization infrastructure.
2
CSAAC / RDK Overview
Supporting the operation and defense of the Cyber mission
space
Supporting the operation and defense of the Cyber mission
space
UNCLASSIFIED
UNCLASSIFIED
Collect Information
Analyze
Visualize
Share
3
Functional Components
Mission
Planning
Continuous
Risk
Management
Network
Management
Enterprise
Service
Management
Cyber Defense
Near Real and
Real Time
*Cyber
Information
Sharing
*Intel
ANALYTIC PLATFORM
DATA INGEST SERVICE
DISN
OSS
JRSS *Commercial
Cloud *Federal CDCs/DECC Gateways
Enclaves &
End Points
*Cyber
Intel
*DIB
*Future Integration
DATA SOURCES
UNCLASSIFIED
UNCLASSIFIED 4
Supports Multiple Mission Sets
to Enhance Decision Support
DISA Command Center, OPS,
CONUS, EUR, PAC, EIS, 
STRATCOM, JSSC, EE, Ent Ops
NORTHCOM, SOUTCHCOM
DECCs: OKC, MECH, ESD‐NA
CYBERCOM
ACOIC, 561st NOS DOK
Joint Staff, NSA, IAD, OSD, 
NTOC, HQDA/ITA,
HQ Air Force
NETCOM, ARCYBER,
TRANSCOM, Army CIO/G6 
USTRANSCOM, AFCYBER
USSOUTHCOM, JFHQ DoDIN
DES Community
Analytics User Base
15 ingested data sources
102 deployed widgets
747+ users
Metrics
Insider Threat Detection Service
Audit Management
Fight By Indicator (FBI)
Defensive Cyber Ops
Defense Enterprise Email Monitoring
DODIN Ops / Situational Awareness
Roadmap Capability
Mission Mapping / 
Continuous Monitoring
UNCLASSIFIED
UNCLASSIFIED 5
CSAAC-RDK Operational Overview
What is CSAAC‐RDK?
CSAAC‐RDK within DISA CSAAC‐RDK Mission Partners
• CSAAC‐RDK is a DISA developed capability for ingesting and 
storing large data sets, building analytics, and visualizing the 
results.
• Allows critical decisions to be made based on a richer and 
broader set of information.
• Developed around open source and unclassified  components 
while leveraging community tech transfer from other DoD 
entities.
• CSAAC‐RDK is a DISA developed capability for ingesting and 
storing large data sets, building analytics, and visualizing the 
results.
• Allows critical decisions to be made based on a richer and 
broader set of information.
• Developed around open source and unclassified  components 
while leveraging community tech transfer from other DoD 
entities.
Production environments 
deployed on NIPR, SIPR, and 
a Private Secret enclave.
Environments available in 
JITC lab for mission partner 
development.
• CSAAC‐RDK has been embraced by multiple mission partners 
including USCYBERCOM, NSA, Army, Navy, Air Force, and the 
Marines.
• CSAAC‐RDK allows mission partners to rapidly meet the 
demands of their mission (e.g. ARL’s mission to operate and 
defend the DREN).
• CSAAC‐RDK has been embraced by multiple mission partners 
including USCYBERCOM, NSA, Army, Navy, Air Force, and the 
Marines.
• CSAAC‐RDK allows mission partners to rapidly meet the 
demands of their mission (e.g. ARL’s mission to operate and 
defend the DREN).
• Aggregate DoD data to operate, assure, and defend the DODIN
• Support JIE & JRSS initiatives of data collection and analysis
• Enable collaborative analytic development across the DoD
• Establish governance aligned with operational requirements
• Aggregate DoD data to operate, assure, and defend the DODIN
• Support JIE & JRSS initiatives of data collection and analysis
• Enable collaborative analytic development across the DoD
• Establish governance aligned with operational requirements
CSAAC‐RDK Key Objectives
UNCLASSIFIED
UNCLASSIFIED 6
Integrated Architecture
RDK provides the 
potential to consolidate 
CSAAC capabilities. 
This is only an example.
UNCLASSIFIED
UNCLASSIFIED 7
CSAAC-RDK Strategic Linkages
• Standards
• Governance
• Consolidate IT
• Joint Operations
• Data Collection
• Analytics
• Visualization
• Info Sharing
• Information Sharing Architecture
Enhance Shared Situational Awareness (ESSA)
UNCLASSIFIED
UNCLASSIFIED 8
Path Toward Convergence
DISACSAAC-
RDK
Unified
Architecture
Future Efforts
Integrate CSAAC-RDK
with the Intelligence
Community and Navy
Tactical Clouds
Present Efforts
Developing a unified
architecture with
common APIs, data
schemas, and data
standards
UNCLASSIFIED
UNCLASSIFIED
Vision: Cross domain capabilities
Real‐Time  
Distributed Architecture
AFCYBER 
(24th AF)
Coast Guard Cyber 
NSA & CYBERCOM
ARCYBER
NIPR
SIPR
JWICS/NSAnet
“Query one, query all”
FLTCYBERCOM 
(10th Flt)
9
AFIT
(Center for Cyberspace Research)
Service / National Research Labs
UNCLASSIFIED
UNCLASSIFIED
There are three predominant opportunities for Industry big data participation:
1. Create solutions that can seamlessly integrate into the existing big data infrastructure
and augment / enhance currently deployed capabilities
2. Develop solutions that support big data analytics which can be shared amongst all
agencies and enhance collaboration
3. Bring your COTS solution:
– Attributes of a COTS tool to be considered as an enterprise solution should provide capabilities
that:
• Satisfy validated DOD operational requirements
• Are not redundant with currently deployed capabilities
• Offer a more cost effective solution which would be too time consuming or expensive to build ourselves
on CAAC-RDK
• Integrate with existing CSAAC-RDK infrastructure
10
Industry’s Role with CSAAC-RDK
UNCLASSIFIED
UNCLASSIFIED
Information
www.disa.mil
Website or Program External Link
https://east1.deps.mil/disa/cop/mae/netops/CSAAC/SitePages/Home.aspx
EMAIL
Robert Landreth – Program Manager
Robert.Landreth2.civ@mail.mil
11
Contact/POC Information
UNCLASSIFIED
UNCLASSIFIED
United in Service to Our Nation
12

More Related Content

What's hot

The Future of Column-Oriented Data Processing With Apache Arrow and Apache Pa...
The Future of Column-Oriented Data Processing With Apache Arrow and Apache Pa...The Future of Column-Oriented Data Processing With Apache Arrow and Apache Pa...
The Future of Column-Oriented Data Processing With Apache Arrow and Apache Pa...
Dremio Corporation
 
SOS: Optimizing Shuffle I/O with Brian Cho and Ergin Seyfe
SOS: Optimizing Shuffle I/O with Brian Cho and Ergin SeyfeSOS: Optimizing Shuffle I/O with Brian Cho and Ergin Seyfe
SOS: Optimizing Shuffle I/O with Brian Cho and Ergin Seyfe
Databricks
 
Apache Spark At Scale in the Cloud
Apache Spark At Scale in the CloudApache Spark At Scale in the Cloud
Apache Spark At Scale in the Cloud
Databricks
 
HDFS Internals
HDFS InternalsHDFS Internals
HDFS Internals
Apache Apex
 
Hadoop File system (HDFS)
Hadoop File system (HDFS)Hadoop File system (HDFS)
Hadoop File system (HDFS)
Prashant Gupta
 
HBase: How to get MTTR below 1 minute
HBase: How to get MTTR below 1 minuteHBase: How to get MTTR below 1 minute
HBase: How to get MTTR below 1 minute
Hortonworks
 
Top 5 Mistakes When Writing Spark Applications
Top 5 Mistakes When Writing Spark ApplicationsTop 5 Mistakes When Writing Spark Applications
Top 5 Mistakes When Writing Spark Applications
Spark Summit
 
The Parquet Format and Performance Optimization Opportunities
The Parquet Format and Performance Optimization OpportunitiesThe Parquet Format and Performance Optimization Opportunities
The Parquet Format and Performance Optimization Opportunities
Databricks
 
Oracle - Checklist for performance issues
Oracle - Checklist for performance issuesOracle - Checklist for performance issues
Oracle - Checklist for performance issues
Markus Flechtner
 
MySQL Optimizer Overview
MySQL Optimizer OverviewMySQL Optimizer Overview
MySQL Optimizer Overview
Olav Sandstå
 
Millions of Regions in HBase: Size Matters
Millions of Regions in HBase: Size MattersMillions of Regions in HBase: Size Matters
Millions of Regions in HBase: Size Matters
DataWorks Summit
 
Data Engineer's Lunch #85: Designing a Modern Data Stack
Data Engineer's Lunch #85: Designing a Modern Data StackData Engineer's Lunch #85: Designing a Modern Data Stack
Data Engineer's Lunch #85: Designing a Modern Data Stack
Anant Corporation
 
Query Compilation in Impala
Query Compilation in ImpalaQuery Compilation in Impala
Query Compilation in Impala
Cloudera, Inc.
 
DATA WAREHOUSING AND DATA MINING
DATA WAREHOUSING AND DATA MININGDATA WAREHOUSING AND DATA MINING
DATA WAREHOUSING AND DATA MINING
Lovely Professional University
 
Hadoop
HadoopHadoop
IoT:what about data storage?
IoT:what about data storage?IoT:what about data storage?
IoT:what about data storage?
DataWorks Summit/Hadoop Summit
 
Distributed Databases Deconstructed: CockroachDB, TiDB and YugaByte DB
Distributed Databases Deconstructed: CockroachDB, TiDB and YugaByte DBDistributed Databases Deconstructed: CockroachDB, TiDB and YugaByte DB
Distributed Databases Deconstructed: CockroachDB, TiDB and YugaByte DB
YugabyteDB
 
Design of Hadoop Distributed File System
Design of Hadoop Distributed File SystemDesign of Hadoop Distributed File System
Design of Hadoop Distributed File System
Dr. C.V. Suresh Babu
 
Migrating Apache Hive Workload to Apache Spark: Bridge the Gap with Zhan Zhan...
Migrating Apache Hive Workload to Apache Spark: Bridge the Gap with Zhan Zhan...Migrating Apache Hive Workload to Apache Spark: Bridge the Gap with Zhan Zhan...
Migrating Apache Hive Workload to Apache Spark: Bridge the Gap with Zhan Zhan...
Databricks
 
A Deep Dive into Spark SQL's Catalyst Optimizer with Yin Huai
A Deep Dive into Spark SQL's Catalyst Optimizer with Yin HuaiA Deep Dive into Spark SQL's Catalyst Optimizer with Yin Huai
A Deep Dive into Spark SQL's Catalyst Optimizer with Yin Huai
Databricks
 

What's hot (20)

The Future of Column-Oriented Data Processing With Apache Arrow and Apache Pa...
The Future of Column-Oriented Data Processing With Apache Arrow and Apache Pa...The Future of Column-Oriented Data Processing With Apache Arrow and Apache Pa...
The Future of Column-Oriented Data Processing With Apache Arrow and Apache Pa...
 
SOS: Optimizing Shuffle I/O with Brian Cho and Ergin Seyfe
SOS: Optimizing Shuffle I/O with Brian Cho and Ergin SeyfeSOS: Optimizing Shuffle I/O with Brian Cho and Ergin Seyfe
SOS: Optimizing Shuffle I/O with Brian Cho and Ergin Seyfe
 
Apache Spark At Scale in the Cloud
Apache Spark At Scale in the CloudApache Spark At Scale in the Cloud
Apache Spark At Scale in the Cloud
 
HDFS Internals
HDFS InternalsHDFS Internals
HDFS Internals
 
Hadoop File system (HDFS)
Hadoop File system (HDFS)Hadoop File system (HDFS)
Hadoop File system (HDFS)
 
HBase: How to get MTTR below 1 minute
HBase: How to get MTTR below 1 minuteHBase: How to get MTTR below 1 minute
HBase: How to get MTTR below 1 minute
 
Top 5 Mistakes When Writing Spark Applications
Top 5 Mistakes When Writing Spark ApplicationsTop 5 Mistakes When Writing Spark Applications
Top 5 Mistakes When Writing Spark Applications
 
The Parquet Format and Performance Optimization Opportunities
The Parquet Format and Performance Optimization OpportunitiesThe Parquet Format and Performance Optimization Opportunities
The Parquet Format and Performance Optimization Opportunities
 
Oracle - Checklist for performance issues
Oracle - Checklist for performance issuesOracle - Checklist for performance issues
Oracle - Checklist for performance issues
 
MySQL Optimizer Overview
MySQL Optimizer OverviewMySQL Optimizer Overview
MySQL Optimizer Overview
 
Millions of Regions in HBase: Size Matters
Millions of Regions in HBase: Size MattersMillions of Regions in HBase: Size Matters
Millions of Regions in HBase: Size Matters
 
Data Engineer's Lunch #85: Designing a Modern Data Stack
Data Engineer's Lunch #85: Designing a Modern Data StackData Engineer's Lunch #85: Designing a Modern Data Stack
Data Engineer's Lunch #85: Designing a Modern Data Stack
 
Query Compilation in Impala
Query Compilation in ImpalaQuery Compilation in Impala
Query Compilation in Impala
 
DATA WAREHOUSING AND DATA MINING
DATA WAREHOUSING AND DATA MININGDATA WAREHOUSING AND DATA MINING
DATA WAREHOUSING AND DATA MINING
 
Hadoop
HadoopHadoop
Hadoop
 
IoT:what about data storage?
IoT:what about data storage?IoT:what about data storage?
IoT:what about data storage?
 
Distributed Databases Deconstructed: CockroachDB, TiDB and YugaByte DB
Distributed Databases Deconstructed: CockroachDB, TiDB and YugaByte DBDistributed Databases Deconstructed: CockroachDB, TiDB and YugaByte DB
Distributed Databases Deconstructed: CockroachDB, TiDB and YugaByte DB
 
Design of Hadoop Distributed File System
Design of Hadoop Distributed File SystemDesign of Hadoop Distributed File System
Design of Hadoop Distributed File System
 
Migrating Apache Hive Workload to Apache Spark: Bridge the Gap with Zhan Zhan...
Migrating Apache Hive Workload to Apache Spark: Bridge the Gap with Zhan Zhan...Migrating Apache Hive Workload to Apache Spark: Bridge the Gap with Zhan Zhan...
Migrating Apache Hive Workload to Apache Spark: Bridge the Gap with Zhan Zhan...
 
A Deep Dive into Spark SQL's Catalyst Optimizer with Yin Huai
A Deep Dive into Spark SQL's Catalyst Optimizer with Yin HuaiA Deep Dive into Spark SQL's Catalyst Optimizer with Yin Huai
A Deep Dive into Spark SQL's Catalyst Optimizer with Yin Huai
 

Viewers also liked

2016 10 31_mef_brief_nonotes_v2
2016 10 31_mef_brief_nonotes_v22016 10 31_mef_brief_nonotes_v2
2016 10 31_mef_brief_nonotes_v2
David Stern
 
DISA: Cloud Computing And SaaS
DISA: Cloud Computing And SaaSDISA: Cloud Computing And SaaS
DISA: Cloud Computing And SaaS
GovCloud Network
 
Industry Panel: Cyber Convergence - Where Do We Go From Here? TechNet Augusta...
Industry Panel: Cyber Convergence - Where Do We Go From Here? TechNet Augusta...Industry Panel: Cyber Convergence - Where Do We Go From Here? TechNet Augusta...
Industry Panel: Cyber Convergence - Where Do We Go From Here? TechNet Augusta...
AFCEA International
 
Network Convergence: TechNet Augusta 2015
Network Convergence: TechNet Augusta 2015Network Convergence: TechNet Augusta 2015
Network Convergence: TechNet Augusta 2015
AFCEA International
 
Cyber Situational Awareness: TechNet Augusta 2015
Cyber Situational Awareness: TechNet Augusta 2015Cyber Situational Awareness: TechNet Augusta 2015
Cyber Situational Awareness: TechNet Augusta 2015
AFCEA International
 
Federal Webinar: RMF, DISA STIGs, and NIST FISMA Compliance using SolarWinds
Federal Webinar: RMF, DISA STIGs, and NIST FISMA Compliance using SolarWindsFederal Webinar: RMF, DISA STIGs, and NIST FISMA Compliance using SolarWinds
Federal Webinar: RMF, DISA STIGs, and NIST FISMA Compliance using SolarWinds
SolarWinds
 
Information Assurance, A DISA CCRI Conceptual Framework
Information Assurance, A DISA CCRI Conceptual FrameworkInformation Assurance, A DISA CCRI Conceptual Framework
Information Assurance, A DISA CCRI Conceptual Framework
James W. De Rienzo
 
What Makes Great Infographics
What Makes Great InfographicsWhat Makes Great Infographics
What Makes Great Infographics
SlideShare
 
Masters of SlideShare
Masters of SlideShareMasters of SlideShare
Masters of SlideShare
Kapost
 
STOP! VIEW THIS! 10-Step Checklist When Uploading to Slideshare
STOP! VIEW THIS! 10-Step Checklist When Uploading to SlideshareSTOP! VIEW THIS! 10-Step Checklist When Uploading to Slideshare
STOP! VIEW THIS! 10-Step Checklist When Uploading to Slideshare
Empowered Presentations
 
You Suck At PowerPoint!
You Suck At PowerPoint!You Suck At PowerPoint!
You Suck At PowerPoint!
Jesse Desjardins - @jessedee
 
10 Ways to Win at SlideShare SEO & Presentation Optimization
10 Ways to Win at SlideShare SEO & Presentation Optimization10 Ways to Win at SlideShare SEO & Presentation Optimization
10 Ways to Win at SlideShare SEO & Presentation Optimization
Oneupweb
 
How To Get More From SlideShare - Super-Simple Tips For Content Marketing
How To Get More From SlideShare - Super-Simple Tips For Content MarketingHow To Get More From SlideShare - Super-Simple Tips For Content Marketing
How To Get More From SlideShare - Super-Simple Tips For Content Marketing
Content Marketing Institute
 
How to Make Awesome SlideShares: Tips & Tricks
How to Make Awesome SlideShares: Tips & TricksHow to Make Awesome SlideShares: Tips & Tricks
How to Make Awesome SlideShares: Tips & Tricks
SlideShare
 

Viewers also liked (14)

2016 10 31_mef_brief_nonotes_v2
2016 10 31_mef_brief_nonotes_v22016 10 31_mef_brief_nonotes_v2
2016 10 31_mef_brief_nonotes_v2
 
DISA: Cloud Computing And SaaS
DISA: Cloud Computing And SaaSDISA: Cloud Computing And SaaS
DISA: Cloud Computing And SaaS
 
Industry Panel: Cyber Convergence - Where Do We Go From Here? TechNet Augusta...
Industry Panel: Cyber Convergence - Where Do We Go From Here? TechNet Augusta...Industry Panel: Cyber Convergence - Where Do We Go From Here? TechNet Augusta...
Industry Panel: Cyber Convergence - Where Do We Go From Here? TechNet Augusta...
 
Network Convergence: TechNet Augusta 2015
Network Convergence: TechNet Augusta 2015Network Convergence: TechNet Augusta 2015
Network Convergence: TechNet Augusta 2015
 
Cyber Situational Awareness: TechNet Augusta 2015
Cyber Situational Awareness: TechNet Augusta 2015Cyber Situational Awareness: TechNet Augusta 2015
Cyber Situational Awareness: TechNet Augusta 2015
 
Federal Webinar: RMF, DISA STIGs, and NIST FISMA Compliance using SolarWinds
Federal Webinar: RMF, DISA STIGs, and NIST FISMA Compliance using SolarWindsFederal Webinar: RMF, DISA STIGs, and NIST FISMA Compliance using SolarWinds
Federal Webinar: RMF, DISA STIGs, and NIST FISMA Compliance using SolarWinds
 
Information Assurance, A DISA CCRI Conceptual Framework
Information Assurance, A DISA CCRI Conceptual FrameworkInformation Assurance, A DISA CCRI Conceptual Framework
Information Assurance, A DISA CCRI Conceptual Framework
 
What Makes Great Infographics
What Makes Great InfographicsWhat Makes Great Infographics
What Makes Great Infographics
 
Masters of SlideShare
Masters of SlideShareMasters of SlideShare
Masters of SlideShare
 
STOP! VIEW THIS! 10-Step Checklist When Uploading to Slideshare
STOP! VIEW THIS! 10-Step Checklist When Uploading to SlideshareSTOP! VIEW THIS! 10-Step Checklist When Uploading to Slideshare
STOP! VIEW THIS! 10-Step Checklist When Uploading to Slideshare
 
You Suck At PowerPoint!
You Suck At PowerPoint!You Suck At PowerPoint!
You Suck At PowerPoint!
 
10 Ways to Win at SlideShare SEO & Presentation Optimization
10 Ways to Win at SlideShare SEO & Presentation Optimization10 Ways to Win at SlideShare SEO & Presentation Optimization
10 Ways to Win at SlideShare SEO & Presentation Optimization
 
How To Get More From SlideShare - Super-Simple Tips For Content Marketing
How To Get More From SlideShare - Super-Simple Tips For Content MarketingHow To Get More From SlideShare - Super-Simple Tips For Content Marketing
How To Get More From SlideShare - Super-Simple Tips For Content Marketing
 
How to Make Awesome SlideShares: Tips & Tricks
How to Make Awesome SlideShares: Tips & TricksHow to Make Awesome SlideShares: Tips & Tricks
How to Make Awesome SlideShares: Tips & Tricks
 

Similar to CSAAC BDP

Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...
Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...
Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...
AIRCC Publishing Corporation
 
CYBER INFRASTRUCTURE AS A SERVICE TO EMPOWER MULTIDISCIPLINARY, DATA-DRIVEN S...
CYBER INFRASTRUCTURE AS A SERVICE TO EMPOWER MULTIDISCIPLINARY, DATA-DRIVEN S...CYBER INFRASTRUCTURE AS A SERVICE TO EMPOWER MULTIDISCIPLINARY, DATA-DRIVEN S...
CYBER INFRASTRUCTURE AS A SERVICE TO EMPOWER MULTIDISCIPLINARY, DATA-DRIVEN S...
ijcsit
 
3 rd International Conference on Signal Processing, VLSI Design & Communicati...
3 rd International Conference on Signal Processing, VLSI Design & Communicati...3 rd International Conference on Signal Processing, VLSI Design & Communicati...
3 rd International Conference on Signal Processing, VLSI Design & Communicati...
AIRCC Publishing Corporation
 
Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...
Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...
Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...
AIRCC Publishing Corporation
 
DT Company Overview January 2013
DT Company Overview January 2013DT Company Overview January 2013
DT Company Overview January 2013
DataTactics
 
Cisco Big Data Use Case
Cisco Big Data Use CaseCisco Big Data Use Case
Cisco Big Data Use Case
Erni Susanti
 
cisco_bigdata_case_study_1
cisco_bigdata_case_study_1cisco_bigdata_case_study_1
cisco_bigdata_case_study_1
Erni Susanti
 
Bringing Cloud Scale Efficiency to Communication Services Providers through R...
Bringing Cloud Scale Efficiency to Communication Services Providers through R...Bringing Cloud Scale Efficiency to Communication Services Providers through R...
Bringing Cloud Scale Efficiency to Communication Services Providers through R...
Radisys Corporation
 
Data Tactics Semantic and Interoperability Summit Feb 12, 2013
Data Tactics Semantic and Interoperability Summit Feb 12, 2013Data Tactics Semantic and Interoperability Summit Feb 12, 2013
Data Tactics Semantic and Interoperability Summit Feb 12, 2013
DataTactics
 
Speak to Your Data
Speak to Your DataSpeak to Your Data
Speak to Your Data
Amer Radwan , PMP , CSM
 
MT129 Isilon Data Lake Overview
MT129 Isilon Data Lake OverviewMT129 Isilon Data Lake Overview
MT129 Isilon Data Lake Overview
Dell EMC World
 
[OpenStack Day in Korea 2015] Keynote 2 - Leveraging OpenStack to Realize the...
[OpenStack Day in Korea 2015] Keynote 2 - Leveraging OpenStack to Realize the...[OpenStack Day in Korea 2015] Keynote 2 - Leveraging OpenStack to Realize the...
[OpenStack Day in Korea 2015] Keynote 2 - Leveraging OpenStack to Realize the...
OpenStack Korea Community
 
DAMA & Denodo Webinar: Modernizing Data Architecture Using Data Virtualization
DAMA & Denodo Webinar: Modernizing Data Architecture Using Data Virtualization DAMA & Denodo Webinar: Modernizing Data Architecture Using Data Virtualization
DAMA & Denodo Webinar: Modernizing Data Architecture Using Data Virtualization
Denodo
 
Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)
Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)
Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)
Denodo
 
Data Virtualization enabled Data Fabric: Operationalize the Data Lake (APAC)
Data Virtualization enabled Data Fabric: Operationalize the Data Lake (APAC)Data Virtualization enabled Data Fabric: Operationalize the Data Lake (APAC)
Data Virtualization enabled Data Fabric: Operationalize the Data Lake (APAC)
Denodo
 
Data Virtualization: An Introduction
Data Virtualization: An IntroductionData Virtualization: An Introduction
Data Virtualization: An Introduction
Denodo
 
Accelerating Cyber Threat Detection With GPU
Accelerating Cyber Threat Detection With GPUAccelerating Cyber Threat Detection With GPU
Accelerating Cyber Threat Detection With GPU
Joshua Patterson
 
Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)
Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)
Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)
Denodo
 
Innovative and Agile Data Delivery, using 'A Logical Data Fabric'
Innovative and Agile Data Delivery, using 'A Logical Data Fabric'Innovative and Agile Data Delivery, using 'A Logical Data Fabric'
Innovative and Agile Data Delivery, using 'A Logical Data Fabric'
Denodo
 
DEVNET-1166 Open SDN Controller APIs
DEVNET-1166	Open SDN Controller APIsDEVNET-1166	Open SDN Controller APIs
DEVNET-1166 Open SDN Controller APIs
Cisco DevNet
 

Similar to CSAAC BDP (20)

Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...
Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...
Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...
 
CYBER INFRASTRUCTURE AS A SERVICE TO EMPOWER MULTIDISCIPLINARY, DATA-DRIVEN S...
CYBER INFRASTRUCTURE AS A SERVICE TO EMPOWER MULTIDISCIPLINARY, DATA-DRIVEN S...CYBER INFRASTRUCTURE AS A SERVICE TO EMPOWER MULTIDISCIPLINARY, DATA-DRIVEN S...
CYBER INFRASTRUCTURE AS A SERVICE TO EMPOWER MULTIDISCIPLINARY, DATA-DRIVEN S...
 
3 rd International Conference on Signal Processing, VLSI Design & Communicati...
3 rd International Conference on Signal Processing, VLSI Design & Communicati...3 rd International Conference on Signal Processing, VLSI Design & Communicati...
3 rd International Conference on Signal Processing, VLSI Design & Communicati...
 
Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...
Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...
Cyber Infrastructure as a Service to Empower Multidisciplinary, Data-Driven S...
 
DT Company Overview January 2013
DT Company Overview January 2013DT Company Overview January 2013
DT Company Overview January 2013
 
Cisco Big Data Use Case
Cisco Big Data Use CaseCisco Big Data Use Case
Cisco Big Data Use Case
 
cisco_bigdata_case_study_1
cisco_bigdata_case_study_1cisco_bigdata_case_study_1
cisco_bigdata_case_study_1
 
Bringing Cloud Scale Efficiency to Communication Services Providers through R...
Bringing Cloud Scale Efficiency to Communication Services Providers through R...Bringing Cloud Scale Efficiency to Communication Services Providers through R...
Bringing Cloud Scale Efficiency to Communication Services Providers through R...
 
Data Tactics Semantic and Interoperability Summit Feb 12, 2013
Data Tactics Semantic and Interoperability Summit Feb 12, 2013Data Tactics Semantic and Interoperability Summit Feb 12, 2013
Data Tactics Semantic and Interoperability Summit Feb 12, 2013
 
Speak to Your Data
Speak to Your DataSpeak to Your Data
Speak to Your Data
 
MT129 Isilon Data Lake Overview
MT129 Isilon Data Lake OverviewMT129 Isilon Data Lake Overview
MT129 Isilon Data Lake Overview
 
[OpenStack Day in Korea 2015] Keynote 2 - Leveraging OpenStack to Realize the...
[OpenStack Day in Korea 2015] Keynote 2 - Leveraging OpenStack to Realize the...[OpenStack Day in Korea 2015] Keynote 2 - Leveraging OpenStack to Realize the...
[OpenStack Day in Korea 2015] Keynote 2 - Leveraging OpenStack to Realize the...
 
DAMA & Denodo Webinar: Modernizing Data Architecture Using Data Virtualization
DAMA & Denodo Webinar: Modernizing Data Architecture Using Data Virtualization DAMA & Denodo Webinar: Modernizing Data Architecture Using Data Virtualization
DAMA & Denodo Webinar: Modernizing Data Architecture Using Data Virtualization
 
Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)
Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)
Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)
 
Data Virtualization enabled Data Fabric: Operationalize the Data Lake (APAC)
Data Virtualization enabled Data Fabric: Operationalize the Data Lake (APAC)Data Virtualization enabled Data Fabric: Operationalize the Data Lake (APAC)
Data Virtualization enabled Data Fabric: Operationalize the Data Lake (APAC)
 
Data Virtualization: An Introduction
Data Virtualization: An IntroductionData Virtualization: An Introduction
Data Virtualization: An Introduction
 
Accelerating Cyber Threat Detection With GPU
Accelerating Cyber Threat Detection With GPUAccelerating Cyber Threat Detection With GPU
Accelerating Cyber Threat Detection With GPU
 
Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)
Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)
Logical Data Lakes: From Single Purpose to Multipurpose Data Lakes (APAC)
 
Innovative and Agile Data Delivery, using 'A Logical Data Fabric'
Innovative and Agile Data Delivery, using 'A Logical Data Fabric'Innovative and Agile Data Delivery, using 'A Logical Data Fabric'
Innovative and Agile Data Delivery, using 'A Logical Data Fabric'
 
DEVNET-1166 Open SDN Controller APIs
DEVNET-1166	Open SDN Controller APIsDEVNET-1166	Open SDN Controller APIs
DEVNET-1166 Open SDN Controller APIs
 

CSAAC BDP

  • 1. UNCLASSIFIED UNCLASSIFIED 1 Cyber Situational Awareness - Big Data Solution Dan Bart & Bob Landreth 17 Jun 2015 DISA ID61
  • 2. UNCLASSIFIED UNCLASSIFIED Cyber Situational Awareness Analytical Capabilities (CSAAC) is a set of NIPRNet and SIPRNet solutions that will provide the ability to collect, analyze, visualize, and share DODIN & Mission Partner information for collaborative DODIN Operations and Defensive Cyberspace Operations. CSAAC enables greater visibility into the enterprise allowing critical decisions to be made based on a richer and broader set of information. The Rapid Deployment Kit (RDK) is the big data solution that supports the data ingest, correlation, and visualization infrastructure. 2 CSAAC / RDK Overview Supporting the operation and defense of the Cyber mission space Supporting the operation and defense of the Cyber mission space
  • 3. UNCLASSIFIED UNCLASSIFIED Collect Information Analyze Visualize Share 3 Functional Components Mission Planning Continuous Risk Management Network Management Enterprise Service Management Cyber Defense Near Real and Real Time *Cyber Information Sharing *Intel ANALYTIC PLATFORM DATA INGEST SERVICE DISN OSS JRSS *Commercial Cloud *Federal CDCs/DECC Gateways Enclaves & End Points *Cyber Intel *DIB *Future Integration DATA SOURCES
  • 4. UNCLASSIFIED UNCLASSIFIED 4 Supports Multiple Mission Sets to Enhance Decision Support DISA Command Center, OPS, CONUS, EUR, PAC, EIS,  STRATCOM, JSSC, EE, Ent Ops NORTHCOM, SOUTCHCOM DECCs: OKC, MECH, ESD‐NA CYBERCOM ACOIC, 561st NOS DOK Joint Staff, NSA, IAD, OSD,  NTOC, HQDA/ITA, HQ Air Force NETCOM, ARCYBER, TRANSCOM, Army CIO/G6  USTRANSCOM, AFCYBER USSOUTHCOM, JFHQ DoDIN DES Community Analytics User Base 15 ingested data sources 102 deployed widgets 747+ users Metrics Insider Threat Detection Service Audit Management Fight By Indicator (FBI) Defensive Cyber Ops Defense Enterprise Email Monitoring DODIN Ops / Situational Awareness Roadmap Capability Mission Mapping /  Continuous Monitoring
  • 5. UNCLASSIFIED UNCLASSIFIED 5 CSAAC-RDK Operational Overview What is CSAAC‐RDK? CSAAC‐RDK within DISA CSAAC‐RDK Mission Partners • CSAAC‐RDK is a DISA developed capability for ingesting and  storing large data sets, building analytics, and visualizing the  results. • Allows critical decisions to be made based on a richer and  broader set of information. • Developed around open source and unclassified  components  while leveraging community tech transfer from other DoD  entities. • CSAAC‐RDK is a DISA developed capability for ingesting and  storing large data sets, building analytics, and visualizing the  results. • Allows critical decisions to be made based on a richer and  broader set of information. • Developed around open source and unclassified  components  while leveraging community tech transfer from other DoD  entities. Production environments  deployed on NIPR, SIPR, and  a Private Secret enclave. Environments available in  JITC lab for mission partner  development. • CSAAC‐RDK has been embraced by multiple mission partners  including USCYBERCOM, NSA, Army, Navy, Air Force, and the  Marines. • CSAAC‐RDK allows mission partners to rapidly meet the  demands of their mission (e.g. ARL’s mission to operate and  defend the DREN). • CSAAC‐RDK has been embraced by multiple mission partners  including USCYBERCOM, NSA, Army, Navy, Air Force, and the  Marines. • CSAAC‐RDK allows mission partners to rapidly meet the  demands of their mission (e.g. ARL’s mission to operate and  defend the DREN). • Aggregate DoD data to operate, assure, and defend the DODIN • Support JIE & JRSS initiatives of data collection and analysis • Enable collaborative analytic development across the DoD • Establish governance aligned with operational requirements • Aggregate DoD data to operate, assure, and defend the DODIN • Support JIE & JRSS initiatives of data collection and analysis • Enable collaborative analytic development across the DoD • Establish governance aligned with operational requirements CSAAC‐RDK Key Objectives
  • 7. UNCLASSIFIED UNCLASSIFIED 7 CSAAC-RDK Strategic Linkages • Standards • Governance • Consolidate IT • Joint Operations • Data Collection • Analytics • Visualization • Info Sharing • Information Sharing Architecture Enhance Shared Situational Awareness (ESSA)
  • 8. UNCLASSIFIED UNCLASSIFIED 8 Path Toward Convergence DISACSAAC- RDK Unified Architecture Future Efforts Integrate CSAAC-RDK with the Intelligence Community and Navy Tactical Clouds Present Efforts Developing a unified architecture with common APIs, data schemas, and data standards
  • 9. UNCLASSIFIED UNCLASSIFIED Vision: Cross domain capabilities Real‐Time   Distributed Architecture AFCYBER  (24th AF) Coast Guard Cyber  NSA & CYBERCOM ARCYBER NIPR SIPR JWICS/NSAnet “Query one, query all” FLTCYBERCOM  (10th Flt) 9 AFIT (Center for Cyberspace Research) Service / National Research Labs
  • 10. UNCLASSIFIED UNCLASSIFIED There are three predominant opportunities for Industry big data participation: 1. Create solutions that can seamlessly integrate into the existing big data infrastructure and augment / enhance currently deployed capabilities 2. Develop solutions that support big data analytics which can be shared amongst all agencies and enhance collaboration 3. Bring your COTS solution: – Attributes of a COTS tool to be considered as an enterprise solution should provide capabilities that: • Satisfy validated DOD operational requirements • Are not redundant with currently deployed capabilities • Offer a more cost effective solution which would be too time consuming or expensive to build ourselves on CAAC-RDK • Integrate with existing CSAAC-RDK infrastructure 10 Industry’s Role with CSAAC-RDK
  • 11. UNCLASSIFIED UNCLASSIFIED Information www.disa.mil Website or Program External Link https://east1.deps.mil/disa/cop/mae/netops/CSAAC/SitePages/Home.aspx EMAIL Robert Landreth – Program Manager Robert.Landreth2.civ@mail.mil 11 Contact/POC Information