DK 'Log


Tutorial 7: Feature highlight / pre-tutorial on Risk Maps
Wed, 15 Oct 2008

Introduction

Today I would to share something interesting we're working on: Risk/Availability/Vulnerability indicator Maps.

The purpose was to fit the most important information that can be gained from ossim all over it's interface, into a simple to use, simple to manage and simple to analyze interface.
We already had an approach to both, to using maps (images) and to aggregate/organize different input into meta-objets (what we called business processes). But, both of them had the same problem: they were complex and they were ugly.


::start here

So now, using the data from that part, we tried to make an interface that was as appealing to the user as possible, but which also was foolproof so that it could be used by less-skilled users (*cough* management *cough*). And here is the result.

I'd love to express my sincere gratitude to Juan Manuel Albarracin, who's coded up the groundworks for all of this in less than four days. Kudos :-).
Also, the screenshots shown here might not reflect the final release. This is work in progress, I'm going to commit code for it to the cvs very soon (tomorrow or monday/tuesday) and it will be in the 1.1 installer release, but of course we''ll be polishing the look and functionality before that.

Sample setup

Final result

The screenshot below these lines shows a finished map of our office, with icons matching people and some specific hosts/environments.

.

On that map you can see the basic object which make up the new map:

  1. The background shape. Usually this would be a network map for your infrastructure, but can be anything from geopolitical maps, to logos, to blank pages or whatever you want.
  2. Configurable icons. A standard set will be provided, custom icons can be uploaded.
  3. Each element can be freely dragged around (during configuration)
  4. Every element can be linked to some url (some part of ossim, another map, an external place)
  5. Each element features it's own easy to understand (green/yellow/red :P) Risk/Vulnerability/Availability indicators

Configuration

Our next screenshot features the configuration interface for all of this.

And again, with the upload part collapsed: .

You've got options to upload maps and icons (icons require a custom name). After having uploaded all the maps you want to configure and all the icons you want to use (besides the default provided ones), you're ready to go.

Toggling away the maps section (we'll replace that nasty link with something niftier) would be a nice first step, leaving only the map and the lower section.

After this, we've got four things to decide:

  1. Choose an icon
  2. Choose an element to report on (more on this later)
  3. Assign a name
  4. Link to another map or to a random url (want to exted this to provide links to standard places across ossim)
Except the link url, the other three elements are mandatory.

The next image shows the nifty icon selector, which uses Lytebox as backend. It allows you to choose icons of your own or select from a set of default icons.

.

As for objects, those usable for placement include:

  • Hosts
  • Networks
  • Host groups
  • Network groups
  • Servers
  • Sensors
  • Businessprocesses

Once that is choosen, you'll add a new indicator. This will place the icon along with it's indicator on the map, allowing you to move it

Last but not least, there's also the ability to add "hot-zones" for those areas where you want to delve into deeper detail. The next image shows a square around Australia, which we could link to a site with info about it, or even better, to a more detailed map with provices/areas and indicators.

.

This has been a brief introduction to the subject, more in-depth information along with how those three final indicators are being calculated will be posted on a follow-up.
From here on what you do is up to your imagination, I guess more obvious environments are those mapping a high level network map of your company to some lower level ones, drilling down on host and network status that way.

posted at: 14:26 | path: /ossim/tutorials | permanent link to this entry | 2 comments |
Tags: maps, risk, indicators, tutorial



* Posted by paul at Wed Oct 15 22:50:04 2008
it is a emplacement for both business and map tab?
* Posted by Gutzba at Thu Jun 11 01:53:18 2009
Very Beautiful

the indicators are alive?? when present in the risk MAp

Name:


E-mail:


URL:


Comment:


Categories

/ (62)
    code/ (1)
    feed/ (1)
    friends/ (1)
    ossim/ (39)
        installer/ (3)
        plugins/ (2)
        tuning/ (3)
        tutorials/ (8)
    personal/ (19)
        campus/ (2)
        opinion/ (1)
        travel/ (1)
    rants/ (1)



Dominique Karg
(feel free to get in touch)
  • Mail (gpg key)
  • Linkedin
  • Twitter
  • Forums

Friend's blogs:
  • /blog/jaime
  • /blog/juanma
  • /blog/santiago






Certified Application Security Specialist




RSS




< October 2008 >
MoTuWeThFrSaSu
   1 2 3 4 5
6 7 8 9101112
13141516171819
20212223242526
2728293031  




Archives

2009-Dec
2009-Sep
2009-Aug
2009-Jul
2009-Jun
2009-May
2009-Apr
2009-Mar
2009-Feb
2009-Jan
2008-Dec
2008-Oct
2008-Aug
2008-Jul
2008-May
2008-Mar
2008-Feb
2008-Jan
2007-Dec
2007-Nov




Tags

installer ossim tutorial untagged




Made with PyBlosxom