Skip to content

Feature/risk object local - #48

Merged
Mitsushima1 merged 6 commits into
mainfrom
feature/risk-object-local
Sep 1, 2026
Merged

Mitsushima1 merged 6 commits into
mainfrom
feature/risk-object-local

Conversation

@Mitsushima1

Copy link
Copy Markdown
Contributor

Risk-Based Alerting (RBA) — feature summary

Entity-centric risk scoring for the ECHO SOC platform. Extracts "risk objects" (IP/user/host/etc.) from ingested alerts, accumulates per-entity risk scores, and surfaces them across UI/dashboard/correlation.

Backend (backend/risk/ — new Django app)

  • Models: RiskObjectProfile (per-entity score, decay), RiskEvent (alert→entity), RiskScoreEntry (score ledger), RiskRuleConfig / GlobalRiskConfig (which fields are risk objects, + field aliases), NotableEvent.
  • Extraction (services.py): reads configured ECS fields from alerts. Resolver is body-aware (searches top-level + body) and spelling-tolerant (auto-tries source.ip↔source_ip)ten/underscore fields work with zero alias config.Free-text values (e.g. process.command_line) are kept as a single value — no comma-splitting; only real list fields stay
    multi-value.
  • Scoring: score = rule.risk_score × severity_weight × asset_multiplier; decays ×0.85 / 6h.
  • Ingestion hooks: risk extraction runs on all 3 arator/utils.py, alerts/services.py,alerts/tasks.py); writes back to Alert.risk_objects.
  • APIs (/api/v1/risk/): rule-config/, global-confilus dashboard aggregations funnel/, sankey/,top-entities/.
  • diagnose_risk management command for troubleshoo

Frontend

  • Detection rule detail: "Risk Object Fields" panes + source→ECS alias mapping; RBA on/off per rule.
  • Alerts table (AlertList.tsx + utils/riskObjects.ts): shape-tolerant parser (JSON string / array / object), compact "Risk
    Objects" column + detail-modal tags (wrap-safe).
  • Correlation: new "Risk Entities" tab + /correlats alerts by shared risk entity (entities linkingmultiple alerts/rules/tickets); activity table shows risk-object tags.

Config flow

Global default fields → per-rule override; source-field aliases map non-ECS names to ECS paths.

qk and others added 5 commits August 18, 2026 16:33
- add rule preview action and result modal in Detection rule detail
- build a dedicated Kibana preview payload separate from publish payload
- query internal Kibana preview alert indices for matched alert count and samples
- display matched event count and first 10 preview alert samples
- add ES|QL regeneration from Sigma
- persist detection schedule, ES|QL source, and entity risk configuration
- support generated risk/notable actions for Kibana publishing
…e/risk-object-local

# Conflicts:
#	frontend/src/modules/detections/DetectionRuleDetail.tsx
#	frontend/src/modules/detections/Detections.tsx
@@ -1,12 +1,37 @@
import React from "react";
import { Button, Card, Input, Popconfirm, Select, Space, Tag, Typography } from "antd";
import { Button, Card, Checkbox, Input, Popconfirm, Select, Space, Tag, Tooltip, Typography } from "antd";
>
{(() => {
const TYPE_MAP: Record<string, string> = Object.fromEntries(ECS_PRESETS.map((p) => [p.field, p.type]));
const GROUP_LABELS: Record<string, string> = {
import React, { useCallback, useEffect, useMemo, useState } from "react";
import { useRouter } from "next/navigation";
import { App, Button, Input, Modal, Space, Tabs } from "antd";
import { App, Badge, Button, Card, Checkbox, Collapse, Input, Modal, Space, Statistic, Switch, Table, Tag, Tabs, Tooltip, Typography } from "antd";
parsed = urlparse(host)
if parsed.hostname and parsed.port == 5601:
host = f"{parsed.scheme}://{parsed.hostname}:9200"
except Exception:
Comment thread backend/risk/services.py Fixed
Comment thread backend/risk/services.py
)
if asset and hasattr(asset, 'criticality') and asset.criticality:
return ASSET_CRITICALITY_WEIGHT.get(asset.criticality.lower(), 1.0)
except Exception:

@alexchen16 alexchen16 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please help to check. Thanks.

优先级 问题 主要影响 阻塞合并
P0 riskEnabled=false 实际不能关闭规则级 RBA 关闭后仍可能继续累计风险分 是
P0/P1 Risk score 更新存在并发竞争,幂等机制不足 重复加分或 profile 分数丢更新 是
P1 修改配置 / resolve 只要求view_integration 权限 只读用户可修改配置、resolve notable event 是

PR48_RBA_Blocking_Issues_Review.docx

  select_for_update/F()), least-privilege write permissions

@alexchen16 alexchen16 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Mitsushima1
Mitsushima1 merged commit 32c4952 into main Sep 1, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants