Threat Analytics
- For the ML Engine to receive logs from Kron PAM and calculate the risk score, the pam-loganomaly service must be active. Use the following commands to start and verify its status:
- [root@ml-engine ML-Engine-Installer]# systemctl start pam-loganomaly
- [root@ml-engine ML-Engine-Installer]# systemctl status pam-loganomaly.
- Navigate to /pam/log-anomaly/config/ folder.
- Open the config.json file with a text editor and edit weights to finetune anomaly detection. These values determine how strongly each field influences the risk score (Please refer to 3.7.0 Reference Guide for detailed information about the parameters).
- Set values between 0 and 1.
{
"weightOfkeys": {
"user": {
"host": 0.5,
"access_protocol": 0.05,
"client_ip": 0.05,
"date": 1,
"command": 1
},
"host": {
"user_name": 0.5,
"access_protocol": 0.05,
"client_ip": 0.05,
"date": 1,
"command": 1
}
},
"Max_fit_size": 100000,
"port": 5010,
"contamination": 0.01
}- Save the config.json file and restart the anomaly detection service.
- [root@ml-engine ML-Engine-Installer]# systemctl restart pam-loganomaly
The port used for Kron PAM to communicate with the ML Engine is defined in the configuration file. Make sure it aligns with your environment’s network settings.
The ML Engine operates over HTTPS. In Kron PAM, be sure to set the ml.log.anomaly.api.server.url parameter as https://ML-ENGINE-URL:port .