Akamai Connected Cloud
Akamai Connected Cloud provides a massively distributed edge and cloud platform where developers can build, run, and secure applications across a continuum of computing power.
Support Added: FortiSIEM 7.2.0
Vendor Version Tested: Not Provided
Vendor: Akamai
Product: Akamai Connected Cloud
Product Information: https://www.akamai.com/
Configuration
Akamai documentation can be found here: https://techdocs.akamai.com/siem-integration/docs/welcome-siem-integration
Take the following steps from the FortiSIEM GUI.
- Navigate to the ADMIN > Setup > Credentials tab.
- In Step 1: Enter Credentials, click New to create a new credential.
- Follow the instructions in "Setting Credentials" in the User's Guide to create a new credential.
- Enter these settings in the Access Method Definition dialog box and click Save:
Settings Description Name Enter a name for the credential Device Type Akamai Connected Cloud Access Protocol Akamai SIEM API Client ID Enter the Client ID associated with Akamai Connected Cloud account. Client Secret/Confirm Client Secret
Enter/paste the client secret into the Client Secret field and Confirm Client Secret field. More information can be found here.
Access Token Enter/paste the access token associated with the Client ID. Configuration ID Enter/paste your configuration ID. More information can be found here. Description Description of the device.
- In Step 2: Enter IP Range to Credential Associations, click New to create a mapping.
- Enter a host name, an IP, or an IP range in the IP/Host Name field.
- Select the name of your Akamai Connected Cloud credential from the Credentials drop-down list if it is not already selected.
- Click Save.
- Click the Test drop-down list and select Test Connectivity without Ping to test the connection to the server.
- Navigate to ADMIN > Setup > Pull Events to see the new job.
Events can be queried from the ANALYTICS page.
Sample Event
[Akamai] = {"attackData":{"clientIP":"192.0.20.0","configId":"14227","policyId":"qik1_26545","ruleActions":"alert;alert;deny","ruleData":"telnet.exe;telnet.exe;Vector Score: 10, DENY threshold: 9, Alert Rules: 950002:950006, Deny Rule: , Last Matched Message: System Command Injection","ruleMessages":"System Command Access;System Command Injection;Anomaly Score Exceeded for Command Injection","ruleSelectors":"ARGS:option;ARGS:option","ruleTags":"OWASP_CRS/WEB_ATTACK/FILE_INJECTION;OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION;AKAMAI/POLICY/CMD_INJECTION_ANOMALY","ruleVersions":"4;4;1","rules":"950002;950006;CMD-INJECTION-ANOMALY"},"botData":{"botScore":"100","responseSegment":"3"},"clientData":{"appBundleId":"com.mydomain.myapp","appVersion":"1.23","sdkVersion":"4.7.1","telemetryType":"2"},"format":"json","geo":{"asn":"14618","city":"ASHBURN","continent":"288","country":"US","regionCode":"VA"},"httpMessage":{"bytes":"266","host":"www.hmapi.com","method":"GET","path":"/","port":"80","protocol":"HTTP/1.1","query":"option=com_jce%20telnet.exe","requestHeaders":"User-Agent%3a%20BOT%2f0.1%20(BOT%20for%20JCE)%0d%0aAccept%3a%20text%2fhtml,application%2fxhtml+xml,application%2fxml%3bq%3d0.9,*%2f*%3bq%3d0.8%0d%0auniqueID%3a%20CR_H8%0d%0aAccept-Language%3a%20en-US,en%3bq%3d0.5%0d%0aAccept-Encoding%3a%20gzip,%20deflate%0d%0aConnection%3a%20keep-alive%0d%0aHost%3a%20www.hmapi.com%0d%0aContent-Length%3a%200%0d%0a","requestId":"1158db1758e37bfe67b7c09","responseHeaders":"Server%3a%20AkamaiGHost%0d%0aMime-Version%3a%201.0%0d%0aContent-Type%3a%20text%2fhtml%0d%0aContent-Length%3a%20266%0d%0aExpires%3a%20Tue,%2004%20Apr%202017%2010%3a57%3a02%20GMT%0d%0aDate%3a%20Tue,%2004%20Apr%202017%2010%3a57%3a02%20GMT%0d%0aConnection%3a%20close%0d%0aSet-Cookie%3a%20ak_bmsc%3dAFE4B6D8CEEDBD286FB10F37AC7B256617DB580D417F0000FE7BE3580429E23D%7epluPrgNmaBdJqOLZFwxqQLSkGGMy4zGMNXrpRIc1Md4qtsDfgjLCojg1hs2HC8JqaaB97QwQRR3YS1ulk+6e9Dbto0YASJAM909Ujbo6Qfyh1XpG0MniBzVbPMUV8oKhBLLPVSNCp0xXMnH8iXGZUHlUsHqWONt3+EGSbWUU320h4GKiGCJkig5r+hc6V1pi3tt7u3LglG3DloEilchdo8D7iu4lrvvAEzyYQI8Hao8M0%3d%3b%20expires%3dTue,%2004%20Apr%202017%2012%3a57%3a02%20GMT%3b%20max-age%3d7200%3b%20path%3d%2f%3b%20domain%3d.hmapi.com%3b%20HttpOnly%0d%0a","start":"1491303422","status":"200"},"type":"akamai_siem","userRiskData":{"allow":"0","general":"duc_1h:10|duc_1d:30","originUserId":"jsmith007","risk":"udfp:1325gdg4g4343g/M|unp:74256/H","score":"75","status":"0","trust":"ugp:US","username":"jsmith@example.com","uuid":"964d54b7-0821-413a-a4d6-8131770ec8d5"},"version":"1.0"}