Security Events — Wazuh SIEM + Suricata IDS + FortiGate, One Cross-Sourced Timeline
Most SOC tooling makes the operator their own correlation engine: Wazuh in one tab, Suricata in another, FortiGate in a third, BGP anomalies in a fourth — and when an attacker pivots across protocols the analyst has to mentally re-stitch the story. RoutePulse cross-correlates every source into a single timeline keyed on host IP + time window, with 45+ human-readable event labels, MITRE ATT&CK Enterprise v15 tagging on every row, and the **8-Gate Blackhole Pipeline + Conviction Engine v2** (SPRT + Thompson Sampling + Conformal Prediction) deciding which events deserve automated response and which deserve human review.
Every FortiGate row carries a rich attack-context panel: FortiGuard Cyber Risk score (0–100), originating policy, source/destination IP, port, protocol, attack-name, and aggregation counters covering “how many sibling events from this actor in the last hour”. Suricata IDS rules are organised into a SID taxonomy (v4.32.101) mapping every signature to a behavioural class — scan, exploit, malware-CnC, policy-violation — so the per-class Behaviour Diary decay τ in `/settings/diary` can be tuned per Suricata family. Cross-source enrichment is bidirectional: a Wazuh `authentication_failure` on a host that Suricata also flagged for SMB-scan and FortiGate dropped on port 445 produces a single composite incident, not three independent rows. WebSocket live feed, configurable 7-min startup grace, own-AS severity gate (CRITICAL only for AS202032 + announced prefixes 185.54.80.0/22), and per-anomaly rate limiting at 20/hr keep the timeline focused.
Wazuh SIEM ingestion — OSSEC + custom decoders
Wazuh agent events stream into cybersecurity-service.ts via the manager’s REST + filebeat tap. Authentication failures, sudo abuse, audit-rule violations and rootkit-scanner findings are normalised into RoutePulse’s event taxonomy and joined against the active host scoring table (`host_threat_details`, v4.32.86–91). The own-AS gate escalates to CRITICAL only when AS202032 or an announced prefix is involved; everything else is WARNING / INFO so the operator’s Telegram doesn’t drown in DFZ noise.
Suricata IDS — SID taxonomy + per-class diary decay
Every Suricata alert carries its SID. v4.32.101 introduced a curated SID→class mapping (scan, exploit, malware-CnC, policy-violation, dns-tunnel, etc.) feeding the **Behaviour Diary** — a per-host, per-class confidence ledger with class-specific exponential-decay constants (τ in hours). Hot-reloadable: operator edits τ for any class in `/settings/diary`; the 5-minute reload tick picks up the new value with **no restart needed**. Aggressive scanners decay fast (low τ); persistent malware-CnC decays slow (high τ). Critical for accurate FP suppression in playbook gates.
FortiGate — rich attack-context panel + CR score
FortiGate logs surface as expandable rows showing the full FortiGuard Cyber Risk score (0–100), policy name, source/destination IP+port, protocol, attack signature, and aggregation counters (“47 sibling drops in last 60min from same source”). The composite actor attribution — `Attacker (external) → Your host: X → Y :port PROTO` — eliminates the “who is attacker, who is target?” guessing game on every Telegram alert.
Cross-source enrichment — single composite incident
When Wazuh, Suricata and FortiGate all witness the same actor in the same window, the **Incident Hub** stitches them into one row in the timeline, MITRE-tagged across techniques (e.g. T1046 + T1110.001 + T1133), and ANIE (Claude Sonnet 4.6) writes the plain-English narrative with citations to every contributing event. One story per actor — not three rows per minute.
Key Capabilities
- Unified timeline merging Wazuh OSSEC alerts, Suricata IDS, FortiGate dropped/blocked sessions, BGP anomalies, ML detections and threat-feed hits
- 45+ human-readable event labels: `cyber_cusum_shift` → “CUSUM Shift Detection”, `cyber_honeypot_hit` → “Honeypot Probe Captured”, etc.
- 47 production playbooks tagged with MITRE ATT&CK Enterprise v15 techniques; auto-filed into NIS2 / DORA compliance dossiers
- Suricata SID taxonomy (v4.32.101) mapping every signature to a behavioural class for per-class Behaviour Diary decay τ
- FortiGate attack-context panel: CR score, policy name, IP/port/proto, attack-signature, aggregation counters
- Composite actor attribution `From (external) → To (yours)` on every Telegram + UI row (v4.32.104–105)
- 8-Gate Blackhole Pipeline: Conviction Engine v2 (SPRT α=0.01 β=0.05) + Thompson Sampling (Beta posterior per action) + Conformal Prediction (FDR-controlled FP bound)
- Own-AS severity gate: CRITICAL only when AS202032 or 185.54.80.0/22 involved — everything else WARNING/INFO
- 3 delivery channels: Telegram (HTML, 20msg/60s rate limit), Email (GOLINE branded), Webhook (Slack/Discord/PagerDuty/Jira recipes)
- Configurable startup grace (1–30 min, default 7 min) suppresses alerts during RIB dump + RPKI load + ML baseline convergence
- Per-anomaly rate limit 20/hr global + per-(IP,type) cooldown 1h for threat-intel hits
- WebSocket live feed; expandable detail rows with IP, ASN, country, threat score, abuse score, ensemble confidence + ANIE narrative
Engineered and operated by the GOLINE SOC & Network Engineering team.
Explore all RoutePulse features →