Skip to main content
Goline It Services Logo

News

  • GOLINE SA is excited to announce a new partnership with NetApp, a global leader in cloud data services and storage solutions. This collaboration aims to help organizations modernize their IT infrastructure, streamline data management, and enhance performance across cloud and hybrid environments. Modern Data Solutions for Businesses Through this partnership, GOLINE integrates advanced data management solutions, enabling businesses to securely store, manage, and access critical information across cloud, on-premises, or hybrid setups. Clients can benefit from: Flexible and scalable storage solutions to meet growing data needs Simplified management of cloud and on-premises environments Enterprise-grade security for sensitive and mission-critical data...
  • GOLINE SA is proud to announce a new strategic partnership with Omnissa, a global leader in digital workspace platforms and Horizon Cloud Service solutions. This collaboration marks a significant step forward in helping organizations embrace secure, flexible, and high-performance work environments. Why Choose Omnissa for Your Business? The platform enables virtual desktops, applications, and unified endpoint management. Organizations can deploy scalable workspaces across cloud, hybrid, or on-premises setups. Key benefits include: Easy access to desktops and apps on any device Centralized management for Windows, macOS, iOS, Android, and ChromeOS Strong security with access controls and multi-factor authentication Automated scaling to...
  • Goline is proud to announce a strategic partnership with Cloudflare, the world leader in web performance and security solutions. This collaboration aims to provide goline.ch customers with state-of-the-art protection against cyber threats while delivering lightning-fast website performance. Through this partnership, Goline integrates Cloudflare’s advanced services, including DDoS protection, CDN caching, DNS security, and edge computing, allowing businesses to secure and optimize their websites effortlessly. Users will benefit from improved page load speed, enhanced reliability, and robust defense against malicious attacks. This partnership with Cloudflare enables goline to offer unmatched security and performance solutions to clients. By leveraging Cloudflare’s cutting-edge technology,...

Back to RoutePulse Overview

RoutePulse — Security Events Timeline (Wazuh + Suricata + FortiGate Cross-Source)

Security Events — Wazuh SIEM + Suricata IDS + FortiGate, One Cross-Sourced Timeline

Most SOC tooling makes the operator their own correlation engine: Wazuh in one tab, Suricata in another, FortiGate in a third, BGP anomalies in a fourth — and when an attacker pivots across protocols the analyst has to mentally re-stitch the story. RoutePulse cross-correlates every source into a single timeline keyed on host IP + time window, with 45+ human-readable event labels, MITRE ATT&CK Enterprise v15 tagging on every row, and the **8-Gate Blackhole Pipeline + Conviction Engine v2** (SPRT + Thompson Sampling + Conformal Prediction) deciding which events deserve automated response and which deserve human review.

Every FortiGate row carries a rich attack-context panel: FortiGuard Cyber Risk score (0–100), originating policy, source/destination IP, port, protocol, attack-name, and aggregation counters covering “how many sibling events from this actor in the last hour”. Suricata IDS rules are organised into a SID taxonomy (v4.32.101) mapping every signature to a behavioural class — scan, exploit, malware-CnC, policy-violation — so the per-class Behaviour Diary decay τ in `/settings/diary` can be tuned per Suricata family. Cross-source enrichment is bidirectional: a Wazuh `authentication_failure` on a host that Suricata also flagged for SMB-scan and FortiGate dropped on port 445 produces a single composite incident, not three independent rows. WebSocket live feed, configurable 7-min startup grace, own-AS severity gate (CRITICAL only for AS202032 + announced prefixes 185.54.80.0/22), and per-anomaly rate limiting at 20/hr keep the timeline focused.

45+
Event Labels
47
MITRE Playbooks
8
Blackhole Gates
<3s
Response Latency

Wazuh SIEM ingestion — OSSEC + custom decoders

Wazuh agent events stream into cybersecurity-service.ts via the manager’s REST + filebeat tap. Authentication failures, sudo abuse, audit-rule violations and rootkit-scanner findings are normalised into RoutePulse’s event taxonomy and joined against the active host scoring table (`host_threat_details`, v4.32.86–91). The own-AS gate escalates to CRITICAL only when AS202032 or an announced prefix is involved; everything else is WARNING / INFO so the operator’s Telegram doesn’t drown in DFZ noise.

Suricata IDS — SID taxonomy + per-class diary decay

Every Suricata alert carries its SID. v4.32.101 introduced a curated SID→class mapping (scan, exploit, malware-CnC, policy-violation, dns-tunnel, etc.) feeding the **Behaviour Diary** — a per-host, per-class confidence ledger with class-specific exponential-decay constants (τ in hours). Hot-reloadable: operator edits τ for any class in `/settings/diary`; the 5-minute reload tick picks up the new value with **no restart needed**. Aggressive scanners decay fast (low τ); persistent malware-CnC decays slow (high τ). Critical for accurate FP suppression in playbook gates.

FortiGate — rich attack-context panel + CR score

FortiGate logs surface as expandable rows showing the full FortiGuard Cyber Risk score (0–100), policy name, source/destination IP+port, protocol, attack signature, and aggregation counters (“47 sibling drops in last 60min from same source”). The composite actor attribution — `Attacker (external) → Your host: X → Y :port PROTO` — eliminates the “who is attacker, who is target?” guessing game on every Telegram alert.

Cross-source enrichment — single composite incident

When Wazuh, Suricata and FortiGate all witness the same actor in the same window, the **Incident Hub** stitches them into one row in the timeline, MITRE-tagged across techniques (e.g. T1046 + T1110.001 + T1133), and ANIE (Claude Sonnet 4.6) writes the plain-English narrative with citations to every contributing event. One story per actor — not three rows per minute.

Key Capabilities

  • Unified timeline merging Wazuh OSSEC alerts, Suricata IDS, FortiGate dropped/blocked sessions, BGP anomalies, ML detections and threat-feed hits
  • 45+ human-readable event labels: `cyber_cusum_shift` → “CUSUM Shift Detection”, `cyber_honeypot_hit` → “Honeypot Probe Captured”, etc.
  • 47 production playbooks tagged with MITRE ATT&CK Enterprise v15 techniques; auto-filed into NIS2 / DORA compliance dossiers
  • Suricata SID taxonomy (v4.32.101) mapping every signature to a behavioural class for per-class Behaviour Diary decay τ
  • FortiGate attack-context panel: CR score, policy name, IP/port/proto, attack-signature, aggregation counters
  • Composite actor attribution `From (external) → To (yours)` on every Telegram + UI row (v4.32.104–105)
  • 8-Gate Blackhole Pipeline: Conviction Engine v2 (SPRT α=0.01 β=0.05) + Thompson Sampling (Beta posterior per action) + Conformal Prediction (FDR-controlled FP bound)
  • Own-AS severity gate: CRITICAL only when AS202032 or 185.54.80.0/22 involved — everything else WARNING/INFO
  • 3 delivery channels: Telegram (HTML, 20msg/60s rate limit), Email (GOLINE branded), Webhook (Slack/Discord/PagerDuty/Jira recipes)
  • Configurable startup grace (1–30 min, default 7 min) suppresses alerts during RIB dump + RPKI load + ML baseline convergence
  • Per-anomaly rate limit 20/hr global + per-(IP,type) cooldown 1h for threat-intel hits
  • WebSocket live feed; expandable detail rows with IP, ASN, country, threat score, abuse score, ensemble confidence + ANIE narrative

Engineered and operated by the GOLINE SOC & Network Engineering team.

Explore all RoutePulse features →
71 / 100 SEO Score