AiLPHA
4.19
2.17
4.20
2016.4.19 " "
2014368
2016203 2016
90% ............ · · · ·
01
02
03
04 AI UEBA
AiLPHA
6
/AiLPHA
kafka/syslog/ftp Web Web SMB ......
WebShell Web
Shellcode AV
WebMail
DGA C&C IP/URL
SMB ......
Web
DNS
HTTP
SMTP/POP3/IMAP/Webmail DNS
82003000
EDR EDR
PC
--+
/
· · DDoSC&C · IOCIP
2.8 483.3 484.9 65.7 4776 6.1Web
180.9Web 1.3IP 8.2 338.3IP 27.8 30.1
AI
warning
Mo
Tu
We
Th
Fr
Sa
Su
APP
'
'
Ailpha 1AilphaLambda 2 3ailpha----SOC9 2003000 4180 5AilphaAI 6ailphaAI
Ailpha
-
1 10
2 23
3 2
4
24
5
3
1 1AiLPHA
2
3 20
4
ISP
IPS
VLAN
IPS
IPS
TAP AiLPHA
Juniper
VPN IPsec
DMZ DMZSDN
DMZ
Cisco NAT DMZ
DMZ
DMZ
F5
Imperva WAF WAF
WAF
F5
WAF
WAF
IPS SDN
SSL
IPS
IPS
SSL
F5
F5
WAF
WAF
WAF
WAF
Web DMZ 500Mbps AiLPHA 3Gbps
DMZ DMZ
AiLPHA 200Web2000 20000EPS1TB8 66 2CPU32 256GB 48TB
312
AiLPHA
99%
,
AiLPHA
2
Webshell 7000Webshell HTTP IP WAFWebshell OpenSSL OpenSSL1.0.1Openssl(CVE-2014-0160) 64K IPSOpenssl SQL SQL
3000 ,
Web Web ISP -> DMZ ->
Ai
18566155557
13703001752
Thanks for watching