Skip to main content

Proof of Value (PoV) of OneFirewall Solution

Introduction

OneFirewall is a threat intelligence sharing platform. It matches network traffic against a threat intelligence database and reports actionable insights on detected threats.

Objective

The Proof of Value (PoV) demonstrates OneFirewall’s ability to identify and mitigate cyber threats in an on-premises or private cloud environment. A VM running the OneFirewall platform is installed, and edge traffic logs are analyzed to detect malicious activity.

Scope

  1. Installation and Setup:
    • Deploy a Virtual Machine with OneFirewall in the on-premises environment.
    • Ensure compatibility with the existing private cloud infrastructure.
  2. Traffic Logging:
    • Enable logging of edge traffic to the OneFirewall VM.
    • Configure the system to capture and forward relevant network traffic for analysis.
  3. Threat Analysis:
    • OneFirewall continuously matches incoming traffic against the threat intelligence database.
    • Provide real-time insights and alerts on detected malicious actors attempting to penetrate the network perimeter.

Process

1. Preparation

  • Prepare a Linux-based virtual machine (Ubuntu, Debian, Red Hat, or equivalent) with Docker and Docker Compose installed.
  • Ensure the selected on-premises environment or private cloud instance meets all network and permission requirements needed for deployment.
  • Provide the required access credentials (i.e. VPN, VM credentials with sudoers rights) to the OneFirewall team, who will handle the setup and configuration.

2. Installation

  • OneFirewall staff deploy and configure the OneFirewall OnPrem Solution, a containerized ecosystem orchestrated via Docker Compose, under a PoV License.
  • Verify network connectivity so the solution can access and process traffic logs.
  • Run final installation and connectivity checks to confirm the solution is operational.

3. Configuration

  • Enable logging of all edge traffic to the OneFirewall VM.
  • Set up the permissions and integrations needed for traffic analysis.

4. Monitoring and Analysis

  • OneFirewall monitors network traffic in real time.
  • Traffic is matched against the threat intelligence database to identify and classify potential threats.
  • Reports and alerts are generated from the analysis.

5. Evaluation

  • Assess the volume and nature of detected threats.
  • Evaluate the responsiveness and accuracy of OneFirewall in identifying and mitigating potential cyber threats.
  • Gather feedback from network security personnel on the platform’s usability and effectiveness.

Deliverables

  • Installation Report: Setup process and initial configuration of the OneFirewall VM.
  • Traffic Analysis Report: Detected threats, including types of attacks, sources, and frequency.
  • Evaluation Report: OneFirewall’s performance during the PoV, including key findings and areas for improvement.

VM Requirement

Network connectivity