127
WWW.FORSVARSMAKTEN.SE Maj Alexandra Larsson, Tech Lead Concept System for Intelligence & Security Swedish Armed Forces - Headquarters @macgirlsweden [email protected] Concept System for Intelligence & Security Konceptsystem Underrättelse- och Säkerhetstjänst (KSUS) Gathering requirements, inspiring the end user and driving business development UNCLASSIFIED REL INTERNET

Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Embed Size (px)

Citation preview

Page 1: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Maj Alexandra Larsson, Tech Lead Concept System for Intelligence & Security

Swedish Armed Forces - Headquarters

@macgirlsweden

[email protected]

Concept System for Intelligence & Security Konceptsystem Underrättelse- och Säkerhetstjänst (KSUS)

Gathering requirements, inspiring the end user and driving business development

UNCLASSIFIED REL INTERNET

Page 2: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Focus: System used in “Office Spaces”Cable-based connectivity

Camp Marmal,AfghanistanCamp Bondsteel, Kosovo

Page 3: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Fokus för KSUS

FörbandStaber

(CC/Op/Strat)

RealtidsdataLångsam info

(dokument)

Sensorer & mtrl

(prylar)Informations

hantering

Epost

Servrar

Nätverk

Länkar

SOA-arkitektur

(stabs)Processer

Analysverktyg

Visualisering

Rapporter

(enstaka data)

Kvalificerade

analyser

(sammanställd info)

Vanligt fokus för projekt inom

Ledningsområdet

$$$ $

Page 4: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Att hantera en ny

Strategisk/Operativ Ledningsmetod

Page 5: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Ny typer av konflikter - irreguljära aktörer

Militära maktmedlet i ett civilt sammanhang (comprehensive)

Nytt militärt tänkande ställer krav på infohantering & undtjänst

Page 6: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Multinational Experiment Series (MNE)Försvarsmakten ska delta i Multinational Experiment

Series (MNE) som syftar till att utveckla och demonstrera

ledningskoncept för multinationell och multifunktionell

krishantering.

(Regleringsbrev för 2008, s .35)

Page 7: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management
Page 8: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management
Page 9: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Fastställ

kunskapsbehoven

Planera & inrikta

Inhämta

information

Bearbeta &

Analysera

Delge kunskapKunskaps

-basen

Figur 7

Page 10: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Eget ÖvrigtNeutraltLEDS analys ur ett

samarbetsperspektiv

Figur 6

Page 11: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Cheforganisationsenhet

Krigsförbandschef

Cheforganisationsenhet

Krigsförbandschef

Cheforganisationsenhet

Krigsförbandschef

C HKVHKV-avdelning

Chef för ledningsstabChefsjurist

EkonomidirektörPersonaldirektör

KommunikationsdirektörLedningsstab

ProduktionschefProduktionsledningen

InsatsschefInsatsledningen

Insatsstaben

Taktiska cheferArmé, Marin och Flyg

C MUSTMil und- o säktjänsten

C InternrevisionRev-avdelning

C InternrevisionRev-avdelning

GeneralläkarenGL-avdelning

FlygsäkinspektörMil flyginspektion

ÖverbefälhavareGeneraldirektör

1)

1) Generalläkaren och flygsäkerhetsinspektören är inte underställda överbefälhavaren vid utövande av tillsyn.

2) Chefer för organisationsenheter och krigsförbandschefer lyder under insatschefen avseende operationer och territoriell verksamhet.

3) I organisationsenheterna I 19, LG, P4 och P7 ingår regionala staber för bl.a. civil samverkan och territoriell verksamhet inom militärregion.

För Försvarsmaktens specialförband gäller särskilda lydnadsförhållanden.

2)

Cheforganisationsenhet

Krigsförbandschef

34 organisationsenheter utgörs avregementen, flottiljer,

skolor och centrum

3)

Försvarsmaktens organisationoch lydnadsförhållanden

Militärstrategiskledningsnivå

Figur 1Högkvarteret

Taktiskledningsnivå

Operativledningsnivå

Page 12: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Underrättelsetjänst

Page 13: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

ÖvrigtNeutraltFientligtMUST analys ur ett

hot- och risk-perspektiv

Figur 5

Page 14: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

“Analysts must absorb information with the thoroughness of historians, organize it with the skill of librarians, and disseminate it with the zeal of journalists.”

”American intelligence and fortune-telling” JAN 7, 2010

Bernd Debusmann, Reuters columnist.

Page 15: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

SWEDISH ARMED FORCES

Joint Concept Development & Experimentation Centre

Processing

Intelligence

Staff

Methods

and

Procedures

Software

Repository(existing information)

Intelligence

Processing & Production

Data about

foreign

entities

Data about

foreign

entities

Data about

foreign

entities

Collection

ResultsS

ou

rce

s Intelligence

Product

Dissemination

Page 16: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Swedish Armed ForcesStrategic Directive 2015

• Increase the national and military

intelligence capability.

Page 17: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Försvarsmaktens Underrättelsereglemente

FM UndR

Page 18: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Samordnat system

av underrättelse-

system.

Grundsyn Underrättelsetjänst

Page 19: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Products created

with internal

resources.

Data created

by external

organisations.

Data organised

with internal

resources.

Government

data

Commercial

data

Data from

Intl. orgs

Contracts & Agreements of delivery/subscription of data

Data collected

with internal

resources.HUMINT DB OSINT DB IMINT DB SIGINT DB MASINT DB

Finished All-Source Fused Analytical Products (Combining data from different sources and classification levels to produced finished intelligence products)

Ingest serviceData cleansing, format Conversion, translation, normalization, caching, indexing & service enablement.

Single-source products

+ datasets.

Sensors Sensors Sensors Sensors Sensors

Foundational Data Services (support data for analytics)Geodata – Airspace Data – Equipment Data – Country Data – Image Libraries - Symbols

Page 20: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Generella utmaningar för

underrättelstjänst

Page 21: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

1

Page 22: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Mängden information ökar

Page 23: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

It is not about information overload

Page 24: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

It is a FILTER failure!

Page 25: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

2

Page 26: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Komplexa konflikter

Page 27: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

”Förhållandet människa, historia, geografi, klimat,

kultur, religion, etnicitet, lokala makt- och

ledarstrukturer samt en utbredd fattigdom och

korruption samt brist på läskunnighet, gör att

omfattningen på komplexiteten ibland inte har några

gränser.”

Rickard Johansson Chef FS21

Page 28: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Command & Control by Cut and Paste in Powerpoint

CCCP2

Page 29: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

3

Page 30: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Re

su

rse

r

SEK

Mängden personal minskar

Page 31: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Mängden personal

minskarMängden info

ökar

Komplexa

konflikter

Page 32: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Digitalisering(Verksamhetsutveckling)

Page 33: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management
Page 34: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management
Page 35: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management
Page 36: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Digital oreda...

Page 37: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management
Page 38: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management
Page 39: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management
Page 40: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

FM processhandbok IT-processen

”Försvarsmaktens verksamhet ska vara säker och effektiv

med en hög kvalité på resultatet. Information ska

tillgängliggöras för organisationens behov och stödja

användare och beslutsfattare. Metodisk

informationsbehovsanalys, inkluderande riskanalys,

kontroll, uppföljning och dokumentation, ska utgöra grund

vid framtagning av lösningar för informationshantering med

tillhörande stödsystem.”

Page 41: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Fastställ

kunskapsbehoven

Planera & inrikta

Inhämta

information

Bearbeta &

Analysera

Delge kunskapKunskaps

-basen

Figur 7

Page 42: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

FM Handbok Målsättningsarbete Tekniska system

2015 och ISO/IEC 15288

• Begreppet system: ”en sammansättning av samverkande element organiserade för att uppnå ett eller flera uttalade syften”.

• En förutsättning för tillämpning av en vidare syn på begreppet system är förståelse och insikt om olika påverkansområden. Begreppet påverkansområden syftar till att belysa behov och kostnader för hela system. Påverkansområden har inga tydliga gränser; de påverkar, överlappar och har beroenden till varandra. Behov och krav från eller på samtliga påverkansområden måste beaktas vid en definition av ett system.

Page 43: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

FM Studie- och konceptutvecklingsplan 2016

”Konceptutveckling är ett specialfall av studier och utgör

första steget i förmågeutveckling. Ett koncept utvecklas i

syfte att beskriva framtida operationsmiljöer, militära

problemområden, användning av nya tekniker och

metoder, förmågebehov och tillhörande lösningsförslag.”

Page 44: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Challenges in IT...

Page 45: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Unclear Requirements

Cost and Time Overruns because of

Page 46: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

What to Build

IT has lots of bricks but does not know

Page 47: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Possible Today

Business Users do not know what is

Page 48: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

The Next (-Gen) SystemBusiness Users are unprepared for

Page 49: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

RISK

MANAGE-MENT

COST ($)

BUSINESS

BENEFITS

Page 50: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Verksamhetsnytta

Effektivitet Säkerhet

Skydd

Page 51: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Concept Development System

• Room

• Location

• System

• Software

• Activities

• External partners

Page 52: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Close to the business user

Page 53: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

T100 Setup

Page 54: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

The System

• Unclassified

• Commercial or Open Source software as building blocks

• Most resources spent on ”Integration glue”

• It is a business prototype – not a technical prototype.

Page 55: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Unclassified/ficticiousA detailed scenario which is

Page 56: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Concept

Development

System

Data Software

Best Practice

External Skills

Influence on methods New Skills

Requirements & Business DevelopmentNeed for Data

Page 57: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Document-based

Requirements Management

Model-based

Requirements Management

Page 58: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Page 59: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Page 60: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Page 61: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Konceptutveckling/Konceptsystem

Page 62: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

FM Studie- och konceptutvecklingsplan 2016

”Konceptutveckling är ett specialfall av studier och utgör

första steget i förmågeutveckling. Ett koncept utvecklas i

syfte att beskriva framtida operationsmiljöer, militära

problemområden, användning av nya tekniker och

metoder, förmågebehov och tillhörande lösningsförslag.”

Page 63: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Innovation

”Kombinera saker på

ett nytt sätt”

Page 64: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Integrate different COTS/OS piecesOur approach

ESRI ArcGIS

EMC Documentum

Palantir

EMC InfoArchive

IBM i2

Solr Search

Carmenta Server

IBM Connections IBM SameTime

Instoremedia

RSA Archer

IBM Watson

RSAVia L&G

Page 65: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Page 66: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Page 67: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Verksamhetsproblem

Förmågebehov

Erfarenhetshantering(Vad är vi dåliga på?)

FM Styrdokument

& Inriktningar(Vad vill andra vi ska bli bättre på?)

Initiering av

nytt konceptKunskaps-

uppbyggnad inom

ett visst område

Problembeskrivning

”hantverksnivå”

Kunskap från

Studier & FoT

Erfarenhetshantering(Vad tycker vi är svårt/tar tid?)

Urval av leverantör

och produkt

Analys av produkter

& leverantörer

KSUS Designprinciper

Funktionell bredd

Kommersiell positionering

Leverantörsdialog

Prisindikation

Konceptuell lösning av

verksamhetsproblem

Demonstration för vht

Workshop med vht

Iteration

tillsammans

med vht

Installation & Konfiguering

av produkt stand-alone

Datamodellering

Verksamhetskonfigurering

Behörighetskonfigurering

Integration i KSUS-

plattformen

Anslutning till integrationsplattform

Anslutning till säkerhetsplattform

Beställning

Teckna avtal

FMV Marknad & Inköp

FM MSK Ledsyst Licence Manager

Avtalsgranskning

FMV Marknad & Inköp

FM MSK Ledsyst Licence Manager

Leverantörsdialog

Förhandling

Erbjuda plats i ”skyltfönster”

Ej produktionssystem

Samtal på Executive-nivå

Leverantörsdialog

Tjänsteinsats

Grundinstallation

Verksamhetskonfigurering

Integration med KSUS

Leverantörsdialog

Integration

Går att köra på KSUS Infrastruktur?

Stödjer standarder & protokoil för

Integration och säkerhetsfunktioner.

Leverantörsdialog

Funktionalitet

Detaljerade genomgång av

tekniska funktioner och

tänkt arbetssätt.

Gartner/Forrester/Ovum

Deltagande i konferenser och seminarier

Omvärldsanalys IT(Vilken teknik finns på

marknaden?)

Identifiering av

branschområde

Omvärldsanalys Metod(Hur borde vi arbeta?)

Militära org, underrättelsemyndigheter,

Think-Tanks, Akademisk forskning

ArbO, Reglementen,

Handböcker, Instruktioner(Hur har vi beslutat att arbeta?)

Verksamhetsarkitektur

Modellering av

Organisation & Process

Resultat från

konceptutveckling

Metodutvecklingsfabriken KSUS• Verksamhetsmässigt realiserbara krav

• Kommersiellt realiserbara krav

• Koncept för metod/teknik/org/kompetens/anläggning

• Datamodeller

Page 68: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Informationshantering

Digitalisering - Modeller - Data

KSUS 2016 - Alexandra

70

Page 69: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Finished product (data + container)

71

Page 70: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Data

72

Page 71: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Container (System component)

73

Page 72: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Commercial data in large quantities

(Jane´s data)

74

Industrial production of refill packages of strawberry jam.

Page 73: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Home-cooked high quality data(Collected by classified means i.e. HUMINT/SIGINT)

75

Page 74: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Multiple types of containers (system components)

76

Solr Search

EMC Documentum

Enterprise Content Management

Palantir (Pattern-Link-Analysis)

IBM i2 (Pattern-Link-Analysis)

Page 75: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Platform for all containers = KSUS

77

Page 76: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Basic

perspectives

on information

Taxonomy/Ontology

Space

Relation

Time

User Interaction

Page 77: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Solr + Documentum + Carmenta + ESRI + OpenNLP

Page 78: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Page 79: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Oracle Fusion MiddlewareOracle SOA Suite 12c, Oracle Service Bus

EMC Documentum Platform

Enterprise Content Management

Solr Enterprise Search

Search Services (“Google”)

Beata GIS/Space+Time

Intelligence Analysis Geospatial Analysis

IBM i2

Pattern-Link Analysis with GIS and Text Analytics

IBM SameTime

Real-time Collaboration

Interactive displays for group collaboration

IBM Connections

Social Collaboration

Intelligence Analysis Platform

Virtual Meeting Room Presence/Chat

QlikSense

Web-based Office

Profile – Status - Bookmarks

Search Profiles – Synonyms - Banners

ESRI ArcGIS

Geospatial Analysis for

Intelligence & Security

Carmenta Server

Interoperable GIS Data

Analyst´s Notebook Premium

Vricon Explorer

Intelligence data in 3D

IBM Watson Content Analytics

Text Analytics Platform

Palantir Gotham

Report management –

Pattern-Link-Analysis

InstoremediaRSA Security Platform

Data Visual./Statistics/Big Data

Page 80: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Integration Platform

SOA Orchestration Layer

Enterprise Service Bus

Queue system

Page 81: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Principles and key requirements

• KSUS consists of several systems– Rationale: multiple systems are required to fulfil all business requirements, no single system can do that.

• Systems should be implemented by COTS, MOTS or OS products which should be kept as “standard” as possible

– Rationale: the cost, time and risk of building and maintaining systems in-house is unacceptable as compared to acquiring, integrating and maintaining COTS/MOTS/OS products.

– Rationale: deviating from “standard” means that the cost, time and risk of building and maintaining the system will increase and the benefits of using standard products supported by vendors or open source organizations will decrease.

• It must be possible to replace the COTS/MOTS/OS products used to implement the systems– Rationale: COTS/MOTS/OS products change over time, business requirements change over time, products reach their

end-of-life, and new products appear which have new / better capabilities which are a better fit to the business requirements.

– Implication: the dependencies between the COTS/MOTS/OS products used must be kept to a minimum.

COTS = Commercial Off-The-Shelf

MOTS = Military Off-The-Shelf

OS = Open Source 84

Page 82: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Principles and key requirements

• End-users must be able to work on the same information using different systems– Rationale: different systems provide different functions and fulfil different business requirements, but the

information managed by the business is the same regardless of systems used. We want to avoid “information silos”.

– Rationale: the information is the main asset of the business and the systems are the “tools” used to manage this asset. Business processes, methods and systems will change over time, and these changes will be smoother if the same information can be managed by different systems.

– Rationale: end-users should be given the freedom to choose the best-tool-for-the-job (in their own opinion) among the available alternatives, for the tasks allocated to them.

– Derived requirement: there will be a need for information governance across systems.

• When information is added, modified, deleted or purged in one system, this must be reflected in all other systems with minimal time delay

– Rationale: this requirement is a pre-requisite to enabling users to work on the same information using different systems.

• No system should be considered “master” for a particular type of information, rather all systems capable of managing a particular type of information should be considered equals

– Rationale: classifying some systems as masters will tend to create stronger dependencies to these systems, making it harder to replace these systems’ implementations with new / better COTS/MOTS/OS products.

– Rationale: if a master system is down, updates to information for which it is master will not be possible.

Information

System

System

System

System

System

85

Page 83: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Principles and key requirementsThe principles and key requirements on the previous slides imply the following technical principles and key requirements:

• KSUS must have the technical capability to synchronize information between heterogeneous COTS/MOTS/OS systems with high reliability and high performance, while still maintaining loose couplings between the COTS/MOTS/OS products used.

– Rationale: virtually all COTS/MOTS/OS products manage their data in their own data stores, and it is rarely possible to “re-direct” them to another data store (e.g. a hypothetical “KSUS Main Data Store”). It is much more common that COTS/MOTS/OS products have APIs or other ways of getting data in and out of the product, making an architecture based on information synchronization much more feasible than an architecture based on connecting systems to a single shared data store.

• Configuration is preferred over coding– Rationale: configuration in this sense means adjusting the behavior of COTS/MOTS/OS products according

to the guidelines and techniques supported by the vendors, while coding increases the risk of deviating from ”standard” as well as increases the cost and risk

• KSUS must provide the technical capabilities to minimize dependencies between COTS/MOTS/OS systems

– Derived principle: Service-Oriented Architecture (SOA) is chosen as a main architectural foundation for achieving loose couplings between systems.

• KSUS integrates systems – not data sources– Rationale: systems, implemented by COTS/MOTS/OS products, typically have supported ways of integrating

through APIs. Data sources used by COTS/MOTS/OS products are often not supported for integration. Directly integrating data sources would risk creating strong couplings and would not be compliant with fundamental SOA principles.

System

System

System

System

System

Information

Synchronization

86

Page 84: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Import external source data (this

example from IHS Jane’s).

Page 85: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

IHS Jane´s data in XML-format

Page 86: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

What do we want to do with the data?

• Process to extract-transform-load (ETL) from external data into our own information model Make data searchable.

• Make data editable.

• Make data explorable.

• Make data available for computation (i.e. GIS threat domes)

• Autogenerate Reports (Fartygskort) from data into PDF.

89

Page 87: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Type of Information Models

• There is a Canonical Platform Independent Model (PIM) that identifies a set ofbusiness objects which is needed to support a specific set of tasks and processes.– PIM business objects are relatively stable over time (eg. intelligence requirement)

– PIMs embody the best practice of a certain line of business.

– In KSUS-system this is the canonical model with mappings running on the Oracle Integration Platform (Weblogic, Service Bus and SOA Suite).

• Each COTS-vendor has a Platform Specific Model (PSM) that implements the Canonical PIM based on:– Technical Capabilities

– Legacy context based on initial customers and their primary business needs.

– Marketing/branding aspects (same technical function has different names)

– Granularity varies based on which parts are considered ”core features” to each vendor.

Page 88: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Platform Independent ModelSparx Systems Enterprise Architect

91

Outputs:

- XSD Schemas

- Word report

- Graphs for PPT

Page 89: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

92

Page 90: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

93

Page 91: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

94

Page 92: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

95

Page 93: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

96

Page 94: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

97

Page 95: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

98

Page 96: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Page 97: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

DocSci xPresso for Word

• EMC Document

Science xPression

is used to generate

various publications

upon request by the

user

100

Page 98: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Custom information products (Rendered with EMC DocSci xPression Server)

Page 99: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Ships

objects (with

correct line

drawing as icon)

from Jane´s

data with links to

images (with

thumbnails) in i2

Analyst’s

Notebook

102

Page 100: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

103

Page 101: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Interactive Visualisation

Page 102: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

105

Page 103: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

106

Page 104: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

107

Page 105: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

108

Page 106: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

109

Page 107: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

110

Page 108: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

111

Page 109: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

112

Page 110: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

113

Page 111: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

114

Page 112: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

115

Page 113: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

116

Page 114: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Automated Document References

• Generates an appended last page with bibliography

– Based on a custom relationship type in DellEMC Documentum D2

• Specify document references in DellEMC Documentum D2

• References can be edited directly in DellEMC Documentum D2

– Implemented using DellEMC Documentum C2, XSL, and DQL

– Formatted to mimic standard bibliography formats using title, author,

and publishing year as metadata

• Currently modified to fit the KSUS object model, but could be more generic

using only standard DellEMC Documentum attributes.

Page 115: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Customizations – Document References

Page 116: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Säkerhetskoncept

Page 117: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Verksamhetens informationsmodell Verksamhetens behörighetsmodell

Vilken information har användaren tagit del av? Vilken behörighet har användaren i systemet?

Identity & Access ManagementVilka behörigheter behöver användaren för att utföra sitt arbete?

Loggström

Verksamhetsarkitektur (modell)Vilken information behöver användaren för att utföra sitt arbete?

Information (object) context Context around the user

2016-11-10:10:30:35 097323878567232 alelar

Metadata om loggade objektAccesslogg / Audit trail

Page 118: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Authentication

Management

Identity & Access

Management

Users

joining/moving/leaving

Entitlements to resources

and information

Key/

Token

Manage-

mentNetwork Monitoring and Analysis – Event Stream Analytics

(Rule and alert definition)

S O U R C E S & S E N S O R S I N T H E N E T W O R K E N V I R O N M E N T

NetflowNetwork

Packet CaptureLog Capture

DLP Network

(Payload – files)Endpoint Agent

(Malware)

Anti-MalwareData Loss

Prevention

Policy

Rules

Intrusion

Detection

Devices

Security Analytics (Data-driven fused analytics of all available data)

Data Correlation, Data Enrichment, Normalization – Storage

Governance – Risk - Compliance

Security Investigation & Response

Endpoint Agent

(DLP Client)

Vulnerabiliy

Scan/StatusDirectory

Service

Threat

Intelligence

Vulnerabilties Database

Next-gen Security Operations Centre (SOC)

Provisioning of

Users

Context

Around

Users

Vulnerability

Scanner

Risk-based

User entitlements

IDS

Platform

User

Enrichment

Page 119: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

RSA

Authentication

Manager

RSA Aveksa/IMG

Identity Management &

Governanance

RSA

Data

Protection

ManagerRSA Security Analytics

(Rule and alert definition)

S O U R C E S & S E N S O R S I N T H E N E T W O R K E N V I R O N M E N T

RSA Security

Analytics

Netflow

RSA Security

Analytics

Network

Packet Capture

RSA Security

Analytics Log

Capture

RSA DLP

Network

(Payload – files)

RSA ECAT

Endpoint Agent

(Malware)

RSA

ECAT

Anti-Malware

RSA Data Loss

Prevention

Policy

Rules

Intrusion

Detection

Devices

RSA Security Analytics (Data-driven fused analytics of all available data)

RSA Pivotal/Greenplum Database - HadoopStorage

RSA Archer - Governance – Risk - Compliance

RSA Archer - Security Investigation & Response

RSA DLP

Server/Client

Qualys

ScannerDirectory

Service

RSA

Live

Vulnerabilties Database

NDV CVE

NVD CPE

US-CERT

Next-gen Security Operations Centre (SOC)

Provisioning of

Users

Context

Around

Users

Qualys

Private Cloud

Platform

Risk-based

User entitlements

Cisco

Sourcefire

NGIS

User

Enrichment

Page 120: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

Storage hardware layer

Compute hardware layer

Network hardware layer

Virtualization layer

Common

Service-

Enabled

Platform

Services

(Server)

Composited

Business

Applications

(Intelligence)

Common

Business

Applications

for Intel

Sec & Log (Server)

Data Loss Preventation

Authentication

Management

Intrusion Detection

System

Identity & Access

Management

Key Management

Anti-virus/Anti-malware

Log capture and

storage

Composited

Business

Applications

(Security)

Governance,

Risk

Compliance

Security Incident

and Event

Managementt

Security

Investigation

Servers

Switch - Firewall

Block SAN Storage Backup software and hardware

Network Monitoring

and Analysis

Virtualised Compute (vSphere), Virtualised Network (NSX)

Provisioning, Management, Load Balancing

Geospatial Analysis Text Analytics

Workflow/Case Management Enterprise Content Management

Social Collaboration Real-time Collaboration

Archiving Services

Big Data Analytics

Interactive group collaboration

Pattern-Link-Analysis Tools

Intelligence Report Production

DevOps Layer Source code and configuration repository

Requirement Mgmt & Information Modeling

Build and automation server

IT Asset ManagementIssue tracking system

Artifact Repository

Big Data File Storage

Page 121: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

RSA portfolioVia L&G Security

analytics

Archer ECAT

Page 122: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Governs interaction between entities and information

Page 123: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

• Som en POC, importerades en

access-logg från Documentum till

Neo4j

• Syftet var att visa att vi kan relatera

datakällor till informationsmodellen,

och sedan använda verktyg för att

utreda informationen

126

Page 124: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

127

Vilken access har en person haft vid en viss tid

Person

Page 125: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Temporal vy över access visualiserat med

IBM i2

128

Page 126: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

GRC

Securityoperation

IAM

SOC

• Define Policy• Map Policy• Measure Policy

• Identity Access Management• Identity Admin & Provisioning• Identity & Access Governance

• IT-security• Detect Potential Threats• Respond to Attacks• Investigate Attacks

GISCarmenta

ESRI

ECMEnterprise content

ELPIBM I2

Palantir

CollaborationSametime

Connections

Oracle integration platform

Use of underlying platformcomponents In security Service e.g. (IBM I2 for processing and analyze) (Documentum for reporting)

Page 127: Concept System for Intelligence & Securitysesam.smart-lab.se/seminarier/Hostsem16/161124AL.pdf · Palantir Gotham Report management

WWW.FORSVARSMAKTEN.SE

Maj Alexandra Larsson, Tech Lead Concept System for Intelligence & Security

Swedish Armed Forces - Headquarters

@macgirlsweden

[email protected]

UNCLASSIFIED REL INTERNET