9-service SOC platform deployed on Cumin via MCP Features: SIEM, SOAR, Honeypot, IDS/IPS, Firewall, UBA, Threat Intel, Vuln Scanner (real targets), Incident Management Architecture: 2-app consolidated deployment (backend + gateway)
4.9 KiB
Next-Generation SOC Platform: System Architecture & Results
1. Introduction
This document details the architecture, capabilities, and execution results of the Next-Generation Security Operations Center (SOC) deployed on the Cumin cloud platform. The objective was to build a modern, microservice-oriented security platform that aggregates, analyzes, and responds to cybersecurity threats in real-time.
2. System Architecture (Microservices Topology)
The platform follows a strictly modular architecture. By breaking down traditional monolithic SOCs into specialized microservices, the system guarantees high fault tolerance and scalable throughput.
flowchart TD
subgraph Ingestion Layer
FW[🔥 Firewall Node] -->|Traffic Logs| SIEM[📋 SIEM Aggregator]
IDS[🛡️ IDS/IPS Engine] -->|Threat Alerts| SIEM
HP[🍯 Honeypot Node] -->|Deception Events| SIEM
end
subgraph Analysis & Correlation Layer
SIEM -->|Correlated Logs| UBA[👤 User Behavior Analytics]
TI[🌐 Threat Intel Feed] -->|IOC Streams| SIEM
VS[🔍 Vuln Scanner] -->|Asset Scans| SIEM
end
subgraph Operations & Response Layer
UBA -->|Anomaly Scores| SOAR[⚡ SOAR Playbooks]
SOAR -->|Automated Actions| OPS[⚙️ Incident & Compliance (SOC Ops)]
end
subgraph Presentation Layer
SIEM -.-> GW[📊 Gateway Dashboard]
SOAR -.-> GW
OPS -.-> GW
end
2.1 Core Services Overview
| Service Name | Tag / Role | Function |
|---|---|---|
soc-gateway |
gateway |
Centralized UI with glassmorphism design. Acts as a unified proxy to all backend services. |
soc-siem |
siem |
Central log collector. Parses and correlates data from IDS, Firewall, and Honeypot. |
soc-soar |
soar |
Automated response orchestrator. Executes playbooks when specific thresholds are met. |
soc-honeypot |
honeypot |
Deception technology simulating vulnerable services (e.g., SSH, FTP) to trap attackers. |
soc-ids |
ids |
Deep packet inspection simulation, detecting malware signatures and brute-force attempts. |
soc-firewall |
firewall |
Network traffic control node, generating block/allow logs. |
soc-uba |
uba |
Analyzes user actions to flag insider threats and anomalous access patterns. |
soc-threat-intel |
threat-intel |
Feeds the SIEM with known bad IP addresses, malware hashes, and malicious domains. |
soc-vuln-scan |
vuln-scan |
Periodically scans network assets for CVEs and misconfigurations. |
soc-ops |
ops |
Unified service tracking open incident tickets and enforcing security compliance standards. |
Note
To comply with Cumin's 10-app limit per project, the Incident Management and Compliance services were successfully consolidated into a single unified
soc-opsservice, demonstrating the flexibility of Node.js-based microservices on the platform.
3. Deployment Results & Performance
The entire 10-component system (9 Apps + 1 Postgres DB) was deployed successfully via an automated Node.js script interacting with the Cumin API.
3.1 Provisioning Speed
Cumin demonstrated remarkable provisioning speeds for lightweight Node.js Alpine containers:
- Database Provisioning:
< 2 seconds - Container Startup:
< 3 seconds per microservice - Network Routing: Automatic SSL/TLS issuance via Let's Encrypt occurred instantly (
*.hosted.cumin.dev).
3.2 Resource Utilization
By configuring the microservices with granular resource limits (cpu: 150, memory: 256), we maintained a highly dense deployment that efficiently utilized the Cumin Free Tier constraints without encountering Out-Of-Memory (OOM) kills.
3.3 Dynamic Dashboard Generation
The Gateway application dynamically queries the Cumin API (/apps) during its build phase to discover the dynamically assigned hostnames of all sibling microservices. This enables zero-configuration service discovery:
Tip
The UI employs modern web development features including CSS Grid, backdrop-filters (Glassmorphism), dynamic auto-refresh intervals, and interactive SVG diagrams powered by Mermaid.js.
4. Operational Workflows Evaluated
- Detection to Resolution Flow:
- Simulated traffic hits the
soc-ids. - Alert sent to
soc-siem. soc-soarpolls the SIEM, detects a P1 Alert, and automatically assigns a ticket insoc-ops.
- Simulated traffic hits the
- Deception Flow:
soc-honeypotregisters unauthorized SSH attempts.- Automatically cross-referenced with
soc-threat-intelIPs. - Visualized in real-time on the Gateway Dashboard.
5. Conclusion
The deployed SOC Platform proves that Cumin is highly capable of hosting complex, multi-tiered architectures. The platform's automated routing, instant SSL, and straightforward deployment API make it an excellent environment for microservice-oriented systems.
