blob: 7cda2604b19ed0813baea72bd496da135488a44b [file] [log] [blame]
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!--
Licensed to the Apache Software Foundation (ASF) under one
or more contributor license agreements. See the NOTICE file
distributed with this work for additional information
regarding copyright ownership. The ASF licenses this file
to you under the Apache License, Version 2.0 (the
"License"); you may not use this file except in compliance
with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing,
software distributed under the License is distributed on an
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
KIND, either express or implied. See the License for the
specific language governing permissions and limitations
under the License.
-->
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<link rel="stylesheet" href="../style/bootstrap-1-3-0-min.css" type="text/css" />
<link rel="stylesheet" href="../style/style.css" type="text/css" />
<title>Metron Incubation Status - Apache Incubator</title>
</head>
<body>
<div class="container">
<div class="row"><div class="span6"><a href="https://www.apache.org/"><img src="http://www.apache.org/img/asf_logo.png" alt="The Apache Software Foundation" border="0" style="margin-top: 2px" height="88"/></a></div>
<div class="span7"><a href="/"><img src="https://incubator.apache.org/images/incubator_feather_egg_logo_sm.png" alt="The Apache Software Foundation Incubator" border="0" style="margin-top: 2px" height="88"/></a></div>
<div class="span2"><a href="https://www.apache.org/foundation/contributing.html"><img src="https://www.apache.org/images/SupportApache-small.png" height="100" width="100"/></a></div>
</div>
<div class="row"><div class="span16"><hr noshade="noshade" size="1"/></div></div>
<div class="row">
<div class="span4">
<form action="http://www.google.com/search" method="get">
<input value="incubator.apache.org" name="sitesearch" type="hidden"/>
<input size="20" name="q" id="query" type="text" value="search..."
onclick="if(this.value == 'search...') {this.value = ''}"/>
<input name="Search" value="Go" type="submit"/>
</form>
<div class="menuheader">General</div>
<menu compact="compact">
<li><a href="../index.html">Welcome</a></li>
<li><a href="../cookbook/">Incubator Cookbook</a></li>
<li><a href="../policy/incubation.html">Incubation Policy</a></li>
<li><a href="../guides/roles_and_responsibilities.html">Roles and Responsibilities</a></li>
<li><a href="../faq.html">General FAQ</a></li>
<li><a href="http://wiki.apache.org/incubator">Incubator Wiki</a></li>
<li><a href="../whoweare.html">Who We Are</a></li>
</menu>
<div class="menuheader">Status</div>
<menu compact="compact">
<li><a href="../projects">Project List</a></li>
<li><a href="../clutch">Clutch Report</a></li>
<li><a href="../ip-clearance">IP Clearance</a></li>
</menu>
<div class="menuheader">Entry Guides</div>
<menu compact="compact">
<li><a href="../guides/proposal.html">Proposal Guide</a></li>
</menu>
<div class="menuheader">Podling Guides</div>
<menu compact="compact">
<li><a href="../guides/committer.html">Podling Committers</a></li>
<li><a href="../guides/ppmc.html">Podling PMC (PPMC)</a></li>
<li><a href="../guides/mentor.html">Podling Mentor</a></li>
<li><a href="../guides/releasemanagement.html">Podling Releases</a></li>
<li><a href="../guides/branding.html">Podling Branding/Publicity</a></li>
<li><a href="../guides/sites.html">Podling Websites</a></li>
<li><a href="../guides/graduation.html">Graduation</a></li>
<li><a href="../guides/retirement.html">Retirement</a></li>
</menu>
<div class="menuheader">Other Guides</div>
<menu compact="compact">
<li><a href="../guides/participation.html">Participation</a></li>
<li><a href="../faq.html">General FAQ</a></li>
<li><a href="../guides/pmc.html">Incubator PMC (IPMC)</a></li>
<li><a href="../guides/chair.html">IPMC Chair</a></li>
<li><a href="../guides/lists.html">Mailing Lists</a></li>
<li><a href="../guides/website.html">Incubator Website</a></li>
</menu>
<div class="menuheader">ASF</div>
<menu compact="compact">
<li><a href="http://www.apache.org/foundation/how-it-works.html">How Apache Works</a></li>
<li><a href="http://www.apache.org/dev/">Developer Documentation</a></li>
<li><a href="http://www.apache.org/foundation/">Foundation</a></li>
<li><a href="http://www.apache.org/foundation/sponsorship.html">Sponsor Apache</a></li>
<li><a href="http://www.apache.org/foundation/thanks.html">Thanks</a></li>
</menu>
<!-- start Ads Server -->
<iframe src="http://www.apache.org/ads/buttonbar.html"
style="border-width:0; float: left" frameborder="0" scrolling="no"
width="135" height="265"></iframe>
<!-- end Ads Server -->
</div>
<div class="span12">
<h2 id='Metron+Project+Incubation+Status'><img src="../images/redarrow.gif" />Metron Project Incubation Status</h2>
<div class="section-content">
<p>This page tracks the project status, incubator-wise. For more general
project status, look on the project website.</p>
<p>The Metron project graduated on 2017-04-19, by Board resolution.</p>
<p><span class="graduated">The Metron project graduated on 2017-04-19</span></p>
</div>
<h2 id='Description'><img src="../images/redarrow.gif" />Description</h2>
<div class="section-content">
<p>Metron integrates a variety of open source big data technologies in
order to offer a centralized tool for security monitoring and
analysis. Metron provides capabilities for log aggregation, full
packet capture indexing, storage, advanced behavioral analytics and
data enrichment, while applying the most current threat-intelligence
information to security telemetry within a single platform.</p>
<p>
Metron can be divided into 4 areas:
<ol>
<li>A mechanism to capture, store, and normalize any type of security
telemetry at extremely high rates. Because security telemetry is
constantly being generated, it requires a method for ingesting the
data at high speeds and pushing it to various processing units for
advanced computation and analytics.</li>
<li>Real time processing and application of enrichments such as threat
intelligence, geolocation, and DNS information to telemetry being
collected. The immediate application of this information to incoming
telemetry provides the context and situational awareness, as well as
the “who” and “where” information that is critical for investigation.</li>
<li>Efficient information storage based on how the information will be used:
<ol>
<li>Logs and telemetry are stored such that they can be efficiently mined
and analyzed for concise security visibility</li>
<li>The ability to extract and reconstruct full packets helps an analyst
answer questions such as who the true attacker was, what data was
leaked, and where that data was sent</li>
<li>Long-term storage not only increases visibility over time, but also
enables advanced analytics such as machine learning techniques to be
used to create models on the information. Incoming data can then be
scored against these stored models for advanced anomaly detection.</li>
</ol></li>
<li>An interface that gives a security investigator a centralized view of
data and alerts passed through the system. Metron’s interface presents
alert summaries with threat intelligence and enrichment data specific
to that alert on one single page. Furthermore, advanced search
capabilities and full packet extraction tools are presented to the
analyst for investigation without the need to pivot into additional
tools.</li>
</ol></p>
<p>Big data is a natural fit for powerful security analytics. The Metron
framework integrates a number of elements from the Hadoop ecosystem to
provide a scalable platform for security analytics, incorporating such
functionality as full-packet capture, stream processing, batch
processing, real-time search, and telemetry aggregation. With Metron,
our goal is to tie big data into security analytics and drive towards
an extensible centralized platform to effectively enable rapid
detection and rapid response for advanced security threats.
</p>
</div>
<h2 id='News'><img src="../images/redarrow.gif" />News</h2>
<div class="section-content">
<ul>
<li>2017-04-19 Board approves graduation resolution.</li>
<li>2017-03-14 New Committer: Matt Foley</li>
<li>2017-03-14 New Committer: Jon Zeolla</li>
<li>2016-11-04 New Committer: Kyle Richardson</li>
<li>2016-10-14 New Committer: Otto Fowler</li>
<li>2016-09-29 New Committer: Michael Miklavcic.</li>
<li>2016-09-29 New Committer: Justin Leet.</li>
<li>2016-09-28 New PPMC Member: David Lyle.</li>
<li>2016-09-28 New PPMC Member: Nick Allen.</li>
<li>2016-03-22 New Committer: David Lyle</li>
<li>2016-02-11 New Committer: Nick Allen</li>
<li>2016-01-08 New Committer: Debo Dutta.</li>
<li>2015-12-06 Project enters incubation.</li>
</ul>
</div>
<h2 id='Project+info'><img src="../images/redarrow.gif" />Project info</h2>
<div class="section-content">
<p>URIs and email addresses below refer to locations used by the project while in incubation.
Now that the project has graduated, please remove "incubator" (and associated delimiters)
from all structured names.
</p>
<table class="colortable" width="100%">
<tr>
<th>item</th>
<th>type</th>
<th>reference</th>
</tr>
<tr>
<td>Website</td>
<td>www</td>
<td id="www">
<a href="http://metron.incubator.apache.org/">http://metron.incubator.apache.org/</a>
</td>
</tr>
<tr>
<td>.</td>
<td>wiki</td>
<td id="www">
<a href="https://cwiki.apache.org/confluence/display/METRON/Metron+Wiki">https://cwiki.apache.org/confluence/display/METRON/Metron+Wiki</a>
</td>
</tr>
<tr>
<td>Mailing list</td>
<td>commits</td>
<td id="mail-commits"><code>commits</code><code>@</code><code>metron.incubator.apache.org</code></td>
</tr>
<tr>
<td>.</td>
<td>dev</td>
<td id="mail-dev"><code>dev</code><code>@</code><code>metron.incubator.apache.org</code></td>
</tr>
<tr>
<td>.</td>
<td>issues</td>
<td id="mail-issues"><code>issues</code><code>@</code><code>metron.incubator.apache.org</code></td>
</tr>
<tr>
<td>.</td>
<td>security</td>
<td id="mail-security"><code>security</code><code>@</code><code>metron.incubator.apache.org</code></td>
</tr>
<tr>
<td>.</td>
<td>user</td>
<td id="mail-user"><code>user</code><code>@</code><code>metron.incubator.apache.org</code></td>
</tr>
<tr>
<td>Bug tracking</td>
<td>.</td>
<td id="tracker">
<a href="https://issues.apache.org/jira/browse/METRON">Metron jira</a>
</td>
</tr>
<tr>
<td>Source code</td>
<td>Git</td>
<td id="git">
<a href="https://gitbox.apache.org/repos/asf/incubator-metron.git">https://gitbox.apache.org/repos/asf/incubator-metron.git</a>
</td>
</tr>
<tr>
<td>Mentors</td>
<td>ptgoetz</td>
<td>P. Taylor Goetz</td>
</tr>
<tr>
<td>.</td>
<td>mattmann</td>
<td>Chris Mattmann</td>
</tr>
<tr>
<td>.</td>
<td>omalley</td>
<td>Owen O'Malley</td>
</tr>
<tr>
<td>.</td>
<td>billie</td>
<td>Billie Rinaldi</td>
</tr>
<tr>
<td>.</td>
<td>vinodkv</td>
<td>Vinod Kumar Vavilapalli</td>
</tr>
<tr>
<td>PPMC</td>
<td>jimbaker</td>
<td>Jim Baker</td>
</tr>
<tr>
<td>.</td>
<td>mbittmann</td>
<td>Mark Bittmann</td>
</tr>
<tr>
<td>.</td>
<td>sheetal_dolas</td>
<td>Sheetal Dolas</td>
</tr>
<tr>
<td>.</td>
<td>ddutta</td>
<td>Debo Dutta</td>
</tr>
<tr>
<td>.</td>
<td>discovery</td>
<td>Discovery Gerdes</td>
</tr>
<tr>
<td>.</td>
<td>ptgoetz</td>
<td>P. Taylor Goetz</td>
</tr>
<tr>
<td>.</td>
<td>dev_warlord</td>
<td>Andrew Hartnett</td>
</tr>
<tr>
<td>.</td>
<td>dbhirko</td>
<td>Dave Hirko</td>
</tr>
<tr>
<td>.</td>
<td>reaperhulk</td>
<td>Paul Kehrer</td>
</tr>
<tr>
<td>.</td>
<td>bjkolly</td>
<td>Brad Kolarov</td>
</tr>
<tr>
<td>.</td>
<td>kirankom</td>
<td>Kiran Komaravolu</td>
</tr>
<tr>
<td>.</td>
<td>lmccay</td>
<td>Larry McCay</td>
</tr>
<tr>
<td>.</td>
<td>rmerriman</td>
<td>Ryan Merriman</td>
</tr>
<tr>
<td>.</td>
<td>.</td>
<td>Michael Perez</td>
</tr>
<tr>
<td>.</td>
<td>cporter</td>
<td>Charles Porter</td>
</tr>
<tr>
<td>.</td>
<td>prhodes</td>
<td>Phillip Rhodes</td>
</tr>
<tr>
<td>.</td>
<td>sirsean</td>
<td>Sean Schulte</td>
</tr>
<tr>
<td>.</td>
<td>jsirota</td>
<td>James Sirota</td>
</tr>
<tr>
<td>.</td>
<td>cestella</td>
<td>Casey Stella</td>
</tr>
<tr>
<td>.</td>
<td>.</td>
<td>Bryan Taylor</td>
</tr>
<tr>
<td>.</td>
<td>.</td>
<td>Ray Urciuoli</td>
</tr>
<tr>
<td>.</td>
<td>vinodkv</td>
<td>Vinod Kumar Vavilapalli</td>
</tr>
<tr>
<td>.</td>
<td>gvetticaden</td>
<td>George Vetticaden</td>
</tr>
<tr>
<td>.</td>
<td>smogg</td>
<td>Oskar Zabik</td>
</tr>
<tr>
<td>.</td>
<td>lyle</td>
<td>David Lyle</td>
</tr>
<tr>
<td>.</td>
<td>nallen</td>
<td>Nick Allen</td>
</tr>
<tr>
<td>Committers</td>
<td>Otto Fowler</td>
<td>otto</td>
</tr>
<tr>
<td>.</td>
<td>kylerichardson</td>
<td>Kyle Richardson</td>
</tr>
<tr>
<td>.</td>
<td>leet</td>
<td>Justin Leet</td>
</tr>
<tr>
<td>.</td>
<td>mmiklavcic</td>
<td>Michael Miklavcic</td>
</tr>
<tr>
<td>.</td>
<td>jonzeolla</td>
<td>Jon Zeolla</td>
</tr>
<tr>
<td>.</td>
<td>mattf</td>
<td>Matt Foley</td>
</tr>
</table>
</div>
<h2 id='Incubation+status+reports'><img src="../images/redarrow.gif" />Incubation status reports</h2>
<div class="section-content">
<ul>
<li><a href="https://whimsy.apache.org/board/minutes/Metron.html">https://whimsy.apache.org/board/minutes/Metron.html</a></li>
</ul>
</div>
<h2 id='Incubation+work+items'><img src="../images/redarrow.gif" />Incubation work items</h2>
<div class="section-content">
<h3 id='Project+Setup'>Project Setup</h3>
<div class="section-content">
<p>This is the first phase on incubation, needed to start the project at Apache.</p>
<p>
<em>Item assignment is shown by the Apache id.</em>
<em>Completed tasks are shown by the completion date (YYYY-MM-dd).</em>
</p>
<h4 id='Identify+the+project+to+be+incubated'>Identify the project to be incubated</h4>
<div class="section-content">
<table class="colortable" width="100%">
<tr>
<th>date</th>
<th>item</th>
</tr>
<tr>
<td>2015-10-24</td>
<td>Make sure that the requested project name does not already exist.</td>
</tr>
<tr>
<td>2015-10-24</td>
<td>If request from outside Apache to enter an existing Apache project,
then post a message to that project for them to decide on acceptance. Done <a href="https://groups.google.com/d/msg/opensoc-support/rFlW2uSSvmU/Sw_cO-T2AAAJ">here</a>.</td>
</tr>
</table>
</div>
<h4 id='Infrastructure'>Infrastructure</h4>
<div class="section-content">
<table class="colortable" width="100%">
<tr>
<th>date</th>
<th>item</th>
</tr>
<tr>
<td>2015-12-07</td>
<td>Ask infrastructure to create source repository modules
and grant the committers karma.</td>
</tr>
<tr>
<td>2015-12-07</td>
<td>Ask infrastructure to set up and archive mailing lists.</td>
</tr>
<tr>
<td>2015-12-15</td>
<td>Ask infrastructure to set up issue tracker (JIRA, Bugzilla).</td>
</tr>
<tr>
<td>2015-12-15</td>
<td>Ask infrastructure to set up wiki (Confluence, Moin).</td>
</tr>
<tr>
<td>2015-12-15</td>
<td>Migrate the project to our infrastructure.</td>
</tr>
</table>
</div>
<h4 id='Interim+responsibility'>Mentor-related responsibility/oversight</h4>
<div class="section-content">
<table class="colortable" width="100%">
<tr>
<th>date</th>
<th>item</th>
</tr>
<tr>
<td>2016-01-08</td>
<td>Subscribe all Mentors on the pmc and general lists.</td>
</tr>
<tr>
<td>2015-12-07</td>
<td>Give all Mentors access to the incubator SVN repository.
(to be done by the Incubator PMC chair or an Incubator PMC
Member wih karma for the authorizations file)</td>
</tr>
<tr>
<td>2015-12-10</td>
<td>Tell Mentors to track progress in the file
'incubator/projects/{project.name}.html'</td>
</tr>
</table>
</div>
<h4 id='Copyright'>Copyright</h4>
<div class="section-content">
<table class="colortable" width="100%">
<tr>
<th>date</th>
<th>item</th>
</tr>
<tr>
<td>2016-01-08</td>
<td>Check and make sure that the papers that transfer rights to the ASF
been received. It is only necessary to transfer rights for the
package, the core code, and any new code produced by the project.
</td>
</tr>
<tr>
<td>2016-01-09</td>
<td>Check and make sure that the files that have been donated have been
updated to reflect the new ASF copyright.</td>
</tr>
</table>
</div>
<h4 id='Verify+distribution+rights'>Verify distribution rights</h4>
<div class="section-content">
<table class="colortable" width="100%">
<tr>
<th>date</th>
<th>item</th>
</tr>
<tr>
<td>2016-11-10</td>
<td>Check and make sure that for all code included with the distribution
that is not under the Apache license, we have the right to combine
with Apache-licensed code and redistribute.
</td>
</tr>
<tr>
<td>2016-11-10</td>
<td>Check and make sure that all source code distributed by the project
is covered by one or more of the following approved licenses: Apache,
BSD, Artistic, MIT/X, MIT/W3C, MPL 1.1, or something with essentially
the same terms.</td>
</tr>
</table>
</div>
<h4 id='Establish+a+list+of+active+committers'>Establish a list of active committers</h4>
<div class="section-content">
<table class="colortable" width="100%">
<tr>
<th>date</th>
<th>item</th>
</tr>
<tr>
<td>2015-12-10</td>
<td>Check that all active committers have submitted a contributors
agreement.</td>
</tr>
<tr>
<td>2015-12-10</td>
<td>Add all active committers in the STATUS file.</td>
</tr>
<tr>
<td>2015-12-10</td>
<td>Ask root for the creation of committers' accounts on
people.apache.org.</td>
</tr>
</table>
</div>
<h4 id='Project+specific'>Project specific</h4>
<div class="section-content">
<p>
<em>Add project specific tasks here.</em>
</p>
</div>
</div>
<h3 id='Incubation'>Incubation</h3>
<div class="section-content">
<p>These action items have to be checked for during the whole incubation process.</p>
<p>
<em>These items are not to be signed as done during incubation, as they
may change during incubation.</em>
<em>They are to be looked into and described in the status reports and
completed in the request for incubation signoff.</em>
</p>
<h4 id='Collaborative+Development'>Collaborative Development</h4>
<div class="section-content">
<ul>
<li>Have all of the active long-term volunteers been identified and
acknowledged as committers on the project? YES
</li>
<li>Are there three or more independent committers? YES (The legal definition
of independent is long and boring, but basically it means that there
is no binding relationship between the individuals, such as a shared
employer, that is capable of overriding their free will as
individuals, directly or indirectly.)</li>
<li>Are project decisions being made in public by the committers? YES</li>
<li>Are the decision-making guidelines published and agreed to by all of
the committers? YES</li>
</ul>
</div>
<h4 id='Licensing+awareness'>Licensing awareness</h4>
<div class="section-content">
<ul>
<li>Are all licensing, trademark, credit issues being taken care of and
acknowleged by all committers? YES</li>
</ul>
</div>
<h4 id='Project+Specific'>Project Specific</h4>
<div class="section-content">
<p>
<em>Add project specific tasks here.</em>
</p>
</div>
</div>
<h3 id='Exit'>Exit</h3>
<div class="section-content">
<p>
<em>Things to check for before voting the project out.</em>
</p>
<h4 id='Organizational+acceptance+of+responsibility+for+the+project'>Organizational acceptance of responsibility for the project</h4>
<div class="section-content">
<ul>
<li>If graduating to an existing PMC, has the PMC voted to accept it?</li>
<li>If graduating to a new PMC, has the board voted to accept it?</li>
</ul>
</div>
<h4 id='Incubator+sign-off'>Incubator sign-off</h4>
<div class="section-content">
<ul>
<li>Has the Incubator decided that the project has accomplished all of
the above tasks?</li>
</ul>
</div>
</div>
</div>
</div>
</div>
<div class="row"><div class="span16"><hr noshade="noshade" size="1"/></div></div>
<div class="row">
<div class="span16 footer">
Copyright &#169; 2009-2021 The Apache Software Foundation<br />
Licensed under the <a href="http://www.apache.org/licenses/LICENSE-2.0">Apache License, Version 2.0</a>.<br/>
Apache Incubator, Apache, the Apache feather logo, and the Apache Incubator project logo are trademarks of The Apache Software Foundation.
</div>
</div>
</div>
</body>
</html>