AI.Dev and Cassandra Summit 2023

On December 12, 2023 in San Jose at the Linux Foundations, AI.dev & Cassandra Summit, I delivered this presentation. The deck and recording is included below.

Abstract

Detecting, catching and successfully prosecuting cybercrime requires collaboration across private sector, law enforcement, insurance companies and national security agencies. Even small organizations produce gigabytes to terabytes of evidence across their internal and cloud instances. Much of this signal evidence contains information protected by law. 

Law enforcement needs to collect evidence from victim organizations without spending hundreds of labor hours. Organizations need a manner to package and share evidence with law enforcement without creating undo risk. Insurers need effective ways of underwriting policies and adjusting claims associated with cybercrime.

In this session, Charles Herring, co-founder and Chief Technology Officer of WitFoo, will detail how terabytes of data collected across hundreds of independent Cassandra clusters each day or safely leveraged to meet the goals of reducing cybercrime and its associated costs.

Charles will cover, build Cassandra schemas to enable cross-organizational sharing, using REST API for facilitating transport across clusters, leaning into Cassandra TTL for data garbage collection and best practices to ensure resilience and performance in diverse environments.

Attachment

About the Author

Charles Herring

Charles Herring

Co-founder & Chairman, WitFoo

I started WitFoo in 2016 to make information and operations shareable across the craft of cybersecurity — between companies, law enforcement, national security and insurers, who mostly cannot see what each other sees. Before that I was at Lancope and Cisco, and I began in 2002 as Network Security Officer for the Naval Postgraduate School.

I lead research and development on a platform that ingests trillions of messages a day across hundreds of clusters. It is sold as Conductor, Reporter and Analytics, licensed flat per appliance with unlimited data — because a team charged by the gigabyte ends up making coverage decisions on a spreadsheet, months before the incident that needed the logs they dropped.

Everything here is mine, not the company's, and it wanders. Corrections are genuinely welcome — I would rather be right than consistent.

A note on how this was written: I use artificial intelligence tools to help me research, check facts, and edit these posts. The ideas, the arguments, and any mistakes are mine. I read the sources, I check the claims, and I take full responsibility for what I publish here. The views are my own and the writing is my intellectual property.