Skip to content
Notifications
Clear all

Just built a map of all blocked attacks by country. Visual is powerful for reports.

1 Posts
1 Users
0 Reactions
15 Views
(@jordanf84)
Trusted Member
Joined: 3 months ago
Posts: 41
Topic starter   [#5099]

I've been working on enhancing our security reporting dashboards, and a recent project involved creating a geographical visualization of all blocked attacks on our Sophos XGS firewalls. While the native reporting is robust, I found that mapping the source countries of blocked intrusion attempts, malware downloads, and web threats provided a uniquely compelling narrative for both technical reviews and executive summaries.

The process required exporting log data and processing it externally. I used a combination of the XGS's syslog forwarding to a central collector and a script to parse and geolocate the source IPs. The key was filtering for `Action: Dropped` or `Action: Blocked` across the relevant security policies, then using a MaxMind GeoLite2 database for the IP-to-country mapping. A simple Python script handled the aggregation.

```python
import pandas as pd
from geoip2.database import Reader

# Pseudocode outline
logs = pd.read_csv('xgs_firewall_logs.csv')
blocked = logs[logs['action'].str.contains('DROP|BLOCK', case=False)]
geo_reader = Reader('GeoLite2-Country.mmdb')

def get_country(ip):
try:
response = geo_reader.country(ip)
return response.country.iso_code
except:
return 'Unknown'

blocked['source_country'] = blocked['src_ip'].apply(get_country)
attack_map_data = blocked['source_country'].value_counts()
```

The resulting data was fed into a simple Grafana world map panel. The visual impact is significant. It immediately highlights whether blocked traffic is predominantly regional, global, or concentrated in specific high-risk jurisdictions. This has been invaluable for:

* **Justifying Security Posture:** Demonstrating the volume and origin of threats reinforces the necessity of our current filter policies and hardware sizing.
* **Incident Response Context:** During an investigation, quickly seeing a surge of blocks from a new country can be a crucial early indicator of a new campaign or compromised infrastructure.
* **SLA and Compliance Reporting:** Providing a clear, at-a-glance chart that shows active threat mitigation is more effective than pages of tabular data for certain stakeholders.

The main pitfall was ensuring consistent log formatting and managing the GeoIP database updates. I would recommend this as a supplementary view rather than a replacement for the XGS's own reports, as it adds a layer of spatial analysis that the built-in tools lack. I'm curious if others have built similar external visualizations and what tools or pipelines you found most effective for correlating XGS data with external threat intelligence feeds.

-jf



   
Quote