Skip to content

Latest commit

Β 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Cloud Security Assessment Agent

An AI-powered cloud security vulnerability detection and remediation platform that scans, analyzes, and provides intelligent remediation guidance for Google Cloud Platform, Amazon Web Services, and Databricks environments.

πŸš€ Features

Multi-Cloud Security Scanning

  • GCP: Cloud Storage buckets, IAM policies, BigQuery datasets, VPC networks, Compute Engine instances
  • AWS: S3 buckets, IAM policies, EC2 instances, Security Groups, Security Hub integration
  • Databricks: Unity Catalog governance, cluster security, workspace access, data access patterns

AI-Powered Analysis

  • Google Gemini Integration: Natural language security analysis and insights
  • Intelligent Remediation: AI-generated step-by-step remediation instructions
  • Risk Scoring: Automated risk assessment with 0-100 scoring
  • Compliance Reporting: CIS benchmark compliance analysis

Automated Monitoring

  • Scheduled Scans: Daily, weekly, or monthly security assessments
  • Real-time Alerts: Immediate notification of critical vulnerabilities
  • Trend Analysis: Historical security posture tracking
  • Executive Reporting: High-level summaries for leadership

Modern Web Interface

  • React Dashboard: Interactive security overview with charts and metrics
  • Detailed Reports: Comprehensive technical and executive reports
  • Finding Management: Track and resolve security issues
  • Real-time Updates: Live scan progress and status updates

πŸ—οΈ Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚   React Frontend β”‚    β”‚  FastAPI Backend β”‚    β”‚  Airflow Schedulerβ”‚
β”‚                 β”‚    β”‚                 β”‚    β”‚                 β”‚
β”‚  - Dashboard    │◄──►│  - Security APIs │◄──►│  - Scheduled Scansβ”‚
β”‚  - Reports      β”‚    β”‚  - AI Analysis   β”‚    β”‚  - Monitoring    β”‚
β”‚  - Findings     β”‚    β”‚  - Cloud Scannersβ”‚    β”‚  - Notifications β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
         β”‚                       β”‚                       β”‚
         β”‚                       β”‚                       β”‚
         β–Ό                       β–Ό                       β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚   Cloud Run     β”‚    β”‚   PostgreSQL    β”‚    β”‚   Redis Cache   β”‚
β”‚   (Frontend)    β”‚    β”‚   Database      β”‚    β”‚                 β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                β”‚
                                β–Ό
                    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                    β”‚  Cloud Storage  β”‚
                    β”‚  (Scan Data)    β”‚
                    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ› οΈ Tech Stack

Backend

  • FastAPI: High-performance Python web framework
  • PostgreSQL: Primary database for findings and reports
  • Redis: Caching and session management
  • SQLAlchemy: ORM for database operations
  • Pydantic: Data validation and serialization

Frontend

  • React 18: Modern UI framework
  • Material-UI: Component library and theming
  • Recharts: Data visualization
  • Axios: HTTP client for API communication

Infrastructure

  • Google Cloud Platform: Primary cloud provider
  • Cloud Run: Serverless container platform
  • Cloud SQL: Managed PostgreSQL database
  • Artifact Registry: Container image storage
  • Terraform: Infrastructure as Code

AI & Security

  • Google Gemini: AI analysis and remediation generation
  • Google Cloud Security Center: GCP security findings
  • AWS Security Hub: AWS security findings
  • Databricks APIs: Unity Catalog and workspace scanning

πŸ“‹ Prerequisites

  • Google Cloud Project with billing enabled
  • Google Gemini API Key for AI features
  • AWS Credentials (if scanning AWS resources)
  • Databricks Token (if scanning Databricks workspaces)
  • Docker for local development
  • Terraform for infrastructure deployment

πŸš€ Quick Start

Option 1: Docker Compose (Local Development)

The simplest way to get started:

# Make the deployment script executable
chmod +x deploy.sh

# Deploy locally with Docker Compose
./deploy.sh --type docker-compose

Option 2: Terraform Deployment (GCP Cloud Run)

For production deployments on Google Cloud Platform:

# Deploy to GCP (replace with your hosting project ID)
./deploy.sh --type terraform --project-id YOUR_HOSTING_PROJECT_ID --region us-central1

Option 3: Manual Docker Compose

If you prefer to run Docker Compose directly:

# Start all services
docker-compose -f infrastructure/docker/docker-compose.yml up -d

# View logs
docker-compose -f infrastructure/docker/docker-compose.yml logs -f

# Stop services
docker-compose -f infrastructure/docker/docker-compose.yml down


## πŸ”§ Local Development

### Backend Development
```bash
cd backend
python -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate
pip install -r requirements.txt

# Start PostgreSQL and Redis
docker-compose -f infrastructure/docker/docker-compose.yml up postgres redis -d

# Run the backend
python -m uvicorn app.main:app --reload --host 0.0.0.0 --port 8000

Frontend Development

cd frontend
npm install
npm start

Full Stack with Docker

docker-compose -f infrastructure/docker/docker-compose.yml up

πŸ“Š Usage

1. Create a Security Scan

  • Navigate to the Scans page
  • Click "New Scan"
  • Select cloud provider (GCP, AWS, Databricks)
  • Enter project/account ID
  • Start the scan

2. Monitor Scan Progress

  • View real-time scan status
  • Monitor finding discovery
  • Track completion progress

3. Review Findings

  • Browse discovered vulnerabilities
  • Filter by severity, type, or resource
  • View detailed AI analysis
  • Access remediation instructions

4. Generate Reports

  • Create executive summaries
  • Generate technical reports
  • Download PDF reports
  • Schedule automated reporting

5. Implement Remediation

  • Follow AI-generated steps
  • Use provided Terraform configurations
  • Execute CLI commands
  • Mark findings as resolved

πŸ” Security Features

Cloud Provider Integrations

  • GCP: Security Command Center, Cloud Asset Inventory, IAM Policy Intelligence
  • AWS: Security Hub, IAM API, CloudTrail, Config API
  • Databricks: Unity Catalog APIs, Clusters API, SCIM API

AI-Powered Analysis

  • Risk Assessment: Automated vulnerability scoring
  • Remediation Generation: Step-by-step fix instructions
  • Compliance Analysis: CIS benchmark evaluation
  • Executive Insights: Business impact assessment

Automated Monitoring

  • Scheduled Scans: Configurable intervals (daily/weekly/monthly)
  • Real-time Alerts: Critical vulnerability notifications
  • Trend Analysis: Security posture tracking over time
  • Compliance Reporting: Regular compliance status updates

πŸ“ˆ Monitoring and Alerting

Built-in Monitoring

  • Health Checks: API and service health monitoring
  • Scan Progress: Real-time scan status tracking
  • Error Handling: Comprehensive error logging and reporting

Integration Options

  • Slack: Security team notifications
  • Email: Executive and technical alerts
  • Webhooks: Custom integration endpoints
  • Cloud Monitoring: GCP monitoring integration

πŸ”§ Configuration

Environment Variables

# Database
DATABASE_URL=postgresql://user:password@host:port/database
REDIS_URL=redis://host:port

# Cloud Providers
GCP_PROJECT_ID=your-gcp-project
AWS_ACCESS_KEY_ID=your-aws-key
DATABRICKS_HOST=your-databricks-host

# AI Integration
GEMINI_API_KEY=your-gemini-key

# Application
SECRET_KEY=your-secret-key
DEBUG=False

Airflow Configuration

# Set scan configurations
airflow variables set scan_configs '[
  {
    "scan_name": "Production GCP Scan",
    "provider": "gcp",
    "project_id": "your-project-id",
    "scan_config": {}
  }
]'

πŸ§ͺ Testing

Backend Tests

cd backend
pytest tests/ -v

Frontend Tests

cd frontend
npm test

Integration Tests

docker-compose -f infrastructure/docker/docker-compose.yml -f docker-compose.test.yml up --abort-on-container-exit

πŸ“š API Documentation

Security Scans

  • POST /api/v1/scans - Create new scan
  • GET /api/v1/scans - List scans
  • GET /api/v1/scans/{id} - Get scan details
  • POST /api/v1/scans/{id}/cancel - Cancel scan

Security Findings

  • GET /api/v1/findings - List findings
  • GET /api/v1/findings/{id} - Get finding details
  • PUT /api/v1/findings/{id} - Update finding
  • POST /api/v1/findings/{id}/remediate - Apply remediation

Reports

  • POST /api/v1/reports - Generate report
  • GET /api/v1/reports - List reports
  • GET /api/v1/reports/{id} - Get report details
  • GET /api/v1/reports/summary - Get security summary

🀝 Contributing

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/amazing-feature)
  3. Commit your changes (git commit -m 'Add amazing feature')
  4. Push to the branch (git push origin feature/amazing-feature)
  5. Open a Pull Request

πŸ“„ License

This project is licensed under the MIT License - see the LICENSE file for details.

πŸ†˜ Support

πŸ—ΊοΈ Roadmap

Phase 1 (Current)

  • βœ… Multi-cloud security scanning
  • βœ… AI-powered analysis and remediation
  • βœ… Web dashboard and reporting
  • βœ… Automated monitoring with Airflow

Phase 2 (Q2 2024)

  • πŸ”„ Advanced compliance frameworks (SOC 2, PCI DSS)
  • πŸ”„ Custom security policies and rules
  • πŸ”„ Integration with SIEM platforms
  • πŸ”„ Mobile application

Phase 3 (Q3 2024)

  • πŸ“‹ Multi-tenant architecture
  • πŸ“‹ Advanced threat detection
  • πŸ“‹ Security orchestration and automation
  • πŸ“‹ Machine learning-based anomaly detection

Built with ❀️ by the Cloud Security Team

About

Repository for the Cloud Security Assesment project.

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages