01
Stage 1 – User Authentication
Process
A user attempts to access the Cloud Identity Application by providing authentication information. The identity service validates the authentication request.
Tools
Keycloak
Implementation
Configure Keycloak to manage users, authentication, and identity information.
02
Stage 2 – Authorization
Process
After successful authentication, the application determines whether the user has permission to access the requested resource.
Tools
Keycloak
Python
Implementation
Configure user roles and access policies and implement authorization checks within the application.
03
Stage 3 – Application Access
Process
An authenticated user accesses the application or cloud resource according to the assigned permissions.
Tools
Python
FastAPI
Implementation
Develop application APIs and enforce authenticated access using identity and authorization information.
04
Stage 4 – Security Event Generation
Process
Authentication and access activities generate security events such as successful logins, failed logins, account changes, permission changes, and rejected access requests.
Tools
Keycloak
Fluent Bit
Implementation
Enable Keycloak security event logging and configure Fluent Bit to collect identity and application logs.
05
Stage 5 – Centralized Log Management
Process
Security logs from the identity service and application are collected and stored centrally for investigation.
Tools
Fluent Bit
OpenSearch
Implementation
Configure Fluent Bit to forward security logs to OpenSearch, where events can be indexed and searched.
06
Stage 6 – Threat Detection
Process
Security events are analyzed to identify suspicious patterns such as repeated failed logins, unusual access attempts, or abnormal authentication activity.
Tools
OpenSearch
Python
Implementation
Create detection rules and analysis logic to identify abnormal authentication and access patterns.
07
Stage 7 – Security Monitoring and Investigation
Process
Detected security events and identity activity are displayed through centralized dashboards so that the security or operations team can investigate suspicious activity.
Tools
OpenSearch
Grafana
Implementation
Create dashboards for authentication failures, successful logins, access denials, suspicious activity, and security events.