Optimizing endpoint detection and monitoring in enterprise solution : a cyber threat intelligence approach

Abstract

Advanced cyber threat intelligence systems are crucial in a time when enterprise solutions are increasing and are being targeted by more sophisticated cyberattacks. This research aims to study ways to improve endpoint detection and monitoring in an enterprise company by installing a Security Information and Event Management (SIEM) system based on Wazuh with integration into ELK Stack. The report performs an inside-out examination of the integration and deployment capability for each technology, focusing on real-time anomaly detection and threat mitigation toolkits at complied states. Together, these techniques create a powerful combination of analytical security, intrusion detection, log data analysis, file integrity monitoring, and vulnerability management capabilities being adopted in a variety of industries that handle sensitive data. This infrastructure uses the Wazuh active response module to detect security threats and look for indications that one is starting up. Denial of Service (DoS), brute-force attacks, simulations, and integrity file delinquencies with tests as proofs tell stories about a good performance estimation when Elasticsearch and FileBeat application is used jointly. Wazuh provides a robust and cost-effective solution for enhancing the security posture of enterprise solutions. Wazuh instantly detects and monitors simulated attacks such as denial-of-service (DoS) attacks by spotting suspicious file changes in real-time, logging failure authentication attempts, and identifying the root source of the flood of requests. This study also provides useful insights on designing and deploying comprehensive cybersecurity solutions with opensource tools such as Wazuh, making visual insights for file integrity monitoring (FIM) in real time.

Description

Cataloged from PDF version of project report.
Includes bibliographical references (pages 53-55).
This project report is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science and Engineering, 2024.

Keywords

Cyber threat, Event management, Vulnerability management, Cost-effective solution, Endpoint detection, Open-source security, Real-time monitoring, Anomaly detection

Citation

Endorsement

Review

Supplemented By

Referenced By