This article presents the implementation of a Wazuh SIEM platform at Innotech-EC with the aim of strengthening its security posture through log correlation and integration with a firewall. This project aims to improve the detection and response to security incidents; a mixed methodology was used for its development, bibliographic information from cybersecurity projects was collected, a survey was conducted with the company’s staff, and a GAP vulnerability analysis was performed. Subsequently, a server was installed as the central component along with its agents on the staff’s computers. The collection of agent information was considered for a month, during which the presence of: suspicious malware on the computers, the use of simple passwords to access the Windows operating system, pending updates, and the version of the host operating systems was detected. With these obtained results, it is demonstrated that the implementation of the SIEM has been effective in the evaluation of the infrastructure, the detection of threats, and the fulfillment of the established security objectives.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Strengthening Perimeter and Endpoint Infrastructure With Open Source SIEM Platform Wazuh

  • Cesar Cruz-Toscano,
  • Iván Andocilla-Oleas,
  • Tannia Mayorga-Jácome,
  • Henry Vivanco-Herrera

摘要

This article presents the implementation of a Wazuh SIEM platform at Innotech-EC with the aim of strengthening its security posture through log correlation and integration with a firewall. This project aims to improve the detection and response to security incidents; a mixed methodology was used for its development, bibliographic information from cybersecurity projects was collected, a survey was conducted with the company’s staff, and a GAP vulnerability analysis was performed. Subsequently, a server was installed as the central component along with its agents on the staff’s computers. The collection of agent information was considered for a month, during which the presence of: suspicious malware on the computers, the use of simple passwords to access the Windows operating system, pending updates, and the version of the host operating systems was detected. With these obtained results, it is demonstrated that the implementation of the SIEM has been effective in the evaluation of the infrastructure, the detection of threats, and the fulfillment of the established security objectives.