Detección de anomalías con Elastic Stack
The dependence on technology makes companies nowday implement security through multiple levels in order to prevent the company from having problems of threats against information security and affecting its internal resources in a critical way. In this Master's thesis, the security solution base...
| Autor: | |
|---|---|
| Tipo de recurso: | tesis de maestría |
| Fecha de publicación: | 2020 |
| País: | España |
| Institución: | Universitat Oberta de Catalunya (UOC) |
| Repositorio: | O2, repositorio institucional de la UOC |
| OAI Identifier: | oai:openaccess.uoc.edu:10609/126629 |
| Acceso en línea: | http://hdl.handle.net/10609/126629 |
| Access Level: | acceso abierto |
| Palabra clave: | seguridad empresarial elastic stack wazuh seguretat empresarial business security Computer security -- TFM Seguretat informàtica -- TFM Seguridad informática -- TFM |
| Sumario: | The dependence on technology makes companies nowday implement security through multiple levels in order to prevent the company from having problems of threats against information security and affecting its internal resources in a critical way. In this Master's thesis, the security solution based on the 'all-in-one' architecture of Wazuh and Elastic Stack is implemented as a laboratory, in order to carry out proofs of concept for the detection of anomalies that occur in the devices on a LAN network, in this case specifically for servers that are in a DMZ, which makes up the Wazuh agent. In this way, the security contribution proactively with the collection of logs in real time, allows this system in question to generate alerts in case of attempted attacks and execute Active Response, an action that allows mitigating the detected incident. This project promotes the opensource software solutions, validating that it is a complete business security solution in the context of log data analysis to secure host of the internal business network. It is concluded that the solution is ideal for business environments of any kind, even more for small environments such as ours simulated. Considering that the way to automate responses against security incidents proposes a great alternative in the field of information technology. |
|---|