Detección de anomalías con Elastic Stack

The dependence on technology makes companies nowday implement security through multiple levels in order to prevent the company from having problems of threats against information security and affecting its internal resources in a critical way. In this Master's thesis, the security solution base...

Descripción completa

Detalles Bibliográficos
Autor: Farinango Endara, Henry Patricio
Tipo de recurso: tesis de maestría
Fecha de publicación:2020
País:España
Institución:Universitat Oberta de Catalunya (UOC)
Repositorio:O2, repositorio institucional de la UOC
OAI Identifier:oai:openaccess.uoc.edu:10609/126629
Acceso en línea:http://hdl.handle.net/10609/126629
Access Level:acceso abierto
Palabra clave:seguridad empresarial
elastic stack
wazuh
seguretat empresarial
business security
Computer security -- TFM
Seguretat informàtica -- TFM
Seguridad informática -- TFM
Descripción
Sumario:The dependence on technology makes companies nowday implement security through multiple levels in order to prevent the company from having problems of threats against information security and affecting its internal resources in a critical way. In this Master's thesis, the security solution based on the 'all-in-one' architecture of Wazuh and Elastic Stack is implemented as a laboratory, in order to carry out proofs of concept for the detection of anomalies that occur in the devices on a LAN network, in this case specifically for servers that are in a DMZ, which makes up the Wazuh agent. In this way, the security contribution proactively with the collection of logs in real time, allows this system in question to generate alerts in case of attempted attacks and execute Active Response, an action that allows mitigating the detected incident. This project promotes the opensource software solutions, validating that it is a complete business security solution in the context of log data analysis to secure host of the internal business network. It is concluded that the solution is ideal for business environments of any kind, even more for small environments such as ours simulated. Considering that the way to automate responses against security incidents proposes a great alternative in the field of information technology.