Organization-wide IOC Monitoring and Security Compliance in Endpoints using Open Source Tools

P J Divya, Reenu Sara George, G Madhusudhan, S. Padmasree · 2022 IEEE 3rd Global Conference for Advancement in Technology (GCAT) · 2022

Endpoint Security is an important layer in cyber security and it is one of the first places organizations look to secure their enterprise network. Proactively and iteratively monitoring endpoints for threats and Indicators of Compromise (IOC), helps security analysts to detect malware/attacks and to respond to incidents quickly. An Indicator of Compromise (IOC) refers to data that indicates that a system may have been infiltrated by a cyber-threat. Cyber security agencies send regular cyber-alerts to various organizations nation-wide and provide IOC list in the form of hashes, IPs, URLs, domains, yara rules, etc. for monitoring the presence of IOCs in their respective network. Periodic auditing of endpoints for security compliance is also a challenging and time-consuming task for every organization. To overcome these challenges, a solution based on client-server architecture is proposed in organizational network using open-source tools named Osquery, Fleet, Filebeat and Graylog. Using these tools, endpoints can be monitored for IOCs on demand or on scheduled manner from a central server. Yara based scan can also be performed efficiently in endpoints to monitor for IOCs using this architecture. In addition to IOC monitoring, this paper explains verifying compliance of endpoints with the organization's security policy using the proposed setup. Impact on performance of the endpoints during query execution was also analyzed. This solution will contribute in strengthening the endpoint security which in turn enhances overall cyber-security posture of the organization.

Read the paper · More papers on PaperTik