Improving Threat Detection with Elastic Stack based Security Information and Event Management
Suraj Regi · International Journal for Research in Applied Science and Engineering Technology · 2024
Abstract: In this digital era, where most businesses are transitioning from traditional to digital data storage methods, attackers are continuously developing new techniques and tools to target these systems. Security Information and Event Management (SIEM) systems have emerged as essential tools, providing a centralized platform for efficiently gathering and analyzing data to detect security breaches. This paper aims to explore an enhanced threat detection approach within the SIEM framework suitable for small to medium-sized organizations. Recognizing the cost constraints associated with traditional SIEM solutions, we have opted for an Elastic Stack-based SIEM solution. The Elastic Stack comprises open-source tools such as Elasticsearch, Logstash, and Kibana, offering scalability and cost efficiency. Additionally, we have integrated various other tools, such as VirusTotal, which provides real-time threat intelligence for detecting malicious files. Arkime, a network traffic analysis tool, has also been integrated with the SIEM system to enhance threat detection and incident response capabilities. Furthermore, the implementation includes the deployment of a honeypot to safeguard the network by diverting attackers from accessing it. This project is dedicated to consolidating these tools into an integrated SIEM solution aimed at improving threat detection and incident response capabilities.