Optimizing endpoint detection and monitoring in enterprise solution : a cyber threat intelligence approach
| dc.contributor.advisor | Seraj, Mehnaz | |
| dc.contributor.author | Sarker, Apurba | |
| dc.contributor.author | Mondal, Joty Prokash | |
| dc.contributor.author | Pran, Suzaur Rashid | |
| dc.contributor.author | Islam, AR Rafiu | |
| dc.contributor.department | Department of Computer Science and Engineering | |
| dc.date.accessioned | 2025-06-29T08:45:13Z | |
| dc.date.available | 2025-06-29T08:45:13Z | |
| dc.date.copyright | 2024 | |
| dc.date.issued | 2024-09 | |
| dc.description | Cataloged from PDF version of project report. | |
| dc.description | Includes bibliographical references (pages 53-55). | |
| dc.description | This project report is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science and Engineering, 2024. | en_US |
| dc.description.abstract | Advanced cyber threat intelligence systems are crucial in a time when enterprise solutions are increasing and are being targeted by more sophisticated cyberattacks. This research aims to study ways to improve endpoint detection and monitoring in an enterprise company by installing a Security Information and Event Management (SIEM) system based on Wazuh with integration into ELK Stack. The report performs an inside-out examination of the integration and deployment capability for each technology, focusing on real-time anomaly detection and threat mitigation toolkits at complied states. Together, these techniques create a powerful combination of analytical security, intrusion detection, log data analysis, file integrity monitoring, and vulnerability management capabilities being adopted in a variety of industries that handle sensitive data. This infrastructure uses the Wazuh active response module to detect security threats and look for indications that one is starting up. Denial of Service (DoS), brute-force attacks, simulations, and integrity file delinquencies with tests as proofs tell stories about a good performance estimation when Elasticsearch and FileBeat application is used jointly. Wazuh provides a robust and cost-effective solution for enhancing the security posture of enterprise solutions. Wazuh instantly detects and monitors simulated attacks such as denial-of-service (DoS) attacks by spotting suspicious file changes in real-time, logging failure authentication attempts, and identifying the root source of the flood of requests. This study also provides useful insights on designing and deploying comprehensive cybersecurity solutions with opensource tools such as Wazuh, making visual insights for file integrity monitoring (FIM) in real time. | en_US |
| dc.description.degree | Bachelor of Science in Computer Science | |
| dc.description.statementofresponsibility | Apurba Sarker | |
| dc.description.statementofresponsibility | Joty Prokash Mondal | |
| dc.description.statementofresponsibility | Suzaur Rashid Pran | |
| dc.description.statementofresponsibility | AR Rafiu Islam | |
| dc.format.extent | 55 pages | |
| dc.identifier.other | ID 18301256 | |
| dc.identifier.other | ID 18301146 | |
| dc.identifier.other | ID 18301223 | |
| dc.identifier.other | ID 18301298 | |
| dc.identifier.uri | http://hdl.handle.net/10361/26424 | |
| dc.language.iso | en | en_US |
| dc.publisher | BRAC University | en_US |
| dc.rights | BRAC University theses reports are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. | |
| dc.subject | Cyber threat | en_US |
| dc.subject | Event management | en_US |
| dc.subject | Vulnerability management | en_US |
| dc.subject | Cost-effective solution | en_US |
| dc.subject | Endpoint detection | en_US |
| dc.subject | Open-source security | en_US |
| dc.subject | Real-time monitoring | en_US |
| dc.subject | Anomaly detection | en_US |
| dc.subject.lcsh | Computer security. | |
| dc.subject.lcsh | Computer networks--Security measures. | |
| dc.subject.lcsh | Real time--Data processing. | |
| dc.subject.lcsh | Cyberinfrastructure--Security measures. | |
| dc.subject.lcsh | Cyberterrorism--Prevention. | |
| dc.title | Optimizing endpoint detection and monitoring in enterprise solution : a cyber threat intelligence approach | en_US |
| dc.type | Project Report | en_US |