Please use this identifier to cite or link to this item: https://hdl.handle.net/10356/177214
Full metadata record
DC FieldValueLanguage
dc.contributor.authorLoh, Yi Hongen_US
dc.date.accessioned2024-05-27T01:29:57Z-
dc.date.available2024-05-27T01:29:57Z-
dc.date.issued2024-
dc.identifier.citationLoh, Y. H. (2024). Malware detection with open source security information and event management (OSSIM). Final Year Project (FYP), Nanyang Technological University, Singapore. https://hdl.handle.net/10356/177214en_US
dc.identifier.urihttps://hdl.handle.net/10356/177214-
dc.description.abstractThe digital age has ushered in a golden era of innovation and connectivity. However, this interconnectedness has also created a breeding ground for cyber threats. Malicious actors are constantly developing new attack vectors, exploiting vulnerabilities, and breaching security perimeters. Traditional security solutions often struggle to keep pace with this ever-evolving threat landscape. In addition, modern organization rely on complex IT infrastructure with multiple endpoints and application. Enterprises are increasingly needing robust network security analysis system in the face of growing cyber threats. This final year project tackles the critical need for improved threat detection and response by developing and implementing a Security Information and Event Management (SIEM) system built on open-source tools. Wazuh, a comprehensive security monitoring and analysis platform, forms the core of this system. Wazuh consists of three key components: Wazuh-Indexer, Wazuh-Manager, and Wazuh-Dashboard. Working together, they provide a data collection, analysis, and visualization engine. Wazuh-Indexer acts as the central hub, collecting security logs from various sources like operating systems, network devices, and applications. Wazuh-Manager then analyses these indexed logs in real-time, identifying potential threats. Finally, Wazuh-Dashboard serves as the user interface, offering security personnel a centralized view of security events, alerts, and overall system health. Beyond Wazuh, the project leverages ElasticSearch for efficient log search, TheHive for managing security incidents and cases, and VirusTotal integration for multi-engine threat analysis. Additionally, Cassandra offers potential high-availability storage for specific datasets, while Shuffle facilitates data sharing, automation, and collaboration between these services. The successful implementation of this project will provide organizations with a cost-effective and effective security information and event management system, enhancing their overall security posture and mitigating cyber threats.en_US
dc.language.isoenen_US
dc.publisherNanyang Technological Universityen_US
dc.subjectComputer and Information Scienceen_US
dc.titleMalware detection with open source security information and event management (OSSIM)en_US
dc.typeFinal Year Project (FYP)en_US
dc.contributor.supervisorCheng Tee Hiangen_US
dc.contributor.schoolSchool of Electrical and Electronic Engineeringen_US
dc.description.degreeBachelor's degreeen_US
dc.contributor.supervisoremailETHCHENG@ntu.edu.sgen_US
dc.subject.keywordsSIEMen_US
dc.subject.keywordsMalwareen_US
item.grantfulltextrestricted-
item.fulltextWith Fulltext-
Appears in Collections:EEE Student Reports (FYP/IA/PA/PI)
Files in This Item:
File Description SizeFormat 
FYP Final Report.pdf
  Restricted Access
3.57 MBAdobe PDFView/Open

Page view(s)

219
Updated on Apr 25, 2025

Download(s)

29
Updated on Apr 25, 2025

Google ScholarTM

Check

Items in DR-NTU are protected by copyright, with all rights reserved, unless otherwise indicated.