Analysis of Wazuh SIEM's Effectiveness in Cloud Security Monitoring
Wasan Saad Ahmed1,*, Ziyad Tariq Mustafa AL-Ta’I1
1Computer Science Department, College of Science, University of Diyala, Diyala, Iraq
Emails: wasan@uodiyala.edu.iq; ziyad1964tariq@uodiyala.edu.iq
Abstract
In today’s rapidly evolving digital landscape and interconnected, organizations are increasingly dependent on cloud -based infrastructure, which introduces significant cybersecurity challenges due to escalating cyber threats and attacks. To effectively manage these threats, a central monitoring system is essential. Security Information and Event Management (SIEM) solution address these issues by providing real-time monitoring and analysis of security events. This research investigates the efficiency of the Wazuh SIEM system in monitoring AWS cloud services, EC2 instance, and File integrity. Wazuh automates the collection, centralization, and analysis of security events. This approach enables the detection of unauthorized activities, monitoring of file integrity, and collection of user activity logs in real-time. This study evaluates Wazuh SIEM's capabilities by executing different types of attacks in an AWS cloud environment. The result was that it generated 1774 security alert within one week. The findings demonstrate that Wazuh SIEM provides comprehensive security monitoring and threat detection, offering significant advantages for organizations security that utilize cloud services.
Keywords: Cloud Computing; Cloud Monitoring; Wazuh; Network security; Security Information