Second Modification
هذا الالتزام موجود في:
81
q4-SIEM-and-Log-Analysis/q4-SIEM-and-Log-Analysis.md
Normal file
81
q4-SIEM-and-Log-Analysis/q4-SIEM-and-Log-Analysis.md
Normal file
@@ -0,0 +1,81 @@
|
||||
Task4:
|
||||
|
||||
1. Python Script to Collect and Analyze Logs
|
||||
Objective
|
||||
Develop a simple SIEM (Security Information and Event Management) system that collects logs from three different sources, analyzes them, and detects suspicious activities.
|
||||
Log Sources
|
||||
The SIEM collects logs from the following sources:
|
||||
1. System Logs (system.log)
|
||||
• Login attempts
|
||||
• User authentication
|
||||
• System events
|
||||
2. Web Server Logs (nginx.log)
|
||||
• HTTP requests
|
||||
• Status codes
|
||||
• Client IP addresses
|
||||
3. Application Logs (application.log)
|
||||
• Authentication failures
|
||||
• SQL Injection attempts
|
||||
• Application errors
|
||||
|
||||
Detection Rules
|
||||
The Python script should detect the following suspicious activities:
|
||||
Event Severity
|
||||
Multiple failed login attempts Medium
|
||||
SQL Injection attempts High
|
||||
Cross-Site Scripting (XSS) attempts High
|
||||
Port scanning High
|
||||
Large number of HTTP 404 errors Medium
|
||||
Root login attempts Critical
|
||||
|
||||
|
||||
Detection Process
|
||||
Read Log Files
|
||||
↓
|
||||
Parse Log Entries
|
||||
↓
|
||||
Match Detection Rules
|
||||
↓
|
||||
Generate Security Alerts
|
||||
↓
|
||||
Store Alerts in alerts.json
|
||||
|
||||
E.G.
|
||||
• More than 10 failed logins from the same IP within one minute → Generate a Medium Alert
|
||||
• Detection of SQL Injection → Generate a Critical Alert
|
||||
________________________________________
|
||||
2. SIEM Dashboard Design
|
||||
The dashboard provides a visual overview of security events.
|
||||
Dashboard Components
|
||||
• Total number of alerts
|
||||
• Alert severity statistics
|
||||
• Top suspicious IP addresses
|
||||
• Recent security events
|
||||
• Alert history
|
||||
|
||||
________________________________________
|
||||
3. Deploying the SIEM on Ghaymah Cloud
|
||||
Deployment Architecture
|
||||
Log Sources
|
||||
Python SIEM Engine => Block Storage => alerts.json => Web Dashboard
|
||||
Deployment Steps
|
||||
1. Create a Virtual Machine on Ghaymah Cloud.
|
||||
2. Install Python and Docker.
|
||||
3. Upload the SIEM project.
|
||||
4. Mount Ghaymah Block Storage to store log files permanently.
|
||||
5. Run the Python monitoring script.
|
||||
6. Deploy the dashboard using Nginx.
|
||||
7. Access the dashboard through a web browser.
|
||||
Why Use Block Storage?
|
||||
Using Ghaymah Block Storage provides:
|
||||
• Persistent storage
|
||||
• Reliable log retention
|
||||
• Easy backup and recovery
|
||||
• Scalability for large log files
|
||||
Future Improvements
|
||||
• Integrate Elasticsearch for log indexing.
|
||||
• Use Grafana or Kibana for advanced visualization.
|
||||
• Send alerts through email or Slack.
|
||||
• Deploy the SIEM inside Kubernetes.
|
||||
• Add machine learning for anomaly detection.
|
||||
|
||||
المرجع في مشكلة جديدة
حظر مستخدم