Second Modification

هذا الالتزام موجود في:
2026-07-28 12:32:40 +03:00
الأصل 5e1dc7b2dd
التزام d2dbeaf675
14 ملفات معدلة مع 585 إضافات و0 حذوفات

عرض الملف

@@ -0,0 +1,81 @@
Task4:
1. Python Script to Collect and Analyze Logs
Objective
Develop a simple SIEM (Security Information and Event Management) system that collects logs from three different sources, analyzes them, and detects suspicious activities.
Log Sources
The SIEM collects logs from the following sources:
1. System Logs (system.log)
• Login attempts
• User authentication
• System events
2. Web Server Logs (nginx.log)
• HTTP requests
• Status codes
• Client IP addresses
3. Application Logs (application.log)
• Authentication failures
• SQL Injection attempts
• Application errors
Detection Rules
The Python script should detect the following suspicious activities:
Event Severity
Multiple failed login attempts Medium
SQL Injection attempts High
Cross-Site Scripting (XSS) attempts High
Port scanning High
Large number of HTTP 404 errors Medium
Root login attempts Critical
Detection Process
Read Log Files
Parse Log Entries
Match Detection Rules
Generate Security Alerts
Store Alerts in alerts.json
E.G.
• More than 10 failed logins from the same IP within one minute → Generate a Medium Alert
• Detection of SQL Injection → Generate a Critical Alert
________________________________________
2. SIEM Dashboard Design
The dashboard provides a visual overview of security events.
Dashboard Components
• Total number of alerts
• Alert severity statistics
• Top suspicious IP addresses
• Recent security events
• Alert history
________________________________________
3. Deploying the SIEM on Ghaymah Cloud
Deployment Architecture
Log Sources
Python SIEM Engine => Block Storage => alerts.json => Web Dashboard
Deployment Steps
1. Create a Virtual Machine on Ghaymah Cloud.
2. Install Python and Docker.
3. Upload the SIEM project.
4. Mount Ghaymah Block Storage to store log files permanently.
5. Run the Python monitoring script.
6. Deploy the dashboard using Nginx.
7. Access the dashboard through a web browser.
Why Use Block Storage?
Using Ghaymah Block Storage provides:
• Persistent storage
• Reliable log retention
• Easy backup and recovery
• Scalability for large log files
Future Improvements
• Integrate Elasticsearch for log indexing.
• Use Grafana or Kibana for advanced visualization.
• Send alerts through email or Slack.
• Deploy the SIEM inside Kubernetes.
• Add machine learning for anomaly detection.