Skip to content
Open access

Analyzing Wazuh-Based File Integrity Monitoring for Layered Academic Server Security

Aug 2026 · bit-Tech · Vol 9, pp. 262-271 · 0 citations

TL;DR

The proposed system demonstrates the potential to serve as an effective and practical host-level security layer for strengthening cybersecurity resilience in academic server environments, although the evaluation was limited to three monitored servers and did not include advanced adversarial attack scenarios.

Abstract

Cybersecurity threats in academic institutions continue to increase, requiring layered protection mechanisms to secure academic services, student records, and research data from unauthorized modification. This study aims to analyze the effectiveness of File Integrity Monitoring (FIM) using Wazuh Security Information and Event Management (SIEM) as a host-based security layer within a Defense in Depth strategy. The research employed the PPDIOO (Prepare, Plan, Design, Implement, Operate, Optimize) methodology because it provides a systematic lifecycle framework for cybersecurity deployment, monitoring, and evaluation in academic server environments. The proposed monitoring system was implemented on three academic servers and tested through 90 controlled experimental scenarios involving file addition, modification, and deletion, while performance was evaluated based on detection accuracy, detection time, and resource efficiency. The experimental results showed that the Wazuh-based FIM successfully detected all unauthorized file changes with 100% accuracy (90/90 scenarios) within the predefined testing environment. The average detection time was 25.4 seconds, ranging from 24.7 to 26.3 seconds across all test cases, while system resource utilization remained stable with minimal operational overhead during continuous monitoring. These findings indicate that Wazuh-based FIM provides reliable near real-time detection of unauthorized file modifications under controlled integrity-monitoring conditions. Therefore, the proposed system demonstrates the potential to serve as an effective and practical host-level security layer for strengthening cybersecurity resilience in academic server environments, although the evaluation was limited to three monitored servers and did not include advanced adversarial attack scenarios.

Read PDF

Similar papers

Open access Jul 2026

SmartGaurd: Real-Time Behavioral Analysis System for Malicious File Activity Detection

The rapid growth of digital documentation in enterprises has created significant challenges in ensuring secure storage, controlled access, and reliable auditing of sensitive information. This research presents a SmartGaurd: Real-Time Behavioral Analysis System for Malicious File Activity Detection  designed to protect confidential organizational data using a layered security architecture. The proposed system is developed using a React-based user interface for responsive and dynamic client interaction, while the server-side operations are handled through the Django framework, enabling robust authentication, authorization, and document processing. The platform integrates SQLite3 as the database engine to maintain structured document metadata, user credentials, and audit logs. To strengthen access control, the system incorporates One-Time Password (OTP) verification mechanisms and encryption techniques to ensure that only authorized users can access or download protected files. This architecture improves data confidentiality while minimizing the risk of unauthorized data exposure. The system workflow includes secure user authentication, encrypted document upload, malware inspection, controlled file sharing, and real-time audit logging to maintain transparency in document access activities. Whenever a user attempts to retrieve protected documents, the system dynamically generates an OTP to validate the request and prevent unauthorized downloads. Additionally, administrative and auditing modules monitor user behavior and maintain detailed activity logs that can be analyzed for compliance verification and anomaly detection. By combining modern web technologies (React and Django) with security mechanisms such as encryption and OTP-based validation, the proposed system provides a scalable and efficient approach to enterprise document security. The implementation demonstrates how integrated authentication, encryption, and auditing mechanisms can significantly enhance data protection while maintaining system usability and operational efficiency.

Prachi Jadhav, Sai Jadhav, N. R. Devadiga et al. · 0 citations
Open access Jul 2026

Cloud Infrastructure Security: Detecting and Analyzing Attacks on Windows Server 2019

Cloud infrastructure security represents a critical challenge in addressing cybersecurity threats, particularly for internet-facing services such as Remote Desktop Protocol (RDP) and SQL Server. This research investigates cloud infrastructure security based on Windows Server 2019 through the development of a proactive and responsive attack detection and analysis framework using the Wazuh platform as Security Information and Event Management (SIEM) integrated with the MITRE ATT&CK framework. The research method employs an experimental approach with continuous monitoring for 30 days of two Windows Server 2019 units running RDP and SQL Server services. Attack simulations were conducted using eight different scenarios including RDP brute force, SQL Server authentication brute force, port scanning, privilege escalation, lateral movement, data exfiltration, persistence mechanisms, and defense evasion. Monitoring results revealed 110,492 total security events, dominated by 109,057 authentication failures (98.7%) and only 171 successful authentications, with the remainder consisting of other activities such as port scanning and process execution. The Wazuh-based detection system with MITRE ATT&CK integration successfully mapped 15 attack techniques, 10 of which were actively observed during the 30-day monitoring period, with a detection rate of 93.2%, false positive rate of 6.8%, and average response time of 2.4 seconds. Compliance analysis showed 87% compliance with PCI DSS, 91% with NIST 800-53, 85% with HIPAA, and 89% with GDPR. The research concludes that the integration of Wazuh SIEM with the MITRE ATT&CK framework is effective in detecting and analyzing cyber attacks on Windows Server 2019, with practical contributions in the form of implementation guidelines for rule-based detection and correlation rules for multi-stage attack detection.

Ikhwan Alfath Nurul Fathony, Affix Mareta, O. Wardhani et al. · 0 citations
#artificial intelligence Open access Nov 2026

A network-based security information system for safeguarding computer-based test platforms in organizational environments

Computer-based testing (CBT) platforms have transformed education and certification by enabling scalable, efficient, and accessible examinations. However, these systems face significant cybersecurity risks, including unauthorized access, denial-of-service (DoS) attacks, and digital cheating, which threaten fairness and reliability. This study proposes a network-based security information system (NBSIS) designed specifically for CBT environments. The framework integrates layered defense, including pfSense firewalls (FW), Snort intrusion detection, Splunk security information and event management (SIEM), and artificial intelligence (AI)-powered analytics, into a unified architecture. A human-centered dashboard ensures usability for non-technical exam administrators, providing real-time alerts and intuitive controls. Validation through simulated attack scenarios demonstrated strong resilience, with high detection accuracy, reduced false positives, and rapid response times. Comparative analysis against intrusion detection system (IDS)-only and SIEM-only systems confirmed superior performance. The findings highlight NBSIS as a robust, scalable, and adaptive solution that safeguards exam integrity while remaining practical for diverse organizational contexts. This research contributes to computer science by advancing secure architecture, applying AI-driven anomaly detection, and integrating human-computer interaction principles into cybersecurity for education.

Ajani Dele, Owolabi Abdulhakim Adewale, Inaya Adesuwa · 0 citations
Review

IN CLOUD AND

Sahayda Anatolii, Andriiovych Student, Yurchenko Yurii Yuriiovych Senior Lecturer · 3 citations · ⚡1
Open access Jul 2026

Modern cybersecurity architecture for fraud prevention in administrative services

As service organizations advance in their digital modernization, security does not always keep pace, generating vulnerabilities that conventional protection schemes fail to address. To tackle this problem, the present work proposes a cybersecurity architecture oriented toward fraud prevention in a service sector company in Lima, Peru, whose design is grounded in the documentary analysis of 385 technical incident records. This analysis revealed that only 54.3% of vulnerabilities were addressed annually, with monthly fluctuations between 44.4% and 62.5%, while the effective response rate did not exceed 34%, reaching lows of 19% during periods of peak operational load. These findings, combined with the concentration of unresolved incidents in malware, unknown threats, and ransomware, expose structural failures in the prioritization and closure of security events. In response to this diagnosis, the proposed architecture integrates identity and access management, advanced threat protection, cloud security, regulatory compliance, and extended analytics powered by artificial intelligence, forming a defense-in-depth capable of reducing residual exposure and sustaining a robust anti-fraud response in digitalized administrative environments.

Enrique Castellares Cuya, José Rengifo Espinal · 0 citations