Abstract

This research builds Security Information & Event Management (SIEM) based on live analysis using machine learning on Intrusion Detection System (IDS). To implement a live analysis technique on IDS using machine learning that is integrated with SIEM, we need a combined system with many processes and services. All processes and services must be orchestrated and combined into one system to make live analysis work. Selection of the right components to be combined into a system that can build live analysis techniques on IDS using machine learning that are integrated with SIEM is needed. In addition, an open-source system for easy deployment is needed in the industrial application. Therefore, this research tries to build the system using most common open-source components for cyberattack live analysis, detection, and monitoring. This research uses a combination of Elastic (ELK) Stack, Slips, and Zeek IDS to build the system. To ensure that the components selected are correct, robust, and reliable, it is necessary to measure the performance of the combined system. Measurement focuses on measuring the performance of resource consumption (CPU and RAM). The proposed system is testing using Denial of Service (DoS) test with 344.1/sec packet. The performance testing shows Elasticsearch is the most component that uses CPU and RAM consumption with 78% of CPU usage and 2300 Mb of RAM usage. The least CPU and RAM consumption is Zeek with 3.5% CPU usage and 225 Mb RAM usage. The proposed system also worked for detecting DoS attacks on the network.

Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.