Skip to content
Open access

Analyzing Wazuh-Based File Integrity Monitoring for Layered Academic Server Security

Aug 2026 · bit-Tech · 0 citations

TL;DR

The proposed system demonstrates the potential to serve as an effective and practical host-level security layer for strengthening cybersecurity resilience in academic server environments, although the evaluation was limited to three monitored servers and did not include advanced adversarial attack scenarios.

Abstract

Cybersecurity threats in academic institutions continue to increase, requiring layered protection mechanisms to secure academic services, student records, and research data from unauthorized modification. This study aims to analyze the effectiveness of File Integrity Monitoring (FIM) using Wazuh Security Information and Event Management (SIEM) as a host-based security layer within a Defense in Depth strategy. The research employed the PPDIOO (Prepare, Plan, Design, Implement, Operate, Optimize) methodology because it provides a systematic lifecycle framework for cybersecurity deployment, monitoring, and evaluation in academic server environments. The proposed monitoring system was implemented on three academic servers and tested through 90 controlled experimental scenarios involving file addition, modification, and deletion, while performance was evaluated based on detection accuracy, detection time, and resource efficiency. The experimental results showed that the Wazuh-based FIM successfully detected all unauthorized file changes with 100% accuracy (90/90 scenarios) within the predefined testing environment. The average detection time was 25.4 seconds, ranging from 24.7 to 26.3 seconds across all test cases, while system resource utilization remained stable with minimal operational overhead during continuous monitoring. These findings indicate that Wazuh-based FIM provides reliable near real-time detection of unauthorized file modifications under controlled integrity-monitoring conditions. Therefore, the proposed system demonstrates the potential to serve as an effective and practical host-level security layer for strengthening cybersecurity resilience in academic server environments, although the evaluation was limited to three monitored servers and did not include advanced adversarial attack scenarios.

Read PDF

Similar papers

Open access Jul 2026

SmartGaurd: Real-Time Behavioral Analysis System for Malicious File Activity Detection

A SmartGaurd: Real-Time Behavioral Analysis System for Malicious File Activity Detection is designed to protect confidential organizational data using a layered security architecture that improves data confidentiality while minimizing the risk of unauthorized data exposure.

Prachi Jadhav, Sai Jadhav, N. R. Devadiga et al. · 0 citations
Open access Jul 2026

Cloud Infrastructure Security: Detecting and Analyzing Attacks on Windows Server 2019

The research concludes that the integration of Wazuh SIEM with the MITRE ATT&CK framework is effective in detecting and analyzing cyber attacks on Windows Server 2019, with practical contributions in the form of implementation guidelines for rule-based detection and correlation rules for multi-stage attack detection.

Ikhwan Alfath Nurul Fathony, Affix Mareta, O. Wardhani et al. · 0 citations
#artificial intelligence Open access Nov 2026

A network-based security information system for safeguarding computer-based test platforms in organizational environments

Computer-based testing (CBT) platforms have transformed education and certification by enabling scalable, efficient, and accessible examinations. However, these systems face significant cybersecurity risks, including unauthorized access, denial-of-service (DoS) attacks, and digital cheating, which threaten fairness and reliability. This study proposes a network-based security information system (NBSIS) designed specifically for CBT environments. The framework integrates layered defense, including pfSense firewalls (FW), Snort intrusion detection, Splunk security information and event management (SIEM), and artificial intelligence (AI)-powered analytics, into a unified architecture. A human-centered dashboard ensures usability for non-technical exam administrators, providing real-time alerts and intuitive controls. Validation through simulated attack scenarios demonstrated strong resilience, with high detection accuracy, reduced false positives, and rapid response times. Comparative analysis against intrusion detection system (IDS)-only and SIEM-only systems confirmed superior performance. The findings highlight NBSIS as a robust, scalable, and adaptive solution that safeguards exam integrity while remaining practical for diverse organizational contexts. This research contributes to computer science by advancing secure architecture, applying AI-driven anomaly detection, and integrating human-computer interaction principles into cybersecurity for education.

Ajani Dele, Owolabi Abdulhakim Adewale, Inaya Adesuwa · 0 citations
Review

IN CLOUD AND

Key trends in the development of cloud service protection tools toward automation and intelligent monitoring are identified, along with the necessity of integrating technical security measures with organizational incident response procedures and continuous staff awareness training on current cyber threats.

Sahayda Anatolii, Andriiovych Student, Yurchenko Yurii Yuriiovych Senior Lecturer · 3 citations · ⚡1
Open access Jul 2026

Modern cybersecurity architecture for fraud prevention in administrative services

A cybersecurity architecture oriented toward fraud prevention in a service sector company in Lima, Peru, whose design is grounded in the documentary analysis of 385 technical incident records is proposed, forming a defense-in-depth capable of reducing residual exposure and sustaining a robust anti-fraud response in digitalized administrative environments.

Enrique Castellares Cuya, José Rengifo Espinal · 0 citations