ejecip Open Access Journal

European Journal of Emerging Cybersecurity and Information Protection

eISSN: Applied
Publication Frequency : 2 Issues per year.

  • Peer Reviewed & International Journal
Table of Content
Issues (Year-wise)
Loading…

Open Access iconOpen Access

ARTICLE

AUGMENTING WAZUH SIEM WITH MACHINE LEARNING FOR ADVANCED CYBER THREAT ANALYTICS

1 Department of Computer Science, Sultan Qaboos University, Oman
2 Department of Computer Science, University of Tunis El Manar, Tunisia
3 Department of Cybersecurity, King Abdullah University of Science and Technology (KAUST), Saudi Arabia

Citations: Loading…
ABSTRACT VIEWS: 235   |   FILE VIEWS: 275   |   PDF: 275   HTML: 0   OTHER: 0   |   TOTAL: 510
Views + Downloads (Last 90 days)
Cumulative % included

Abstract

The escalating sophistication of cyber threats necessitates a paradigm shift from traditional, signature-based security measures to more dynamic, intelligent defense mechanisms. This article explores the enhancement of Wazuh, a widely adopted open-source Security Information and Event Management (SIEM) solution, through the integration of machine learning techniques. The primary limitation of rule-based systems, such as high false-positive rates and an inability to detect novel threats, is a significant challenge for modern Security Operations Centers (SOCs). This study proposes and evaluates a hybrid framework that integrates both supervised (K-Nearest Neighbors, Random Forest, Naive Bayes, Logistic Regression, Support Vector Machine) and unsupervised (DBSCAN, K-Means, Isolation Forest) machine learning models into the Wazuh detection pipeline. By leveraging algorithms such as these, this work demonstrates the potential to significantly improve threat detection rates, reduce false positives, and automate complex security event analysis. This study details a comprehensive framework for data collection in a simulated enterprise environment, extensive preprocessing and feature engineering, the application of various machine learning models for threat identification, and a rigorous comparative analysis of their performance. The findings indicate that the Random Forest classifier achieves a superior accuracy of 97.2%, while the DBSCAN algorithm demonstrates 91.1% accuracy in anomaly detection, significantly enhancing the quality of alerts. Furthermore, the real-world viability is assessed through latency and scalability testing, confirming that the proposed system can operate effectively within the stringent time constraints of a real-time SOC. This fusion of machine learning with Wazuh's robust monitoring capabilities offers a formidable, cost-effective, and scalable solution for organizations, particularly Small and Medium-sized Enterprises (SMEs), to bolster their cybersecurity posture against an evolving threat landscape. The article further discusses the practical implications, limitations, and future research directions, emphasizing the synergy between automated systems and human expertise within a modern SOC.


Keywords

Wazuh, SIEM, Machine Learning, Threat Detection

References

1. Chamkar, S.A.; Maleh, Y.; Gherabi, N. Security Operations Centers: Use Case Best Practices, Coverage, and Gap Analysis Based on MITRE Adversarial Tactics, Techniques, and Common Knowledge. J. Cybersecur. Priv. 2024, 4, 777–793.

2. Mokalled, H.; Catelli, R.; Casola, V.; Debertol, D.; Meda, E.; Zunino, R. The Applicability of a SIEM Solution: Requirements and Evaluation. In Proceedings of the 28th IEEE International Conference on Enabling Technologies: Infrastructure for Collaborative Enterprises, Naples, Italy, 12–14 June 2019.

3. Sheeraz, M.; Paracha, M.A.; Haque, M.U.; Durad, M.H.; Mohsin, S.M.; Band, S.S.; Mosavi, A. Effective security monitoring using efficient SIEM architecture. Hum.-Centric Comput. Inf. Sci. 2023, 13, 1–18.

4. Khayat, M.; Barka, E.; Serhani, M.A.; Sallabi, F.; Shuaib, K.; Khater, H.M. Empowering Security Operation Center with Artificial Intelligence and Machine Learning–A Systematic Literature Review. IEEE Access 2025, 13, 19162–19197.

5. Hughes, K.; McLaughlin, K.; Sezer, S. Dynamic countermeasure knowledge for intrusion response systems. In Proceedings of the 2020 31st Irish Signals and Systems Conference (ISSC), Letterkenny, Ireland, 11–12 June 2020; pp. 1–6.


How to Cite

AUGMENTING WAZUH SIEM WITH MACHINE LEARNING FOR ADVANCED CYBER THREAT ANALYTICS. (2024). European Journal of Emerging Cybersecurity and Information Protection, 1(01), 57-67. https://parthenonfrontiers.com/index.php/ejecip/article/view/84

Related articles

Share Link