The diploma thesis addresses the development of an experimental Security
Information and Event Management system that enables the collection, nor-
malization, stream processing, storage, and analysis of security events. The
system is based on a modular architecture in which synthetically generated
log records and system metrics are transformed into the standardized OCSF
format and forwarded through the messaging system Redpanda. As part
of the thesis, an analytical module for threat detection based on rules and
anomalies is implemented, together with multi-tier data storage using hot
and cold storage. The result of the thesis is a working SIEM system pro-
totype that demonstrates the usefulness of modern streaming architectures
and analytics in the detection of security incidents.
|