International Journal of Innovative Research in Computer and Communication Engineering

ISSN Approved Journal | Impact factor: 8.771 | ESTD: 2013 | Follows UGC CARE Journal Norms and Guidelines

| Monthly, Peer-Reviewed, Refereed, Scholarly, Multidisciplinary and Open Access Journal | High Impact Factor 8.771 (Calculated by Google Scholar and Semantic Scholar | AI-Powered Research Tool | Indexing in all Major Database & Metadata, Citation Generator | Digital Object Identifier (DOI) |


TITLE Design and Implementation of an Enhanced SIEM (Wazuh) Framework with SOAR, XDR, and ARP Spoofing Detection
ABSTRACT Cyber threats are continuously evolving, making traditional security monitoring insufficient for modern organizations. Security Information and Event Management (SIEM), Extended Detection and Response (XDR), Intrusion Detection Systems (IDS), and Security Orchestration, Automation and Response (SOAR) technologies play a crucial role in identifying, analyzing, and responding to cyberattacks. This project presents the design and implementation of a cybersecurity monitoring laboratory using Wazuh SIEM, Suricata IDS, and Ubuntu Linux. The environment simulates real-world attacks from a Kali Linux attacker machine and demonstrates centralized log collection, threat detection, alert generation, attack visibility, and automated notification capabilities. The project also explores ARP spoofing attacks, network monitoring, active response concepts, and email-based alerting mechanisms. The implemented solution provides a cost-effective open-source security monitoring platform suitable for learning, research, and small-scale enterprise environments. The results demonstrate the effectiveness of combining multiple security technologies in a unified monitoring framework to detect and respond to modern cyber threats in real time.
AUTHOR MEDHA C CHALAGERI, G. CHIDAMBARAM, A.SUDHAKAR PG Student, Department of Computer Science and Engineering, Bharathidasan Engineering College, Vellore, Tamil Nadu, India Assistant Professor, Department of Computer Science and Engineering, Bharathidasan Engineering College, Vellore, Tamil Nadu, India Head of the Department, Department of Computer Science and Engineering, Bharathidasan Engineering College, Vellore, Tamil Nadu, India
VOLUME 185
DOI DOI: 10.15680/IJIRCCE.2026.1406046
PDF pdf/46_Design and Implementation of an Enhanced SIEM (Wazuh) Framework with SOAR, XDR, and ARP Spoofing Detection.pdf
KEYWORDS
References [1] L. Fachruddin and S. Neyman, “Analisis Integrasi Security Information and Event Management (SIEM) Wazuh dengan Suricata pada Azure Cloud Web Server,” Repository IPB University, 2023. [Online]. Available: https://repository.ipb.ac.id/handle/123456789/136766
[2] G.-R. Andreica, I.-A. Ivanciu, D. Zinca, and V. Dobrota, “Integration of the Suricata Intrusion Detection System and of the Wazuh Security Information and Event Management for Real-Time Denial-of-Service and Data Tampering Detection and Alerting,” Technical University of Cluj-Napoca, 2024. [Online]. Available: https://oasis.utcluj.app/items/06fe9ec4-df09-48aa-a00a-b2419a3e3eb4
[3] M. Vasilakis, M. G. Tampouratzis, and A. Dimitriadis, “Integrated Threat Intelligence and Event Correlation with Wazuh, Suricata, and MISP,” in Proc. 6th Int. Conf. Communications, Information, Electronic and Energy Systems (CIEES), 2025, doi: 10.1109/CIEES66347.2025.11300009.
[4] R. S. Chouhan, Y. S. Bisht, and V. Rawat, “A Fuzzy Logic-Based Intrusion Detection and Prevention System Using Suricata, Wazuh and MITRE ATT&CK Framework for Virtualized Network Environments,” IJRASET, vol. 14, no. 4, 2026. doi: 10.22214/ijraset.2026.81227.
[5] M. S. R. Setyo, “Implementasi SIEM (Security Information & Event Management) Menggunakan Wazuh & Suricata Untuk Monitoring Dalam Lingkup Departemen Teknologi Informasi,” ITS Repository, 2023. [Online]. Available: https://repository.its.ac.id/101897/.
[6] B. Alboushy et al., “Context-Aware Web Attack Detection in Open-Source SIEM Systems via MITRE ATT&CK-Enriched Behavioral Profiling,” arXiv preprint arXiv:2605.13337, 2026. [Online]. Available: https://arxiv.org/abs/2605.13337
[7] H. A. Damanik and M. Anggraeni, “Hybrid Intrusion Detection System and Network Infrastructure Vulnerability Mitigation using Active Response (XDR) Technique Wazuh and Suricata,” Jurnal Pekommas, vol. 9, no. 2, 2024. doi: 10.56873/jpkm.v9i2.5829.
[8] H. A. Damanik and M. Anggraeni,
“Hybrid Intrusion Detection System and Network Infrastructure Vulnerability Mitigation using Active Response (XDR) Technique Wazuh and Suricata,” Jurnal Pekommas, vol. 9, no. 2, pp. 309–322, Dec. 2024, doi: 10.56873/jpkm.v9i2.5829.
[9] G.-R. Andreica, I.-A. Ivanciu, D. Zinca, and V. Dobrota,
“Integration of the Suricata Intrusion Detection System and of the Wazuh Security Information and Event Management for Real-Time Denial-of-Service Detection,” in Proc. CIEES, 2024, doi: 10.1109/CIEES66347.2025.11300009.
[10] B. Alboushy et al.,
“Context-Aware Web Attack Detection in Open-Source SIEM Systems via MITRE ATT&CK-Enriched Behavioral Profiling,” arXiv preprint arXiv:2605.13337, 2026.
[11] R. A. Bridges et al.,
“Testing SOAR Tools in Use,” arXiv preprint arXiv:2208.06075, 2022.
[12] M. Vasilakis, M. G. Tampouratzis, and A. Dimitriadis,
“Integrated Threat Intelligence and Event Correlation with Wazuh, Suricata, and MISP,” in 2025 6th Int. Conf. Communications, Information, Electronic and Energy Systems (CIEES), 2025.
[13] H. Kim et al.,
“Enhancing Security Operations Center: Wazuh Security Event Response with Retrieval-Augmented Generation-Driven Copilot,” Sensors, vol. 25, no. 3, p. 870, 2025, doi: 10.3390/s25030870.
[14] J. M. P. Silva et al.,
“Modeling Wazuh Rules with Weighted Timed Automata,” Procedia Computer Science, vol. 251, pp. 75–82, 2024, doi: 10.1016/j.procs.2024.11.086.
[15] M. Al-Siam et al.,
“Improving Threat Detection in Wazuh Using Machine Learning Techniques,” J. Cybersecur. Priv., vol. 5, no. 2, 2025.
[16] A. A. Katresna,
“Integrasi Wazuh dan Suricata (IDS) untuk Deteksi Medusa Ransomware,” Polibatam Repository, 2025.
image
Copyright © IJIRCCE 2020.All right reserved