Log Correlation with Wazuh: Integration with IDS, Firewall, XDR and other network tools

sentinelcore-dognettechnologies

Introduction

The correlation of logs has become a critical component in modern cyber defense. In a complex network environment, where threats can manifest through multiple carriers, the ability to aggregate, normalize and correlate events from different sources is essential to detect sophisticated attacks and reduce false positives. Wazuh, an open-source security solution, offers powerful log correlation features that can be integrated with various network tools to create a complete detection and response system.

Fundamentals of Log Correlation

The correlation of logs allows to identify patterns and relationships between apparently disconnected events, revealing malicious activities that could go unnoticed if analyzed isolatedly. Some key benefits include:

  • Detection of advanced threats: Multi-phase attack identification
  • Reduction of false positives: Confirming threats through related events
  • Complete visibility: holistic understanding of the state of safety
  • Acceleration of investigation: Reduction of analysis and response times

Wazuh Architecture for Log Correlation

Wazuh works as a SIEM (Security Information and Event Management) system that can collect, decode and analyze data from different sources. Its architecture is based on:

  • Wazuh Manager: The central component that receives and analyzes data
  • Wazuh Agent: Installed on endpoint devices to collect local data
  • Elastic Stack: For archiving, indexing and displaying data

Integration with Network Tools

Suricata IDS

Suricata is a powerful open-source IDS/IPS engine that can be integrated with Wazuh to significantly increase detection capabilities.

Configuration of integration:

  1. Installation of Suricata:
sudo apt-get install suricata
  1. Configuration of Suricata output in JSON format:
    Edit /etc/suricata/suricata.yaml:
outputs:
  - eve-log:
      enabled: yes
      filetype: regular
      filename: /var/log/suricata/eve.json
      types:
        - alert
  1. Wazuh configuration to read Suricata alerts:
    Add to Wazuh configuration file (/var/ossec/etc/ossec.conf):
<ossec_config>
  <localfile>
    <log_format>json</log_format>
    <location>/var/log/suricata/eve.json</location>
  </localfile>
</ossec_config>
  1. Creating custom correlation rules:
    Add a custom rules file in /var/ossec/etc/rules/suricata_correlation_rules.xml:
<group name="suricata,correlation,">
  <rule id="100001" level="10">
    <if_sid>86601</if_sid>
    <field name="alert.signature">SQL Injection</field>
    <description>Possible SQL injection attack detected</description>
  </rule>

  <rule id="100002" level="12">
    <if_sid>100001</if_sid>
    <if_group>authentication_success</if_group>
    <same_source_ip />
    <description>SQL injection followed by successful authentication</description>
  </rule>
</group>

Firewall (pfSense/OPNsense)

Integrating firewall logs allows you to correlate network access events with other security tasks.

Configuration of integration:

  1. Configuration of pfSense to send logs to Syslog:
  • Login to pfSense web interface
  • Go to Status > System Logs > Settings
  • Enable Remote Logging
  • Add your Wazuh server IP address
  1. Wazuh configuration to receive Syslog logs:
    Edit /var/ossec/etc/ossec.conf:
<ossec_config>
  <remote>
    <connection>syslog</connection>
    <port>514</port>
    <protocol>udp</protocol>
  </remote>
</ossec_config>
  1. Rules of correlation for the firewall:
<rule id="100101" level="10">
  <if_sid>4100</if_sid> <!-- pfSense block rule -->
  <field name="action">block</field>
  <description>Blocked connection attempt</description>
</rule>

<rule id="100102" level="12">
  <if_sid>100101</if_sid>
  <if_matched_sid>100001</if_matched_sid> <!-- SQL injection rule -->
  <same_source_ip />
  <timeframe>300</timeframe>
  <description>SQL injection attempt after blocked connection</description>
</rule>

XDR (Endpoint Detection and Response)

Integration with XDR solutions to correlate endpoint events with other network activities.

Configuration of integration:

  1. Install Agent Wazuh on endpoint with XDR:
curl -so wazuh-agent.deb https://packages.wazuh.com/4.x/apt/pool/main/w/wazuh-agent/wazuh-agent_4.3.10-1_amd64.deb && sudo dpkg -i wazuh-agent.deb
  1. Configure Wazuh to collect logs from XDR solution:
    If XDR generates logs in JSON format:
<ossec_config>
  <localfile>
    <log_format>json</log_format>
    <location>/var/log/xdr/alerts.json</location>
  </localfile>
</ossec_config>
  1. Rules of correlation for XDR:
<rule id="100201" level="10">
  <decoded_as>json</decoded_as>
  <field name="source">xdr</field>
  <field name="alert_type">malware_detected</field>
  <description>XDR detected potential malware</description>
</rule>

<rule id="100202" level="14">
  <if_sid>100201</if_sid>
  <if_matched_sid>100001</if_matched_sid> <!-- SQL injection rule -->
  <same_source_ip />
  <timeframe>600</timeframe>
  <description>Possible coordinated attack: SQL injection and malware detected</description>
</rule>

Router and Switch (Cisco)

Integrating logs from network devices is crucial to having a complete vision of security.

Configuration of integration:

  1. Configuration of the Cisco router to send logs to Syslog:
router# configure terminal
router(config)# logging host 192.168.1.100
router(config)# logging trap notifications
router(config)# logging facility local7
router(config)# end
  1. Wazuh configuration to receive Syslog logs:
    Edit /var/ossec/etc/ossec.conf (as already shown for firewalls)
  2. Rules of correlation for routers:
<rule id="100301" level="8">
  <if_sid>4000</if_sid> <!-- Cisco router alerts -->
  <match>SECURITY-6-IPACCESSLOGP</match>
  <description>Cisco router access denied</description>
</rule>

<rule id="100302" level="12">
  <if_sid>100301</if_sid>
  <if_matched_sid>100101</if_matched_sid> <!-- Firewall block rule -->
  <same_source_ip />
  <timeframe>120</timeframe>
  <description>Potential network scan: Multiple access denied events</description>
</rule>

Wireless Access

Monitoring Wireless APs can help detect attacks such as rogue access points or brute force attempts.

Configuration of integration:

  1. AP configuration to send logs to Syslog:
    The configuration depends on the supplier, but generally similar to the router.
  2. Related Rules for AP Wireless:
<rule id="100401" level="8">
  <if_sid>4000</if_sid>
  <match>authentication failed</match>
  <description>Failed authentication on wireless AP</description>
</rule>

<rule id="100402" level="12">
  <if_sid>100401</if_sid>
  <same_source_ip />
  <timeframe>60</timeframe>
  <frequency>5</frequency>
  <description>Potential brute force attack on wireless AP</description>
</rule>

Creation of Correlation Dashboard

Wazuh integrated with Kibana allows you to create custom dashboards to view and analyze related data.

Example of dashboard for Suricata-Firewall correlation:

  1. Creating a display of related events:
  • Login to Kibana
  • Go to Visualize > Create new visualization
  • Select "Pie chart"
  • Filter for rule.groups:correlation
  • Dividends rule.description
  1. Creating a timeline of related events:
  • Select "Vertical bar chart"
  • Filter for rule.level:>=10
  • Divide by timestamp (an hour interval)
  • Subdivided rule.description

Advanced Correction Rules implementation

Correlation based on behavior patterns

<rule id="100501" level="14">
  <if_matched_sid>100001</if_matched_sid> <!-- SQL injection -->
  <if_matched_sid>100201</if_matched_sid> <!-- Malware XDR -->
  <if_matched_sid>100301</if_matched_sid> <!-- Router access denied -->
  <timeframe>1800</timeframe>
  <same_source_ip />
  <description>Potential APT attack: Multiple security events from same source</description>
</rule>

Context-based correlation

<rule id="100502" level="15">
  <if_sid>100001</if_sid> <!-- SQL injection -->
  <field name="srcip">^10\.0\.0\.</field> <!-- Internal network -->
  <description>Internal SQL injection attempt: Possible compromised host</description>
</rule>

Time correction

<rule id="100503" level="13">
  <if_matched_sid>100101</if_matched_sid> <!-- Firewall block -->
  <if_matched_sid>100401</if_matched_sid> <!-- Wireless auth failed -->
  <timeframe>300</timeframe>
  <same_source_ip />
  <description>Potential lateral movement: Network and wireless attacks</description>
</rule>

Automated Response to Related Events

Wazuh supports automatic response to related events through its Active Response system.

Configuration of Active Response to block suspicious IP:

  1. Definition of commands:
<command>
  <name>block-ip</name>
  <executable>firewall-drop.sh</executable>
  <expect>srcip</expect>
  <timeout_allowed>yes</timeout_allowed>
</command>
  1. Configuration of active responses:
<active-response>
  <command>block-ip</command>
  <location>server</location>
  <rules_id>100502,100503</rules_id> <!-- High-level correlation rules -->
  <timeout>600</timeout>
</active-response>

Performance optimization

To manage large volumes of data, it is important to optimize system performance:

  1. Efficient indexing:
  • Use hot/warm/cold architecture in Elasticsearch
  • Optimize field mapping
  1. Filtering logs:
  • Set filters to eliminate unnecessary events
  • Use <if_sid> in the rules to reduce processing load
  1. Scalability:
  • Implement a Wazuh cluster to distribute the load
  • Use multiple Elasticsearch nodes to manage high data volumes

Cases of Study

Case 1: Detection of a Multi-phase Attack

An attack begins with an attempt by SQL injection detected by Suricata, followed by an abnormal access detected by the XDR and ends with the execution of a suspicious process. Thanks to the correlation rules, the system is able to connect these events and generate a single high-level alert.

Case 2: Reduction of Positive False

A false positive generated by Suricata is automatically declassified because there are no related events from other sources in the specified observation period.

Conclusion

The correlation of logs with Wazuh is a powerful tool to improve the security posture of an organization. By integrating different data sources and creating meaningful correlation rules, you can get a full view of the security state and detect threats that otherwise could go unnoticed.

The effectiveness of this approach depends on the quality of the correlation rules and the ability to adapt them to the specific needs of the environment. It is important to constantly review and refine these rules based on false positives and new attack vectors that emerge.

Resources and Tools


It might also interest you

EnglishenEnglishEnglish