Analyzing Wazuh-Based File Integrity Monitoring for Layered Academic Server Security
Abstract
Cybersecurity threats in academic institutions continue to increase, requiring layered protection mechanisms to secure academic services, student records, and research data from unauthorized modification. This study aims to analyze the effectiveness of File Integrity Monitoring (FIM) using Wazuh Security Information and Event Management (SIEM) as a host-based security layer within a Defense in Depth strategy. The research employed the PPDIOO (Prepare, Plan, Design, Implement, Operate, Optimize) methodology because it provides a systematic lifecycle framework for cybersecurity deployment, monitoring, and evaluation in academic server environments. The proposed monitoring system was implemented on three academic servers and tested through 90 controlled experimental scenarios involving file addition, modification, and deletion, while performance was evaluated based on detection accuracy, detection time, and resource efficiency. The experimental results showed that the Wazuh-based FIM successfully detected all unauthorized file changes with 100% accuracy (90/90 scenarios) within the predefined testing environment. The average detection time was 25.4 seconds, ranging from 24.7 to 26.3 seconds across all test cases, while system resource utilization remained stable with minimal operational overhead during continuous monitoring. These findings indicate that Wazuh-based FIM provides reliable near real-time detection of unauthorized file modifications under controlled integrity-monitoring conditions. Therefore, the proposed system demonstrates the potential to serve as an effective and practical host-level security layer for strengthening cybersecurity resilience in academic server environments, although the evaluation was limited to three monitored servers and did not include advanced adversarial attack scenarios.