Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Wazuh is a Host-based Intrusion Detection service provided by CloudAware via Kibana platform user interface. Wazuh is available via CloudAware Launcher.

...

This article explains how Cloudaware capabilities should be deployed to improve AWS security, mitigate risks associated with operating cloud-based computing infrastructure, address compliance and change management.


Audience:

  • Security Engineers
  • Cloudaware Engineers
  • Chief Security Officers
  • Compliance Officers
  • AWS Cloud Engineers
  • Cloud Operations Teams


HIDS Server Deployment Options


Cloudaware CloudAware HIDS solution consists of three parts:

...

Optionally, customers can deploy their own IDS servers. IDS dashboard is part of the CloudAware and all IDS servers report into the dashboard. There are two ways to deploy CloudAware IDS services.


Managed IDS


Using Managed IDS deployment option, customers leverage IDS servers that are managed by CloudAware.

...

Advantages

Disadvantages

  • Hassle free operations
  • Customers do not need to worry about IDS Server's 
    • availability
    • patching
    • performance
    • costs
    • scalability
    • maintenance
Not able to deploy common OSSEC customizations without involving CloudAware support.


Customer Managed IDS


Under this approach customers maintain their own set of IDS servers and are responsible for many operational aspects including backup, disaster recovery and availability. CloudAware recommends one IDS server per 500 agents and that IDS servers are deployed in the same region as agents. 


Customers may also choose to deploy a hybrid approach where some agents use CloudAware-managed IDS servers and some agents user customer-managed IDS servers. 


IDS Status


If Intrusion Detection module is deployed, the tile 'IDS status' on an instance may display 3 values:

  • Monitored
  • Not monitored
  • Under Attack


 Image Removed
Image Removed
More information about building reports in Salesforce is available here and here.


Click the tab 'Security' to review HIDS Alerts:

Image Added