Software Technology / IT · REF. TA-21576
Design and Evaluation of a Wazuh-Based Threat Detection Framework for Enhancing Cyber Resilience in Banking IT Infrastructure in Nigeria
Abstract
Nigerian banks operate under a threat landscape that has grown considerably more hostile in recent years, facing everything from credential-stuffing attempts against internet banking portals to targeted intrusions aimed at core banking infrastructure, while many mid-tier institutions still rely on commercial SIEM and endpoint detection platforms whose licensing costs put continuous, comprehensive monitoring out of reach for anything beyond a subset of critical systems. This project investigates whether Wazuh, an open-source security monitoring platform combining host-based intrusion detection, log analysis, file integrity monitoring and vulnerability detection, can be designed and configured into a threat detection framework capable of giving a Nigerian bank's IT infrastructure meaningfully better visibility into intrusion attempts without the licensing cost of a comparable commercial platform. It designs a Wazuh deployment spanning a simulated banking IT environment — core banking application servers, database servers and endpoint workstations — configured with custom detection rules targeting attack patterns relevant to financial institutions: brute-force login attempts, unauthorised configuration changes, suspicious file modifications on transaction-processing systems, and anomalous outbound network activity consistent with data exfiltration. The framework is evaluated by simulating a set of realistic attack scenarios against the test environment and measuring detection rate, time to alert, and false-positive rate, benchmarked against the bank's existing monitoring approach. The project's findings are directly relevant to the practical question many Nigerian financial institutions face: whether open-source security monitoring tooling, properly designed and tuned, can close a meaningful part of the cyber resilience gap that commercial platform costs currently leave open.
Chapter One — 1.1 Background to the Study
The Nigerian banking sector has digitised rapidly over the past decade — internet banking, mobile banking applications, USSD channels and interbank payment switches have all expanded the attack surface a bank's IT infrastructure presents, at the same time as the financial incentive for attackers targeting that infrastructure has grown. Central Bank of Nigeria guidelines and the wider regulatory push toward stronger cybersecurity posture in the sector reflect a recognition that this threat has become material rather than theoretical, with reported incidents ranging from card-skimming and phishing campaigns against retail customers to more sophisticated intrusion attempts against banks' internal networks.
Effective defence against this threat landscape depends heavily on continuous security monitoring — the ability to detect an intrusion attempt, a policy violation or an anomalous system change as it happens rather than discovering it during a post-incident review. Commercial SIEM and endpoint detection platforms provide this capability, but their licensing models are typically priced per monitored endpoint or per volume of log data ingested, a cost structure that scales poorly for a bank seeking to monitor a large and growing IT estate. Open-source alternatives such as Wazuh, which combine several of the same detection capabilities without per-endpoint licensing costs, have matured considerably as a result, but their suitability for a Nigerian banking IT environment specifically — with its particular mix of legacy core banking systems, modern digital channels and regulatory reporting obligations — has not been systematically evaluated.
1.2 Statement of the Problem
Nigerian banks, particularly mid-tier and smaller institutions, face a widening gap between the security monitoring coverage their threat exposure warrants and what commercial SIEM and endpoint detection licensing costs make affordable in practice, leaving parts of their IT infrastructure with limited or no continuous monitoring. Open-source platforms such as Wazuh are frequently proposed as a cost-effective alternative, but without a concrete framework demonstrating how such a platform should be designed, configured and tuned for a banking IT environment's specific threat patterns, banks have limited practical basis for adopting one over continuing with partial commercial coverage or foregoing comprehensive monitoring altogether. This project addresses that gap by designing and evaluating a Wazuh-based threat detection framework configured specifically for a simulated banking IT infrastructure.
1.3 Objectives of the Study
- To examine the cybersecurity monitoring challenges and threat patterns characteristic of Nigerian banking IT infrastructure.
- To design a Wazuh-based threat detection framework, including custom detection rules targeting banking-relevant attack patterns.
- To implement the framework across a simulated banking IT environment comprising core banking, database and endpoint systems.
- To evaluate the framework's detection rate, alert latency and false-positive rate against a set of realistic simulated attack scenarios.
- To assess the framework's viability as a cost-effective complement or alternative to commercial SIEM and endpoint detection platforms for Nigerian banks.
1.4 Research Questions
- What cybersecurity monitoring challenges and threat patterns are most characteristic of Nigerian banking IT infrastructure?
- How should a Wazuh-based threat detection framework be designed and configured to address those patterns?
- How effectively does the resulting framework detect simulated attack scenarios, in terms of detection rate, alert latency and false-positive rate?
- How does the framework's monitoring coverage and cost profile compare with a conventional commercial SIEM or endpoint detection approach?
1.5 Significance of the Study
This project is significant to Nigerian banks and other financial institutions evaluating how to extend security monitoring coverage without a proportional increase in licensing expenditure, offering a concrete, evaluated framework rather than a general recommendation to 'consider open-source tooling'. It is equally relevant to IT security practitioners and researchers, contributing an empirical, banking-context evaluation of Wazuh's detection capability to a body of literature that has so far addressed open-source SIEM platforms mostly in generic or non-financial settings.
1.6 Scope of the Study
The project is limited to the design, implementation and evaluation of a Wazuh-based threat detection framework within a simulated banking IT environment built for this study, rather than deployment within a live bank's production infrastructure. It covers host-based intrusion detection, log analysis, file integrity monitoring and the custom detection rules built around them, and does not extend to network-layer intrusion prevention, physical security controls, or regulatory compliance reporting obligations beyond the monitoring capability itself.
Chapters Two through Five, references and appendices are available for a one-time fee of ₦75,000.
Unlock Full Document