Network Connection Monitoring
Zeek monitors network connections involving the Ubuntu server.
Provide visibility into network communication.
Organizations operate Linux servers that expose network services such as SSH, HTTP, HTTPS, DNS, databases, and internal application services. Attackers commonly perform Port Scanning Attacks during reconnaissance to identify reachable services and determine which network ports are open.
A port scan may generate a large number of connection attempts against different ports within a short period. If this activity is not monitored, reconnaissance can occur without generating sufficient visibility for the Security Operations Center.
In this use case, an enterprise-like Ubuntu Linux server is deployed inside an isolated laboratory using VirtualBox. The server contains controlled services representing a typical Linux application environment. Kali Linux is used as the authorized security-testing system.
A controlled port-scanning scenario is generated against the Ubuntu server using Nmap. The objective is to determine whether the SOC can identify the abnormal pattern of repeated connection attempts across multiple ports.
Zeek is used as the network-security monitoring component to collect connection telemetry. Wazuh collects and analyzes the relevant security events and generates alerts when the configured port-scanning detection condition is satisfied.
OpenSearch is used as the centralized SOC investigation platform to visualize connection activity, identify the scanning source, reconstruct the reconnaissance timeline, and support incident investigation.
When the scanning behavior is detected, the configured response mechanism can temporarily restrict the laboratory source.
The complete SOC workflow is: Linux Server → Network Traffic → Multiple Port Connection Attempts → Zeek Telemetry → Wazuh Detection → Security Alert → SOC Investigation → Source Attribution → Automated Response → Containment → Validation
The Ubuntu server hosts controlled network services that represent services commonly found on enterprise Linux systems.
An attacker may scan a Linux server to determine which ports are reachable and which services may be available. A single connection attempt is not necessarily suspicious because legitimate clients may connect to individual services. However, repeated connection attempts against many different ports from the same source within a short period can indicate reconnaissance activity.
The security problem is therefore:
The controlled attack scenario simulates a port-scanning attack against the authorized Ubuntu Linux server. Kali Linux performs a controlled Nmap scan against only the laboratory target. The scan generates multiple connection attempts across a defined range of ports. The objective is to determine whether the SOC monitoring environment can distinguish normal network connections from reconnaissance behavior.
The primary security concept is SOC-based network reconnaissance detection.
The objective is to continuously monitor network connections and identify abnormal patterns associated with port-scanning activity.
The secure processing flow is:
Zeek monitors network connections involving the Ubuntu server.
Provide visibility into network communication.
Network connection events containing destination-port information are collected.
Identify which ports are being contacted.
Multiple connection attempts against different ports are correlated.
Detect systematic reconnaissance behavior.
The originating source address is identified.
Determine which system is performing the scan.
The number of contacted ports and connection frequency are evaluated against configured detection conditions.
Reduce reliance on individual connection events.
Wazuh generates an alert when the configured port-scanning condition is satisfied.
Provide immediate SOC visibility.
OpenSearch provides centralized access to network events and alerts.
Allow analysts to investigate the scanning activity.
The configured response mechanism can temporarily restrict the identified laboratory source.
Prevent continued reconnaissance activity.
Related network events are correlated chronologically.
Understand the progression of the scanning activity.
Network activity is monitored after containment.
Verify that scanning has stopped while legitimate service communication remains functional.
Wazuh is the primary SOC platform because it provides security-event collection, rule-based analysis, alert generation, and automated response capabilities. Wazuh can also work with network telemetry and custom detection rules for reconnaissance activity.
Zeek is used to monitor network connections involving the Ubuntu server.
OpenSearch is used as the centralized investigation and visualization platform.
Nmap is used only within the isolated laboratory to generate the controlled port-scanning activity.
The Ubuntu Linux networking subsystem provides the underlying network activity observed by the monitoring infrastructure.
Ubuntu provides the controlled Linux server environment.
Kali Linux provides the controlled security-testing environment.
VirtualBox provides the isolated laboratory infrastructure.