Research Article

Cyber Monitor: A Lightweight Real-Time Framework for Integrated System and Network Security Monitoring

by  Apel Mahmud
journal cover
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 187 - Issue 129
Published: July 2026
Authors: Apel Mahmud
10.5120/ijca1d794ae35290
PDF

Apel Mahmud . Cyber Monitor: A Lightweight Real-Time Framework for Integrated System and Network Security Monitoring. International Journal of Computer Applications. 187, 129 (July 2026), 53-59. DOI=10.5120/ijca1d794ae35290

                        @article{ 10.5120/ijca1d794ae35290,
                        author  = { Apel Mahmud },
                        title   = { Cyber Monitor: A Lightweight Real-Time Framework for Integrated System and Network Security Monitoring },
                        journal = { International Journal of Computer Applications },
                        year    = { 2026 },
                        volume  = { 187 },
                        number  = { 129 },
                        pages   = { 53-59 },
                        doi     = { 10.5120/ijca1d794ae35290 },
                        publisher = { Foundation of Computer Science (FCS), NY, USA }
                        }
                        %0 Journal Article
                        %D 2026
                        %A Apel Mahmud
                        %T Cyber Monitor: A Lightweight Real-Time Framework for Integrated System and Network Security Monitoring%T 
                        %J International Journal of Computer Applications
                        %V 187
                        %N 129
                        %P 53-59
                        %R 10.5120/ijca1d794ae35290
                        %I Foundation of Computer Science (FCS), NY, USA
Abstract

The increasing complexity of cybersecurity threats demands monitoring solutions that are both lightweight and comprehensive. This paper presents Cyber Monitor, a desktop-based real-time security monitoring framework developed in Python, designed specifically for small-scale environments and educational use. Unlike heavyweight enterprise solutions such as Splunk or complex frameworks like Metasploit, Cyber Monitor integrates system log analysis, process monitoring, file system activity tracking, and network connection monitoring into a single unified interface with minimal system overhead. This research makes five contributions: (1) a novel integrated monitoring architecture that combines system-level and network-level visibility in a single lightweight tool; (2) a demand-driven monitoring strategy that reduces resource consumption compared to continuous polling, demonstrated empirically; (3) a rule-based severity scoring engine for real-time threat classification; (4) a qualitative comparative evaluation against five existing tools across seven dimensions; and (5) an open-source release enabling reproducibility and community extension. Performance evaluation demonstrates under 7% CPU utilisation and sub-second response times. Comparative evaluation against existing tools including Wireshark, Snort, Nagios, Metasploit and OSSEC demonstrates that Cyber Monitor fills a gap in accessible, low-overhead monitoring for non-enterprise environments. Experimental results confirm that the framework provides effective real-time monitoring capability while introducing minimal performance overhead, making it suitable for educational environments, individual system administrators, and resource-constrained deployments.

References
  • Skopik, F., Landauer, M. and Wurzenberger, M., 2022. Blind spots of security monitoring in enterprise infrastructures: a survey. IEEE Security & Privacy, 20(6), pp.18-26.
  • Chidukwani, A., Zander, S. and Koutsakis, P., 2022. A survey on the cyber security of small-to-medium businesses: challenges, research focus and recommendations. IEEE Access, 10, pp.85701-85719.
  • Waleed, A., Jamali, A.F. and Masood, A., 2022. Which open-source ids? snort, suricata or zeek. Computer Networks, 213, p.109116.
  • Manzoor, J., Waleed, A., Jamali, A.F. and Masood, A., 2024. Cybersecurity on a budget: Evaluating security and performance of open-source SIEM solutions for SMEs. PLOS ONE, 19(3), p.e0301183.
  • Scarfone, K. and Mell, P., 2007. Guide to intrusion detection and prevention systems (idps). NIST special publication, 800(2007), p.94.
  • Neupane, S., Ables, J., Anderson, W., Mittal, S., Rahimi, S., Banicescu, I. and Seale, M., 2022. Explainable intrusion detection systems (x-ids): A survey of current methods, challenges, and opportunities. IEEE Access, 10, pp.112392-112415.
  • Thakkar, A. and Lohiya, R., 2022. A survey on intrusion detection system: feature selection, model, performance measures, application perspective, challenges, and future research directions. Artificial Intelligence Review, 55(1), pp.453-563.
  • Suricata Project (2024) Suricata — Open Source IDS/IPS/NSM Engine. Open Information Security Foundation. Available at: https://suricata.io.
  • Anderson, J.P., 1980. Computer security threat monitoring and surveillance. Technical Report, James P. Anderson Company.
  • Lansky, J., Ali, S., Mohammadi, M., Majeed, M.K., Karim, S.H.T., Rashidi, S., Hosseinzadeh, M. and Rahmani, A.M., 2021. Deep learning-based intrusion detection systems: a systematic review. IEEE Access, 9, pp.101574-101599.
  • Esseghir, A., Kamoun, F. and Hraiech, O., 2022. AKER: An open-source security platform integrating IDS and SIEM functions with encrypted traffic analytic capability. Journal of Cyber Security Technology, 6(1-2), pp.27-64.
  • Sarker, I.H., 2021. Machine learning: Algorithms, real-world applications and research directions. SN computer science, 2(3), pp.1-21.
  • Arnob, A.K.B., Chowdhury, R.R., Chaiti, N.A., Saha, S. and Roy, A., 2025. A comprehensive systematic review of intrusion detection systems: emerging techniques, challenges, and future research directions. Journal of Edge Computing, 4(1), pp.73-104.
  • Wireshark Foundation (2023) Wireshark Network Analyzer. Available at: https://www.wireshark.org.
  • Snort Project (2023) Snort — Network Intrusion Detection and Prevention System. Available at: https://www.snort.org.
  • Nmap Project (2024) Nmap: Network Mapper. Available at: https://nmap.org.
  • Tcpdump/Libpcap Project (2023) Tcpdump and Libpcap. Available at: https://www.tcpdump.org.
  • Zeek Project (2023) Zeek Network Security Monitor — Documentation. Available at: https://docs.zeek.org.
  • Nagios Enterprises (2024) Nagios — The Industry Standard in IT Infrastructure Monitoring. Available at: https://www.nagios.org.
  • Zabbix LLC (2024) Zabbix — Enterprise-class Open Source Monitoring Solution. Available at: https://www.zabbix.com.
  • Wazuh Inc. (2023) Wazuh — The Open Source Security Platform. Available at: https://wazuh.com.
  • Rodola, G. (2023) psutil — process and system utilities. Available at: https://psutil.readthedocs.io/.
  • Python Software Foundation (2024) Python 3 Documentation. Available at: https://docs.python.org/3/.
  • OSSEC Project (2024) OSSEC — Open Source HIDS Security. Available at: https://www.ossec.net.
  • Mutz, D., Robertson, W., Vigna, G. and Kemmerer, R., 2007, September. Exploiting execution context for the detection of anomalous system calls. In International Workshop on Recent Advances in Intrusion Detection (pp. 1-20). Berlin, Heidelberg: Springer Berlin Heidelberg.
  • Kruegel, C., Valeur, F., Vigna, G. and Kemmerer, R., 2002, May. Stateful intrusion detection for high-speed networks. In Proceedings 2002 IEEE Symposium on Security and Privacy (pp. 285-293). IEEE.
  • Moser, O., Rosenberg, F. and Dustdar, S., 2010, December. Event driven monitoring for service composition infrastructures. In International Conference on Web Information Systems Engineering (pp. 38-51). Berlin, Heidelberg: Springer Berlin Heidelberg.
  • Blažič, A.J. and Blažič, B.J., 2024. Toward effective learning of cybersecurity: new curriculum agenda and learning methods. Journal of Cybersecurity, 10(1), p.tyae018.
  • Vykopal, J., Čeleda, P., Seda, P., Švábenský, V. and Tovarňák, D., 2021, October. Scalable learning environments for teaching cybersecurity hands-on. In 2021 IEEE frontiers in education conference (FIE) (pp. 1-9). IEEE.
  • Apruzzese, G., Laskov, P., Montes de Oca, E., Mallouli, W., Brdalo Rapa, L., Grammatopoulos, A.V. and Di Franco, F., 2023. The role of machine learning in cybersecurity. Digital threats: research and practice, 4(1), pp.1-38.
  • Peffers, K., Tuunanen, T., Rothenberger, M.A. and Chatterjee, S., 2007. A design science research methodology for information systems research. Journal of management information systems, 24(3), pp.45-77.
  • Axelsson, S. (2000) Intrusion detection systems: A survey and taxonomy. Chalmers University Technical Report.
Index Terms
Computer Science
Information Sciences
No index terms available.
Keywords

Cyber Monitor real-time monitoring network security system monitoring lightweight framework Python intrusion detection security dashboard

Powered by PhDFocusTM