, 2026
Security Operations Centers commonly visualize alerts as text logs or static dashboards, which impairs situational awareness in the case of high-volume attacks. This paper describes a real-time visualization layer built on top of an on-premises Wazuh and Suricata deployment that converts incoming security alerts into animated geographic arcs on an interactive map, using the source IP of each event to estimate its country of origin. The system is composed entirely of freely available components and operates within the organization’s own network, so raw event data never leaves local infrastructure. The proposed system differs from public threat maps provided by commercial vendors, which are based on aggregated and anonymized feeds that do not correspond to any particular network. Instead, the system provides a shared and immediately readable picture of ongoing activity to analysts and non-technical stakeholders, displaying only alerts generated by the monitored infrastructure (pp.106-112).
- Alakbarova, I. (2026). Analysis of the possibilities of applying video analytics in ensuring cyber sovereignty. Problems of Information Society, 17(1), 50–60. https://doi.org/10.25045/jpis.v17.i1.06
- Alhaidari, F., Tammas, R., Alghamdi, D., Alrashedi, R., Althani, N., Alsaidan, S., AlFosail, M., Zagrouba, R., & Alattas, H. (2022). A study on automated cyberattacks detection and visualization. In Proceedings of the 14th International Conference on Computational Intelligence and Communication Networks (CICN) (pp. 715–722). IEEE. https://doi.org/10.1109/CICN56167.2022.10008351
- Aliyev, R., & Peñalver, L. (2016). Analyzing vulnerability databases. In Proceedings of the 10th IEEE International Conference on Application of Information and Communication Technologies (AICT2016).
- Aliyev, R. (2025, December). Establishing a cybersecurity laboratory. In Proceedings of the III International Conference “Sustainable Development Strategy: Global Trends, National Experience and New Goals.” Mingachevir State University.
- Bhatt, S., Manadhata, P. K., & Zomlot, L. (2014). The operational role of security information and event management systems. IEEE Security & Privacy, 12(5), 35–41. https://doi.org/10.1109/MSP.2014.103
- Duo, W., Zhou, M., & Abusorrah, A. (2022). A survey of cyber attacks on cyber physical systems: Recent advances and challenges. IEEE/CAA Journal of Automatica Sinica, 9(5), 784–800. https://doi.org/10.1109/JAS.2022.105548
- González-Granadillo, G., González-Zarzosa, S., & Diaz, R. (2021). Security information and event management (SIEM): Analysis, trends, and usage in critical infrastructures. Sensors, 21(14), 4759. https://doi.org/10.3390/s21144759
- Jumiaty, & Soewito, B. (2024). SIEM and threat intelligence: Protecting applications with Wazuh and TheHive. International Journal of Advanced Computer Science and Applications, 15(9). https://doi.org/10.14569/IJACSA.2024.0150923
- Lallie, H. S., Debattista, K., & Bal, J. (2020). A review of attack graph and attack tree visual syntax in cyber security. Computer Science Review, 35, 100219. https://doi.org/10.1016/j.cosrev.2019.100219
- Mahmudova, R. S. (2024). Smart socio-technological infrastructures: Cyber security risks and the human factor. Problems of Information Society, 15(2), 49–60. https://doi.org/10.25045/jpis.v15.i2.06
- Seong, Y., Nuamah, J. K., & Yi, S. (2020). Guidelines for cybersecurity visualization design. In Proceedings of the 24th International Database Engineering and Applications Symposium (IDEAS ’20) (pp. 1–6). ACM. https://doi.org/10.1145/3410566.3410596





.jpg)









