MODEL FOR REPLACING COMMERCIAL EDR/XDR SOLUTIONS WITH A LOCAL OPEN-SOURCE ARCHITECTURE WITH AI SUPPORT FOR SOC PROCESSES
DOI:
https://doi.org/10.31673/2412-4338.2026.036022Abstract
The article considers an approach to building a local system for monitoring and responding to cybersecurity incidents that can serve as an alternative or complement to commercial EDR/XDR solutions. The relevance of the study is driven by the growing number of endpoints in corporate infrastructures and the significant costs associated with subscription-based security platforms. The introduction substantiates the need to find cost-effective solutions capable of ensuring an appropriate level of threat detection, event storage, and analysis.
The paper formulates the problem of limitations inherent in traditional approaches to implementing EDR/XDR in environments with a large number of devices and establishes its connection with practical tasks of ensuring organizational cyber resilience. An analysis of the functional capabilities of modern security monitoring systems is carried out, along with identification of their key advantages and limitations in terms of cost, scalability, and vendor dependency.
The purpose of the study is to develop a model of a local open-source architecture that combines functions of event collection, indexing, and storage with analytical processing capabilities using a local artificial intelligence layer. The results section describes the proposed architecture, which includes the use of Wazuh as an endpoint monitoring platform, event indexing systems, centralized log storage, and a dedicated AI layer to support SOC processes. The hardware configuration, data processing and storage parameters, as well as approaches to ensuring scalability and system resilience are also considered. A mathematical model of the system is constructed that links the number of endpoints to the event stream, storage volumes, the number of processing nodes, SOC analyst workload and total cost of ownership, and an architectural diagram of the solution is presented.
Particular attention is paid to the technical and economic analysis of the proposed solution, including the evaluation of initial infrastructure investments, operational costs, and comparison with traditional subscription models. The study also identifies limitations and risks associated with the open-source approach, including the need for additional configuration, absence of fully automated response mechanisms, and increased requirements for staff expertise. Quantitative evaluation with the model shows that over a five-year horizon the proposed architecture becomes more cost-effective than a commercial solution starting from approximately 450 endpoints, and for an infrastructure of 1,000 endpoints it yields savings of about 40% with a payback period of about 1.2 years.
The conclusions summarize the research findings and confirm the feasibility of using a local open-source architecture in scenarios where cost control and data ownership are critical. Further research directions are proposed, including pilot implementation and evaluation of system performance under real-world conditions.
Keywords: cybersecurity, EDR, XDR, SIEM, Wazuh, open-source, artificial intelligence, SOC, mathematical model, total cost of ownership.