E. Ologunde Case file

Case file EOSection: Hands-on practiceRef. EO-LABBack to the case file

Homelab

A self-hosted security monitoring and detection lab, and the Breakwater OT/IoT vulnerability lab from my doctoral coursework.

01

Security monitoring lab

In plain English: a small version of the monitoring a company’s security team runs, built on two machines at home, so I can test tools before I recommend them.

I run a small, self-hosted lab where I try out SIEM, host-based detection and monitoring tooling before I recommend it to Cyntraix clients. It runs on two small machines at home.

Architecture, by role

Two hypervisor nodes, one log pipeline

  • Virtualization: two Proxmox VE nodes running lightweight containers and full virtual machines, kept deliberately unclustered.
  • Network services: an open-source firewall VM, a DNS sinkhole for ad and tracker filtering, and a reverse proxy in front of the web consoles.
  • Detection: a SIEM with dedicated syslog inputs and a host-based intrusion detection manager with agents on the lab’s Linux hosts.
  • Monitoring: uptime checks for every core service, reachability probes with an uplink dashboard, and LAN device discovery.
  • Testing and AI: a penetration-testing VM, and a small language model running locally on CPU.
What it does

From raw logs to a daily digest

  • Firewall, DNS, proxy, container, Linux and host-agent alert logs are forwarded over syslog into one SIEM index.
  • Each source’s time zone is normalized so events land in the right search window.
  • Scheduled searches produce a daily digest and a critical-event watch, running under a search-only service account scoped to that one index.
  • A new device joining the network raises an alert in the SIEM.
  1. Firewall, DNS, proxy, containers, host agents
  2. Syslog forwarding
  3. SIEM index
  4. Scheduled detection searches
  5. Digest and critical-event watch
Diagram of the security monitoring lab: log sources forward over syslog into one SIEM index, which feeds scheduled detection searches and alerting, with uptime checks, reachability and device discovery alongside.
Generic by design: roles only, no addresses or hostnames.
A SIEM search over the homelab index returning about 304,700 events in 24 hours from five sources, with a stacked bar chart of hourly volume by source.
Real results from a live search over the lab’s index, redrawn as a sanitized excerpt: source names and counts only, no hosts or addresses.
Top host-based detection alerts over 7 days by rule and level, about 3,700 in total, dominated by one rootcheck rule.
Real alert counts from the lab’s index, redrawn as a sanitized excerpt: rule names and levels only, no hosts or addresses.
02

Decisions and lessons

In plain English: what I decided while building the lab, and what went wrong and how it was fixed.

Security trade-offs

Choosing the safer option

  • Kept the firewall console off the reverse proxy, because fronting it would have meant turning off TLS certificate verification.
  • Remote shell access to the second node is key-only, and the automation key works from one machine only.
  • The local language model listens on the lab network only and was installed only after its release checksum was verified.
  • Automated log review uses a read-only account that can search one index and nothing else.
Troubleshooting

What the lab taught me

  • Found a VPN container that had never worked, crash-looping more than 12,000 times and writing about 361 GB to disk. Retired it and removed its agent.
  • Decommissioned an unused DNS filter after confirming it had zero clients, then reused its slot.
  • Traced a flapping, slow network link to a bad cable before blaming the network card.
  • Learned that one spinning disk under a SIEM, a HIDS and a metrics store is the bottleneck. Moving those to SSD is next.
  • Proxmox VE
  • Splunk
  • Wazuh
  • OPNsense
  • Pi-hole
  • Caddy
  • Uptime Kuma
  • Docker
  • Prometheus · Grafana
  • rsyslog
  • Kali Linux
  • Ollama
03

Breakwater lab

In plain English: a practice network of simulated devices from my doctorate, used to find and rank security flaws safely.

Doctoral coursework, George Washington University (SEAS 8414, Analytical Tools for Cyber). A containerized OT/IoT simulation network used to build an end-to-end security-analytics pipeline, one phase at a time.

26devices declared in the simulated network
20 (77%)confirmed by active and passive discovery
0phantom hosts
Doctoral coursework

Discovery, identity and triage

  • Asset inventory: active and passive discovery against a declared 26-device simulated network confirmed 20 devices (77%) with zero phantom hosts. TCP probing found the most.
  • Device identity: fingerprinting from management-plane self-reports rather than transport banners, with three-witness corroboration and an admissibility gate before any downstream use.
  • Vulnerability triage: NVD CVEs fused with CISA KEV and FIRST EPSS into a transparent score, CVSS + 10·EPSS + 5·[KEV] + 2·[ransomware].
Doctoral coursework

From risk models to remediation

  • Attack paths: attack graphs with k-shortest-path analysis, mapped to MITRE ATT&CK for ICS and exported as STIX 2.1.
  • Simulation: a digital twin built from scan data, with checkpoint rollback for testing remediation before touching the real network.
  • Crypto readiness: harvest-now-decrypt-later exposure and a migration plan toward NIST post-quantum standards.
  • Write-up: an ACM-format paper, “Evidence-Bounded Vulnerability Intelligence for OT/IoT Networks,” in preparation.
The AI thread

Where AI helps, and where it is kept on a leash

  • AI proposes, evidence decides: LLM-guided mutation fuzzing and AutoML ranking may propose and rank, but a finding closes only on a measured or scoped, simulated witness.
  • Models as targets: a federated, Transformer-based intrusion-detection model trained across simulated sites, with Multi-Krum against poisoned client updates, differential privacy (Gaussian mechanism, Rényi accounting) and SCAFFOLD for client drift.
  • Agents behind safety controls: a PPO reinforcement-learning agent for offensive testing behind a tiered safety controller with SHA-256 evidence-chain logging, and remediation that runs simulate, verify, approve, execute, health-check.

The AI security exhibit in the case file

All Breakwater devices are simulated containers. No real operational network was scanned.