Abstract
The complexity of cyber threats against the network infrastructure of companies, educational institutions, and government makes protecting network infrastructure a top priority. Router and server devices are highly vulnerable to various types of cyber threats, requiring comprehensive detection and response solutions. This research will implement an intrusion detection system by integrating SIEM technology and Wazuh XDR (Extended Detection and Response). This system analyzes index pattern data from Wazuh agent devices to detect and respond to attacks using the XDR active response firewall. The testing was conducted MikroTik RouterOS, Ubuntu Server 20.04 as Wazuh agent to test reconnaissance attacks, brute force and DoS attacks. The results of the research show Nmap and brute force attacks were successfully detected by Wazuh manager and blocked the attacker IP malicious through active response. Detection of brute force attacks showed an increase in traffic of up to 60 Kbps and CPU usage reached 100%, then decreased after the active response firewall was activated. Authentication failure reached 2198 times in the first hour of the brute force attack. CPU usage increased from 20% to 85% during the attack and decreased to 15% after the active response firewall was activated. DoS attacks, on MikroTik experienced an increase in CPU usage of up to 61% and memory of 67%. After activating the active response firewall, CPU usage decreased to 3%. Traffic on the MikroTik interface increased to 3.3 Mbps during the attack, then decreased to 1 Kbps after the firewall was activated Kompleksitas ancaman siber pada infrastruktur jaringan perusahaan, institusi pendidikan, dan pemerintah menjadikan perlindungan infrastruktur jaringan sebagai prioritas utama. Berbagai perangkat router dan server sangat rentan terhadap berbagai jenis ancaman siber, sehingga memerlukan solusi deteksi dan respons yang komprehensif. Penelitian ini akan mengimplementasikan sistem deteksi intrusi dengan mengintegrasikan teknologi SIEM dan (Extended Detection and Response) XDR Wazuh. Sistem ini menganalisis data index pattern dari perangkat Wazuh agent untuk mendeteksi dan merespons serangan menggunakan firewall active response XDR. Pengujian dilakukan pada perangkat MikroTik Router, ubuntu server untuk menguji serangan reconnaissance attack, brute force dan DoS. Hasil penelitian menunjukkan serangan Nmap dan brute force berhasil dideteksi oleh Wazuh manager dan memblokir IP penyerang melalui active response. Pendeteksian serangan brute force menunjukkan peningkatan traffic hingga 60 Kbps dan penggunaan CPU mencapai 100%, kemudian terjadi penurunan setelah firewall active response diaktifkan. Authentication failure mencapai 2198 kali dalam satu jam pertama serangan brute force. Penggunaan CPU meningkat dari 20% hingga 85% selama serangan dan menurun menjadi 15% setelah firewall active response diaktifkan. Serangan DoS, pada MikroTik mengalami peningkatan penggunaan CPU hingga 89% dan memori 56.32%. Setelah aktivasi firewall active response, penggunaan CPU menurun menjadi 3%. Traffic pada interface MikroTik meningkat hingga 3.3 Mbps selama serangan, kemudian menurun menjadi 1 Kbps setelah firewall diaktifkan
Cite
CITATION STYLE
Damanik, H. A., & Anggraeni, M. (2024). Sistem Deteksi Intrusi Hybrid dan Mitigasi Kerentanan Infrastruktur Jaringan Menggunakan Teknik Active Response (XDR) Wazuh dan Suricata. Jurnal Pekommas, 9(2), 309–322. https://doi.org/10.56873/jpkm.v9i2.5829
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.