0Viewes
Analisis Deteksi Serangan Siber Menggunakan Wazuh SIEM pada Lab CTF Berbasis MITRE ATT&CK dengan Kontrol Keamanan Berdasarkan Prinsip Zero Trust
Repository Analytics
Statistic Details
0Downloaded
0Accessed per month
0Countries
Statistic not available yet or restricted.
Loading...
Date
Authors
Monalisa, Pransiska
Journal Title
Journal ISSN
Volume Title
Publisher
Politeknik Negeri Batam
Abstract
The increasingly complex threat of cyber attacks demands a detection system capable of identifying the stages of an attack comprehensively. This study evaluates the ability of Wazuh SIEM version 4.7.5 in detecting the stages of a cyber attack in the KMIPN 2024 CTF lab on the Amethysts machine, which applies security controls based on Zero Trust principles, and maps the generated alerts to the MITRE ATT&CK framework. Attack scenarios include Port Enumeration, Service Enumeration, SMB Enumeration, RPC Enumeration, FTP Enumeration, ZIP Password Cracking, MD5 Hash Cracking, Web Directory Enumeration, Hydra Brute Force, File Upload, Remote Code Execution, Credential Leakage, Privilege Escalation. The detection performance of Wazuh SIEM is evaluated using True Positive Rate, False Positive Rate, precision, and recall metrics based on alerts triggered at each stage of the attack.
Description
Keywords
Citation
IEEE
