Analisis Deteksi Serangan Siber Menggunakan Wazuh SIEM pada Lab CTF Berbasis MITRE ATT&CK dengan Kontrol Keamanan Berdasarkan Prinsip Zero Trust

Repository Analytics

Statistic Details

Updated data
0Viewes
0Downloaded
0Accessed per month
0Countries

Statistic not available yet or restricted.

Loading...
Thumbnail Image

Authors

Monalisa, Pransiska

Journal Title

Journal ISSN

Volume Title

Publisher

Politeknik Negeri Batam

Abstract

The increasingly complex threat of cyber attacks demands a detection system capable of identifying the stages of an attack comprehensively. This study evaluates the ability of Wazuh SIEM version 4.7.5 in detecting the stages of a cyber attack in the KMIPN 2024 CTF lab on the Amethysts machine, which applies security controls based on Zero Trust principles, and maps the generated alerts to the MITRE ATT&CK framework. Attack scenarios include Port Enumeration, Service Enumeration, SMB Enumeration, RPC Enumeration, FTP Enumeration, ZIP Password Cracking, MD5 Hash Cracking, Web Directory Enumeration, Hydra Brute Force, File Upload, Remote Code Execution, Credential Leakage, Privilege Escalation. The detection performance of Wazuh SIEM is evaluated using True Positive Rate, False Positive Rate, precision, and recall metrics based on alerts triggered at each stage of the attack.

Description

Keywords

Citation

IEEE

Endorsement

Review

Supplemented By

Referenced By