7Viewes
Analysis of the Effectiveness of Wazuh Rules in Detecting Web Application Threats Generating Error Codes Based on OWASP Top 10 Guidelines
Repository Analytics
Statistic Details
0Downloaded
7Accessed per month
2Countries
Loading...
Date
Authors
Darmawan, Fatih Rizky
Journal Title
Journal ISSN
Volume Title
Publisher
Politeknik Negeri Batam
Abstract
Web application security has become a paramount concern in the digital ecosystem due to the
escalation of aggressive scanning and exploitation activities targeting vulnerabilities listed in
the OWASP Top 10 guidelines. Web attack behaviors consistently leave telemetry footprints
in the form of HTTP error status codes within server logs. Although open-source Security
Information and Event Management (SIEM) platforms like Wazuh offer robust log
normalization capabilities, their default rules trigger alert fatigue by individualizing every
generated error code into a single event alert. This research aims to analyze and optimize the
detection effectiveness of Wazuh through the development of customized rules built upon
frequency-based threshold correlation criteria. Comprehensive testing and attack simulations
were executed against the Damn Vulnerable Web Application (DVWA) platform by
bombarding it with variations of successful and failed incidents encompassing SQL Injection
(SQLi), Local File Inclusion (LFI), and Remote Code Execution (RCE) tactics. The tuning
methodology was implemented using a custom XML configuration file (fatih.xml) designed to
segregate successful HTTP 200 attacks into instant critical thresholds (level="12") while
muting redundant HTTP 302, 400, 404, and 500 noise logs into internal memory (level="1")
prior to aggregate time-frequency calculations. Experimental results demonstrate that the
customized Wazuh rules superiorly mitigate alert fatigue by compressing noise log volume by
over 90% into high-value alerts, whilst simultaneously unlocking visibility into RCE threats
that previously evaded default signature lookups.
Description
Keamanan aplikasi web menjadi prioritas utama dalam ekosistem digital seiring
eskalasi aktivitas pemindaian agresif dan eksploitasi celah keamanan yang tercantum
dalam pedoman OWASP Top 10. Aktivitas serangan web secara konsisten
meninggalkan jejak telemetri berupa status kode kesalahan HTTP (error code) pada
log server. Meskipun platform Security Information and Event Management (SIEM)
open-source seperti Wazuh memiliki kemampuan normalisasi log, aturan bawaan
(default rules) memicu fenomena alert fatigue karena merekam setiap kode kesalahan
secara individu sebagai single event alert. Penelitian ini bertujuan untuk menganalisis
dan mengoptimalkan efektivitas deteksi Wazuh melalui pengembangan aturan kustom
(custom tuning rules) berbasis korelasi kriteria frequency threshold. Pengujian dan
simulasi serangan komprehensif dilakukan terhadap platform Damn Vulnerable Web
Application (DVWA) dengan memuntahkan variasi insiden sukses dan gagal untuk
taktik SQL Injection (SQLi), Local File Inclusion (LFI), dan Remote Code Execution
(RCE). Metode tuning diimplementasikan melalui berkas konfigurasi XML fatih.xml
dengan memisahkan serangan sukses pada level kritis instan (level="12") berstatus
HTTP 200, serta meredam log noise status HTTP 302, 400, 404, dan 500 ke tingkat
memori internal (level="1") sebelum diagregasikan ke dalam batas ambang frekuensi
waktu. Hasil eksperimen menunjukkan bahwa aturan kustom Wazuh secara superior
menekan alert fatigue dengan mengompresi volume log noise hingga lebih dari 90%
menjadi hit alert bernilai tinggi, sekaligus meningkatkan visibilitas ancaman RCE yang
sebelumnya tidak terdeteksi oleh aturan bawaan.
Keywords
Citation
IEEE
