9Viewes
INTEGRASI ODOO DAN WAZUH UNTUK DETEKSI DAN VISUALISASI SERANGAN SIBER DENGAN GRAFANA DI PT. XYZ
Repository Analytics
Statistic Details
0Downloaded
9Accessed per month
3Countries
Loading...
Date
Authors
Nazir, Muhammad
Journal Title
Journal ISSN
Volume Title
Publisher
Politeknik Negeri Batam
Abstract
PT. XYZ relies on the Odoo Enterprise Resource Planning (ERP) platform to manage its inventory and invoicing processes, making the system a critical repository of sensitive operational data. However, Odoo logs cannot be interpreted directly by Security Information and Event Management (SIEM) platforms, because decoder not suited for odoo log format. Consequently, application-layer attacks leave traces in raw logs without ever being elevated to correlated security events, creating a blind spot. This study addresses that log-interpretation gap by designing and implementing an integrated monitoring architecture comprising Odoo, Wazuh SIEM, and Grafana. The main contribution is the mapping of Odoo's log structure, covering werkzeug HTTP logs and res_users authentication logs, into Wazuh SIEM architecture through custom decoders and detection rules. The monitoring scope focuses on the login form and URL input, covering common web attack patterns such as repeated authentication attempts and malicious URL manipulation. Evaluated in a controlled environment, the system achieved a 100% detection rate, a mean time to detect (MTTD) of 0.277 seconds, and a false positive rate of 3.00%, with real-time visualization through a Grafana dashboard.
Description
Keywords
Citation
IEEE
