INTEGRASI ODOO DAN WAZUH UNTUK DETEKSI DAN VISUALISASI SERANGAN SIBER DENGAN GRAFANA DI PT. XYZ

Repository Analytics

Statistic Details

Updated data
9Viewes
0Downloaded
9Accessed per month
3Countries
Loading...
Thumbnail Image

Authors

Nazir, Muhammad

Journal Title

Journal ISSN

Volume Title

Publisher

Politeknik Negeri Batam

Abstract

PT. XYZ relies on the Odoo Enterprise Resource Planning (ERP) platform to manage its inventory and invoicing processes, making the system a critical repository of sensitive operational data. However, Odoo logs cannot be interpreted directly by Security Information and Event Management (SIEM) platforms, because decoder not suited for odoo log format. Consequently, application-layer attacks leave traces in raw logs without ever being elevated to correlated security events, creating a blind spot. This study addresses that log-interpretation gap by designing and implementing an integrated monitoring architecture comprising Odoo, Wazuh SIEM, and Grafana. The main contribution is the mapping of Odoo's log structure, covering werkzeug HTTP logs and res_users authentication logs, into Wazuh SIEM architecture through custom decoders and detection rules. The monitoring scope focuses on the login form and URL input, covering common web attack patterns such as repeated authentication attempts and malicious URL manipulation. Evaluated in a controlled environment, the system achieved a 100% detection rate, a mean time to detect (MTTD) of 0.277 seconds, and a false positive rate of 3.00%, with real-time visualization through a Grafana dashboard.

Description

Citation

IEEE

Endorsement

Review

Supplemented By

Referenced By