Analysis of the Effectiveness of Wazuh Rules in Detecting Web Application Threats Generating Error Codes Based on OWASP Top 10 Guidelines

dc.contributor.advisorArif, Hamdani
dc.contributor.authorDarmawan, Fatih Rizky
dc.date.accessioned2026-08-28T02:05:56Z
dc.date.issued2026-07-21
dc.descriptionKeamanan aplikasi web menjadi prioritas utama dalam ekosistem digital seiring eskalasi aktivitas pemindaian agresif dan eksploitasi celah keamanan yang tercantum dalam pedoman OWASP Top 10. Aktivitas serangan web secara konsisten meninggalkan jejak telemetri berupa status kode kesalahan HTTP (error code) pada log server. Meskipun platform Security Information and Event Management (SIEM) open-source seperti Wazuh memiliki kemampuan normalisasi log, aturan bawaan (default rules) memicu fenomena alert fatigue karena merekam setiap kode kesalahan secara individu sebagai single event alert. Penelitian ini bertujuan untuk menganalisis dan mengoptimalkan efektivitas deteksi Wazuh melalui pengembangan aturan kustom (custom tuning rules) berbasis korelasi kriteria frequency threshold. Pengujian dan simulasi serangan komprehensif dilakukan terhadap platform Damn Vulnerable Web Application (DVWA) dengan memuntahkan variasi insiden sukses dan gagal untuk taktik SQL Injection (SQLi), Local File Inclusion (LFI), dan Remote Code Execution (RCE). Metode tuning diimplementasikan melalui berkas konfigurasi XML fatih.xml dengan memisahkan serangan sukses pada level kritis instan (level="12") berstatus HTTP 200, serta meredam log noise status HTTP 302, 400, 404, dan 500 ke tingkat memori internal (level="1") sebelum diagregasikan ke dalam batas ambang frekuensi waktu. Hasil eksperimen menunjukkan bahwa aturan kustom Wazuh secara superior menekan alert fatigue dengan mengompresi volume log noise hingga lebih dari 90% menjadi hit alert bernilai tinggi, sekaligus meningkatkan visibilitas ancaman RCE yang sebelumnya tidak terdeteksi oleh aturan bawaan.
dc.description.abstractWeb application security has become a paramount concern in the digital ecosystem due to the escalation of aggressive scanning and exploitation activities targeting vulnerabilities listed in the OWASP Top 10 guidelines. Web attack behaviors consistently leave telemetry footprints in the form of HTTP error status codes within server logs. Although open-source Security Information and Event Management (SIEM) platforms like Wazuh offer robust log normalization capabilities, their default rules trigger alert fatigue by individualizing every generated error code into a single event alert. This research aims to analyze and optimize the detection effectiveness of Wazuh through the development of customized rules built upon frequency-based threshold correlation criteria. Comprehensive testing and attack simulations were executed against the Damn Vulnerable Web Application (DVWA) platform by bombarding it with variations of successful and failed incidents encompassing SQL Injection (SQLi), Local File Inclusion (LFI), and Remote Code Execution (RCE) tactics. The tuning methodology was implemented using a custom XML configuration file (fatih.xml) designed to segregate successful HTTP 200 attacks into instant critical thresholds (level="12") while muting redundant HTTP 302, 400, 404, and 500 noise logs into internal memory (level="1") prior to aggregate time-frequency calculations. Experimental results demonstrate that the customized Wazuh rules superiorly mitigate alert fatigue by compressing noise log volume by over 90% into high-value alerts, whilst simultaneously unlocking visibility into RCE threats that previously evaded default signature lookups.
dc.identifier.citationIEEE
dc.identifier.kodeprodiKODEPRODI57302#Rekayasa Keamanan Siber
dc.identifier.nidnNIDN0001129002
dc.identifier.nim4332101023
dc.identifier.urihttps://repository.polibatam.ac.id//handle/PL29/6392
dc.language.isoother
dc.publisherPoliteknik Negeri Batam
dc.subjectwazuh
dc.subjectSIEM
dc.subjectOwasp Top 10
dc.subjectError Code
dc.subjectAlert Fatigue
dc.subjectCustom Rules
dc.subjectDVWA
dc.titleAnalysis of the Effectiveness of Wazuh Rules in Detecting Web Application Threats Generating Error Codes Based on OWASP Top 10 Guidelines
dc.title.alternativeANALISIS EFEKTIVITAS ATURAN WAZUH DALAM MENDETEKSI ANCAMAN WEB APLIKASI YANG MENGHASILKAN ERROR CODE DENGAN MENGIKUTI PEDOMAN OWASP TOP 10
dc.typeArticle

Files

Original bundle

Now showing 1 - 3 of 3
Loading...
Thumbnail Image
Name:
4332101023_Analysis of the Effectiveness of Wazuh Rules in Detecting Web Application Threats.pdf
Size:
857.84 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
Lebar_Pengesahan.pdf
Size:
118.81 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
Borang_Publikasi_Fatih Rizky Darmawan.pdf
Size:
208.45 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: