Analysis of the Effectiveness of Wazuh Rules in Detecting Web Application Threats Generating Error Codes Based on OWASP Top 10 Guidelines
| dc.contributor.advisor | Arif, Hamdani | |
| dc.contributor.author | Darmawan, Fatih Rizky | |
| dc.date.accessioned | 2026-08-28T02:05:56Z | |
| dc.date.issued | 2026-07-21 | |
| dc.description | Keamanan aplikasi web menjadi prioritas utama dalam ekosistem digital seiring eskalasi aktivitas pemindaian agresif dan eksploitasi celah keamanan yang tercantum dalam pedoman OWASP Top 10. Aktivitas serangan web secara konsisten meninggalkan jejak telemetri berupa status kode kesalahan HTTP (error code) pada log server. Meskipun platform Security Information and Event Management (SIEM) open-source seperti Wazuh memiliki kemampuan normalisasi log, aturan bawaan (default rules) memicu fenomena alert fatigue karena merekam setiap kode kesalahan secara individu sebagai single event alert. Penelitian ini bertujuan untuk menganalisis dan mengoptimalkan efektivitas deteksi Wazuh melalui pengembangan aturan kustom (custom tuning rules) berbasis korelasi kriteria frequency threshold. Pengujian dan simulasi serangan komprehensif dilakukan terhadap platform Damn Vulnerable Web Application (DVWA) dengan memuntahkan variasi insiden sukses dan gagal untuk taktik SQL Injection (SQLi), Local File Inclusion (LFI), dan Remote Code Execution (RCE). Metode tuning diimplementasikan melalui berkas konfigurasi XML fatih.xml dengan memisahkan serangan sukses pada level kritis instan (level="12") berstatus HTTP 200, serta meredam log noise status HTTP 302, 400, 404, dan 500 ke tingkat memori internal (level="1") sebelum diagregasikan ke dalam batas ambang frekuensi waktu. Hasil eksperimen menunjukkan bahwa aturan kustom Wazuh secara superior menekan alert fatigue dengan mengompresi volume log noise hingga lebih dari 90% menjadi hit alert bernilai tinggi, sekaligus meningkatkan visibilitas ancaman RCE yang sebelumnya tidak terdeteksi oleh aturan bawaan. | |
| dc.description.abstract | Web application security has become a paramount concern in the digital ecosystem due to the escalation of aggressive scanning and exploitation activities targeting vulnerabilities listed in the OWASP Top 10 guidelines. Web attack behaviors consistently leave telemetry footprints in the form of HTTP error status codes within server logs. Although open-source Security Information and Event Management (SIEM) platforms like Wazuh offer robust log normalization capabilities, their default rules trigger alert fatigue by individualizing every generated error code into a single event alert. This research aims to analyze and optimize the detection effectiveness of Wazuh through the development of customized rules built upon frequency-based threshold correlation criteria. Comprehensive testing and attack simulations were executed against the Damn Vulnerable Web Application (DVWA) platform by bombarding it with variations of successful and failed incidents encompassing SQL Injection (SQLi), Local File Inclusion (LFI), and Remote Code Execution (RCE) tactics. The tuning methodology was implemented using a custom XML configuration file (fatih.xml) designed to segregate successful HTTP 200 attacks into instant critical thresholds (level="12") while muting redundant HTTP 302, 400, 404, and 500 noise logs into internal memory (level="1") prior to aggregate time-frequency calculations. Experimental results demonstrate that the customized Wazuh rules superiorly mitigate alert fatigue by compressing noise log volume by over 90% into high-value alerts, whilst simultaneously unlocking visibility into RCE threats that previously evaded default signature lookups. | |
| dc.identifier.citation | IEEE | |
| dc.identifier.kodeprodi | KODEPRODI57302#Rekayasa Keamanan Siber | |
| dc.identifier.nidn | NIDN0001129002 | |
| dc.identifier.nim | 4332101023 | |
| dc.identifier.uri | https://repository.polibatam.ac.id//handle/PL29/6392 | |
| dc.language.iso | other | |
| dc.publisher | Politeknik Negeri Batam | |
| dc.subject | wazuh | |
| dc.subject | SIEM | |
| dc.subject | Owasp Top 10 | |
| dc.subject | Error Code | |
| dc.subject | Alert Fatigue | |
| dc.subject | Custom Rules | |
| dc.subject | DVWA | |
| dc.title | Analysis of the Effectiveness of Wazuh Rules in Detecting Web Application Threats Generating Error Codes Based on OWASP Top 10 Guidelines | |
| dc.title.alternative | ANALISIS EFEKTIVITAS ATURAN WAZUH DALAM MENDETEKSI ANCAMAN WEB APLIKASI YANG MENGHASILKAN ERROR CODE DENGAN MENGIKUTI PEDOMAN OWASP TOP 10 | |
| dc.type | Article |
Files
Original bundle
1 - 3 of 3
Loading...
- Name:
- 4332101023_Analysis of the Effectiveness of Wazuh Rules in Detecting Web Application Threats.pdf
- Size:
- 857.84 KB
- Format:
- Adobe Portable Document Format
Loading...
- Name:
- Lebar_Pengesahan.pdf
- Size:
- 118.81 KB
- Format:
- Adobe Portable Document Format
Loading...
- Name:
- Borang_Publikasi_Fatih Rizky Darmawan.pdf
- Size:
- 208.45 KB
- Format:
- Adobe Portable Document Format
License bundle
1 - 1 of 1
Loading...
- Name:
- license.txt
- Size:
- 1.71 KB
- Format:
- Item-specific license agreed upon to submission
- Description:
