Implementation of Suricata and Cyber Attack Analysis with SIEM for Attack Verification and Mitigation

dc.contributor.advisorNelmiawati
dc.contributor.authorRaffer, Valentino
dc.date.accessioned2026-08-19T06:04:37Z
dc.date.issued2026-07-22
dc.description.abstractThe escalating complexity of cyber threats, encompassing web application exploitations, Denial-of-Service (DoS), and brute-force attacks, necessitates cloud infrastructures to deploy adaptive and automated defense mechanisms. Standalone conventional detection systems frequently fall short in delivering immediate responses to multi-vector attacks. This research aims to design and implement a robust Defense in Depth (DiD) security architecture that synergizes network visibility, application-level security, and automated incident response powered by Security Information and Event Management (SIEM). The experimental environment was constructed on a cloud server, utilizing the Damn Vulnerable Web Application (DVWA) as the evaluation target. The defensive framework integrates ModSecurity as a Web Application Firewall (WAF) at the application layer, Suricata as a Network Intrusion Detection System (NIDS) at the network layer, and Wazuh as the centralized SIEM orchestrator. Penetration testing was executed via Kali Linux, simulating critical attack vectors including DoS, authentication brute-force, and web-based injections (SQLi, XSS, and File Upload). The empirical results demonstrate the architecture's high efficacy in real-time threat detection and mitigation. ModSecurity instantaneously intercepted malicious applicationlayer payloads, while Wazuh successfully correlated logs from Suricata and ModSecurity to trigger its Active Response module. This automation seamlessly executed a full IP block via iptables upon reaching predefined threat thresholds. Ultimately, the integration of Wazuh, Suricata, and ModSecurity establishes a resilient Defense in Depth ecosystem, significantly minimizing incident response times and fortifying cloud server defenses without requiring manual administrative intervention.
dc.identifier.citationIEEE
dc.identifier.kodeprodiKODEPRODI57302#Rekayasa Keamanan Siber
dc.identifier.nidnNIDN0029088902
dc.identifier.nimNIM4332001031
dc.identifier.urihttps://repository.polibatam.ac.id//handle/PL29/5333
dc.language.isoother
dc.publisherPoliteknik Negeri Batam
dc.subjectActive Response
dc.subjectCloud Security
dc.subjectDefense in Depth
dc.subjectModSecurity
dc.subjectSIEM
dc.subjectSuricata
dc.subjectWazuh
dc.titleImplementation of Suricata and Cyber Attack Analysis with SIEM for Attack Verification and Mitigation
dc.typeArticle

Files

Original bundle

Now showing 1 - 3 of 3
Loading...
Thumbnail Image
Name:
4332001031_Article.pdf
Size:
547.93 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
Lembar_Pengesahan.pdf
Size:
118.43 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
Borang_Publikasi.pdf
Size:
195.8 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: