Implementation of Suricata and Cyber Attack Analysis with SIEM for Attack Verification and Mitigation
| dc.contributor.advisor | Nelmiawati | |
| dc.contributor.author | Raffer, Valentino | |
| dc.date.accessioned | 2026-08-19T06:04:37Z | |
| dc.date.issued | 2026-07-22 | |
| dc.description.abstract | The escalating complexity of cyber threats, encompassing web application exploitations, Denial-of-Service (DoS), and brute-force attacks, necessitates cloud infrastructures to deploy adaptive and automated defense mechanisms. Standalone conventional detection systems frequently fall short in delivering immediate responses to multi-vector attacks. This research aims to design and implement a robust Defense in Depth (DiD) security architecture that synergizes network visibility, application-level security, and automated incident response powered by Security Information and Event Management (SIEM). The experimental environment was constructed on a cloud server, utilizing the Damn Vulnerable Web Application (DVWA) as the evaluation target. The defensive framework integrates ModSecurity as a Web Application Firewall (WAF) at the application layer, Suricata as a Network Intrusion Detection System (NIDS) at the network layer, and Wazuh as the centralized SIEM orchestrator. Penetration testing was executed via Kali Linux, simulating critical attack vectors including DoS, authentication brute-force, and web-based injections (SQLi, XSS, and File Upload). The empirical results demonstrate the architecture's high efficacy in real-time threat detection and mitigation. ModSecurity instantaneously intercepted malicious applicationlayer payloads, while Wazuh successfully correlated logs from Suricata and ModSecurity to trigger its Active Response module. This automation seamlessly executed a full IP block via iptables upon reaching predefined threat thresholds. Ultimately, the integration of Wazuh, Suricata, and ModSecurity establishes a resilient Defense in Depth ecosystem, significantly minimizing incident response times and fortifying cloud server defenses without requiring manual administrative intervention. | |
| dc.identifier.citation | IEEE | |
| dc.identifier.kodeprodi | KODEPRODI57302#Rekayasa Keamanan Siber | |
| dc.identifier.nidn | NIDN0029088902 | |
| dc.identifier.nim | NIM4332001031 | |
| dc.identifier.uri | https://repository.polibatam.ac.id//handle/PL29/5333 | |
| dc.language.iso | other | |
| dc.publisher | Politeknik Negeri Batam | |
| dc.subject | Active Response | |
| dc.subject | Cloud Security | |
| dc.subject | Defense in Depth | |
| dc.subject | ModSecurity | |
| dc.subject | SIEM | |
| dc.subject | Suricata | |
| dc.subject | Wazuh | |
| dc.title | Implementation of Suricata and Cyber Attack Analysis with SIEM for Attack Verification and Mitigation | |
| dc.type | Article |
Files
Original bundle
1 - 3 of 3
Loading...
- Name:
- 4332001031_Article.pdf
- Size:
- 547.93 KB
- Format:
- Adobe Portable Document Format
Loading...
- Name:
- Lembar_Pengesahan.pdf
- Size:
- 118.43 KB
- Format:
- Adobe Portable Document Format
Loading...
- Name:
- Borang_Publikasi.pdf
- Size:
- 195.8 KB
- Format:
- Adobe Portable Document Format
License bundle
1 - 1 of 1
Loading...
- Name:
- license.txt
- Size:
- 1.71 KB
- Format:
- Item-specific license agreed upon to submission
- Description:
