7Viewes
Integrasi SIEM & SOAR untuk Otomatisasi Pemblokiran IP Address pada Router MikroTik
Repository Analytics
Statistic Details
0Downloaded
7Accessed per month
2Countries
Loading...
Date
Authors
Albazi, Muhammad Mirza
Journal Title
Journal ISSN
Volume Title
Publisher
Politeknik Negeri Batam
Abstract
The increasing sophistication of cyber threats and the enactment of Indonesia Law Number 27 of 2022 on Personal Data Protection require organizations to implement adequate security controls. PT XYZ has implemented a Security Information and Event Management (SIEM) system to monitor and analyze Indicators of Compromise (IoC) from internal servers. However, the response process and IP address blocking on MikroTik routers are still performed manually by the IT Division, leading to delayed responses and increased risk of data breaches. This study proposes the integration of SIEM and Security Orchestration, Automation, and Response (SOAR)to automate the threat response workflow, from IoC validation using threat intelligence to automatic IP address blocking execution on MikroTik routers via Application Programming Interface (API). The system was implemented in a UAT environment using Wazuh as SIEM, Shuffle as SOAR, MISP as threat intelligence, and a MikroTik RB951Ui-2nD router. System feasibility was evaluated using the User Acceptance Testing (UAT) method with a Likert scale-based questionnaire involving 14 respondents from all members of the IT Division of PT XYZ. The results show that all four evaluation variables system usability, ease of use, system reliability, and user satisfaction achieved scores in the "Very Good" category, with percentages of 88%, 87%, 90%, and 92% respectively. These findings indicate that the SIEM-SOAR integration system is well accepted and effective in automating IP address blocking as an initial step in mitigating cyber threats.
Description
Keywords
Citation
IEEE
