Analisis Efektivitas Integrasi Suricata dan Fail2Ban untuk Mendeteksi dan Memitigasi Serangan Brute Force SSH di Lingkungan Virtual

Repository Analytics

Statistic Details

Updated data
20Viewes
0Downloaded
20Accessed per month
4Countries
Loading...
Thumbnail Image

Authors

Ismail, Kevin

Journal Title

Journal ISSN

Volume Title

Publisher

Politeknik Negeri Batam

Abstract

A brute force attack is a type of cyberattack involving repeated login attempts using several combinations of usernames and passwords to gain unauthorized access. This attack also resulted in unauthorized access to the Secure Shell (SSH) protocol on a server if the attacker successfully obtains credentials. This study aims to analyze the effectiveness of the integration of Suricata and Fail2ban to detect and mitigate brute force attacks against the SSH protocol on a server running Proxmox VE by creating two virtual machines (VMs): an attacker VM and a target VM. The method used in this study was a quantitative method with an experimental approach. This study simulated an SSH brute force attack and measured the effectiveness of both systems to evaluate them using several parameters, namely Detection Rate, Detection Time, and Blocking Time. The results of the study show that integration of Suricata and Fail2ban is successful and effective in detecting and blocking brute force attacks on the SSH protocol.

Description

Citation

IEEE

Endorsement

Review

Supplemented By

Referenced By