Tri Sudinugraha
Universiti Malaysia Sarawak

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Experimental Web Server Incident Detection Based on Wazuh-Snort using SPDLC Method Agus Wijayanto; Ahmad Yazid Bustomi; Syaddam; Tri Sudinugraha
Intelligent System and Computation Vol 7 No 2 (2025): INSYST: Journal of Intelligent System and Computation
Publisher : Institut Sains dan Teknologi Terpadu Surabaya (d/h Sekolah Tinggi Teknik Surabaya)

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.52985/insyst.v7i2.477

Abstract

Web servers are essential but vulnerable to network attacks such as SYN Flood and port scanning. This study designs and implements an incident detection system by integrating Wazuh, Snort (IDS), and Telegram notifications following the Security Policy Development Life Cycle. Snort functions as a network sensor generating alerts forwarded to Wazuh for centralized log management and correlation; critical alerts are pushed to administrators via a Telegram bot for real-time response. The experimental environment uses virtualized machines that host a Wazuh server, a Snort IDS, a web server, and an attacker node. Evaluation metrics include detection accuracy, false-negative rate, and notification response time under two attack scenarios: SYN Flood and port scanning. Results indicate detection accuracy of 41.34% and a false-negative rate of 58.6% for SYN Flood attacks, with Snort-to-Wazuh latency of 13.559 ms and Telegram delivery of 0.4 s. Port scanning was detected with 100% accuracy and 0% false-negative rate, recording Snort-to-Wazuh latency of 1.490 ms and Telegram delivery of 1.33 s. The integration enhances centralized visibility and accelerates administrator awareness, yet it exhibits limitations for high-volume DoS traffic due to log buffering and throughput constraints. Recommendations include increasing Wazuh agent buffer capacity, optimizing Snort rules, and deploying higher-capacity hardware to improve detection under heavy attack loads.