Jurnal Saintekom : Sains, Teknologi, Komputer dan Manajemen
Vol 15 No 2 (2025): September 2025

Implementasi Wazuh-ELK-Suricata untuk Deteksi Privilege Escalation di Ubuntu Server

Nuswantoro, Setio ardy (Unknown)
Ziaurrahman, M. (Unknown)
Miftahurrizqi, Miftahurrizqi (Unknown)
Achiril Haq, Muhammad (Unknown)
Rashid, Reza Athallah (Unknown)



Article Info

Publish Date
30 Sep 2025

Abstract

Privilege escalation is one of the most critical cyberattacks because it enables adversaries with limited rights to gain full system control. Such attacks often act as gateways to larger data breaches, as seen in the 2016 Uber incident that exposed 57 million users’ personal data. This study implements and evaluates an open-source integrated intrusion detection system by combining Wazuh (HIDS), Suricata (NIDS), and the ELK Stack (Elasticsearch, Logstash, Kibana) on Ubuntu Server.Experiments were conducted through privilege escalation attack simulations using Metasploit, covering kernel exploits, misconfigurations, and software vulnerabilities. Findings reveal that the integrated system delivers broader detection compared to the default Wazuh configuration, capturing both host-level activities and network traffic. Quantitatively, a major difference was observed in response time: the integrated system detected and blocked malicious actions within 1–2 seconds, whereas the standalone system required 2–5 minutes and lacked automated blocking capabilities.Additionally, integration with the Kibana dashboard provided real-time, interactive visualization of threats, enabling administrators to trace attack patterns and respond swiftly. Overall, this research demonstrates that an integrative approach enhances detection accuracy, shortens response time, and significantly improves the quality of cybersecurity monitoring

Copyrights © 2025






Journal Info

Abbrev

saintekom

Publisher

Subject

Computer Science & IT Decision Sciences, Operations Research & Management

Description

Jurnal Saintekom adalah singkatan dari Sains, Teknologi, Komputer dan Manajemen, merupakan jurnal ilmiah yang berfungsi sebagai media mengkomunikasikan ide, gagasan dan pemikiran seputar kajian aktual tentang sains, teknologi, komputer dan manajemen antarkademisi dan ...